top of page

ISO 27001 Statement of Applicability review

The Statement of Applicability is one of the most important documents in an ISO 27001 information security management system

It explains which Annex A controls apply to your organisation, which controls do not apply, why those decisions have been made, and how the selected controls are implemented. It should also link back to your information security risk assessment and risk treatment decisions.

In many organisations, however, the Statement of Applicability is created during implementation and then left largely unchanged. This can create problems when the business changes, new systems are introduced, suppliers change, customer requirements increase, or information security risks move on.

ID Risk and Compliance provides ISO 27001 Statement of Applicability reviews to help organisations check whether their SoA is accurate, current, properly justified and supported by evidence.

Why the Statement of Applicability matters

The Statement of Applicability is not just a certification document. It is a key link between your risk assessment, your selected controls and the way information security is managed in practice.

A good Statement of Applicability should help the organisation understand which controls are relevant, why they are relevant, how they are applied, and where evidence can be found.

It should also help auditors, customers and senior management understand the logic behind your control decisions.

If the SoA is weak, outdated or poorly justified, it can undermine confidence in the wider ISMS. For example, a control may be marked as implemented when there is little evidence to support it. A control may be excluded even though the organisation now has a clear reason to apply it. Or the implementation description may no longer match how the business actually works.

A review helps identify these issues before they become audit findings.

Common problems with ISO 27001 Statements of Applicability

A common issue is that the SoA simply repeats the wording of Annex A rather than explaining how the control applies to the organisation. This makes it difficult to show that the control has been properly considered.

Another issue is weak justification for exclusions. Some controls may be marked as not applicable, but without a clear explanation. In ISO 27001, exclusions should be justified. The organisation should be able to explain why a control does not apply, based on its risks, activities, services, technology, legal obligations and interested party requirements.

There can also be gaps between the SoA and the risk assessment. If a risk has been identified and treated using a particular control, the SoA should reflect that decision. If the risk assessment has changed but the SoA has not, the system may no longer be aligned.

Other common problems include outdated implementation notes, missing evidence, unclear control ownership, duplicated controls, controls marked as implemented too early, and failure to reflect new suppliers, systems, cloud services, remote working practices or customer security requirements.

What an SoA review covers

An ISO 27001 Statement of Applicability review looks at whether the document is complete, accurate and suitable for the organisation.

This may include reviewing the applicability of Annex A controls, checking exclusion justifications, reviewing implementation descriptions, comparing the SoA against the risk assessment, checking links to the risk treatment plan, reviewing control ownership, testing selected evidence, and identifying areas where the document does not reflect current practice.

The review can also consider whether the SoA is clear enough for internal users, external auditors and customers. A Statement of Applicability should not be so vague that it becomes difficult to audit. It should provide enough detail to demonstrate that control decisions are deliberate, justified and understood.

The aim is not to make the SoA unnecessarily complicated. The aim is to make it accurate, defensible and useful.

Reviewing Annex A control applicability

ISO 27001:2022 includes Annex A controls covering organisational, people, physical and technological areas of information security.

The SoA should show which of these controls are applicable to your organisation. This decision should not be based on guesswork or copied from a generic template. It should be based on the organisation’s information security risks, business activities, customer requirements, legal obligations, technology environment and operational context.

For example, controls relating to supplier relationships may be highly relevant if your organisation uses outsourced IT, cloud platforms, software providers or external consultants. Controls relating to secure development may be relevant if your organisation develops software or manages code. Physical security controls may apply differently depending on whether you operate offices, shared workspaces, remote working arrangements or secure facilities.

An SoA review helps check that these decisions still make sense.

Checking implementation evidence

The SoA should not simply say that a control is implemented. The organisation should be able to demonstrate how it is implemented.

Evidence may include policies, procedures, access reviews, supplier assessments, contracts, risk assessments, training records, incident logs, asset registers, configuration records, monitoring outputs, backup evidence, business continuity tests, vulnerability scans, meeting minutes, audit reports and corrective action records.

An SoA review can test whether selected controls have evidence to support them. This is particularly useful before certification, surveillance or recertification audits.

Where evidence is weak or missing, the review can identify practical actions to strengthen the ISMS.

Keeping the SoA aligned with business change

Your Statement of Applicability should be reviewed when significant changes occur.

This might include introducing new software, moving services to the cloud, changing IT providers, adopting remote working, onboarding a major customer, changing how personal data is processed, introducing new locations, outsourcing key services, developing new products, or responding to a security incident.

If the SoA is not updated when the business changes, it may quickly become inaccurate.

For example, a business that did not previously develop software may later introduce internal development work. A business that did not rely heavily on cloud platforms may later move core systems into cloud services. A business that previously worked from one office may later adopt hybrid or remote working. Each of these changes could affect control applicability and implementation.

A periodic SoA review helps keep the document current.

Supporting ISO 27001 audit readiness

Certification bodies often spend time reviewing the Statement of Applicability because it is central to the structure of the ISMS.

They may ask why controls have been included, why controls have been excluded, how the SoA links to the risk assessment, how implementation is evidenced, and whether the document has been reviewed following changes.

If the SoA is unclear, inconsistent or unsupported, this can lead to audit findings.

An independent review before an external audit can help identify weaknesses early. It can also help staff understand the reasoning behind control decisions so they can explain the system more confidently during the audit.

This can be particularly helpful where the original ISO 27001 implementation was completed by someone who has since left the organisation, or where the SoA was created from a template and has not been fully tailored.

Who this service is for

An ISO 27001 Statement of Applicability review is suitable for organisations preparing for certification, organisations already certified to ISO 27001, and businesses that need to check whether their ISMS still reflects current practice.

It is particularly useful if your SoA has not been reviewed for some time, if the business has changed since certification, if your external audit is approaching, if exclusions are not clearly justified, if implementation notes are vague, or if you are unsure whether your Annex A controls are properly evidenced.

It may also be useful if customers are asking more detailed security questions, if you are preparing for supplier assurance reviews, or if you want greater confidence in the structure of your ISMS.

How ID Risk and Compliance can help

ID Risk and Compliance can provide an independent review of your ISO 27001 Statement of Applicability.

We can assess whether the SoA is complete, whether control applicability is justified, whether exclusions are defensible, whether implementation descriptions reflect current practice, and whether evidence exists to support selected controls.

We can also identify practical improvements, help align the SoA with your risk assessment, and support preparation for certification, surveillance, recertification or customer audits.

Our approach is practical and proportionate. We focus on making the Statement of Applicability useful, accurate and audit-ready, rather than creating unnecessary complexity.

Need your ISO 27001 Statement of Applicability reviewed?

ID Risk and Compliance can help you check control applicability, strengthen justifications, review evidence and improve audit readiness.

Contact us to discuss an independent SoA review for your organisation.

bottom of page