Annex A.5: Organizational Controls
The largest theme — 37 controls covering policy, roles, supplier risk, cloud, incident management and legal compliance. This is where the 2022 revision added the controls auditors now probe hardest: threat intelligence, cloud service security and ICT readiness for business continuity.
Reviewed by Tanya Kumari, Director — compliance assessment & certification readiness · Part of the Annex A series
The controls that decide your audit
Control numbers reference ISO/IEC 27001:2022 Annex A (ISO/IEC 27002:2022 numbering). The 2013→2022 transition ended 31 October 2025 — audits now run against this control set.
Where audits actually fail
A.5.7 evidence must show intelligence being assessed and acted on — a risk-register update, a rule change, a patch decision — not an unread inbox folder.
A.5.23 expects per-service governance: which cloud services, what data, who owns the relationship, shared-responsibility matrix, exit plan.
Contracts sampled by auditors routinely predate the ISMS and carry no security, breach-notification or audit-rights language (A.5.20).
Zero recorded incidents in a year reads as "not detecting", not "secure". Near-misses and lessons-learned records prove A.5.26/5.27 operate.
Evidence an auditor accepts
- Approved policy set with review history and communication records
- Threat-intel workflow samples: source → assessment → action taken (A.5.7)
- Supplier register with security clauses, assessments and review records
- Cloud service register with shared-responsibility and exit documentation (A.5.23)
- Incident log incl. near-misses, post-incident reviews, evidence-handling procedure
- ICT continuity test records mapped to BC objectives (A.5.30)
Annex A.5 FAQ
How many controls are in Annex A of ISO 27001:2022?
93 controls in four themes: A.5 Organizational (37), A.6 People (8), A.7 Physical (14), A.8 Technological (34) — down from 114 controls in 14 domains under the 2013 edition, with 11 new controls added.
Do we have to implement all 37 organizational controls?
You must consider all of them: Annex A is a reference set filtered through your risk assessment, and every exclusion needs justification in the Statement of Applicability.
What does an auditor accept as threat-intelligence evidence?
Defined sources, someone accountable for triage, and traceable outcomes — an advisory that led to an emergency patch, a rule update or a risk-register entry. Subscription alone fails A.5.7.
Annex A.5 in your ISMS
We take organisations from gap assessment to certificate — and keep the ISMS audit-ready on SigmaTrust afterwards.
