DoAIRight
ISO/IEC 42001

ISO 42001 Statement of Applicability (SoA) Explained

PUBLISHED 06 AUG 2026

In ISO/IEC 42001:2023, a Statement of Applicability (SoA) is a mandatory documented record that declares which Annex A control objectives and controls your organization has selected to manage artificial intelligence risks, along with clear justifications for including or excluding each one. Derived directly from your risk and impact assessments under Clause 6, the SoA bridges high-level governance requirements with day-to-day operational controls. It provides external auditors, regulatory bodies, and business partners with a transparent summary of your AI Management System (AIMS) security and safety posture.

What Is an ISO 42001 Statement of Applicability (SoA)?

The Statement of Applicability acts as the blueprint for your AI control framework. While ISO/IEC 42001 Clause 6 requires organizations to establish risk management and AI impact assessment processes, Annex A provides 38 reference control objectives across 9 distinct domains.

Because no two AI deployments are identical—a healthcare provider fine-tuning large language models faces vastly different risks than a enterprise software firm integrating third-party APIs—ISO 42001 allows you to tailor these controls. The SoA is the official document where you formally declare:

  • Which Annex A controls are applicable to your organization's context.
  • The rationale behind selecting those specific controls.
  • The justification for excluding any Annex A controls.
  • The current implementation status of each chosen control.

Key Components of an ISO 42001 SoA

To meet auditor expectations during an ISO/IEC 42006 accreditation audit, your SoA should be structured logically. Typically maintained in a spreadsheet or dynamic compliance platform, every entry in an ISO 42001 SoA must include:

  1. Control Identification: The official Annex A code (e.g., A.7.2) and control title.
  2. Applicability Status: A clear binary determination ("Applicable" or "Not Applicable").
  3. Justification for Inclusion: Alignment with identified AI risks, organizational context (Clause 4), or legal and regulatory obligations.
  4. Justification for Exclusion: A defensible, documented reason explaining why a control is unnecessary (for example, excluding AI development controls if you exclusively consume third-party SaaS tools).
  5. Implementation Status: Indication of whether the control is planned, partially implemented, or fully operational.
  6. Reference to Documentation: Direct links to policies, procedures, code repositories, or operational evidence supporting the control.

Structure of Annex A Controls in ISO 42001

Your SoA must evaluate controls across all nine Annex A domains defined in ISO/IEC 42001:

  • A.2 Policies related to AI: Governance framework, AI usage policies, and executive alignment.
  • A.3 Internal organization: Roles, responsibilities, allocation of resources, and reporting mechanisms.
  • A.4 Resources for AI systems: Technical infrastructure, compute resources, and human competencies.
  • A.5 Assessing impacts of AI systems: Frameworks for evaluating impacts on individuals, groups, and society.
  • A.6 AI system life cycle: Management of requirements, design, development, verification, and retirement.
  • A.7 Data for AI systems: Data acquisition, quality management, provenance, and privacy considerations.
  • A.8 Information for interested parties: Transparency, external disclosures, and user documentation.
  • A.9 Use of AI systems: Operational guidance, intended use oversight, and human-in-the-loop controls.
  • A.10 Third-party and customer relationships: Supplier management, vendor risk assessments, and contractual obligations.

How to Develop Your Statement of Applicability

Creating an accurate SoA requires a methodical approach that links organizational context to operational controls.

Step 1: Map Your AI Context and Use Cases

Under Clause 4, define your organizational role (e.g., AI provider, developer, or deployer) and identify all AI systems in scope. Context dictates which risks are prominent.

Step 2: Conduct AI Risk and Impact Assessments

Perform risk assessments and AI impact assessments (Annex A.5) targeting potential harms to individuals, specific groups, and society at large. Identify the risk mitigation strategies needed.

Step 3: Review Annex A Controls Line-by-Line

Evaluate all 38 Annex A controls against your risk treatment plan. Select controls that directly mitigate identified risks or satisfy legal and stakeholder expectations.

Step 4: Document Rationales for Exclusions

Auditors pay special attention to excluded controls. Ensure exclusions are based on factual scope constraints rather than a lack of resources or oversight.

Step 5: Keep the SoA Up-to-Date

An SoA is not a static document. Clause 8 (Operation) and Clause 10 (Improvement) require you to update your SoA whenever your AI portfolio, technical architecture, or regulatory environment evolves.

Preparing for ISO 42001 Certification

Independent certification bodies accredited under ISO/IEC 42006 use your SoA as a baseline to plan their audit procedures. While tools like DoAIRight streamline governance and help prepare your organization to become certification-ready, actual certification is granted exclusively by accredited human auditors.

To determine how ready your organization is to draft its SoA and meet ISO 42001 standards, try DoAIRight's free readiness assessment today.

Frequently asked

Is the Statement of Applicability mandatory for ISO 42001 certification?

Yes. A Statement of Applicability (SoA) is a mandatory documented requirement in ISO/IEC 42001. An accredited certification body cannot grant certification without evaluating your SoA.

Can we exclude Annex A controls from our ISO 42001 SoA?

Yes, you can exclude controls if they are not relevant to your organizational role, operational context, or risk profile. However, you must provide a clear, documented justification in the SoA for every excluded control.

How does an ISO 42001 SoA differ from an ISO 27001 SoA?

While both documents declare applicable controls, an ISO 27001 SoA focuses on information security controls. An ISO 42001 SoA specifically addresses AI-specific risks, such as algorithmic fairness, data provenance, AI impact assessments on society, and life-cycle governance.

Does DoAIRight issue ISO 42001 certificates?

No. Certification can only be granted by accredited third-party certification bodies. DoAIRight provides platforms and tools—including a free readiness assessment—to help organizations implement controls and prepare for formal audit.

See where you stand on ISO 42001.

A free readiness assessment scores you against every clause and control.

Get your score