Compliance Management guide

Build the Statement of Applicability

Set Annex A control applicability, record justification and link policies, risk assessments and evidence to demonstrate implementation.

Compliance Manager, Control Owner or ISMS Manager Ongoing programme activity Updated 27 July 2026

Purpose of the Statement of Applicability

The Statement of Applicability records which ISO 27001 Annex A controls apply, why they apply or do not apply, their implementation status and the evidence that supports the organisation's position.

1. Set control applicability and status

Open the Statement of Applicability and review each Annex A control. Mark the control Applicable or Not Applicable, then set the implementation status such as Not Started or In Progress.

The control editor records applicability, implementation progress and linked evidence for an Annex A control.
Justification is mandatory for Not Applicable. Explain why the control is outside the ISMS scope or why the associated risk does not require it. Avoid generic wording.

3. Review the complete SoA

Check totals for applicable, not applicable, in-progress and not-started controls. Review controls with no evidence or incomplete justification and assign the work to an accountable owner.

Evidence quality

RelevantDirectly supports the control and period under review.
TraceableHas a source, owner, date and enough context for a reviewer.
CurrentReflects the present operating state rather than an obsolete process.
ProportionateProvides sufficient assurance without collecting unnecessary sensitive data.

Common problems

A control marked Not Applicable cannot be saved

Provide a meaningful justification before saving.

A policy is not available to link

Confirm that the policy has completed the required approval or publication state and that you can access it.