Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 42001 Statement of Applicability explained

ISO 42001 Statement of Applicability: A Clear 2026 Guide

The ISO 42001 Statement of Applicability is the document that turns Annex A from a list of 38 reference controls into a record of what your organization has decided to do about AI risk — and why. Clause 6.1.3 f) of ISO/IEC 42001:2023 requires it, certification auditors read it before they read anything else, and most first drafts get one thing badly wrong.

This guide covers what the clause actually says, how the 38 controls are organised, how to justify inclusions and exclusions so they survive an audit, and where a Statement of Applicability written from ISO 27001 habit goes astray.

ISO 42001 Statement of Applicability: the 38 Annex A controls in 9 sections
Nine sections, thirty-eight controls, and a justification against each one.

What clause 6.1.3 says about the ISO 42001 Statement of Applicability

Clause 6.1.3 describes the AI risk treatment process. After selecting treatment options, the organization determines the controls necessary to implement them, compares that list with Annex A to make sure nothing necessary has been omitted, considers Annex A controls relevant to the treatment, and identifies any additional controls beyond Annex A. Then, at 6.1.3 f), it shall:

produce a statement of applicability that contains the necessary controls and provide justification for inclusion and exclusion of controls.

The clause adds that justification for exclusion can include where the controls are not deemed necessary by the risk assessment and where they are not required by (or are subject to exceptions under) applicable external requirements. Note 2 to the clause makes the other important point: Annex A is not exhaustive, and if different or additional controls are needed, the organization can design its own or take them from other sources.

Two things follow. The ISO 42001 Statement of Applicability is an output of the risk treatment process, not a checklist filled in before it. And it can legitimately contain controls that are not in Annex A at all — from ISO/IEC 27001, from the EU AI Act, from your own engineering practice.

The 38 controls the ISO 42001 Statement of Applicability has to cover

Annex A groups its controls into nine sections, each with a control objective. Every one of the 38 has to appear in the statement with a decision against it.

Section Objective (in short) Controls
A.2 Policies related to AI Management direction and support for AI A.2.2 AI policy · A.2.3 Alignment with other organizational policies · A.2.4 Review of the AI policy
A.3 Internal organization Accountability for AI A.3.2 AI roles and responsibilities · A.3.3 Reporting of concerns
A.4 Resources for AI systems Account for the resources AI systems need A.4.2 Resource documentation · A.4.3 Data resources · A.4.4 Tooling resources · A.4.5 System and computing resources · A.4.6 Human resources
A.5 Assessing impacts of AI systems Assess impacts on individuals, groups and society A.5.2 AI system impact assessment process · A.5.3 Documentation of AI system impact assessments · A.5.4 Assessing AI system impact on individuals or groups of individuals · A.5.5 Assessing societal impacts of AI systems
A.6 AI system life cycle Responsible design, development and operation A.6.1.2 Objectives for responsible development · A.6.1.3 Processes for responsible design and development · A.6.2.2 Requirements and specification · A.6.2.3 Documentation of design and development · A.6.2.4 Verification and validation · A.6.2.5 Deployment · A.6.2.6 Operation and monitoring · A.6.2.7 Technical documentation · A.6.2.8 Recording of event logs
A.7 Data for AI systems Understand the role and impact of data A.7.2 Data for development and enhancement · A.7.3 Acquisition of data · A.7.4 Quality of data · A.7.5 Data provenance · A.7.6 Data preparation
A.8 Information for interested parties Tell interested parties what they need to know A.8.2 System documentation and information for users · A.8.3 External reporting · A.8.4 Communication of incidents · A.8.5 Information for interested parties
A.9 Use of AI systems Responsible use A.9.2 Processes for responsible use · A.9.3 Objectives for responsible use · A.9.4 Intended use of the AI system
A.10 Third-party and customer relationships Manage risk across the supply chain A.10.2 Allocating responsibilities · A.10.3 Suppliers · A.10.4 Customers

For what each control asks in practice, see our guide to the ISO 42001 Annex A controls. The implementation guidance for each control sits in Annex B, and clause 6.1.3 e) asks you to consider it when deciding how to implement what you have included.

Building the ISO 42001 Statement of Applicability: five columns that make it auditable

The standard does not prescribe a format for the ISO 42001 Statement of Applicability. Auditors, however, need to be able to follow a line from a control decision back to the risk that drove it and forward to the document that implements it. A workable layout has five columns per control:

  1. Applicable — yes or no. The decision itself.
  2. Justification. For an inclusion: the risk, treatment option or external requirement that makes it necessary. For an exclusion: why the risk assessment does not need it, or which external requirement exempts you.
  3. Implementation status. Implemented, partially implemented, or planned — with a date for anything not yet in place. The statement must contain the necessary controls whether or not they are implemented yet; hiding an unimplemented control is what turns an observation into a nonconformity.
  4. Implementing document. The policy, procedure, register or record where the control lives. This is the column most first drafts leave blank, and the one auditors use to navigate.
  5. Evidence. What an auditor can look at to see the control operating — a log, a completed assessment, a review record.

Add a sixth column mapping each control to any external requirement it satisfies — the EU AI Act article, a contractual clause, an ISO/IEC 27001 control — if you operate under those regimes. It saves rebuilding the mapping later and it is the first thing an integrated audit asks for.

Justifying exclusions in the ISO 42001 Statement of Applicability

The ISO 42001 Statement of Applicability is more permissive than people expect about exclusions, but only if the reasoning is written down. The clause gives two grounds, and each needs a different kind of justification.

“Not deemed necessary by the risk assessment”

This has to be traceable. If A.10.4 (Customers) is excluded, the risk assessment should show that the organization does not provide AI systems to customers — a fact about scope, recorded in clause 4.3 — or that the risk to customers was assessed and no treatment beyond existing controls was needed. “We do not think it applies” is not a justification; “no AI system in scope is provided to external customers (see AIMS scope, section 3)” is.

“Not required by applicable external requirements”

Useful where a law or contract carves out an obligation — but check it does not cut the other way. Under the EU AI Act, for instance, a provider of a high-risk system cannot exclude A.6.2.7 (technical documentation) or A.6.2.8 (event logs) on any ground, because Articles 11 and 12 require them. Our comparison of ISO 42001 and the EU AI Act lists where the two overlap.

Exclusions in an ISO 42001 Statement of Applicability worth scrutinising before an auditor does:

  • A.5.5 Assessing societal impacts — commonly excluded by organizations that only use AI internally. Clause 6.1.4 requires the impact assessment to cover societies regardless; the control can rarely be excluded, though the assessment may conclude the impact is low.
  • A.7.x Data controls — excluded by organizations that buy models rather than train them. A.7.3 (acquisition) and A.7.5 (provenance) still apply to any data you use to fine-tune, evaluate or prompt the system.
  • A.3.3 Reporting of concerns — sometimes excluded on the grounds that a general whistleblowing channel exists. That is an inclusion with an existing implementing document, not an exclusion.

The mistake ISO 27001 teams make with the ISO 42001 Statement of Applicability

Organizations that already hold ISO 27001 certification tend to copy the shape of their information security statement — and with it a habit that does not transfer: marking everything applicable and writing “best practice” as the justification. It passes in an ISMS because most of the 93 controls genuinely do apply to most organizations. It fails in an AIMS for two reasons.

First, the 38 AI controls are role-dependent. A.6.1 and A.6.2 are written for organizations that develop AI systems; A.9 is written for organizations that use them; A.10 for both ends of a supply chain. An organization that only deploys a vendor’s model will include A.9 in full and A.6.2 selectively, and its justification column should say so, control by control.

Second, clause 6.1.3 makes the statement an output of risk treatment. An auditor who sees 38 inclusions and no link to the risk assessment will ask how the treatment plan produced them — and “we included everything” is an admission that it did not. The ISO 27001 Statement of Applicability guide explains why the ISMS version can afford to be broad; the AIMS version cannot.

Keeping the ISO 42001 Statement of Applicability current

The ISO 42001 Statement of Applicability changes whenever the risk treatment plan changes, which in an AI management system is more often than in an ISMS: a new AI system in scope, a shift from using a model to fine-tuning it, a new jurisdiction, a re-run impact assessment under clause 8.4. Version it, date it, record who approved it — clause 6.1.3 requires management approval of the risk treatment plan and acceptance of residual risk, and the statement is the visible part of that plan — and review it at each management review under 9.3.

Frequently asked questions

Is the ISO 42001 Statement of Applicability mandatory?
Yes. Clause 6.1.3 f) requires the organization to produce one containing the necessary controls with justification for inclusions and exclusions. It is one of the documents a stage 1 auditor will ask for by name.

Do all 38 Annex A controls have to be implemented?
No. All 38 have to be considered and appear in the statement with a decision. Controls not needed by the risk assessment can be excluded with a documented justification.

Can we include controls that are not in Annex A?
Yes. Clause 6.1.3 d) asks you to identify additional controls beyond Annex A where the treatment options need them, and Note 2 confirms you can design your own or take them from other sources. List them in the statement alongside the Annex A ones.

Can one statement cover ISO 27001 and ISO 42001?
It can, as a single register with both control sets, but keep the justification columns separate. The two standards have different risk assessments feeding them, and an auditor for either needs to trace decisions to the right one.

What is the difference between the statement and the risk treatment plan?
The treatment plan says what will be done about each risk, by whom and when. The statement says which controls are in scope and why. The plan produces the statement; the statement summarises the plan’s control decisions.

Where this leaves you

Write the ISO 42001 Statement of Applicability after the risk assessment and impact assessments, not before. Put all 38 controls in it, decide each one against your role in the AI life cycle, justify exclusions against the risk assessment or an external requirement, and point every inclusion at the document that implements it and the evidence that shows it working. Then keep it under version control, because the AI systems it describes will change faster than the standard does.

References

  • ISO/IEC 42001:2023 — the AI management system standard; clause 6.1.3 f) requires the statement of applicability, Annex A lists the 38 controls.
  • ISO/IEC 23894:2023 — guidance on AI risk management, referenced by ISO 42001 for the risk process that feeds the statement.

More on AI governance

A Statement of Applicability workbook with all 38 controls, justification columns and the EU AI Act crosswalk is included in the ISO 42001 Toolkit (68 templates), or start with the free ISO templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.