What Are Legal and Other Requirements in ISO 45001?
Understand applicable legal and other requirements, how organisations identify and evaluate them, and how auditors examine compliance within an ISO 45001 Occupational Health and Safety Management System.
Legal and other requirements in ISO 45001 are the obligations that an organisation must identify, access, understand and consider when managing occupational health and safety. These can include applicable laws, regulations, permits, contractual requirements and other commitments related to OH&S.
What Are Legal Requirements in ISO 45001?
Legal requirements are the occupational health and safety laws and regulations that apply to an organisation's activities. The exact requirements depend on the country, industry, workplace activities and other circumstances of the organisation.
For example, an organisation may need to consider requirements related to workplace safety, machinery, hazardous substances, personal protective equipment, emergency arrangements, working conditions or occupational health.
The organisation needs to determine which legal requirements apply to its activities rather than simply maintaining a general list of laws.
What Are Other Requirements in ISO 45001?
Other requirements are obligations that are not necessarily legal requirements but that the organisation has chosen or is required to follow.
Obligations established through contracts or agreements.
OH&S-related requirements established by customers.
Applicable industry codes or relevant commitments.
Internal agreements or other relevant organisational obligations.
The important point is that the organisation should determine which requirements are applicable to its OH&S activities and consider them within its OHSMS.
Why Are Legal and Other Requirements Important in ISO 45001?
Understanding applicable requirements helps an organisation identify what it needs to do to manage occupational health and safety responsibilities.
Legal and other requirements can also influence hazard identification, risk assessment, operational controls, objectives and other parts of the OHSMS.
Legal and other requirements should not be treated as an isolated compliance list. They can influence how an organisation plans, controls and evaluates its OH&S activities.
For a related topic, see What Is Risk Assessment in ISO 45001? A Simple Guide for Beginners .
What Does ISO 45001 Require About Legal and Other Requirements?
ISO 45001 requires an organisation to determine and have access to applicable legal requirements and other requirements related to its hazards and OH&S risks.
Identify applicable legal and other requirements.
Maintain access to relevant requirements and information.
Understand how requirements apply to the organisation.
The organisation should determine how these requirements apply to its activities and what needs to be communicated to relevant people.
It should also maintain and retain appropriate documented information about these requirements and how they apply to the organisation.
How Does an Organisation Identify Legal Requirements?
An organisation can begin by reviewing the laws and regulations applicable to its locations, activities and OH&S risks.
Review relevant government information and official sources.
Use information from applicable regulatory authorities.
Use suitable legal databases to identify applicable requirements.
Professional bodies or competent external support may also be used where appropriate.
The organisation should then determine which requirements are relevant to its OHSMS and keep the information updated when applicable requirements change.
The process should be connected to the organisation's actual activities rather than being treated as a separate list of legislation.
How Are Legal Requirements Evaluated in ISO 45001?
Identifying a legal requirement is only one part of the process. The organisation also needs to evaluate whether it is fulfilling the applicable requirements.
If a particular regulation requires specific workplace controls or inspections, the organisation should have appropriate evidence showing how those requirements are being addressed.
During an audit, the auditor may examine the relationship between the applicable requirement, the organisation's processes and the available objective evidence.
What Evidence Can an ISO 45001 Auditor Review?
An auditor may review the organisation's information about applicable legal and other requirements and examine evidence showing how those requirements are being addressed.
Information showing which legal and other requirements apply.
Information showing how the organisation evaluates applicable requirements.
Evidence from actual workplace conditions and activities.
Discussions with responsible personnel about compliance processes.
The auditor may also interview responsible personnel, inspect workplace conditions and compare actual practices with applicable requirements.
This is why legal compliance should be connected to the practical operation of the OHSMS rather than maintained only as documented information.
You can also read What Are the Common Documents Required for an ISO 45001 Audit? to understand the types of documented information that may be reviewed during an audit.
How Do Legal Requirements Connect With ISO 45001 Risk Assessment?
Legal requirements can influence how an organisation manages its OH&S risks. When identifying hazards and assessing risks, the organisation should consider applicable requirements that relate to those hazards and activities.
For example, where a workplace activity is subject to specific safety requirements, those requirements may need to be considered when determining appropriate controls.
Connecting legal and other requirements with hazard identification, risk assessment and operational controls helps incorporate compliance considerations into OH&S planning.
What Is the Role of Top Management?
Top management has an important role in ensuring that the organisation provides the resources and support needed to manage applicable legal and other requirements.
Support the resources needed to manage applicable requirements.
Ensure relevant responsibilities are assigned within the organisation.
Support processes for understanding and evaluating applicable requirements.
Ensure compliance-related information is considered within the OHSMS.
For more information, see What Is the Role of Top Management in ISO 45001? .
How Does an ISO 45001 Auditor Check Legal Requirements?
An auditor may ask how the organisation identifies applicable legal requirements, how it keeps the information current and how it evaluates compliance.
How does the organisation identify applicable legal requirements?
How does the organisation keep its legal and other requirements information current?
How does the organisation evaluate whether requirements are being fulfilled?
What records, workplace evidence or other information demonstrate how requirements are being addressed?
The auditor may also speak with employees responsible for compliance and examine relevant records or workplace evidence.
Develop Your ISO 45001 Auditing Skills
Understanding how to identify, evaluate and collect objective evidence related to legal and other requirements is an important part of ISO 45001 auditing.
Professionals interested in developing these skills can explore ISO 45001 Lead Auditor Training by 3FOLD Training.
Explore ISO 45001 Lead Auditor TrainingFrequently Asked Questions
What are legal requirements in ISO 45001?
Legal requirements are applicable laws and regulations related to an organisation's occupational health and safety activities.
What are other requirements in ISO 45001?
Other requirements are applicable obligations that are not necessarily laws or regulations, such as contractual requirements, customer requirements, industry commitments or organisational agreements.
Which ISO 45001 clause covers legal and other requirements?
Legal and other requirements are addressed under Clause 6.1.3 of ISO 45001:2018.
Does ISO 45001 require organisations to identify legal requirements?
Yes. Organisations need to determine and have access to applicable legal requirements and other requirements related to their OH&S hazards and risks.
How does an ISO 45001 auditor check legal compliance?
An auditor may review applicable requirements, compliance evaluation information, documented evidence, workplace conditions and interviews with relevant personnel.
Do legal requirements differ between countries under ISO 45001?
Yes. Applicable legal requirements depend on the country or jurisdiction, the organisation's activities, workplace conditions and other relevant factors.
Does ISO 45001 require a legal register?
ISO 45001 requires organisations to determine and maintain appropriate information about applicable legal and other requirements. The standard does not prescribe one specific format for this information, so organisations may use a legal register or another suitable method.
Conclusion
Legal and other requirements are an important part of ISO 45001 because they help organisations understand the OH&S obligations that apply to their activities.
The organisation needs to identify applicable requirements, understand how they apply, keep relevant information updated and evaluate whether those requirements are being fulfilled.
For ISO 45001 auditors, understanding how legal and other requirements connect with hazards, risks, controls and objective evidence is an important part of auditing an effective OHSMS.





Leave a Reply
Your email is safe with us.