Skip to main content

Free ISO 27001 templates: Statement of Applicability, risk register and control mapping

By Harry Sidhu — ISO 27001 Lead Implementer · Director and Principal Consultant, Aegentra · Updated

Three ISO 27001 working documents, published in full and free to use — no email, no form, no account. These are the artefacts an auditor asks for first, each shipping as an editable CSV and a formatted PDF.

Courses that teach these documents

Three official PECB certifications against ISO/IEC 27001:2022. What separates them is what you will do with an ISMS — understand it, build it, or audit it. Every price includes the official PECB examination voucher and two exam attempts — the initial sit plus one free resit within 12 months — with no separate exam fee later.

CourseCourse focusExam & attemptsPrice (+ GST)
ISO 27001 FoundationUnderstand the documents — describe the standard, the four Annex A themes, and how an ISMS runs day to day. The right starting point if you have been handed a Statement of Applicability and need to know what you are reading.Voucher included · 2 attempts · 1 hour, closed-book$379 + GST
ISO 27001 Lead ImplementerWrite the documents — scope an ISMS, run the risk assessment, and write the Statement of Applicability and risk treatment plan from a blank sheet. This is the method every template on this page came out of.Voucher included · 2 attempts · 3 hours, open-book, scenario-based$829 + GST
ISO 27001 Lead AuditorTest the documents — plan and lead internal, supplier and certification audits against ISO 19011, including how a Statement of Applicability and a risk register get sampled and what makes an exclusion defensible.Voucher included · 2 attempts · 3 hours, open-book, scenario-based$829 + GST

Foundation is recommended but is not a prerequisite. Delivery formats vary by course. The ISO 27001 Lead Implementer public live option is online by registration; no Melbourne or Sydney public classroom venue or date is currently published. Aegentra Academy is an official PECB authorised training partner. See the full course catalogue.

The templates

Every file below is the real artefact, complete. Nothing is truncated to make you ask for the rest, and nothing sits behind a form. Open the CSV in Excel, Google Sheets or Numbers and start editing. All three are written against ISO/IEC 27001:2022 including Amendment 1:2024 — the current 93-control Annex A across four themes, not the superseded 114-control 2013 edition.

  • Statement of Applicability — all 93 Annex A controls, each with an applicability decision and a written justification, worked through for a fictional 100-staff Australian B2B SaaS. Includes one fictional exclusion with scope-based reasoning to evaluate against the applicable audit criteria. CSV · PDF
  • Risk register — 18 worked risks with inherent and residual scoring, treatment decisions, named owners, and the Annex A controls that treat each one. CSV · PDF
  • APRA CPS 234 and DISP mapping — 17 obligations cross-referenced to potentially relevant ISO 27001 clauses or Annex A controls, plus evidence examples to evaluate against the applicable obligation. CSV · PDF
  • Internal audit plan — objective, criteria, scope, impartiality, the two-year audit programme and the risk-based sampling rationale, each with what a certification body checks. CSV · PDF
  • Clause 4–10 audit checklist — worked lines of enquiry to help plan clause-based checks and evidence requests. CSV · PDF
  • Nonconformity report — one major and one minor finding in full, with grading rationale, objective evidence, root cause and effectiveness verification. CSV · PDF
  • Audit report structure — an illustrative structure to adapt to the agreed audit scope, methods, evidence, findings and reporting requirements. CSV · PDF

Statement of Applicability template

The Statement of Applicability records the necessary controls, the reasons for including them, whether they are implemented, and the justification for excluding Annex A controls. Use it to connect your control decisions with your scope, risk treatment and applicable requirements.

This template carries all 93, each with an applicability decision, a written justification, and the implementation status. It is worked through for a fictional 100-staff Australian B2B SaaS business, and includes one worked exclusion — A.8.30 outsourced development — argued from scope rather than convenience, which is the distinction an assessor is testing. For the control catalogue on its own, see the full list of all 93 Annex A controls.

Risk register template

This worked register records inherent and residual risk assessments before and after treatment. The scores reflect the assessment method; they do not by themselves demonstrate that a control operated effectively. Retain supporting evidence and record the relevant risk-owner approval and acceptance decisions.

Each row carries a named owner, a treatment decision — modify, retain, avoid or share — and the Annex A controls that treat it, so the register and the Statement of Applicability reconcile against each other. Auditors cross-check exactly that: a control marked applicable with no risk driving it, or a risk with no control treating it, is where the questions start.

APRA CPS 234 and DISP mapping template

This worked mapping links selected APRA CPS 234 and Defence Industry Security Program obligations to potentially relevant ISO 27001 clauses or Annex A controls and evidence examples. Check the obligations that apply to your organisation and assess the evidence against each requirement. An ISO mapping or certificate does not by itself establish compliance with those obligations.

Audit artefacts — the other side of the standard

The three documents above are what you produce to build an ISMS. These four are what you produce to verify one — the working papers a Clause 9.2 internal audit generates, and what a certification body reads as evidence that the audit happened properly. All seven describe the same worked organisation, so you can follow one company end to end: Statement of Applicability, risk register, audit plan, checklist, nonconformity, report.

The audit checklist covers Clauses 4 to 10 only, and that is deliberate. Those clauses are mandatory for everyone. Annex A is sampled risk-based against your Statement of Applicability, so a fixed Annex A checklist cannot be correct for two different organisations — anyone selling one is selling a shape, not an audit.

If you would rather have the audit run for you, we deliver independent Clause 9.2 internal audits. To run them yourself, the ISO 27001 Lead Auditor course teaches the method these papers came out of.

How to use them without failing Stage 2

Use the structure. Write your own content. The columns, the justification wording and the way exclusions are argued are transferable; the asset list, the scope and the risk scores are not.

  • Define your ISMS scope first — the Statement of Applicability is downstream of scope, and filling it in beforehand produces a document arguing for controls you may not need.
  • Run your own risk assessment before touching the register. The register is the output of the method, not a substitute for it; clause 6.1.2 requires that method to be documented and repeatable.
  • Rewrite every justification in your own words. An auditor who reads identical wording across two organisations treats both management systems as unowned.
  • Keep the revision dates current. Auditors check them, and a register written once and never reviewed fails clause 8.2 regardless of how good the rows are.
  • Reconcile the two documents against each other before Stage 1 — every applicable control should trace to a risk, every unacceptable risk to a control.

For the wider sequence these documents sit inside, see the ISO 27001 implementation checklist and the ISO 27001 certification guide for Australia.

What a template cannot do for you

Templates do not secure an audit appointment, complete an internal audit or management review, or demonstrate that controls operate. Confirm the certification body's availability and readiness requirements early, allow time to address findings, and retain operating evidence as the work is performed.

The other constraint is ownership. Programmes succeed when one named person owns the ISMS and has the authority to get evidence out of other teams. Only 34 of the 93 controls are technical: HR owns screening and offboarding, legal owns supplier clauses, management owns the review. If the internal audit is the gap, we run independent Clause 9.2 audits. If you want to own it yourself, the PECB ISO 27001 Lead Implementer course teaches the method these documents came out of.