Checklist for Clause 7.5.2 of ISO/IEC 42001 (AIMS): Creating and Updating Documented Information
1. Introduction
Below is a certification-grade, auditor-ready tabular checklist for Clause 7.5.2 of ISO/IEC 42001 - Creating and Updating Documented Information, developed directly from the PECB auditing slides and expanded into clear, testable, evidence-based audit criteria aligned with PECB / IAS-accredited audit practice.
This checklist ensures documented information is clearly identified, fit for purpose, properly formatted, stored appropriately, reviewed, approved, and kept current.
2. ISO/IEC 42001 - Clause 7.5.2: Creating and Updating Documented Information
Audit Checklist (Identification, Format, Media, Review & Control)
| # | Clause 7.5.2 Requirement Area | Audit Objective | Audit Questions (Checklist) | Expected Evidence | Conformance (Y/N/Partial) | Findings / Gaps | Risk Rating | Improvement Actions |
|---|---|---|---|---|---|---|---|---|
| 7.5.2-1 | Identification & Description | Confirm clear identification | Is documented information appropriately identified and described (title, date, author/owner, reference number)? | Document headers; metadata | ||||
| 7.5.2-2 | Unique Identification | Prevent confusion | Does each document have a unique identifier to distinguish it from others? | Document numbering scheme | ||||
| 7.5.2-3 | Document Purpose | Ensure relevance | Is the purpose and scope of each document clearly stated? | Purpose statements | ||||
| 7.5.2-4 | Format Appropriateness | Validate usability | Is documented information created in an appropriate format for its intended use? | Templates; format standards | ||||
| 7.5.2-5 | Language Suitability | Ensure understanding | Is the language used appropriate for the intended audience (clarity, terminology)? | Document samples | ||||
| 7.5.2-6 | Software Version Control | Prevent incompatibility | Where applicable, is the software version specified to ensure consistency and usability? | Version references | ||||
| 7.5.2-7 | Use of Graphics | Enhance clarity | Are graphics, diagrams, or tables used where necessary to aid understanding and accuracy? | Visual content review | ||||
| 7.5.2-8 | Media Specification | Confirm storage choice | Has the organization specified appropriate media for documented information (paper, electronic, or both)? | Media policy; procedures | ||||
| 7.5.2-9 | Accessibility | Ensure availability | Is documented information accessible to relevant users in the chosen media? | Access permissions; retrieval tests | ||||
| 7.5.2-10 | Security & Integrity | Protect information | Is documented information protected against unauthorized access, loss, or alteration? | Access controls; backups | ||||
| 7.5.2-11 | Review Process | Confirm quality control | Is there a defined process to review documented information for suitability and adequacy? | Review procedures | ||||
| 7.5.2-12 | Review Competence | Validate reviewers | Are documents reviewed by individuals with appropriate competence and authority? | Reviewer roles; approvals | ||||
| 7.5.2-13 | Accuracy & Relevance | Ensure correctness | Does the review process ensure content is accurate, relevant, and fit for purpose? | Review checklists | ||||
| 7.5.2-14 | Approval Before Issue | Confirm governance | Is documented information approved before initial issue or re-issue? | Approval records | ||||
| 7.5.2-15 | Change Identification | Maintain traceability | When documents are updated, are changes identified and traceable? | Change logs; revision history | ||||
| 7.5.2-16 | Version Status | Prevent obsolete use | Is the current revision status clearly indicated to prevent unintended use of obsolete information? | Version markings | ||||
| 7.5.2-17 | Timeliness of Updates | Ensure currency | Are documents updated promptly when changes to AIMS, risks, or processes occur? | Update records | ||||
| 7.5.2-18 | Alignment with AIMS | Ensure consistency | Do updates remain aligned with AIMS policy, objectives, and controls? | Cross-reference checks | ||||
| 7.5.2-19 | Record of Reviews | Provide evidence | Are records of reviews and approvals retained as documented information? | DMS records | ||||
| 7.5.2-20 | Management Oversight | Confirm accountability | Is the creation and updating of documented information subject to management oversight? | Management review minutes |
3. Auditor's Conclusion - Clause 7.5.2
| Assessment Area | Conclusion |
|---|---|
| Overall Conformance Status | ☠Conform ☠Minor NC ☠Major NC |
| Quality of Document Creation & Update | ☠High ☠Adequate ☠Weak |
| Control of Document Changes | ☠Effective ☠Partially Effective ☠Ineffective |
| Risk of Document-Related Failure | ☠Low ☠Medium ☠High |
4. Common Auditor Findings (Clause 7.5.2)
Auditors frequently raise findings where:
- Documents lack clear identification or ownership
- Formats are inconsistent or not fit for purpose
- Reviews are informal or not documented
- Obsolete documents remain accessible
- Updates occur but are not approved or traceable
This checklist explicitly prevents those nonconformities.
5. ISOLTX Operational Alignment
Clause 7.5.2 is operationalised through:
- DMS → Document templates, versioning, approvals
- AUDIT → Verification of document control effectiveness
- ERMS → Risk-driven document updates
- CAS/CAL → Mandatory documentation tracking
It ensures documented information is accurate, current, controlled, and audit-defensible.
6. Contact Us Today
Are you looking to grow into an Artificial Intelligence (AI) trusted company?
Contact Crest Advisory Africa today for expert guidance on implementing ISO 42001 frameworks tailored to your organization's needs.
Start your journey today. Visit crestadvisoryafrica.com or contact us at +27 (0) 764034307 or nico@crestadvisoryafrica.com.
Let's make 2026 the year of your professional breakthrough!