What are the ISO 27001 Annex A controls and how do they relate to the Statement of Applicability?
ISO 27001 Annex A controls provide a recognised reference set of information security measures that an organisation can use to treat risk. The Statement of Applicability, often shortened to SoA, records which controls the organisation needs, why it needs them, whether it has implemented them, and why it has excluded any Annex A controls.
The relationship between Annex A and the SoA is central to ISO 27001. Annex A supplies the control reference. Risk assessment and risk treatment determine what the organisation actually needs. The SoA then records those decisions in a clear, auditable form.
UK Cyber Compliance supports organisations through this process with an automated and AI-driven platform. UK Cyber Compliance (a part of UK Cyber Security Group) provides these services and has a platform to make certification much easier and cheaper. The platform helps businesses connect risks, controls, owners, evidence, actions, policies, and audit preparation in one place.
A well-prepared SoA does more than satisfy an auditor. It gives leaders a practical view of the organisation’s security position. Customers can also gain confidence that the business has selected controls for clear reasons rather than copying a generic checklist.
The practical purpose of Annex A
Annex A sits within ISO/IEC 27001:2022 as a reference set of 93 information security controls. The controls help organisations address risks affecting the confidentiality, integrity, and availability of information.
Confidentiality means that information only reaches authorised people and systems. Integrity means that information remains accurate, complete, and trustworthy. Availability means that authorised users can access information and services when they need them.
The 93 controls appear across four broad areas:
Organisational controls cover governance, policies, responsibilities, suppliers, incidents, assets, legal duties, continuity, and related management activity.
People controls address screening, employment responsibilities, awareness, confidentiality, remote working, and reporting security events.
Physical controls protect premises, secure areas, equipment, media, cabling, utilities, and assets used away from business locations.
Technological controls address devices, access, authentication, malware, vulnerabilities, configuration, logging, networks, cryptography, development, testing, backup, monitoring, and other digital safeguards.
These controls create a strong reference point, but ISO 27001 does not require every organisation to implement every control automatically. The organisation must identify its own risks, choose the controls it needs, and justify its decisions.
What is ISO 27001 Certification?
ISO 27001 certification is independent confirmation that an organisation operates an Information Security Management System that meets the requirements of ISO/IEC 27001.
An Information Security Management System, often called an ISMS, gives the organisation a structured way to manage information security. It covers business context, scope, leadership, risk assessment, risk treatment, objectives, resources, awareness, operational controls, internal audit, management review, corrective action, and continual improvement.
The Annex A controls support the risk treatment element of the ISMS. The SoA shows how the organisation has considered those controls and which measures form part of its security approach.
Certification does not guarantee that no incident will ever occur. It shows that the organisation has established a risk-based management system, assigned responsibilities, selected controls, gathered evidence, and created processes for monitoring and improvement.
Customers often value this assurance because it shows that information security receives structured management attention rather than relying on informal practice.
what is iso 27001
ISO 27001 is an international standard that defines requirements for establishing, implementing, maintaining, and continually improving an ISMS.
The standard applies a risk-based approach. An organisation first understands its context and scope. It then identifies information security risks, evaluates them using agreed criteria, and chooses how to treat them.
Risk treatment may involve reducing a risk, avoiding the activity that creates it, transferring part of the exposure, or accepting the remaining risk under approved criteria.
Annex A helps with the reduction option by providing a comprehensive control reference. ISO/IEC 27002 provides more detailed guidance on applying those controls. ISO 27001 states what the management system must achieve, while ISO 27002 helps organisations understand how individual controls may work in practice.
The SoA links these standards to the real organisation. It explains which controls the business has chosen and why those choices make sense for its services, information, customers, suppliers, technology, legal duties, and risk profile.
Annex A is a reference set, not a shopping list
Businesses sometimes approach Annex A as though every control must appear in the same way across every organisation. That approach misses the risk-based purpose of ISO 27001.
A cloud software provider may need strong controls for secure development, identity management, cloud services, logging, monitoring, supplier relationships, and vulnerability management. A professional consultancy may focus more heavily on client information, staff awareness, remote working, device security, access rights, document handling, and cloud applications.
Both organisations must consider all Annex A controls. They do not need identical implementations because their risks, services, dependencies, and operating environments differ.
The organisation can also select controls outside Annex A when its risk treatment needs them. Annex A acts as a cross-check so the business does not overlook common information security measures. It does not limit the organisation to those 93 controls.
This distinction matters during an audit. An auditor expects control selection to follow risk treatment and business requirements, not a copied template.
How risk assessment leads to the SoA
The SoA should grow from the risk assessment and risk treatment process.
First, the organisation identifies information assets, business processes, systems, suppliers, people, locations, and services within the ISMS scope.
Next, it identifies threats and weaknesses that could affect those areas. Examples may include phishing, ransomware, unauthorised access, supplier failure, human error, service disruption, data loss, poor configuration, unsupported software, or physical theft.
The organisation then evaluates likelihood and impact using its approved method. Each risk receives an owner and a treatment decision.
When the business chooses to reduce a risk, it determines which controls will provide suitable protection. It then compares those selected controls with Annex A to check that it has not missed a necessary measure.
The SoA records the final control position. This creates a traceable route from risk to decision, from decision to control, and from control to evidence.
What the Statement of Applicability must show
ISO 27001 places the SoA within the information security risk treatment process. At a minimum, the document needs to record the controls the organisation has determined are necessary, the justification for including them, whether they have been implemented, and the justification for excluding any Annex A controls.
A practical SoA often contains additional information that makes management and audit work easier. Common fields include:
The Annex A control reference and title
Whether the control applies
The reason for inclusion or exclusion
The risk, legal duty, contract, or business need linked to the decision
The implementation status
The control owner
References to relevant policies, procedures, systems, or records
Evidence locations
Review notes and action status
Not every extra field represents a direct requirement of the standard. Organisations add them because they improve ownership, traceability, and audit readiness.
The SoA should remain clear enough for leaders and control owners to use. A document that only an external adviser understands will offer limited long-term value.
Inclusion decisions need clear reasoning
A strong inclusion reason explains why the control matters to the organisation.
The reason may come from a risk assessment. For example, the organisation may select secure authentication controls because account compromise could expose customer information.
Legal and regulatory duties can also drive inclusion. Privacy, record protection, incident reporting, and secure disposal controls may support data protection or sector obligations.
Contracts often influence the SoA. A customer may require encryption, resilience, logging, supplier assurance, or strict access management.
Business needs provide another valid reason. The organisation may select backup and continuity controls because service availability supports customer commitments and operational resilience.
A weak justification such as “required by ISO” does not explain the organisation’s actual reason. Annex A controls do not all apply automatically. The SoA should show the link to risk, law, contracts, interested parties, or business operations.
Exclusions require honest justification
An organisation may exclude an Annex A control when it does not apply to the ISMS scope or when risk treatment does not require it. The exclusion must make sense.
For example, a control linked to a particular physical environment may not apply when the organisation has no such environment within scope and a third party manages the relevant service. Even then, the business should consider whether supplier management controls address the dependency.
Convenience does not justify exclusion. A business should not exclude a control simply because implementation would require effort.
The organisation must also avoid using scope boundaries to hide important risks. If a system, supplier, or team directly supports the certified service, excluding it without a sound basis may weaken the ISMS and raise audit questions.
Good exclusions show that the business considered the control carefully and reached a reasoned decision.
Implementation status must reflect reality
The SoA needs to show whether necessary controls have been implemented. Accuracy matters.
A business should not mark a control as implemented because it has drafted a policy or plans to complete the work later. Implementation means that the organisation has put the control into operation to the extent required by its risk treatment decision.
Some organisations use status labels such as implemented, partly implemented, planned, not applicable, or under review. The chosen approach should remain clear and consistent.
Control evidence should support the status. Access control may require approval records, account reviews, and authentication settings. Supplier security may require due diligence, contracts, and review notes. Awareness may require training records and staff communications.
An inaccurate SoA can create serious audit issues because the auditor will compare the document with real practice.
The four Annex A areas explained
Organisational controls
The organisational area contains 37 controls. These controls shape governance and coordinated security management.
They include information security policies, roles and responsibilities, segregation of duties, contact with authorities, threat intelligence, security in project management, asset management, acceptable use, information classification, transfer of information, access management, supplier relationships, cloud service security, incident management, business continuity, legal compliance, privacy, records protection, and documented procedures.
Many SoA decisions in this area connect directly to leadership, contracts, customer expectations, and operational processes.
A small business can implement these controls proportionately. It may use concise processes and clearly assigned owners rather than complex departments.
People controls
The people area contains eight controls. These measures recognise that staff, contractors, and other users can protect information or create risk.
The controls cover screening, employment terms, information security awareness, disciplinary arrangements, responsibilities after employment changes, confidentiality agreements, remote working, and reporting information security events.
The SoA should reflect how these controls work across the employee journey. Recruitment, onboarding, role changes, ongoing awareness, and leaver processes all create evidence.
A policy alone rarely proves effective implementation. The organisation should show how staff understand and follow their responsibilities.
Physical controls
The physical area contains 14 controls. These controls protect buildings, rooms, equipment, media, and supporting infrastructure.
They cover physical security boundaries, entry controls, office protection, physical monitoring, environmental threats, secure working areas, clear desk practices, equipment placement, assets used away from business premises, storage media, supporting utilities, cabling, maintenance, and secure disposal or reuse.
Remote and cloud-based organisations still need to consider physical risk. Staff laptops, home working locations, mobile devices, and supplier facilities may remain relevant.
The SoA should explain where responsibility sits, especially when a hosting or cloud provider manages physical infrastructure.
Technological controls
The technological area contains 34 controls. These measures address systems, devices, applications, networks, development, and technical monitoring.
They cover endpoint devices, privileged access, information access restrictions, source code access, secure authentication, capacity management, malware protection, vulnerability management, configuration, information deletion, data masking, data leakage prevention, backup, redundancy, logging, monitoring, clock synchronisation, privileged utilities, software installation, network security, web filtering, cryptography, secure development, application requirements, architecture, coding, testing, outsourced development, environment separation, change management, test information, and protection during audit testing.
Technical controls often generate clear evidence through system settings, logs, reports, tickets, scans, reviews, and test results.
The business should still explain the management purpose behind each technical measure. Technology without ownership and review may not remain effective.
Who needs iso 27001 certification
ISO 27001 certification can benefit organisations that handle sensitive information or need to demonstrate structured security management.
Technology providers, managed service providers, software businesses, professional firms, healthcare suppliers, finance-related organisations, recruitment companies, public sector suppliers, charities, manufacturers, and consultancies may all gain value.
Customer requirements often drive certification. A larger client may need evidence that its supplier manages information security risks across people, processes, systems, and third parties.
Tender requirements, board assurance, insurance discussions, investor expectations, and international growth can also create a need.
Smaller businesses can achieve ISO 27001 when they apply a proportionate ISMS. The standard does not require unnecessary complexity. It requires clear scope, risk-based decisions, effective controls, reliable evidence, and ongoing management.
The SoA becomes especially useful for a smaller team because it provides one clear view of control decisions and progress.
ISO 27001 Certification Levels
People often search for ISO 27001 Certification Levels, but ISO 27001 does not use achievement bands such as entry, intermediate, or advanced.
An organisation either holds certification for its stated ISMS scope or it does not. The certificate should identify the standard, organisation, scope, and certification body.
Businesses do move through practical stages. They may begin with a gap review, define scope, assess risk, prepare the SoA, implement controls, complete internal audit, hold management review, and proceed to external audit.
Maturity can improve after certification. The organisation may strengthen evidence, automate tasks, expand scope, improve monitoring, or refine controls over time.
That growth reflects continual improvement rather than a formal certification band.
How the Certification Works
The organisation starts by defining its ISMS scope and understanding its business context. It identifies interested parties, legal duties, customer expectations, suppliers, and internal requirements.
Next comes information security risk assessment. The business identifies and evaluates risks using a consistent method.
Risk treatment then determines which controls the organisation needs. The business compares those controls with Annex A and prepares the Statement of Applicability.
The organisation implements its policies, processes, technical measures, training, supplier checks, monitoring, and other selected controls. It gathers evidence as part of normal operations.
Internal audit checks whether the ISMS meets the organisation’s requirements and the standard. Management review gives leaders a formal opportunity to evaluate performance, risks, findings, resources, and improvement needs.
An external certification body normally conducts a Stage 1 audit followed by a Stage 2 audit. Stage 1 examines readiness, scope, documented information, risk treatment, and core ISMS arrangements. Stage 2 tests whether the ISMS and selected controls operate effectively.
If the organisation meets the requirements, the certification body can issue the certificate. Surveillance audits then check continued operation during the certification cycle.
How auditors use the SoA
Auditors use the SoA as a map of the organisation’s control environment.
During Stage 1, the auditor may review whether the SoA contains the required information, matches the ISMS scope, and aligns with the risk treatment process.
During Stage 2, the auditor samples controls and evidence. They may speak with owners, inspect records, review system settings, and compare practice with the SoA.
The auditor can also test exclusion reasoning. If the organisation excludes a control that appears relevant, it should explain the decision convincingly.
Consistency matters. The scope, risk register, risk treatment plan, SoA, policies, procedures, and evidence should support one another.
A well-maintained SoA makes audit discussions clearer because it shows the reasoning behind the organisation’s security approach.
Common SoA mistakes
One common mistake involves copying another organisation’s SoA. Generic decisions rarely match the real scope and risk profile.
Another problem occurs when businesses mark every control as applicable without explaining why. Applying every control can still produce a weak SoA if no clear reasoning exists.
Some organisations exclude difficult controls for convenience. Auditors may challenge those decisions when the related risk remains relevant.
Outdated implementation status creates another weakness. A control may have changed, failed, or lost its owner while the SoA still says fully implemented.
Poor links between risks and controls also cause confusion. The business should be able to explain which risks, obligations, or business needs support each important control.
Finally, organisations sometimes prepare the SoA for audit day and then stop updating it. The document should change when the scope, systems, suppliers, risks, laws, or services change.
Evidence makes the SoA credible
The SoA states the control position. Evidence proves that position.
Strong evidence can include policy approvals, meeting records, risk decisions, access reviews, training records, supplier assessments, vulnerability reports, backup results, incident records, logs, monitoring reports, change tickets, test outcomes, and management review actions.
The organisation should keep evidence proportionate. Collect records that demonstrate control operation rather than producing documents with no clear purpose.
Control owners should know what evidence they maintain and how often they review it.
An automated platform can help by linking each control to owners, tasks, documents, and records. This reduces time spent searching through separate files when an auditor asks a question.
UK Cyber Compliance provides this structured approach through risk, control, policy, evidence, and audit-readiness functions.
How the SoA supports customer assurance
Customers often ask suppliers to complete long security questionnaires. Many questions cover access, incident management, suppliers, backup, encryption, staff awareness, monitoring, and continuity.
A current SoA helps the organisation respond consistently. It shows which controls apply and where supporting evidence exists.
The business may not share the entire SoA with every customer because parts may contain sensitive information. It can provide a suitable summary, controlled extract, or assurance response where appropriate.
A strong SoA also helps sales and operational teams avoid unsupported claims. They can refer to approved control information rather than guessing.
This improves trust and reduces the risk of promising controls that the organisation does not actually operate.
Why current cyber risk makes the SoA valuable
The UK Government’s Cyber Security Breaches Survey 2025 to 2026 found that 43 per cent of businesses identified a cyber breach or attack during the previous 12 months. The estimate represents roughly 612,000 UK businesses.
This level of exposure shows why organisations need more than isolated security tools. They need governance, clear ownership, risk-based decisions, effective controls, monitoring, and improvement.
Annex A provides a broad control reference across organisational, people, physical, and technological concerns.
The SoA turns that reference into an organisation-specific security position. It helps leaders see what the business relies on and where action remains open.
Which UK-based firms offer ISO 27001 consultancy services?
UK businesses can obtain ISO 27001 support from information security consultancies, compliance specialists, managed service providers, audit-readiness advisers, and platform-led providers.
UK Cyber Compliance supports ISO 27001 through an automated and AI-driven platform. As part of UK Cyber Security Group, it combines structured compliance workflows with practical cyber security knowledge.
A capable provider should help the organisation understand its scope, risk assessment method, treatment decisions, Annex A controls, SoA, evidence, internal audit, management review, and ongoing responsibilities.
Good support should leave the organisation in control of its ISMS. An external adviser can guide the process, but leaders and control owners need to understand the decisions and operate the system.
Choose a provider that explains controls in business language and helps create a sustainable management process rather than a temporary audit project.
How UK Cyber Compliance supports Annex A and the SoA
Managing 93 controls can become difficult when risks, tasks, evidence, and owners sit across separate spreadsheets and folders.
UK Cyber Compliance provides a central platform for managing the relationship between risk and control. Teams can track implementation, assign actions, organise evidence, identify gaps, and prepare for audit.
Automation can reduce repeated manual work and highlight areas that need attention. AI-driven support can also help users navigate requirements and organise compliance activity more efficiently.
Human judgement remains essential. The organisation must decide its scope, assess risks, approve treatment, assign ownership, and confirm that controls work.
The platform supports those decisions by making the information clearer and easier to manage.
A practical SoA review checklist
Before an external audit, check whether the SoA answers the following questions:
Does it match the current ISMS scope?
Does it include every control the organisation has determined is necessary?
Has the organisation compared its selected controls with Annex A?
Does every included control have a clear justification?
Does every excluded Annex A control have a credible justification?
Does the implementation status match reality?
Can each control owner explain their responsibilities?
Does evidence support each important control?
Do the risk register and risk treatment plan align with the SoA?
Do legal, contractual, customer, and business requirements appear where relevant?
Has the organisation reviewed changes to suppliers, systems, services, and locations?
Did internal audit examine the SoA and related controls?
Did management review consider major gaps and improvement needs?
A “no” answer does not always mean certification will fail. It identifies an area that needs attention before the auditor tests it.
Turning Annex A into real business protection
Annex A gives organisations a recognised set of information security controls. The SoA explains how those controls apply to a specific business.
Risk assessment provides the starting point. Risk treatment identifies necessary measures. Annex A provides the cross-check. The SoA records the decisions. Evidence then proves that the selected controls operate.
This connected process helps prevent ISO 27001 from becoming a paperwork exercise. It turns risks into accountable action and gives leaders a clear view of security priorities.
UK Cyber Compliance helps organisations manage that relationship through an automated and AI-driven platform. By connecting risks, controls, owners, policies, tasks, and evidence, the platform supports a clearer route to certification and ongoing improvement.
For UK businesses seeking ISO 27001, the SoA should never sit forgotten in an audit folder. It should remain a living record of how the organisation protects information, supports customers, manages obligations, and responds to changing risk.
UK Cyber Compliance is here to help
For more information, please do get in touch.
Please check out our Free Cyber Insurance
Other blog posts, Your ISO 27001 Questions Answered, Get ISO 27001 Certified ,
If you would like to know more, do get in touch as we are happy to answer any questions. Looking to improve your cybersecurity but not sure where to start? Begin by getting certified in Cyber Essentials, the UK government’s scheme that covers all the technical controls that will provide the protection that you need to help guard against criminal attacks.

