The largest of the four Annex A themes, covering governance, policy, supplier relationships, incident management and compliance.
A.5 is where an ISO 27001 audit starts and where most non-conformities are raised, because these controls are about decisions and accountability rather than technology. There is rarely a product you can buy to satisfy them: the evidence is a named owner, an approval trail, and proof the control is exercised on a defined cadence. Organisations transitioning from ISO 27001:2013 find the heaviest consolidation here — several 2013 controls frequently collapse into a single 2022 control, so the transition work is usually re-pointing existing evidence rather than building new controls.
There are 37 controls in the A.5 Organisational Controls theme, of which 3 are new in the 2022 revision. Annex A defines 93 controls in total across four themes: Organisational (37), People (8), Physical (14) and Technological (34).
No. Clause 6.1.3 requires you to compare your risk treatment plan against Annex A and justify any exclusion in the Statement of Applicability — it does not require you to apply all 93. What auditors test is whether the justification is risk-based and documented, not whether the count is high.
The 2013 edition organised 114 controls into 14 domains (A.5–A.18). The 2022 revision restructured them into 93 controls across four themes, merging 57 and introducing 11 new ones. Each control page below lists its 2013 predecessors so you can re-point existing evidence during transition.