3.3 Clause 6.1.3: Legal and Other Compliance Obligations
Key Takeaways
- ISO 45001:2018 Clause 6.1.3 mandates a three-part process: determining and accessing up-to-date legal and other requirements, determining their exact operational application, and integrating them into the OH&S MS.
- 'Other requirements'—such as collective bargaining agreements, corporate mandates, and voluntary industry codes—become legally binding within the management system once the organization subscribes to them.
- Clause 6.1.3 represents the planning phase (determining what applies), whereas Clause 9.1.2 represents the performance evaluation phase (measuring actual compliance status).
- Lead auditors must verify the currency of the legal register by testing whether recent legislative changes have been analyzed and operationalized at the shop-floor level.
3.3 Clause 6.1.3: Legal and Other Compliance Obligations
A credible Occupational Health and Safety Management System requires robust compliance with statutory regulations and voluntary commitments. Under ISO 45001:2018 Clause 6.1.3, the organization must establish, implement, and maintain a process to determine, access, and apply its legal requirements and other requirements. For a lead auditor, auditing Clause 6.1.3 involves verifying that statutory obligations are not merely listed in an administrative register, but actively translated into operational controls, training, and workplace behaviors.
1. The Three-Step Process of Clause 6.1.3
Clause 6.1.3 mandates three interconnected operational steps:
- Determine and Access (6.1.3.a): The organization must determine and maintain access to up-to-date legal and other requirements applicable to its hazards, risks, and OH&S management system. Access requires operational personnel to be able to review current statutory texts (e.g., via commercial databases, gazettes, or industry bulletins).
- Determine Applicability and Communication (6.1.3.b): The organization must determine how these requirements apply to its operations and what needs to be communicated. This operational translation is vital: a statutory noise regulation must be converted into specific site requirements (e.g., 85 dBA 8-hour TWA limit, biennial audiometric testing, designated hearing protection zones).
- Integrate into Planning (6.1.3.c): Requirements must be incorporated when establishing, implementing, operating, and improving the OH&S MS—directly shaping operational controls (Clause 8.1), competence (Clause 7.2), monitoring (Clause 9.1.1), and management reviews (Clause 9.3).
The organization must maintain and retain documented information on its legal and other requirements and update it to reflect any changes.
2. Legal Requirements vs. Other Requirements
Auditors must distinguish between statutory mandates and subscribed voluntary commitments:
Statutory Legal Requirements
Legally binding obligations enacted by governmental or administrative authorities. Non-compliance risks fines, operational closures, or criminal prosecution:
- National occupational safety statutes and regulations (e.g., OSHA, HSE, EU Directives);
- State, provincial, and municipal safety, fire, and building codes;
- Operating licenses, air discharge permits, and hazardous materials permits;
- Mandatory statutory inspection frequencies for safety-critical assets (e.g., boilers, pressure vessels, cranes, hoists, local exhaust ventilation).
Other Requirements
Non-statutory obligations to which an organization voluntarily commits. Key Exam Principle: Once subscribed to, voluntary obligations become mandatory compliance requirements under ISO 45001. Violations constitute auditable nonconformities:
- Collective Bargaining Agreements (CBAs): Union accords establishing mandatory rest breaks, maximum shift lengths, or safety committee ratios;
- Corporate Group Policies: Internal safety standards exceeding statutory local requirements;
- Customer Safety Specifications: Contractual safety mandates required on client industrial sites;
- Voluntary Industry Standards: Specialized industry codes (e.g., Responsible Care, ANSI/ASSP);
- Insurance Requirements: Risk engineering stipulations mandated by property and casualty insurers.
3. Operationalizing Compliance: Beyond the Generic Title List
A frequent audit failure is maintaining a generic list of standard titles (e.g., 'OSHA 29 CFR 1910') without detailing site-level application. Clause 6.1.3 requires establishing an explicit link between statutory articles and workplace controls:
| Statutory Citation | Requirement Summary | Specific Site Applicability | Operational Control Link |
|---|---|---|---|
| Pressure Systems Safety Regs | Pressure vessels > 0.5 bar require inspection every 14 months by certified inspector. | Main autoclave (Unit 3) and compressed air receiver tanks (A & B). | SOP-MNT-04; Maintenance Work Order #8821. |
| Noise Exposure Regulations | Upper Action Value: 85 dBA 8-hr TWA. Mandatory hearing protection and audiometry. | Stamping Press Bay (89 dBA) and Wood Mill (91 dBA). | Signage SIG-012; Annual Audiometry; PPE Policy. |
| Confined Space Directives | Continuous atmospheric monitoring, rescue team, permit-to-work before entry. | Wastewater sump and grain storage silos. | Permit-to-Work PTW-CS-01; Calibrated 4-gas meters; ERP-04. |
| Union CBA §14 | VDT operators entitled to 10-minute rest breaks per 50 minutes of continuous typing. | Call Center (120 workstations). | Automated desktop software prompts; Shift Schedule SCHED-2026. |
4. Distinguishing Clause 6.1.3 from Clause 9.1.2
Candidates must distinguish between planning and performance evaluation:
- Clause 6.1.3 (Plan): Determining what requirements exist, accessing texts, establishing operational applicability, and maintaining documented information. Focus: 'What applies to us and how do we integrate it?'
- Clause 9.1.2 (Check): Periodically and systematically evaluating whether the organization is actually complying with those determined requirements. Focus: 'Are we actively conforming to our obligations, and what objective evidence supports compliance?'
An organization may maintain a comprehensive register under Clause 6.1.3 but fail Clause 9.1.2 if it never conducts audits to confirm current operational conformity.
5. Lead Auditor Protocols: Auditing Legal Registers and Verifying Currency
During a Stage 2 audit, the lead auditor should execute these verification steps:
- Verify Update Mechanisms: Inquire how legislative changes are tracked. Check whether the organization uses structured update services, legal gazettes, or professional subscriptions, and check the date of the latest register revision.
- Execute the 'Newly Enacted Law' Test: Prior to the on-site audit, research recent health and safety legislation enacted within the past 6–12 months. Verify whether the new law appears in the register, whether applicability was analyzed, and whether operational controls were adjusted.
- Sample Statutory Certificates: Inspect physical assets on the shop floor (e.g., cranes, boilers, forklifts). Verify that statutory inspection plates and certificates match legal requirements and maintenance records.
- Sample Worker Understanding: Interview supervisors and workers (Clause 7.4) to verify awareness of mandatory statutory limits and permit protocols applicable to their tasks.
6. Real-World Audit Scenario: The Lapsed Vessel and Missing Regulation
Context: During an audit of a chemical blending plant, the auditor reviews the legal compliance register, last updated 18 months ago. The auditor discovers two issues:
- A national regulation on chemical packaging and hazard pictograms (incorporating GHS Revision 8) came into force 10 months ago. The register makes no reference to it, and production lines still utilize obsolete hazard labels.
- The register correctly notes the statutory annual ultrasonic inspection requirement for pressurized chlorine tanks. However, inspection certificates for Tank C-102 expired four months ago, and testing was deferred to reduce costs.
Evaluation: The auditor issues two findings:
- A Minor Nonconformity under Clause 6.1.3 for failing to maintain an ongoing process to determine and access newly enacted legal requirements;
- A Major Nonconformity under Clause 9.1.2 and Clause 8.1 for operating a safety-critical pressure vessel with an expired statutory certificate, representing an active breach of legal compliance and operational control.
7. Common Exam Traps and Candidate Errors
- Trap 1: Ignoring 'Other Requirements.' Candidates frequently assume that only governmental legislation matters. Subscribed voluntary agreements (e.g., union CBAs, customer codes) carry mandatory audit weight under ISO 45001.
- Trap 2: Equating Access with Compliance. Subscribing to an online legal database satisfies the 'access' requirement of Clause 6.1.3(a), but does not satisfy Clause 6.1.3(b) (determining applicability) or Clause 9.1.2 (evaluating compliance).
- Trap 3: Assuming Regulatory Fines Preclude Certification. Prior citations or fines do not automatically bar an organization from certification. The auditor evaluates whether corrective actions (Clause 10.2) were implemented and operational controls strengthened.
What is a mandatory requirement of ISO 45001:2018 Clause 6.1.3 regarding an organization's legal and other compliance obligations?
An industrial manufacturing facility signs a formal collective bargaining agreement with the national labor union establishing mandatory 15-minute ergonomic rest pauses every two hours for packing workers. During an audit, the lead auditor finds that plant supervisors routinely cancel these pauses to meet production quotas. Management claims that because union agreements are private labor contracts rather than federal statutes, this cannot be cited as a nonconformity under ISO 45001. How should the auditor rule?
Which of the following best describes the fundamental operational distinction between Clause 6.1.3 and Clause 9.1.2 in ISO 45001:2018?