The Statement of Applicability, Explained

The Statement of Applicability, Explained

Of all the documents in an ISO 27001 program, the Statement of Applicability is the one auditors reach for first. It is the spine of the whole system, the place where your risk decisions and your controls meet. Get it right and the audit goes smoothly. Get it wrong and everything downstream is suspect.

Here is what it is, what belongs in it, and how to keep it honest.

What the Statement of Applicability Is

The Statement of Applicability, often shortened to SoA, lists every control in Annex A of ISO 27001, states whether you applied it, and explains why. In the 2022 version of the standard, that is 93 controls across four themes: organizational, people, physical, and technological. For each one, the SoA records your decision and your justification.

Why It Exists

ISO 27001 does not require you to implement every control. It requires you to make a reasoned decision about each one, based on your risk assessment. The SoA is the record of those decisions. It connects the risks you identified to the controls you chose to treat them, and it documents why any control was left out. That link between risk and control is the heart of a real management system.

What Goes in It

The SoA is not a checklist you fill in at the end. It is a living document that reflects the real state of your controls.

Where Companies Go Wrong

The most common failure is a Statement of Applicability copied from a template, with justifications that do not match the company's actual risk assessment. Auditors see this immediately. A control marked applicable with a generic justification, but no evidence it operates, is a finding waiting to happen. So is an exclusion with no real reasoning behind it.

The fix is not more words. It is honest analysis. Every entry should trace back to a risk you actually assessed and a control that actually exists.

Keeping It Current

Your SoA is not finished at certification. As your risks change, your systems evolve, and your controls mature, the SoA has to keep pace. At every surveillance audit, it is one of the first documents reviewed. A stale SoA signals a stale management system.

Frequently Asked Questions

How many controls are in the Statement of Applicability?

In ISO 27001:2022, Annex A has 93 controls across four themes. The SoA addresses every one, applied or not, with a justification.

Can we exclude controls?

Yes, if you can justify it based on your risk assessment and scope. Every exclusion needs a documented, defensible reason. Excluding a control you actually need is a fast way to a finding.

Is the SoA the same as the risk assessment?

No, but they are tightly linked. The risk assessment identifies and evaluates risks. The SoA records which controls you chose to treat them and why. The two must be consistent.

If you are building toward ISO 27001, the Statement of Applicability is where the program comes together. A readiness assessment makes sure it reflects real analysis, not a template. Talk with a senior advisor at JBW Group.

← Back to all posts