processes. Its clause 9.1.2 is healthcare quality indicators. There is no clause anywhere in the standard requiring a register of statutory and regulatory requirements, an applicability determination, an evaluation frequency, or a compliance status.
What it does contain is ten separate places where a statutory or regulatory duty is imposed — beginning in the Scope and running through leadership, records, facilities, waste, service design and diagnostic safety. Clause 5.1 q) makes top management responsible for requesting evidence of compliance with legal and regulatory requirements. It never says what produces that evidence.
That gap is why this procedure exists. Healthcare is the most heavily regulated sector any management system standard is applied to. An organization certified to ISO 7101 with no register is conforming to the standard and exposed to its regulator at the same time.
| Clause | What it requires |
|---|---|
| 1 a) | Demonstrate the ability to consistently meet applicable statutory and regulatory requirements |
| 4.1 | Be an entity that can be held legally responsible for its activities |
| 5.1 q) | Top management responsibility for requesting evidence of compliance with legal and regulatory requirements |
| 5.5 | Access to care in accordance with the mandate, considering the laws and regulations by which the organization operates |
| 7.2 f) | Documented procedures for credentialing and privileging of healthcare professionals |
| 7.5.6 d) | Ensure clinical records meet any legal requirements |
| 8.2.1 j), q) | Water systems cleaned in accordance with regulatory requirements; signage taking statutory and regulatory requirements into consideration |
| 8.3.1 a) | Waste handled taking local regulatory requirements into consideration |
| 8.7 e) | Service design shall demonstrate or document compliance with legal or statutory requirements |
| 8.12.8 d) | Diagnostic safety — compliance with applicable regulatory requirements |
Section 15.0 of the template maps all ten, and closes by naming what is deliberately absent from the table — there is no row for determining compliance obligations, no row for evaluating compliance, and no row for maintaining compliance status, because ISO 7101 contains none of them. When a surveyor asks which clause this procedure satisfies, that section is the answer.
Directors of quality and regulatory affairs, chief medical officers and accreditation leads at healthcare organizations certified or working toward certification to ISO 7101:2023 — particularly those where licensure sits with administration, credentialing with medical staff services, controlled substances with pharmacy, clinical waste with facilities and privacy with information governance, and no single view of the whole exists.
Section 7.8 exists for one purpose: when top management requests evidence of compliance, the evidence is produced rather than assembled. Five request types with stated response times — the current position the same day, evidence for a single requirement in a working day, everything relating to a named license in two. The fifth row is the one that makes it honest: what has not been evaluated, and why, same day. A request for evidence of compliance that returns only the favorable answers has not been answered.
Worked example one follows a facility license carrying 34 conditions, recorded in the register as a single row reading compliant. One of those conditions required a stated air pressure differential verified at a stated interval. Facilities believed it was covered by the annual ventilation service; the service report recorded airflow, not differential. Infection prevention assumed facilities had it. When the register was broken down properly it grew from 96 rows to 214 — not because the organization took on new duties, but because it stopped hiding the ones it already had.
When a requirement is found not to be met, the notifiable event determination and the duty of candour or open disclosure determination are both same-day steps, made before the corrective action process begins. They run on separate timescales from each other and from the corrective action, and missing the second converts a manageable regulatory matter into a more serious one.
41 pages, 43 tables, every bracketed placeholder a decision you make rather than a blank someone forgot.
| What | How much of it |
|---|---|
| Numbered sections | 18 — 0.0 Document Control through 17.0 Revision History |
| Appendices | 5 — A, B, C, E and F |
| ISO 7101 clauses mapped | 10 clauses that impose a statutory or regulatory duty, each with what it requires and where the procedure serves it |
| Trigger table | 14 named triggers, each with the role that raises it and a time limit |
| Responsibilities | 7 roles, each gating role with a named alternate |
| Regulatory source map | 12 sources, each with the function that owns it and where the instrument is held |
| Procedure steps | 13 numbered steps, 7.1 through 7.13 |
| Evidence-on-request table | 5 request types with stated response times — the clause 5.1 q) answer |
| Evaluation methods | 8 methods including reconciliation and observation of practice, each with the evidence the record must name |
| Exception paths | 9 cases, each with what happens, an owner and a record |
| Records table | 12 records, each with location, owning role and retention period |
| Process interfaces | 11 interfaces, what flows in and what flows out |
| Key performance indicators | 8 indicators with target, method and owner |
| Maturity ladder | 8 elements, 4 levels each, described as observable behavior |
| Clause cross-reference | 24 rows, including what is deliberately absent and why |
| Requirements register | 29 fields, ready to use as a spreadsheet |
| Compliance evaluation record | 16 fields |
| Nonfulfillment action record | 18 fields, including the notifiable event and duty of candour determinations |
| Worked examples | 2, deliberately different in shape |
| Surveyor questions answered | 12, each with where in the document the answer is |
| Determination worksheet | 5 parts, to be completed before the procedure runs |
Every procedure Management Systems International publishes is built to seven structural marks. Most procedures in circulation satisfy four or five, and the ones they miss are almost always the same ones.
Worked example two: the new service. An outpatient infusion service added to an existing day unit. Sound clinical model, approved business case, opened on schedule, and nothing about it referred as a regulatory matter — because adding a service is a clinical and commercial decision. It engaged storage duties for a new medicine category, a waste classification the unit had not previously generated, supervision requirements attaching to the extended hours, and an accreditation standard element on monitoring during extended stays.
Two register entries were not fulfilled at the point they were created, because the service had been running for eleven weeks. One was notifiable. This is the pattern the procedure most reliably prevents: new services are where healthcare organizations take on regulatory exposure, and the people designing them are not the people who read the regulations.
Appendix F sets out where the three standards diverge on compliance machinery. ISO 14001 and ISO 45001 both carry an explicit compliance obligations clause and an explicit evaluation of compliance clause; ISO 7101 carries neither. But ISO 7101 is the only one of the three that names a top management duty to request evidence of compliance — and the only one that provides no mechanism for producing it.
Where you run more than one, hold one register with a scope field rather than three. Variants of this procedure are available for ISO 14001:2026 and ISO 45001:2018, and a combined HSE variant holds one register serving both.
Ten of them, and that is the point. ISO 7101:2023 has no compliance obligations clause and no evaluation of compliance clause — its 6.1.3 is risk management processes and its 9.1.2 is healthcare quality indicators. What it has instead is ten separate clauses that impose statutory and regulatory duties, beginning in the Scope at 1 a) and running through 4.1, 5.1 q), 5.5, 7.2 f), 7.5.6 d), 8.2.1, 8.3.1 a), 8.7 e) and 8.12.8 d). Section 15.0 of the template maps all of them, and it is the answer when a surveyor asks.
Because the duties exist whether or not the standard names a mechanism for them. Clause 5.1 q) makes top management responsible for requesting evidence of compliance with legal and regulatory requirements, and clause 8.7 e) requires service design to demonstrate or document compliance with legal or statutory requirements. Neither says what produces that evidence. An organization certified to ISO 7101 with no register is conforming to the standard and exposed to its regulator at the same time.
No, and it was never designed to. The two are assessed by different bodies against different criteria on different cycles. An organization that treats them as the same thing has one assurance and believes it has two. The template says this plainly in the leadership section, phrased so it can be said out loud to a board.
No to both. Clause 9.2 asks whether the management system for quality conforms to your own requirements and to ISO 7101 and is effectively implemented. It is not scoped to ask whether you are meeting your statutory duties. An accreditation survey tests the accreditation standard, which overlaps your regulatory duties without covering them. Neither produces the evidence clause 5.1 q) asks top management to be able to request.
Every condition attached to every license and authorization, broken out one row per condition. Statutory duties not tied to any license — controlled substances, clinical waste, health information privacy, device servicing and adverse event reporting, blood product traceability, notifiable conditions, radiation and fire safety. Payer and commissioning conditions. And the clinical guidelines your organization has decided are mandatory, which are requirements it chose to comply with.
For an acute site, typically 150 to 400 rows, with 20 to 60 of those being license and authorization conditions. Fewer than 80 almost always means duties have been recorded at the level of the regulation rather than the duty. Worked example one in the template follows a license with 34 conditions that had been recorded as a single row reading compliant.
Yes. Health regulation is overwhelmingly sub-national, and the template treats jurisdiction, site and source as register fields. It covers license conditions that differ by site, accreditation programs that differ by service, practitioner scope of practice, and care delivered remotely across a jurisdictional boundary — which commonly engages the regulation where the service user is rather than where the clinician is.
The evaluation record establishes that a requirement was met for the population concerned; it does not carry individual health information. Where a method would require access to individual data, the exception path redesigns it to test the population instead, or has the access authorized and recorded. Confidentiality duties are themselves register entries, so an evaluation that breaches one has created a second nonfulfillment.
Where a regulatory failure reached a service user, a duty of candour or open disclosure obligation may attach in its own right, on its own timescale, entirely separately from the notification to the regulator. The template makes it a same-day determination alongside the notifiable event decision, because missing it converts a manageable regulatory matter into a more serious one.
A procedure does not pass a survey; an organization does. What this gives you is a document that addresses every statutory and regulatory duty ISO 7101 imposes, with a named owner and a named record, and a section that answers the clause question directly. Conformity is demonstrated by implementation and evidence. Unfilled placeholders are unmet requirements, so fill them.
Editable Microsoft Word (.docx). Purchase grants your organization a perpetual, non-exclusive license to edit, rebrand and adopt it, including at multiple sites under common ownership. It may not be resold or distributed outside your organization.
New to ISO 7101? The ISO 7101 Overview course covers the healthcare quality management system standard end to end.
Want help implementing it? Call Management Systems International at 760-434-9141 to schedule a planning session.
Management Systems International is a veteran-owned, female-owned ISO consulting firm founded in 1998. Across 28 years we have supported 80+ certifications, attended 200+ audits alongside our clients, and trained 600+ professionals across manufacturing, technology, medical device, government, healthcare, and other regulated industries.
We write these templates the way we write procedures for clients: as finished, worked documents with the judgment calls already made and explained, so you can see what a decided position looks like before you make your own.
Perennia Healthcare is a fictional organization used for illustration throughout the template, and is not connected with any real organization of the same or a similar name. This is a template and guide, not certification, regulatory or legal advice, and it is not clinical guidance. Your statutory and regulatory requirements are yours to determine, and unfilled placeholders are unmet requirements.
ISO 7101 is a trademark of the International Organization for Standardization. This template is an independent work by Management Systems International, LLC and is not endorsed by or affiliated with ISO or any certification or accreditation body. The standard is not reproduced in the template.
© 2026 Management Systems International, LLC · All rights reserved. · msi-international.com · 760-434-9141
Notifications