Skip to content
VISCOUNTQuality Certifications

Guidance

Compliance obligations: what ISO 14001 and 45001 auditors check

A legal register is half of it. What clauses 6.1.3 and 9.1.2 of ISO 14001 and ISO 45001 require, and the findings raised when nobody evaluates compliance.

Published

A legal register is half of what ISO 14001 and ISO 45001 ask for. Clause 6.1.3 in both standards asks you to determine the requirements that apply to you and how they apply. Clause 9.1.2 asks you to evaluate your compliance against them at a frequency you have determined, take action where you find a gap, and retain the results. Most of the findings we raise on this subject sit between a register that exists and an evaluation that was never carried out.

The two requirements produce different evidence, which is why an auditor asks for both. Clause 6.1.3 produces a list with a column saying how each item applies to your operations. Clause 9.1.2 produces dated records showing what you checked, when you checked it, and what you found.

What counts as an obligation

ISO 14001 uses the term compliance obligations, and defines it as the legal requirements you have to comply with together with other requirements you have to or choose to comply with. ISO 45001 splits the same idea into legal requirements and other requirements, and adds a step: you determine how they apply and what needs to be communicated.

In the UAE the legal half reaches past federal and emirate law into documents specific to your facility. The conditions on your trade license, the municipality or free zone environmental approvals for the site, Civil Defence approvals, and the conditions attached to a permit for a particular plant item are all obligations, and they are the ones a template register cannot know about.

The other requirements half is where registers are usually thin. A commitment given in a tender response and a main contractor's HSE plan you signed up to both become obligations under clause 6.1.3 once you have accepted them. On a project site the main contractor's plan is the common case, and the subcontractor's register lists federal legislation only.

The register we see most often is a table of legislation by title, with a compliance column ticked down its length. Clause 6.1.3 asks how each requirement applies to the organization, so a title with no applicable requirement identified against it is a finding before anyone reaches the evaluation. A copied register shows itself in what it contains: laws with no bearing on the activities named on the certificate, and nothing about the permit pinned up in the workshop.

Evaluating compliance

Clause 9.1.2 asks you to establish, implement and maintain a process for evaluating compliance. You determine the frequency of evaluation, evaluate, take action where needed, maintain knowledge and understanding of your compliance status, and retain documented information of the results. ISO 45001 asks you to determine the methods as well as the frequency.

Maintaining knowledge and understanding of your compliance status describes a continuing state, and an evaluation performed once during implementation stops describing it within months. Frequency is yours to set, and the standard asks that you have set it deliberately. A quarterly check on waste manifests alongside an annual check on a five-year permit is defensible when the reasoning behind the difference is recorded.

What we sample is narrow. An auditor takes two or three obligations that bite in your operations, asks for the evaluation record for each, and then asks for the evidence that record rests on. A permit whose expiry date passed last quarter, still showing as compliant in the register, answers the question about the process as a whole, and expired permits are among the more common things we find in a register that is otherwise well kept.

The results travel further than the register. Compliance evaluation is an input to management review under clause 9.3 in both standards, so a review pack with no compliance status in it produces a second finding from the same gap. Clause 9.2 asks a different question, since an internal audit tests conformity with the standard and with your own requirements, and a small system that merges the two usually leaves 9.1.2 with no record of its own.

What a certificate says about your compliance

Certification against ISO 14001 or ISO 45001 certifies the management system. The authority that decides whether you comply with a law is the one that issued it, and the certificate carries no verdict on your legal status. What it evidences is that you determined what applies to you, evaluated yourself against it, and acted on what the evaluation found.

That boundary changes how a breach reads during an audit. An obligation your own evaluation caught, recorded and acted on is the system doing its job, and what we audit is the action you took. One your register never captured is a finding against clause 6.1.3 or 9.1.2, graded and issued in writing with the evidence it rests on and a window to respond.

ISO 9001 carries no compliance obligations clause. Statutory and regulatory requirements enter a quality system through clause 8.2.2, as requirements for the products and services you offer. Where you hold all three certificates, a single shared register works as long as the environmental and OH&S evaluation keeps its own frequency and its own records, because those two clauses are audited against their own standards.

Before your next surveillance, three things in your own register are worth checking. Each entry says how the requirement applies to you rather than what the law is called. The evaluation records cover the period since your last audit rather than the year the system was built. And every obligation carrying an expiry date has been checked against the document itself.