MSI's ISO 14001 Compliance obligation procedure template

ISO 14001:2026 Compliance Obligations Procedure Template

$149

A complete ISO 14001:2026 editable compliance obligation procedure. Written as a working document, not an outline. One register, a severity model that routes, and an effectiveness check with a defined interval.

Most environmental management systems can produce last year's compliance evaluation. Far fewer can answer the question an auditor actually asks, which is what the organization's compliance status is today.

ISO 14001:2026 separates the two. Clause 9.1.2 c) requires the organization to maintain knowledge and understanding of its compliance status — a continuing state held between evaluations, not a document produced once a year. Clause 9.1.2 a) requires the organization to determine the frequency that compliance will be evaluated, which makes the interval a determination to be made and recorded rather than a habit inherited from the previous system.

This is a complete, worked procedure covering ISO 14001:2026 clause 6.1.3 and clause 9.1.2 together, written as though the judgment calls had already been made, so you can see a decided position before you make your own.

Who this is for

Environmental managers, EHS leads and integrated management system managers at organizations certified or working toward certification to ISO 14001:2026, who need a compliance obligations process that survives contact with an auditor rather than a register of statutes with a column marked compliant.

It is equally for anyone transitioning from ISO 14001:2015 who has been told clause 9.1.2 is unchanged and wants to know what that actually means for the document they already have.

Three things this procedure does that most do not

1. It treats the frequency as a determination, not a habit

Clause 9.1.2 a) requires the frequency to be determined. Most registers apply one interval to everything — usually annual — with no record of who chose it or why. This procedure sets frequency per obligation against four factors, records which factor drove the interval, and applies three standing rules that fix a frequency regardless: the evaluation is never less frequent than a duty that prescribes its own monitoring interval; anything notifiable to a regulator is evaluated at least quarterly; and any entry that has been at risk or in nonfulfillment in the last twelve months has its interval shortened until two consecutive evaluations are clear.

2. It makes compliance status a state, with somewhere for the honest answer to go

Five states, including one most registers do not have: not yet evaluated. An entry that passes its due date reverts to it automatically rather than continuing to report the result it had last time. A register showing every obligation as met, where a third have not been looked at since the system was built, is not a picture of compliance status — it is a picture of the last time somebody had time. Showing the gap costs nothing and is the single most useful thing this procedure produces for leadership.

3. It separates evaluation of compliance from the internal audit

Clause 9.2 and clause 9.1.2 ask different questions and produce different evidence. Scheduling the evaluation inside the audit program is fine; letting the audit report stand as the evaluation record is not. Section 7.7 states the separation and Appendix A.2 holds evaluation records that exist independently of any audit.

What is inside

38 pages, 43 tables, every bracketed placeholder a decision you make rather than a blank someone forgot.

What How much of it
Numbered sections 18 — 0.0 Document Control through 17.0 Revision History
Appendices 5 — A, B, C, E and F
Trigger table 12 named triggers, each with the role that raises it and a time limit
Responsibilities 6 roles, each gating role with a named alternate
Procedure steps 12 numbered steps, 7.1 through 7.12
Evaluation methods 6 methods, each with what it suits and the evidence the record must name
Exception paths 7 cases, each with what happens, an owner and a record
Records table 11 records, each with location, owning role and retention period
Process interfaces 10 interfaces, what flows in and what flows out
Key performance indicators 7 indicators with target, method, owner and reporting route
Maturity ladder 8 elements, 4 levels each, described as observable behavior
Clause cross-reference 19 rows mapping every requirement to where it is satisfied
Compliance obligations register 26 fields, ready to use as a spreadsheet
Compliance evaluation record 14 fields
Nonfulfillment action record 13 fields
Worked examples 2, deliberately different in shape
Auditor questions answered 15, each with where in the document the answer is
Determination worksheet 5 parts, to be completed before the procedure runs

Why this is not the clause reworded

Every procedure Management Systems International publishes is built to seven structural marks. Most procedures in circulation satisfy four or five, and the ones they miss are almost always the same ones.

  • A real trigger — enumerated channels, including the informal route a worker actually uses
  • One accountable owner — with a named alternate for every gating role
  • Stated decision criteria — thresholds and factors, not intentions
  • Records as a byproduct — the register and the evaluation record are the work, not a report about it
  • A defined exception path — for the ambiguous requirement, the missing evidence, the missed due date
  • Trainable in one sitting — a desk-level work instruction with two worked examples
  • A built-in review trigger — event-based, with the calendar as backstop only

The register of statutes problem. A row naming an environmental protection act with a column marked compliant is not evaluable, because nobody can say what was checked. This template breaks each source down to the individual duties that attach to your operation — one row per duty, each with its own limit, method, frequency and owner. Section 5.6 tells you what a right-sized register looks like and what it means if yours is much smaller.

Worked example two covers the obligation almost nobody has in their register: the commitment the organization made itself. A published diversion target, cited in two customer tenders, is a compliance obligation the moment the organization decides to comply — and it usually arrives through marketing or sales, with no route into the management system.

Transitioning from ISO 14001:2015

Appendix F is written for you. The clause 6.1.3 requirements did not materially change, so an existing register with applicability determinations transfers without rework. What does change is the numbering: risks and opportunities moved from 6.1.1 to 6.1.4 and planning action to 6.1.5, which breaks cross-references in most 2015-era documents. The appendix carries a seven-step transition sequence with effort estimates and a short list of what not to do.

Already certified to ISO 14001:2015? The ISO 14001:2026 Transition course walks the changes clause by clause. Relevant only if you hold a current ISO 14001:2015 certificate — if you are implementing for the first time, build to the 2026 edition directly and the procedure alone is what you want.

Pricing

$149 — ISO 14001:2026 variant, editable Word document.

Also available: the ISO 45001:2018 variant at $149, and the combined HSE variant at $249, which holds one register serving both standards and records the nine points at which the two standards genuinely differ.

This procedure is included in the ISO 14001:2026 Procedure Templates and Guides Package, which covers the environmental management system end to end and includes the transition course.

Common questions

Which ISO 14001:2026 clauses does this cover?

Clause 6.1.3, compliance obligations, and clause 9.1.2, evaluation of compliance, together in one procedure. It also addresses the clauses that feed them — 4.2 c) on which interested party expectations become obligations, 7.4 on communication, 7.5 on external-origin documents, 9.3.2 on the two management review inputs, and 10.2 on corrective action.

Why are determining obligations and evaluating them in the same procedure?

Because the evaluation method and frequency are properties of the individual obligation, decided when it is entered in the register. Split across two documents, the frequency column ends up in neither, and the organization discovers at audit that nobody chose the interval.

Our register says annual for everything. Is that a problem?

Clause 9.1.2 a) requires the organization to determine the frequency that compliance will be evaluated. The determination is the requirement. A register where every row reads annually, produced without a recorded reason, has applied a default rather than made a determination — and it cannot be less frequent than a duty that prescribes its own monitoring interval. A permit with monthly discharge monitoring cannot be evaluated once a year.

Isn't evaluation of compliance just part of the internal audit?

No, and this is the most common conflation. Clause 9.2 asks whether the management system conforms to the organization's own requirements and to the standard, and whether it is effectively implemented. Clause 9.1.2 asks whether the organization is meeting its compliance obligations. The two can be scheduled together and often should be, but they produce separate results and separate evidence. An audit report saying no findings does not evidence clause 9.1.2.

What does maintaining knowledge of compliance status actually mean?

Clause 9.1.2 c) asks for a continuing state, not an annual document. This procedure holds five states — met, at risk, not fulfilled, not yet evaluated, and not applicable — and an entry that passes its due date reverts automatically to not yet evaluated rather than continuing to report its last result. That is what makes the picture honest, and it is what gives leadership an answer when someone asks how many obligations have not been looked at.

Does it cover requirements in more than one country?

Yes. Section 5.2 covers multi-jurisdiction operations: which countries, states or provinces you operate in, which sites hold their own permits, how you record which requirement governs where national and local overlap, and the obligations that follow the product into a destination market rather than attaching to the place of manufacture. Jurisdiction and site are fields in the register.

Is this written to ISO 14001:2026 or ISO 14001:2015?

The 2026 edition, published April 15, 2026. The clause cross-reference carries a 2015 column, and Appendix F covers the transition — including the cross-reference that breaks most transitioned documents, because risks and opportunities moved from 6.1.1 to 6.1.4 and planning action to 6.1.5.

Will this pass an audit?

A procedure does not pass an audit; an organization does. What this gives you is a document addressing every requirement in both clauses with a named owner and a named record, describing a process people can follow. Conformity is demonstrated by implementation and evidence. Unfilled placeholders are unmet requirements, so fill them.

What format is it, and can we rebrand it?

Editable Microsoft Word (.docx). Purchase grants your organization a perpetual, non-exclusive license to edit, rebrand and adopt it, including at multiple sites under common ownership. It may not be resold or distributed outside your organization.

Want help implementing it? Call Management Systems International at 760-434-9141 to schedule a planning session.

About Management Systems International

Management Systems International is a veteran-owned, female-owned ISO consulting firm founded in 1998. Across 28 years we have supported 80+ certifications, attended 200+ audits alongside our clients, and trained 600+ professionals across manufacturing, technology, medical device, government, healthcare, and other regulated industries.

We write these templates the way we write procedures for clients: as finished, worked documents with the judgment calls already made and explained, so you can see what a decided position looks like before you make your own.


Perennia Corp is a fictional company used for illustration throughout the template, and is not connected with any real organization of the same or a similar name. This is a template and guide, not certification or legal advice. Your compliance obligations are yours to determine, and unfilled placeholders are unmet requirements.

ISO 14001 and ISO 45001 are trademarks of the International Organization for Standardization. This template is an independent work by Management Systems International, LLC and is not endorsed by or affiliated with ISO or any certification body. Neither standard is reproduced in the template.

© 2026 Management Systems International, LLC · All rights reserved. · msi-international.com · 760-434-9141