markdowneditor

Legal, Regulatory & Contractual Requirements Register

Legal/regulatory/contractual obligations

ISO & ConformitéLégerlegalregister

Mode d'emploi: Proves you know what applies to you. The obligation-mapping column is where auditors test that the register is operational, not decorative.

Aperçu

Legal, Regulatory & Contractual Requirements Register

ISO/IEC 27001:2022 A.5.31 + ISO 9001 context. The register auditors use to verify the organization knows what it must comply with – ignorance is not a defense.

FieldValue
Document IDDOC-ISMS-014
OwnerCompliance / legal
ReviewOn regulatory change + annual

Register

IDRequirementTypeJurisdictionApplies to (process/data)Key obligationHow compliedEvidenceOwnerReview date
LR-01GDPRRegulationEUpersonal data processingconsent, DPO, 72h breach noticeDPIA + policiesDPO records@nameYYYY-MM
LR-02Data breach lawStatutecountry/statePII systemsnotify authority+subjectsIR planIR tests@nameYYYY-MM
LR-03Client contract NDAContractual–customer dataconfidentiality, audit rightsaccess controlscontract review@nameYYYY-MM
LR-04Industry standardRegulationsectorproductscertificationQA recordscerts@nameYYYY-MM
LR-05Employment records lawStatutecountryHR dataretention periodretention scheduleHRIS@nameYYYY-MM

Obligation mapping

RequirementRelevant controlsCompliance gap
LR-01A.5.34 privacy + DPIAnone / gap + plan

Change log

DateRegulatory changeImpact assessmentAction
new/updated lawwhat must changeplan

Sources monitored

  • Regulator websites, industry bodies, legal counsel alerts

Modèles associés