Compliance guide

Build the Statement of Applicability

Set Annex A applicability and implementation status, record justification and link Policies, Risks and evidence to the organisation's compliance position.

Compliance Manager, Control Owner or ISMS Manager Ongoing programme activity Updated 9 September 2026

Purpose of the Statement of Applicability

The Statement of Applicability records which ISO 27001 Annex A Controls apply to the ISMS, why they apply or do not apply, their implementation status and the supporting governance context.

The SoA is a compliance decision record. It explains the organisation's position against the standard. Operational Control lifecycle and assurance are managed in Control Management.

1. Set Control applicability and status

Open the Statement of Applicability and review each Annex A Control. Mark it Applicable or Not Applicable, record the justification and maintain the implementation status such as Not Started, Planned, In Progress or Implemented.

The SoA records applicability, justification and implementation progress for the selected standard Control.
Justification is required for Not Applicable. Explain why the Control is outside the ISMS scope or why the organisation has determined it is not necessary. Avoid generic wording.

3. Review the complete SoA

Review applicable and not-applicable totals, implementation status, owners, target dates, missing justification and supporting links. Use the SoA change history or review process to preserve material changes to the compliance position.

4. Use Control Management for operational assurance

When the question is whether a Control is adopted, where it applies operationally, whether it is implemented on an Asset, or whether assessments/tests support effectiveness, open Control Management. Do not use the SoA row as a replacement for those assurance records.

Evidence quality

RelevantDirectly supports the Control and period under review.
TraceableHas a source, owner, date and enough context for a reviewer.
CurrentReflects the present operating state rather than an obsolete process.
ProportionateProvides sufficient assurance without collecting unnecessary sensitive data.

Common problems

A Control marked Not Applicable cannot be saved

Provide a meaningful justification and complete any other required SoA fields before saving.

A Policy is not available to link

Confirm that the document is in an eligible governed state and that your role can access it.

The SoA says Implemented but operational assurance is incomplete

Review the organisation Control in Control Management. SoA status and Control assurance are related but separate records and should be reconciled rather than assumed to be identical.