What are the Annex A controls for in ISO 27001?
Annex A controls in ISO 27001 help organisations choose practical security measures that reduce information security risk. They give businesses a structured set of controls to consider when building an Information Security Management System, often called an ISMS.
For many organisations, ISO 27001 can feel complex at first. There are risks to assess, policies to prepare, controls to select, evidence to gather, audits to complete, and improvement actions to manage. Annex A helps bring structure to that work. It gives businesses a clear control set that supports risk treatment, audit readiness, customer assurance, and stronger information security management.
UK Cyber Compliance provides ISO 27001 certification support through an automated and AI-driven platform. UK Cyber Compliance (a part of UK Cyber Security Group) provides these services and has a platform to make certification much easier and cheaper. The platform helps organisations manage risk, controls, tasks, evidence, policies, audit readiness, and continual improvement in one place.
Annex A is not a random checklist. It should not be copied without thought. ISO 27001 expects organisations to understand their risks, decide which controls apply, justify those decisions, and show evidence that selected controls work in practice. That makes Annex A one of the most important areas of ISO 27001 preparation.
Why Annex A controls matter
Annex A controls matter because they help organisations move from risk assessment to action. A business may identify risks such as unauthorised access, data loss, supplier failure, phishing, ransomware, cloud misconfiguration, staff error, or service disruption. Annex A helps the organisation decide which security controls can reduce those risks.
ISO 27001:2022 includes 93 Annex A controls. These controls sit across four broad areas: organisational, people, physical, and technological. Together, they cover governance, policies, roles, suppliers, incidents, assets, access, staff responsibilities, premises, devices, systems, networks, monitoring, backup, secure development, cloud services, and many other information security concerns.
This matters because information security is not only an IT issue. It involves leadership, people, suppliers, contracts, data, physical spaces, business continuity, risk decisions, and customer trust. Annex A helps businesses build a balanced approach rather than relying on one narrow set of technical measures.
A good ISO 27001 project uses Annex A to support real risk management. It asks which controls are needed, why they are needed, who owns them, whether they are working, and what evidence proves they are working.
What is ISO 27001 Certification?
ISO 27001 certification is formal recognition that an organisation has implemented an ISMS that meets the requirements of the ISO 27001 standard. An independent audit checks whether the organisation has established, implemented, maintained, reviewed, and improved its ISMS.
The ISMS provides a structured way to manage information security. It includes scope, leadership, risk assessment, risk treatment, policies, legal and regulatory requirements, interested parties, objectives, resources, staff awareness, supplier management, internal audit, management review, corrective action, and continual improvement.
Annex A controls support certification because they help the organisation select suitable measures to treat risk. The business does not have to apply every control automatically, but it must consider the controls and justify its decisions.
Certification does not mean the business has removed every possible security risk. No standard can promise that. It shows that the organisation has a structured, risk-based, and independently assessed approach to protecting information.
For customers, suppliers, partners, and senior leaders, this provides reassurance. It shows that security decisions are not based on guesswork. The organisation has reviewed risks, selected controls, recorded decisions, and prepared evidence.
what is iso 27001
ISO 27001 is an international standard for information security management. It sets out the requirements for building, operating, reviewing, and improving an ISMS.
The standard focuses on protecting confidentiality, integrity, and availability. Confidentiality means information only reaches authorised people. Integrity means information stays accurate and trustworthy. Availability means information and systems remain accessible when needed.
ISO 27001 uses a risk-based approach. The organisation identifies what could harm information security, assesses how serious those risks are, and chooses controls to reduce them to an acceptable level.
Annex A supports that approach by providing a recognised control catalogue. These controls help organisations protect information across business operations, staff activity, physical environments, and technology.
A small consultancy, software company, managed service provider, cyber security firm, accountancy practice, healthcare supplier, or public sector contractor can all use ISO 27001. Each organisation should apply it in a way that matches its own risks, scope, customers, systems, suppliers, and legal obligations.
Annex A in simple business language
Annex A is the control reference section of ISO 27001. It helps the business decide what security measures may be needed.
Think of Annex A as a structured control library. It does not replace risk assessment. It supports risk assessment by giving the business a clear set of controls to consider.
For example, if a company identifies a risk around staff using weak access controls, Annex A points toward controls for identity management, authentication, access rights, privileged access, and user responsibilities.
If the business identifies supplier risk, Annex A points toward controls for supplier relationships, cloud services, contractual security, and monitoring of supplier services.
If the business identifies physical office risk, Annex A points toward controls for secure areas, physical entry, equipment protection, clear desk arrangements, and secure disposal.
The value comes from linking risks to controls. That link helps auditors, customers, and leaders see why the organisation has chosen particular measures.
The four areas of Annex A
ISO 27001:2022 arranges Annex A controls across four areas: organisational, people, physical, and technological.
Organisational controls focus on governance and management. They include policies, roles, responsibilities, threat intelligence, project security, asset management, information classification, supplier security, incident management, legal duties, privacy, independent review, and documented procedures.
People controls focus on staff and others who work with the organisation. They include screening, employment terms, awareness, disciplinary process, responsibilities after employment changes, confidentiality agreements, remote working, and reporting information security events.
Physical controls focus on protecting places, equipment, records, and working environments. They include physical security perimeters, entry controls, offices, secure areas, equipment placement, assets off premises, storage media, supporting utilities, cabling, maintenance, and secure disposal.
Technological controls focus on systems and digital protection. They include endpoint devices, privileged access, access restrictions, secure authentication, capacity management, malware protection, vulnerability management, configuration management, logging, monitoring, network security, cryptography, secure development, change management, and audit testing.
These areas help organisations avoid a one-sided approach. A business that only focuses on software may miss staff, supplier, or physical risks. A business that only focuses on policies may miss technical weaknesses. Annex A helps create balance.
Who needs iso 27001 certification
ISO 27001 certification is useful for organisations that need to protect information and prove that security is managed properly. It is especially relevant for businesses that handle client data, personal data, confidential records, financial information, intellectual property, supplier data, regulated information, cloud services, or sensitive operational information.
Technology providers, managed service providers, SaaS businesses, cyber security firms, consultants, legal firms, accountants, finance-related organisations, healthcare suppliers, recruitment agencies, public sector suppliers, and professional services firms often benefit from certification.
Many organisations pursue ISO 27001 because a customer asks for it during supplier due diligence. Others need it for tenders, contract requirements, board assurance, investor confidence, insurance conversations, or stronger internal governance.
Annex A controls are important for all of these organisations because they turn certification from a paperwork exercise into a practical security system. They help the business show how information security risks are managed in daily operations.
For smaller organisations, Annex A also helps focus effort. Instead of trying to do everything at once, the business can use risk assessment to decide which controls matter most and which controls need stronger evidence.
Annex A and risk treatment
Risk treatment is the process of deciding what to do about each information security risk. Annex A controls often provide the treatment measures.
A business may reduce a risk by applying controls. It may avoid a risk by stopping a risky activity. It may transfer part of a risk through contracts or insurance. It may accept a risk when the level falls within agreed risk acceptance criteria.
Annex A mainly supports the risk reduction part. It gives the organisation control options that can lower likelihood or impact.
For example, a risk involving unauthorised access to customer data may lead to controls around access rights, authentication, logging, monitoring, and information classification. A risk involving ransomware may lead to controls around malware protection, backup, vulnerability management, incident management, awareness, and recovery planning.
The chosen controls should match the risk. A control should not appear in the ISMS simply because it sounds impressive. It should have a clear purpose.
Annex A and the Statement of Applicability
The Statement of Applicability, often called the SoA, is one of the most important ISO 27001 documents. It records which Annex A controls apply, why they apply, whether they have been implemented, and why any controls have been excluded.
The SoA gives auditors a clear view of control decisions. It shows that the organisation has considered Annex A properly and can justify its choices.
If a control applies, the organisation should explain why. The reason may link to risk treatment, legal duties, customer expectations, contracts, business needs, supplier obligations, or operational resilience.
If a control does not apply, the organisation should explain why not. The reason must be credible. A business should not exclude a control simply because it feels inconvenient.
The SoA should stay current. When the business changes, the SoA may need review. New services, new suppliers, new cloud platforms, new risks, or new customer requirements can all affect control decisions.
UK Cyber Compliance can help by keeping risks, controls, owners, evidence, and SoA activity organised in one platform.
Annex A and audit evidence
Auditors do not only want to see that controls have been selected. They want to see evidence that selected controls work.
Evidence may include policies, risk assessments, access reviews, supplier assessments, incident records, training records, asset registers, internal audit records, management review notes, backup records, vulnerability reports, logging records, monitoring outputs, change records, and corrective action logs.
The evidence should match the control. If the SoA says access control is implemented, the business should show access records, approval processes, reviews, and account management evidence.
If the SoA says supplier security is implemented, the business should show supplier reviews, contracts, due diligence, service monitoring, or security questionnaires.
If the SoA says staff awareness is implemented, the business should show training records, communications, attendance records, or awareness materials.
A strong evidence trail makes the audit process smoother. It also helps the business manage information security beyond certification.
ISO 27001 Certification Levels
People often search for ISO 27001 Certification Levels, but the phrase needs careful explanation. ISO 27001 is not usually awarded in separate bands such as basic, advanced, bronze, silver, or gold. An organisation is either certified to ISO 27001 or it is not.
However, businesses do move through practical stages. A typical route includes readiness review, ISMS scope definition, interested party review, legal and regulatory review, risk assessment, risk treatment, Annex A control selection, Statement of Applicability preparation, evidence gathering, internal audit, management review, corrective action, and external certification audit.
External certification normally involves two audit stages. Stage one checks readiness, scope, documented information, and whether the ISMS appears prepared for deeper assessment. Stage two checks whether the ISMS operates effectively in practice.
Annex A controls play a key role throughout this route. They support risk treatment, evidence gathering, audit preparation, and ongoing review. After certification, the organisation must keep controls active and improve the ISMS over time.
How Annex A supports customer trust
Customers often ask how a supplier protects information. They may want assurance around access control, data handling, supplier management, incident response, encryption, backup, cloud security, staff training, and business continuity.
Annex A helps the business answer those questions in a structured way. It shows that the organisation has reviewed recognised information security controls and selected measures based on risk.
This can reduce friction during supplier onboarding. A certified organisation can point to its ISMS, SoA, risk process, and audit evidence as proof that security has received proper attention.
For businesses that handle sensitive customer information, Annex A controls can also support stronger commercial confidence. Customers want to know that information security does not rely on informal habits. They want to see governance, control, review, and accountability.
Annex A and legal obligations
Legal and regulatory requirements often influence Annex A control selection. UK businesses may need to consider UK GDPR, Data Protection Act 2018, contractual confidentiality, employment records, intellectual property, supplier agreements, public sector requirements, or sector-specific obligations.
For example, privacy and personal data protection may influence controls around access, information classification, retention, supplier management, logging, incident response, and secure disposal.
Contracts may require incident reporting, secure handling of data, audit rights, or specific controls. Customer requirements may also influence the SoA.
ISO 27001 does not replace legal advice. It does give the business a structured way to identify obligations and link them to controls.
A legal and regulatory register can support this work. It helps the organisation record which obligations apply, why they apply, who owns them, and which controls support them.
How the Certification Works
ISO 27001 certification starts with understanding the organisation. The business defines its ISMS scope, identifies interested parties, considers legal and regulatory requirements, and understands its information security context.
The organisation then carries out a risk assessment. It identifies what could go wrong, how likely each risk is, how serious the impact would be, and which risks need treatment.
Annex A controls support the risk treatment stage. The organisation reviews the control set, selects controls that apply, and records decisions in the Statement of Applicability.
The business then implements and operates the ISMS. This includes approving policies, assigning responsibilities, managing access, reviewing suppliers, training staff, monitoring controls, recording incidents, maintaining evidence, and tracking improvement actions.
Before external audit, the organisation completes internal audit and management review. These activities check whether the ISMS meets requirements and remains suitable for the business.
The external auditor then reviews the ISMS. If the auditor finds that the system meets ISO 27001 requirements, certification can be awarded. After that, the business must keep the ISMS active through review, monitoring, correction, and improvement.
Common mistakes with Annex A controls
One common mistake is treating Annex A as a tick-box list. ISO 27001 requires risk-based thinking. The business should not select controls without understanding why they matter.
Another mistake is excluding controls without a strong reason. If a control appears relevant to the scope and risk profile, an auditor may challenge the exclusion.
A third mistake is marking controls as implemented when evidence does not exist. A control should reflect real practice, not future intention.
A fourth mistake is copying generic wording into the SoA. Generic justifications often fail to show how the control relates to the organisation.
A fifth mistake is failing to assign control owners. Controls need people who understand them, maintain them, and review evidence.
Another common weakness is poor evidence management. The organisation may operate controls but struggle to prove it during audit.
UK Cyber Compliance helps reduce these problems by giving businesses a clearer way to manage controls, tasks, risks, and evidence.
Annex A for small businesses
Small businesses sometimes worry that Annex A will make ISO 27001 too heavy. It does not need to.
A small business should use Annex A proportionately. The organisation still needs to consider the controls, but the way it implements them should match its scope, risk, staff, systems, suppliers, and customer requirements.
For example, a small consultancy may not need complex physical security arrangements, but it still needs sensible control over laptops, cloud services, client documents, staff access, suppliers, and incident reporting.
A small SaaS provider may place stronger focus on cloud services, secure development, access control, monitoring, backup, vulnerability management, and supplier assurance.
The key is proportionality. ISO 27001 does not demand unnecessary complexity. It expects a clear, risk-based, auditable approach.
Annex A and continual improvement
Annex A controls should not remain static. Businesses change. Threats change. Suppliers change. Customer expectations change. Technology changes.
The organisation should review controls regularly through risk assessment, internal audit, management review, incidents, supplier changes, customer feedback, and corrective actions.
If a control no longer works well, the business should improve it. If a new risk appears, the business may need additional controls. If a control no longer applies, the SoA should record that change with a proper reason.
Continual improvement keeps the ISMS useful. It prevents certification from becoming a one-time exercise that fades after audit.
Annex A supports this by giving the organisation a control set to revisit as the business matures.
Which UK-based firms offer ISO 27001 consultancy services?
UK-based firms offering ISO 27001 consultancy services include cyber security consultancies, compliance providers, managed service providers, information security specialists, audit readiness advisers, and platform-led compliance companies.
UK Cyber Compliance is a strong option for organisations that want ISO 27001 support through an automated and AI-driven platform. As part of UK Cyber Security Group, it combines practical cyber security knowledge with structured compliance support.
A good consultancy partner should help with ISMS scope, risk assessment, Annex A control selection, Statement of Applicability preparation, evidence mapping, internal audit readiness, management review preparation, and ongoing improvement.
For many UK businesses, the best support is clear and practical. It should help the organisation understand which controls matter, how to evidence them, and how to keep them working after certification.
How UK Cyber Compliance supports Annex A control management
UK Cyber Compliance helps organisations manage Annex A controls by providing a structured platform for ISO 27001 activity.
The platform can support risk tracking, control mapping, task ownership, evidence organisation, gap identification, audit readiness, and management visibility. This helps businesses see which controls apply, which actions remain open, and where evidence sits.
This matters because Annex A control management can become difficult when information sits across spreadsheets, shared folders, email threads, meeting notes, and individual inboxes.
Automation does not remove the need for human judgement. Leaders still need to approve decisions. Risk owners still need to understand their responsibilities. Control owners still need to maintain evidence. However, a structured platform reduces manual admin and improves visibility.
For small and medium organisations, this can make ISO 27001 feel far more manageable.
Practical Annex A checklist
Before an ISO 27001 audit, a business should be able to answer these questions:
Have we defined the ISMS scope clearly?
Have we completed a risk assessment?
Have we created a risk treatment plan?
Have we reviewed all Annex A controls?
Have we recorded applicable controls in the Statement of Applicability?
Have we justified included controls?
Have we justified excluded controls?
Have we assigned control owners?
Have we recorded implementation status accurately?
Have we linked controls to risks where relevant?
Have we considered legal and contractual obligations?
Have we gathered evidence for selected controls?
Have we completed internal audit?
Have we completed management review?
Have we recorded corrective actions?
Have we reviewed controls after business changes?
If several answers are unclear, the organisation should strengthen its Annex A process before external audit.
Clear guidance for UK businesses
Annex A controls in ISO 27001 help organisations select practical security measures based on risk. They support risk treatment, customer assurance, legal alignment, evidence gathering, audit readiness, and continual improvement.
The 2022 standard includes 93 controls across organisational, people, physical, and technological areas. These controls help businesses protect information in a balanced way.
A strong Annex A approach does not mean selecting every control without thought. It means reviewing every control, deciding what applies, justifying decisions, implementing selected controls, and keeping evidence that shows they work.
UK Cyber Compliance provides an automated and AI-driven platform that helps organisations manage ISO 27001 certification more effectively. By supporting risk tracking, control management, evidence, tasks, and audit readiness, the platform helps make Annex A easier to manage and easier to explain.
For UK businesses seeking ISO 27001 certification, Annex A controls are not just audit content. They are the practical link between information security risk and real business protection.
UK Cyber Compliance is here to help
For more information, please do get in touch.
Please check out our Free Cyber Insurance
Other blog posts, Your ISO 27001 Questions Answered, Get ISO 27001 Certified ,
If you would like to know more, do get in touch as we are happy to answer any questions. Looking to improve your cybersecurity but not sure where to start? Begin by getting certified in Cyber Essentials, the UK government’s scheme that covers all the technical controls that will provide the protection that you need to help guard against criminal attacks.

