ISO 27001 controls explained: Annex A & the 93 controls (2026 guide)

Annex A & the 93 controls (2026 guide)

This guide explains ISO 27001 controls, Annex A structure, audit expectations, common failures, and how to implement controls correctly.

Key takeaways

  1. ISO 27001 controls are practical safeguards chosen to reduce your real risks, not a checklist you must complete in full.
  2. The 93 Annex A controls (taken from the controls in ISO 27002) cover organisational, people, physical, and technological areas, but auditors assess effectiveness, not simply control adoption.
  3. Passing the audit depends on clear ownership, regular reviews, and strong evidence showing your controls operate consistently over time.

ISO 27001 controls are the safeguards and measures an organisation uses to protect its information. They are not a one-size-fits-all checklist - you only implement the ones that address your risks.

The ISO/IEC 27001:2022 standard defines 93 controls grouped in Annex A, covering areas like people, technology, and processes. These are documented in your Statement of Applicability (SoA), which shows which controls you’ve chosen, why, and what evidence supports them.

This guide explains how the controls work, what auditors look for, and how to prepare for audit success.

Understanding ISO 27001

ISO 27001 is an international standard for managing information security, developed by the International Organisation for Standardisation (ISO) and the International Electrotechnical Commission (IEC). First published in 2005, revised in 2013, and updated in 2022, it helps organisations identify risks, apply appropriate controls, and systematically protect sensitive information.

What are ISO 27001 controls?

ISO 27001 controls are safeguards that reduce information security risk. They are practical measures you put in place to protect your data and systems from threats, such as cyber attacks, human error, or misuse.

Under ISO/IEC 27001:2022, there are 93 controls, grouped into 4 themes:

  • Organisational controls - Policies, roles, supplier management, incident response.
  • People controls - Screening, training, awareness, disciplinary processes.
  • Physical controls - Secure offices, access badges, equipment protection.
  • Technological controls - Access control, encryption, monitoring, secure development.

Together, these controls protect the 3 core principles of information security:

  • Confidentiality - Only authorised people can access information.
  • Integrity - Information remains accurate and complete.
  • Availability - Information is accessible when needed.

However, you do not automatically implement all 93 controls. Each control must be selected based on your risk assessment, not because it simply appears in Annex A.

Annex A vs Clauses 4-10

This is where many organisations get confused.

ISO 27001 contains two key parts:

  • Clauses 4-10 - These define the management system requirements.
  • Annex A - This provides the control catalogue (93 controls).

In simple terms:

  • Clauses = What you must have in place to run your ISMS.
  • Annex A = Possible controls you may use to treat identified risks.

Clauses 4-10 are mandatory requirements. Every certified organisation must meet them. They cover areas such as leadership, planning, support, operations, performance evaluation, and continual improvement.

Annex A controls, on the other hand, are not automatically mandatory. You must:

  1. Identify risks through a formal risk assessment
  2. Select appropriate controls to reduce those risks
  3. Justify your decisions in your Statement of Applicability (SoA)

If you exclude a control, you must explain why. Auditors will always review your SoA to ensure your control selection is logical, risk-based, and supported by evidence.

This distinction is critical for audit readiness. Many certification delays happen because organisations focus heavily on policies, but fail to clearly connect risk → control → SoA justification.

How many ISO 27001 controls are there?

Under ISO/IEC 27001:2022, there are 93 controls listed in Annex A, which in turn are taken from the controls listed in ISO 27002.

In the previous 2013 version, there were 114 controls.

The 2022 update did not weaken the standard. Instead:

  • Controls were restructured and streamlined
  • Several were combined for clarity
  • 11 new controls were introduced to reflect current security challenges

So while the number reduced from 114 to 93, the overall level of protection did not decrease. In fact, the structure is now more practical and easier to audit.

ISO 27001:2022 control breakdown

The 93 controls are grouped into 4 themes:

Theme Number of controls
Organisational 37
People 8
Physical 14
Technological 34

This structure replaces the old 14-domain model from ISO 27001:2013 and makes control ownership clearer, particularly for SMEs and SaaS organisations.

From an audit perspective, the number itself matters less than how well your selected controls map to your risks and your Statement of Applicability. Auditors are not checking whether you implemented 93 controls. They are checking whether you implemented the right controls for your organisation.

Are organisations still mixing up the 2013 and 2022 versions?

This is no longer a live issue. The formal transition period has closed, and all certified organisations must now meet ISO 27001:2022. New certifications are only assessed against the 2022 version.

Although Annex A was reorganised and reduced from 114 to 93 controls, the core clauses and overall structure of the standard remain largely consistent. Even during the transition period, confusion was limited. Where it did occur, it was usually due to older 2013-based templates referencing outdated control numbers, which auditors could quickly identify and correct.

The 4 themes of ISO 27001 controls [2022 structure]

The 2022 update reorganised Annex A into 4 clear themes: Organisational, People, Physical, and Technological.

Organisational controls (A.5 - 37 controls)

These controls focus on governance and oversight. They set the foundation for how information security is managed across the organisation.

They cover:

  • Governance and policy
  • Risk management
  • Supplier management
  • Incident management
  • Business continuity
  • Legal and regulatory compliance

From an audit perspective, this section often determines whether your ISMS feels structured or informal.

Auditors typically check:

  • Are policies documented, version-controlled, and formally approved?
  • Are roles and responsibilities clearly assigned?
  • Is supplier risk assessed and reviewed regularly?
  • Is there evidence of independent management review?

Annex A.5 – Organisational controls list

View ISO 27001 Annex A.5 controls +
Control no. Control title
A.5.1Policies for information security
A.5.2Information security roles and responsibilities
A.5.3Segregation of duties
A.5.4Management responsibilities
A.5.5Contact with authorities
A.5.6Contact with special interest groups
A.5.7Threat intelligence Information about emerging security threats
A.5.8Information security in project management
A.5.9Inventory of information and associated assets
A.5.10Acceptable use of information and associated assets
A.5.11Return of assets
A.5.12Classification of information
A.5.13Labelling of information
A.5.14Information transfer
A.5.15Access control
A.5.16Identity management
A.5.17Authentication information
A.5.18Access rights
A.5.19Information security in supplier relationships
A.5.20Addressing information security within supplier agreements
A.5.21Managing information security in the ICT supply chain
A.5.22Monitoring, review and change management of supplier services
A.5.23Information security for the use of cloud services
A.5.24Information security incident management planning and preparation
A.5.25Assessment and decision on information security events
A.5.26Response to information security incidents
A.5.27Learning from information security incidents
A.5.28Collection of evidence
A.5.29Information security during disruption
A.5.30ICT readiness for business continuity
A.5.31Legal, statutory, regulatory and contractual requirements
A.5.32Intellectual property rights
A.5.33Protection of records
A.5.34Privacy and protection of personally identifiable information
A.5.35Independent review of information security
A.5.36Compliance with policies, rules and standards for information security
A.5.37Documented operating procedures

People controls (A.6 - 8 controls)

People remain one of the largest sources of risk. These controls ensure that employees and contractors understand their responsibilities and behave securely.

They focus on:

  • Background screening
  • Contracts and NDAs
  • Ongoing awareness training
  • Remote working security
  • Secure termination and role changes

Audit evidence usually includes:

  • Training logs and attendance records
  • Signed employment contracts and NDAs
  • Offboarding checklists
  • Clear incident reporting mechanisms

A common gap is treating awareness training as a one-off exercise rather than an ongoing programme.

Annex A.6 – People controls list

View ISO 27001 Annex A.6 controls +
Control no. Control title
A.6.1Screening
A.6.2Terms and conditions of employment
A.6.3Information security awareness, education and training
A.6.4Disciplinary process
A.6.5Responsibilities after termination or change of employment
A.6.6Confidentiality or non-disclosure agreements
A.6.7Remote working
A.6.8Information security event reporting

Physical controls (A.7 - 14 controls)

Physical controls protect offices, facilities, and equipment from unauthorised access or damage.

They focus on:

  • Entry controls and visitor management
  • Secure areas
  • Equipment protection
  • Clear desk and clear screen practices
  • Secure disposal of assets

Auditors often review:

  • Office access logs
  • CCTV coverage
  • Evidence of laptop encryption
  • Asset disposal certificates

A common SME issue is that physical controls exist informally but are not documented or consistently applied.

Annex A.7 - Physical controls list

View ISO 27001 Annex A.7 controls +
Control no. Control title
A.7.1Physical security perimeters
A.7.2Physical entry controls
A.7.3Securing offices, rooms and facilities
A.7.4Physical security monitoring
A.7.5Protecting against physical and environmental threats
A.7.6Working in secure areas
A.7.7Clear desk and clear screen
A.7.8Equipment siting and protection
A.7.9Security of assets off-premises
A.7.10Storage media
A.7.11Supporting utilities
A.7.12Cabling security
A.7.13Equipment maintenance
A.7.14Secure disposal or re-use of equipment

Technological controls (A.8 - 34 controls)

These controls address technical safeguards across networks, systems, applications, and data.

They focus on:

  • Access control and privileged access
  • Malware protection
  • Logging and monitoring
  • Backup management
  • Encryption
  • Secure development
  • Change management
  • Vulnerability management

Auditors expect to see:

  • Documented change control procedures
  • Evidence that backups are tested
  • Vulnerability scanning and patch reports
  • Privileged access reviews
  • Logging that is reviewed, not just enabled

A frequent nonconformity is having system logs switched on but never reviewed or analysed.

Annex A.8 - Technological controls list

View ISO 27001 Annex A.8 controls +
Control no. Control title
A.8.1User endpoint devices
A.8.2Privileged access rights
A.8.3Information access restriction
A.8.4Access to source code
A.8.5Secure authentication
A.8.6Capacity management
A.8.7Protection against malware
A.8.8Management of technical vulnerabilities
A.8.9Configuration management
A.8.10Information deletion
A.8.11Data masking
A.8.12Data leakage prevention
A.8.13Information backup
A.8.14Redundancy of information processing facilities
A.8.15Logging
A.8.16Monitoring activities
A.8.17Clock synchronisation
A.8.18Use of privileged utility programs
A.8.19Installation of software on operational systems
A.8.20Network security
A.8.21Security of network services
A.8.22Segregation of networks
A.8.23Web filtering
A.8.24Use of cryptography
A.8.25Secure development life cycle
A.8.26Application security requirements
A.8.27Secure system architecture and engineering principles
A.8.28Secure coding
A.8.29Security testing in development and acceptance
A.8.30Outsourced development
A.8.31Separation of development, test and production environments
A.8.32Change management
A.8.33Test information
A.8.34Protection of information systems during audit testing

How to apply ISO 27001 controls in practice

Understanding the 93 ISO 27001 controls is one thing. Applying them properly is what determines whether you pass the audit with confidence.

Implementation should always follow a clear, risk-based path. When that structure is missing, controls often exist on paper but not in practice.

1. Conduct a risk assessment

Everything starts with risk.

You first identify:

  • Your information assets (data, systems, people, suppliers)
  • Relevant threats (phishing, insider misuse, system failure, supplier breach)
  • Existing vulnerabilities
  • The impact and likelihood of each risk

This process explains why you need certain controls. Without it, control selection becomes arbitrary, which auditors will quickly challenge.

Related read - https://www.tempoaudits.com/iso-27001/risk-assessment

2. Map risks to Annex A controls

Once risks are defined, you select controls that reduce them to an acceptable level.

For example:

  • Risk: Phishing attack leading to account compromise
  • Relevant controls might include:
    • Awareness training (People control)
    • Multi-factor authentication (Technological control)
    • Logging and monitoring (Technological control)
    • Incident response procedures (Organisational control)

This mapping demonstrates that controls are chosen intentionally, not copied from a template.

Auditors will often ask: “Show me which risk this control addresses.”

If you cannot answer clearly, your SoA is likely weak.

3. Document in the Statement of Applicability (SoA)

The Statement of Applicability is where everything comes together.

It should clearly show:

  • Which Annex A controls are included
  • Which controls are excluded
  • The justification for each decision
  • The implementation status of each control

Exclusions are allowed. However, they must be logically justified. Simply stating “not applicable” without explanation is a common audit finding.

A strong SoA makes the audit structured and predictable. A vague SoA invites deeper scrutiny.

4. Implement and embed the controls

This is where many organisations underestimate the effort required.

Implementation means:

  • Updating and approving policies
  • Assigning clear ownership
  • Training staff
  • Embedding processes into daily operations
  • Monitoring performance
  • Conducting internal audits
  • Reviewing at the management level

A control is only effective if it operates consistently over time.

Control ownership: Who is responsible for implementing the controls?

A common misconception is that ISO 27001 controls are owned by IT. In reality, information security is cross-functional. Controls sit across the organisation, and responsibility must reflect that.

For example

  • HR is typically responsible for screening, employment terms, NDAs, awareness training, and offboarding processes.
  • Legal or compliance oversees regulatory obligations, contractual requirements, and privacy controls.
  • Facilities or operations manage physical security, access controls, CCTV, and secure disposal.
  • IT or engineering handle access management, logging, backups, secure development, and vulnerability management.
  • Leadership owns governance, risk acceptance decisions, resource allocation, and management review.

When ownership is unclear, tasks are delayed, reviews are missed, and audit findings become more likely.

How auditors distinguish real accountability from paper responsibility

One of the strongest indicators of ISMS maturity is whether control ownership is genuine or merely documented. Auditors can usually identify the difference quickly because real ownership leaves a clear evidential trail.

Area Real ownership (strong evidence) Name-only responsibility (audit risk)
Knowledge Owner explains the control clearly and confidently. Owner speaks in general terms and struggles with specifics.
Documentation trail Name appears in policies, meeting notes, action logs, and reviews. Name appears only on policy documents.
Decision-making Evidence of decisions made, including nuanced or difficult ones. Describes process steps but not decisions.
Ongoing review Control reviewed, updated, and challenged over time. Policy unchanged since initial implementation.
Action ownership Actions completed and tracked by the named owner. Actions consistently completed by others.
Management review Minutes show engagement, challenge, and resource discussion. Only a signature appears with little visible engagement.

Auditors often test ownership through scenario-based questions. Genuine owners respond with judgment and decisions. Nominal owners tend to repeat documented procedures.

Auditor insight: Controls that look simple but require ongoing operational effort

Several ISO 27001 controls appear straightforward at implementation, but require sustained operational time.

  • Access reviews - Writing an access policy is quick. Running documented, periodic access reviews across every system - and evidencing changes - is not. In growing organisations, this becomes a recurring commitment.
  • Asset management - Keeping your asset register accurate as devices, cloud resources, and licences change requires discipline or tooling. Registers often drift over time.
  • Supplier reviews - Having a supplier policy can be simple. Conducting and documenting meaningful security reviews of key suppliers regularly is resource-intensive, particularly where third parties are slow to provide evidence.
  • Training and awareness - Delivering annual training is manageable. Demonstrating that it is current, relevant, and effective - not just completed - requires engagement tracking and follow-up.

Common ISO 27001 control failures in audits

  1. Access control (A.8.2 / A.8.3) is one of the most common failure areas. Organisations often have a policy, but leavers retain access, privileged rights are too widely distributed, and formal access reviews are either not performed or not evidenced.
  2. Supplier security (A.5.19 / A.5.20) is another frequent gap. A supplier register may exist, yet there is little evidence of security assessments, contractual review, or ongoing monitoring.
  3. In incident management (A.5.24–A.5.28), policies are in place, but incident logs lack detail, root cause analysis, or documented learning.
  4. With cryptography (A.8.24), encryption is implemented, but key management responsibilities and rotation processes are unclear.
  5. For vulnerability management (A.8.8), patching policies exist, yet there is limited evidence of scanning, remediation tracking, or review.

Auditors ultimately look for consistent, documented operation over time, not one-off implementation activity.

How ISO 27001 controls are assessed in certification audits

Understanding the controls is important.

Understanding how they are assessed in a certification audit is no less.

A common question is whether an ISO 27001 audit must be conducted on-site. The answer depends on whether a remote approach can deliver the same level of assurance as a physical visit.

The key consideration is whether the organisation operates critical physical infrastructure, such as server rooms, on-premise hardware, or secure storage, that genuinely requires in-person inspection. Where such infrastructure exists, on-site audit activity is typically required for those elements.

For many clients of Tempo Audits, particularly cloud-native technology businesses, there is no significant on-premise infrastructure. In those cases, audits are conducted entirely remotely because that reflects the organisation’s actual risk profile and control environment.

Remote assessment does not mean physical controls are accepted without scrutiny. Auditors gather robust evidence through live video walkthroughs of offices or secure areas, photographic confirmation of access controls and clean desk practices, and review of access logs, visitor records, CCTV policies, and physical security risk assessments.

Whether remote or on-site, the objective remains the same: to verify that ISO 27001 controls are operating effectively, proportionately, and in line with the organisation’s real-world risk exposure.

Ready to certify with confidence?

If you are preparing for ISO 27001 certification and want clarity on how your controls will stand up to audit scrutiny, speak to Tempo Audits. Request a quote to receive a clear, transparent proposal and understand what your certification journey will involve.

Reviews

Trusted by fast-moving tech teams across the world who value a more human audit experience.

We transferred to Tempo from one of the established certification bodies — and we are delighted with the choice. Our audit was one of the smoothest we’ve had in terms of collaboration and engagement.
Laurence, Director of IT & Client Services @ RDT
If Carlsberg did auditors… We use Tempo for our ISO 27001 auditing and I'm thrilled that we were introduced. They ensured that the process dovetailed so smoothly with our ongoing operational activities that the impact was barely noticeable.
Jason, Director of Operations @ The Risk Factor
The Tempo team moved really fast to help us meet our timeframes — it’s rare to have an audit firm move at the speed of a start-up.
Ellie, COO @ Everblue Technology
Alfonso was nothing short of brilliant. Having worked with many auditors over the years, he stood out for his clarity, professionalism, and kindness. He completely changed my view of auditors.
Amardeep, Director @ Blue Edge
Tempo lives up to its name. No other company we contacted was faster or more straightforward during the process.
Lukas, CEO @ Noreja Intelligence
Is it weird to say I had a good time? We had worked with a more traditional auditor, but they didn't understand the needs/tech of our start-up. Tempo knew how to use our ISMS software and understood our business.
Jonny, Head of Engineering @ Nomio

Resources

Audit Timeline

How long does ISO 27001 certification take? Explore audit timelines, preparation requirements, common delays, and certification expectations.

Stage 1 Audit

Understand ISO 27001 Stage 1 audit requirements, checklists, costs, and preparation steps. Learn how to assess ISMS readiness and progress confidently to Stage 2.

Stage 2 Audit

Learn how the ISO 27001 Stage 2 audit works, what evidence is required, common mistakes to avoid, and how to achieve certification.

Internal Audit

ISO 27001 internal audit guide covering Clause 9.2 requirements, audit planning, Annex A controls, checklists, evidence collection, and compliance.

Statement of Applicability

Learn what an ISO 27001 Statement of Applicability (SoA) is, what it must include, common audit expectations, and how to avoid certification delays.

Certification Scope

Learn how to define your ISO 27001 certification scope, what it should include, common mistakes to avoid, and what auditors expect during certification.

Controls

ISO 27001 controls explained: Annex A & the 93 controls (2026 guide)

Audit Preparation

Learn how to prepare for ISO 27001 certification with a practical guide to audit readiness, risk management, internal audits, and UKAS audits.

UKAS Accreditation

A practical guide to UKAS-accredited ISO 27001 certification, including audit stages, accreditation benefits, procurement requirements, and certification verification.

Requirements

Get audit-ready with our guide to ISO 27001 certification requirements, including mandatory clauses, controls, documentation, and certification steps.

Certification Cost

How much does ISO 27001 certification cost in the UK? Learn typical audit fees, pricing by company size, and the factors that influence certification costs.

Risk Assessment

ISO 27001 risk assessment explained. Learn the 5-step process, risk treatment methods, Statement of Applicability, and audit requirements.

ISO 27001 Resources

FAQs

ISO 27001 can feel complicated at first. Here are the answers to the questions we hear most from growing teams.

No. ISO 27001 is risk-based, not checklist-based. Small businesses do not automatically implement all 93 controls. Instead, controls are selected based on identified risks and justified in the Statement of Applicability.

Auditors look for proof that controls operate consistently over time. This typically includes access review records, vulnerability scan reports, supplier assessments, incident logs, training records, management review minutes, and documented decisions.

Implementation timelines vary depending on organisational size, complexity, and existing maturity. For SMEs with defined processes, implementation typically takes 3-6 months. Larger or more complex organisations may take longer.

Book a call

No forms, no faff – just a conversation and a quote. Prefer to skip straight to it? Fill out the application form and we'll get moving.

Alternatively, if you have all the details,
fill out this form here.

Latest Articles

July 15, 2026

Case Study: How The Risk Factor achieved ISO 27001 certification in 4 weeks

ISO 27001
July 8, 2026

ISO 27001 Audit: What to Expect and How to Prepare

ISO 27001
July 5, 2026

ISO 27001 Remote Auditing: The Future Of Information Security Audits

ISO 27001
June 22, 2026

ISO 27001 vs. SOC 2: Which Certification is Right for Your Business?

ISO 27001, SOC 2
June 10, 2026

ISO 27001 Benefits for SaaS: Win Clients Faster

ISO 27001
May 12, 2026

What Is ISO 27001? A Complete Guide to Information Security Standards

ISO 27001
April 30, 2026

How to Get ISO 27001 Certified: A Step-by-Step Guide for 2026

ISO 27001
April 28, 2026

Why ISO 27001 Certification is Important for Small Businesses

ISO 27001
April 7, 2026

ISO 27001 Accreditation Bodies: A Complete Guide for Tech Companies

ISO 27001
April 7, 2026

ISO 27001 Stage 1 vs Stage 2: What's the Difference?

ISO 27001