GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

GOV-010 Legal, Regulatory and Contractual Compliance Inventory

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

An inventory of applicable legal, statutory, regulatory and contractual information security obligations exists. Each entry names the obligation, the instrument or contract it arises from, the systems or processes it binds and the person accountable for meeting it. The inventory carries a review date within the defined interval and records the date each obligation was added, so an obligation that arose mid-cycle is visible without waiting for the next review. An obligation that reaches the organisation through a customer contract rather than through an instrument binding it directly is recorded on the same terms, naming the contract that transmits it, the instrument behind it and the authority supervising that customer.

Rationale

An organisation cannot comply with an obligation it has not identified. The commonest failure is usually not a missing control but a contract or a regulation nobody read. The inventory is the list the compliance programme is built from: GOV-011 tests against it, GOV-013 records the exceptions to it and DAT-011 and DAT-019 carry the data protection obligations it names. Where an obligation applies only to part of the estate, the entry says which part. An obligation in a signed schedule is invisible to a compliance programme assembled from a list of applicable laws, because no jurisdictional analysis returns it. An entry that names the transmitting contract, the instrument behind it and the supervising authority tells the owner of a duty who will eventually ask about it, and it puts a regulated customer's expectations inside the organisation's own audit scope rather than leaving them to surface when that customer's auditor arrives.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredrisk class duty

Art.16(a) is the entry the inventory gains: compliance with the whole of Chapter III Section 2, Arts. 9 to 15, as one obligation binding the organisation directly rather than reaching it through a customer contract, with its own application dates of 2 December 2027 for an Annex III system and 2 August 2028 for an Annex I system and 2 August 2030 for a legacy system used by a public authority (ADR-025). Art.22 is a second entry that bites only where the provider is established outside the Union and the inventory is where that determination is recorded as owned before AIG-041 acts on it.

Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredrole duty

EX-99 written in S8 wave B (migration 057). GOV-010 now records an obligation that reaches the organisation through a customer contract rather than through an instrument binding it directly, naming the contract that transmits it, the instrument behind it and the authority supervising that customer, so an Art. 30 duty living in a signed schedule is visible to the compliance programme. The inventory is also what a provider answers from when a customer reports the arrangement to its own supervisor under Art. 28(3).

NIS2 Cloud Provider (EU)stablerequiredrole duty

Both instruments belong in the inventory, and so does the Member State whose transposing law and whose coordinated vulnerability disclosure policy apply, because Annex point 6.10.2(e) and Art. 12(1) of the Directive make the disclosure procedure depend on a national designation. Art. 4 of the Directive also records where DORA displaces Arts. 21 and 23 for a financial entity.

Framework Mappings (19)

A&A-04Requirements Compliancepartial
GRC-07Information System Regulatory Mappingfull
A&A-04Requirements Compliancepartial
GRC-07Information System Regulatory Mappingfull
DORA-Art.28.3Register of information on contractual arrangementsinformative
DORA-Art.28.5Information security standards of the ICT third-party service providerinformative
DORA-Art.30.3.bNotice periods and reporting obligations of the providerinformative
DORA-Art.30.3.cBusiness contingency plans and ICT security measuresinformative
EU-AI-Art.16.1Provider Obligations — Compliance with Section 2 Requirementsinformative
EU-AI-Art.22Provider Obligations — Authorised Representative for Non-EU Providersinformative
EU-AI-Art.54GPAI Model Obligations — Authorised Representative for Non-EU Providersinformative
HIPAA-164.316.aPolicies and Proceduresinformative
5.31Legal, statutory, regulatory and contractual requirementsfull
NIS2-Art.22Union Level Coordinated Security Risk Assessments of Critical Supply Chainsinformative
NIS2-CIR-10.4Disciplinary Processinformative
NIS2-CIR-Art.2.2Proportionality and Documented Reasoning for Non-Applicationinformative
PL-1Policy and Procedurespartial
GV-1.1-001Legal and Regulatory AI Requirements | GV-1.1-001informative
MAP 4.1AI Technology and Legal Risk Mappingpartial

Evidence (2)

recorddocumentmanual

Compliance obligations inventory listing applicable legal, regulatory, and contractual information security requirements with assigned owners and last-reviewed dates. Obligations transmitted by a customer contract carry the contract, the instrument behind it and the authority supervising that customer.

Example: Compliance obligations register (Confluence / GRC platform / spreadsheet), with columns for: obligation name, source (e.g. GDPR Art.32, SOC 2 CC6), jurisdiction, owner (named individual or team), and last review date, reviewed within the last 12 months.

Test: Request the compliance obligations inventory. Verify: (1) each applicable regulation, law, and contractual requirement is listed, (2) each entry has a named owner, (3) the inventory has been reviewed within the last 12 months and the review date is recorded, (4) additions since the prior review reflect any new contracts or regulatory changes during that period. (5) obligations arriving through a customer contract appear in the inventory, each naming the contract that transmits it, the instrument behind it and the authority supervising that customer.

reportdocumentmanual

Annual compliance review report showing the obligations inventory was reviewed, updated, and presented to management.

Example: Compliance review report or management meeting minutes (Google Drive) documenting the annual review of the obligations inventory, noting additions, removals, and no-change confirmations with named reviewer and date.

Test: Request the most recent compliance review report or meeting minutes. Verify: (1) the inventory review took place within the last 12 months, (2) a named reviewer is recorded, (3) the report was communicated to or acknowledged by a named manager.

Questions (3)

boolean

Does your organisation maintain an inventory of applicable legal, regulatory and contractual information security obligations?

The inventory should cover obligations across all operating jurisdictions and be reviewed at least annually, with additions made when new contracts or regulations apply.

select

How frequently is the compliance obligations inventory reviewed and updated?

At least annually, with ad hoc updates on new contracts or regulatory changesAnnually on a fixed schedule onlyOnly when triggered by an audit or regulatory inquiryNo formal review cadence is defined

An annual review that produces a dated record with a named reviewer is the minimum. Updates should be visible whenever new obligations arise mid-year.

multi

What does each entry in the obligations inventory record?

The obligation itselfThe instrument or contract it arises fromThe systems or processes it bindsThe person accountable for meeting itThe date the obligation was addedWhere the obligation arrives through a customer contract, that contract, the instrument behind it and the authority supervising the customerNone of the above

Options run from the most commonly recorded to the least. The date an obligation was added is what makes an obligation that arose mid-cycle visible without waiting for the next review. The last item is the one an inventory built from a jurisdictional analysis never returns, because the duty exists in a signed schedule rather than in a law that binds the organisation directly.