Information and Cyber Security

Statement of Applicability: The ISO 27001 Document Everyone Underestimates

Author: Tejaswi
Aug 21, 2026
28

When companies prepare for ISO 27001 certification, most of the attention goes to policies, assessments on risk, and technical controls. But one document quietly stays at the centre of the whole Information Security Management System (ISMS), which is the Statement of Applicability (SoA).

The SoA is often misunderstood, even though it is important. Some companies treat it like a normal checklist of Annex A controls. Some others copy generic templates without connecting them to the main risks or business operations. Sadly, auditors notice this immediately.

The ISO 27001 Statement of Applicability is one of the important audit documents in the whole certification process. It explains why specific types of controls are included, excluded, or implemented and proves that security decisions are based on risk, not guesswork.

Statement of Applicability in ISO 27001

The Statement of Applicability (SoA) is a mandatory ISO 27001 document that identifies which security controls are applied to your company and why.

It is primarily based on:

  • Risk assessment results
  • Risk treatment decisions
  • Annex A control requirements
  • Business and regulatory obligations

In simple terms, the SoA answers:

“Which controls are relevant to our organization, and how are we addressing them?”

The SoA acts as a bridge between:

  • Risk assessment
  • Risk treatment plan
  • Actual control implementation

Without it, there is no clear connection between identified risks and selected safeguards.

SoA Is Not Just a Checklist

One of the main misconceptions about the SoA in ISO 27001 is that it is just a list of Annex A controls with “Yes” or “No” responses. This approach creates weak documentation and frequently leads to findings in the audit.

A strong SoA should establish:

  • Thoughtful Control selection
  • Making a decision based on risk
  • Business operations need to be aligned
  • Exclusions are Justified
  • Real implementation status

For instance, excluding a control simply is not enough. Auditors may expect companies to explain:

  • Why are the controls excluded
  • What type of risks were considered
  • Whether alternative safeguards exist

The SoA is not just a checkbox exercise. It is evidence that your ISMS is guided by risk management.

Linking SoA to Risk Assessment and Risk Treatment

The SoA cannot exist independently. It must directly connect with the companies:

  • ISO 27001 risk assessment
  • ISO 27001 risk treatment plan

Here’s how it works:

Step 1: Risk Assessment

The company identifies:

  • Assets
  • Threats
  • Vulnerabilities
  • Impacts of Business
  • Levels of Risk

Example:

  • Risk: Unauthorized access to customer databases
Step 2: Risk Treatment

The company decides how to handle the risk:

  • Mitigate
  • Transfer
  • Accept
  • Avoid
Step 3: Statement of Applicability

The selected controls are documented in the SoA, including:

  • Applicability status
  • Justification
  • Implementation details

This creates accountability between risks and controls.

What needs to be included in the SoA?

A complete ISO 27001 SoA typically includes:

  • Annex A Control Reference
  • Control Description
  • Applicability Status
  • Justification for Inclusion or Exclusion
  • Implementation Status
  • Related Policies or Procedures
Common Statement of Applicability Mistakes

Many companies underestimate how comprehensive and accurate the SoA needs to be.

1. Copying General Templates

Using already filled SoA templates without any customization creates audit issues. Auditors quickly identify when the document does not reflect actual operations.

2. Weak Justifications

Statements like “Controls are not needed” are not acceptable. Exclusions must be risk-based and clearly explained.

3. Missing Alignment with Risk Treatment

Related controls are absent, even though the risks are identified from the SoA; auditors may question the efficiency of the ISMS.

4. Outdated SoA Versions

Companies often update controls but forget to update the SoA.

The document should develop alongside:

  • Latest technologies
  • Change in Process
  • Assessments based on Risk
  • Findings during Audit

5. Treating the SoA as a Compliance Document

The best companies use the SoA operationally, not only during audits.

It supports:

  • Security governance
  • Risk tracking
  • Auditing Internally
  • Improving Continuously

Auditors Focusing Heavily on the SoA

The Statement of Applicability provides auditors with a roadmap to the ISMS.

It helps them to understand:

  • Which controls are implemented
  • Why were controls selected
  • How risks are managed
  • Where evidence should exist

A weak SoA signals intense issues in:

  • Risk management
  • Scope definition
  • ISMS maturity

A strong, well-maintained SoA creates confidence during audits.

Conclusion

The Statement of Applicability is more required than an administrative requirement. It is the document that connects risks, controls, and business decisions into a structured and auditable security framework.

Companies that underestimate the SoA struggle with inconsistent controls, weak audit evidence, and certification delays. Those that treat them as a strategic ISMS document build stronger governance, clearer risk management, and smoother audit experiences.

In ISO 27001, the SoA is not just paperwork; it is proof that security decisions are intentional, justified, and aligned with organizational risk.

Why Azpirantz for ISO 27001 Consulting?

A strong Statement of Applicability is essential for demonstrating that ISO 27001 controls are selected, justified, implemented, and maintained based on organizational risks. Azpirantz helps organizations develop a practical and audit-ready SoA by aligning Annex A controls with risk assessment outcomes, risk treatment plans, business requirements, regulatory obligations, and ISMS scope. With expertise in ISO 27001 implementation, control applicability review, SoA documentation, risk-based justifications, internal audits, and certification readiness, Azpirantz ensures that the SoA reflects actual security practices rather than generic checklist responses. By creating a clear connection between risks, controls, and evidence, Azpirantz helps organizations improve audit confidence, reduce compliance gaps, strengthen governance, and build a more mature information security management system.

*This content has been created and published by the Azpirantz Marketing Team and should not be considered as professional advice. For expert consulting and professional advice, please reach out to [email protected].

Ready To Get Started?
We're Here To Help