unified
UC-AUDIT-24 — Manage compliance with external legal and regulatory requirements
The organization identifies applicable external legal, regulatory, and contractual requirements - including intellectual property rights and software licensing obligations - and maintains them in a compliance register with assigned owners. Compliance with these requirements is evaluated on a defined cadence, confirmed through documented reviews, and non-compliance is remediated with status reported to management. The register and evaluation results are retained as evidence.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Compliance, Audit & Assurance
- type
- detective
- category
- administrative
Details
- unified_id
- UC-AUDIT-24
- title
- Manage compliance with external legal and regulatory requirements
- statement
- The organization identifies applicable external legal, regulatory, and contractual requirements - including intellectual property rights and software licensing obligations - and maintains them in a compliance register with assigned owners. Compliance with these requirements is evaluated on a defined cadence, confirmed through documented reviews, and non-compliance is remediated with status reported to management. The register and evaluation results are retained as evidence.
- domain
- Compliance, Audit & Assurance
- control_type
- detective
- control_category
- administrative
- members
- framework
- cobit-2019
- control_id
- MEA03
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.5.32
- coverage
- partial
- delta
- operational IPR safeguards - license/asset registers with usage-vs-entitlement enforcement, proof-of-license retention, and acquisition from authorized sources - beyond registering and periodically evaluating the obligation
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- EU AI Act Obligation Impact Analysis oversees UC-AUDIT-24 — Manage compliance with external legal and regulatory requirements
- UC-AUDIT-24 — Manage compliance with external legal and regulatory requirements maps_to MEA03 — Managed Compliance With External Requirements
- framework
- cobit-2019
- control_id
- MEA03
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2019
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Regulatory Exam & External Audit Management oversees UC-AUDIT-24 — Manage compliance with external legal and regulatory requirements
- UC-AUDIT-24 — Manage compliance with external legal and regulatory requirements mitigates Use of unlicensed, counterfeit or pirated software
- strength
- primary
- rationale
- Maintaining a register of software-licensing/IP obligations and evaluating compliance (ISO A.5.32) directly reduces use of unlicensed or pirated software.
- UC-AUDIT-24 — Manage compliance with external legal and regulatory requirements mitigates Adverse regulatory or policy change
- strength
- related
- rationale
- Maintaining and periodically re-evaluating the requirements register helps detect and adapt to changes in law and regulation.
- UC-AUDIT-24 — Manage compliance with external legal and regulatory requirements maps_to A.5.32 — Intellectual property rights
- framework
- iso-27001
- control_id
- A.5.32
- coverage
- partial
- delta
- operational IPR safeguards - license/asset registers with usage-vs-entitlement enforcement, proof-of-license retention, and acquisition from authorized sources - beyond registering and periodically evaluating the obligation
- relationship
- intersects_with
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-AUDIT-24 — Manage compliance with external legal and regulatory requirements
- UC-AUDIT-24 — Manage compliance with external legal and regulatory requirements mitigates Intellectual property loss or infringement
- strength
- related
- rationale
- Identifying and tracking intellectual-property-rights obligations and confirming compliance reduces infringement of third-party IP.
- Regulatory Compliance Attestation Cycle oversees UC-AUDIT-24 — Manage compliance with external legal and regulatory requirements
- UC-AUDIT-24 — Manage compliance with external legal and regulatory requirements mitigates Sector regulatory non-compliance (financial, healthcare, trade)
- strength
- primary
- rationale
- A register of applicable legal/regulatory requirements with owners, evaluated on a cadence and remediated, is the operative defense against sector non-compliance.
- UC-AUDIT-24 — Manage compliance with external legal and regulatory requirements mitigates Environmental regulatory non-compliance
- strength
- related
- rationale
- Environmental permit and reporting obligations tracked in the register and evaluated for compliance reduce environmental non-compliance.
- Legal & Regulatory Compliance Register Evaluation operates UC-AUDIT-24 — Manage compliance with external legal and regulatory requirements
- Regulatory Impact Analysis & Obligation Mapping oversees UC-AUDIT-24 — Manage compliance with external legal and regulatory requirements
- UC-AUDIT-24 — Manage compliance with external legal and regulatory requirements mitigates Litigation, investigation and enforcement exposure
- strength
- related
- rationale
- Documented compliance evaluation and remediation of non-compliance reduces exposure to enforcement actions and litigation.