6.3 Clause 9.1.2: Evaluation of Legal and Regulatory Compliance

Key Takeaways

  • Clause 9.1.2 mandates establishing, implementing, and maintaining processes to evaluate compliance with applicable legal requirements and other requirements determined under Clause 6.1.3.
  • Lead auditors enforce a strict distinction between identifying legal requirements (Clause 6.1.3 - Planning) and verifying actual physical and operational compliance (Clause 9.1.2 - Performance Evaluation).
  • Organizations must evaluate compliance across all applicable requirements; conducting partial reviews or relying solely on executive legal certifications violates the standard.
  • Under Clause 9.1.2(c), the organization must maintain continuous knowledge and understanding of its compliance status and take immediate corrective action when non-compliance is identified.
Last updated: September 2026

6.3 Clause 9.1.2: Evaluation of Legal and Regulatory Compliance

Lead Auditor Core Concept: An organization can maintain a beautifully bound legal register detailing every national, regional, and municipal safety regulation and yet remain in total non-compliance with the law on the factory floor. Clause 9.1.2 represents the auditable bridge between legal awareness and physical reality. A Lead Auditor must distinguish between identifying legal obligations (Clause 6.1.3) and conducting rigorous, evidence-based evaluations to verify that those obligations are actually being fulfilled in daily operations.


1. The Normative Mandate of Clause 9.1.2

ISO 45001:2018 Clause 9.1.2 requires the organization to establish, implement, and maintain a process for evaluating compliance with legal requirements and other requirements determined under Clause 6.1.3.

The standard imposes five specific auditable requirements on the organization (Clause 9.1.2 a–d):

  1. a) Determine frequency and method: Define how often compliance is evaluated and what specific evaluation methods will be deployed.
  2. b) Evaluate compliance and take action: Actively evaluate whether the organization fulfills every applicable legal and other requirement, and take immediate corrective action when non-compliances are identified.
  3. c) Maintain knowledge and understanding of compliance status: Ensure that top management and operational leadership maintain continuous awareness of the organization's true compliance posture.
  4. d) Retain documented information: Preserve detailed records demonstrating the results of compliance evaluations as auditable evidence.

2. The Critical Audit Distinction: Clause 6.1.3 vs. Clause 9.1.2

One of the most frequent conceptual errors made by audit candidates and auditees alike is conflating Clause 6.1.3 with Clause 9.1.2. Lead auditors evaluate these clauses as two distinct halves of the PDCA cycle:

Evaluation DimensionClause 6.1.3: Determination (Planning)Clause 9.1.2: Evaluation (Performance Evaluation)
Core Question"What legal and other requirements apply to our hazards and operations?""Are we actually complying with each requirement in daily practice?"
PDCA QuadrantPlan (Planning for the management system)Check (Measuring and evaluating performance)
Primary ActivityIdentifying laws, accessing regulatory databases, determining applicability to specific site hazards.Conducting inspections, testing emissions, sampling maintenance permits, verifying worker licenses.
Typical ArtifactLegal and Other Requirements Register (Legal Matrix).Legal Compliance Evaluation Reports, Line-by-Line Evidence Logs, Corrective Action Requests.
Frequency TriggerDynamic: triggered by new legislation, altered processes, or new chemical introductions.Periodic and systematic: determined by operational risk, regulatory volatility, and compliance history.
Auditor FocusCompleteness of legal identification and access to up-to-date statutory publications.Depth and validity of objective evidence proving operational conformity with specific legal clauses.

Auditor Takeaway: An auditee who presents an updated legal register when asked for evidence of compliance evaluation demonstrates a fundamental misunderstanding of the standard. A register is merely a list of rules; Clause 9.1.2 requires physical, verifiable proof of adherence.


3. Determining Evaluation Frequency and Methodologies

Clause 9.1.2(a) requires the organization to determine the frequency and methods for evaluation. ISO 45001 does not prescribe an arbitrary "annual" timeline; rather, evaluation frequency must be calibrated to risk and operational complexity.

Factors Influencing Evaluation Frequency

  • Regulatory Risk and Hazard Severity: High-hazard facilities (e.g., chemical manufacturing, explosive storage, commercial diving) require frequent or continuous evaluation of critical statutory controls.
  • Regulatory Volatility: Industries subject to frequent statutory revisions (e.g., chemical exposure limits or environmental waste laws) demand shorter evaluation intervals.
  • Past Compliance History: Operational areas with histories of regulatory citations, near-misses, or audit findings must be evaluated more frequently.
  • Equipment Life Cycles: Specific statutory mandates dictate their own evaluation cadences (e.g., annual crane load testing, biennial pressure vessel inspections, triennial noise surveys).

Robust Compliance Evaluation Methodologies

An organization cannot rely on a single administrative review. Defensible evaluation methodologies combine multiple assessment techniques:

  1. Physical Workplace Inspections (Gemba Walkthroughs): Directly auditing physical safeguards against statutory mandates (e.g., verifying machine guard dimensions against machinery safety regulations, checking chemical storage bunding volumes).
  2. Review of Permits, Licenses, and Statutory Consents: Verifying validity dates, operational parameters, and reporting conditions attached to government operating permits (e.g., hazardous waste disposal manifests, atmospheric discharge permits, trade effluent consents).
  3. Examination of Mandatory Competence Credentials: Auditing employee licensing for high-risk statutory activities (e.g., certified forklift licenses, licensed industrial radiographers, certified high-voltage electricians).
  4. Statutory Health and Environmental Test Sampling: Reviewing third-party laboratory test reports for workplace air quality, local exhaust ventilation (LEV) testing, and occupational medical surveillance records.
  5. Third-Party Legal Compliance Audits: Commissioning independent external environmental, health, and safety (EHS) legal specialists to conduct exhaustive compliance assessments.

4. Maintaining Knowledge and Understanding of Compliance Status (Clause 9.1.2c)

Clause 9.1.2(c) imposes a powerful continuous requirement: the organization must maintain knowledge and understanding of its compliance status. Top management and department heads cannot claim ignorance between periodic audit cycles.

If a statutory permit expires, a regulatory inspection issues a citation, or a continuous emission monitor detects an exceedance, management cannot wait eleven months for the next scheduled compliance audit to recognize the deficiency. The organization must operate management tracking systems—such as automated compliance software, regulatory alert feeds, and recurring EHS operational meetings—that maintain live visibility over compliance performance.


5. Addressing Identified Non-Compliance: The Lead Auditor's Stance

A critical tenet of ISO 45001 certification auditing is that the discovery of a legal non-compliance does not automatically result in immediate certification failure or certification denial. ISO 45001 recognizes that in complex regulatory landscapes, non-compliances will occasionally occur.

What the auditor evaluates is how the management system reacts under Clause 9.1.2(b) and Clause 10.2:

  • Did the organization's internal processes detect the non-compliance, or did it remain undetected until the certification auditor pointed it out?
  • Did management take immediate action to contain the risk and prevent worker harm?
  • Did the organization notify regulatory authorities if legally mandated to do so?
  • Did the organization initiate root-cause analysis and implement corrective actions to prevent recurrence?

When Does Legal Non-Compliance Warrant a Major Nonconformity?

A Lead Auditor must issue a Major Nonconformity under Clause 9.1.2 when:

  1. The organization has completely failed to establish or execute a compliance evaluation process;
  2. Management was aware of an ongoing legal violation but took no corrective action;
  3. The non-compliance represents imminent danger to worker life, health, or safety;
  4. The organization deliberately concealed regulatory citations or statutory violations from the audit team;
  5. Systemic non-compliances indicate a total failure of operational controls under Clause 8.1.

6. Documented Information: Distinguishing Robust Evidence from Paper Exercises

Clause 9.1.2(d) mandates retaining documented information of the compliance evaluation results. During audits, Lead Auditors frequently encounter "paper exercises"—checklists where an auditee has simply stamped "Compliant" next to 150 complex legal statutes without recording any factual evidence.

Characteristics of Auditable Compliance Records

DimensionSuperficial "Paper Exercise" (Unacceptable)Rigorous Clause 9.1.2 Evidence (Acceptable)
Level of DetailHigh-level checklist listing the title of the law with a single generic checkbox.Line-by-line breakdown of specific legal sections and individual auditable requirements.
Objective EvidenceBlank or states "Verified by observation" with no dates, locations, or equipment IDs.Records explicit evidence: "Sampled Crane #4 load test certificate #8812 dated 2026-03-12; inspected 12 chemical drums in Yard B, secondary bunding intact."
Competence of EvaluatorCompleted by an administrative clerk with no legal or technical safety training.Executed by qualified EHS professionals, certified auditors, or specialized legal counsel.
Handling GapsShows 100% compliance year after year despite obvious physical factory floor violations.Honestly records identified gaps, references formal Corrective Action Request (CAR) numbers, and logs containment steps.
Worker ParticipationCompleted in an isolated executive office without consulting workers or floor supervisors.Involves worker safety representatives and frontline operators in verifying operational practices (Clause 5.4).

7. Real-World Audit Scenario: The "Check-the-Box" Legal Evaluation

Audit Context: During a Stage 2 certification audit of a steel fabrication and heavy equipment assembly facility, the Lead Auditor audits Clause 9.1.2. The facility operates overhead bridge cranes, spray paint booths, and large plasma-cutting tables.

Audit Investigation:

  1. The Lead Auditor requests documented evidence of the most recent compliance evaluation. The Safety Director presents an Excel spreadsheet listing 45 national safety statutes. Beside each statute, a column marked "Status" displays the word "Compliant", with a single signature from the Corporate Legal Director dated six months prior.
  2. The auditor asks for the specific objective evidence used to verify compliance with National Statutory Regulation 44 (Inspection and Certification of Lifting Appliances). The Safety Director admits: "Our corporate attorney checked that box based on our general maintenance policy. He didn't physically inspect individual crane records."
  3. The auditor conducts a physical walkaround of the fabrication bay and examines the inspection tags on six 20-ton overhead cranes. Five cranes have statutory inspection tags that expired nine months ago. Maintenance files confirm that required annual non-destructive hook testing has been deferred indefinitely due to production demands.
  4. Further sampling reveals that four paint booth operators have never undergone mandated annual biological exposure testing for solvent metabolites.

Lead Auditor Evaluation: The Lead Auditor raises a Major Nonconformity against Clause 9.1.2(a), (b), and (c). The organization failed to deploy effective evaluation methods to verify compliance, failed to maintain accurate knowledge of its compliance status, and failed to take action on critical safety violations involving lifting equipment and toxic exposure.


8. Common Exam Traps and Candidate Errors

  • Trap 1: Conflating Internal Audits (9.2) with Compliance Evaluations (9.1.2). An internal audit under Clause 9.2 evaluates conformance to the ISO 45001 standard and the organization's own procedures. A compliance evaluation under Clause 9.1.2 specifically evaluates adherence to statutory, regulatory, and subscribed legal requirements. While an organization may coordinate these activities, an internal audit checklist does not inherently satisfy Clause 9.1.2 unless every applicable legal requirement is systematically evaluated.
  • Trap 2: Assuming Any Legal Non-Compliance Forfeits Certification. A certification auditor is not a law enforcement officer. If an organization has identified a legal breach through its own Clause 9.1.2 process, logged it, contained the risk, and initiated robust corrective action under Clause 10.2, the auditor sees a functioning, conforming management system.
  • Trap 3: Accepting High-Level Executive Certifications Without Operational Proof. An executive memo stating "To the best of our knowledge, the plant complies with all labor laws" is opinion, not auditable objective evidence. Auditors must verify physical records, permits, measurements, and floor conditions.
Loading diagram...
Clause 6.1.3 to Clause 9.1.2 Compliance Evaluation Architecture
Test Your Knowledge

What is the fundamental difference between ISO 45001 Clause 6.1.3 and Clause 9.1.2?

A
B
C
D
Test Your Knowledge

During an audit, an organization presents a signed compliance evaluation report from its corporate legal counsel stating: 'The organization is deemed in full compliance with all federal and provincial safety statutes.' However, the Lead Auditor finds that statutory annual thickness testing for six high-pressure boilers has been overdue for eight months. How should the Lead Auditor assess this situation?

A
B
C
D
Test Your Knowledge

An organization identifies during its quarterly compliance evaluation that exposure levels of crystalline silica in its abrasive blasting booth exceeded national statutory limits by 15%. What is the organization required to do under ISO 45001?

A
B
C
D