Skip to content

Compliance

What is Compliance?

The state of conforming to laws, regulations, standards, or internal policies. In information security, compliance is typically demonstrated through audits, certifications, and continuous monitoring.

Compliance

What the standards actually require on compliance

Requirements naming compliance across 6 standards, quoted from the control text.

Per PSTI: Defined Support Period (Minimum Security Update Period Declaration) + Statement of Compliance + Manufacturer Identification.

UKPSTIACT-3 · Defined Support Period and Statement of Compliance

FLA Accreditation is the multi-year assurance mechanism by which FLA Member Companies + Supplier Companies + Universities + Civil Society Organisations demonstrate sustained implementation of the Workplace Code of Conduct.

FLA-Accreditation · FLA Accreditation, Independent External Monitoring and Sustainable Compliance Initiative
ISO 37301:202111 controls

Requirement defined in ISO 37301:2021, clause 5.2 (Compliance policy). See licensed source for normative text. Implementation focus is to demonstrate conformity with the obligations of this clause through the artefacts listed in evidence_requirements.

iso-37301-2021::5.2 · Compliance policy
ISO 27701:201910 controls

Applicable legislation and contractual requirements must be identified, and the organization should identify the potential legal sanctions arising from missed obligations for the processing of personal data, including substantial fines from a supervisory autho...

iso-27701-2019::6.15.1 · Compliance with legal and contractual requirements
EU AI Act9 controls

Providers of high-risk AI systems shall ensure compliance with the Section 2 requirements (Arts 9-15), taking into account the intended purpose, the generally acknowledged state of the art and the integration of the AI system into other systems.

EUAI-Art.8 · Compliance with the requirements

Questions people ask about compliance

What is Compliance?
The state of conforming to laws, regulations, standards, or internal policies. In information security, compliance is typically demonstrated through audits, certifications, and continuous monitoring.
Why is Compliance important for compliance?
Compliance is a key concept in Compliance. Understanding compliance helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
What concepts are related to Compliance?
Key concepts related to Compliance include Audit, Certification. Understanding these interconnected concepts provides a more comprehensive view of Compliance requirements and helps organizations build holistic compliance programs.
Which compliance frameworks address Compliance?
Compliance appears in the requirement text of UK Product Security and Telecommunications Infrastructure Act (PSTI), Fair Labor Association (FLA) Workplace Code of Conduct, ISO 37301:2021, ISO 27701:2019, Jamaica Data Protection Act 2020. Across these standards we have identified 67 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Compliance?
Explore our compliance framework pages to see how compliance applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Compliance applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.