Compliance obligation

A requirement an organization must meet, or has chosen to meet, arising from law, regulation, a regulator's rule, a contract, a code or a voluntary commitment.

A compliance obligation is a requirement an organization has to meet, or has chosen to meet: a duty arising from a statute, a regulation, a regulator's rule, a license condition, a court order, a contract, an industry code or a voluntary commitment. ISO 37301:2021, the international standard for compliance management systems that replaced the ISO 19600:2014 guidelines, treats compliance obligations as both the requirements an organization must comply with and those it voluntarily chooses to comply with.

A bank's obligations extend beyond its prudential and conduct rules to the undertakings it gave a supervisor, the industry codes it signed and the public commitments it made. Once adopted, a voluntary commitment is managed like any other obligation, because regulators, auditors and counterparties can hold the organization to it.

Obligations are more granular than laws. A single regulation contains many of them, each with its own trigger, addressee, deadline and evidence. In the GDPR, for example, Article 30 is one obligation (keep a record of processing activities with prescribed content) and Article 33 is another (notify the supervisory authority of a personal data breach, where feasible within 72 hours of becoming aware of it). Treating each as a separate item is what makes compliance testable.

ISO 37301 clause 4.5 asks organizations to identify their compliance obligations systematically, assess their impact on operations, and keep that identification current as obligations change. The usual tools are an obligations register, where each obligation becomes a row with an owner and controls, and regulatory mapping, which links each obligation to the policies, processes and controls that discharge it. When a rule changes, regulatory change management decides which obligations are created, amended or retired.

For a worked example of breaking one regulation into testable obligations, see the DORA rows in our obligations register template.

This entry is general information, not legal advice.

Sources

  1. ISO 37301:2021 Compliance management systems accessed 30 Sep 2026
  2. Regulation (EU) 2016/679 (GDPR), EUR-Lex accessed 30 Sep 2026

Know which changes apply to your business.

RegWatch reads the regulators you choose and explains every change it surfaces.

Book a demo