Skip to main content
Category: Risk Assessment & Analysis

Determination Statement

Also known as: SDS, Status Determination Statement, SDS
Simply put

A Status Determination Statement (SDS) is a written document produced by an end client (the organization engaging a worker) that states its decision about a worker's employment status for tax purposes and explains the reasons behind that decision. It is associated with the UK's IR35 off-payroll working rules, where the client must communicate its status conclusion to the worker. Workers who disagree with the statement generally have a right to challenge it through a disagreement process.

Formal definition

In the context of the UK IR35 off-payroll working regime, a Status Determination Statement (SDS) is a written statement prepared by the end-hirer (client) that records the outcome of an employment status assessment for a given engagement and sets out the reasons supporting that determination. Based on the evidence, an SDS must both state the status decision and provide the reasoning; a statement that is not issued, is incomplete, or lacks reasons may fail to satisfy the obligation. The evidence also indicates a formal disagreement process exists through which a worker may contest a determination they believe is incorrect. Note: the evidence describes this term solely in relation to UK IR35 employment-status obligations and does not address any distinct use of 'determination statement' within U.S. defense or federal cybersecurity compliance frameworks; readers in those domains should verify terminology against the applicable authoritative sources, as the concept described here does not cover such contexts.

Why it matters

For organizations engaging contractors in the UK, the Status Determination Statement (SDS) is the mechanism through which an end client formally communicates and justifies its IR35 employment-status decision. The obligation matters because it is not satisfied by simply reaching a conclusion internally; the evidence indicates the client must both state the decision and provide the reasons behind it. A statement that is never issued, is incomplete, or lacks reasoning may fail to meet the obligation, which can leave the engagement exposed to challenge and the client unable to demonstrate that it exercised reasonable care in reaching its determination.

The SDS also protects the worker's interests by making the client's reasoning transparent and by anchoring a right to contest an incorrect decision. Because workers who disagree with a determination generally have a right to challenge it through a formal disagreement process, a poorly documented or unsupported SDS is more likely to be disputed and harder to defend. The quality of the statement, not merely its existence, therefore directly affects both compliance posture and the client's relationship with its contingent workforce.

Readers working in U.S. defense or federal cybersecurity compliance should note that the SDS described here is a UK IR35 employment-status concept and is not the same as any 'determination' terminology used in those domains. The evidence addresses only the UK off-payroll context, and terminology in other frameworks should be verified against the applicable authoritative sources rather than assumed to be equivalent.

Who it's relevant to

End clients (hirers) engaging UK contractors
As the decision-maker under the IR35 off-payroll rules, the end client is responsible for producing the SDS. This entry is directly relevant to organizations that must both state their status decision and document the reasons for it, since an SDS that is not issued, is incomplete, or lacks reasoning may fail to satisfy the obligation.
Contractors and temporary workers
Workers whose engagements are subject to an IR35 determination receive the SDS and rely on its stated reasons to understand how their status was decided. They generally have the right to raise a disagreement if they believe the determination is incorrect, following the client's defined disagreement process.
HR, procurement, and compliance staff administering off-payroll engagements
Personnel who manage contingent-workforce engagements are typically responsible for preparing, issuing, and defending SDS documents and for operating the disagreement process. The completeness and reasoning within each statement affect whether the client can demonstrate a defensible determination.
Defense and federal cybersecurity compliance readers (caution)
This entry describes a UK IR35 employment-status concept only. It does not cover any distinct use of 'determination statement' within U.S. defense or federal cybersecurity compliance frameworks, and readers in those domains should verify terminology against the applicable authoritative sources rather than treating the two as equivalent.

Inside SDS

Control Effectiveness Judgment
A statement of whether an assessed security or privacy control is satisfied, other than satisfied, or not applicable, based on the assessor's evaluation of the assessment objectives and determination statements associated with that control.
Basis in Assessment Objectives
Each determination statement is typically tied to the assessment objectives derived from a control's requirements, such as those articulated in NIST SP 800-53A, which decomposes controls into discrete, assessable determination statements. Readers should verify the applicable revision, since these objectives evolve across publication versions.
Supporting Evidence Reference
A determination generally references the assessment methods used (examine, interview, test) and the evidence or artifacts reviewed that support the conclusion reached for the associated control or control element.
Assessor Attribution
The determination reflects the professional judgment of the assessor or assessment team documented in an assessment report; it is an input to, not a substitute for, an authorizing official's risk-based authorization decision.

Common questions

Answers to the questions practitioners most commonly ask about SDS.

Does a determination statement mean a control is fully compliant or that a system is secure?
No. A determination statement records whether a security control (or control element) was assessed as satisfied, other than satisfied, or not applicable based on the assessor's evidence and procedures. It reflects an assessment outcome, not a guarantee of security. Compliance with a control set is not the same as being secure, and a favorable determination does not by itself authorize a system to operate. Authorization is a separate decision made by the authorizing official. You should confirm how your assessment framework defines determination outcomes against the current authoritative guidance.
Is a determination statement the same thing as an authorization decision or an ATO?
No. Assessment and authorization are distinct activities. A determination statement is an artifact of the assessment phase that documents whether individual controls were found to be satisfied or not. An Authority to Operate (ATO) is a risk-based decision issued by an authorizing official that considers the aggregate assessment results, residual risk, and other factors. The determination statements inform that decision but do not constitute it. An ATO is also time-bound and subject to continuous monitoring, so favorable determinations at one point do not remain authoritative indefinitely.
Where in the assessment documentation do determination statements typically appear?
Determination statements generally appear within the security assessment report (SAR) and are tied to the assessment procedures applied to each control or control element. In most implementations they are aligned to the assessment objectives and methods (examine, interview, test) used by the assessor. You should verify the exact documentation structure and required fields against the applicable assessment methodology and your organization's or agency's templates, as formats vary by framework and tailoring.
What outcomes can a determination statement record for a given control?
Determination statements commonly express whether a control or control element is satisfied or other than satisfied, and some methodologies also allow a not-applicable designation with supporting rationale. The precise terminology and permitted outcomes depend on the assessment framework in use and its applicable revision. When a control is determined other than satisfied, the finding typically feeds into remediation planning artifacts such as a plan of action and milestones. Confirm the exact outcome vocabulary and handling requirements in the current authoritative guidance for your framework.
What supporting evidence should back a determination statement?
A determination statement should be supported by the evidence and results obtained through the assessment methods applied, which may include examined artifacts, interview records, and test results tied to the relevant assessment objectives. The rigor and depth of evidence generally scale with factors such as the system's impact level and the assessment's intended use. You should verify the specific evidence expectations against the applicable assessment methodology and any agency-specific or contractual requirements before finalizing statements.
How do determination statements relate to remediation and follow-on tracking?
Controls determined to be other than satisfied typically generate weaknesses or deficiencies that are carried into remediation tracking artifacts, such as a plan of action and milestones, for the authorizing official's consideration. Determination statements themselves are point-in-time assessment records; ongoing status is managed through continuous monitoring and updates to the relevant artifacts. Because determinations can change as findings are remediated or as the system evolves, confirm your organization's process for revisiting and updating them against current authoritative and agency-specific guidance.

Common misconceptions

A determination statement of 'satisfied' means the system is secure.
A determination reflects whether a control met its assessment objectives at the time of assessment; it documents compliance with specific objectives and is not equivalent to overall system security. Compliance and security are distinct, and residual risk may remain even when controls are assessed as satisfied.
The determination statement itself grants or constitutes an authorization to operate.
Determinations are assessment findings that inform the authorization decision. Assessment and authorization are separate steps; the authorizing official makes a risk-based ATO decision using the assessment results, and the ATO remains time-bound and subject to continuous monitoring.
A determination is a permanent statement about a control's status.
A determination generally reflects the state of a control at the point in time it was assessed. Control implementations and the environment can change, and continuous monitoring or reassessment may alter the finding for a subsequent assessment cycle.

Best practices

Anchor each determination statement to the specific assessment objectives for the control, and confirm you are using the assessment procedures aligned with the applicable revision of the governing publication (for example NIST SP 800-53A) rather than an outdated version.
Document the assessment methods used (examine, interview, test) and cite the specific artifacts or evidence supporting each 'satisfied' or 'other than satisfied' finding so the conclusion is traceable and reproducible.
Keep determinations objective and evidence-based, clearly separating the assessor's finding from the authorizing official's subsequent risk-based authorization decision.
Record dates and scope for each determination so that its point-in-time nature is explicit and it can be revisited during continuous monitoring or reassessment.
For 'other than satisfied' determinations, capture enough detail on the deficiency to support development of a plan of action and milestones and to inform residual risk analysis.
Verify agency-specific or program-specific tailoring and interpretation against current authoritative sources, since determination statement wording and objectives can differ by baseline, impact level, and applicable framework.