ISO27001:2022 – A5.31 – Identification of legal, statutory, regulatory and contractual requirements

Introduction to ISO 27001 – A5.31

Implementing ISO27001 isn’t just about cybersecurity—it’s often a strategic move to meet growing compliance demands. ISO 27001 – A5.31 is all about understanding and documenting the legal and contractual drivers that shape your information security programme.

What does ISO 27001 – A5.31 require?

“Legal, statutory, regulatory and contractual requirements relevant to information security and the organisation’s approach to meet these requirements shall be identified, documented and kept up to date.”

(A5.31 – Identification of legal, statutory, regulatory and contractual requirements)

Why is this required?

Your business is subject to laws and obligations from regulators, clients, and suppliers. Failing to meet these obligations could lead to contractual breaches, fines, or worse—legal proceedings.

This control ensures that you identify, document and regularly review those obligations to remain compliant and secure. It also gives you a great opportunity to align ISO27001 with your broader legal risk management strategy.

Examples include:

  • GDPRArticles 32, 33 and 34 require robust information security and data breach reporting.
  • Client contracts – May mandate specific reporting timelines or encryption methods.
  • Cyber insurance policies – Often include minimum security controls.

What the auditor is looking for

The auditor will be looking for a documented Legal & Contractual Register that includes:

  • Relevant laws, regulations, and contractual clauses linked to information security
  • Details of how your business meets each requirement
  • Evidence of how the list is maintained and kept current

They may also review:

  • Meeting minutes that discuss legal/compliance risks
  • Audit logs confirming checks against legal requirements
  • Updates to objectives or policies triggered by changing obligations

What do you need to do?

  1. Create a Legal Register – Capture relevant info-sec-related legislation and contracts.
  2. Include how each requirement is met and assign ownership.
  3. Review contracts for clauses around breach notification, encryption, and processing terms.
  4. Speak with legal, procurement, and leadership teams to gather relevant obligations.
  5. Include review of legal requirements in your internal audit plan.

Don’t forget suppliers and insurance agreements—many contain security clauses. And keep your scope focused: this register is for information security only—not general business law or tax.

Q & A

Do I need to include all laws?

No. Include only those that directly relate to information security. Including too much will dilute focus and create unnecessary audit work.

How do we stay up to date?

Use your audit schedule and management review meetings to reassess legal risks. Controls like A5.6 (Contact with Special Interest Groups) and A5.7 (Threat Intelligence) can also help you stay informed of changes.

Difficulty Rating

2 out of 5 – This is more about business analysis and contractual awareness than technical expertise. You’ll need to work with stakeholders across legal, compliance, and IT.

More Questions?

As always, ISO27001 works best when its controls are seen as interconnected. This control supports many others by clarifying why you’re putting security measures in place.

We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… The Real Easy Guide to ISO27001 on Amazon or get in touch for tailored support.

ISO 27001 – A5.31