Statutory Requirement
A statutory requirement is a legal duty that a law passed by a legislature places on a person or organization, obliging them to do or refrain from doing something. Examples often cited include obligations under statutes such as the Sarbanes-Oxley Act (SOX), HIPAA, and GLBA. Because these duties are set out in law, meeting them is mandatory rather than optional, though the specific obligations and their applicability depend on jurisdiction and circumstances.
A statutory requirement is a legal obligation imposed directly by a statute (an act of a legislative body) upon an individual or organization, requiring adherence to defined mandatory duties. Within a GRC context, statutory requirements typically fall under the compliance pillar, since they concern conformance with binding external law, and they are commonly distinguished from regulatory requirements, which derive from rules issued by regulators or agencies under delegated authority rather than from the primary statute itself. Statutory requirements may prescribe specific obligations such as reporting, record-keeping, safety inspections, or the appointment of responsible individuals, and their scope, wording, and applicability vary by jurisdiction, sector, and the entity concerned; determining precise obligations under any given statute is a matter of legal interpretation that generally warrants professional advice.
Why it matters
Statutory requirements sit at the foundation of an organization's compliance obligations because they derive directly from law passed by a legislature, which makes meeting them mandatory rather than a matter of discretion. Unlike voluntary standards or leading practices, a statutory duty is binding: failing to satisfy it can expose an organization to legal consequences, enforcement action, and reputational harm. For this reason, identifying which statutes apply to a given entity, and what specific obligations they impose, is typically one of the first steps in scoping a compliance program.
Statutory requirements also anchor accountability within an organization. Some statutes prescribe specific obligations such as reporting, record-keeping, safety inspections, or the appointment of responsible individuals, which means the law can dictate not only what must be done but who must be positioned to ensure it happens. Widely cited examples include obligations under statutes such as the Sarbanes-Oxley Act (SOX), HIPAA, and GLBA, each of which reflects how a legislature can impose duties tailored to particular sectors or subject matter.
Because the scope, wording, and applicability of statutory requirements vary by jurisdiction, sector, and the entity concerned, treating them as uniform or universally applicable can create blind spots. Determining precise obligations under any given statute is a matter of legal interpretation that generally warrants professional advice, and organizations that map their duties carefully are better positioned to demonstrate a defensible basis for their compliance decisions.
Who it's relevant to
Inside Statutory Requirement
Common questions
Answers to the questions practitioners most commonly ask about Statutory Requirement.