MSI's ISO 45001 compliance obligations and evaluation of compliance

ISO 45001 Legal Requirements and Evaluation of Compliance Procedure Template

$149

A complete ISO 45001:2018 editable compliance obligation procedure. Written as a working document, not an outline. One register, a severity model that routes, and an effectiveness check with a defined interval.

Most OH&S management systems can produce last year's compliance evaluation. Far fewer can answer the question an inspector actually asks, which is what the organization's compliance status is today.

ISO 45001 separates the two. Clause 9.1.2 c) requires the organization to maintain knowledge and understanding of its compliance status — a continuing state held between evaluations. Clause 9.1.2 a) requires the frequency and the method to be determined, so both the interval and how it is checked are decisions to be made and recorded rather than habits inherited from the previous system.

A third requirement sits alongside them and is the one most often missing entirely. Clause 5.4 d) 4) requires the organization to emphasize the consultation of non-managerial workers on determining how to fulfill legal requirements and other requirements. The people the duty exists to protect have a say in how it is met.

Who this is for

OH&S managers, safety advisors and integrated management system managers at organizations certified or working toward certification to ISO 45001:2018, who need a legal requirements process that produces evidence rather than a list.

Three things this procedure does that most do not

1. It records the method as well as the frequency

Clause 9.1.2 a) names both. An interval without a method is not an evaluation plan — two people will do different things and the record will not show which. This procedure sets both per requirement against four factors, records which factor drove the interval, and lists 7 evaluation methods with the evidence each one obliges the record to name: measurement against an exposure limit, statutory examination report, health surveillance coverage, inspection, records review, worker interview and third-party verification.

2. It builds in the consultation requirement everybody misses

Clause 5.4 d) 4) has been in the standard since 2018 and is routinely absent from otherwise competent systems. The register gets built by a qualified professional working alone, the controls are technically correct, and no non-managerial worker was consulted on any of it. Section 5.5 covers what workers are consulted on and when, section 7.5 is the process step, the register carries a consultation field, and one of the indicators measures whether it is happening rather than described.

Worked example two is the case for it: a health surveillance requirement where the applicability determination was correct, the arrangement was capable, and cohort coverage was still drifting below the interval — because appointments were being booked at shift changeover when the line could not be released. Nobody had asked. Coverage rose from 68 to 97 percent over two cycles with no change to the requirement or the budget.

3. It makes compliance status a state, with somewhere for the honest answer to go

Five states, including one most registers do not have: not yet evaluated. An entry that passes its due date reverts to it automatically rather than continuing to report the result it had last time.

What is inside

39 pages, 43 tables, every bracketed placeholder a decision you make rather than a blank someone forgot.

What How much of it
Numbered sections 18 — 0.0 Document Control through 17.0 Revision History
Appendices 5 — A, B, C, E and F
Trigger table 14 named triggers, each with the role that raises it and a time limit
Responsibilities 7 roles, each gating role with a named alternate
Procedure steps 13 numbered steps, 7.1 through 7.13
Evaluation methods 7 methods, each with what it suits and the evidence the record must name
Exception paths 8 cases, each with what happens, an owner and a record
Records table 12 records, each with location, owning role and retention period
Process interfaces 10 interfaces, what flows in and what flows out
Key performance indicators 7 indicators with target, method, owner and reporting route
Maturity ladder 8 elements, 4 levels each, described as observable behavior
Clause cross-reference 24 rows mapping every requirement to where it is satisfied
Compliance obligations register 27 fields, ready to use as a spreadsheet
Compliance evaluation record 15 fields
Nonfulfillment action record 16 fields
Worked examples 2, deliberately different in shape
Auditor questions answered 14, each with where in the document the answer is
Determination worksheet 5 parts, to be completed before the procedure runs

Why this is not the clause reworded

Every procedure Management Systems International publishes is built to seven structural marks. Most procedures in circulation satisfy four or five, and the ones they miss are almost always the same ones.

  • A real trigger — enumerated channels, including the informal route a worker actually uses
  • One accountable owner — with a named alternate for every gating role
  • Stated decision criteria — thresholds and factors, not intentions
  • Records as a byproduct — the register and the evaluation record are the work, not a report about it
  • A defined exception path — for the ambiguous requirement, the missing evidence, the missed due date
  • Trainable in one sitting — a desk-level work instruction with two worked examples
  • A built-in review trigger — event-based, with the calendar as backstop only

The register of regulations problem. One row naming a health and safety regulation, evaluated annually, marked compliant. Worked example one is exactly that: fourteen items of lifting equipment behind a single row, two of them overdue for statutory thorough examination, one by four months — while the row said compliant and was accurate about the regulation. Operators knew and had assumed it was being handled. There was no route to tell.

This template breaks each source down to the individual duties that attach to your operation, one row per duty per asset, each with its own interval, method and owner.

Pricing

$149 — ISO 45001:2018 variant, editable Word document.

Also available: the ISO 14001:2026 variant at $149, and the combined HSE variant at $249, which holds one register serving both standards and records the nine points at which the two standards genuinely differ.

Common questions

Which ISO 45001 clauses does this cover?

Clause 6.1.3, determination of legal requirements and other requirements, and clause 9.1.2, evaluation of compliance, together in one procedure. It also addresses clause 5.4 d) 4) on consulting non-managerial workers, 7.4.1 on communication, 9.3 on the two management review inputs, and 10.2 on incident, nonconformity and corrective action.

What is clause 5.4 d) 4) and why does it matter here?

It requires the organization to emphasize the consultation of non-managerial workers on determining how to fulfill legal requirements and other requirements. Not consultation on safety generally — on how these specific duties are met. It is one of the most commonly missed requirements in the whole standard, and it is usually found by an auditor talking to a worker rather than reading a document. This procedure gives it a section, a process step, a register field, an indicator and a maturity element.

Our register says annual for everything. Is that a problem?

Clause 9.1.2 a) requires the frequency and the method to be determined — both are named, and this is stricter than the ISO 14001 equivalent. A register where every row reads annually with no method column has made neither determination. It also cannot be less frequent than a duty that prescribes its own interval: statutory examination intervals govern the evaluation, not the other way around.

Isn't evaluation of compliance just part of the internal audit?

No. Clause 9.2 asks whether the management system conforms and is effectively implemented. Clause 9.1.2 asks whether you are meeting your legal requirements and other requirements. They can be scheduled together but produce separate results and separately retained evidence. Note that clause 9.1.2 d) says retain, not make available.

What does maintaining knowledge of compliance status actually mean?

Clause 9.1.2 c) asks for a continuing state, not an annual document. This procedure holds five states — met, at risk, not fulfilled, not yet evaluated, and not applicable — and an entry that passes its due date reverts automatically to not yet evaluated rather than continuing to report its last result. Worker representatives can see the picture, which is difficult to withhold while asking for consultation under 5.4 d) 4).

Does it handle collective agreements and host site rules?

Yes, both. They are other requirements the organization has to comply with, and they are frequently missing from registers built by reading legislation. Where an agreement sets a standard above the legal minimum — on hours, health surveillance or representation — that higher standard is the duty to be evaluated. Host site rules and multi-employer duties are covered in the multi-jurisdiction section.

How does it handle health surveillance and long retention periods?

The evaluation record establishes that surveillance happened at the required interval for the required cohort and that outcomes were acted on; it does not carry individual results, and confidentiality duties are themselves register entries. The records table flags that exposure monitoring and health surveillance for specified agents commonly carry retention periods measured in decades, which breaks most standing records policies.

ISO 45001 is being revised. Should we wait?

No. The duties in the register are legal duties and they do not wait for a standard. Appendix F sets out why waiting costs more than building, and what a revision is unlikely to change here — the structure of clause 6.1.3 and the four parts of clause 9.1.2 are common to the harmonized structure and stable. Buyers of the current version receive the rebuilt edition at no additional cost when a new edition publishes; the version stamp in the template is what makes that administrable.

What format is it, and can we rebrand it?

Editable Microsoft Word (.docx). Purchase grants your organization a perpetual, non-exclusive license to edit, rebrand and adopt it, including at multiple sites under common ownership. It may not be resold or distributed outside your organization.

Want help implementing it? Call Management Systems International at 760-434-9141 to schedule a planning session.

About Management Systems International

Management Systems International is a veteran-owned, female-owned ISO consulting firm founded in 1998. Across 28 years we have supported 80+ certifications, attended 200+ audits alongside our clients, and trained 600+ professionals across manufacturing, technology, medical device, government, healthcare, and other regulated industries.

We write these templates the way we write procedures for clients: as finished, worked documents with the judgment calls already made and explained, so you can see what a decided position looks like before you make your own.


Perennia Corp is a fictional company used for illustration throughout the template, and is not connected with any real organization of the same or a similar name. This is a template and guide, not certification or legal advice. Your compliance obligations are yours to determine, and unfilled placeholders are unmet requirements.

ISO 14001 and ISO 45001 are trademarks of the International Organization for Standardization. This template is an independent work by Management Systems International, LLC and is not endorsed by or affiliated with ISO or any certification body. Neither standard is reproduced in the template.

© 2026 Management Systems International, LLC · All rights reserved. · msi-international.com · 760-434-9141