Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

The ISO 45001 evaluation of compliance

Evaluation of Compliance: A Clear Guide to ISO 45001 9.1.2

The evaluation of compliance is the clause that catches organizations who have written a legal register and never gone back to it. ISO 45001 clause 9.1.2 asks for something more specific than “we obey the law”: a process, a frequency, an assessment, action where you fall short, and records of the result.

This guide covers what the clause requires, how it differs from an internal audit, and how to run an evaluation of compliance that produces evidence rather than reassurance.

Evaluation of compliance under ISO 45001: from legal register to documented status
The chain the clause expects: identify, evaluate, act, know your status, keep the record.

What ISO 45001 clause 9.1.2 asks for

Clause 9.1.2 requires you to establish, implement and maintain a process for evaluating compliance with the legal requirements and other requirements you identified under clause 6.1.3. Within that process you have to determine the frequency and methods, carry the evaluation out, take action if anything is not being met, maintain knowledge and understanding of your compliance status, and retain documented information as evidence of the results.

Five obligations, and the two most often missed are the middle ones. “Maintain knowledge and understanding of its compliance status” means somebody can answer the question today, not after a three-week exercise. And “take action” means a nonconformity route exists — an evaluation of compliance that ends in a spreadsheet cell marked non-compliant with no linked action has not met the clause.

It is not the same as an internal audit

  Evaluation of compliance (9.1.2) Internal audit (9.2)
Question Are we meeting our legal and other requirements? Does our system conform to ISO 45001 and to our own arrangements?
Benchmark Statute, regulation, permits, customer and corporate requirements The standard and your documented processes
Who runs it Whoever holds the competence — often line management with specialist support Auditors independent of the area audited
Output A compliance status per requirement, with evidence Findings against clauses and processes

An audit can sample legal compliance, and often does. It does not discharge 9.1.2, because an audit covers the areas on the programme this year while the evaluation of compliance has to cover every requirement you have listed.

Running the evaluation of compliance

  1. Start from a register that is actually a register. Each entry needs the instrument, the specific duty it places on you, who it applies to, and where in your system that duty is met. A list of statute titles cannot be evaluated against.
  2. Set frequency by consequence, not by convenience. Statutory inspection regimes, permit conditions and exposure limits deserve more than an annual glance; a general duty that has not changed in a decade does not. Write the frequency into the register.
  3. Choose a method per requirement. Document review, physical inspection, records check, measurement, interview, or a specialist opinion. The clause asks for methods, and “we checked” is not one.
  4. Record the evidence, not the conclusion. “Compliant — see LEV test certificates 12 Mar 2026” survives an audit. “Compliant” does not.
  5. Route every shortfall through your nonconformity process. Same route as any other finding, with an owner, a date and an effectiveness check.
  6. Report the status upward. Compliance status is an explicit management review input, and it is one of the few places where legal exposure reaches the top table in writing.

The “other requirements” half nobody scopes

ISO 45001 says legal requirements and other requirements: contractual terms, customer requirements, corporate standards, voluntary commitments, collective agreements, and the codes you have publicly signed up to. Organizations evaluate the statute and quietly skip the rest — and the missed requirement is usually a customer’s safety schedule that carries a commercial penalty the law never would.

Where the evaluation of compliance falls down

The register was bought, not built. A subscription list of applicable legislation is a good starting input and a poor register: nothing in it says how the duty applies to your sites, so nothing in it can be evaluated.

One person holds it all. When the evaluation lives with a single specialist, compliance status is unknown for the period between their leaving and the next hire. The clause’s “maintain knowledge and understanding” wording is aimed squarely at that risk.

Contractors are outside the scope. Duties you hold for people working on your premises do not transfer with the work. If your evaluation covers only direct employees, it covers less than your legal exposure.

Frequently asked questions

How often must an evaluation of compliance be done?
The standard does not set a frequency — you do, and you have to justify it. Annual is the common baseline, with higher-risk or fast-changing requirements evaluated more often.

Does it need to be documented?
Yes. Clause 9.1.2 requires documented information as evidence of the compliance evaluation results, which means a record of the assessment, not just of the requirement.

Can we combine it with ISO 14001?
Yes, and most integrated systems do. ISO 14001 carries an equivalent clause, and one process with one register split by discipline is easier to keep current than two.

Who should perform it?
Someone competent in the requirement being evaluated. Independence is not required by 9.1.2 in the way it is for internal audit, but self-evaluation by the person responsible for the duty is worth challenging.

What if we find non-compliance?
Act on it through the nonconformity process, and record it. Discovering and correcting a breach is a working management system; the finding at certification is for the organization that did not look.

Where this leaves you

Make the register the foundation: duty by duty, applied to your sites, with a frequency and a method attached to each line. Evaluate against evidence, route every shortfall into corrective action, and make sure someone can state the compliance status on any given day without a project. Cover the “other requirements” as seriously as the statutory ones, and take the result to management review — an evaluation of compliance that never reaches the people who allocate money cannot change anything.

References

More on ISO 45001

Scored evaluation sheets, a legal register structure and management review inputs are in the ISO 45001 Assessment Tool, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.