8 min read
How do you evaluate compliance with legal and other requirements in ISO 14001:2026?
How to identify your compliance obligations, choose how often and how to check them, record the results and act when you fall short.
3FOLD Training is a CQI IRCA Approved Training Partner (ATP 6039853) · Licensed by KHDA, Dubai
Knowing the law is one thing, and being able to show that you follow it is another. An environmental management system (EMS) has to do both, and an auditor will ask for proof of the second. This guide explains how to evaluate compliance with legal and other requirements in ISO 14001:2026, for managers and for anyone preparing for the CQI (Chartered Quality Institute) and IRCA (International Register of Certificated Auditors) ISO 14001 Lead Auditor course.
To evaluate compliance in ISO 14001:2026, first identify your compliance obligations, which are the legal requirements and the other requirements you have to or choose to meet. Then set how often you will evaluate each one, check them using suitable methods such as inspections, monitoring data and internal audits, act on any gap and keep records of the results. The aim is to know your compliance status at any time, not only on audit day.
| Standard | ISO 14001:2026, Environmental management systems |
| Step 1 | Determine compliance obligations and how they apply (planning clause 6.1.3) |
| Step 2 | Evaluate compliance at set intervals and act on gaps (performance evaluation, clause 9.1.2 in the 2015 edition) |
| Evidence | Documented results of the evaluation |
| Who decides frequency | The organization, based on its obligations and risks |
| Auditor course | ISO 14001 Lead Auditor · PR376 · CQI and IRCA |
What does ISO 14001:2026 require for compliance evaluation?
It requires the organization to determine its compliance obligations, evaluate whether it meets them and keep the results.
Two parts of the standard work together. In planning, the organization determines the compliance obligations that relate to its environmental aspects and how they apply, and takes them into account in its EMS. In performance evaluation, it sets how often it will evaluate compliance, evaluates it, acts if needed and keeps knowledge of its compliance status up to date. It also keeps documented information as evidence of the results. In the 2015 edition these were clauses 6.1.3 and 9.1.2, so confirm the numbering in the 2026 text. According to the CQI and IRCA summary of key updates, clause 6.1.3 has minor changes related to documenting compliance obligations. Our guide to what ISO 14001:2026 is gives the wider picture.
What counts as legal and other requirements?
Compliance obligations are the legal requirements you must meet and the other requirements you have to or choose to meet.
The key point is that “other requirements” go beyond the law. Use the table below to check you have covered each type.
| Type | Examples | Where to find them |
|---|---|---|
| Legal requirements | Laws, regulations and permit or licence conditions | Regulators, permits and legal updates |
| Customer requirements | Environmental clauses in contracts | Contracts and purchase terms |
| Group or industry commitments | Corporate policies and codes you have signed up to | Head office and industry bodies |
| Voluntary commitments | Public pledges or community agreements | Management and communications records |
You cannot show you comply with a requirement you have not written down.
Want to practice auditing compliance evidence? The course includes audit working documents and a case study.
How do you set up a compliance evaluation process?
List your obligations, give each an owner, decide how often to check, choose a method and record the result.
- List the obligations that relate to your environmental aspects, and note how each applies to your sites and activities.
- Assign an owner for each obligation or group of obligations.
- Decide the frequency of evaluation, based on the obligation and its risk.
- Choose the method for each, such as inspection, data review or audit.
- Record the result with a date, what was checked and what was found.
- Act on gaps and report the compliance status to management.
The list of obligations can be a register, a spreadsheet or a database. The standard does not prescribe the format, so choose one people will keep up to date. Our guide to environmental aspects and impacts in ISO 14001:2026 shows where the obligations link to your activities.
How often should you evaluate compliance, and by what method?
The organization decides the frequency and the method, based on the obligation and the risk of getting it wrong.
A permit with a monitoring limit may need regular checks, while a stable contract clause may need a yearly check. Different methods suit different obligations, and one evaluation can often cover several.
| Method | Good for | Evidence you can keep |
|---|---|---|
| Inspection or walk-through | Site conditions, storage and waste handling | Dated checklist with findings |
| Review of monitoring data | Limits on emissions, discharges or consumption | Results compared with the limit |
| Internal audit | Whole-system checks across sites | Audit report and findings |
| Permit and contract review | Conditions that change or expire | Dated review record |
Our guide to how to conduct an ISO 14001 internal audit shows how an internal audit can feed the evaluation, and our guide to management review in ISO 14001:2026 shows where the results should be reported.
What do auditors look for when they check compliance evaluation?
Auditors look for a complete list of obligations, evidence that each was evaluated and proof that gaps were acted on.
Expect questions such as “How do you know which requirements apply to you?” and “Show me the last evaluation for this permit.” An auditor will sample a few obligations and trace them from the list to the evaluation record and to any action taken. They will also talk to the people responsible, to see whether they know their obligations. Our guide to what auditors ask during an ISO 14001:2026 audit lists more of these questions, and our guide to operational control in ISO 14001:2026 shows the controls that keep you compliant day to day.
Not sure how auditors build a sample? Ask us how the course teaches audit planning and evidence.
What should you do when the evaluation finds non-compliance?
Treat it as a nonconformity: correct it, find the cause, take action and tell management.
The evaluation exists to find gaps, so finding one is a sign it works. React to the problem first, so it stops. Then look for the cause and take corrective action, and check later that the action worked. Report significant gaps to management, for example through the management review. Keep records of what you found and did, because an auditor will want to see how the organization responded, not only that it found the issue.
What mistakes should you avoid?
The common mistakes are an out-of-date list, no dated results and checking only the law.
- An out-of-date list. New or changed requirements never reach the list.
- No dated results. The list exists, but nobody can show when each item was last checked.
- Only the law. Customer requirements and voluntary commitments are missing.
- One person holds it all. Nobody else knows the obligations or the status.
- No follow-up. Gaps are found but not acted on or reported.
For the wider picture on documents, see our guide on documented information in ISO 14001:2026.
Compliance evidence simulation: choose the best auditor action
For practice only. Read each situation and choose the best response. These scenarios were written by 3FOLD Training and are not real exam questions.
1 scenario answered: 1 of 1 correct
Preloaded example: Situation 1 is already answered. A register shows what applies, and dated results show that you checked.
Frequently asked questions
What is evaluation of compliance in ISO 14001?
Evaluation of compliance in ISO 14001 is the process by which an organization checks whether it meets its compliance obligations, acts if it does not and keeps knowledge of its compliance status up to date. In the 2015 edition it was clause 9.1.2, and the 2026 edition keeps the idea within performance evaluation.
What are compliance obligations in ISO 14001?
Compliance obligations in ISO 14001 are the legal requirements that an organization has to comply with and the other requirements that it has to or chooses to comply with. They can include permits, customer requirements, group policies and voluntary commitments.
How often must you evaluate compliance in ISO 14001?
ISO 14001 does not set a fixed interval. The organization determines how often it will evaluate compliance, based on its obligations and the risk of non-compliance, and then follows that plan.
What evidence do auditors look for in an ISO 14001 compliance evaluation?
Auditors look for a list of compliance obligations, dated results showing each was evaluated, and records of action taken on any gap. They usually sample some obligations and trace each from the list to the evaluation and to the follow-up.
Is a legal register mandatory in ISO 14001?
ISO 14001 requires the organization to determine its compliance obligations and keep documented information on them, but it does not prescribe a register or a format. A register or spreadsheet is a common way to do it, as long as it is kept up to date.
What happens if an ISO 14001 compliance evaluation finds non-compliance?
The organization should react to correct the problem, find the cause, take corrective action and check later that it worked. It should keep records and report significant gaps to management, for example in the management review.
Did ISO 14001:2026 change the requirements on compliance obligations?
According to the CQI and IRCA summary of key updates to ISO 14001:2026, clause 6.1.3 has minor changes related to documenting compliance obligations. Check the full ISO 14001:2026 text for the exact wording of both the obligations and the compliance evaluation clauses.
Where 3FOLD Training fits
3FOLD Training is a CQI IRCA Approved Training Partner (ATP 6039853), licensed by the Knowledge and Human Development Authority (KHDA) in Dubai, with offices in Dubai and Chennai. Our ISO 14001 Lead Auditor course is delivered online as 40 hours of Virtual Instructor Led Training (VILT), and you can check the next available batch on the course page. We prepare you for the exam; CQI and IRCA examine and certify. You can also browse our CQI IRCA certified training courses.
Want to audit an EMS with confidence? See what the ISO 14001 Lead Auditor course covers.
UAE mobile and WhatsApp: +971 50 481 9989
India mobile: +91 91762 57536
Chennai: Plot No: 1342, HIG, TNHB Main Road, Sithalapakkam, Chennai 600126
Monday to Friday 9:00 am to 5:00 pm, Saturday 9:00 am to 2:00 pm. See the 3FOLD Training contact page for all details.





Leave a Reply
Your email is safe with us.