Skip to content

Regulatory Change

What is Regulatory Change?

A modification to existing regulations or introduction of new regulations that may affect an organization's compliance obligations.

Compliance and Regulatory

Each of these is named in at least one of the same controls as regulatory change. The number is how many controls name both.

What the standards actually require on regulatory change

Requirements naming regulatory change across 6 standards, quoted from the control text.

Establish cybersecurity governance and policy structures appropriate to retail industry characteristics per the NRF Cybersecurity and Data Privacy Framework guidance and supporting NIST CSF alignment.

NRFCS-1 · Retail Cybersecurity Governance, Policy, and Regulatory Change Management
C5 (Germany)1 control

Have subject matter experts review the security policies and instructions for adequacy at least once a year, weighing organisational and technical changes in how the cloud service is delivered and legal or regulatory change, and approve revised versions before...

C5-SP-02 · Review and Approval of Policies and Instructions
ISMAP (Japan)1 control

ISMAP Assessment positions ISMAP within the comprehensive Japanese and international cloud security regulatory landscape. (1) External Assessment by ISMAP-Approved Auditor: CSP must undergo annual third-party assessment by ISMAP-approved audit organisation inc...

ISMAP-Assessment-ExternalAuditor-AnnualReview-CustomerTransparency-Coord-FedRAMP-IRAP-GCloud-PIPA-ISO27017 · ISMAP Assessment - External ISMAP-Approved Auditor + Annual Review + Customer Information and Transparency + Coordination FedRAMP/UK G-Cloud/Australia IRAP/Singapore MTCS + ISO 27017 + PIPA + Japan Digital Agency

Defines events that trigger information updates, such as maintenance activities, renovations, and regulatory changes.

ISO-19650-3-5.3 · Trigger events for information exchange

Monitor privacy risks continuously through KRIs, incident data, regulatory changes, and processing changes.

ISO27557-9.1 · Privacy Risk Monitoring

Address Mandatory Criterion 5 of Modern Slavery Statement under Section 16(1)(e) - describe how reporting entity assesses effectiveness of actions to assess and address modern slavery risks.

AU-MSA-Mandatory-Criterion-5-Effectiveness-Section-16-1e-Assurance-KPIs-Continuous-Improvement · Australia MSA Mandatory Criterion 5 + Effectiveness + Section 16(1)(e) + Independent Assurance + KPIs + Continuous Improvement

Questions people ask about regulatory change

What is Regulatory Change?
A modification to existing regulations or introduction of new regulations that may affect an organization's compliance obligations.
Why is Regulatory Change important for compliance?
Regulatory Change is a key concept in Compliance and Regulatory. Understanding regulatory change helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Regulatory Change?
Regulatory Change appears in the requirement text of NRF Cybersecurity and Data Privacy Framework (National Retail Federation), C5 (Germany), ISMAP (Japan), ISO 19650 - Organisation and Digitisation of Information about Buildings and Civil Engineering Works (BIM), ISO/IEC 27557:2022 - Organisational Privacy Risk Management. Across these standards we have identified 6 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Regulatory Change?
Explore our compliance framework pages to see how regulatory change applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Regulatory Change applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.