← ISO 27001 · A.5 — Organisational

A.5.31 — Legal, statutory, regulatory and contractual requirements

high policy-governancerecords

Requirement

Legal, statutory, regulatory and contractual requirements relevant to information security and the organisation's approach to meeting them shall be identified, documented and kept up to date.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
legalregulatorystatutorycontractualcompliance obligation
Required element 2 — any one of
identifiedregisterdocumentedrequirement
Supporting terms — specificity signals
gdprccpahipaandpamonitor changeslegal counselhorizon scanning

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
GDPR Art.5(2) Accountability policy-governance records
NDPA 2023 s.44 Registration as a data controller or processor of major importance policy-governance records
GDPR Art.24 Responsibility of the controller policy-governance
GDPR Art.30 Records of processing activities records
GDPR Art.31 Cooperation with the supervisory authority policy-governance
CCPA/CPRA Regs 7101 Records of consumer requests kept for 24 months records
SOC 2 CC1.1 Commitment to integrity and ethical values policy-governance
SOC 2 CC1.2 Board independence and oversight policy-governance