Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Business Manager

previous version on gdrive

A.5.31 Legal, Statutory, Regulatory and Contractual Requirements

Control Objective

Legal, statutory, regulatory and contractual requirements relevant to information security and the organisation’s approach to meet these requirements shall be identified, documented and kept up to date.

Policy Statement

anDREa systematically identifies, documents, and maintains compliance with all applicable legal, statutory, regulatory, and contractual obligations. We proactively monitor legislative shifts (such as GDPR and NIS 2 mandates) and maintain total transparency regarding customer commitments via publicly accessible service agreements.


Compliance Monitoring and Customer Obligations

  • Regulatory Tracking: A centralized inventory of applicable laws and compliance controls is maintained within the Legal - Controls section. The Management Team reviews this inventory periodically under the Periodic Controls MT and Periodic Security Controls schedules to incorporate new legislative requirements.
  • Customer Agreements: anDREa adheres to standardized customer contracts and a unified Service Level Agreement. The Business Manager holds primary accountability for ensuring all active customer agreements and delivery parameters are met.
  • SLA Transparency: The SLA Performance is publicly hosted on the anDREa Knowledge Base. Platform availability metrics are verified and updated at least monthly.
  • Non-Compliance Escalation: In the event that an overlooked or unaddressed legal or contractual obligation is discovered, it is treated as an information security event. It must be reported and tracked immediately in accordance with A.05.26 - Response to information security incidents.