The Statement of Applicability Problem
Every ISO 27001 certification hinges on a single artifact: the Statement of Applicability (SoA). This document declares which of the 93 Annex A controls are applicable to the organization's ISMS scope, the justification for inclusion or exclusion, and the implementation status of each applicable control.
The SoA is not a checklist — it's a risk-driven declaration that must demonstrably trace back to the risk assessment (Clause 6.1.3). When auditors find that SoA decisions cannot be traced to identified risks, or when implementation claims cannot be evidenced, the result is a major nonconformity. And major nonconformities mean failed audits.