Skip to main content
Category: Regulatory Compliance

Prescribed Requirement

Also known as: Prescription Requirement
Simply put

A prescribed requirement is a condition or specification that is formally set out in a law, regulation, or rule and that must be met for an activity to be lawful or valid. In the pharmacy and controlled substances context, for example, prescription requirements are the specific elements a prescription must contain and the conditions under which it may be issued. The term signals that the requirement originates from an authoritative source rather than being a matter of discretion.

Formal definition

A prescribed requirement is a mandatory condition or specification laid down ("prescribed") by an external legal or regulatory authority, such as a statute, administrative code, or rule, that an organization or individual must satisfy for conduct to be compliant or an instrument to be valid. It sits within the compliance pillar of GRC, as adherence is measured against an externally imposed standard rather than internal policy discretion. The precise content and applicability of a prescribed requirement are jurisdiction- and sector-specific: for instance, in the United States, requirements for controlled-substance prescriptions derive from federal law (21 U.S.C. 829 and the Controlled Substances Act) and are further specified by state-level rules such as those in the Ohio Administrative Code, meaning the operative details vary by jurisdiction. This entry addresses the general meaning of the term and illustrative pharmacy-law usage only; it does not enumerate the specific elements required in any given jurisdiction, provide legal advice, or address implementation or enforcement specifics.

Why it matters

Prescribed requirements matter because they mark the boundary between conduct that is lawful and conduct that is not. When a requirement is prescribed by a statute, administrative code, or rule, satisfying it is typically a condition of validity or legality rather than a matter of organizational preference. In regulated activities such as the issuing and dispensing of controlled-substance prescriptions, failing to meet the prescribed elements can render an instrument invalid and expose the organization or individual to regulatory consequences.

The term also carries an important signal about the source of authority. Because a prescribed requirement originates from an external legal or regulatory authority, compliance is measured against that externally imposed standard, not against internal policy discretion. In the United States, for example, the requirements governing controlled-substance prescriptions derive from federal law, including the Controlled Substances Act and 21 U.S.C. 829, and are further specified by state-level rules such as the Ohio Administrative Code. This layering means the operative details commonly vary by jurisdiction, and organizations operating across state or national lines cannot assume a single uniform standard applies.

For compliance functions, treating prescribed requirements as fixed and authoritative supports defensible adherence: they can be mapped to specific legal citations, monitored, and evidenced. Confusing a prescribed requirement with a discretionary internal preference can lead an organization to under-comply with a binding obligation or, conversely, to treat an internal choice as though it were legally mandated.

Who it's relevant to

Compliance officers
Compliance officers rely on the concept to distinguish externally imposed, mandatory conditions from discretionary internal policy. Identifying prescribed requirements allows them to map obligations to specific legal citations and monitor adherence against an authoritative standard rather than internal preference.
Pharmacy and controlled-substances professionals
Pharmacists, prescribers, and dispensing organizations encounter prescribed requirements directly, since the elements a prescription must contain and the conditions under which it may be issued are set out in law, federally under the Controlled Substances Act and 21 U.S.C. 829, and further specified by state rules such as the Ohio Administrative Code. The operative details commonly vary by jurisdiction.
Legal and regulatory specialists
Legal and regulatory specialists advise on which prescribed requirements apply to a given activity and jurisdiction, tracing conditions back to their authoritative source. They are also positioned to address the jurisdiction-specific enumeration of elements and enforcement matters that fall outside the scope of a general reference entry.
Internal auditors and assurance functions
Auditors testing compliance treat prescribed requirements as fixed, externally derived criteria against which they can evaluate whether controls and instruments meet the mandated conditions, keeping their assurance role distinct from the management activities that operate the controls being tested.

Inside Prescribed Requirement

Source of Prescription
The authority that mandates the requirement, which may be an external law, regulation, or supervisory rule, or an internal policy or standard adopted by the organization. Identifying the source is essential because it determines the requirement's binding force and the consequences of non-adherence.
Specificity of Obligation
A prescribed requirement typically sets out a defined, mandated action, condition, or standard to be met, as distinguished from principles-based or outcomes-based approaches that grant discretion in how objectives are achieved. The prescriptive character lies in reduced latitude for interpretation.
Applicable Scope and Context
The jurisdiction, sector, entity type, or activity to which the requirement applies. Prescribed requirements commonly vary by regulatory regime and industry, so scope defines who is bound and under what circumstances.
Compliance Obligation Linkage
The connection between the prescribed requirement and the organization's compliance obligations register, situating it primarily within the compliance pillar of GRC while it may also inform control design and risk treatment.
Evidence and Demonstrability
The expectation that adherence to a prescribed requirement can be demonstrated, typically through documentation, records, or controls that show the mandated condition has been satisfied.

Common questions

Answers to the questions practitioners most commonly ask about Prescribed Requirement.

Is a prescribed requirement the same as an internal policy the organization sets for itself?
No. A prescribed requirement typically refers to an obligation that is externally imposed and specified by a competent authority, such as a statute, regulation, or a rule issued by a regulator or standards body. An internal policy, by contrast, is set by the organization itself to direct behavior and support its objectives. The two can overlap where an internal policy is drafted to implement a prescribed requirement, but they should not be treated as equivalent. The defining difference is the source of the obligation and whether the organization has discretion over its content.
Does meeting all prescribed requirements mean an organization is fully compliant and its risks are addressed?
Not necessarily. Satisfying prescribed requirements addresses adherence to the specific external obligations that apply, which sits within the compliance pillar. It does not automatically mean broader compliance obligations, internal policy commitments, or risk management objectives are met. Prescribed requirements commonly represent a minimum specified baseline rather than a complete assurance that residual risk is within appetite. Compliance with a requirement and effective treatment of the underlying risk are distinct considerations that may not fully coincide.
How do we identify which prescribed requirements apply to our organization?
Applicability commonly depends on jurisdiction, industry or sector, and organizational characteristics such as size, licensing status, and the activities undertaken. A typical approach is to maintain a mapping, sometimes called a regulatory or obligations inventory, that links each applicable requirement to its issuing authority and the parts of the business it affects. Because obligations differ across jurisdictions and change over time, this identification is generally treated as an ongoing exercise rather than a one-time task. This entry does not provide legal advice on specific obligations.
Who is typically responsible for interpreting and operationalizing a prescribed requirement?
In many organizations that use a three lines model, management in the first line owns and operates the controls that implement a prescribed requirement, while a second line function such as compliance or risk provides interpretation, guidance, and oversight. Independent assurance over whether requirements are being met is commonly provided by internal audit in the third line. These roles should be kept distinct so that the function operating a control is not the same function providing independent assurance over it.
How can we demonstrate that a prescribed requirement is being met?
Organizations commonly demonstrate adherence by linking each requirement to the specific controls, policies, and procedures intended to satisfy it, and by retaining evidence that those controls operate as designed. This may include records, approvals, monitoring outputs, and testing results. The nature and extent of evidence expected can vary by requirement and by the expectations of the relevant authority. This entry does not address specific tooling or documentation formats.
What should happen when a prescribed requirement changes or a new one is introduced?
A common practice is to operate a change-monitoring process that tracks developments from relevant authorities, assesses the impact on existing controls and obligations, and updates the obligations inventory accordingly. Where a change affects how the organization must operate, this may trigger revisions to policies, standards, and procedures, and reassessment of associated risks. Because timing and applicability can vary across jurisdictions and sectors, impact assessment is typically handled case by case rather than through a single universal rule.

Common misconceptions

A prescribed requirement is the same as a control.
A prescribed requirement is an obligation that mandates a defined action or condition, whereas a control is a measure implemented to help meet obligations and manage risk. Controls may be designed to satisfy a prescribed requirement, but the two are distinct: one states what must be met, the other is a means of meeting it.
All prescribed requirements apply universally to every organization.
Prescribed requirements commonly depend on jurisdiction, sector, entity type, and activity. A requirement mandatory in one regulatory regime or industry may not apply, or may apply differently, elsewhere. Scope must be assessed for each organization's specific context.
Prescribed and principles-based requirements are interchangeable labels.
Prescribed (or prescriptive) requirements typically mandate specific actions or conditions with limited discretion, while principles- or outcomes-based approaches specify objectives and leave the method of achievement to the obligated party. Treating them as equivalent obscures the differing latitude each affords.

Best practices

Identify and record the authoritative source of each prescribed requirement, distinguishing externally mandated legal or regulatory requirements from internally adopted policies and standards.
Confirm the applicable scope for your organization, including jurisdiction, sector, entity type, and activity, rather than assuming a requirement applies universally.
Map each prescribed requirement to the compliance obligations register and to the controls implemented to meet it, keeping the requirement distinct from the controls that address it.
Maintain documentation and records sufficient to demonstrate adherence, so that satisfaction of the mandated condition can be evidenced.
Monitor for changes in the underlying laws, regulations, or internal standards, since prescribed requirements may be revised and vary across jurisdictions over time.
Assign clear ownership for interpreting and meeting each requirement, and route independent verification through assurance functions rather than the same personnel responsible for compliance.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.