Skip to content

ISO 27001 Annex A: organizational controls (A.5)

By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · ISO 27001

A.5 is the biggest Annex A theme and the most policy-heavy. It is also where most of your existing governance already lives.

The four-theme structure

The 2022 revision collapsed the old 14 Annex A domains into four themes and 93 controls. The first theme, organizational controls (A.5), is the largest and most governance-oriented — it is where your policies, roles, and management processes are credited.

What A.5 covers

Organizational controls span information security policies, roles and responsibilities, segregation of duties, supplier and cloud-service security, threat intelligence, information classification and handling, access control policy, incident management, and continuity. It is broad because it is the governance layer the rest of the controls hang from.

Mostly things you already have

For a company with any security maturity, much of A.5 already exists in some form — a security policy, defined roles, a vendor process, an incident plan. The ISO 27001 work is documenting them coherently and selecting/justifying each control against your risk, not inventing governance from nothing.

Tie selection to risk

Annex A is a menu, not a mandate — you select controls based on your risk assessment and record the include/exclude decision in the Statement of Applicability. A.5 controls are rarely excluded because governance applies to everyone, but the depth should match your risk. SentinelPanda maps your controls to the Annex A themes and keeps the SoA current.

ISO 27001 Annex A people controls (A.6) ISO 27001 Statement of Applicability ISO 27001 Annex A: 2022 changes

Run your compliance program in one workspace.