Skip to main content
Category: ISMS Clauses and Planning

Harmonized Structure (Annex SL)

Also known as: Annex SL, High-Level Structure, HLS, Harmonised Structure
Simply put

The Harmonized Structure, defined in Annex SL, is a common framework that ISO uses to write its management system standards so they share the same overall organization and core language. This shared structure makes it easier to understand and combine standards such as ISO 27001 with other management system standards. It was previously known as the High-Level Structure (HLS), a term that was formally replaced by 'Harmonized Structure' as of 2021.

Formal definition

Annex SL is a section of the ISO/IEC Directives Part 1 that prescribes how ISO Management System Standards (MSS) are to be written, providing a common high-level structure, identical core text, and shared terms and definitions. Formerly referred to as the High-Level Structure (HLS), it was renamed the Harmonized Structure in 2021. For ISO/IEC 27001, this structure underlies the arrangement of the ISMS requirement clauses (clauses 4 through 10), promoting interoperability and easier integration across management system standards. MSS writers are advised to use the flowcharts in Annex SL Appendix 3 when drafting terms and definitions. Note that the Harmonized Structure governs how standards are drafted and does not itself specify certifiable controls; for ISO 27001, reference controls remain in Annex A and are selected via the Statement of Applicability.

Why it matters

For organizations managing multiple ISO management system standards, the Harmonized Structure is what makes integration practical rather than burdensome. Because Annex SL prescribes a common high-level structure, identical core text, and shared terms and definitions across ISO Management System Standards, an organization running ISO 27001 alongside other management system standards can align overlapping requirements, such as leadership commitment, risk-based thinking, internal audit, and continual improvement, rather than maintaining wholly separate and duplicative systems. This shared architecture supports the interoperability and user-friendliness of management standards worldwide.

Understanding the Harmonized Structure also clarifies what ISO 27001 certification does and does not cover. The structure governs how the standard is drafted, it underlies the arrangement of the ISMS requirement clauses (clauses 4 through 10), but it does not itself specify certifiable controls. For ISO 27001, reference controls remain in Annex A and are selected via the Statement of Applicability, informed by risk assessment. Compliance professionals who conflate the harmonized clause structure with control selection risk misunderstanding where certifiable requirements actually reside.

Finally, the terminology change matters for accuracy in documentation and communication. What was long known as the High-Level Structure (HLS) was formally renamed the Harmonized Structure as of 2021. Using current terminology helps avoid confusion in audit documentation, internal policies, and cross-team discussions, particularly where older references to HLS persist in legacy materials.

Who it's relevant to

GRC and compliance managers running multiple ISO standards
Professionals maintaining ISO 27001 alongside other ISO management system standards benefit most directly from the Harmonized Structure, since the shared high-level structure and identical core text make it easier to integrate common requirements, such as leadership, planning, and continual improvement, into a single coordinated management system rather than duplicating effort.
ISO 27001 implementers and internal auditors
Those building or auditing an ISMS should understand that the Harmonized Structure underlies the arrangement of clauses 4 through 10 but does not specify certifiable controls. Recognizing this boundary helps ensure that control selection is correctly grounded in Annex A and the Statement of Applicability rather than in the clause structure itself.
Documentation owners and policy writers
Anyone drafting or maintaining compliance documentation should note that the term 'High-Level Structure (HLS)' was formally replaced by 'Harmonized Structure' as of 2021. Updating legacy references helps keep policies, audit records, and cross-team communications consistent with current ISO terminology.

Inside Harmonized Structure (Annex SL)

Common Clause Framework
Annex SL provides a standardized high-level structure that ISO management system standards share, organizing certifiable requirements across a consistent set of clauses. For ISO/IEC 27001, this manifests in clauses 4 through 10, which contain the ISMS requirements.
Identical Core Text and Common Terminology
The harmonized structure supplies shared subclause headings, common definitions, and consistent terminology across management system standards, so that concepts such as context of the organization, leadership, planning, and performance evaluation are expressed comparably from one standard to another.
Consistent Management System Elements
The structure aligns recurring management system components, including scope determination, leadership commitment, risk-based planning, support and resources, operational controls, monitoring and measurement, and improvement, allowing organizations to recognize familiar patterns when adopting multiple standards.
Relationship to ISO 27001 Requirements versus Annex A
The harmonized structure governs the certifiable ISMS requirements in clauses 4 through 10; it is distinct from Annex A, which lists reference controls selected via a Statement of Applicability informed by risk assessment. The structure shapes how the management system is organized, not which specific security controls are chosen.

Common questions

Answers to the questions practitioners most commonly ask about Harmonized Structure (Annex SL).

Does adopting the Harmonized Structure mean ISO 27001 and other management system standards share identical requirements?
No. The Harmonized Structure (formerly known as Annex SL) provides a common high-level clause layout, shared section titles, and a core set of common terms and definitions across ISO management system standards, but it does not make their requirements identical. Each standard, including ISO/IEC 27001, adds discipline-specific requirements within that shared framework. In ISO 27001, this is what populates the ISMS requirements in clauses 4 through 10 with information-security-specific content, so certifying against ISO 27001 is not satisfied simply by conforming to the common structure of another standard.
Is the Harmonized Structure the same thing as ISO 27001's Annex A controls?
No, these are distinct elements. The Harmonized Structure governs the arrangement of the certifiable ISMS requirements, which sit in clauses 4 through 10. Annex A is a separate reference set of controls that organizations select from via a Statement of Applicability, informed by risk assessment. The common structure shapes how the management system clauses are organized; it does not define or replace the Annex A reference controls.
How does the Harmonized Structure affect the numbering of the certifiable clauses in ISO 27001?
The common structure aligns the high-level clauses so that, in most ISO management system standards, the certifiable requirements fall under a consistent set of numbered clauses. In ISO/IEC 27001, the ISMS requirements are found in clauses 4 through 10, covering areas such as context of the organization, leadership, planning, support, operation, performance evaluation, and improvement. Because this layout is shared, practitioners familiar with one Annex SL-based standard can typically navigate the clause organization of another more easily, though the specific requirements within each clause differ.
If our organization already maintains a management system under another Annex SL standard, does that simplify ISO 27001 implementation?
In many cases it can help, because elements such as document control, management review, internal audit, and continual improvement processes are structured similarly across standards that follow the common framework. This may allow you to reuse or extend existing management system processes. However, the degree of reuse depends on scope and how the systems are integrated, and you would still need to address the information-security-specific requirements of clauses 4 through 10 and the Annex A control selection process, so treat overlap as a starting point rather than a shortcut.
Can we integrate an ISO 27001 ISMS with another management system because they share the Harmonized Structure?
Integration is often feasible, and the shared clause layout and common terminology are intended to support combining management systems. Many organizations maintain an integrated management system covering multiple disciplines under a unified set of processes. That said, each standard's distinct requirements must still be met, and the extent of integration typically depends on organizational scope and the boundaries of each management system. Confirm that the defined scope of your ISMS remains clear, since ISO 27001 certification covers only the ISMS scope you define.
How does the common terminology in the Harmonized Structure affect how we write our documentation?
The shared set of core terms and definitions promotes consistent language across clauses and across integrated management systems, which can reduce ambiguity in policies and procedures. When drafting documentation, aligning your terminology with the common definitions typically makes the system easier to audit and to maintain alongside other standards. Bear in mind that discipline-specific terms unique to information security still apply within ISO 27001, so the common vocabulary supplements rather than fully replaces standard-specific terminology.

Common misconceptions

A shared harmonized structure means certification to one ISO management system standard automatically satisfies another.
The common structure aids integration and reduces duplication, but each standard has its own discipline-specific requirements. ISO/IEC 27001 certification covers only the defined scope of the ISMS and does not, by itself, satisfy the requirements of other standards even when they follow the same Annex SL structure.
The harmonized structure applies to the Annex A controls in ISO 27001.
The structure applies to the ISMS requirements in clauses 4 through 10, not to Annex A. Annex A reference controls are selected through the Statement of Applicability and informed by risk assessment, and are separate from the harmonized clause framework. Note that Annex A was restructured in the 2022 revision from 114 controls in the 2013 version into 93 controls organized in four themes.
Because SOC 2 and ISO 27001 both address security, the harmonized structure lets them be treated as equivalent.
SOC 2 is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard and results in a report, while ISO 27001 is a certification issued by an accredited certification body. Annex SL applies to ISO management system standards, not to SOC 2. Mapping between the two frameworks is possible but partial, and satisfying one does not automatically satisfy the other.

Best practices

Leverage the shared clause structure to integrate an ISO 27001 ISMS with other ISO management systems already in place, reducing duplication of context, leadership, and improvement documentation where scopes align.
Keep the ISMS requirements in clauses 4 through 10 clearly separated in your documentation from Annex A control selection, so auditors can distinguish management system conformity from control implementation.
Specify the version of ISO 27001 you are working against when citing control counts or Annex A structure, since the 2013 and 2022 revisions differ in both control numbers and organization.
Use the Statement of Applicability, informed by a documented risk assessment, to justify which Annex A reference controls are included or excluded rather than assuming the harmonized structure dictates control choices.
When pursuing both SOC 2 and ISO 27001, treat any mapping between the Trust Services Criteria and the ISMS requirements or Annex A as partial, and confirm scope boundaries with your certification body and CPA firm rather than assuming equivalence.
Define and document the ISMS scope precisely, recognizing that certification covers only that defined scope and does not guarantee freedom from incidents outside or within it.