Skip to content

The ISO 42001 statement of applicability

By Sam Rivera, Founder, SentinelPanda · June 20, 2026 · 1 min read · ISO 42001

The applicability statement is where you justify your AI control set — which Annex A controls you apply, which you do not, and why.

Justifying the control set

Mirroring ISO 27001, ISO 42001 requires a statement of applicability: a documented record of which Annex A controls you apply, which you exclude, and the justification for each decision. It is how you show the control set was chosen deliberately and risk-based, not arbitrarily.

It connects risk to controls

The applicability statement is the bridge between the AI risk assessment and implementation: risks the assessment surfaces drive controls into scope, which appear in the statement with the risk as justification. It makes the logic of your AIMS auditable.

Inclusions and exclusions

For each control, you state whether it applies and why. Excluding a control requires a defensible reason — a system that does not exist in your context, for instance. As with ISO 27001, weak or convenient exclusions are exactly what an auditor probes.

Keep it current

As you add AI systems or your risk picture shifts, the applicable controls change — so the statement is reviewed alongside the risk assessment, not written once. SentinelPanda keeps the applicability statement linked to your AI risk assessment and controls.

ISO 27001 Statement of Applicability ISO 42001 Annex A controls The ISO 42001 AI risk assessment

Run your compliance program in one workspace.