← All Terms

Statement of Applicability

SoA

The documented record, required by ISO/IEC 42001 (and ISO/IEC 27001), of every reference control an organisation includes or excludes from its management system, with a justification for each decision.

Governance & Risk

A statement of applicability (SoA) is the document that ties an organisation’s risk assessment to the reference controls listed in a management-system standard’s normative annex, such as Annex A of ISO/IEC 42001 or ISO/IEC 27001. For every control, the organisation records whether it’s included or excluded, and the specific reason: the risk assessment didn’t identify a need for it, an external requirement already covers it, or it simply doesn’t apply to the systems in scope.

It’s usually the first document a certification auditor asks to see, because it’s a map of everything else they’re about to go check: an included control should have evidence behind it, and an excluded one needs a justification that holds up. Treating it as a one-time deliverable signed at project kickoff is one of the most common ways a management system fails an audit, because it stops reflecting reality within a few months of being written.

The SoA is a living document by design, not a compliance artefact filed away once. Every time a risk assessment identifies something new, or a new system enters scope, it needs to be revisited, which makes it a reliable proxy for whether the rest of the management system is still running.