
Short answer: regulatory mapping means linking each rule that applies to your business to one line in a list of duties, called an obligations register. Each line holds the rule's exact citation and a plain-words statement of what it requires. It also names the person who owns the duty and the step you take to comply. Finally it holds the proof that you did and a date to review it. Done well, a register lets you answer an auditor in minutes.
TL;DR
- An obligation is something a rule requires you to do. A register is the list where each one is recorded, once, with an owner.
- Every line needs six things: the citation (the rule's official address, such as a code title and section), a plain statement, an owner, a control, evidence and a review date.
- A control is the step you take to meet the duty. Evidence is the record that shows you took it.
- Cite the exact paragraph of the rule, and record which version of the text you read.
- Rules change. A register with no review date and no link to monitoring goes stale.
What regulatory mapping is
A regulation is a rule written by a government agency under power a law gives it. Mapping is the work of turning one of those rules into something your team can act on.
A rule is written for the public. Your company needs it written for a person with a job. Mapping closes that gap. You take the rule's words, decide whether they apply to you, and tie them to a named owner and a real business step.
Some vendors use the terms "obligation mapping" or "regulatory obligations register" for the same thing. The names differ, the work does not. Guides from software sellers usually stop at the definition. They rarely show a filled-in line, which is the part you can copy.
The fields of an obligation
Six fields are essential: citation, plain statement, owner, control, evidence and review date. Two more, "applies to" and "version read", save arguments later.
| Field | What goes in it | Example from the rule below |
|---|---|---|
| Citation | The exact paragraph, with the code and title | 16 CFR 314.4(j)(1) |
| Plain statement | What the rule requires, in one or two plain sentences | If a breach exposes unencrypted customer data on 500 or more people, tell the Federal Trade Commission (FTC) within 30 days of discovery |
| Applies to | Which part of your business is covered, and why | The whole company, because we prepare tax returns |
| Owner | One named role, plus a backup | Head of Security, backup: the company lawyer |
| Control | The step that meets the duty | The incident plan has a step to count affected people and file the FTC form |
| Evidence | The record that proves you did it | Incident log, a saved copy of the filed form, the filing date |
| Review date | When someone rereads the rule | Every six months, and on any amendment |
| Version read | Which text you checked, and when | eCFR (the Electronic Code of Federal Regulations, an informational online version of the CFR), read October 5, 2026 |
Name a role as owner, not a whole department. To use this as a template, put each field in a column of a spreadsheet and give every obligation its own row. The example column here is one row. These are sample entries to show the shape. They are not advice on what your own company must do.
One real rule, turned into a row
Take a rule many businesses meet without knowing it: the FTC's Safeguards Rule, which sets data security duties for certain financial businesses. It sits in Part 314 of Title 16 of the Code of Federal Regulations (the CFR, which collects agency rules by subject).
Who it covers. Section 314.1 says it applies to "financial institutions" under the FTC's authority. It lists, among others, mortgage lenders, mortgage brokers, finance companies, collection agencies and tax preparation firms. If you are unsure whether you are one, that is itself an item for your register, with a lawyer's name beside it.
What it requires. Paragraph (j)(1) of section 314.4 is the part that creates the duty:
"Upon discovery of a notification event as described in paragraph (j)(2) of this section, if the notification event involves the information of at least 500 consumers, you must notify the Federal Trade Commission as soon as possible, and no later than 30 days after discovery of the event."
The rule's definitions fill in the rest. A "notification event" is the "acquisition of unencrypted customer information without the authorization of the individual to which the information pertains." Paragraph (j)(2) adds a rule on timing. An event counts as discovered on "the first day on which such event is known to you." You are treated as knowing it if it is known to "any person, other than the person committing the breach, who is your employee, officer, or other agent."
That last sentence matters for the owner and control columns. The clock does not start when management hears. It can start when any employee knows. So the control must tell every employee how to report a suspected breach, and the owner must be someone who can act the same day.
Section 314.6 gives a small-business exception for firms holding data on fewer than five thousand consumers. It lists four paragraphs, and (j) is not among them. The agency also publishes a plain guide, What Your Business Needs to Know. Read the current text of section 314.4 yourself before you fill in the row.
State breach laws are separate duties with their own deadlines. Each one gets its own row. Our guide to state data breach notification laws shows where to find them.
Why the citation and amendment history matter
Now watch what happens when the rule changes. This one did, twice.
December 9, 2021: a proposal. The FTC proposed a breach reporting duty in the Federal Register, the daily journal where agencies publish proposed and final rules (volume 86, page 70062, written 86 FR 70062). It would have applied where misuse of customer information was likely and at least 1,000 consumers were affected.
November 13, 2023: the final rule. The final rule (88 FR 77499, meaning volume 88, page 77499) set a lower number, 500 or more consumers. Its trigger is unauthorized acquisition of unencrypted information, not likely misuse. It took effect on May 13, 2024.
A register that stored the 2021 draft would have the wrong number. A register that never reread the section would have no row at all. You can check this yourself. The eCFR page for May 12, 2024 has no paragraph (j) in section 314.4. The page for May 13, 2024 has it. The section number stayed the same. Only the content moved.
So two habits protect you. First, cite to the paragraph, not just the section, so a reviewer opens the exact words. Second, store the amendment trail. The eCFR ends each section with a source line. For this one it reads "[86 FR 70307, Dec. 9, 2021, as amended at 88 FR 77508, Nov. 13, 2023]". Each entry in that line is a Federal Register page you can open. Copy it into the "version read" field. Our guide to amendment history and point-in-time law shows what such trails can and cannot tell you.
A short history of one rule, and what its preamble teaches
The Safeguards Rule is older than most of the programs that follow it. Congress passed the Gramm-Leach-Bliley Act in 1999. The FTC issued the first Safeguards Rule in 2002 and it took effect on May 23, 2003. The FTC's own account of the rule's history picks up on April 4, 2019, when it proposed amendments and drew 49 comments. A workshop followed on July 13, 2020, with 11 more comments. The amendments were finalized on December 9, 2021, and the same day the FTC proposed the breach reporting duty, which drew 14 comments. The final version came on November 13, 2023. So a row written in 2010 and never reread would have fallen behind the rule at least twice, in 2021 and again in 2023.
When you map a rule, read the preamble, the explanation an agency prints above the rule's text in the Federal Register. It tells you why the rule says what it says, and that helps you decide what applies to you. In this one, the FTC explains why it picked 500 consumers. It looked at other breach laws and wrote that "numerous State laws require notification of breaches either with no minimum threshold, or with a threshold of 250 or 500 people." Its footnotes give three examples: Texas (250 Texas residents), Virginia (1,000 Virginia residents) and Florida (500 individuals in Florida), each with a notice to its own state office. One commenter wanted a higher federal threshold and another wanted none at all. The FTC settled on 500 and said an event that size "is significant enough to warrant notification of the Commission, regardless of the size of the financial institution." FTC staff also estimated that the duty would reach about 115 financial institutions a year, at about five hours of reporting work each.
Two things follow for your register. First, one breach can start several clocks with different triggers, which is why each state law gets its own row. Second, the FTC wrote those state numbers down in 2023, so treat them as a pointer to check, not as the current law.
The rule's own text gives you owner and review fields to copy. Section 314.4(a) tells a covered business to designate a "Qualified Individual" to oversee its security program, and says that if a service provider or affiliate fills that role, the business must "retain responsibility for compliance." If you outsource the work, you keep the duty, so the owner field still names someone on your side. Paragraph (d)(2) says that a business without effective continuous monitoring must run annual penetration testing (a simulated attack to find weak spots) and vulnerability assessments at least every six months. That is a review date written into the rule. You can read the full text of section 314.4 on the eCFR.
How mapping connects to monitoring
Mapping answers "what must we do today?" Monitoring answers "has that changed?" They feed each other. Monitoring finds a new or amended rule. Mapping decides which rows it touches, who owns them and what proof to collect. Then the review date resets.
The monitoring side is covered in regulatory monitoring: how to keep track of rule changes. Use the same citation in both places. A change alert that names "16 CFR 314.4" should lead straight to the register row with that citation.
What goes wrong
- Stale citations. The row quotes a section that was amended, renumbered or removed. Reread the text on the review date and record the date you read it. A guide on what a regulation is helps new staff learn the pieces.
- Rules that moved. A rule reappears under a different number. A citation search on the old number finds nothing, and the duty is dropped by accident.
- No owner. A line owned by "Compliance" or "IT" is owned by nobody. Name one person.
- No evidence. The step happens but leaves no trace. Decide up front which record proves it.
- Summaries that drift. The plain statement says 1,000 when the text now says 500. Copy numbers from the text, not from memory.
- One giant row. A whole part of the CFR in one line cannot be owned. Split it by paragraph.
Questions to ask a tool vendor
If a product maintains your register, ask whether each row links to the official text, whether it records which version you read, and whether it shows when the source was last checked. Our ten questions for a legal data vendor cover the rest. Ask for the text as it stood on a past date, not only today's text, since the Safeguards Rule example above turns on that. Be wary if a vendor cannot show the exact source text and the date it was checked. This is general information, not legal advice.
A tax preparer's register says the FTC must be told about a breach once enough people are affected. The number was copied from a news story about the proposed rule. What is the problem?
FAQ
What is regulatory mapping? It is the work of linking each rule that applies to your business to a duty with an owner, a control and evidence. The output is usually a register. Some vendors call it obligation mapping.
What is a compliance obligations register? It is a list with one row per duty. Each row holds the citation, a plain statement, the owner, the control, the evidence and a review date. It is the file you open when a regulator or customer asks how you comply.
How is a regulatory map different from a risk register? A risk register lists what could go wrong and how likely it is. A regulatory map lists what the rules require. The two connect, because a missed obligation is a risk, but they answer different questions.
What counts as a control? A control is a step you take that meets a duty. It can be a procedure, a system setting, a training session or a review. Write it so a new employee could follow it.
How often should I review the register? Set a date for each row and also review on any amendment to the rule. Monitoring should tell you when that happens. Quarterly or twice a year is common for rules that rarely change.
Which version of the rule should I cite? Cite the current paragraph and note the date you read it. Keep the amendment trail so you can show what the rule said when you acted. Our freshness guide explains how current an online source can be.
Can I build a register without software? Yes, for a small set of rules. A spreadsheet with the columns above can work at first. The hard part is keeping citations, owners and review dates current as rules change.
If you keep a register and want US statutes and regulations tied to their citations as data your software can pull, start at the legal API, a service your software can use to pull the text of laws (statutes, passed by legislatures) and regulations (agency rules) by citation. For where US rules come from, see US Law Data: The Complete Guide.
New legal AI guides, weekly.
Further Reading
Regulatory Monitoring: How to Keep Track of Rule Changes
Read postCompliance API: Two Meanings, and Where Regulatory Data Comes From
Read postAI Compliance Check: CCPA, GDPR, and SOX for In-House Teams (2026)
Read postUS Law Data: The Complete Guide for Business and Technical Readers
Read postHow Does a Bill Become a Law? From Idea to the US Code
Read postFlorida Attorney General Opinions: How to Find, Read and Cite Them
Read post
Co-Founder & CTO
Priyansh leads engineering and AI at Vaquill AI: the pipelines that pull statutes, regulations and court rules from every US jurisdiction's official publisher, and the REST API, MCP server and open dataset that serve them.