ISO 27001 Statement of Applicability: What It Should Do
The SoA should explain applicability decisions—not merely reproduce a control catalogue.
The purpose of the SoA
The Statement of Applicability records the organization's decisions about applicable controls and the status of implementation. It gives auditors and management a concise view of what has been selected, why it applies, and how the organization addresses it.
Start with the risk and context
Applicability should make sense in the context of the ISMS scope, information-security risks, legal and contractual requirements, and other organizational needs. A control should not be marked applicable simply because it appears in a checklist.
Document exclusions carefully
When a control is not applicable, the rationale should be clear enough for another reviewer to understand the decision. “Not relevant” is usually a weak explanation unless the organization can show why the control has no meaningful relationship to its scope or risk context.
Keep implementation status honest
An applicable control being listed in the SoA does not by itself prove that it operates effectively. Maintain a useful distinction between selection, implementation, ownership and operating evidence.
Use the SoA as a management tool
- Link controls to accountable owners.
- Reference supporting policies or processes where useful.
- Track implementation gaps rather than hiding them.
- Keep applicability decisions synchronized with significant scope or risk changes.
Building your ISO 27001 ISMS?
See how BlueLock connects scope, risk, controls and evidence through implementation.