A.5.31Legal, statutory, regulatory and contractual requirements
Identify the legal, regulatory and contractual obligations that apply to your information security, and keep your approach aligned with them as they change.
Mapping at a glance
A.5.31Legal, statutory, regulatory and contractual requirementsISO/IEC 27001:2022
What an auditor, or Sekit's evidence engine, asks for.
Regulatory obligations register
The list of laws, regulations and frameworks that apply to the company (e.g. GDPR, sector rules) and how they map to your internal controls.
Compliance calendar
The calendar where the company tracks its regulatory deadlines, audit cycles and recurring compliance obligations.
From the Sekit evidence catalog
In practice
The practical version of this control is a single register listing every law and framework the company must follow, GDPR, sector rules, client contracts, each mapped to who owns it and what evidence proves compliance. Small companies often know their obligations informally but have never written them down, which falls apart the moment a new hire needs to know what applies. A compliance calendar with reminders ahead of deadlines catches the annual filing that would otherwise be missed. Auditors test whether the register is current: does it include a regulation that changed recently, or is everyone still working from the version drafted at incorporation.
Common gaps
The regulatory obligations register was last updated when the company was founded and does not reflect laws that now apply, such as NIS2.
Compliance deadlines are tracked informally by the person who happens to remember, with no calendar or automated reminder system.
The mapping between a legal obligation and the internal control that satisfies it does not exist, so nobody can show how the requirement is met.
Questions your auditor will ask
How do you know which laws and regulations currently apply to the company?
A regulatory obligations register lists every applicable law and framework, reviewed and updated as the business or regulations change.
How are compliance deadlines tracked and who is notified?
A compliance calendar lists every recurring obligation with a deadline and a named owner, with automated reminders ahead of each due date.
Can you show which control satisfies a specific legal requirement?
The regulatory mapping links each identified obligation to the internal control or document that addresses it, visible in one place.
Where regulation demands it
NIS2 1.1 requires a policy on the security of network and information systems that reflects applicable legal obligations.
ENS org.2 requires formal security regulations that translate legal and regulatory requirements into internal rules.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.