Required Documents
Getting started with Required Documents
Required Documents holds the evidence-style documents your frameworks demand but that aren't policy: an internal audit report, an organisation chart, a network diagram, your information security objectives. You'll find them under Documents in the menu.
They behave like policies in almost every respect — same overview, same statuses, same editor, same scope rule. The one difference that matters is what happens over time, and it's the reason they get their own page.
Required documents versus policies
A policy is one living document. Your access control policy this year is the same access control policy as last year, revised. Approving it produces a new version of the same thing, and the older versions become history.
A required document is a recurring obligation. Your 2026 internal audit report doesn't replace the 2025 one — both have to exist, because an auditor asking for three years of audit reports wants three reports, not the newest one with a version history behind it.
| Policies | Required Documents | |
|---|---|---|
| What it is | One document, maintained over time | A recurring obligation, met again each cycle |
| What builds up | Versions of the same document | Separate documents, one per cycle |
| Typical rhythm | Revised when something changes | Produced on a schedule, often annually |
| Examples | Access control policy, acceptable use policy | Internal audit report, management review, organisation chart |
This is a difference in how you use them, not in what the screens can do. Both pages offer the same three routes for filling a document, the same approval and review flow, and the same version history.
What that looks like in practice
For a policy, opening the document history shows the same policy at different points in its life — v1.0 approved, v1.1 draft, and so on.
For a required document, it shows the separate documents you've filed against that obligation. Each one is approved in its own right, and each stays available after the next one arrives.
Filing this year's report? Add a new document rather than editing last year's approved one. Editing creates a new version of the existing report, which is the policy pattern — it leaves you with one report that claims to cover two years.
Read more about this in Working with required documents.
The overview
When you open Documents you see every required document that applies to your organisation, at "Not started" until you give it content.
For each one you see:
- Name and Tidal ID
- Type (paperclip for uploaded files)
- Owners (if already assigned)
- Status (Not started, Draft, Approved, To Review)
- Last approval (if applicable)
- Actions (Start button to begin)
Status meanings
- Not started: No document linked yet
- Draft: Document available but not yet approved
- Approved: Approved document within the last 12 months
- To Review: No recent approval (older than 12 months)
"To Review" after 12 months is what makes the recurring rhythm visible. A required document that was approved more than a year ago moves to "To Review" on its own, which is your prompt that this cycle's document is due.
Search and filter
- In scope / Out of scope tabs - Switch between required documents that count towards compliance and those that don't
- Search bar - Type names or Tidal IDs to find a specific document
- Status filter - Filter on Not started, Draft, Approved, or To Review
- Framework filter - Show only documents required by a specific framework
- Type filter - Distinguish between internally managed and uploaded documents (paperclip icon)
In scope vs Out of scope
Scope works exactly as it does for policies. Every required document has its own test in Tidal, named after the document, and that test decides the scope:
In scope required documents:
- Test is linked to at least one control in your ISMS
- Count towards framework progress and compliance scoring
- Shown by default when you open Documents
Out of scope required documents:
- Test is linked to no control at all
- No effect on your scores - the document isn't required in your environment
- Only visible under the "Out of scope" tab
To bring one in scope, link its test to the control that requires it, on the control's "Tests" tab. The full steps are in Getting started with Policies, and they apply here unchanged.
Don't see a required document you expected? Check the "Out of scope" tab before assuming it's missing.
Next steps
- Fill your first required document via Working with required documents
- Bring documents in scope by linking their tests in Editing and managing controls
- Compare with policies in Getting started with Policies
- Previous
- Troubleshooting & FAQ