Statement of Applicability (SoA)
An ISO/IEC 27001 document listing Annex A controls, whether each is applicable, and justification for inclusions and exclusions based on the organization's risk assessment.
In practice
A working Statement of Applicability lists all 93 Annex A controls, marks each as included or excluded, cites the risk assessment finding that drove the decision, and names where evidence for included controls lives. Auditors read it line by line during certification and surveillance audits, so a justification like "not applicable to our business" without a documented risk rationale behind it is a common nonconformity.
Common confusion
Some teams treat the SoA as a static checklist completed once during initial certification. It's meant to be a living document, updated whenever the risk assessment changes, new systems or cloud services are introduced, or a control's implementation status shifts — reviewed at least at every periodic risk/SoA review, not only when an auditor asks for it.