Statement of Applicability: keep control decisions explainable

The Statement of Applicability should not be a copied control list. It should show which controls apply, why, who owns them and what evidence supports the status.

Who this is for: For teams preparing ISO 27001 control decisions before auditor review.

Start from risk and scope

Control applicability should follow the ISMS boundary, risk treatment decisions, legal obligations and customer commitments.

  • Applies
  • Does not apply
  • Justification

Track implementation status

Each applicable control needs an owner, status, review note and evidence link so the SoA stays connected to operating reality.

Keep exclusions defensible

If a control is excluded, the reason should be specific enough for a reviewer to understand and challenge.

Common questions

Do we still need an auditor?

Yes. We help you prepare the work: scope, owners, policies, risks and evidence. An auditor still decides what is acceptable for certification, and legal interpretation stays with qualified advisers.

Which integrations are available today?

The current evidence sources are GitHub, Google Workspace and AWS. Jira can be used for remediation work. Other systems should be treated as manual evidence unless they are scoped separately.

What can AI help with?

AI can prepare drafts, summarise notes and suggest first-pass wording. Scope, evidence approval, legal interpretation and customer-facing statements still need owner review.

Which standards should we lead with?

ISO 27001 and GDPR are the strongest starting points. SOC 2, NIS2 and DORA can be handled as preparation or mapping work once the exact scope is agreed.