Auditen
Home / Frameworks / ISO 42001 / Annex A controls and the Statement of Applicability
ISO 42001 · Annex A

Annex A controls and the Statement of Applicability

Annex A provides a catalog of reference controls designed to manage risks associated with artificial intelligence. Organizations must evaluate these controls, determine which are necessary based on their specific AI risk assessment, and document the results in a Statement of Applicability (SoA).

What it means

The intent of Annex A is to provide a structured menu of safeguards that address AI-specific challenges, such as data quality, transparency, and algorithmic bias. Unlike the core clauses of the standard which mandate "what" must be done, Annex A provides the "how" through specific control objectives.

In practice, not every control in Annex A will apply to every organization. The Statement of Applicability (SoA) serves as the definitive record of your security and ethical posture for AI. It bridges the gap between your high-level risk assessment and your actual operational activities.

The SoA is not merely a checklist; it is a justification document. It proves that you have thoughtfully considered every reference control and made an informed decision to either implement it or exclude it based on your specific AI use cases and risk profile.

How to meet it

Evidence an auditor asks for

  • The completed Statement of Applicability (SoA) document.
  • Risk assessment reports that demonstrate a logical link between identified AI risks and the selected Annex A controls.
  • Internal policies and standard operating procedures (SOPs) that operationalize the applicable controls.
  • Technical evidence or records (e.g., logs, validation reports, data lineage documentation) proving that the controls listed as "implemented" in the SoA are actually functioning.

Common pitfalls

  • Excluding controls without providing a concrete justification, leading to auditor findings of "incomplete risk treatment."
  • Treating the SoA as a static document and failing to update it when the AI system's scope or functionality changes.
  • Marking all controls as "Applicable" by default to avoid justifying exclusions, which then creates an impossible burden of evidence during the audit.
  • Confusing the SoA with a general risk register; the SoA must specifically address the reference controls in Annex A.