When companies prepare for ISO 27001 certification, most of the attention goes to policies, assessments on risk, and technical controls. But one document quietly stays at the centre of the whole Information Security Management System (ISMS), which is the Statement of Applicability (SoA).
The SoA is often misunderstood, even though it is important. Some companies treat it like a normal checklist of Annex A controls. Some others copy generic templates without connecting them to the main risks or business operations. Sadly, auditors notice this immediately.
The ISO 27001 Statement of Applicability is one of the important audit documents in the whole certification process. It explains why specific types of controls are included, excluded, or implemented and proves that security decisions are based on risk, not guesswork.
The Statement of Applicability (SoA) is a mandatory ISO 27001 document that identifies which security controls are applied to your company and why.
It is primarily based on:
In simple terms, the SoA answers:
“Which controls are relevant to our organization, and how are we addressing them?”
The SoA acts as a bridge between:
Without it, there is no clear connection between identified risks and selected safeguards.
One of the main misconceptions about the SoA in ISO 27001 is that it is just a list of Annex A controls with “Yes” or “No” responses. This approach creates weak documentation and frequently leads to findings in the audit.
A strong SoA should establish:
For instance, excluding a control simply is not enough. Auditors may expect companies to explain:
The SoA is not just a checkbox exercise. It is evidence that your ISMS is guided by risk management.
Linking SoA to Risk Assessment and Risk Treatment
The SoA cannot exist independently. It must directly connect with the companies:
Here’s how it works:
The company identifies:
Example:
The company decides how to handle the risk:
The selected controls are documented in the SoA, including:
This creates accountability between risks and controls.
A complete ISO 27001 SoA typically includes:
Many companies underestimate how comprehensive and accurate the SoA needs to be.
1. Copying General Templates
Using already filled SoA templates without any customization creates audit issues. Auditors quickly identify when the document does not reflect actual operations.
2. Weak Justifications
Statements like “Controls are not needed” are not acceptable. Exclusions must be risk-based and clearly explained.
3. Missing Alignment with Risk Treatment
Related controls are absent, even though the risks are identified from the SoA; auditors may question the efficiency of the ISMS.
4. Outdated SoA Versions
Companies often update controls but forget to update the SoA.
The document should develop alongside:
5. Treating the SoA as a Compliance Document
The best companies use the SoA operationally, not only during audits.
It supports:
Auditors Focusing Heavily on the SoA
The Statement of Applicability provides auditors with a roadmap to the ISMS.
It helps them to understand:
A weak SoA signals intense issues in:
A strong, well-maintained SoA creates confidence during audits.
The Statement of Applicability is more required than an administrative requirement. It is the document that connects risks, controls, and business decisions into a structured and auditable security framework.
Companies that underestimate the SoA struggle with inconsistent controls, weak audit evidence, and certification delays. Those that treat them as a strategic ISMS document build stronger governance, clearer risk management, and smoother audit experiences.
In ISO 27001, the SoA is not just paperwork; it is proof that security decisions are intentional, justified, and aligned with organizational risk.
A strong Statement of Applicability is essential for demonstrating that ISO 27001 controls are selected, justified, implemented, and maintained based on organizational risks. Azpirantz helps organizations develop a practical and audit-ready SoA by aligning Annex A controls with risk assessment outcomes, risk treatment plans, business requirements, regulatory obligations, and ISMS scope. With expertise in ISO 27001 implementation, control applicability review, SoA documentation, risk-based justifications, internal audits, and certification readiness, Azpirantz ensures that the SoA reflects actual security practices rather than generic checklist responses. By creating a clear connection between risks, controls, and evidence, Azpirantz helps organizations improve audit confidence, reduce compliance gaps, strengthen governance, and build a more mature information security management system.
*This content has been created and published by the Azpirantz Marketing Team and should not be considered as professional advice. For expert consulting and professional advice, please reach out to [email protected].