Why it matters
This is where GDPR, sector regulation, and customer contract security clauses all get tracked in one place.
How a self-led small team implements it
A single register listing applicable laws/contracts and what each requires is enough; you don't need separate legal review per clause.
What auditors expect to see
Legal/regulatory requirements register.
Track A.5.31 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.
Start your ISMS