DRAFT — REQUIRES REVIEW BY EXTERNAL ISO 27001 CONSULTANT AND SIGN-OFF BY BRITIAI CTO BEFORE USE IN BID OR AUDIT.

ISO/IEC 27001:2022 — Statement of Applicability (SoA)

Document ID: ISO02 Version: 0.1 (Draft) Date: 15 June 2026 Owner: BritiAI CISO (interim: CTO) Standard reference: ISO/IEC 27001:2022 Clause 6.1.3 d) and Annex A (93 controls across A.5, A.6, A.7, A.8)

Legend

  • Applicability: A = Applicable, X = Excluded
  • Status: I = Implemented, P = Partial, PL = Planned, NA = Not Applicable
  • Owners: CTO, CISO (interim CTO), Head of Engineering (HoE), Head of People (HoP), DPO, Head of Ops (HoO)
  • Evidence references point to documents in the BritiAI ISMS document library (placeholders pending external review).

A.5 — Organisational controls (37)

IDControlApplic.JustificationStatusEvidenceOwner
A.5.1Policies for information securityATop-level policy required by Clause 5.2PISMS-POL-001CTO
A.5.2Information security roles and responsibilitiesARoles required for ISMS operationPOrg chart, RACICTO
A.5.3Segregation of dutiesAReduces risk of unauthorised change in cloud/MLOpsPIAM matrixHoE
A.5.4Management responsibilitiesARequired by Clause 5.1PBoard minutesCTO
A.5.5Contact with authoritiesAICO, NCSC, NHS contactsPLContacts registerDPO
A.5.6Contact with special interest groupsACiSP, NCSC, AI safety bodiesPLMembership logCISO
A.5.7Threat intelligenceANEW in 2022; required for cloud/AI threat landscapePLTI feed configCISO
A.5.8Information security in project managementAAll eng projects coveredPProject templateHoE
A.5.9Inventory of information and other associated assetsAAsset register requiredPAsset register v0.3HoO
A.5.10Acceptable use of information and other associated assetsAAUP for all staffIAUP-POL-002HoP
A.5.11Return of assetsALeaver processPLeaver checklistHoP
A.5.12Classification of informationANHS data sensitivity drives thisPClassification schemeDPO
A.5.13Labelling of informationATied to classificationPLLabel schemaDPO
A.5.14Information transferACustomer data ingress/egressPTransfer policyCISO
A.5.15Access controlAIAM foundationPIAM policyHoE
A.5.16Identity managementASSO via IdPIIdP configHoE
A.5.17Authentication informationASecrets, passwords, keysPSecrets policyHoE
A.5.18Access rightsAJML processPJML runbookHoP/HoE
A.5.19Information security in supplier relationshipsACritical for Votee/Beever flow-downPSupplier policyHoO
A.5.20Addressing information security within supplier agreementsAInter-co MSA + DPAsPMSA templateLegal
A.5.21Managing information security in the ICT supply chainACloud + SaaS chainPLSupply chain registerCISO
A.5.22Monitoring, review and change management of supplier servicesAAnnual supplier reviewPLReview logHoO
A.5.23Information security for use of cloud servicesANEW in 2022; UK region enforcementPCloud security stdHoE
A.5.24Information security incident management planning and preparationAIR plan requiredPIR plan v0.2CISO
A.5.25Assessment and decision on information security eventsATriage criteriaPLTriage SOPCISO
A.5.26Response to information security incidentsARequiredPIR runbooksCISO
A.5.27Learning from information security incidentsAPost-incident reviewPLPIR templateCISO
A.5.28Collection of evidenceAForensics readinessPLEvidence SOPCISO
A.5.29Information security during disruptionABCP overlapPLBCP docHoO
A.5.30ICT readiness for business continuityANEW in 2022PLICT BCPHoE
A.5.31Legal, statutory, regulatory and contractual requirementsAUK GDPR, DPA, NHS contractsPLegal registerLegal/DPO
A.5.32Intellectual property rightsAModel weights, code, OSS licencesPIP registerLegal
A.5.33Protection of recordsARecords retentionPRetention scheduleDPO
A.5.34Privacy and protection of PIIAUK GDPRPDPIA processDPO
A.5.35Independent review of information securityAInternal audit + external Stage 2PLAudit planCTO
A.5.36Compliance with policies, rules and standards for information securityAConformance checksPLConformance logCISO
A.5.37Documented operating proceduresARunbooksPRunbook libraryHoE

A.6 — People controls (8)

IDControlApplic.JustificationStatusEvidenceOwner
A.6.1ScreeningAPre-employment checks (NHS context requires BPSS-equivalent for cleared staff)PScreening SOPHoP
A.6.2Terms and conditions of employmentASecurity clauses in contractsIEmployment contract templateHoP
A.6.3Information security awareness, education and trainingAAnnual + role-specificPLMS recordsHoP
A.6.4Disciplinary processAFor policy breachIDisciplinary policyHoP
A.6.5Responsibilities after termination or change of employmentALeaver obligationsPLeaver checklistHoP
A.6.6Confidentiality or non-disclosure agreementsAAll staff + suppliersINDA templatesLegal
A.6.7Remote workingAUK remote workforcePRemote work policyHoP
A.6.8Information security event reportingAReporting channelPReporting SOPCISO

A.7 — Physical controls (14)

IDControlApplic.JustificationStatusEvidenceOwner
A.7.1Physical security perimetersAOffice perimeter; cloud DC handled by provider attestationPOffice assessmentHoO
A.7.2Physical entryAOffice accessPAccess logHoO
A.7.3Securing offices, rooms and facilitiesAOffice hygienePOffice SOPHoO
A.7.4Physical security monitoringANEW in 2022PLCCTV/log reviewHoO
A.7.5Protecting against physical and environmental threatsAOffice fire/floodPH&S riskHoO
A.7.6Working in secure areasASensitive work zonesPLZone SOPHoO
A.7.7Clear desk and clear screenAAll staffPCDS policyHoP
A.7.8Equipment siting and protectionAOffice equipmentPAsset registerHoO
A.7.9Security of assets off-premisesARemote-work laptopsPMDM policyHoE
A.7.10Storage mediaAEncrypted only; no removable media policyPMedia policyCISO
A.7.11Supporting utilitiesAInherited from cloud provider; office UPS where applicablePProvider attestationHoO
A.7.12Cabling securityAOffice cablingPOffice build docHoO
A.7.13Equipment maintenanceAEndpoint maintenancePMDM patch recordsHoE
A.7.14Secure disposal or re-use of equipmentACertified wipe/destroyPLDisposal certsHoO

A.8 — Technological controls (34)

IDControlApplic.JustificationStatusEvidenceOwner
A.8.1User end point devicesAManaged endpoints onlyPMDM baselineHoE
A.8.2Privileged access rightsAAdmin role minimisationPPAM designHoE
A.8.3Information access restrictionARBAC/ABACPIAM matrixHoE
A.8.4Access to source codeARepo access controlsIRepo permsHoE
A.8.5Secure authenticationAMFA enforcedIIdP MFA policyHoE
A.8.6Capacity managementACloud autoscale + monitoringPCapacity dashboardHoE
A.8.7Protection against malwareAEDR + email filteringPEDR consoleCISO
A.8.8Management of technical vulnerabilitiesAScanning + patch SLAPVuln dashboardCISO
A.8.9Configuration managementAIaC + drift detectionPIaC repoHoE
A.8.10Information deletionANEW in 2022; data deletion SLAsPLDeletion SOPDPO
A.8.11Data maskingANEW in 2022; needed for training data pipelinesPLMasking stdHoE
A.8.12Data leakage preventionANEW in 2022; DLP in M365/Google + egress controlsPLDLP configCISO
A.8.13Information backupACloud-native backupPBackup policyHoE
A.8.14Redundancy of information processing facilitiesAMulti-AZ within UK regionPArchitecture docHoE
A.8.15LoggingACentralised SIEMPSIEM configCISO
A.8.16Monitoring activitiesANEW in 2022; 24/7 alertingPLMonitoring SOPCISO
A.8.17Clock synchronisationANTP from authoritative sourceINTP configHoE
A.8.18Use of privileged utility programsARestrictedPPAM policyHoE
A.8.19Installation of software on operational systemsAAllowlistingPMDM allowlistHoE
A.8.20Networks securityAVPC segmentation, WAFPNetwork designHoE
A.8.21Security of network servicesATLS everywhereITLS policyHoE
A.8.22Segregation of networksAProd/non-prod/NHS tenant isolationPNetwork designHoE
A.8.23Web filteringANEW in 2022; via EDR/secure web gatewayPLSWG configCISO
A.8.24Use of cryptographyATLS 1.2+, AES-256 at rest, FIPS-aligned KMSPCrypto stdHoE
A.8.25Secure development lifecycleASDLC requiredPSDLC policyHoE
A.8.26Application security requirementsASecurity reqs per projectPSecurity reqs templateHoE
A.8.27Secure system architecture and engineering principlesAThreat modellingPLThreat model templateHoE
A.8.28Secure codingANEW in 2022; secure coding stdPCoding stdHoE
A.8.29Security testing in development and acceptanceASAST/DAST + manualPCI security gatesHoE
A.8.30Outsourced developmentAVotee/Beever code contributions governedPSupplier dev SOPHoE
A.8.31Separation of development, test and production environmentsAEnvironment isolationPEnv designHoE
A.8.32Change managementAChange ticketingPChange policyHoE
A.8.33Test informationASynthetic/anonymised test data; no NHS data in non-prodPLTest data SOPDPO
A.8.34Protection of information systems during audit testingARead-only audit credsPLAudit access SOPCISO

Summary counts (target Stage 1):

  • Total Annex A controls: 93
  • Applicable: 93 (no full exclusions; some controls inherited from cloud provider with reduced direct implementation burden)
  • Implemented (I): ~10
  • Partial (P): ~55
  • Planned (PL): ~28

This profile is consistent with an SME at Stage 1 readiness. The Gap Analysis (ISO03) prioritises the Planned items for closure ahead of Stage 2.

End of document.