What the SoA contains
For every control in Annex A, the SoA states whether it is included, why, and whether it is already implemented. It must also justify any exclusion. It can include additional controls the organisation uses beyond Annex A.
How it connects to risk
The SoA is the output of risk treatment. Controls are included because the risk assessment shows they are needed, or because a law, contract or customer requires them. A control excluded without a solid reason is one of the first things an auditor questions.
Why it matters in the audit
Auditors use the SoA as their map: it tells them which controls to test and what evidence to ask for. It is also often shared with customers to show the scope of the security programme.
Keeping it current
The SoA is a living document. It should be updated when the scope changes, new risks appear or controls are implemented, and it is reviewed at every surveillance audit.




