MSI ISO 7101 Evaluation of compliance procedure

ISO 7101 Evaluation of Compliance Procedure Template and Guide

$149

ISO 7101 imposes statutory and regulatory duties in ten clauses and provides no mechanism for any of them. One register broken down to individual duties and license conditions, an evaluation frequency you can defend, and evidence that exists at the moment clause 5.1 q) asks for it.

ISO 7101:2023 does not contain a compliance obligations clause. Its clause 6.1.3 is risk management

processes. Its clause 9.1.2 is healthcare quality indicators. There is no clause anywhere in the standard requiring a register of statutory and regulatory requirements, an applicability determination, an evaluation frequency, or a compliance status.

What it does contain is ten separate places where a statutory or regulatory duty is imposed — beginning in the Scope and running through leadership, records, facilities, waste, service design and diagnostic safety. Clause 5.1 q) makes top management responsible for requesting evidence of compliance with legal and regulatory requirements. It never says what produces that evidence.

That gap is why this procedure exists. Healthcare is the most heavily regulated sector any management system standard is applied to. An organization certified to ISO 7101 with no register is conforming to the standard and exposed to its regulator at the same time.

The ten clauses that impose a duty

Clause What it requires
1 a) Demonstrate the ability to consistently meet applicable statutory and regulatory requirements
4.1 Be an entity that can be held legally responsible for its activities
5.1 q) Top management responsibility for requesting evidence of compliance with legal and regulatory requirements
5.5 Access to care in accordance with the mandate, considering the laws and regulations by which the organization operates
7.2 f) Documented procedures for credentialing and privileging of healthcare professionals
7.5.6 d) Ensure clinical records meet any legal requirements
8.2.1 j), q) Water systems cleaned in accordance with regulatory requirements; signage taking statutory and regulatory requirements into consideration
8.3.1 a) Waste handled taking local regulatory requirements into consideration
8.7 e) Service design shall demonstrate or document compliance with legal or statutory requirements
8.12.8 d) Diagnostic safety — compliance with applicable regulatory requirements

Section 15.0 of the template maps all ten, and closes by naming what is deliberately absent from the table — there is no row for determining compliance obligations, no row for evaluating compliance, and no row for maintaining compliance status, because ISO 7101 contains none of them. When a surveyor asks which clause this procedure satisfies, that section is the answer.

Who this is for

Directors of quality and regulatory affairs, chief medical officers and accreditation leads at healthcare organizations certified or working toward certification to ISO 7101:2023 — particularly those where licensure sits with administration, credentialing with medical staff services, controlled substances with pharmacy, clinical waste with facilities and privacy with information governance, and no single view of the whole exists.

Three things this procedure does that most do not

1. It makes clause 5.1 q) answerable

Section 7.8 exists for one purpose: when top management requests evidence of compliance, the evidence is produced rather than assembled. Five request types with stated response times — the current position the same day, evidence for a single requirement in a working day, everything relating to a named license in two. The fifth row is the one that makes it honest: what has not been evaluated, and why, same day. A request for evidence of compliance that returns only the favorable answers has not been answered.

2. It breaks licenses down to conditions

Worked example one follows a facility license carrying 34 conditions, recorded in the register as a single row reading compliant. One of those conditions required a stated air pressure differential verified at a stated interval. Facilities believed it was covered by the annual ventilation service; the service report recorded airflow, not differential. Infection prevention assumed facilities had it. When the register was broken down properly it grew from 96 rows to 214 — not because the organization took on new duties, but because it stopped hiding the ones it already had.

3. It carries the two clocks healthcare has that other sectors do not

When a requirement is found not to be met, the notifiable event determination and the duty of candour or open disclosure determination are both same-day steps, made before the corrective action process begins. They run on separate timescales from each other and from the corrective action, and missing the second converts a manageable regulatory matter into a more serious one.

What is inside

41 pages, 43 tables, every bracketed placeholder a decision you make rather than a blank someone forgot.

What How much of it
Numbered sections 18 — 0.0 Document Control through 17.0 Revision History
Appendices 5 — A, B, C, E and F
ISO 7101 clauses mapped 10 clauses that impose a statutory or regulatory duty, each with what it requires and where the procedure serves it
Trigger table 14 named triggers, each with the role that raises it and a time limit
Responsibilities 7 roles, each gating role with a named alternate
Regulatory source map 12 sources, each with the function that owns it and where the instrument is held
Procedure steps 13 numbered steps, 7.1 through 7.13
Evidence-on-request table 5 request types with stated response times — the clause 5.1 q) answer
Evaluation methods 8 methods including reconciliation and observation of practice, each with the evidence the record must name
Exception paths 9 cases, each with what happens, an owner and a record
Records table 12 records, each with location, owning role and retention period
Process interfaces 11 interfaces, what flows in and what flows out
Key performance indicators 8 indicators with target, method and owner
Maturity ladder 8 elements, 4 levels each, described as observable behavior
Clause cross-reference 24 rows, including what is deliberately absent and why
Requirements register 29 fields, ready to use as a spreadsheet
Compliance evaluation record 16 fields
Nonfulfillment action record 18 fields, including the notifiable event and duty of candour determinations
Worked examples 2, deliberately different in shape
Surveyor questions answered 12, each with where in the document the answer is
Determination worksheet 5 parts, to be completed before the procedure runs

Why this is not the clause reworded

Every procedure Management Systems International publishes is built to seven structural marks. Most procedures in circulation satisfy four or five, and the ones they miss are almost always the same ones.

  • A real trigger — fourteen enumerated channels, including the informal route a clinician actually uses
  • One accountable owner — with a named alternate for every gating role, and function owners named per requirement
  • Stated decision criteria — four factors and five standing rules that fix a frequency, not intentions
  • Records as a byproduct — the register and the evaluation record are the work, not a report about it
  • A defined exception path — nine cases, including the one where a regulatory duty collides with operational pressure
  • Trainable in one sitting — a desk-level work instruction with two worked examples
  • A built-in review trigger — event-based, with the calendar as backstop only

Worked example two: the new service. An outpatient infusion service added to an existing day unit. Sound clinical model, approved business case, opened on schedule, and nothing about it referred as a regulatory matter — because adding a service is a clinical and commercial decision. It engaged storage duties for a new medicine category, a waste classification the unit had not previously generated, supervision requirements attaching to the extended hours, and an accreditation standard element on monitoring during extended stays.

Two register entries were not fulfilled at the point they were created, because the service had been running for eleven weeks. One was notifiable. This is the pattern the procedure most reliably prevents: new services are where healthcare organizations take on regulatory exposure, and the people designing them are not the people who read the regulations.

If you also run ISO 14001 or ISO 45001

Appendix F sets out where the three standards diverge on compliance machinery. ISO 14001 and ISO 45001 both carry an explicit compliance obligations clause and an explicit evaluation of compliance clause; ISO 7101 carries neither. But ISO 7101 is the only one of the three that names a top management duty to request evidence of compliance — and the only one that provides no mechanism for producing it.

Where you run more than one, hold one register with a scope field rather than three. Variants of this procedure are available for ISO 14001:2026 and ISO 45001:2018, and a combined HSE variant holds one register serving both.

Common questions

Which ISO 7101 clause does this procedure satisfy?

Ten of them, and that is the point. ISO 7101:2023 has no compliance obligations clause and no evaluation of compliance clause — its 6.1.3 is risk management processes and its 9.1.2 is healthcare quality indicators. What it has instead is ten separate clauses that impose statutory and regulatory duties, beginning in the Scope at 1 a) and running through 4.1, 5.1 q), 5.5, 7.2 f), 7.5.6 d), 8.2.1, 8.3.1 a), 8.7 e) and 8.12.8 d). Section 15.0 of the template maps all of them, and it is the answer when a surveyor asks.

If the standard does not require a register, why build one?

Because the duties exist whether or not the standard names a mechanism for them. Clause 5.1 q) makes top management responsible for requesting evidence of compliance with legal and regulatory requirements, and clause 8.7 e) requires service design to demonstrate or document compliance with legal or statutory requirements. Neither says what produces that evidence. An organization certified to ISO 7101 with no register is conforming to the standard and exposed to its regulator at the same time.

Does ISO 7101 certification demonstrate regulatory compliance?

No, and it was never designed to. The two are assessed by different bodies against different criteria on different cycles. An organization that treats them as the same thing has one assurance and believes it has two. The template says this plainly in the leadership section, phrased so it can be said out loud to a board.

Is evaluation of compliance the same as our internal audit or our accreditation survey?

No to both. Clause 9.2 asks whether the management system for quality conforms to your own requirements and to ISO 7101 and is effectively implemented. It is not scoped to ask whether you are meeting your statutory duties. An accreditation survey tests the accreditation standard, which overlaps your regulatory duties without covering them. Neither produces the evidence clause 5.1 q) asks top management to be able to request.

What goes in the register that would not be in an accreditation binder?

Every condition attached to every license and authorization, broken out one row per condition. Statutory duties not tied to any license — controlled substances, clinical waste, health information privacy, device servicing and adverse event reporting, blood product traceability, notifiable conditions, radiation and fire safety. Payer and commissioning conditions. And the clinical guidelines your organization has decided are mandatory, which are requirements it chose to comply with.

How big should the register be?

For an acute site, typically 150 to 400 rows, with 20 to 60 of those being license and authorization conditions. Fewer than 80 almost always means duties have been recorded at the level of the regulation rather than the duty. Worked example one in the template follows a license with 34 conditions that had been recorded as a single row reading compliant.

Does it handle more than one site or jurisdiction?

Yes. Health regulation is overwhelmingly sub-national, and the template treats jurisdiction, site and source as register fields. It covers license conditions that differ by site, accreditation programs that differ by service, practitioner scope of practice, and care delivered remotely across a jurisdictional boundary — which commonly engages the regulation where the service user is rather than where the clinician is.

How does it handle patient confidentiality during an evaluation?

The evaluation record establishes that a requirement was met for the population concerned; it does not carry individual health information. Where a method would require access to individual data, the exception path redesigns it to test the population instead, or has the access authorized and recorded. Confidentiality duties are themselves register entries, so an evaluation that breaches one has created a second nonfulfillment.

What is the duty of candour handling for?

Where a regulatory failure reached a service user, a duty of candour or open disclosure obligation may attach in its own right, on its own timescale, entirely separately from the notification to the regulator. The template makes it a same-day determination alongside the notifiable event decision, because missing it converts a manageable regulatory matter into a more serious one.

Will this pass a survey?

A procedure does not pass a survey; an organization does. What this gives you is a document that addresses every statutory and regulatory duty ISO 7101 imposes, with a named owner and a named record, and a section that answers the clause question directly. Conformity is demonstrated by implementation and evidence. Unfilled placeholders are unmet requirements, so fill them.

What format is it, and can we rebrand it?

Editable Microsoft Word (.docx). Purchase grants your organization a perpetual, non-exclusive license to edit, rebrand and adopt it, including at multiple sites under common ownership. It may not be resold or distributed outside your organization.

New to ISO 7101? The ISO 7101 Overview course covers the healthcare quality management system standard end to end.

Want help implementing it? Call Management Systems International at 760-434-9141 to schedule a planning session.

About Management Systems International

Management Systems International is a veteran-owned, female-owned ISO consulting firm founded in 1998. Across 28 years we have supported 80+ certifications, attended 200+ audits alongside our clients, and trained 600+ professionals across manufacturing, technology, medical device, government, healthcare, and other regulated industries.

We write these templates the way we write procedures for clients: as finished, worked documents with the judgment calls already made and explained, so you can see what a decided position looks like before you make your own.


Perennia Healthcare is a fictional organization used for illustration throughout the template, and is not connected with any real organization of the same or a similar name. This is a template and guide, not certification, regulatory or legal advice, and it is not clinical guidance. Your statutory and regulatory requirements are yours to determine, and unfilled placeholders are unmet requirements.

ISO 7101 is a trademark of the International Organization for Standardization. This template is an independent work by Management Systems International, LLC and is not endorsed by or affiliated with ISO or any certification or accreditation body. The standard is not reproduced in the template.

© 2026 Management Systems International, LLC · All rights reserved. · msi-international.com · 760-434-9141