Regulatory Change Management: Why EHS Registers Always Lag

EHS Compliance Obligations · ISO 14001:2026 · ISO 45001

Detect. Decide. Document.

Regulatory change management is the process an environmental, health and safety management system uses to detect a change in the law, decide whether it applies, and drive it into controlled action before the compliance date — and it is the single most commonly missing process in an otherwise mature EHS management system. Most organizations have a compliance obligations register. Very few have a documented mechanism that keeps it current. The register is a photograph; regulatory change management is the camera that keeps taking new ones.

Direct Answer: Regulatory change management is the documented process by which an organization monitors legal and regulatory developments, evaluates whether each development creates or modifies a compliance obligation, and converts applicable changes into planned actions, revised procedures, updated controls and refreshed competence. Under ISO 14001:2026 it sits at the junction of Clause 6.1.3 (compliance obligations), Clause 6.3 (planning of changes) and Clause 9.1.2 (evaluation of compliance). Under ISO 45001 the equivalent duty is to keep legal and other requirements up to date. Neither standard names the process, which is precisely why so many systems do not have one.

There is no better live illustration of the problem than the Toxic Substances Control Act, which is being revised right now on three tracks at once — in Congress, at the U.S. Environmental Protection Agency, and in federal court. Nobody can tell you today what the law will say a year from now. That uncertainty is not a reason to wait. It is the case for having a process that does not depend on knowing.

This article walks through what is actually on the table, sets out four possible outcomes rather than one prediction, and then shows the operational answer that is identical in every branch. That last part is the point. Good regulatory change management means your response to a proposed rule does not change based on which version passes.


The Missing Process

What Is Regulatory Change Management in an EHS Management System?

Inputs. Judgment. Evidence.

Ask most EHS managers to show you their compliance obligations process and they will open a spreadsheet. Permit numbers, statutory citations, reporting deadlines, a column marked compliant. That artifact answers one question well: are we meeting what we already know about? It answers a second question not at all: how does something new get in here?

That second question is regulatory change management, the discipline that keeps the register honest, and it decomposes into five distinct decisions, each of which needs an owner and a record:

1. Detection. Which sources are monitored, by whom, how often. A rule you never saw is not a compliance failure of diligence — it is a compliance failure of design.

2. Applicability. Does this touch our aspects, our substances, our workers, our sites? Recorded as a determination with a rationale, not an assumption.

3. Impact. What in the system has to move — a procedure, a control, a monitoring interval, a training module, a supplier specification, a capital project.

4. Planned change. The action, sequenced against the compliance date, with resources named. This is where ISO 14001:2026 Clause 6.3 does real work.

5. Closure and verification. The register entry updated, the evaluation frequency set, the evidence retained. Otherwise the whole exercise is an email thread.

Each of those five regulatory change management steps is a decision point where an audit finding can be written, and each is separately auditable. A system with a beautiful register and no regulatory change management process is a system that can prove yesterday and nothing else. MSI's guide to evaluation of compliance covers the downstream half of this — how often you check and against what — and the two processes only work when they are designed together.

A register with no change process tells an auditor what you knew on the day you built it. Nothing more.


Why The Lag Happens

Why Does the Compliance Obligations Register Always Lag Behind the Law?

Structural. Predictable. Fixable.

Direct Answer: Compliance obligations registers lag because they are built as annual documents against a legal environment that changes continuously, and because regulatory change management is usually treated as an individual's habit rather than a defined process with an owner, a frequency and a record. When the person who reads the Federal Register leaves, the mechanism leaves with them.

Three structural causes of weak regulatory change management recur across the audits MSI has attended, and none of them is about effort or competence.

The Register Is Reviewed on a Calendar, Not on a Trigger

Annual review is the default setting for regulatory change management because annual review is easy to schedule. But regulations do not publish annually. A proposed rule with a 60-day comment period and an 18-month compliance runway can appear, close, finalize and start its clock entirely inside one review interval. The organization is not late because it was slow; it is late because the frequency was chosen for administrative convenience rather than against the rate of change in the underlying subject.

Proposals Are Filtered Out as Not Yet Real

This is the most expensive habit in EHS regulatory change management. A notice of proposed rulemaking is treated as news rather than as an input, on the reasonable-sounding logic that it is not law yet. But the window in which an organization can influence a rule, model its cost, plan capital, qualify a substitute chemistry or negotiate a supply contract is the proposal window. By the time it is law, the only remaining variable is how fast you can comply. Proposals belong in the process as watch items with owners — not in the register as obligations, which would be wrong, but in the pipeline that feeds it.

The Obligation Arrives Through a Door the EMS Does Not Watch

Not every input to regulatory change management is a statute. A customer contract clause, a corporate diversion commitment published in a sustainability report, a trade association code, a lender covenant — ISO 14001 treats a voluntary commitment as an obligation the moment the organization decides to adopt it. These arrive through sales, marketing, legal and finance, none of which report to EHS. A regulatory change management process that only monitors government sources will miss them structurally. MSI's work on ISO 14001 environmental aspects and on the ISO 14001 environmental policy both touch this boundary, because a policy commitment made at the top becomes an obligation the register has to carry.


The Live Case

What Is Actually Being Revised in the Toxic Substances Control Act?

Congress. Agency. Courts.

The Toxic Substances Control Act is the federal law governing the manufacture, import, processing, use and disposal of industrial chemicals. It was substantially amended in 2016 by the Frank R. Lautenberg Chemical Safety for the 21st Century Act, and those amendments are now at their ten-year mark. For regulatory change management purposes, three separate revision tracks are running simultaneously, which is why the picture looks confusing from the outside.

Track One: Congress, With a Hard Deadline

The fee provisions established in the 2016 amendments fund a substantial share of EPA's New Chemicals Program and expire on 30 September 2026. That expiration is the forcing function driving everything else.

Two legislative vehicles are in play. The House Energy and Commerce Subcommittee on Environment released a Discussion Draft of Legislation to Modernize the Toxic Substances Control Act and held a hearing on it on 22 January 2026. The Senate Committee on Environment and Public Works released the Toxic Substances Control Act Fee Reauthorization and Improvement Act of 2026 in late February and held a legislative hearing on 4 March 2026 . The committee's own summary of the discussion draft sets out its stated intent, and the committee maintains a standing TSCA resource page.

The Senate draft is the narrower of the two, concentrating on new chemical review under Section 5. It would extend fee authority for ten years, establish a tiered review framework so that lower-risk or well-characterized chemistries move faster than complex submissions, and authorize accredited third parties in parts of the review. The House draft is broader, reaching definitions, testing authority, existing-chemical management, inventory nomenclature and citizens' petitions.

The Four Changes That Would Matter Most Operationally

Across both drafts, four proposed changes would alter how risk is calculated rather than merely how fast:

  • The evidentiary standard. Current law directs EPA to act on new chemicals that may present an unreasonable risk. The proposals would require EPA to establish that unreasonable risk is more likely than not to occur.
  • Conditions of use. Language narrowing EPA's discretion to identify reasonably foreseen circumstances to those more likely than not to occur, which shrinks the set of exposure scenarios inside a risk evaluation.
  • Assumed regulatory compliance. Explicit direction to consider the effect of existing federal limits and not to assume noncompliance — including with Occupational Safety and Health Administration standards.
  • Judicial review timing. Making final risk evaluations immediately reviewable as final agency action, rather than deferring review until a Section 6 risk management rule is promulgated.

Both sides of the debate belong on an EHS watch list, and both arguments are on the public record and seriously made. Committee Republicans argue that a slow, unpredictable review process discourages the commercialization of newer and often safer chemistries and harms domestic manufacturing — and note that a single semiconductor involves hundreds of distinct chemistries moving through that queue. Committee Democrats and public health organizations counter that several provisions could weaken EPA's ability to act where data is thin, that the more likely than not standard shifts the burden at exactly the point of greatest uncertainty, and that third-party participation in reviewing chemicals raises conflict-of-interest questions.

Chemical & Engineering News covered the March hearing, and the written testimony submitted to the House hearing sets out the public health critique in detail. MSI takes no position on the policy question. The operational point is narrower and applies regardless of which view prevails: an EHS manager's regulatory change management process has to be able to absorb either result.

Track Two: EPA, Moving Without Congress

Independently of any legislation, EPA published proposed revisions to the procedural framework rule for conducting risk evaluations on 23 September 2025. The Federal Register notice proposes to rescind or revise portions of the 2024 rule, moving away from the whole-chemical risk determination approach and allowing scope to be narrowed by excluding particular conditions of use and exposures considered unlikely to result in unreasonable risk. The underlying regulation sits at 40 CFR Part 702 Subpart B, with the components of a risk evaluation specified at § 702.39. EPA's own risk evaluation program page is the authoritative status source, and the broader EPA site carries the docket links.

Alongside the framework rule, EPA has signalled proposed amendments to existing risk management rules for perchloroethylene, trichloroethylene and carbon tetrachloride, potential final rules for 1-bromopropane, N-methylpyrrolidone and Pigment Violet 29, and proposed risk management rules for formaldehyde and hexabromocyclododecane. For a facility using any of those substances, that is a live list, not background reading.

Track Three: The Courts

Several risk management rules are under judicial review, with decisions expected in the methylene chloride and chrysotile asbestos matters, and at least one case stayed while EPA develops revisions. A court can vacate, remand or uphold, and each of those does something different to a compliance date already sitting in your register. Litigation status is itself a monitoring input for regulatory change management, and almost nobody has it in their process.


Scenario Planning

What Are the Possible Outcomes, and How Would Each Affect Health and the Environment?

Branches. Consequences. Actions.

Direct Answer: Four outcomes are plausible: fee authority lapses with no bill; a narrow Senate bill passes; a broad House-style framework is enacted; or Congress does nothing and EPA finalizes its rules regardless. Health and environmental consequences differ meaningfully across the four. The regulatory change management actions an EHS manager should take do not — which is exactly why scenario planning is the right way to prepare for a statute in flux.

What follows are possible outcomes, not forecasts, and scenario branches are how mature regulatory change management handles a statute in motion. Nobody outside the process knows how this resolves, and anyone telling you otherwise is selling certainty that does not exist. The value of laying them out is that it makes the common denominator visible.

Outcome One: Fee Authority Lapses, No Bill Passes

If the legislative calendar closes without action, the fee provisions expire on 30 September 2026. Existing statutory duties do not change — TSCA remains the law and current rules remain in force. What changes is capacity. A programme losing a meaningful share of its funding runs slower, which affects prioritization, risk evaluation throughput and new chemical review timelines.

Possible health and environmental effect: slower review means chemistries of concern stay in commerce longer without a determination, and it also means safer substitutes wait longer to reach market. Both directions are real. Regulatory change management implication: your register does not change, but your watch list grows — a backlog is a queue of future obligations with unpredictable arrival dates, which argues for shorter monitoring intervals, not longer.

Outcome Two: A Narrow Senate Bill Passes

Fee authority is extended ten years, a tiered review framework is established for new chemicals under Section 5, and existing-chemical duties under Section 6 remain largely as they are. For regulatory change management, this is the outcome with the narrowest operational footprint for most facilities, because most facilities are downstream users rather than submitters of premanufacture notices.

Possible health and environmental effect: a faster path to market for new chemistries, with the protective question turning on how the tiers are defined and how much data a lower tier requires. Advocates of the approach argue substitution accelerates; critics argue that speed without data is where surprises come from. Regulatory change management implication: if you formulate, import or introduce new substances, your submission process and its lead-time assumptions change. If you do not, your register barely moves — but you should record the determination that it does not apply, because we looked and it did not affect us is only defensible if it is written down.

Outcome Three: A Broad House-Style Framework Is Enacted

This is the outcome with the widest consequences in both directions. The evidentiary shift to more likely than not, narrowed conditions of use, assumed compliance with existing federal limits, and immediate judicial reviewability of risk evaluations together change what a risk evaluation calculates, not just how quickly it gets calculated.

Possible health and environmental effect: the assumed-compliance provision is where the EHS-specific concern concentrates. If risk evaluations must presume that permissible exposure limits are being met, modelled worker exposure falls on paper. Many OSHA limits date to the early 1970s and are less protective than current toxicological understanding, so the presumption can produce a lower calculated risk without any change on the floor. Narrowing conditions of use similarly removes legacy uses, disposal pathways and general-population exposure from the arithmetic — the pathways that most affect communities near facilities. Supporters counter that assuming noncompliance with binding federal law is not a defensible modelling assumption either, and that immediate judicial review produces earlier legal certainty rather than years of downstream litigation.

Regulatory change management implication, and this is the important one: a lower federal determination does not lower your actual exposure. If your risk assessments have been relying on a federal finding as a proxy for a hazard judgment, that proxy weakens. Organizations running ISO 45001 already own an independent hazard identification duty that does not depend on what a federal risk evaluation concluded. That duty becomes more load-bearing, not less, in this branch. MSI's coverage of the ISO 45001 revision walks through where those obligations sit.

Outcome Four: Congress Stalls, EPA Finalizes Anyway

This branch is the easiest to overlook, and for regulatory change management it is arguably the most likely to produce near-term work. The framework rule revision, the solvent rule amendments and the pending risk management rules are agency actions on agency timelines. None of them needs a bill. A facility using perchloroethylene, trichloroethylene, carbon tetrachloride, N-methylpyrrolidone, formaldehyde or 1-bromopropane could see a compliance date move — forward or backward — without a single vote being taken.

Possible health and environmental effect: highly substance-specific. An extended compliance date for a solvent rule prolongs current exposure; a finalized worker protection programme reduces it. Regulatory change management implication: this is the branch that most clearly proves the general case. If your process only monitors legislation, you will miss it entirely, because nothing in Congress will have happened.

The common denominator across all four outcomes: an organization with a documented detection-to-action mechanism responds to whichever branch materializes in the same number of steps. An organization without one responds by scrambling, and scrambles differently each time.


Where It Lives In The Standard

Where Does Regulatory Change Management Sit in ISO 14001:2026?

Three clauses. One process.

Direct Answer: Regulatory change management is not a named clause in ISO 14001:2026. It is distributed across Clause 6.1.3, which requires the organization to determine and have access to its compliance obligations; Clause 6.3, the planning-of-changes requirement with no 2015 predecessor; Clause 9.1.2, evaluation of compliance; and Clause 9.3.2, which puts changes in compliance obligations into management review as an explicit input. Because it is distributed, it is frequently owned by nobody.

Understanding where regulatory change management lives in the text starts with the edition itself. ISO 14001:2026 was published on 15 April 2026 with a three-year transition running to roughly April 2029. The compliance obligations requirements at Clause 6.1.3 did not change materially in substance. What did change is the numbering around them — risks and opportunities moved to 6.1.4, planning of action to 6.1.5 — which breaks cross-references in most 2015-era procedures. MSI's ISO 14001 transition scoring guide covers the clause-by-clause movement, and the combined ISO 9001 and 14001 transition plan covers sequencing where both revisions land in the same window.

Clause 6.3: The Requirement That Transitions Quietly Delete

Clause 6.3, planning of changes, is the clause most directly built for regulatory change management, and it is the clause most transitions lose. The reason is mechanical: transitions are usually run from a mapping table, old clause in the left column, new clause in the right. A requirement that did not previously exist has nothing in the left column to map from, so it silently drops out of the project. The same thing happened to ISO 9001's contingency planning in an earlier cycle and a great many systems still do not have it.

A new or amended regulation is the textbook Clause 6.3 trigger. It is a change to the management system, it needs to be carried out in a planned manner, and the standard expects the purpose of the change, its potential consequences, the integrity of the system through the change, and the resources and responsibilities to be considered. If your regulatory change management process produces a record that answers those four points for each applicable change, you have satisfied 6.3 and 6.1.3 with one artifact rather than two.

Transition Your ISO 14001:2015 System to the 2026 Edition in a Week — Without Writing Seven Procedures From Scratch

The ISO 14001:2026 Procedure Templates and Guides package was built for exactly the reader of this article: an experienced EHS manager with a working system, a 2029 deadline, and no spare month to rewrite documentation. Complete editable Microsoft Word procedures covering the EMS end to end — leadership and commitment, aspect identification, compliance obligations, monitoring and measuring equipment, document and records control, purchasing and supplier control, operational control, human resource management — plus the Clause 6.3 change process that mapping-table transitions delete. The ISO 14001:2026 Transition course is included.

The judgment calls are already made. You edit the specifics, not the architecture.

See the ISO 14001:2026 Procedure Package →

The ISO 45001 Half of the Same Process

EHS managers rarely run one standard. ISO 45001 asks for access to up-to-date legal and other requirements and for that documented information to be maintained and retained — a live-currency duty. In practice this means a safety register that has not been reviewed against regulatory change in eighteen months is a finding in its own right, entirely separate from whether any individual duty is being met.

The two standards ask separately what changed in the obligations, and separately about results in meeting them. A management review that reports one compliance percentage has answered a fraction of what the two standards ask, and the change input is exactly where a new duty with an implementation deadline would have surfaced. Running one integrated regulatory change management process across both scopes is more efficient and more defensible than two registers that never quite agree — which is why MSI's integrated ISO 14001:2026 and ISO 45001 compliance obligations procedure handles both in one document. Single-standard versions exist for ISO 14001:2026 and ISO 45001 where only one applies, and the full ISO 45001 procedure package covers the safety system end to end.


The Mechanism

What Does a Working Regulatory Change Management Process Look Like?

Named. Scheduled. Recorded.

Direct Answer: A working regulatory change management process has seven components: a defined source list, a named monitor with a defined frequency, a triage rule separating proposals from enacted requirements, a recorded applicability determination, an impact assessment routed through planning of changes, an owner and date for each resulting action, and a closure record that updates the register and sets the evaluation frequency. Anything less produces activity without evidence.

One: Write Down the Sources

The regulatory change management source list is a controlled document, not a browser bookmark folder. For a typical manufacturing site it includes the Federal Register, the relevant agency programme pages, the state environmental and labour agencies for every site, the permit-issuing authorities, the standards bodies whose editions you are certified to, and — the one most often missing — the internal functions that create voluntary commitments. Each source gets a review frequency proportionate to how fast it changes.

Two: Name the Monitor and the Frequency

Assign regulatory change management to a role, not a person — roles survive turnover. Frequency should be set per source, and a rule worth adopting is that anything notifiable to a regulator gets monitored at least quarterly. Uniform annual monitoring across every source is the same design error as uniform annual evaluation of every obligation.

Three: Triage Proposals Separately From Enacted Requirements

Regulatory change management runs in two lanes. The register holds obligations that bind. A watch list holds proposals, drafts, pending litigation and announced agency intentions, each with an owner and a next-check date. The TSCA situation lives entirely in the second lane today — and every branch of it that matters to you will move to the first lane with a compliance clock attached.

Four: Record the Applicability Determination, Including the Negatives

This is the highest-value habit in the whole process and the one most often skipped. When a change does not apply to you, write down that you looked and why it does not apply. Auditors ask how you knew a regulation was out of scope far more often than they ask about the ones you captured. A regulatory change management log containing only positives looks identical to no process at all.

Five: Route Impact Through Planning of Changes

The regulatory change management impact assessment asks which procedures, controls, monitoring arrangements, competence requirements, supplier specifications and capital items are affected. Routing it through Clause 6.3 rather than handling it informally is what converts a memo into a planned change with resources and a date. It also means the same record satisfies two clauses. MSI's guidance on document control covers the version discipline that keeps the revised procedure from living in three incompatible copies.

Six: Assign Owner and Date Against the Compliance Clock

Regulatory change management schedules backwards from the compliance date, not forwards from today. Training has a lead time, equipment has a lead time, supplier qualification has a lead time, and permit modifications have a queue that is entirely outside your control. Organizations typically report that the binding constraint is rarely the paperwork — it is the item with a procurement or regulatory lead time that nobody sequenced.

Seven: Close the Loop Into the Register and the Evaluation Frequency

The new obligation enters the register with a determined evaluation frequency, an evaluation method and a named owner. This is the handoff from regulatory change management into evaluation of compliance, and it is where the two processes have to be designed as one document rather than two — because when they are split, the frequency column ends up in neither and nobody discovers it until an audit.

Score your own process before you rebuild it

MSI's compliance obligations maturity check scores where your current mechanism sits across the seven components above, in a few minutes and at no cost. Most EHS managers find the gap is at components three and four, not at the register itself.


Not Just TSCA

What Else Is Changing That Your Register Should Already Be Tracking?

Statutes. Standards. Schemes.

If TSCA were the only thing in motion, an EHS manager could handle regulatory change management by paying attention. It is not. A representative register in 2026 carries several simultaneous changes, which is the practical argument for a process rather than vigilance.

  • PFAS at state level. Reporting, labelling and commercial restriction requirements have proliferated across states on independent timelines, which means a multi-site organization faces a patchwork rather than a single federal date.
  • Federal PFAS rulemaking. Effluent guidelines revisions and drinking water regulation changes are separately in motion.
  • ISO 14001:2026. Published 15 April 2026; transition deadline roughly April 2029; certificates to the 2015 edition stop being issued well before that.
  • ISO 9001:2026. Reached Final Draft stage with the ballot closed 9 July 2026 and publication anticipated September 2026. The technical content is frozen but the text is not public and should not be quoted.
  • ISO 19011:2026. Published 27 May 2026 and withdrew the 2018 edition immediately, with no transition period — which means audit programme documents citing the 2018 edition are citing a withdrawn standard today.
  • ISO 45001. A revision is under development, so the current edition remains in force but the watch list entry should already exist.
  • Accreditation architecture. Global ACI assumed the former IAF and ILAC roles effective 1 January 2026, so documents referencing those bodies point at organizations that no longer operate under those names.

That is seven live items before a single site-specific permit renewal is counted. Handling them one at a time by reaction is how systems fall behind; handling them through one regulatory change management mechanism is how they stay current. MSI's coverage of the ISO 19011:2026 changes and the specific internal audit procedure edits the revision requires covers one of them in detail, and the risk management procedure guidance covers the register structure the 2026 edition expects.


Proving It

How Do You Prove Regulatory Change Management to an Auditor?

Records. Not intentions.

Direct Answer: You prove regulatory change management with four records: the source list with monitoring frequencies, the dated monitoring log including determinations that a change did not apply, the planned-change records for changes that did apply, and the management review minute showing changes in compliance obligations as an explicit input with a discussion, not a line item. An auditor who sees those four stops asking.

The common regulatory change management audit failure is not that organizations are non-compliant with a regulation. It is that they cannot demonstrate the mechanism by which they would know. An auditor's natural question — show me how a change in the law reaches this procedure — is answerable in about ninety seconds with the four records above and not answerable at all without them. MSI's guidance on internal audit planning covers how to sample this area deliberately rather than by clause traversal, which is how the gap usually stays hidden until a certification body finds it.

One further point on the management review input, because it is where regulatory change management most often dies quietly. Reporting a compliance percentage answers the results question and leaves the changes question untouched. The changes input is precisely where a new duty with an implementation deadline would surface for leadership attention — and if it is not surfaced there, the first time leadership hears about it is when the deadline is close enough to cost money. Linking this into ISO 14001 continual improvement is what turns compliance work into performance work.


Working With MSI

Where Does Outside Help Actually Shorten Regulatory Change Management Work?

Documented. Decided. Delivered.

The detection half of regulatory change management is yours — nobody outside your organization knows your substances, sites and contracts well enough to own it. The documentation half is where an outside firm compresses months into days, because the architecture of a compliance obligations procedure is the same across every organization that has one, and only the specifics differ.

MSI's ISO consulting practice is built on 28 years of implementation work: 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries. Those numbers matter here for one specific reason. A procedure written from 200+ audits encodes the questions auditors actually ask about regulatory change management — the applicability negatives, the frequency rationale, the management review changes input — rather than the questions the standard's text suggests they might.

Every Procedure, Every Standard, With the Judgment Calls Already Made

The full ISO Procedure Templates and Guides library covers ten procedure topics across ISO 9001, ISO 13485, ISO 14001, ISO 45001 and ISO 7101, plus the integrated versions that run two or three standards from one document set. Editable Microsoft Word, worked examples, records and forms included. Written as working documents an auditor can follow, not outlines you still have to finish.

Browse the Full Procedure Library →

Three Ways to Move From Here

  • Score it free. Run the compliance obligations maturity check and see which of the seven components you are actually missing.
  • Talk it through. Call MSI at 760-434-9141 to book a planning session. Bring your register and your source list — an hour on those two documents usually settles the scope question.
  • Hand over the whole programme. SurePath is MSI's turnkey certification engagement, and SureResults keeps the system current year-round once you hold the certificate — which is, in the end, what regulatory change management is for.

Executives weighing the transition as a business decision rather than a documentation exercise can watch MSI's ISO Executive Decision Briefs — short, leadership-level sessions on what certification costs, what it returns, and where the real risk sits.


Questions Answered

Regulatory Change Management: Frequently Asked Questions

Short. Direct. Useful.

Does ISO 14001:2026 require a documented regulatory change management procedure?

Not by that name. The standard requires the organization to determine and have access to its compliance obligations, to plan changes in a planned manner, and to evaluate compliance at determined frequencies. A documented procedure is the practical way to satisfy all three coherently, and it is what auditors look for, but the requirement is for the process and its records rather than for a document with a particular title.

Should proposed rules go in the compliance obligations register?

No — a proposal does not bind, and putting it in the register misstates your obligations. It belongs on a watch list that feeds the register, with an owner and a next-check date. Keeping the two lanes distinct is a core design feature of regulatory change management, and conflating them creates audit problems in both directions.

How often should an EHS team monitor for regulatory changes?

Per source, not uniformly. Set the frequency against how fast each source changes and how severe the consequence of missing something would be. A defensible baseline is quarterly for anything notifiable to a regulator or subject to active rulemaking, and annually for stable sources — with the rationale recorded so the interval is a decision rather than an inheritance.

What happens to my obligations if TSCA fee authority lapses in September 2026?

Your existing obligations do not change. TSCA remains in force and current rules remain binding. What a lapse would affect is EPA's capacity to run the programme, which changes the pace of future determinations rather than any duty you hold today. It is a watch list event, not a register event — which is a useful worked example of the distinction.

Could the proposed TSCA changes reduce protection for workers even where nothing on the floor changes?

That is the concern raised by public health and labour organizations, and it turns on the assumed-compliance provisions: if a risk evaluation must presume that existing federal exposure limits are being met, modelled exposure falls without actual exposure falling. Supporters respond that assuming noncompliance with binding law is not a sound modelling assumption either. Either way, an organization's own hazard identification duty under ISO 45001 is independent of what a federal risk evaluation concludes, and remains the more reliable basis for worker protection decisions.

Where does regulatory change management fit if we run ISO 9001, ISO 14001 and ISO 45001 together?

One process, one register with scope and jurisdiction fields, one management review input covering both changes and results. The standards share the Harmonized Structure, so the mechanism is common even though the obligation types differ — environmental duties follow the site and the product, occupational health and safety duties follow the site and the worker. Splitting the process by standard duplicates effort and produces registers that disagree.

Do customer contract requirements count as compliance obligations?

Under ISO 14001, a requirement the organization chooses to adopt becomes a compliance obligation once that choice is made — which includes contractual environmental clauses and published voluntary commitments. This is the category that most often bypasses the EHS function entirely, arriving through sales or marketing, and it is why the source list has to include internal functions and not only government bodies.

What is the single fastest improvement to a weak regulatory change management process?

Start recording the negatives. Log every change you reviewed and determined did not apply, with the reason. It takes minutes per entry, requires no new system, and converts an invisible process into an auditable one immediately. MSI client experience suggests this single habit closes more findings in this area than any other single change.


References and Primary Sources

Legislative and rulemaking status described in this article reflects publicly available information as of the publication date. Because all three tracks are active, readers should verify current status against the primary sources above before making compliance decisions. This article is general guidance and not legal advice.

About Management Systems International (MSI)

Diana Lynn is President and Principal ISO Consultant at Management Systems International (MSI), a veteran-owned, female-owned ISO consulting firm she co-founded in 1998. With 28 years of experience including extensive AS9100 work in MSI's early years, MSI's track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries.

Today MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality.

msi-international.com  ·  760-434-9141

Share this post:
post by:
Picture of Diana Lynn

Diana Lynn

Founder and Principal of Management Systems International (MSI), a veteran-owned, female-owned ISO consulting firm she founded in 1998. Diana implements management systems, conducts audits, and develops MSI's entire training curriculum — 80+ organizations certified, 200+ audits, and 600+ professionals trained across manufacturing, technology, aerospace, medical device, government, healthcare, defense, and other regulated industries.
In This Guide
Stay Informed

Join our early-access list for ISO 14001:2026 briefings.

Trusted by Global Leaders

Don't miss our latest news!

Get on our Email list. MSI emails new offers, training dates, and ISO updates to our list before anyone else.

Twenty-eight years of practice, written down.
New: complete ISO procedure templates and guides. 13 procedure topics, five standards and combos, editable Word — with the judgment calls already made.
See the templates →

Buy any Template Packages and the price is credited 100% to ISO Consulting Projects, SurePath or SureResults Online or Traditional. Terms apply