ISO 27001

Legal & regulatory requirements register

Track the legal, statutory, regulatory, and contractual obligations that apply to you, the ISO 27001 Annex A 5.31 register, each with an owner and a compliance status.

Start free See pricing
app.keelgrc.com/legal-requirements
Compliance
Legal & regulatory requirements
27
Requirements
24
Mapped to controls
12
Owners
3
Gaps
RequirementSourceOwnerControlsStatus
Personal-data breach notificationGDPRLegal3Met
Cardholder data protectionPCI DSSSecurity5Met
Consumer data requestsCCPAPrivacy2In progress
Safeguards for health dataHIPAACompliance4Met

ISO 27001 Annex A 5.31 asks you to identify the legal, statutory, regulatory, and contractual requirements relevant to information security, and to keep that up to date. Keel gives you a living register for exactly that: each obligation with its type, jurisdiction, and citation, an accountable owner, and a compliance status, plus a note on how you meet it.

Obligations scattered across contracts, laws, and someone’s memory

Most teams can’t produce a single list of the laws, regulations, and contract clauses they’re bound by. It lives across MSAs, DPAs, statute, and a few people’s heads. Annex A 5.31 asks for that list, kept current, with evidence you actually meet each one. Without a register, an auditor’s “show me your legal and regulatory requirements” becomes a scramble.

What legal & regulatory requirements register does

Every obligation type in one register

Record legal, statutory, regulatory, and contractual requirements together (GDPR and other statutes, sector regulations, and the security clauses in your customer and vendor contracts), the full Annex A 5.31 scope in one place.

Jurisdiction and citation on each entry

Tag where an obligation applies (EU/EEA, UK, a US state) and cite the exact source, e.g. “Regulation (EU) 2016/679, Art. 32”, so the register is precise enough to act on and to show an auditor.

An accountable owner for each requirement

Assign who owns meeting each obligation. Keel flags requirements with no owner, so accountability gaps don’t hide in the list.

A compliance status you can track

Mark each requirement met, partially met, not met, or not yet assessed, and record how you meet it. The register becomes a real compliance view, not a static inventory.

Gaps surfaced up front

See how many obligations are met, how many have gaps, and how many are still unassessed, so you know where to focus before a regulator or auditor does.

Why it matters

  • Satisfy ISO 27001 Annex A 5.31 with one living register
  • Capture legal, regulatory, and contractual obligations with jurisdiction and citation
  • Assign an owner and a compliance status to every requirement
  • Show, on demand, that you know and meet the obligations that apply to you

Get audit-ready, and prove it

Legal & regulatory requirements register is one module of a full GRC platform: controls crosswalked across every framework, so you collect evidence once and comply everywhere. Start free, no credit card, no sales call.

Start free

Frequently asked questions

What is a legal and regulatory requirements register?

It’s the list of legal, statutory, regulatory, and contractual obligations that apply to your organization’s information security, with how each is met. ISO 27001 Annex A 5.31 requires you to identify and keep these up to date.

Which ISO 27001 control does it map to?

Annex A 5.31, “Legal, statutory, regulatory and contractual requirements”, in ISO/IEC 27001:2022. It also supports the context and planning clauses (4 and 6) where you determine relevant requirements.

Does it include contract obligations?

Yes. Alongside laws and regulations, you can record contractual requirements, for example the security or data-protection clauses in customer MSAs and vendor agreements, each with its own owner and status.

How do I show an auditor we meet each one?

Each requirement carries a compliance status and a “how it’s met” note describing the controls, evidence, or process that satisfy it, so the register itself is the answer when an auditor asks.