ISO 27001A.5 — Legal, statutory, regulatory and contractual requirements
A.5.31
Legal, statutory, regulatory and contractual requirements
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Identify, document, and keep up to date the legal, statutory, regulatory, and contractual requirements relevant to information security.
Points of focus
- Requirements register maintained
- Owners for legal/contractual tracking
- Changes trigger risk/SoA review
- Evidence of periodic refresh
Implementation notes
Maintain a lightweight obligations register: GDPR/HIPAA/CCPA as applicable, customer MSAs with security exhibits, and certification commitments. Assign legal + security co-owners. Feed new contract clauses into risk treatment before promising them in sales. Do not treat this page as legal advice — point to counsel for interpretation.
Audit tip: Show the register entry for one regulation and one customer contract, with last review date.
Evidence auditors typically request:
- Compliance obligations register
- Contract security requirement extracts for key customers
- Legal update review notes
- Link from obligations to controls
Common gaps
- Register frozen at certification kickoff
- Sales signs security addenda ISMS never sees
- GDPR/HIPAA obligations informal
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.5.31 | This control |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.5.31)
Frequently Asked Questions
No. The SoA selects Annex A controls; A.5.31 tracks external requirements that drive those decisions.
Typically legal/compliance with security as co-owner for technical implications.
Start with laws that clearly apply and your top customer security schedules; expand as pipeline diversifies.