The ISO 42001 statement of applicability
By Sam Rivera, Founder, SentinelPanda · June 20, 2026 · 1 min read · ISO 42001
The applicability statement is where you justify your AI control set — which Annex A controls you apply, which you do not, and why.
Justifying the control set
Mirroring ISO 27001, ISO 42001 requires a statement of applicability: a documented record of which Annex A controls you apply, which you exclude, and the justification for each decision. It is how you show the control set was chosen deliberately and risk-based, not arbitrarily.
It connects risk to controls
The applicability statement is the bridge between the AI risk assessment and implementation: risks the assessment surfaces drive controls into scope, which appear in the statement with the risk as justification. It makes the logic of your AIMS auditable.
Inclusions and exclusions
For each control, you state whether it applies and why. Excluding a control requires a defensible reason — a system that does not exist in your context, for instance. As with ISO 27001, weak or convenient exclusions are exactly what an auditor probes.
Keep it current
As you add AI systems or your risk picture shifts, the applicable controls change — so the statement is reviewed alongside the risk assessment, not written once. SentinelPanda keeps the applicability statement linked to your AI risk assessment and controls.