ISO 14001:2015 replaced the former “legal and other requirements” with the broader term compliance obligations, encompassing both mandatory legal requirements and voluntary commitments. Clause 6.1.3 requires organizations to identify, access, and determine how these obligations apply to their environmental aspects, and to take them into account when establishing, implementing, maintaining, and continually improving the EMS.
Types of Compliance Obligations
Mandatory (Legal) Requirements
- Federal environmental statutes (Clean Air Act, Clean Water Act, RCRA, CERCLA, EPCRA)
- State and local environmental regulations and permits
- Consent orders, enforcement actions, and court orders
- Permits, licenses, and authorizations
Voluntary Commitments
- Industry codes of practice and best management practices
- Contractual requirements with customers or suppliers
- Voluntary environmental programs (EPA voluntary programs, industry initiatives)
- Organizational policies and standards that exceed regulatory requirements
- Agreements with community groups or environmental organizations
Building a Compliance Register
While the standard doesn’t prescribe a specific format, a compliance register (or legal register) is the most common approach. Effective registers include the obligation name and citation, applicable aspects and activities, specific requirements, responsible person, evaluation method and frequency, status, and next review date. The register must be a living document updated when regulations change, new permits are issued, or organizational activities evolve.
Integration with EMS Planning
Compliance obligations must be taken into account when establishing environmental objectives, implementing operational controls, conducting risk assessment (Clause 6.1), and planning monitoring and measurement. They are also a required input to management review.
Evaluation of Compliance
Clause 9.1.2 requires a dedicated process to evaluate fulfillment of compliance obligations. This process determines evaluation frequency based on obligation importance and risk, evaluates compliance status, takes action when noncompliance is identified, and maintains documented records of evaluation results. See the Monitoring and Measurement page for detailed evaluation guidance.
Common Pitfalls
- Incomplete identification of applicable regulations
- Not tracking voluntary commitments alongside legal requirements
- Static compliance register not updated when regulations change
- Compliance evaluation frequency insufficient for high-risk obligations
- Not connecting compliance obligations to specific operational controls
Frequently Asked Questions
What are compliance obligations in ISO 14001?
Compliance obligations are the legal requirements an organization must comply with and the other requirements it chooses to or has to comply with. Legal requirements include statutes, regulations, permits, licences, and court orders. Other requirements include customer and contractual commitments, corporate and group standards, voluntary codes and industry agreements, and obligations to community groups or non-governmental organizations.
What replaced legal and other requirements in ISO 14001:2015?
The 2015 revision replaced the 2004 phrase legal requirements and other requirements with the single term compliance obligations. The scope is essentially the same, but the newer wording makes it clearer that voluntary commitments carry the same weight within the EMS as regulatory ones once the organization adopts them.
Is a compliance obligations register required?
Clause 6.1.3 requires documented information on compliance obligations to be maintained, and does not prescribe a format. A register is the standard way to meet this and is what auditors expect. A workable register records each obligation, its source, which operations and aspects it applies to, the specific action or limit it imposes, who owns it, and when it was last verified as current.
What is the difference between compliance obligations and compliance evaluation?
Clause 6.1.3 is about identifying what applies to you and how those obligations bear on the EMS. Clause 9.1.2 is about periodically checking whether you are actually meeting them. One defines the requirement set; the other tests performance against it. Auditors commonly find organizations with a well-maintained register and no evidence that compliance against it was ever evaluated.
How often should compliance obligations be updated?
Whenever regulations change, operations change, or new commitments are made, and on a defined periodic review in any case. Most organizations perform a formal regulatory applicability review annually and monitor for regulatory change continuously through subscription services or trade association updates. Permit renewal dates and expiring commitments should be tracked so obligations are never silently out of date.
Ecesis maintains your compliance obligations register and links each obligation to the operations it affects.
Request a free 30-minute demo

