The Statement of Applicability (SoA) is a mandatory ISO 27001 document that ties an organisation’s risk assessment to the controls it has chosen. For each control in the standard’s Annex A reference set, the SoA records whether the control is applicable, the justification for including or excluding it, and its current implementation status.
The SoA is essentially the bridge between risk and control. It demonstrates that control selection was deliberate and risk-driven rather than arbitrary, and it gives the certification auditor a single map of the ISMS to test against. A weak or out-of-date SoA is one of the most common sources of audit findings.
Maintaining the SoA is an ongoing task: as risks, controls, and the business change, the document must be kept consistent with what is actually implemented, or it loses its evidentiary value.
Comply automates this — see the ISO 27001 framework page.