Most ISO 28000 projects slow down when the team asks a simple question: “What documents do we actually need?” For logistics companies, ports, warehouses, freight forwarders, customs brokers, and import/export businesses, the pressure is usually commercial. A customer, port authority, tender, insurer, or enterprise buyer wants proof that supply chain security is managed properly. This guide gives you a documentation-first ISO 28000 documentation requirements checklist for 2026, with the documents, audit evidence, risk records, and implementation checklists you should prepare before certification.
Quick Answer
ISO 28000 documentation requirements are based on documented information needed to establish, operate, monitor, audit, review, and improve a supply chain security management system. For certification, you normally need a defined scope, security policy, risk assessment, security objectives, operational controls, incident records, competence records, internal audit evidence, management review minutes, and corrective action records.
The safest approach is to build your ISO 28000 file around Clauses 4 to 10, then map each document to audit evidence. An auditor will not only check whether the document exists; they will check whether your records prove the security management system is working in real logistics, warehouse, port, or supply chain operations.
In This Guide
- What Documents Are Required for ISO 28000 Certification?
- ISO 28000 Documentation Checklist by Clause
- ISO 28000 Supply Chain Security Risk Assessment Documents
- ISO 28000 Audit Evidence: What Records Do You Need?
- ISO 28000 vs ISO 22301: Which Standard Do You Need?
- ISO 28000 Templates for Logistics and Supply Chain Companies
- Common Mistakes in ISO 28000 Documentation Requirements
- Frequently Asked Questions
- Next Steps
What Documents Are Required for ISO 28000 Certification?
ISO 28000:2022 uses the modern ISO management system structure, so the language is “documented information” rather than a fixed list of forms. In practice, certification bodies still expect a clear document set showing how your supply chain security management system is planned, controlled, measured, audited, and improved.
ISO describes ISO 28000:2022 as a security management system standard covering aspects relevant to the supply chain. You can confirm the official standard listing through the ISO standards catalogue.
What should be in an ISO 28000 document set?
A practical ISO 28000 document set should include:
- Scope of the security management system
- Context and interested parties analysis
- Security policy
- Security roles, responsibilities, and authorities
- Supply chain security risk assessment methodology
- Risk register and risk treatment plan
- Security objectives and action plans
- Operational security procedures and control plans
- Supplier, contractor, visitor, cargo, and facility security controls where relevant
- Incident reporting and investigation procedure
- Emergency preparedness and response arrangements
- Competence, awareness, and training records
- Monitoring and measurement records
- Internal audit programme, checklist, and audit reports
- Management review agenda, minutes, and actions
- Nonconformity and corrective action records
For UAE and GCC supply chains, this documentation is especially useful where operations involve free zones, bonded warehouses, cross-border transport, customs coordination, high-value cargo, port operations, or subcontracted logistics providers. The standard is not only about theft prevention. It is about building a repeatable management system for security risks across the chain.
Quick check: Can you explain your ISO 28000 scope in one sentence? If your scope does not clearly state the sites, services, cargo flows, and activities covered, your documentation will feel vague during Stage 1 audit review.
ISO 28000 Documentation Checklist by Clause
The easiest way to organise your ISO 28000 checklist is to map each document to Clauses 4 to 10. This helps you avoid a common problem: having plenty of forms, but no clear evidence that each clause has been addressed.
| ISO 28000 clause | Documented information to prepare | Audit evidence to keep |
|---|---|---|
| Clause 4 — Context of the organization | Scope, internal and external issues, interested parties, supply chain boundaries | Approved scope statement, stakeholder register, context review notes |
| Clause 5 — Leadership | Security policy, roles and responsibilities, accountability structure | Signed policy, organization chart, role descriptions, leadership communications |
| Clause 6 — Planning | Security risk assessment, risk treatment plan, security objectives | Risk register, objective tracking, action plans, risk review records |
| Clause 7 — Support | Competence matrix, training plan, communication process, document control process | Training records, awareness briefings, document revision history, communication logs |
| Clause 8 — Operation | Operational control procedures, supplier controls, incident response process | Access logs, shipment checks, contractor approvals, incident reports, drill records |
| Clause 9 — Performance evaluation | Monitoring plan, internal audit procedure, management review process | KPIs, inspection results, audit reports, management review minutes |
| Clause 10 — Improvement | Nonconformity and corrective action procedure, improvement log | Corrective action records, root cause analysis, effectiveness checks |
How do you turn ISO 28000 clauses into an audit checklist?
Start with the clause requirement, then ask: “What document proves we planned this?” and “What record proves we did it?” For example, Clause 9.2 requires internal audits. The procedure explains how audits are planned and performed. The audit programme, completed checklist, audit report, findings, and corrective actions prove it happened.
If your organization already has ISO 9001, ISO 14001, ISO 45001, or ISO 22301, you may be able to integrate document control, internal audit, management review, corrective action, and competence processes. For organizations comparing standards or building an integrated system, the ISO documentation toolkits collection is a useful place to review related document packages.
ISO 28000 Supply Chain Security Risk Assessment Documents
Your risk assessment is the centre of an ISO 28000 supply chain security management system. Auditors will expect to see a structured method, not just a list of security worries. The risk process should cover threats, vulnerabilities, consequences, existing controls, residual risk, treatment actions, responsibilities, and review dates.
What risks should an ISO 28000 risk register include?
Typical supply chain security risks include theft, cargo tampering, unauthorized access, smuggling, fraudulent documentation, subcontractor failure, cyber-enabled disruption, insider threats, route disruption, customs delay, counterfeit goods, and security incidents at third-party facilities. The exact list depends on your scope.
| Risk | Control | Document | Record |
|---|---|---|---|
| Unauthorized access to warehouse or yard | Access control, visitor approval, badge checks, CCTV monitoring | Access control procedure | Visitor log, access review, CCTV maintenance record |
| Cargo tampering during storage or transit | Seal checks, loading supervision, exception reporting | Cargo security inspection procedure | Seal verification record, loading checklist, incident report |
| Unverified subcontracted transport provider | Supplier due diligence and approved carrier list | Supplier security evaluation procedure | Supplier assessment, approval record, performance review |
| Fraudulent shipping or customs documentation | Document verification, segregation of duties, escalation rules | Document control and shipment verification procedure | Shipment file review, discrepancy log, corrective action |
| Security incident at port, free zone, or border crossing | Incident response plan and communication escalation | Security incident response procedure | Incident report, investigation record, lessons learned log |
Pro tip: Do not make your risk register too generic. “Supply chain disruption” is not enough. Break it down by facility, route, cargo type, supplier category, and security scenario so the control is specific enough to audit.
How often should ISO 28000 security risks be reviewed?
ISO management systems require risks and controls to stay current. In practical terms, many logistics and warehouse businesses review risks at planned intervals, after incidents, after major operational changes, and before expanding into new routes or facilities. For fast-moving UAE and GCC operations, a quarterly risk review can be sensible where cargo types, customer requirements, or subcontractors change frequently.
ISO 28000 Audit Evidence: What Records Do You Need?
ISO 28000 audit evidence is the record trail proving that your system works. Policies and procedures show intent. Records show implementation. During certification, the auditor will sample evidence across the scope, usually during a Stage 1 documentation review and Stage 2 implementation audit.
What ISO 28000 records do auditors usually sample?
Expect auditors to sample records connected to real operations. For a freight forwarder, that may include shipment files, carrier approvals, route risk decisions, and customer security requirements. For a warehouse, it may include access records, visitor logs, loading checks, CCTV maintenance records, incident reports, and training evidence.
- Approved ISO 28000 scope and security policy
- Risk assessment and risk treatment records
- Security objectives and KPI tracking
- Operational control records for cargo, site, supplier, and route security
- Competence records for staff in security-sensitive roles
- Internal audit programme, audit checklist, findings, and report
- Management review minutes and action tracking
- Nonconformity, corrective action, and effectiveness review records
How do you prepare ISO 28000 audit evidence before certification?
Use a simple evidence index. List each clause, the document that addresses it, the record that proves implementation, the owner, and the location of the file. This avoids last-minute searching during the audit and makes your team look controlled and prepared.
- Confirm the scope: Define the sites, services, cargo flows, departments, and outsourced activities included in the ISO 28000 system.
- Build the document map: Match each clause to the relevant policy, procedure, form, register, or plan.
- Collect live records: Gather evidence from real operations, not sample forms created only for the auditor.
- Run an internal audit: Test whether the system meets the standard and whether staff can explain their responsibilities.
- Hold management review: Review performance, risks, incidents, audit results, objectives, resources, and improvement actions.
- Close corrective actions: Record root cause, action taken, responsibility, due date, and effectiveness review.
Quick check: Pick one recent shipment, visitor entry, supplier approval, or security incident. Can you trace it from risk assessment to operational control to record? If not, your audit evidence is probably fragmented.
ISO 28000 vs ISO 22301: Which Standard Do You Need?
ISO 28000 and ISO 22301 are both resilience-related standards, but they solve different problems. ISO 28000 focuses on security management, including aspects relevant to the supply chain. ISO 22301:2019 focuses on business continuity management: keeping critical activities running during disruption.
| Question | ISO 28000:2022 | ISO 22301:2019 |
|---|---|---|
| Main purpose | Manage security risks affecting the organization and supply chain | Maintain and recover critical business activities during disruption |
| Best fit | Logistics, ports, freight forwarding, warehousing, import/export, high-value cargo | Organizations needing formal continuity plans, recovery strategies, and crisis response |
| Core documents | Security risk assessment, security controls, incident response, supplier security records | Business impact analysis, continuity plans, recovery objectives, exercise records |
| Audit focus | Security threats, vulnerabilities, operational controls, supply chain assurance | Continuity risks, recovery capability, crisis response, testing and exercises |
Do logistics companies need ISO 28000 or ISO 22301?
Choose ISO 28000 if your main concern is supply chain security: cargo protection, facility access, supplier security, transport risks, and security incident control. Choose ISO 22301 if the main concern is business continuity after disruption, such as IT outage, facility loss, major supplier failure, or regional crisis. Some ports, logistics groups, and critical supply chain operators use both because the standards support different types of assurance.
If continuity planning is also part of your customer or tender requirement, review the ISO 22301 BCMS Documentation Toolkit alongside your ISO 28000 planning.
ISO 28000 Templates for Logistics and Supply Chain Companies
ISO 28000 templates help you avoid writing every policy, procedure, register, and form from scratch. They are especially useful when the person managing certification already has a full-time role in operations, compliance, QHSE, or logistics management.
What should ISO 28000 templates include?
Good ISO 28000 templates should cover the management system documents and the operational records needed for audit evidence. Look for editable Word documents, clear ownership fields, clause references, version control, practical forms, and templates that can be adapted for ports, warehouses, transport providers, freight forwarders, and import/export companies.
A template should not lock you into generic wording. It should give you a strong starting point, then allow you to customise the scope, risks, controls, roles, and records to match your actual operation.
Can ISO 28000 templates be used without a consultant?
Many SMEs can use ISO 28000 templates without a full implementation consultant if they have a capable internal owner and a clear project plan. Larger, multi-site, high-risk, or regulated operations may still benefit from external support, especially if the certification deadline is tight or the business has complex outsourced activities.
If you need hands-on implementation support instead of a documentation package, UCS ISO Certification Services can support organizations that prefer guided implementation.
Pro tip: Before buying any ISO 28000 templates, check whether the package includes records as well as procedures. Auditors cannot certify a well-written procedure alone; they need evidence that the procedure has been used.
Common Mistakes in ISO 28000 Documentation Requirements
Most ISO 28000 documentation problems are not caused by the standard being too difficult. They happen because organizations prepare documents that look polished but do not reflect how the supply chain actually works.
What are the most common ISO 28000 documentation mistakes?
- Writing a scope that is too broad: If the scope says “all logistics activities” but excludes subcontracted transport, bonded storage, or port handover in practice, the auditor will challenge the boundary.
- Using a generic risk register: A useful risk register should reflect cargo type, route, facility, supplier, and security scenario.
- Separating documents from records: A procedure without completed forms, logs, reviews, or incident records will not prove implementation.
- Ignoring outsourced providers: Freight carriers, warehouse contractors, security guards, customs agents, and IT providers can all affect supply chain security.
- Treating ISO 28000 as a one-time project: Certification requires ongoing internal audit, management review, monitoring, corrective action, and continual improvement.
- Preparing only for Stage 2: Stage 1 often identifies documentation gaps before the implementation audit. Your document map should be ready before Stage 1.
How do you avoid ISO 28000 audit findings?
Audit your own system before the certification body arrives. Select a sample of real activities, then test whether the risk assessment, operational controls, training records, supplier records, and incident process line up. If your evidence chain is weak, fix it before the external audit.
For broader ISO planning, especially if you are comparing management system standards across the business, our complete guide to ISO standards can help you decide how ISO 28000 fits with other certification goals.
Frequently Asked Questions
What documents are required for ISO 28000 certification?
ISO 28000 certification normally requires documented information covering the scope, context, interested parties, security policy, risk assessment, risk treatment, security objectives, operational controls, competence, communication, document control, internal audit, management review, incidents, nonconformities, corrective actions, and continual improvement. The exact document set depends on your organization’s size, scope, supply chain activities, and security risks.
What is ISO 28000 used for?
ISO 28000:2022 is used to establish, implement, maintain, and improve a security management system, including aspects relevant to the supply chain. Organizations use it to manage security risks such as cargo theft, unauthorized access, tampering, supplier security failures, documentation fraud, and security incidents across logistics, warehousing, ports, transport, and import/export operations.
Is ISO 28000 for logistics companies?
Yes, ISO 28000 is highly relevant for logistics companies, freight forwarders, warehouses, ports, customs brokers, transport providers, and import/export businesses. It is not limited to logistics, but supply chain security is one of its strongest use cases because these organizations manage cargo movement, third-party providers, facilities, routes, documentation, and handover points where security risks can occur.
What is the difference between ISO 28000 and ISO 22301?
ISO 28000:2022 focuses on security management, including risks relevant to the supply chain. ISO 22301:2019 focuses on business continuity management, including recovery plans, business impact analysis, continuity strategies, and disruption response. Choose ISO 28000 when security assurance is the priority. Choose ISO 22301 when continuity and recovery capability are the main business need.
How long does ISO 28000 certification take?
ISO 28000 certification commonly takes 8 to 12 weeks for a small or mid-size organization with a clear scope, active management support, and existing operational controls. Complex, multi-site, port, warehouse, or cross-border supply chain operations may take longer, especially where risk assessments, supplier controls, incident processes, training records, and internal audits need to be built from scratch.
Can ISO 28000 help with supply chain security risk?
Yes, ISO 28000 helps organizations manage supply chain security risk through a structured management system. It supports risk identification, risk treatment, operational controls, supplier oversight, incident response, monitoring, internal audit, management review, and continual improvement. The value is not only having controls, but proving that those controls are planned, implemented, checked, and improved over time.
Can I use ISO 28000 templates for certification?
Yes, ISO 28000 templates can be used for certification if they are properly customised to your organization’s scope, risks, operations, roles, suppliers, and records. Templates are a starting point, not a substitute for implementation. Certification auditors will expect completed evidence such as risk records, training records, internal audits, management reviews, incident reports, and corrective actions.
Next Steps
ISO 28000 documentation requirements are manageable when you treat them as an evidence system, not a paperwork exercise. Start with the scope, map documents to Clauses 4 to 10, build a practical security risk register, then collect records that prove the controls work in day-to-day logistics and supply chain operations.
Ready to build your ISO 28000 certification file faster? Our ISO 28000 Documentation Toolkit gives you editable templates for policies, procedures, forms, checklists, and audit evidence so you do not have to write everything from scratch.


