Statement of Applicability Documentation
A Statement of Applicability is a document used in information security management that lists the security controls an organization has considered and explains which ones apply to it and which do not, along with the reasoning for each decision. It is a central document in the ISO 27001 standard for information security management systems, where it is commonly described as a required part of certification. In practice, it serves as a record showing which controls the organization has chosen to implement and why others were left out.
Within the ISO/IEC 27001 Information Security Management System (ISMS) framework, the Statement of Applicability (SoA) is a document that enumerates the assessable information security controls (commonly the controls listed in Annex A) and records, for each, whether it is included or excluded, together with the justification for that determination. According to the evidence, one source characterizes it as a mandatory document covering the full set of Annex A controls; because control counts and Annex structure differ across editions (for example, the 2022 revision), practitioners should confirm the applicable version rather than assume a fixed number. The SoA is frequently identified as one of the core documents required for ISO 27001 certification, functioning as the auditable link between an organization's risk assessment and its implemented control set. Note: this evidence packet addresses the SoA specifically as an ISO 27001 ISMS artifact and does not establish its use, definition, or requirement status under other frameworks (such as AI-specific standards or model risk management guidance).
Why it matters
The Statement of Applicability sits at the heart of an ISO/IEC 27001 Information Security Management System because it is the auditable record that connects an organization's risk assessment to the specific controls it has chosen to implement or exclude. Without it, an auditor cannot readily verify that control decisions were made deliberately and with justification rather than left to chance. For this reason, several sources describe the SoA as one of the core documents required for ISO 27001 certification, and one source characterizes it as a mandatory document covering the full set of Annex A controls.
The document matters most as evidence of reasoned decision-making. Because it requires the organization to state, for each assessable control, whether the control applies and why, the SoA forces explicit accountability for both inclusions and exclusions. This makes it a focal point during certification and surveillance audits, where the justifications recorded in the SoA can be tested against the underlying risk assessment and the controls actually operating in the environment.
A common pitfall is treating the SoA as a static checklist rather than a living document tied to risk. Control counts and Annex structure differ across editions of the standard—for example, one source references 93 Annex A controls—so practitioners should confirm the applicable version and control set rather than assume a fixed number. This evidence addresses the SoA specifically as an ISO 27001 ISMS artifact; it does not establish the document's meaning or requirement status under other frameworks, such as AI-specific standards or model risk management guidance.
Who it's relevant to
Inside SoA
Common questions
Answers to the questions practitioners most commonly ask about SoA.