Documents say what you intend to do; records prove what you did. Documents are living and get revised. Records are historical and must not be altered. Management systems require both, control them differently, and a surprising proportion of routine findings come from treating them the same way.
The distinction in practice
| Documents | Records |
|---|---|
| Policies, standards, procedures, the SoA, network diagrams | Access review exports, meeting minutes, incident tickets, training completions, audit reports |
| Revised over time; only the current version is authoritative | Fixed once created; superseding one is falsification |
| Need version control and approval | Need integrity, retention and retrievability |
| Answer "what are you supposed to do?" | Answer "did you do it?" |
ISO standards fold both into the single term documented information, with different requirements attached to each - which is why the clause reads as bureaucratic until you separate the two ideas.
Controlling documents
- A single authoritative location. The most common finding of all: three versions of the same policy in a wiki, a shared drive and someone's email. If people cannot tell which is current, the document is not controlled.
- Version number, approval date, approver and owner on the document itself - not only in the repository metadata, because documents get downloaded and circulated.
- A review cycle - annually is the norm, and the review must be evidenced even when nothing changes. "Reviewed, no changes required" with a date and a name is a valid record; silence is a finding.
- Change history showing what changed and why.
- Communication. An approved policy nobody was told about does not affect behaviour, and auditors test awareness, not publication.
- Withdrawal of superseded versions, or clear marking if they must be retained.
One place for policies and the evidence they generate
GRC Copilot keeps policy versions, approvals and acknowledgements together with the records your controls produce - each mapped to the requirements it satisfies.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Controlling records
- Integrity. A record stored where its author can silently edit it is weak evidence. System-generated records in ticketing or identity platforms are stronger than files in a folder for exactly this reason.
- Retention periods, defined and applied. Long enough for audit cycles and legal obligations; short enough to satisfy data protection requirements. Both directions are failure modes - insufficient retention loses evidence, indefinite retention of personal data is its own violation.
- Retrievability. Evidence you cannot find within a reasonable time is functionally absent during fieldwork.
- Legibility and context. A spreadsheet named "review final v3" tells the auditor nothing about what was reviewed, by whom, or when.
- Protection from loss - backed up like any other asset.
Never correct a record. If it was wrong, add a dated correction that references the original. Editing history to look better converts a control exception into an integrity finding, which is a categorically worse conversation.
The failures auditors find most
- Policies overdue for review - by far the most common, and the easiest to prevent with a calendar entry.
- Multiple versions in circulation with no clear authority.
- No approval evidence. The document says "approved by the board"; there are no minutes recording it.
- Records that cannot be produced - the activity happened, the evidence was never kept.
- Undated evidence. A screenshot with no timestamp cannot be tied to the audit period.
- Retention undefined, so records are deleted or hoarded arbitrarily.
Keeping it proportionate
None of this requires a document management system. A repository with version history, a naming convention, an owner per document, and review dates in the compliance calendar covers the requirement for most organisations. What it does require is that one person is accountable for the set - otherwise documents drift out of date individually and nobody notices until fieldwork.
Frequently asked questions
How often must policies be reviewed?
Annually is the common baseline, plus on significant change. Whatever interval your own policy states becomes the standard you are audited against - so do not commit to quarterly unless you mean it.
Do we need a formal document management system?
No. Any repository with version history and controlled access is sufficient if it is used consistently and there is one authoritative copy.
Can a wiki be the source of truth?
Yes, provided it supports approval, version history and access control. Pure wiki pages that anyone can edit without an approval trail are weak for policies, though fine for supporting guidance.
How long should we keep evidence?
At minimum through the current certification cycle plus the previous one - commonly three years - subject to legal, contractual and data protection constraints that may pull in either direction.
Key takeaways
- Documents are revised and need version control; records are fixed and need integrity and retention.
- One authoritative location, with version, owner, approver and date on the document itself.
- Evidence a review happened even when nothing changed.
- Correct records by appending, never by editing - the alternative is an integrity finding.