Evaluation of Compliance: Why Annual Never Proves Status

ISO 14001 · ISO 45001 · ISO 7101

Evaluation of compliance is the requirement that separates organizations who know where they stand from organizations who can only prove where they stood. Your certified management system can almost certainly produce last year's evaluation. The question an experienced auditor asks next is a different question entirely, and it is the one that empties the room.

The question is: what is your compliance status today?

Not last March. Not at the close of the last evaluation cycle. Today. As of this morning, against every obligation you hold, which ones are you meeting, which ones are you not, and which ones do you genuinely not know about? Most organizations answer by reaching for a document. That reach is the finding. The standards do not ask for a document at that moment — they ask for a state, held continuously, and almost no management system in the world is architected to hold one.

Direct Answer: Evaluation of compliance is the process of establishing whether an organization is meeting its compliance obligations — at a frequency the organization determines, by a method the organization determines, with evidence of the result retained. ISO 14001:2026 and ISO 45001:2018 both place it at Clause 9.1.2. ISO 7101:2023 has no equivalent clause at all, yet still makes top management responsible for requesting evidence of compliance.

This article works through what evaluation of compliance actually asks across all three standards, where the differences between them are real rather than cosmetic, why the word annual in a register column is usually a confession rather than a plan, and the one part of the clause that nearly every certified organization leaves structurally unimplemented. Two worked examples follow — deliberately different in shape, because the two ways this requirement fails have nothing in common.

If you would rather look at your own documents than read about someone else's, the ISO procedure templates and guides library holds the compliance obligation procedures for each of these standards, written to be evaluable rather than merely complete.

And if you would rather measure before you read, the free Compliance Obligations Maturity Check scores your evaluation of compliance against the eight elements this article ends on and returns your weakest one immediately. It takes about five minutes and needs nothing in front of you but your register.


The Requirement

What Does Evaluation of Compliance Actually Require?

Four parts. One clause. Rarely all four.

Read the evaluation of compliance clause at 9.1.2 slowly and it resolves into four separate obligations rather than one. Organizations routinely implement the first, partially implement the fourth, and treat the middle two as though they were description rather than requirement. That is where findings come from.

a) Determine the frequency. The organization decides how often each obligation is evaluated. The decision is the requirement. Not the interval — the act of determining it, on a basis somebody can articulate.

b) Evaluate, and take action if needed. Perform the evaluation of compliance, then do something about what it found. An evaluation of compliance that produces a status and no consequence has stopped halfway.

c) Maintain knowledge and understanding of compliance status. This is the sentence this article spends most of its length on. It is a continuous obligation, not a periodic one, and it is the part almost nobody builds.

d) Retain documented information on the results. Evidence of the evaluation of compliance, kept.

Parts a) and c) are the two that carry the intellectual weight of the clause, and they are the two that get read as scene-setting for part b).

The reason this matters more in the current revision cycle than it did five years ago is that the surrounding architecture tightened. ISO 14001:2026 was published April 15, 2026, cancelling and replacing ISO 14001:2015 together with its climate-change amendment. The revision deliberately limited new requirements and concentrated on clarifying existing ones — which is precisely the condition under which a weakly implemented clause becomes easier for an assessor to see. Nothing new was added to hide behind. The transition runs three years from publication, with the end date set through accreditation arrangements now coordinated by Global Accreditation Cooperation Incorporated, the body that unified the former International Accreditation Forum and International Laboratory Accreditation Cooperation on January 1, 2026. Confirm your own date with your certification body rather than with a blog — including this one. MSI's breakdown of the ISO 2026 transition deadline arithmetic covers why the overlapping revision clocks compress the available window more than the headline three years suggests.

On the safety side, ISO 45001:2018 remains the current edition, reviewed and confirmed in 2024, carrying Amendment 1:2024 on climate action, with a revision at Draft International Standard stage. Its compliance clauses were written later than ISO 14001's and are noticeably more demanding — a point the comparison table below makes concrete.


The Comparison

Where the Three Standards Differ on Evaluation of Compliance

Compare. Contrast. Comply.

Organizations running an integrated environmental and safety system usually assume the two evaluation of compliance clauses are the same clause with different nouns. They are not. ISO 45001 asks for more than ISO 14001 in seven distinct places, and ISO 7101 — the standard with no evaluation of compliance clause whatsoever — is the only one of the three that names a top management duty to request evidence of compliance, while providing no mechanism for producing it.

Requirement ISO 14001:2026 ISO 45001:2018 ISO 7101:2023
Compliance obligations clause 6.1.3 6.1.3 None
Evaluation of compliance clause 9.1.2 9.1.2 None
Register as documented information Available Maintained, retained, kept updated Not required
Access to requirements Have access Access to up-to-date requirements Not required
Determine how they apply Yes Yes, plus what must be communicated Not required
Frequency determined Yes Yes Not required
Method determined No Yes Not required
Knowledge of compliance status Yes Yes Not required
Evidence of results Available Retained Not required
Worker consultation on how duties are met 5.4 d) 4)
Top management requests evidence of compliance 5.1 q)

The Three Lines Worth Drawing Out of the Table

One: ISO 45001 requires a determined method; ISO 14001 does not. This is the single most consequential difference for anyone writing one procedure to serve both. Under ISO 45001, “we look at the register once a year” is not a method — a method states who examines what evidence against which requirement and what constitutes a pass. Under ISO 14001 you are not obliged to state it. Write to the safety requirement and the environmental requirement comes free; write to the environmental requirement and your safety evaluation of compliance is short a mandatory element.

Two: ISO 45001 wants the register kept updated and the requirements up to date. ISO 14001 asks the organization to have access to its compliance obligations. ISO 45001 asks for access to up-to-date legal and other requirements and for the documented information to be maintained and retained. That is a live-currency obligation, and it is why a safety register that has not been reviewed against regulatory change in eighteen months is a finding in its own right, entirely separate from whether any individual duty is being met. MSI's guide to document control that survives contact with reality covers the currency mechanism that makes this workable rather than aspirational.

Three: ISO 7101 imposes duties without providing the machinery. ISO 7101:2023 is the first international consensus standard for healthcare quality management, developed under United States leadership of ISO Technical Committee 304 with the American National Standards Institute holding the secretariat. It contains no compliance obligations clause and no evaluation of compliance clause. It nonetheless imposes statutory and regulatory duties in ten separate places — Clauses 1 a), 4.1, 5.1 q), 5.5, 7.2 f), 7.5.6 d), 8.2.1 j) and q), 8.3.1 a), 8.7 e) and 8.12.8 d) — and Clause 5.1 q) makes top management responsible for requesting evidence of compliance. A healthcare organization certified to ISO 7101 therefore has a leadership duty to ask a question the standard never obliges anyone to be able to answer. Building the answer is optional under the standard and essential in practice, which is the whole argument for treating evaluation of compliance as a designed process in healthcare rather than an inherited one.

ISO 7101 is the only one of the three standards with no evaluation of compliance clause, and the only one that names a top management duty to request evidence of compliance. The gap between those two facts is where healthcare quality systems get caught.

For organizations building a healthcare quality management system from scratch, MSI's overview of ISO 7101 healthcare quality consulting covers what certification involves, and the companion piece on ISO 7101 service design controls covers the delivery side of the same architecture.


Argument One

Why “Annual” Is Never a Frequency for Evaluation of Compliance

Decide. Record. Defend.

Open almost any compliance obligations register and scroll the frequency column. Annual. Annual. Annual. Annual. Forty rows, one word, repeated.

The problem is not that annual is wrong. For a great many obligations annual is exactly right. The problem is that a column of identical values with no recorded reasoning is indistinguishable from a default, and a default is the one thing Clause 9.1.2 a) specifically does not permit. The clause requires the organization to determine the frequency. Determination is an act. If nobody performed the act, the register is reporting a habit and calling it a decision — and the auditor gets to discover that by asking one question: why annual for this row?

Direct Answer: How often should evaluation of compliance be carried out? There is no prescribed interval in any of the three standards. Evaluation of compliance is carried out at a frequency the organization determines and records for each obligation — and never less often than any monitoring, inspection or examination interval the obligation itself prescribes.

The Four Factors That Actually Set the Interval

Consequence of failure. An obligation whose breach means a fatality, a licence condition, or a reportable release does not get evaluated on the same cycle as one whose breach means a late form. Rank by what happens when you are wrong, not by how much effort the check takes.

Rate of change in the requirement. Some duties are static for a decade. Others move with permit renewals, regulatory amendment cycles, or contractual review dates. A requirement that changes twice a year evaluated once a year is evaluated against a version that no longer exists half the time.

Rate of change in your own operation. New line, new site, new substance, new service, new contractor population. Compliance status against a stable requirement still moves when the operation underneath it moves. This is the factor most registers ignore entirely, and it is the reason a planning-of-changes process and evaluation of compliance need to be wired to each other rather than run in parallel ignorance.

Prior results. An obligation that has returned a clean result for six consecutive cycles has earned a longer interval. One that returned a partial result last time has earned a shorter one. A frequency that never responds to its own history is not being determined; it is being inherited.

The Two Standing Rules That Prevent Most Findings

Rule one: never longer than the obligation's own interval. If a regulation prescribes a monthly inspection, evaluation of compliance for that duty cannot be annual. It is arithmetically impossible to conclude in March that you were compliant across twelve monthly cycles you never looked at. This sounds obvious written down. It is violated in most registers, and the next section shows exactly how.

Rule two: a recorded reason beside every interval. One short sentence per row. “Quarterly — permit condition changes at each renewal and last two cycles returned partial.” That sentence converts a habit into a determination, and it is the cheapest single improvement available to any compliance obligations register in existence. It also survives staff turnover, which the reasoning inside somebody's head does not.


Argument Two

The Part of Evaluation of Compliance Almost Nobody Implements

State. Not. Record.

Clause 9.1.2 c) asks the organization to maintain knowledge and understanding of its compliance status. Not to have evaluated. To know, on an ongoing basis, where it stands.

Nearly every certified organization can produce last year's evaluation of compliance. Very few can say what their compliance status is this morning. Auditors write the finding up against 9.1.2; organizations read it and think but we did the evaluation — and they did. They did part b) and part d) and they skipped part c) without ever deciding to.

Direct Answer: Compliance status is the organization's current position against its obligations, held continuously between exercises of evaluation of compliance. It is a state rather than a document, and Clause 9.1.2 c) of ISO 14001 and ISO 45001 requires it to be maintained — which means a system that can only report the date of the last evaluation has not met the requirement.

Why This Fails Structurally, Not Through Carelessness

It is tempting to read this as a discipline problem. It is not. Competent, diligent organizations with strong systems fail this requirement for four architectural reasons, and naming them is more useful than exhorting anybody to try harder.

It is a state, and management systems are built to produce records of events. Every other clause in the standard you satisfy leaves an artifact behind — a report, a minute, a signed form. A state leaves nothing behind, because it is not something that happened. There is no natural artifact, so nothing gets created, so nothing gets audited internally, so the absence is invisible until an external assessor asks the question directly.

It has no obvious owner. A record has an author. A state has a maintainer — and no organization appoints one, because the role never appears in the clause and never appears in a job description. The evaluation of compliance exercise has an owner. The condition between exercises has nobody.

It cannot be produced retrospectively. This is the one that catches good organizations. Most audit evidence is assembled shortly before it is needed, and that works because the underlying events genuinely happened and the documentation is catching up. Compliance status does not work that way. You cannot reconstruct on Thursday what your position was on Monday, because on Monday nobody was holding it. The gap is unrecoverable by definition, which is why the fix has to be built before it is needed rather than found afterward.

An honest register reports unflattering numbers. A register with a not yet evaluated state will, on any given morning, show a number of rows sitting in it. That is uncomfortable to look at and uncomfortable to show a customer. Systems that only report favorable states feel safer to build, and they are worthless the first time anybody asks a real question. This is the quiet reason the field does not exist in most registers: somebody thought about adding it and decided they did not want to see the answer.

A register that can only show favorable states is not a picture of compliance. It is a picture of the last time somebody had time.

The Fix Is One Field and One Rule

Every entry in the register carries a next-due date. Any entry that passes its next-due date reverts automatically to not yet evaluated. That is the entire mechanism.

What it buys is disproportionate to what it costs. The register stops reporting history and starts reporting position. On any morning, anybody can look at it and see three groups: obligations currently evaluated and met, obligations currently evaluated and not met, and obligations whose status is genuinely unknown because the evaluation of compliance for them is overdue. That third group is the honest answer to the auditor's question, and an organization that can name it is in materially better shape than one that cannot — even when the group is large. “We know of eleven duties whose current status we cannot assert, here they are, here is when each is scheduled” is a controlled system. “Everything says compliant” with a stale evaluation behind it is not.

A four-state model works better than a binary in practice: met, at risk, not met, and not yet evaluated. The at risk state is what lets an organization act before there is a nonconformity to act on — a trajectory heading the wrong way against a target with time still on the clock is a preventive action, not a corrective one, and collapsing it into met because it has not failed yet destroys the only warning the system was ever going to give you. MSI's guide to building a risk management procedure that works in practice covers the register-design principle underneath this: a structure that cannot represent a state will never record one.

One more design note, because it decides whether the mechanism survives its first year. The next-due date belongs to the obligation, not to the evaluation cycle. If a single annual exercise sets every next-due date to the same day twelve months out, you have rebuilt the annual habit with extra steps. The dates should be staggered by the four factors above, which means the register produces a rolling workload rather than one enormous week. Organizations that get this right find the evaluation of compliance workload roughly halves in perceived effort while roughly doubling in coverage, because the work is distributed rather than survived.


Argument Three

Evaluation of Compliance Is Not Your Internal Audit

Different question. Different evidence.

This is the most common structural misunderstanding in the clause, and it is expensive because organizations that make it believe they have covered a requirement they have not touched.

Direct Answer: Is evaluation of compliance the same as an internal audit? No. Evaluation of compliance asks whether the organization is meeting its compliance obligations. An internal audit under Clause 9.2 asks whether the management system conforms to the standard and to the organization's own requirements and is effectively implemented. They ask different questions, examine different evidence, and produce separate results that cannot substitute for one another.

Consider the same subject examined both ways. An internal auditor looking at lifting equipment asks whether a procedure exists, whether it reflects the standard, whether records show it being followed, and whether the people doing the work are competent and understand it. A compliance evaluator looking at the same lifting equipment asks whether every statutory examination that was due has happened, on every item, within the interval the regulation prescribes.

Both are legitimate. Neither answers the other's question. A management system can be entirely conforming and still be in breach — the procedure is excellent, everybody follows it, and it prescribes an interval longer than the law allows. Equally, an organization can be meeting every duty it holds through the sheer competence of individuals while running a management system that would not survive a Clause 9.2 audit for five minutes. The two findings are independent, and any system that produces only one of them is blind in one eye.

The practical consequence is that evaluation of compliance results and internal audit results are separate records with separate retention, and the evaluation of compliance record should name the evidence examined rather than only the conclusion reached. “Reviewed and found compliant” is not a result. “Examined the twelve monthly rope inspection certification records for crane 4 against the interval at 29 CFR 1910.179(j); all present and within interval” is a result, and it is a result a successor can verify without repeating the work.

There is a scheduling relationship worth exploiting even though the two exercises stay distinct. ISO 19011:2026 raised the bar on internal audit programs, including the requirement that each audit state defined objectives, and an audit whose stated objective includes verifying that the evaluation of compliance process is being run as designed is a legitimate and efficient use of that requirement. The internal audit does not perform the evaluation of compliance. It checks that the evaluation of compliance happened, on schedule, by the determined method, with results retained. MSI's guidance on internal audit planning across multiple standards and on running effective internal audits covers how to schedule the two so they reinforce rather than duplicate.

One more distinction that catches integrated systems. Management review is a third thing again. Clause 9.3 asks leadership to consider the organization's fulfilment of its compliance obligations — not to be shown the register, but to be shown the trend. MSI's article on management review procedures that prove the review happened works through why presenting a compliance register as a review input satisfies the sentence on its face and misses what the clause is asking for.


Worked Example One

The Register That Was Technically Correct and Never Evaluable

One row. Fourteen duties.

A manufacturer holds fourteen items of lifting equipment across two buildings — overhead cranes, hoists, and the sling inventory that goes with them. Its ISO 45001 compliance obligations register handles all of it in a single row. The row names the regulation. Status: compliant. Frequency: annual. Last evaluated: eleven months ago.

Nothing in that row is false. The regulation is correctly identified, the entry is in the register, the evaluation of compliance was performed and recorded on schedule. An auditor skimming for completeness sees a register that covers lifting equipment, and an evaluation of compliance that ran on time. So does the safety manager, which is the harder problem.

What the Single Row Concealed

Statutory examination intervals for this equipment are not annual and are not uniform. Under 29 CFR 1910.179, overhead and gantry crane inspections divide into frequent inspections at daily-to-monthly intervals and periodic inspections at one-to-twelve-month intervals depending on service; running ropes require a thorough inspection at least once a month with a certification record naming the date, the inspector's signature and the rope inspected. Under 29 CFR 1910.184, slings must be inspected each day before use by a competent person, and alloy steel chain slings require a thorough periodic inspection at intervals no greater than twelve months, with the employer maintaining a record of the most recent month in which each sling was inspected. The published standard text sets these out per item, per type, per duty.

So the single row saying compliant, annual was making a claim about a family of duties running on daily, monthly and up-to-twelve-month clocks across fourteen distinct assets. When the register was finally decomposed, three items were overdue — one of them by four months. The row had read compliant throughout.

The detail that makes this example worth telling is what the operators knew. Two of them were aware of one overdue item. They had assumed it was being handled, because it appeared on a register that said compliant and nobody had told them otherwise. There was no route in the system for a person on the floor to say this one is late and have it reach the compliance status. ISO 45001 anticipates exactly this at Clause 5.4 d) 4), which requires consultation with non-managerial workers on determining and taking action on compliance obligations — the requirement ISO 14001 has no equivalent of, and the one most often satisfied on paper by a committee of supervisors. The workers closest to the hazard held information the compliance status needed and had no channel into it.

A register that shrinks the number of things you can be found against does not reduce your exposure. It reduces your visibility of it.

The correction: one row per duty per asset, not one row per regulation. The register grew substantially and became evaluable for the first time. Each row carried its own interval, drawn from the regulation rather than from the review calendar, and its own next-due date. The overdue items surfaced immediately — which is the point. Every row that reverts to not yet evaluated on its own schedule is a row that can no longer hide inside an aggregate.

The generalizable rule: granularity in a compliance obligations register is set by the finest interval any duty inside it carries. If one duty in a row runs monthly, the whole row runs monthly or the row splits. Most organizations set granularity by how the regulation is titled, which is a filing convention, not a compliance decision. The ISO 45001 legal requirements and evaluation of compliance procedure template builds the decomposition rule and the worker-consultation route into the procedure itself, so the register cannot be constructed at the wrong granularity by accident.

Figures in this example are illustrative and drawn from a fictional organization. They are not MSI client outcomes.


Worked Example Two

The Obligation the Organization Created for Itself

Published. Cited. Binding.

The second example has a completely different shape, which is why it is here. Nothing was technically wrong. The register was well built, the intervals were reasoned, the evaluation of compliance ran on schedule. The exposure arrived from outside the compliance function entirely.

The organization published a waste diversion target on its website. Marketing wrote it. It was subsequently cited in two customer tenders as evidence of environmental performance. It was not in the compliance obligations register, because nobody in the environmental function thought of it as a compliance matter. It was one, and had been from the day it was published.

Why a Voluntary Commitment Is a Compliance Obligation

ISO 14001 defines compliance obligations as legal requirements and other requirements — and other requirements explicitly include commitments the organization adopts voluntarily. The decision to publish the target is the decision to comply with it. There is no separate step where the organization elects to be bound.

In the United States there is a second edge to this that environmental managers frequently do not know about. A published environmental performance claim is an environmental marketing claim, and the Federal Trade Commission's Green Guides, codified at 16 CFR Part 260, address how such claims are interpreted and what substantiation they require. The Guides do not themselves bind, but claims inconsistent with them may be treated as unfair or deceptive under Section 5 of the FTC Act, and the Commission has periodically reviewed and sought comment on them through the Federal Register. A diversion figure published on a website and repeated in a tender is precisely the kind of claim that needs substantiation on the day it is made and on every day it remains published. Evaluation of compliance is the process that produces that substantiation, and if the target is not in the register the substantiation does not exist.

When the target was finally entered into the register and evaluated, the first result came back at risk: the rolling diversion rate was running below the interim figure the organization had published, with fourteen months left to close the gap. That is not a nonconformity. Nothing had been breached — the commitment ran to a future date and the trajectory was still recoverable. What it triggered was a preventive action, opened against a trend rather than against a failure, with more than a year of runway to act in.

Under a binary register, that result does not exist. The target is either met or breached, it was not yet breached, so it would have been recorded as met and reviewed again twelve months later — two months before the deadline, with no time to do anything. The four-state model is what converted a future crisis into a present workstream, and it is the clearest single argument for building the at risk state that most registers omit.

Obligations arrive through marketing, sales and service design far more often than through the environmental or safety function — and they enter the management system only if somebody built a route.

The correction: a standing intake route into the compliance obligations register from the three functions that create obligations without noticing — marketing, sales, and service or product design. In practice this is a single question added to existing approval steps: does this commit us to anything measurable? If yes, it goes in the register before it goes on the website. Cheap, unglamorous, and it closes the largest blind spot in most environmental management systems. The ISO 14001:2026 compliance obligation procedure template carries the intake route as a defined step rather than as advice.

Organizations working through the 2026 revision have a natural moment to build this, since they are already in the files. MSI's coverage of ISO 14001:2026 ecosystem health requirements and of continual improvement under the new edition covers the adjacent changes worth handling in the same pass, and the combined ISO 9001 and 14001 transition plan covers sequencing when both revisions land in the same window.

Figures in this example are illustrative and drawn from a fictional organization. They are not MSI client outcomes.


Healthcare

Does ISO 7101 Require Evaluation of Compliance?

No clause. Ten duties. One question.

Direct Answer: ISO 7101:2023 contains no evaluation of compliance clause and no compliance obligations clause. It nonetheless imposes statutory and regulatory duties across ten clauses, and Clause 5.1 q) makes top management responsible for requesting evidence of compliance — so a healthcare organization needs an evaluation of compliance process to answer a question its own standard obliges leadership to ask.

Healthcare organizations reading the table earlier in this article sometimes conclude they are off the hook. The opposite is true, and for a reason worth stating plainly: healthcare is among the most heavily regulated environments any management system operates in, and ISO 7101 is the standard that gives its practitioners the least structural help in tracking that regulation.

The duties are distributed rather than absent. Clause 4.1 puts statutory and regulatory requirements into the organization's context. Clause 5.5 carries them into organizational roles. Clause 7.2 f) reaches competence. Clause 7.5.6 d) reaches documented information. Clause 8.2.1 j) and q), Clause 8.3.1 a), Clause 8.7 e) and Clause 8.12.8 d) reach into service planning, design, delivery and specific care processes. Clause 1 a) frames the whole standard around consistently meeting applicable statutory and regulatory requirements. Ten places, no register, no frequency requirement, no method requirement, no retention requirement — and a top management duty at 5.1 q) to request the evidence.

The practical failure mode in healthcare is the licence with conditions. A facility licence carrying dozens of individual conditions gets recorded as one register row naming the licence. The organization holds every one of those conditions as a separate duty and reports on one. It is the same failure as the lifting equipment row in the first worked example, at a scale that makes it worse: decomposing a licence with thirty-four conditions turns one row into thirty-four, and the organization discovers it was always holding thirty-four duties and always reporting on one.

The sensible approach for an ISO 7101 organization is to borrow the ISO 45001 architecture wholesale, since it is the most demanding of the three and costs nothing extra to adopt: a register at duty-level granularity, a determined frequency with a recorded reason, a determined method, retained results, and a maintained compliance status with the four states. Nothing in ISO 7101 prohibits it and Clause 5.1 q) effectively presumes it. The ISO 7101 evaluation of compliance procedure template and guide maps the ten duty-imposing clauses to a single process, which is the part healthcare teams otherwise have to assemble themselves from a standard that never gathers them in one place.

Health systems that hold vendor relationships face the mirror image of this problem when assessing suppliers, which MSI covers in its work on remote patient monitoring compliance — the questions you ask a vendor about their compliance evidence are the questions you should already be able to answer about your own.


The Standard to Hold

What Good Evaluation of Compliance Looks Like: Eight Elements

Eight. Elements. Measurable.

Across 200+ audits attended in 28 years, MSI client experience suggests that organizations whose evaluation of compliance holds up under assessment tend to be strong on the same eight elements, and organizations that struggle tend to be weak on the same ones. Naming them separately matters, because it stops the improvement conversation collapsing into a single verdict. Almost nobody is uniformly weak.

One — Granularity. One row per duty per asset or per condition. Not one row per regulation, per licence, or per topic.

Two — Determined frequency with a recorded reason. One sentence per row explaining the interval. The sentence is the evidence that a determination occurred.

Three — Determined method. Who examines what evidence, against which requirement, and what constitutes a pass. Mandatory under ISO 45001, and worth adopting under the others.

Four — Four states, not two. Met, at risk, not met, not yet evaluated. The register must be able to represent a state before it can ever record one.

Five — Next-due dates that expire. Every entry carries one, and passing it reverts the entry automatically. This is the mechanism that makes compliance status a maintained state rather than a remembered one.

Six — Intake routes from outside the function. Marketing, sales and design can create obligations. A register fed only by the compliance function will always be missing the ones that hurt most.

Seven — Results that name evidence. The record states what was examined, not only what was concluded. A conclusion nobody can retrace is an opinion with a date on it.

Eight — A worker or staff route into the status. Required explicitly by ISO 45001 at Clause 5.4 d) 4), and valuable everywhere. The people closest to the duty usually know before the register does.

Scoring yourself honestly against those eight is harder than reading them, because the weak one is rarely the one you expect. The Compliance Obligations Maturity Check scores all eight in about five minutes, returns a level for each rather than a single verdict, and names the one to fix first. Free, no document upload, and it works whether your evaluation of compliance runs under ISO 14001, ISO 45001 or ISO 7101.

Direct Answer: What records does evaluation of compliance require? ISO 45001 requires documented information on the results to be retained; ISO 14001 requires evidence of the results to be available. Either way the record should name the evidence examined and the requirement it was examined against, not only the conclusion reached — a result a successor cannot retrace is not usable evidence.

A procedure that carries all eight is not longer than one that carries three. It is differently shaped. This is the general principle MSI sets out in its work on what makes an ISO procedure effective: length is not the variable that matters, and a document that is complete but not evaluable has met the wrong test.


Practical Next Steps

Where to Start on Monday

Three actions. One week.

Action one — find your widest row. Open the register and identify the entry covering the largest number of distinct duties. It is usually a regulation with per-asset requirements, a licence with conditions, or a permit with multiple limits. Decompose that one row. Do not decompose the whole register in week one; decompose the worst offender and see what surfaces. What surfaces will tell you how much of the rest needs the same treatment.

Action two — add the next-due column and let it expire. One field. Populate it from each row's determined interval and last evaluation date. Then look at what is already overdue. That number is your honest starting position, and seeing it once is worth more than any amount of discussion about whether the process is working.

Action three — ask marketing what the company has promised. One conversation, thirty minutes. Ask for every published environmental, safety, quality or service commitment that carries a number or a date. Check each one against the register. In MSI's experience this conversation produces at least one obligation the compliance function did not know it held, and organizations typically report it is the single highest-yield half hour in the whole exercise.

None of these three requires software, budget approval, or a consultant. They require somebody with authority to look at the register honestly for one week. If what you find is larger than a week's work — and for organizations decomposing a licence or a multi-asset regulation it usually is — that is the point at which structured ISO consulting support earns its cost, because the sequencing decisions about what to fix first are harder than the fixes.


Build It Instead of Drafting It

Get the Procedure That Already Passes These Eight Tests

Every element in this article — duty-level granularity, recorded frequency reasoning, a determined method, four status states, expiring next-due dates, intake routes, evidence-naming results, and the worker consultation route — is already built into MSI's compliance obligation procedure templates. Each one ships as an editable procedure with the register structure, the forms, and a worked example, so the decisions in this article are made rather than described.

Not sure which you need? Start with the free Compliance Obligations Maturity Check — eight scored elements, about five minutes, and it tells you which of the four procedures below matches where your system actually is.

Browse the full ISO procedure templates and guides library → — every procedure family MSI publishes, across all five standards, with the standard-by-standard variants laid out side by side.

Or go straight to the one you need:

If your transition to the 2026 edition is the reason evaluation of compliance is on your desk this quarter, MSI's ISO 14001:2026 Transition course walks a certified environmental management system through every change that touches the clause. Healthcare teams starting from a standard that never gathers its regulatory duties in one place will get more out of the ISO 7101 Overview course first. For organizations that would rather have the whole path run for them, SurePath covers implementation end to end. To talk through where your own register sits before committing to anything, call MSI for a planning session at 760-434-9141.


Questions

Evaluation of Compliance: Frequently Asked Questions

Asked. Answered. Honestly.

Is evaluation of compliance the same as an internal audit?

No. Evaluation of compliance asks whether the organization is meeting its compliance obligations. An internal audit under Clause 9.2 asks whether the management system conforms and is effectively implemented. A system can be fully conforming and still in breach, and an organization can be meeting every duty while running a management system that would fail an audit. The results are separate records and one cannot substitute for the other.

Our register says annual for everything. Is that a problem?

It is a problem if no reason is recorded beside any of the intervals, because Clause 9.1.2 a) requires the frequency to be determined and a uniform column with no reasoning is indistinguishable from a default. It is also a problem wherever an obligation prescribes its own shorter interval — a duty requiring monthly inspection cannot be evaluated annually. Annual is often the right answer; it just has to be an answer somebody gave.

Does an ISO certificate demonstrate regulatory compliance?

No, and this is the most consequential misunderstanding in the whole area. A certificate demonstrates that a management system conforms to the standard. It does not certify that the organization is compliant with any law, permit or licence. ISO 14001 and ISO 45001 require the organization to run its own evaluation of compliance precisely because certification does not perform that function. Customers and regulators who read a certificate as a compliance guarantee are reading it wrong, and organizations that let them are accumulating a risk they did not price.

What is the difference between compliance obligations and legal requirements?

Legal requirements are the subset imposed by law — statutes, regulations, permits, licences, consent orders. Compliance obligations is the wider term, covering legal requirements plus other requirements the organization adopts: customer contract terms, industry codes, group policies, and voluntary commitments the organization publishes about itself. The voluntary category is where most missed obligations live, because it enters through functions that do not think of themselves as compliance functions.

Does ISO 7101 have a compliance obligations clause?

No. ISO 7101:2023 has neither a compliance obligations clause nor an evaluation of compliance clause. It imposes statutory and regulatory duties in ten separate clauses instead, and Clause 5.1 q) makes top management responsible for requesting evidence of compliance. Healthcare organizations therefore need the process even though no clause names it, and the practical route is to adopt the ISO 45001 architecture, which is the most demanding of the three and costs nothing extra to follow.

How many entries should a compliance obligations register have?

There is no target number, and chasing a small one is actively harmful. The right granularity is one row per duty per asset or per condition, which means the count is a consequence of your operation rather than a design choice. Registers usually grow substantially when decomposed correctly — a licence recorded as one row can hold dozens of conditions. A shorter register does not mean fewer duties; it means fewer duties you can see.

Who should carry out evaluation of compliance?

Whoever can competently examine the evidence for that duty, which is frequently not the management representative. Independence in the internal audit sense is not required — the person who maintains the equipment can evaluate whether the statutory examinations happened. What the determined method needs to state is who does it and what they examine, so the answer is documented per duty rather than assumed to be one person for everything. Concentrating all of it in one role is the most common reason evaluation of compliance falls behind.


Related Reading

Continue Building the System

References and Primary Sources

About Management Systems International (MSI)

Diana Lynn is President and Principal ISO Consultant at Management Systems International (MSI), a veteran-owned, female-owned ISO consulting firm she co-founded in 1998. With 28 years of experience including extensive AS9100 work in MSI's early years, MSI's track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries. Today MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality.

msi-international.com  ·  760-434-9141

© 2026 Management Systems International, LLC · All rights reserved.

Share this post:
post by:
Picture of Diana Lynn

Diana Lynn

Founder and Principal of Management Systems International (MSI), a veteran-owned, female-owned ISO consulting firm she founded in 1998. Diana implements management systems, conducts audits, and develops MSI's entire training curriculum — 80+ organizations certified, 200+ audits, and 600+ professionals trained across manufacturing, technology, aerospace, medical device, government, healthcare, defense, and other regulated industries.
In This Guide
Stay Informed

Join our early-access list for ISO 14001:2026 briefings.

Trusted by Global Leaders

Don't miss our latest news!

Get on our Email list. MSI emails new offers, training dates, and ISO updates to our list before anyone else.

Twenty-eight years of practice, written down.
New: complete ISO procedure templates and guides. 13 procedure topics, five standards and combos, editable Word — with the judgment calls already made.
See the templates →

Buy any Template Packages and the price is credited 100% to ISO Consulting Projects, SurePath or SureResults Online or Traditional. Terms apply