In this guide you will learn how to implement ISO 27001 Annex A 5.31 Legal Requirements and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.
ISO 27001 Annex 5.31 is an ISO 27001 control that wants you understand external requirements on your information security and implement them.
Table of contents
- Purpose & Definition
- FREE ISO 27001 Annex A 5.31 Training Video
- Implementation Guide
- How to implement ISO 27001 Annex 5.31
- 1. Identify Applicable Jurisdictions and Legal Frameworks
- 2. Formalise the Legal and Regulatory Requirements Register
- 3. Map and Document Intellectual Property Rights (IPR)
- 4. Verify Privacy and Data Protection Alignment
- 5. Audit Contractual Security Obligations
- 6. Provision Cryptographic Controls and Export Compliance
- 7. Synchronise the Asset Register with Compliance Metadata
- 8. Establish IAM Roles and MFA for Regulated Data
- 9. Establish a Recurring Legislative Review Cycle
- 10. Validate Compliance through Internal Audit Evidence
- ISO 27001 Templates
- ISO 27001 Annex A 5.31 FAQ
- ISO 27001 Controls and Attribute values
- Stuart Barker
Purpose & Definition
The purpose of ISO 27001 Annex A 5.31 Legal, statutory, regulatory and contractual requirements is to ensure you comply with legal, statutory, regulatory and contractual requirements related to information security.
An organisations information security responsibilities are informed by laws, regulations and contractual requirements.
Organisations should have a clear understanding of their obligations and be prepared to include those in their information security practices.
The ISO 27001 standard defines ISO 27001 Annex A 5.31 as:
Legal, statutory, regulatory and contractual requirements relevant to information security and the organisations approach to meet these requirements should be identified, documented and kept up to date.
ISO/IEC 27001:2022 Annex A 5.31 Legal, Statutory, Regulatory and Contractual Requirements
White Label
ISO 27001 for Consultants
Custom-brandable ISO 27001 documentation for consultants. Easily rebrand, reduce project time, and deliver professional, high-value security systems. Focus on delivery, not drafting.
FREE ISO 27001 Annex A 5.31 Training Video
In this free training video you will learn How to implement ISO 27001 Legal Statutory Regulatory Contractual Requirements (Annex A 5.31) & Pass.
Implementation Guide
Annex A 5.31 requirements are to understand and record the requirements on your information security from any legal, statutory, regulatory or contractual requirements.
There are 5 general guidance points to consider.
Organisation’s should take into consideration external requirements for their legal, statutory, regulatory and contractual requirements when:
- Developing your information security policies and processes
- Developing or changing your information security controls
- Classifying your data and assets
- Doing risk assessments and risk management
- Performing supplier management and supplier contracts
ISO 27001 Legal Register Template
Having an ISO 27001 template for control 5.31 can help fast track your implementation. You can read a beginners guide to the ISO 27001 Legal Register and you can download a copy of the ISO 27001 Legal Register that comes pre populated with common laws. As always, you should seek legal advice.

Legal and Regulatory Guidance
You should record your legal and regulatory requirements in an ISO 27001 Legal Register.
You are going to identify all of the laws and regulations that apply to you and write them down in order to be aware of the requirements and how they apply to you.
It is best practice to get legal advice to help you comprise this list.
It can be difficult as you have to consider the compliance requirements of all the countries in which you operate. This includes the transfer of information across borders where those countries laws could apply to you.
Cryptographic Guidance
It is recommended to get legal advice on all aspects of this control, including on the cryptography. It can be quite specialised in its requirements.
The legal advice will look at any restrictions on the import and export of cryptographic technologies and usage.
A significant one to note is the requirements of in country requirements to access encrypted information.
All in all, get some legal advice.
Contract Guidance
Which contracts could have requirements that impact your information security implementation? Well there are many but they would include
- contracts with your suppliers
- contracts with your clients
- contracts with your insurers
- contracts with your investors / funding
Guidance relating to supplier contracts is covered in ISO 27001 Annex A 5.20
How to implement ISO 27001 Annex 5.31
Implementing ISO 27001 Annex A 5.31 is more than a legal hurdle: it is about building a defensible security posture that satisfies regulators, clients, and partners. As an ISO 27001 Lead Auditor, I expect to see a robust system for identifying and maintaining compliance. Follow these ten technical steps to formalise your legal, statutory, regulatory, and contractual obligations and ensure you pass your certification audit.
1. Identify Applicable Jurisdictions and Legal Frameworks
Identify all geographical and industry specific jurisdictions where the organisation operates. Result: Establishes a comprehensive list of legal boundaries to ensure no regional mandate is overlooked in the ISMS scope.
- Review business locations to identify local data protection and employment laws.
- Consult legal counsel to determine industry specific regulations such as HIPAA, PCI-DSS, or DORA.
- Document the process for determining legal applicability for future audit evidence.
2. Formalise the Legal and Regulatory Requirements Register
Formalise a central Legal Register that lists every identified statutory and regulatory requirement. Result: Provides the Incident Response Team and Auditors with a single source of truth for compliance mapping.
- Include the source of the law, a brief description, and the specific ISO control it relates to.
- Assign a “Compliance Owner” for every entry to ensure accountability.
- Link the register to your Risk Management Framework to track legal risks.
3. Map and Document Intellectual Property Rights (IPR)
Map all intellectual property, including software licences and proprietary source code. Result: Protects the organisation from litigation regarding copyright infringement and unauthorised use of proprietary assets.
- Perform an audit of software install counts versus purchased licence entitlements.
- Update the Asset Register to include unique data sets and trade secrets.
- Include IPR protection clauses in employee and contractor Rules of Engagement (ROE) documents.
4. Verify Privacy and Data Protection Alignment
Verify that your technical and organisational controls align with GDPR and local privacy statutes. Result: Ensures personal data is processed lawfully and reduces the risk of significant regulatory fines.
- Conduct Data Protection Impact Assessments (DPIAs) for high risk processing activities.
- Confirm that Privacy Notices are transparent, up to date, and easily accessible.
- Verify that specific IAM roles are restricted based on data residency requirements.
5. Audit Contractual Security Obligations
Audit all client and vendor agreements to extract specific information security commitments. Result: Guarantees the organisation is technically capable of meeting its promised security levels to external parties.
- Create a “Contractual Matrix” that maps client security requirements to technical controls.
- Ensure vendor contracts include the “Right to Audit” and mandatory breach notification timelines.
- Communicate specific contractual uptime or encryption requirements to the technical team.
6. Provision Cryptographic Controls and Export Compliance
Provision cryptographic systems that align with national and international export laws. Result: Prevents legal breaches regarding the transfer of restricted encryption technologies across borders.
- Identify any jurisdictions where the import of high strength encryption is restricted.
- Verify that your Cryptographic Policy accounts for statutory requirements for lawful intercept.
- Maintain technical documentation for all cryptographic modules used in the infrastructure.
7. Synchronise the Asset Register with Compliance Metadata
Synchronise the Asset Register by tagging specific assets with their governing legal requirements. Result: Enables granular reporting and ensures that technical controls are applied specifically where mandated by law.
- Label assets that process PII, financial data, or sensitive government information.
- Map technical owners to the specific compliance requirements of the assets they manage.
- Ensure the register is updated whenever a new legislative requirement is identified.
8. Establish IAM Roles and MFA for Regulated Data
Establish strict Identity and Access Management (IAM) roles and Multi-Factor Authentication (MFA) for systems containing regulated data. Result: Provides the forensic evidence of restricted access required to satisfy regulatory scrutiny.
- Implement mandatory MFA for all accounts with access to legally sensitive data sets.
- Perform quarterly access reviews for users with “Privileged Access” to regulated systems.
- Automate the revocation of access for “Leavers” to prevent residual compliance risks.
9. Establish a Recurring Legislative Review Cycle
Establish a formal process for monitoring and reviewing changes in the legal and regulatory landscape. Result: Prevents “compliance drift” by ensuring the ISMS evolves in tandem with emerging global laws.
- Schedule bi-annual reviews of the Legal Register with key stakeholders.
- Subscribe to regulatory update services or industry bodies for early warning of changes.
- Document any changes to technical controls that were triggered by legislative updates.
10. Validate Compliance through Internal Audit Evidence
Validate the effectiveness of implementation through a rigorous internal audit programme. Result: Confirms that the organisation is fully prepared for the external Stage 2 certification audit.
- Test a sample of legal requirements to verify that documented controls are active.
- Ensure any compliance gaps are logged in the Corrective Action Log and remediated.
- Review the Statement of Applicability (SoA) to confirm it correctly references Annex A 5.31.
Check Your Work?
You built it yourself. Maybe with AI. But will it pass the audit?
Don’t gamble – let an ISO 27001 Lead Auditor check your work.

ISO 27001 Templates

ISO 27001 Annex A 5.31 FAQ
Yes, while the standard does not explicitly name it a “Legal Register,” maintaining a documented list of all relevant legal and contractual requirements is mandatory to satisfy the requirements of Control 5.31. This register serves as primary evidence for Stage 1 and Stage 2 certification audits, categorising obligations by jurisdiction and business relevance to demonstrate a proactive compliance posture.
It serves as primary evidence for Stage 1 and Stage 2 certification audits.
It categorises obligations by jurisdiction and business relevance.
It links specific external laws to internal security controls.
It demonstrates a proactive approach to compliance monitoring.
The legal register should be reviewed at least annually or whenever significant changes occur in the business environment, technology stack, or geographic operations. Reviews are specifically triggered when entering new markets, following major legislative changes like the introduction of NIS2 or the EU AI Act, or when contractual changes with major clients occur.
Reviews are triggered when entering new markets (e.g., expanding into the US or EU).
Updates are required following major legislative changes like the introduction of NIS2 or AI Acts.
It should be a standing item in the annual ISMS Management Review Meeting.
Contractual changes with major clients or suppliers may necessitate an immediate update.
Clause 4.2 is a high-level governance requirement for understanding the needs of interested parties, whereas Annex A 5.31 is the operational control used to document and manage the specific legal requirements derived from those parties. While Clause 4.2 identifies “who” cares about your security, Annex A 5.31 documents “what” specific laws and contracts those parties require you to follow.
Clause 4.2 identifies “who” the interested parties are.
Annex A 5.31 documents “what” specific laws and contracts those parties require you to follow.
Clause 4.2 is part of the “Context of the Organisation,” while 5.31 is an Annex A security control.
Requirements under 5.31 encompass all applicable data protection laws, industry-specific regulations, and private service level agreements (SLAs) with clients. This includes global privacy statutes like the UK GDPR or EU GDPR, industry mandates like PCI DSS, cybersecurity legislation such as NIS2, and technical security annexes found in client contracts.
Data Privacy laws such as UK GDPR, EU GDPR, or CCPA.
Industry regulations like PCI DSS for payments or SOC2 requirements.
Cybersecurity legislation such as the NIS2 Directive.
Specific security annexes and NDAs found in client contracts.
The EU AI Act represents a new statutory requirement that organisations using high-risk AI must identify under Annex A 5.31. In 2026, organisations must document their adherence to Article 17 regarding Quality Management and Article 62 concerning Serious Incident Reporting to prove their ISMS is legally robust and avoid potential fines of up to 7% of global turnover.
Failing an Annex A 5.31 audit leads to certification failure and significant financial exposure, as regulatory fines for non-compliance exceeded €2.4 million on average in 2025. Beyond the loss of the ISO 27001 certificate, failing to document and manage contractual obligations can trigger 100% liability for data breach costs during client-led litigation.
ISO 27001 Controls and Attribute values
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|---|---|---|---|---|
| Preventive | Availability | Identify | Legal and compliance | Protection |
| Confidentiality | Governance and EcoSystem | |||
| Integrity |
Stuart Barker
I am the ISO 27001 Ninja.
I help tech companies, start-ups, and small businesses implement information security management systems without the corporate bloat or massive consultant fees.
If you want to pass your audit the first time, book a call.
