A statement of applicability (SoA) is the document that ties an organisation’s risk assessment to the reference controls listed in a management-system standard’s normative annex, such as Annex A of ISO/IEC 42001 or ISO/IEC 27001. For every control, the organisation records whether it’s included or excluded, and the specific reason: the risk assessment didn’t identify a need for it, an external requirement already covers it, or it simply doesn’t apply to the systems in scope.
It’s usually the first document a certification auditor asks to see, because it’s a map of everything else they’re about to go check: an included control should have evidence behind it, and an excluded one needs a justification that holds up. Treating it as a one-time deliverable signed at project kickoff is one of the most common ways a management system fails an audit, because it stops reflecting reality within a few months of being written.
The SoA is a living document by design, not a compliance artefact filed away once. Every time a risk assessment identifies something new, or a new system enters scope, it needs to be revisited, which makes it a reliable proxy for whether the rest of the management system is still running.