GOV-010 Legal, Regulatory and Contractual Compliance Inventory
Description
An inventory of applicable legal, statutory, regulatory and contractual information security obligations exists. Each entry names the obligation, the instrument or contract it arises from, the systems or processes it binds and the person accountable for meeting it. The inventory carries a review date within the defined interval and records the date each obligation was added, so an obligation that arose mid-cycle is visible without waiting for the next review. An obligation that reaches the organisation through a customer contract rather than through an instrument binding it directly is recorded on the same terms, naming the contract that transmits it, the instrument behind it and the authority supervising that customer.
Rationale
An organisation cannot comply with an obligation it has not identified. The commonest failure is usually not a missing control but a contract or a regulation nobody read. The inventory is the list the compliance programme is built from: GOV-011 tests against it, GOV-013 records the exceptions to it and DAT-011 and DAT-019 carry the data protection obligations it names. Where an obligation applies only to part of the estate, the entry says which part. An obligation in a signed schedule is invisible to a compliance programme assembled from a list of applicable laws, because no jurisdictional analysis returns it. An entry that names the transmitting contract, the instrument behind it and the supervising authority tells the owner of a duty who will eventually ask about it, and it puts a regulated customer's expectations inside the organisation's own audit scope rather than leaving them to surface when that customer's auditor arrives.
Applicability (9 profiles)
Art.16(a) is the entry the inventory gains: compliance with the whole of Chapter III Section 2, Arts. 9 to 15, as one obligation binding the organisation directly rather than reaching it through a customer contract, with its own application dates of 2 December 2027 for an Annex III system and 2 August 2028 for an Annex I system and 2 August 2030 for a legacy system used by a public authority (ADR-025). Art.22 is a second entry that bites only where the provider is established outside the Union and the inventory is where that determination is recorded as owned before AIG-041 acts on it.
EX-99 written in S8 wave B (migration 057). GOV-010 now records an obligation that reaches the organisation through a customer contract rather than through an instrument binding it directly, naming the contract that transmits it, the instrument behind it and the authority supervising that customer, so an Art. 30 duty living in a signed schedule is visible to the compliance programme. The inventory is also what a provider answers from when a customer reports the arrangement to its own supervisor under Art. 28(3).
Both instruments belong in the inventory, and so does the Member State whose transposing law and whose coordinated vulnerability disclosure policy apply, because Annex point 6.10.2(e) and Art. 12(1) of the Directive make the disclosure procedure depend on a national designation. Art. 4 of the Directive also records where DORA displaces Arts. 21 and 23 for a financial entity.
Framework Mappings (19)
| A&A-04 | Requirements Compliance | partial |
| GRC-07 | Information System Regulatory Mapping | full |
| A&A-04 | Requirements Compliance | partial |
| GRC-07 | Information System Regulatory Mapping | full |
| DORA-Art.28.3 | Register of information on contractual arrangements | informative |
| DORA-Art.28.5 | Information security standards of the ICT third-party service provider | informative |
| DORA-Art.30.3.b | Notice periods and reporting obligations of the provider | informative |
| DORA-Art.30.3.c | Business contingency plans and ICT security measures | informative |
| EU-AI-Art.16.1 | Provider Obligations — Compliance with Section 2 Requirements | informative |
| EU-AI-Art.22 | Provider Obligations — Authorised Representative for Non-EU Providers | informative |
| EU-AI-Art.54 | GPAI Model Obligations — Authorised Representative for Non-EU Providers | informative |
| HIPAA-164.316.a | Policies and Procedures | informative |
| 5.31 | Legal, statutory, regulatory and contractual requirements | full |
| NIS2-Art.22 | Union Level Coordinated Security Risk Assessments of Critical Supply Chains | informative |
| NIS2-CIR-10.4 | Disciplinary Process | informative |
| NIS2-CIR-Art.2.2 | Proportionality and Documented Reasoning for Non-Application | informative |
| PL-1 | Policy and Procedures | partial |
| GV-1.1-001 | Legal and Regulatory AI Requirements | GV-1.1-001 | informative |
| MAP 4.1 | AI Technology and Legal Risk Mapping | partial |
Evidence (2)
Compliance obligations inventory listing applicable legal, regulatory, and contractual information security requirements with assigned owners and last-reviewed dates. Obligations transmitted by a customer contract carry the contract, the instrument behind it and the authority supervising that customer.
Example: Compliance obligations register (Confluence / GRC platform / spreadsheet), with columns for: obligation name, source (e.g. GDPR Art.32, SOC 2 CC6), jurisdiction, owner (named individual or team), and last review date, reviewed within the last 12 months.
Test: Request the compliance obligations inventory. Verify: (1) each applicable regulation, law, and contractual requirement is listed, (2) each entry has a named owner, (3) the inventory has been reviewed within the last 12 months and the review date is recorded, (4) additions since the prior review reflect any new contracts or regulatory changes during that period. (5) obligations arriving through a customer contract appear in the inventory, each naming the contract that transmits it, the instrument behind it and the authority supervising that customer.
Annual compliance review report showing the obligations inventory was reviewed, updated, and presented to management.
Example: Compliance review report or management meeting minutes (Google Drive) documenting the annual review of the obligations inventory, noting additions, removals, and no-change confirmations with named reviewer and date.
Test: Request the most recent compliance review report or meeting minutes. Verify: (1) the inventory review took place within the last 12 months, (2) a named reviewer is recorded, (3) the report was communicated to or acknowledged by a named manager.
Questions (3)
Does your organisation maintain an inventory of applicable legal, regulatory and contractual information security obligations?
The inventory should cover obligations across all operating jurisdictions and be reviewed at least annually, with additions made when new contracts or regulations apply.
How frequently is the compliance obligations inventory reviewed and updated?
An annual review that produces a dated record with a named reviewer is the minimum. Updates should be visible whenever new obligations arise mid-year.
What does each entry in the obligations inventory record?
Options run from the most commonly recorded to the least. The date an obligation was added is what makes an obligation that arose mid-cycle visible without waiting for the next review. The last item is the one an inventory built from a jurisdictional analysis never returns, because the duty exists in a signed schedule rather than in a law that binds the organisation directly.