← ISO 27001 · A.5 — Organisational
A.5.31 — Legal, statutory, regulatory and contractual requirements
high
policy-governancerecords
Requirement
Legal, statutory, regulatory and contractual requirements relevant to information security and the organisation's approach to meeting them shall be identified, documented and kept up to date.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Required element 1 — any one of
legalregulatorystatutorycontractualcompliance obligation
Required element 2 — any one of
identifiedregisterdocumentedrequirement
Supporting terms — specificity signals
gdprccpahipaandpamonitor changeslegal counselhorizon scanning
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| GDPR | Art.5(2) | Accountability | policy-governance records |
| NDPA 2023 | s.44 | Registration as a data controller or processor of major importance | policy-governance records |
| GDPR | Art.24 | Responsibility of the controller | policy-governance |
| GDPR | Art.30 | Records of processing activities | records |
| GDPR | Art.31 | Cooperation with the supervisory authority | policy-governance |
| CCPA/CPRA | Regs 7101 | Records of consumer requests kept for 24 months | records |
| SOC 2 | CC1.1 | Commitment to integrity and ethical values | policy-governance |
| SOC 2 | CC1.2 | Board independence and oversight | policy-governance |