Legal & regulatory requirements register
Track the legal, statutory, regulatory, and contractual obligations that apply to you, the ISO 27001 Annex A 5.31 register, each with an owner and a compliance status.
| Requirement | Source | Owner | Controls | Status |
|---|---|---|---|---|
| Personal-data breach notification | GDPR | Legal | 3 | Met |
| Cardholder data protection | PCI DSS | Security | 5 | Met |
| Consumer data requests | CCPA | Privacy | 2 | In progress |
| Safeguards for health data | HIPAA | Compliance | 4 | Met |
ISO 27001 Annex A 5.31 asks you to identify the legal, statutory, regulatory, and contractual requirements relevant to information security, and to keep that up to date. Keel gives you a living register for exactly that: each obligation with its type, jurisdiction, and citation, an accountable owner, and a compliance status, plus a note on how you meet it.
Obligations scattered across contracts, laws, and someone’s memory
Most teams can’t produce a single list of the laws, regulations, and contract clauses they’re bound by. It lives across MSAs, DPAs, statute, and a few people’s heads. Annex A 5.31 asks for that list, kept current, with evidence you actually meet each one. Without a register, an auditor’s “show me your legal and regulatory requirements” becomes a scramble.
What legal & regulatory requirements register does
Every obligation type in one register
Record legal, statutory, regulatory, and contractual requirements together (GDPR and other statutes, sector regulations, and the security clauses in your customer and vendor contracts), the full Annex A 5.31 scope in one place.
Jurisdiction and citation on each entry
Tag where an obligation applies (EU/EEA, UK, a US state) and cite the exact source, e.g. “Regulation (EU) 2016/679, Art. 32”, so the register is precise enough to act on and to show an auditor.
An accountable owner for each requirement
Assign who owns meeting each obligation. Keel flags requirements with no owner, so accountability gaps don’t hide in the list.
A compliance status you can track
Mark each requirement met, partially met, not met, or not yet assessed, and record how you meet it. The register becomes a real compliance view, not a static inventory.
Gaps surfaced up front
See how many obligations are met, how many have gaps, and how many are still unassessed, so you know where to focus before a regulator or auditor does.
Why it matters
- Satisfy ISO 27001 Annex A 5.31 with one living register
- Capture legal, regulatory, and contractual obligations with jurisdiction and citation
- Assign an owner and a compliance status to every requirement
- Show, on demand, that you know and meet the obligations that apply to you
Get audit-ready, and prove it
Legal & regulatory requirements register is one module of a full GRC platform: controls crosswalked across every framework, so you collect evidence once and comply everywhere. Start free, no credit card, no sales call.
Start freeFrequently asked questions
What is a legal and regulatory requirements register?
It’s the list of legal, statutory, regulatory, and contractual obligations that apply to your organization’s information security, with how each is met. ISO 27001 Annex A 5.31 requires you to identify and keep these up to date.
Which ISO 27001 control does it map to?
Annex A 5.31, “Legal, statutory, regulatory and contractual requirements”, in ISO/IEC 27001:2022. It also supports the context and planning clauses (4 and 6) where you determine relevant requirements.
Does it include contract obligations?
Yes. Alongside laws and regulations, you can record contractual requirements, for example the security or data-protection clauses in customer MSAs and vendor agreements, each with its own owner and status.
How do I show an auditor we meet each one?
Each requirement carries a compliance status and a “how it’s met” note describing the controls, evidence, or process that satisfy it, so the register itself is the answer when an auditor asks.
Related features: Controls & crosswalk · Risk register · Policy management
Works with: ISO/IEC 27001