Skip to main content
Category: Management System Governance

Annex A Controls

Also known as: ISO 27001 Annex A controls, ISO/IEC 27001 Annex A
Simply put

Annex A controls are a catalogue of security measures listed within the ISO 27001 standard that organizations can use to help protect information and demonstrate compliance with the standard. They cover practical safeguards such as physical protections, technical measures like encryption and firewalls, and organizational practices. Organizations typically select and apply these controls based on the risks they have identified rather than adopting every control by default.

Formal definition

Within ISO 27001, Annex A is a reference set of classified information security controls that support the standard's management-system requirements set out in its main clauses. According to the evidence, the ISO 27001:2022 revision enumerates 93 controls spanning categories that include physical, technical, and organizational measures. In practice, Annex A functions as a control catalogue against which an organization documents risk-based selection and applicability decisions (commonly recorded in a statement of applicability), rather than a mandatory checklist requiring implementation of all controls; determination of which controls apply follows from the organization's risk assessment. Note: the specific control count and categorization cited here reflect the sources provided and pertain to the ISO 27001:2022 version; earlier or later versions may differ, and the exact structure should be confirmed against the current published standard.

Why it matters

Annex A controls sit at the operational core of demonstrating conformance with ISO 27001, an information security management system standard. For organizations seeking certification or maintaining an information security program, the way Annex A controls are selected, justified, and documented is often what auditors scrutinize most closely. Because the standard treats Annex A as a reference catalogue rather than a mandatory implementation list, the discipline of risk-based selection—and the record of that reasoning—becomes the evidence that security decisions are deliberate rather than ad hoc.

The practical stakes are that Annex A provides a common vocabulary and structure for security measures, which can reduce ambiguity between internal teams, external auditors, and customers performing vendor due diligence. According to the sources provided, the ISO 27001:2022 revision enumerates 93 controls spanning organizational, technical, and physical categories. Organizations frequently err by treating Annex A as a compliance checklist to be implemented in full; the standard instead expects controls to be applied, or excluded with justification, based on an organization's own risk assessment. Misunderstanding this distinction can lead to wasted effort, gaps that are not properly reasoned through, or a statement of applicability that fails to withstand audit scrutiny.

It is worth noting the scope limits here: Annex A is a set of information security controls, not an AI governance or model risk management framework. Where AI systems process sensitive information, Annex A controls may be relevant to protecting that data, but they do not by themselves address model-specific concerns such as validation, performance degradation, bias, or explainability. The control count and categorization cited reflect the 2022 version described in the sources; earlier or later versions may differ, and the current published standard should be consulted for authoritative structure.

Who it's relevant to

Information security and compliance officers
Those responsible for pursuing or maintaining ISO 27001 certification use Annex A as the framework for selecting and documenting security controls. Their central task is often preparing a defensible statement of applicability that ties each applicable control—and each exclusion—back to a risk assessment, rather than implementing every control by default.
Auditors and assessors
Internal and external auditors evaluate whether an organization's control selection is justified and whether implemented controls operate as intended. As the sources note, Annex A controls are critical to the ISO 27001 audit process, and the reasoning behind applicability decisions is a common focus of examination.
IT and security operations teams
Teams that deploy and maintain the underlying safeguards—physical protections, firewalls, encryption, and organizational practices—translate control selections into operational reality. They are often the practitioners who must demonstrate that a chosen control is actually functioning, not merely documented.
Vendor risk and procurement professionals
Those performing third-party due diligence frequently rely on ISO 27001 conformance, and by extension Annex A control coverage, as one signal of a vendor's information security posture. They should understand that certification reflects a risk-based selection of controls rather than uniform implementation across all vendors.
AI governance and data protection specialists
Where AI systems process sensitive or regulated information, Annex A controls can be relevant to protecting that data. However, these specialists should recognize that Annex A addresses information security, not model-specific risks such as validation, bias, or performance degradation, and should not treat it as a substitute for AI-focused governance instruments.

Inside Annex A Controls

Reference control set
In the context of management system standards such as ISO/IEC 42001 (an AI management system standard published by ISO and IEC), an annex commonly provides a catalogue of reference controls that organizations may consider. As commonly structured, these are illustrative or selectable controls rather than a mandatory checklist, and organizations typically justify inclusions and exclusions.
Control objectives and controls
Such annexes typically pair control objectives (the outcome a control is intended to achieve) with individual controls (the measures used to achieve that outcome). The distinction matters because objectives describe intent while controls describe implementable measures.
Applicability determination
A recurring element is the process by which an organization decides which annex controls apply to its context, often documented in a statement-of-applicability-style artifact. This ties selected controls to identified risks and to the organization's scope.
Governance versus risk-treatment linkage
Annex-style controls commonly span both AI governance elements (roles, accountability, policies, oversight) and risk-treatment measures (identification, monitoring, and control of risks from AI systems). These are related but distinct: governance establishes the structures and accountability, while risk treatment addresses specific risks, and a single annex may include controls of both kinds.
Traceability to risk assessment
Controls are typically intended to be selected and implemented on the basis of a prior risk assessment, so that residual risk (risk remaining after controls) is understood relative to inherent risk (risk before controls).

Common questions

Answers to the questions practitioners most commonly ask about Annex A Controls.

Are the Annex A controls in ISO/IEC 27001 mandatory requirements that every organization must implement?
No. Annex A is commonly treated as a reference set of controls rather than a mandatory checklist. In the ISO/IEC 27001 model, the controls an organization implements are typically driven by its risk assessment and risk treatment decisions, and an organization documents which controls apply and which are excluded (with justification) in a Statement of Applicability. So Annex A functions as a catalogue to consider, not a set of clauses that all must be adopted verbatim. Note that the precise structure and count of Annex A controls has changed across editions of the standard, so verify against the specific edition you are working with.
Does implementing the Annex A controls by itself mean an organization is certified or compliant with ISO/IEC 27001?
Not on its own. Annex A addresses the control side, but ISO/IEC 27001 certification typically also depends on the management system requirements found in the main clauses of the standard (such as context, leadership, planning, risk assessment, operation, performance evaluation, and improvement). Selecting and operating controls is one input; the broader information security management system and its processes are also assessed. Treating control implementation as equivalent to full conformity is a frequent error.
How should an organization decide which Annex A controls apply to it?
In many implementations the selection flows from a documented risk assessment and risk treatment process: identify risks to information assets, decide how to treat each risk, and then map applicable controls to those treatment decisions. Controls that are not relevant to identified risks can be excluded, provided the exclusion is justified. This rationale is typically captured in the Statement of Applicability. The goal is a defensible link between assessed risk and the controls chosen, rather than adopting the full catalogue by default.
What role does the Statement of Applicability play in relation to Annex A?
The Statement of Applicability is commonly used to record, for each Annex A control, whether it applies, the justification for inclusion or exclusion, and its implementation status. It serves as a traceable bridge between the risk treatment decisions and the controls in operation. Auditors often use it as a reference point to check that control decisions are consistent with the organization's assessed risks and that exclusions are reasoned rather than arbitrary.
How do organizations demonstrate that an Annex A control is actually operating, not just documented?
Documentation alone is generally not treated as sufficient. Organizations typically gather evidence that a control is designed appropriately and functioning over time, such as records, logs, configuration evidence, or process outputs that show the control in use. Distinguishing whether a control exists on paper from whether it operates effectively is important, and this distinction often mirrors the broader difference between having a policy and being able to show it works in practice.
How are Annex A controls kept current as risks and the environment change?
Because control selection is tied to assessed risk, changes in the threat environment, technology, or business context can change which controls are relevant or how they should operate. In many management system approaches, controls are reviewed periodically and after significant changes, with the risk assessment and Statement of Applicability updated accordingly. This ongoing review supports the idea that controls manage and reduce risk over time rather than eliminate it permanently.

Common misconceptions

Implementing every Annex A control is required for conformity.
In many management system standards, annex controls function as a reference set to be selected based on risk and applicability, not as a mandatory list. Organizations typically justify which controls they include or exclude rather than adopting all of them. The exact treatment depends on the specific standard, so confirm against the applicable text.
Annex A controls apply universally across all AI regulatory regimes.
Annex controls within a voluntary standard (such as an ISO/IEC management system standard) are not interchangeable with binding law such as the EU AI Act, with guidance such as SR 11-7 / OCC 2011-12 in U.S. banking model risk management, or with a voluntary framework such as the NIST AI Risk Management Framework. Each is issued by a different body, has a different jurisdiction and legal status, and should be scoped accordingly.
Applying the controls eliminates AI risk.
Controls are measures that reduce or manage risk; they do not eliminate it. After implementing controls, residual risk typically remains and should be assessed, monitored, and accepted or further treated as appropriate.

Best practices

Base control selection on a documented risk assessment, mapping each selected control to the specific AI risks it is intended to address and recording justifications for any exclusions.
Maintain a clear applicability artifact that links selected controls to your defined scope, so that inclusions and exclusions are traceable and defensible.
Distinguish governance-oriented controls (accountability, policy, oversight) from risk-treatment controls (monitoring, measurement, mitigation) when implementing, so responsibilities are assigned appropriately without collapsing the two.
Assess and document residual risk after control implementation, rather than assuming controls remove the underlying risk.
Confirm the legal status and jurisdiction of the standard whose annex you are applying, and do not treat its controls as equivalent to obligations under separate binding regulations or other frameworks.
Review selected controls periodically and after material changes to AI systems or risk profile, since control adequacy can drift as models, data, and context evolve.