ISO 42001 Gap Assessmentby Agent Trust Cloud

ISO 42001 Statement of Applicability

The Statement of Applicability (SoA) is the record that links your AI risk treatment to the 38 Annex A controls of ISO/IEC 42001: which controls you apply, which you exclude and why, and how far each one is implemented. Below, what it records, how to justify exclusions and a template row for every control, described in our own words.

Build a draft SoA from the gap assessment

Where the SoA comes from

  1. Assess the risks of the AI systems in scope (clause 6.1.2).
  2. Choose a treatment for each risk and the controls that carry it out (clause 6.1.3).
  3. Compare those controls with Annex A so nothing needed is missed; add your own controls where Annex A has no match.
  4. Record the result for every Annex A control in the Statement of Applicability, and have the risk owners approve it with the risk treatment plan.

The Annex A controls guide explains each control, and the ISO 42001 checklist lists the SoA among the documents an auditor asks for.

What each row records

Justifying an exclusion

An exclusion is credible when it follows from your scope and roles, not from effort. "We don't develop AI systems; we only use third-party AI services" is a reason to exclude development-stage controls; "not enough time" isn't. If you exclude a control, check that no risk in your risk register relies on it, and revisit the decision when your scope changes. The certification guide explains how the Stage 1 audit reviews these documents.

Common audit findings on the SoA

Template: every Annex A control

One row per control (38 rows under 9 objectives). Copy it into your own document, or let the gap assessment fill it from your answers.

ControlTopic (our summary)Included?JustificationTypical evidence
A.2.2AI policyYes / NoAI policy document
A.2.3Alignment with other policiesYes / NoPolicy cross-reference or mapping
A.2.4Review of the AI policyYes / NoPolicy review record
A.3.2AI roles and responsibilitiesYes / NoRole descriptions; AI RACI
A.3.3Reporting of concernsYes / NoConcern-reporting procedure; channel details
A.4.2Resource documentationYes / NoAI system resource inventory
A.4.3Data resourcesYes / NoData inventory per AI system
A.4.4Tooling resourcesYes / NoTooling and model inventory
A.4.5System and computing resourcesYes / NoInfrastructure inventory
A.4.6Human resourcesYes / NoStaffing and skills plan
A.5.2Impact assessment processYes / NoImpact assessment procedure
A.5.3Documenting impact assessmentsYes / NoStored impact assessment reports
A.5.4Impact on individuals and groupsYes / NoIndividual and group impact analysis
A.5.5Societal impactsYes / NoSocietal impact analysis
A.6.1.2Objectives for responsible developmentYes / NoResponsible AI development objectives
A.6.1.3Responsible design and development processesYes / NoDevelopment process with review gates
A.6.2.2Requirements and specificationYes / NoRequirements specifications
A.6.2.3Design and development recordsYes / NoDesign documents; decision records
A.6.2.4Verification and validationYes / NoTest plans and results; acceptance criteria
A.6.2.5DeploymentYes / NoDeployment checklist; release approval
A.6.2.6Operation and monitoringYes / NoMonitoring dashboards; operations runbook
A.6.2.7Technical documentationYes / NoTechnical documentation set
A.6.2.8Event logsYes / NoLogging configuration; retention settings
A.7.2Data for development and enhancementYes / NoData management procedure
A.7.3Acquisition of dataYes / NoData source register; licences or consents
A.7.4Data qualityYes / NoData quality rules and check results
A.7.5Data provenanceYes / NoLineage records
A.7.6Data preparationYes / NoData preparation procedures
A.8.2Information for usersYes / NoUser documentation; AI notices
A.8.3External reportingYes / NoExternal reporting channel
A.8.4Communicating incidentsYes / NoIncident communication plan
A.8.5Information for interested partiesYes / NoRegister of reporting obligations
A.9.2Processes for responsible useYes / NoResponsible use procedure
A.9.3Objectives for responsible useYes / NoResponsible use objectives
A.9.4Intended use and human oversightYes / NoIntended use statements; oversight records
A.10.2Allocating responsibilitiesYes / NoResponsibility matrix in contracts
A.10.3SuppliersYes / NoSupplier assessments; contract clauses
A.10.4CustomersYes / NoCustomer requirements; terms of use

Control references follow ISO/IEC 42001:2023; topics and evidence are our own descriptions. The standard itself is available from ISO (iso.org/standard/42001).

Questions

Is a Statement of Applicability required for ISO 42001?

Yes. Clause 6.1.3 (AI risk treatment) asks for one: a record of the controls your risk treatment needs, whether each Annex A control is included or excluded, and why. Certification auditors read it early, because it defines what they will test.

When can an Annex A control be excluded from the SoA?

When a control isn't needed to treat the AI risks of the systems in scope, for example the data-for-development controls when you only use AI services built by others. Every exclusion needs a written reason. The clause 4 to 10 requirements can't be excluded.

How often should the Statement of Applicability be updated?

Whenever your AI risk treatment changes: a new AI system in scope, a new supplier, a changed role, or a risk assessment that calls for a new control. Most organisations also review it before each internal audit and management review.

Is there a Statement of Applicability template for Excel?

Yes. The free gap assessment on this site builds a draft Statement of Applicability from your answers as an .xlsx file with live formulas, covering all 38 Annex A controls.

Sources