· Guide · 2 min read
Statement of Applicability Examples: How to Write Better Control Rationales
Improve your ISO 27001 Statement of Applicability with clear rationales, implementation references, ownership and evidence examples.

The Statement of Applicability is not strongest when it is longest. It is strongest when a reviewer can understand the control decision and trace it to implementation.
Weak rationale: “Required by ISO”
This does not explain the organization’s need. Better: Applicable because privileged access to production systems creates a material integrity and availability risk, and customer contracts require controlled administrative access.
Weak rationale: “Not applicable—we use cloud”
Cloud changes the allocation of responsibilities. Better: The physical data-center implementation is performed by the cloud provider, while the organization remains responsible for supplier assurance, contractual requirements and customer-side configuration. Reference the shared-responsibility analysis.
Weak rationale: “Implemented”
This gives no route to evidence. Better: Implemented through the Access Control Policy, joiner-mover-leaver workflow, identity-provider configuration and quarterly access review. Owner: Head of IT. Evidence: approved requests, removal tickets and completed reviews.
Useful Statement of Applicability fields
- control identifier and short name;
- applicability;
- rationale;
- implementation status;
- implementation description or reference;
- owner;
- evidence reference;
- risks or requirements supported;
- last review; and
- approval or change history. Avoid copying control text into a spreadsheet without adding organizational meaning.
Use the free ISO 27001 Statement of Applicability Builder to record applicability, justifications, implementation status and evidence references across all 93 Annex A controls. The tool works in your browser and supports CSV, print and local backup workflows.
How to review exclusions
For every exclusion, ask:
- Is the underlying risk genuinely absent?
- Is another control or arrangement addressing it?
- Has responsibility been outsourced rather than removed?
- Does a contract or law still create a need?
- Would a reasonable reviewer understand the boundary?
- Has anything changed since the decision? Use the Annex A Control Lookup to navigate the controls: Annex A Control Lookup Use the Clause Explainer for risk treatment and Statement of Applicability context: ISO 27001 Clause Explainer