Guidance: building on what it learned under 4.2.4, the organization should set up, run and keep up a process for identifying, and keeping access to, the compliance obligations that attach to the environmental aspects of what it does and supplies, anticipate new or changed obligations so it can prepare and maintain conformity, and consider what new developments, and any change in what it does or supplies, mean for its compliance status. Legal requirements can be identified through regulators, industry associations, commercial databases and professional advisers; other obligations adopted from interested parties should be related to the organization's aspects. Information on obligations should be communicated to persons under the organization's control, including contractors and suppliers, whose actions affect fulfilment. A register or list of obligations should be maintained and periodically reviewed, recording the origin of each obligation and the interested party, an overview of it, and how it relates to the organization's aspects or interested party requirements. Compliance obligations run through the whole system: policy commitment, objectives, planned actions, operational controls, awareness, competence, communication, evaluation of compliance, corrective action, audit and management review.
This control maps to 7 controls across 6 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 7 it maps to, and the evidence behind each claim, over MCP and REST.