Required Documents

Getting started with Required Documents

Required Documents holds the evidence-style documents your frameworks demand but that aren't policy: an internal audit report, an organisation chart, a network diagram, your information security objectives. You'll find them under Documents in the menu.

They behave like policies in almost every respect — same overview, same statuses, same editor, same scope rule. The one difference that matters is what happens over time, and it's the reason they get their own page.

Required documents versus policies

A policy is one living document. Your access control policy this year is the same access control policy as last year, revised. Approving it produces a new version of the same thing, and the older versions become history.

A required document is a recurring obligation. Your 2026 internal audit report doesn't replace the 2025 one — both have to exist, because an auditor asking for three years of audit reports wants three reports, not the newest one with a version history behind it.

PoliciesRequired Documents
What it isOne document, maintained over timeA recurring obligation, met again each cycle
What builds upVersions of the same documentSeparate documents, one per cycle
Typical rhythmRevised when something changesProduced on a schedule, often annually
ExamplesAccess control policy, acceptable use policyInternal audit report, management review, organisation chart
Info

This is a difference in how you use them, not in what the screens can do. Both pages offer the same three routes for filling a document, the same approval and review flow, and the same version history.

What that looks like in practice

For a policy, opening the document history shows the same policy at different points in its life — v1.0 approved, v1.1 draft, and so on.

For a required document, it shows the separate documents you've filed against that obligation. Each one is approved in its own right, and each stays available after the next one arrives.

Tip

Filing this year's report? Add a new document rather than editing last year's approved one. Editing creates a new version of the existing report, which is the policy pattern — it leaves you with one report that claims to cover two years.

Read more about this in Working with required documents.

The overview

When you open Documents you see every required document that applies to your organisation, at "Not started" until you give it content.

For each one you see:

  • Name and Tidal ID
  • Type (paperclip for uploaded files)
  • Owners (if already assigned)
  • Status (Not started, Draft, Approved, To Review)
  • Last approval (if applicable)
  • Actions (Start button to begin)

Status meanings

  • Not started: No document linked yet
  • Draft: Document available but not yet approved
  • Approved: Approved document within the last 12 months
  • To Review: No recent approval (older than 12 months)
Note

"To Review" after 12 months is what makes the recurring rhythm visible. A required document that was approved more than a year ago moves to "To Review" on its own, which is your prompt that this cycle's document is due.

Search and filter

  • In scope / Out of scope tabs - Switch between required documents that count towards compliance and those that don't
  • Search bar - Type names or Tidal IDs to find a specific document
  • Status filter - Filter on Not started, Draft, Approved, or To Review
  • Framework filter - Show only documents required by a specific framework
  • Type filter - Distinguish between internally managed and uploaded documents (paperclip icon)

In scope vs Out of scope

Scope works exactly as it does for policies. Every required document has its own test in Tidal, named after the document, and that test decides the scope:

In scope required documents:

  • Test is linked to at least one control in your ISMS
  • Count towards framework progress and compliance scoring
  • Shown by default when you open Documents

Out of scope required documents:

  • Test is linked to no control at all
  • No effect on your scores - the document isn't required in your environment
  • Only visible under the "Out of scope" tab

To bring one in scope, link its test to the control that requires it, on the control's "Tests" tab. The full steps are in Getting started with Policies, and they apply here unchanged.

Info

Don't see a required document you expected? Check the "Out of scope" tab before assuming it's missing.

Next steps