Skip to content

ISO Glossary

Legal and other requirements

The compliance obligations an organisation must identify, access and evaluate under ISO 14001 and ISO 45001. Broader than law — it includes anything you have voluntarily committed to.

Also called: compliance obligations

Legal and other requirements, also called compliance obligations, are the legal requirements an organisation must comply with and the other requirements it chooses to comply with. They appear in ISO 14001 clause 6.1.3 and ISO 45001 clause 6.1.3.

The “other” is doing real work

Legal — statutes, regulations, permits, licences, consent orders, court judgments.

Other — customer contract terms, industry codes of practice, voluntary commitments, agreements with community groups, parent company policies, and public pledges.

A voluntary commitment becomes an obligation once made. An organisation that publishes an emissions target has created an “other requirement” against which an auditor may reasonably assess it.

What is required

  • Determine the requirements applicable to your aspects or hazards
  • Determine how they apply to your organisation
  • Take them into account when establishing and maintaining the system
  • Maintain documented information about them

Both standards separately require periodic evaluation of compliance — you must know whether you are actually meeting these obligations, not merely have listed them.

Where organisations get caught

A register that is a list of statute names. The requirement is to determine how they apply to you. “Clean Air Act” is not a determination; the specific permit conditions applying to your specific equipment is.

No process for staying current. Regulations change. A register compiled once at implementation and never revisited fails the maintenance requirement, and by the second surveillance audit it is usually visibly out of date.

All glossary terms