Help center

Help center

All collectionsControlsAssurancePrepare, approve and sign a Statement of Applicability

Prepare, approve and sign a Statement of Applicability

Build a version of a standard's Statement of Applicability from your controls, give every row a reason, submit it, send it back or approve and sign it, and find the signed record.

Build a version of a standard's Statement of Applicability from your controls, give every row a reason, submit it, send it back or approve and sign it, and find the signed record.

A Statement of Applicability lists every control in a standard's reference set and says, for each one, whether it applies to your organisation, why, and whether it is in place. ISO/IEC 27001 clause 6.1.3 d) requires one that management has approved. In ComplyTrain you do not type it from scratch: each version is assembled from your controls, you add the reasons, and an approver signs it. Each standard has its own numbered series of versions.

Who can do what

Product location: /qms/controls/standards/{standardId}/soa (fallback: /qms/controls). Open the standard's Statement of Applicability, or open Library in Controls, choose the standard in the Standard filter and choose Statement of Applicability.

Action

Permission

Open the page and read any version

View controls (controls:view_controls)

Start a version, write reasons, rebuild and submit

Manage controls (controls:manage_controls)

Send a submitted version back, or approve and sign it

Approve Statement of Applicability (controls:approve_soa)

Organisation administrators can do all of these, and by default the Quality Manager role holds all three permissions. Anyone with Approve Statement of Applicability can approve and sign a submitted version, including the person who submitted it. See the Controls permissions for the other roles. Buttons for actions you cannot perform are not shown.

Approving is an electronic signature, so the approver also needs a registered signing credential. See signing credentials.

Open the page

Product location: /qms/controls/standards/{standardId}/soa (fallback: /qms/controls). Open the standard's Statement of Applicability, or open Library in Controls, choose the standard in the Standard filter and choose Statement of Applicability.

Open the standard in QMS and go to its Statement of Applicability. You can also reach it from Controls:

  1. Open Library in Controls.

  2. Choose the standard in the Standard: any filter.

  3. Choose Statement of Applicability in the filter row.

The page shows one standard. At the top is either the approved version, for example Version 2 is approved, or No approved Statement of Applicability yet. Below it is the open version, for example Version 3 with its status, and then the rows of the version being shown: Showing version 3 — Draft.

Status

Meaning

Rows editable

Draft

Being assembled. Reasons can be written and the rows rebuilt.

Yes

Awaiting approval

Submitted and waiting for an approver.

No

Approved

Signed. This is the controlled record to show an auditor.

No

Superseded

A later version has been approved. Kept as history.

No

A standard can have only one open version, Draft or Awaiting approval, at a time. Start a new version appears only when none is open.

Start a new version

Product location: /qms/controls/standards/{standardId}/soa (fallback: /qms/controls). Open the standard's Statement of Applicability, or open Library in Controls, choose the standard in the Standard filter and choose Statement of Applicability.

  1. Choose Start a new version.

  2. Wait for the rows to appear. The version is built from your controls immediately and shows as Draft.

The draft contains the standard's controls that are not retired: the controls that came in with the standard's control packs and every control mapped to one of its clauses. Controls marked Not in scope are included as excluded rows. There is one row for each control and each clause it is mapped to. Only confirmed mappings count: a suggestion from the control catalogue or the assistant stays out of the version until someone confirms it. A control with no confirmed mapping to the standard's clauses has a single row showing No clause.

While you work on the draft, the approved version stays in force and visible at the top of the page.

Read the rows

Product location: /qms/controls/standards/{standardId}/soa (fallback: /qms/controls). Open the standard's Statement of Applicability, or open Library in Controls, choose the standard in the Standard filter and choose Statement of Applicability.

Column

What it shows

Control

The control's code and name.

Clause

The clause the row is about, or No clause.

Applies

Applies when the control's applicability is In scope; Partly applicable when it applies to only part of your organisation; Excluded when you have marked it Not in scope. A partly applicable control counts as applicable, and its reason should say which part it covers.

Reason

Why the control applies, or why it does not. Editable while the version is a draft.

In place

In place when at least one implementation of the control is running; Planned when none is. The control's effectiveness appears beneath, for example Working or Not yet known.

Evidence

How many evidence items are attached to the control's test results.

Everything except the reason is taken from the control as it was when the version was built or last rebuilt. To change whether a control applies, change Does this control apply to you? on the control's Scope and handling tab, then rebuild the draft. See building your control library.

Give every row a reason

Product location: /qms/controls/standards/{standardId}/soa (fallback: /qms/controls). Open the standard's Statement of Applicability, or open Library in Controls, choose the standard in the Standard filter and choose Statement of Applicability.

The standard asks why each control applies as well as why each excluded control does not, so every row needs a reason. While any row lacks one, a warning such as 12 controls still need a reason is shown and Submit for approval is unavailable.

  1. Click in the row's Reason box. Its placeholder reads Why this control applies, or why it does not.

  2. Type the reason, up to 4,000 characters.

  3. Click outside the box. The reason is saved and the warning count updates.

A reason belongs to the control, once per standard. A control that appears on several rows, one for each clause, has one reason, shown on each of its rows. The reason is stored on the control and appears in every version you build for this standard, so the next version starts with it filled in. You can edit it here while the version is a draft, or on the control's Scope and handling tab; a change in either place shows in the other. A signed version keeps the reasons it was approved with.

Write the reason that someone who disagrees would need to answer. Name the risk, obligation or business fact behind the decision, for example:

  • Applies: "Customer data is held in two cloud services; our risk assessment (R-014, R-022) requires access to be reviewed."

  • Partly applicable: "Applies to the Copenhagen office only; the Aarhus site has no on-premise servers."

  • Excluded: "We develop no software in-house. All applications are bought as SaaS, so secure development does not apply."

"Not applicable" on its own is not a reason an auditor will accept.

Rebuild from current controls

Product location: /qms/controls/standards/{standardId}/soa (fallback: /qms/controls). Open the standard's Statement of Applicability, or open Library in Controls, choose the standard in the Standard filter and choose Statement of Applicability.

Choose Rebuild from current controls after you change controls, mappings or implementations, so the draft matches them. Rebuilding:

  • refreshes every row from the controls as they are now;

  • keeps the reasons, because they are stored on the controls;

  • asks you to confirm before it removes anything, for example the rows of a control retired since the draft was built.

Rebuild is available only while the version is a draft.

Submit for approval

Product location: /qms/controls/standards/{standardId}/soa (fallback: /qms/controls). Open the standard's Statement of Applicability, or open Library in Controls, choose the standard in the Standard filter and choose Statement of Applicability.

  1. Check that the reason warning has gone.

  2. Choose Submit for approval.

The status changes to Awaiting approval and the rows become read-only. Tell your approver that the version is ready.

Send a version back

Product location: /qms/controls/standards/{standardId}/soa (fallback: /qms/controls). Open the standard's Statement of Applicability, or open Library in Controls, choose the standard in the Standard filter and choose Statement of Applicability.

If you hold Approve Statement of Applicability and the version is not ready:

  1. Open the page, check the version shows Awaiting approval, and read every row.

  2. Choose Send back for changes.

  3. In What needs to change, say exactly what to fix, for example "The exclusion of A.5.23 must name the cloud services that are out of scope."

  4. Choose Send it back. Cancel closes the box without sending anything.

The version returns to Draft and the author sees your reason on the page. They make the changes and submit again. The send-back and its reason are also recorded in the organisation's audit trail.

Approve and sign

Product location: /qms/controls/standards/{standardId}/soa (fallback: /qms/controls). Open the standard's Statement of Applicability, or open Library in Controls, choose the standard in the Standard filter and choose Statement of Applicability.

  1. Open the version that is Awaiting approval and review every row, reason and In place value.

  2. Choose to approve the version.

  3. Confirm with your signing credential and second factor when asked.

When the signature succeeds:

  • the status becomes Approved and the top panel reads, for example, Version 3 is approved, with the approval date, the number of applicable and excluded controls, and Electronically signed. This is the controlled record to show an auditor.;

  • the signed version is filed as a document in the standard's Statement of Applicability vault in Documents;

  • the version is read-only and shows This version is a signed record and cannot be edited. Start a new version to make changes.;

  • the previously approved version becomes Superseded and is kept;

  • the approval is recorded in the organisation's audit trail.

If you cancel or cannot complete the signature, nothing is approved and the version stays Awaiting approval.

Find the signed record

Product location: /document-vault/vaults. Open Documents and the vault named after the standard's code followed by Statement of Applicability.

Choose View the approved version to see the approved rows on the page, even while a newer draft is open. The signed documents are in Documents, in the vault named after the standard's code followed by "Statement of Applicability". That vault is not indexed into the knowledge base, so the assistant does not answer from an approved version that a later one has replaced.

Show an auditor the approved version, never the open draft.

Revise it later

Product location: /qms/controls/standards/{standardId}/soa (fallback: /qms/controls). Open the standard's Statement of Applicability, or open Library in Controls, choose the standard in the Standard filter and choose Statement of Applicability.

When your scope, risks or controls change, choose Start a new version once no version is open. The new draft starts with the reasons stored on your controls, so you only review what changed. Approving it supersedes the previous approved version, which stays available as history.

Example: prepare for certification

Product location: /qms/controls/standards/{standardId}/soa (fallback: /qms/controls). Open the standard's Statement of Applicability, or open Library in Controls, choose the standard in the Standard filter and choose Statement of Applicability.

Your ISO 27001 Stage 1 audit is on 12 November. The information security manager prepares the Statement of Applicability and the chief information security officer approves it.

  1. Open Framework coverage for ISO 27001 and resolve the clauses with no control. Confirm the suggested mappings you agree with. See framework coverage.

  2. For each control you exclude, set Does this control apply to you? to Not in scope on its Scope and handling tab and give the reason there, for example "We have no premises; all staff work remotely."

  3. Choose Start a new version and work through the rows until the reason warning disappears.

  4. Check the In place column. An applicable control showing Planned has nothing running: switch on its implementation and rebuild, or state in the reason when it will start.

  5. Choose Submit for approval.

  6. The approver sends the version back once, asking for a fuller reason for one exclusion. You correct it and submit again.

  7. The approver approves and signs. On audit day, show the signed version from the vault or through View the approved version.

Related views

Product location: /qms/controls/standards/{standardId}/soa (fallback: /qms/controls). Open the standard's Statement of Applicability, or open Library in Controls, choose the standard in the Standard filter and choose Statement of Applicability.

  • Framework coverage shows, clause by clause, which clauses have controls behind them.

  • The Controls overview warns Some exclusions have no reason recorded while any excluded control lacks a reason.

  • The Statement of Applicability report in Reporting is a live list of all your current controls with their applicability and reasons. Use it as a working list; the signed version in the vault is the controlled record. See running a report.

Did this answer your question?
😞
😐
😁