Skip to content
arrow_back
search
Annex A 5.37 verified ISO/IEC 27001:2022

Documented Operating Procedures for Information Processing

Ensure procedures are written down and accessible to those who need them.

record_voice_over

Plain language

Imagine running a business where no one knows exactly how to do their job because the instructions aren't written down. This control is basically saying: 'Let's not leave things to chance!' By documenting how information is processed, you ensure everyone knows what to do and how to do it, reducing mistakes and making sure everything runs smoothly.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Organisational controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

19 Mar 2026

Maturity levels

N/A

Official control statement

Operating procedures for information processing facilities shall be documented and made available to personnel who need them.
verified ISO/IEC 27001:2022 Annex A 5.37
priority_high

Why it matters

Without documented operating procedures, staff run processing tasks inconsistently, increasing outages, data handling errors and inability to repeat or audit processing steps.

settings

Operational notes

Maintain version-controlled operating procedures for each processing facility; assign owners, review after changes/incidents, and publish them where relevant staff can easily access.

Mapping detail

Mapping

Direction

Controls