IT Documentation for Audits: What Indian Regulators Actually Expect to See

By Deepika Nair · 17 March 2026

Documentation is the Audit Currency

"We do this" is not evidence. "Here is the policy, here is the procedure, here is the log showing it was executed on this date by this person" — that is evidence. Every Indian compliance framework demands documented evidence of controls, not verbal assurances. ISO/IEC 27001:2022 Clause 7.5 dedicates a section to Documented Information requirements, specifying what must be documented, how it must be controlled, and how it must be retained. CERT-In incident reporting obligations require documented incident response procedures to be in place before an incident occurs. The RBI Cybersecurity Framework requires a documented information security policy approved at board level.

Mandatory Documentation by Framework

DocumentISO 27001CERT-InRBI
Information Security Policy✓ Required✓ Required✓ Required
Asset Inventory Register✓ Required✓ RequiredRecommended
Risk Assessment & Treatment Plan✓ RequiredRecommended✓ Required
Incident Response Procedure✓ Required✓ Required✓ Required
BCP / DR Plan✓ Required✓ Required✓ Required
Change Management Log✓ RequiredPartial✓ Required

Document Control Essentials

Every policy and procedure document must include: a version number, effective date, review date, approver name and signature, and a change history log. Store documents in a version-controlled system (SharePoint, Confluence, or a dedicated DMS). ISO 27001 auditors will specifically check that documents are approved, reviewed within their required frequency (typically annually), and accessible to those who need them.

Evidence vs. Policy: Understanding the Difference

  • Policy: The rule — "All user accounts must be reviewed quarterly." This is the documented intent.
  • Procedure: How the rule is executed — "The IAM team will generate an access report from AD on the first Monday of each quarter and distribute to department heads for review."
  • Evidence: Proof it happened — the access report, the distribution email, the completed review forms with manager signatures, and the access revocations executed.

All three levels are required. A policy without evidence of execution is a compliance finding.

Documentation Gaps Assessment Included in IGaaS

InfraVeritas 360 reviews your existing policy documentation, identifies gaps against CERT-In and ISO 27001 mandatory requirements, and provides a prioritised documentation remediation plan.

Assess Your Documentation Readiness →