ISO 27001 Annex A: organizational controls (A.5)
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · ISO 27001
A.5 is the biggest Annex A theme and the most policy-heavy. It is also where most of your existing governance already lives.
The four-theme structure
The 2022 revision collapsed the old 14 Annex A domains into four themes and 93 controls. The first theme, organizational controls (A.5), is the largest and most governance-oriented — it is where your policies, roles, and management processes are credited.
What A.5 covers
Organizational controls span information security policies, roles and responsibilities, segregation of duties, supplier and cloud-service security, threat intelligence, information classification and handling, access control policy, incident management, and continuity. It is broad because it is the governance layer the rest of the controls hang from.
Mostly things you already have
For a company with any security maturity, much of A.5 already exists in some form — a security policy, defined roles, a vendor process, an incident plan. The ISO 27001 work is documenting them coherently and selecting/justifying each control against your risk, not inventing governance from nothing.
Tie selection to risk
Annex A is a menu, not a mandate — you select controls based on your risk assessment and record the include/exclude decision in the Statement of Applicability. A.5 controls are rarely excluded because governance applies to everyone, but the depth should match your risk. SentinelPanda maps your controls to the Annex A themes and keeps the SoA current.