What makes a Statement of Applicability pass or fail an audit?
A Statement of Applicability (SoA) passes an ISO 27001 audit when it accurately reflects the organisation's information security risk treatment decisions, clearly justifies the inclusion or exclusion of each Annex A control, and documents the implementation status. Failure occurs if the SoA is incomplete, inconsistent with the risk assessment, lacks clear rationale for control choices, or if implemented controls do not match the documented status, indicating a fundamental disconnect from the Information Security Management System (ISMS).
Practitioners often err by treating the SoA as a mere checklist rather than a critical output of the risk management process. The SoA must directly flow from the organisation's information security risk assessment and subsequent risk treatment plan. Each control from Annex A must be considered, and its applicability justified based on identified risks, legal obligations, and business requirements. A common pitfall is providing generic justifications or failing to document the specific implementation status for each applicable control, which auditors will scrutinise for evidence of thoughtful consideration and integration into the ISMS.
During an audit, the SoA serves as a roadmap for the assessor, who will verify its alignment with the organisation's defined scope and context. Auditors will cross-reference the SoA with the risk assessment, risk treatment plan, and evidence of control implementation. A SoA fails if it contains controls marked as implemented but for which no evidence exists, or if controls deemed non-applicable are later found to be relevant to the organisation's risk profile. The SoA's integrity is paramount; it must accurately represent the current state of information security controls and the rationale behind their selection and deployment.
Sources
- ISO/IEC 27001:2022, Clause 6.1.3 c)
- ISO/IEC 27001:2022, Clause 6.1.2
- ISO/IEC 27001:2022, Annex A