You need written policies before an auditor will certify your ISMS. Clause 5.2 requires an information security policy, and Annex A expects a documented set of rules behind your controls. Starting from a blank page is slow, and most teams waste weeks on wording that an auditor never reads closely.
So here is the short answer. ISO 27001 compliance policy templates give you a structure to adapt, but they only pass an audit when you tailor them to how your business actually works. A generic iso 27001 compliance template copied word for word is the most common reason we see policies fail the Stage 1 audit.
This article covers seven core policies every ISMS needs, from the information security policy to the acceptable use policy. For each one, you will see what it must contain, who should own it, and what auditors look for. We have supported ISO 27001 implementation and certification for years, so the advice comes from real audits, not theory. Adapt, approve, then communicate each policy, and you will have a defensible foundation for certification.
1. Information security policy
This is the first document an auditor asks for, so write it before anything else. Every other policy in your ISMS documentation hangs off it, and it sets the tone for the audit.

What it covers and why Clause 5.2 requires it
Clause 5.2 makes top management responsible for a policy that fits your organisation’s purpose. It must include information security objectives (or a framework for setting them) and a commitment to meet applicable requirements. It also needs a commitment to continual improvement. You keep it as documented information, communicate it internally and make it available to interested parties where relevant. Annex A control 5.1 adds that it must be approved and reviewed at planned intervals.
What to include in the template
Keep it to one or two pages. A usable template has seven parts:
- Purpose and scope, matching your ISMS scope statement
- Security objectives, measurable where possible
- Commitments to legal, regulatory and contractual requirements
- Commitment to continual improvement
- Roles and responsibilities
- References to supporting policies
- Approval signature, version number and review date
Who it is for and who should own it
Every employee, contractor and relevant supplier within your scope should be able to read it. Ownership matters more than most teams expect. Top management must approve and sign it, while an ISMS manager or CISO maintains it day to day. In a smaller business, that usually means the managing director signs and the IT manager keeps it current.
The information security policy is a commitment from top management, not a document written by IT and filed away.
Common mistakes to avoid
Mistakes are predictable. The first is leaving template wording in place, such as another company’s name or a scope that does not match yours. The second is setting objectives nobody can measure, like "improve security". Aim for something testable, such as completing phishing training for 95% of staff each year. Auditors also ask for evidence of communication, so keep induction records or intranet acknowledgements. Finally, diarise the annual review, because an out-of-date policy is an easy nonconformity.
2. Acceptable use policy
Next comes the policy your staff will actually read. It turns top-level commitments into plain rules for daily behaviour, and it is usually the quickest of these ISO 27001 compliance policy templates to adapt.
What it covers and why Clause 5.2 requires it
Strictly, Clause 5.2 requires only the top-level policy. This one sits beneath it. Annex A control 5.1 expects topic-specific policies, and control 5.10 requires rules for the acceptable use of information and assets.
Auditors read it as evidence that commitments reach people’s daily habits, and they often sample staff to check.
What to include in the template
Cover these areas in plain English, keeping the document to two or three pages:
- Company devices, email and internet use
- Personal devices and remote working
- Password and screen-lock rules
- Removable media and cloud storage
- Handling confidential data and social media
- Reporting incidents, and the consequences of breaches
Who it is for and who should own it
Everyone with access to your systems must follow it, including contractors and temps. The IT or ISMS manager usually drafts it, HR enforces it through contracts, and top management approves it.
Get a signed acknowledgement at induction, then repeat it annually.
An acceptable use policy only counts once staff have read it and signed to say so.
Common mistakes to avoid
Many teams copy a legalistic template that nobody understands. Others ban everything, so staff ignore the lot. Watch for missing acknowledgement records and for gaps around personal devices and AI tools, which your people already use.
Review it yearly alongside the information security policy so the two stay aligned.
3. Access control policy
Third on the list is the policy that decides who sees what. Auditors test it harder than most, because weak access is behind a large share of breaches.
What it covers and why Clause 5.2 requires it
Clause 5.2 does not name this policy, but your top-level commitment to protect information has to be backed by rules. Annex A control 5.15 requires documented access control rules based on business and security needs. Controls 5.16 to 5.18 and 8.2 extend that to identity management, access rights and privileged accounts.
What to include in the template
Keep it to two or three pages and cover:
- Least privilege and need-to-know as the guiding principles
- A joiner, mover and leaver process, with access removed on the leaving day
- Approval of access requests by the information owner
- Password and multi-factor authentication rules
- Tighter controls for admin and privileged accounts
- Physical access to offices and server rooms
- Scheduled access reviews, more often for admin accounts
Who it is for and who should own it
Every user, administrator and supplier with system access falls under it. The IT manager usually owns it, HR triggers the joiner and leaver steps, and information owners approve access to their own data. Top management signs it off.
Common mistakes to avoid
Leavers are the classic failure. Auditors pick recent leavers and check that accounts were disabled promptly. Others promise quarterly reviews that never happen. Keep dated review records with sign-off, and include shared accounts and cloud apps, which often escape the process.
Grant access for a reason, review it on a schedule and remove it on time.
4. Risk assessment and treatment policy
Risk drives everything else in ISO 27001. Of all the ISO 27001 compliance policy templates, this is the one where copying hurts most, because your risks are specific to you and auditors know it.
What it covers and why Clause 5.2 requires it
Clause 5.2 does not name this policy, but Clauses 6.1.2 and 6.1.3 require a defined risk assessment process and a risk treatment process. The results feed your Statement of Applicability, which explains why each Annex A control is in or out. Auditors want to see repeatable, consistent scoring.
What to include in the template
Keep it to two or three pages and define:
- Your risk assessment framework and scoring scales for likelihood and impact
- Risk acceptance criteria
- How you identify assets, threats and vulnerabilities
- Named risk owners
- Treatment options: modify, retain, avoid or share
- The risk treatment plan, reviewed at least yearly and after major change
Who it is for and who should own it
The ISMS manager or CISO runs the process, but risk owners must be business people who can accept residual risk. Top management approves the policy and the acceptance criteria.
A risk is only treated once a named owner has accepted what remains.
Common mistakes to avoid
Overly complex scoring is the usual trap, because nobody can repeat it. Others build a register once and never update it. Auditors check that residual risk is signed off and that the treatment plan matches your Statement of Applicability. A well-adapted iso 27001 compliance template with a simple spreadsheet works fine for most small businesses.
5. Incident response policy
When something goes wrong, nobody wants to improvise. This policy sets out who does what in the first hour, and auditors treat it as proof that your ISMS works under pressure.

What it covers and why Clause 5.2 requires it
Clause 5.2 does not name this policy, but a commitment to protect information needs a plan for when protection fails. Annex A controls 5.24 to 5.28 and 6.8 require planned incident management, covering reporting, assessment, response, learning and evidence collection.
What to include in the template
Keep it to two or three pages, with a one-page playbook attached. Define:
- What counts as an event versus an incident
- How staff report, and to whom, including an out-of-hours contact
- Severity levels with target response times
- Incident response roles: incident lead, IT, communications and legal
- Escalation and notification rules, including the ICO’s 72-hour window under UK GDPR
- Evidence preservation
- A post-incident review with lessons logged
Who it is for and who should own it
Every member of staff must know how to report a suspected incident. The ISMS manager or CISO owns the policy, and top management approves it. Senior leaders also make the external communication decisions, so name them in advance.
Common mistakes to avoid
Untested plans are the biggest failure. Run a tabletop exercise at least once a year and keep the notes. Teams also forget to list insurer and legal contacts, which costs time on the day. Auditors expect an incident log and evidence of lessons learned, even when the log only holds near misses.
An incident response policy is only worth the last time you rehearsed it.
6. Business continuity and backup policy
Ransomware, a failed supplier or a flooded office all lead to the same question: how fast can you recover? Of all the ISO 27001 compliance policy templates, this is the one where evidence beats wording, because auditors ask to see a backup actually restored.

What it covers and why Clause 5.2 requires it
Clause 5.2 does not name this policy, but a commitment to protect information has to hold during disruption too. Annex A controls 5.29 and 5.30 cover security and ICT readiness for business continuity, while control 8.13 requires backups that are maintained and tested.
What to include in the template
Keep it to two or three pages and set recovery objectives for each critical service. Cover:
- Recovery time and recovery point objectives
- Backup scope, frequency and the 3-2-1 rule (three copies, two media types, one offsite)
- Encryption, plus offline or immutable copies
- A restore testing schedule
- Disaster recovery steps and alternative working arrangements
- A communication plan for staff and customers
- Review dates, including after major change
Who it is for and who should own it
Every team that runs or depends on a critical system needs to know its part. The IT manager usually owns the policy, and top management approves the recovery objectives because they carry the cost. Heads of department confirm how much downtime their teams can really tolerate.
Common mistakes to avoid
The classic failure is untested backups. Teams find corrupt or incomplete copies only in a crisis, so test a restore at least twice a year and keep the results.
A backup you have never restored is only a hope.
Also watch for backups on the same network as production, which ransomware encrypts too. Finally, avoid objectives set without the business, since IT alone cannot judge what an hour of downtime costs.
7. Supplier and third-party security policy
Your ISMS is only as strong as the weakest supplier holding your data. Cloud hosts, payroll bureaus and IT contractors all sit inside your risk, so auditors want a documented supplier process and proof that you follow it.
What it covers and why Clause 5.2 requires it
Clause 5.2 does not name this policy, but a commitment to protect information cannot stop at your own network. Annex A controls 5.19 to 5.23 require security requirements in supplier relationships and agreements, plus ICT supply chain management, monitoring of supplier services and rules for cloud use.
What to include in the template
Keep it to two pages and cover:
- Supplier tiers by risk, such as critical, important and low
- Due diligence before onboarding, including ISO 27001 or Cyber Essentials Plus evidence
- Mandatory contract clauses, including breach notification times and audit rights
- UK GDPR data processing terms
- Annual reviews for critical suppliers
- Exit arrangements covering data return and deletion
- A maintained supplier register
Who it is for and who should own it
Anyone who buys, renews or manages a third-party service must follow it, so that includes procurement, finance and department heads. The IT manager or ISMS manager usually owns it, and top management approves it. Name a relationship owner for each critical supplier, because someone has to chase the evidence.
A supplier becomes part of your risk the day it touches your data.
Common mistakes to avoid
Questionnaires that get filed and never read are the classic failure. Even the best ISO 27001 compliance policy templates cannot tell you which suppliers are critical, so tier them yourself. Teams also forget shadow IT, such as a SaaS tool bought on a company card, which never reaches the register. Finally, check that contracts contain the security clauses you list, since auditors sample both.
Turning templates into a working ISMS
Seven policies will not certify you on their own. Treat each template as a starting point, then adapt it, get top management to approve it and prove that staff have read it. Keep dated records of every review, restore test and acknowledgement, because auditors ask for them.
Good ISO 27001 compliance policy templates save you weeks of drafting, but auditors still judge what you do, not what you wrote. Policies that match real practice pass. Policies copied from a download rarely survive a sample of staff.
If you would rather not do this alone, TrustedIA’s ISO 27001 specialists can help you tailor these policies to your business and get ISO 27001 certified, drawing on over 30 years of IT services experience.



