Skip to content
Reference

Regulatory Inventory (Compliance Obligations Inventory), Defined

The short version

A regulatory inventory, also called a compliance obligations inventory, is a maintained list of the laws, regulations, supervisory guidance, standards and binding commitments that apply to an organization, with each requirement mapped to the business lines it affects, an accountable owner, and the policies and controls that address it. It is the reference point for the rest of a compliance program: the risk assessment, testing plans, training and regulatory change management all draw on it. ISO 37301:2021 requires organizations to identify and document their compliance obligations (clause 4.5), and U.S. bank supervisors assess whether a compliance management system addresses all applicable laws and regulations.

A regulatory inventory is a documented, maintained list of the legal and regulatory requirements that apply to an organization, together with the analysis that shows why each applies and the mappings that show where each is addressed. It is also called a compliance obligations inventory, a regulatory requirements inventory or a law and regulation inventory. Each entry identifies a requirement by citation, records the business lines, products or processes it affects, names an accountable owner, and links to the policies, procedures and controls through which the organization meets it.

The inventory answers a basic question that every other part of a compliance program assumes has been answered: which rules apply here. A risk assessment scores the risk of failing to meet requirements; a testing plan tests whether controls meet them; training teaches staff about them. None of these can be complete unless the list of requirements is complete.

Where the expectation comes from

No U.S. statute requires a document called a regulatory inventory. The expectation arises from standards that require an organization to know, and to be able to show that it knows, the requirements it is subject to.

In practice, an examiner or auditor who asks how an organization knows its policies cover every applicable requirement is asking for the inventory, whether or not the organization calls it that.

What an entry contains

The level of detail varies by organization. A common structure records the following fields for each requirement.

FieldContent
CitationThe source and pinpoint, for example a section of the Code of Federal Regulations, a state statute, a guidance document or a standard's clause, with its effective date.
Requirement summaryA plain-language statement of what the requirement obliges the organization to do or not do.
ApplicabilityWhether it applies, to which legal entities, jurisdictions, products and business lines, and the reasoning, including thresholds or exemptions relied on.
OwnerThe person or function accountable for meeting the requirement, usually in the first line, with a second-line compliance contact.
Policies and proceduresLinks to the documents that implement the requirement.
ControlsLinks to the controls in the control library that address it, and to the tests of those controls.
Risk ratingThe compliance risk associated with the requirement, drawn from or feeding the compliance risk assessment.
Review historyThe date of the last review, the reviewer and any open changes.

Granularity is a design choice. Some inventories record each regulation as one entry; others break a regulation into its individual requirements, which makes the mapping to controls more precise but the inventory larger to maintain.

Applicability analysis

Building an inventory starts with a scan of the requirements that could apply, drawn from the organization's charter or licences, the jurisdictions in which it operates or has customers, its products and services, its size, and its contracts. Each candidate requirement then receives an applicability decision. Many rules turn on thresholds or definitions: an asset size, a transaction volume, whether a product is offered to consumers, whether the organization is a covered entity under a particular statute. The applicability record states the facts relied on, so that the decision can be revisited when those facts change, for example when the organization crosses a threshold or launches a new product.

Decisions that a requirement does not apply are recorded as well. They show that the requirement was considered, and they identify what change in the business would make it applicable.

Mapping to policies and controls

The mappings are what distinguish an inventory from a list of laws. A requirement mapped to a policy, a procedure and a tested control can be shown to be met. A requirement with no mapping is a visible gap. Mappings run in both directions: from a requirement to the controls that address it, and from a control to every requirement it supports, which shows the consequence of changing or removing that control.

Maintenance through regulatory change management

An inventory is accurate only as of its last update. It is kept current through regulatory change management, which identifies new and amended requirements, decides their applicability, and updates the inventory and its mappings. Internal changes also trigger updates: new products, new jurisdictions, acquisitions, and changes in size that cross regulatory thresholds. Many organizations also perform a periodic full review of the inventory, commonly annually, to catch changes that the event-driven process missed.

Who maintains it and where it is kept

The compliance function usually owns the inventory, with legal counsel for interpretation and business-line owners confirming how requirements are met in practice. Small organizations often keep it in a spreadsheet. Larger organizations commonly keep it in GRC software, where each requirement can be linked to policies, controls, risks, test results and issues, and where changes can be tracked with a history.

Common weaknesses

Primary sources

Common questions

What is a regulatory inventory?
A regulatory inventory, or compliance obligations inventory, is a maintained list of the laws, regulations, guidance, standards and binding commitments that apply to an organization, with each requirement mapped to the business lines it affects, an accountable owner, and the policies and controls that address it.
Is a regulatory inventory required?
No U.S. statute requires one by name. ISO 37301:2021 clause 4.5 requires organizations to identify and document their compliance obligations, and U.S. bank supervisors, including the OCC and the CFPB, assess whether a compliance management system addresses all applicable laws and regulations, which in practice requires such a list.
What fields does a regulatory inventory entry contain?
Typically the citation and effective date, a plain-language summary, the applicability decision and its reasoning, the accountable owner, links to implementing policies and procedures, links to controls and their tests, a risk rating, and the review history.
How is a regulatory inventory kept current?
Through regulatory change management, which identifies new and amended requirements and updates the inventory, and through updates triggered by internal changes such as new products, new jurisdictions or crossing a size threshold. Many organizations also review the full inventory periodically.
How does a regulatory inventory relate to GRC software?
GRC software is a common place to keep the inventory, because it can link each requirement to policies, controls, risks, test results and issues. The inventory can also be kept in a spreadsheet; its accuracy and mappings matter more than the tool.
About this library

This reference library is maintained by Rupture Labs. We perform BSA/AML independent testing and automated control testing against every record, with each requirement cited to its rule. Talk to a practitioner.