Skip to main content
Category: Control Types and Framework

Contact with Authorities

Also known as: Annex A 5.5, Contact with Government Authorities
Simply put

Contact with Authorities is an ISO/IEC 27001 control that requires an organization to have a defined process for reaching relevant authorities, such as regulators or law enforcement, when needed. It also involves keeping up-to-date contact information so the organization can respond appropriately during security incidents or when legal and regulatory obligations require it.

Formal definition

Referenced as Annex A Control 5.5 in the ISO/IEC 27001:2022 revision, Contact with Authorities is an organizational reference control directing an organization to establish and maintain a process for liaising with relevant authorities (for example, regulatory, law enforcement, or supervisory bodies) in accordance with its legal, regulatory, and contractual obligations. As an Annex A control, it is applied only if selected through the Statement of Applicability and informed by the organization's risk assessment, rather than being mandatory for every ISMS; the certifiable requirements themselves reside in clauses 4 through 10. In practice, implementation typically includes maintaining current contact information and defining when and how authorities are engaged, which supports timely response and reporting during security incidents. The control is organizational in nature and its applicability and depth depend on scope and the organization's compliance requirements.

Why it matters

When a security incident occurs, delays in reaching the right regulator, supervisory body, or law enforcement agency can turn a manageable situation into a compliance failure. Many legal and regulatory regimes impose obligations to notify authorities within defined timeframes, and an organization that has not identified who to contact or how to reach them may miss those windows. Contact with Authorities (Annex A 5.5 in the ISO/IEC 27001:2022 revision) addresses this by requiring a defined, maintained process for engaging relevant authorities, so that response and reporting can happen in a timely manner rather than being improvised under pressure.

Who it's relevant to

Compliance and GRC Managers
Those responsible for mapping legal, regulatory, and contractual obligations to controls need to determine, through the Statement of Applicability and risk assessment, whether 5.5 applies to their organization and how deeply it should be implemented. They typically own the process definition and ensure contact information stays current.
Incident Response Teams
Responders rely on a defined process for liaising with regulatory and law enforcement agencies following security incidents. Having authority contacts and engagement criteria established in advance supports timely reporting and helps ensure compliance obligations are met during a live event.
ISO 27001 Auditors and Certification Bodies
Auditors assessing an ISMS scoped to include Annex A 5.5 will look for evidence that a process for contacting authorities exists, that contact information is maintained, and that engagement is aligned with the organization's obligations. They also confirm the control's inclusion or exclusion is justified in the Statement of Applicability.
Legal and Regulatory Affairs Functions
Because the control is tied to legal, regulatory, and contractual obligations, legal teams often help define which authorities are relevant and when engagement is required, ensuring the process reflects the organization's actual reporting duties.

Inside Contact with Authorities

Defined authority contacts
A maintained list of relevant external authorities, such as law enforcement, regulatory bodies, data protection supervisory authorities, and other government agencies, that the organization may need to engage, along with the circumstances that would trigger such contact.
Contact procedures
Documented processes specifying who is authorized to contact each authority, how contact is initiated, and how communications are recorded, so that engagement is timely and consistent when incidents or legal obligations arise.
Trigger conditions
The scenarios that typically prompt contact with authorities, such as security incidents with legal or regulatory reporting obligations, data breaches subject to notification requirements, or requests originating from authorities themselves.
ISO 27001 Annex A reference control
In the ISO/IEC 27001 context, Contact with Authorities appears as a reference control in Annex A, selected via the Statement of Applicability and informed by risk assessment. The precise control identifier and grouping depend on the edition, as Annex A was restructured in the 2022 revision (from 114 controls in the 2013 version to 93 organized into four themes).
Roles and responsibilities
Assignment of accountability for maintaining authority contact information and for making the decision to engage, typically integrated with incident response and, where applicable, breach notification workflows.

Common questions

Answers to the questions practitioners most commonly ask about Contact with Authorities.

Is 'Contact with Authorities' a SOC 2 Trust Services Criterion?
No. Contact with Authorities is an ISO/IEC 27001 Annex A reference control, not a SOC 2 Trust Services Criterion. SOC 2 organizes its requirements around the Common Criteria (Security) plus the optional categories of Availability, Processing Integrity, Confidentiality, and Privacy. While a SOC 2 engagement may examine controls related to how an organization interacts with authorities or handles incidents, the specific 'Contact with Authorities' control is defined within ISO 27001's Annex A and selected via the Statement of Applicability, not the Trust Services Criteria.
Does implementing Contact with Authorities mean an organization must notify regulators of every incident?
Not necessarily. The control concerns maintaining appropriate contacts with relevant authorities so that the organization can reach them when needed, rather than mandating notification of every event. Whether and when notification is required depends on applicable legal, regulatory, and contractual obligations and on the organization's own scope and risk assessment. The Annex A control supports readiness to make contact; it does not by itself define reporting thresholds, which vary by jurisdiction and circumstance.
How is this Annex A control typically selected and documented within an ISMS?
Like other Annex A reference controls, it is considered during the risk assessment and treatment process and its inclusion or exclusion is recorded in the Statement of Applicability, with justification. In most implementations, an organization that faces regulatory reporting obligations or that may need to engage emergency services, regulators, or law enforcement would justify its inclusion. The precise treatment depends on scope and the risks identified for the defined ISMS.
What kinds of authorities does this control typically cover?
Depending on scope, relevant authorities can include regulators, data protection or supervisory bodies, law enforcement, and emergency services, among others applicable to the organization's operations and jurisdictions. The specific set is determined by the organization's context, legal and regulatory environment, and risk assessment rather than a fixed list, so it varies from one ISMS to another.
How can an organization demonstrate this control to a certification body during an ISO 27001 audit?
Evidence typically includes documented, maintained points of contact for relevant authorities, defined responsibilities for who initiates contact and when, and integration of these contacts into incident response or business continuity procedures. Auditors generally look for evidence that the contacts are current and that personnel understand the process. The exact evidence expected depends on the certification body, the auditor, and the defined scope of the ISMS.
Does this control overlap with incident response and business continuity activities?
It commonly relates to them. Maintaining contact with authorities often supports incident response and business continuity processes, since timely engagement with regulators or emergency services may be part of managing a serious incident. In many implementations these areas are coordinated, but they are addressed by distinct Annex A controls and requirements, and how they interrelate depends on the organization's design decisions and scope.

Common misconceptions

Contact with Authorities is a required control in every ISO 27001 certification.
As an Annex A reference control, its applicability is determined through the Statement of Applicability and risk assessment. The certifiable ISMS requirements reside in clauses 4 through 10; Annex A controls are selected based on scope and risk rather than being universally mandatory.
SOC 2 has an equivalent 'Contact with Authorities' control that mirrors the ISO 27001 control one-to-one.
SOC 2 is an attestation examination against the Trust Services Criteria, not the ISO 27001 Annex A control set. While incident response and communication expectations may relate to the Common Criteria depending on scope, mapping between the two frameworks is partial, and satisfying one does not automatically satisfy the other.
Having authority contacts on file guarantees compliant breach reporting.
Maintaining contacts supports readiness, but actual notification obligations depend on applicable laws, regulations, and the specifics of an incident. The control addresses preparedness and does not by itself ensure that all reporting requirements are met.

Best practices

Maintain an up-to-date register of relevant authorities and their contact details, and review it periodically so information remains current.
Define clear trigger conditions and decision authority for when and how each type of authority is contacted, integrating these into the broader incident response process.
Document the rationale for the control's inclusion or exclusion in the Statement of Applicability, and align this decision with the outcomes of your risk assessment, specifying the ISO 27001 edition you are working against.
Assign explicit ownership for maintaining authority contacts and for authorizing engagement, avoiding ambiguity during time-sensitive incidents.
Coordinate with legal and privacy functions so that any statutory or regulatory notification obligations are identified and handled correctly for the scope in question.
Record communications with authorities to support evidence needs during a SOC 2 examination or ISO 27001 certification assessment, recognizing that such evidence covers only the controls and period or scope in question.