Annex A Controls
Annex A controls are a catalogue of security measures listed within the ISO 27001 standard that organizations can use to help protect information and demonstrate compliance with the standard. They cover practical safeguards such as physical protections, technical measures like encryption and firewalls, and organizational practices. Organizations typically select and apply these controls based on the risks they have identified rather than adopting every control by default.
Within ISO 27001, Annex A is a reference set of classified information security controls that support the standard's management-system requirements set out in its main clauses. According to the evidence, the ISO 27001:2022 revision enumerates 93 controls spanning categories that include physical, technical, and organizational measures. In practice, Annex A functions as a control catalogue against which an organization documents risk-based selection and applicability decisions (commonly recorded in a statement of applicability), rather than a mandatory checklist requiring implementation of all controls; determination of which controls apply follows from the organization's risk assessment. Note: the specific control count and categorization cited here reflect the sources provided and pertain to the ISO 27001:2022 version; earlier or later versions may differ, and the exact structure should be confirmed against the current published standard.
Why it matters
Annex A controls sit at the operational core of demonstrating conformance with ISO 27001, an information security management system standard. For organizations seeking certification or maintaining an information security program, the way Annex A controls are selected, justified, and documented is often what auditors scrutinize most closely. Because the standard treats Annex A as a reference catalogue rather than a mandatory implementation list, the discipline of risk-based selection—and the record of that reasoning—becomes the evidence that security decisions are deliberate rather than ad hoc.
The practical stakes are that Annex A provides a common vocabulary and structure for security measures, which can reduce ambiguity between internal teams, external auditors, and customers performing vendor due diligence. According to the sources provided, the ISO 27001:2022 revision enumerates 93 controls spanning organizational, technical, and physical categories. Organizations frequently err by treating Annex A as a compliance checklist to be implemented in full; the standard instead expects controls to be applied, or excluded with justification, based on an organization's own risk assessment. Misunderstanding this distinction can lead to wasted effort, gaps that are not properly reasoned through, or a statement of applicability that fails to withstand audit scrutiny.
It is worth noting the scope limits here: Annex A is a set of information security controls, not an AI governance or model risk management framework. Where AI systems process sensitive information, Annex A controls may be relevant to protecting that data, but they do not by themselves address model-specific concerns such as validation, performance degradation, bias, or explainability. The control count and categorization cited reflect the 2022 version described in the sources; earlier or later versions may differ, and the current published standard should be consulted for authoritative structure.
Who it's relevant to
Inside Annex A Controls
Common questions
Answers to the questions practitioners most commonly ask about Annex A Controls.