Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 5.5

Contact with Authorities: A Practical Implementation Guide

Prepare trusted communication channels with relevant authorities before an incident or legal obligation makes them urgent.

This control concerns establishing and maintaining appropriate contact with authorities such as law enforcement, regulators, supervisory bodies, emergency services and sector-specific agencies.

Practical interpretation: The organization should know which authority to contact, for what reason, who is authorized to communicate and what information may be shared. A list of telephone numbers alone is not an operational process.

What should the control achieve?

  • Relevant authorities and reporting obligations are identified.
  • Authorized contact persons and deputies are assigned.
  • Notifications are timely, accurate and legally reviewed where necessary.
  • Contact details and procedures are periodically tested and updated.

Step-by-step implementation

1

Identify relevant authorities

Map jurisdictions, regulated activities, incident types and mandatory notification duties. Include data protection, cyber security, financial, sector and emergency authorities as applicable.

2

Define notification triggers

Document events that require or may benefit from contact, including statutory deadlines, evidence preservation needs and escalation thresholds.

3

Assign authorized contacts

Name roles responsible for decisions and communication, with deputies and 24/7 arrangements for urgent situations.

4

Prepare communication procedures

Create templates and checklists covering approval, confidentiality, facts to verify, secure channels and record keeping.

5

Exercise and maintain

Test contact paths during incident exercises and review details after legal, organizational or jurisdictional changes.

What this could look like in practice

A SaaS provider maintains a jurisdiction matrix linking customer locations and incident types to competent privacy and cyber authorities. During a tabletop exercise, the Incident Manager coordinates facts, Legal confirms the reporting duty, the CEO approves external communication and a designated Privacy Officer submits the notification through the authority's portal.

ActivityPractical implementationEvidence
Regulatory mappingLegal maintains authority, jurisdiction, trigger and deadline information.Regulatory contact register
Incident notificationIncident team uses an approved decision checklist and message template.Decision log and submitted notice
Routine liaisonSecurity representative attends sector briefings and records relevant guidance.Meeting notes and action log

Implementation evidence

  • Authority contact register
  • Notification decision matrix
  • Legal and regulatory obligations register
  • Named authorized contacts and deputies
  • Incident communication procedure
  • Notification templates
  • Exercise records
  • Submitted reports and correspondence

Useful metrics

  • Percentage of authority contacts reviewed on schedule
  • Time from confirmed trigger to notification decision
  • Number of missed or late mandatory notifications
  • Percentage of exercises that test external notification

Common mistakes

  • Using outdated or unverified contact details.
  • Allowing unauthorized personnel to speak for the organization.
  • Contacting authorities before facts and legal constraints are assessed.
  • Failing to retain the decision and communication record.
  • Assuming one country's process applies in every jurisdiction.

Questions an auditor may ask

  • Which authorities are relevant to your operations and why?
  • Who decides whether a notification is required?
  • Show a recent test or actual authority communication.
  • How do you track jurisdiction-specific deadlines?
Implementation test: Run a tabletop scenario at 16:00 on a Friday. Can the team identify the correct authority, decision maker, deadline, secure channel and approved information without improvising?

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.