Skip to content
compliancebase
ISO 27001A.5 — Legal, statutory, regulatory and contractual requirements

A.5.31

Legal, statutory, regulatory and contractual requirements

ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026

Objective

Identify, document, and keep up to date the legal, statutory, regulatory, and contractual requirements relevant to information security.

Points of focus

  • Requirements register maintained
  • Owners for legal/contractual tracking
  • Changes trigger risk/SoA review
  • Evidence of periodic refresh

Implementation notes

Maintain a lightweight obligations register: GDPR/HIPAA/CCPA as applicable, customer MSAs with security exhibits, and certification commitments. Assign legal + security co-owners. Feed new contract clauses into risk treatment before promising them in sales. Do not treat this page as legal advice — point to counsel for interpretation.

Audit tip: Show the register entry for one regulation and one customer contract, with last review date.

Evidence auditors typically request:

  • Compliance obligations register
  • Contract security requirement extracts for key customers
  • Legal update review notes
  • Link from obligations to controls

Common gaps

  • Register frozen at certification kickoff
  • Sales signs security addenda ISMS never sees
  • GDPR/HIPAA obligations informal

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.5.31This control

Primary sources

Frequently Asked Questions

No. The SoA selects Annex A controls; A.5.31 tracks external requirements that drive those decisions.

Typically legal/compliance with security as co-owner for technical implications.

Start with laws that clearly apply and your top customer security schedules; expand as pipeline diversifies.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: July 2026 · Primary sources linked above