ISO 45001:2018 clause 6.1.3 Determination of legal requirements and other requirements

ISO 45001:2018 Requirements

The organization shall establish, implement and maintain a process(es) to:
a) determine and have access to up-to-date legal requirements and other requirements that are applicable to its hazards, OH&S risks and OH&S management system;
b) determine how these legal requirements and other requirements apply to the organization and what needs to be communicated;
c) take these legal requirements and other requirements into account when establishing,
implementing, maintaining and continually improving its OH&S management system.
The organization shall maintain and retain documented information on its legal requirements and other requirements and shall ensure that it is updated to reflect any changes.
NOTE Legal requirements and other requirements can result in risks and opportunities for the organization.

As per Annex A (Guidance on the use of ISO 45001:2018 standard) of ISO 45001:2018 standard it further explains

  1. Legal requirements can include:
    • legislation (national, regional or international), including statutes and regulations;
    • decrees and directives;
    • orders issued by regulators;
    • permits, licences or other forms of authorization;
    • judgments of courts or administrative tribunals;
    • treaties, conventions, protocols;
    • collective bargaining agreements.
  2. Other requirements can include:
    • the organization’s requirements;
    • contractual conditions;
    • employment agreements;
    • agreements with interested parties;
    • agreements with health authorities;
    • non-regulatory standards, consensus standards and guidelines;
    • voluntary principles, codes of practice, technical specifications, charters;
    • public commitments of the organization or its parent organization.

1) The organization shall establish, implement and maintain a processes to determine and have access to up-to-date legal requirements and other requirements that are applicable to its hazards, OH&S risks and OH&S management system;

To meet the requirement of establishing, implementing, and maintaining processes to determine and have access to up-to-date legal requirements and other requirements applicable to hazards, Occupational Health and Safety (OH&S) risks, and the OH&S management system, you can follow these steps:

  1. Identify and assign responsibilities to individuals or teams within your organization for tracking and staying informed about legal and other requirements related to OH&S. These individuals could be from the legal department, EH&S (Environment, Health, and Safety) team, or a dedicated compliance team.
  2. Determine which legal and other requirements are relevant to your organization based on your industry, location, and specific hazards and risks. This can include local, national, and international regulations, industry standards, and best practices.
  3. Establish a systematic approach for monitoring changes in relevant laws, regulations, and standards. This may involve subscribing to government updates, industry publications, and legal databases. Use technology tools and services that provide notifications for regulatory changes.
  4. Maintain comprehensive records of all identified legal and other requirements. Organize these documents in a structured manner, ensuring that they are easily accessible to relevant personnel. Keep records of when requirements were last reviewed and any updates made.
  5. Implement a periodic review process to assess the applicability and effectiveness of the identified requirements. Assess whether your organization is in compliance and if any changes are needed to align with new regulations or standards.
  6. Ensure that all relevant employees are aware of the identified legal and other requirements that pertain to their roles. Provide training and awareness programs as needed.
  7. Incorporate the identified legal and other requirements into your organization’s OH&S management system. This includes updating policies, procedures, and risk assessments to reflect compliance with these requirements.
  8. Encourage a culture of continuous improvement by using feedback mechanisms to capture insights from employees, audits, and incident investigations. Use this feedback to update your processes and stay current with evolving requirements.
  9. Consider seeking external expertise, such as legal counsel or OH&S consultants, to ensure your processes for determining and accessing legal requirements are effective and compliant.
  10. Ensure that your organization is prepared to respond promptly to any legal changes that may require immediate action, such as new safety regulations or reporting requirements.
  11. Document your organization’s processes for determining and accessing legal requirements and other relevant requirements. This documentation should be part of your OH&S management system documentation.
  12. Regularly audit and verify your organization’s compliance with legal and other requirements. Use these audits to identify any gaps or areas that require improvement.

Organizations can ensure they have access to up-to-date legal requirements and other requirements related to Occupational Health and Safety (OH&S) by implementing a systematic approach to compliance management. Here are steps to help achieve this:

  1. Legal Research and Monitoring: Assign responsibility to a dedicated team or individual to regularly monitor and track changes in OH&S regulations, laws, and standards. This can involve subscribing to government agencies’ newsletters, using legal databases, and following industry associations.
  2. Identify Relevant Authorities: Determine the specific governmental bodies, agencies, or industry groups that oversee OH&S regulations in your jurisdiction. Make sure to consider local, state, national, and international regulations that may apply to your organization.
  3. Regular Audits and Assessments: Conduct regular internal audits and assessments to evaluate your organization’s compliance with existing OH&S requirements. This can help identify areas where updates may be necessary.
  4. Documentation and Record-Keeping: Maintain comprehensive records of all relevant legal requirements, including legislation, regulations, codes of practice, and industry standards. This documentation should be organized, accessible, and regularly reviewed.
  5. Consult Legal Experts: Consider consulting legal experts or OH&S consultants who specialize in compliance. They can provide guidance on interpreting complex regulations and ensuring your organization’s adherence.
  6. Industry Associations and Networks: Join industry associations or networks related to your field. These organizations often provide members with updates on relevant regulations and best practices.
  7. Subscribe to Online Resources: Subscribe to online resources or databases that provide access to up-to-date legal and regulatory information related to OH&S. These resources may offer alerts and notifications for changes.
  8. Training and Education: Ensure that relevant personnel within your organization, including those responsible for compliance, undergo continuous training and education on OH&S requirements and updates.
  9. Integration into Management Systems: Integrate compliance with OH&S requirements into your organization’s overall management systems, such as ISO 45001 for Occupational Health and Safety Management Systems. This helps ensure that compliance is part of your organization’s culture and operations.
  10. Regular Review and Update: Set up a schedule for regularly reviewing and updating your organization’s policies, procedures, and practices to reflect any changes in OH&S requirements.
  11. Feedback and Reporting Mechanisms: Establish mechanisms for employees to report potential compliance issues or concerns. This can help identify areas that require attention.
  12. Collaborate with Legal Counsel: Maintain open communication with your organization’s legal counsel to ensure a proactive approach to compliance and to address any legal concerns promptly.

Below are some common examples of legal requirements and other requirements that organizations may need to consider:

Legal Requirements:

  1. Occupational Safety and Health Act (OSHA): In the United States, OSHA sets out legal requirements for workplace safety and health, covering topics such as hazard communication, fall protection, and respiratory protection.
  2. Workplace Health and Safety Regulations: Various countries have their own workplace health and safety regulations that specify requirements related to safety equipment, emergency procedures, and hazard assessment.
  3. Environmental Regulations: Depending on your industry, environmental regulations may require you to manage hazardous materials, emissions, and waste disposal in a way that ensures the safety of employees.
  4. Fire Safety Regulations: Fire codes and regulations require organizations to maintain fire prevention systems, conduct regular fire drills, and ensure proper exits and emergency lighting.
  5. Building Codes: Compliance with building codes is often required to ensure that the workplace is structurally safe and that there are appropriate fire prevention measures in place.
  6. Labor Laws: Labor laws may require organizations to provide safe working conditions, limit working hours, and establish rest periods.
  7. Transportation Safety Regulations: If your organization involves transportation, you may need to comply with regulations related to the safety of drivers, vehicles, and cargo.

Other Requirements:

  1. Industry Standards: Depending on your industry, there may be specific safety standards and guidelines that are considered best practices. For example, ISO 45001 provides a framework for OH&S management.
  2. Customer Requirements: Clients or customers may have specific safety requirements that you must meet as part of your contractual obligations.
  3. Supplier Requirements: Suppliers may have safety and quality requirements that must be adhered to when purchasing materials or products.
  4. Internal Policies and Procedures: Your organization may establish its own internal policies and procedures related to safety, such as a safety manual, incident reporting protocols, or emergency response plans.
  5. Certification Standards: To achieve certain certifications like ISO 14001 (Environmental Management) or ISO 9001 (Quality Management), you may need to adhere to specific OH&S requirements as part of the certification process.
  6. Risk Assessments and Hazard Analyses: Performing risk assessments and hazard analyses is often considered a best practice and may be required in certain industries or by internal policies.
  7. Emergency Response Plans: Developing and maintaining emergency response plans, which outline actions to take in case of various types of emergencies, is often recommended.
  8. Safety Training Programs: Employee training and awareness programs that cover safety procedures, hazard recognition, and emergency response are essential in many workplaces.

2) The organization shall establish, implement and maintain a processes to determine how these legal requirements and other requirements apply to the organization and what needs to be communicated

To establish, implement, and maintain processes that determine how legal requirements and other relevant requirements apply to the organization, you can follow these steps:

  1. Ensure that relevant personnel within your organization understand the OH&S legal requirements and other applicable requirements. Interpret these requirements in the context of your organization’s operations and hazards.
  2. Integrate OH&S legal requirements and other applicable requirements into your organization’s policies, procedures, and work instructions. This includes safety manuals, emergency response plans, and standard operating procedures.
  3. Conduct training programs and awareness campaigns to educate employees at all levels about the specific OH&S requirements that apply to their roles. This can include training on safety protocols, hazard identification, and compliance with regulations.
  4. Clearly define roles and responsibilities for ensuring compliance with OH&S legal requirements. Assign specific individuals or teams to oversee compliance, monitor progress, and address any non-compliance issues.
  5. Integrate OH&S requirements into your organization’s risk assessment processes. Identify potential risks associated with non-compliance and implement mitigation measures.
  6. Maintain accurate records of compliance activities, including inspections, audits, and incident reports related to OH&S. This documentation provides evidence of your organization’s commitment to compliance.
  7. Establish effective communication channels to inform employees about OH&S requirements, changes in regulations, and safety updates. Encourage reporting of safety concerns and incidents.
  8. Implement a monitoring system to track compliance with OH&S requirements. Regularly review and report on compliance status to senior management and relevant stakeholders.
  9. Foster a culture of continuous improvement by regularly reviewing and updating processes and procedures in response to changing requirements and lessons learned from incidents or near-misses.
  10. Consider conducting third-party audits or assessments to validate compliance with OH&S legal requirements. External audits can provide an objective evaluation of your organization’s compliance efforts.
  11. Ensure that your organization’s emergency response plans and procedures are aligned with OH&S requirements. Conduct drills and exercises to test the effectiveness of these plans.
  12. Develop protocols for addressing non-compliance issues promptly. This may involve corrective actions, root cause analysis, and preventative measures to avoid future non-compliance.
  13. Consult legal counsel or OH&S experts when interpreting and applying complex legal requirements to ensure that your organization’s actions align with regulatory expectations.
  14. Document and report compliance efforts regularly to demonstrate adherence to OH&S legal requirements to regulatory agencies, clients, or other relevant stakeholders as required.
  15. Encourage employees to provide feedback and participate in the improvement of OH&S compliance processes. Act on their suggestions and concerns.

To effectively communicate Occupational Health and Safety (OH&S) legal requirements and other requirements within your organization, you need a structured and comprehensive approach. Here’s how you can achieve this:

  1. Maintain a central repository for all OH&S legal requirements and other relevant requirements. This repository should include the full text of laws, regulations, standards, and any other applicable documents.
  2. Ensure that the documentation is kept up to date. Assign responsibility to a designated person or team to review and update the repository whenever there are changes in OH&S legal requirements or other relevant requirements.
  3. Make the documentation easily accessible to all employees who need it. Use digital platforms, such as an intranet or document management system, to store and distribute the information.
  4. Develop a clear communication plan outlining how and when OH&S legal requirements and other relevant requirements will be communicated to employees. This plan should detail the frequency, channels, and responsible parties for communication.
  5. Provide training and educational programs to ensure that employees understand the OH&S legal requirements that apply to their roles. Training can include workshops, seminars, e-learning modules, and on-the-job training.
  6. Launch awareness campaigns to highlight the importance of compliance with OH&S legal requirements. Use posters, newsletters, email updates, and other communication channels to reinforce the message.
  7. Hold regular OH&S meetings, toolbox talks, or safety briefings where you discuss and emphasize compliance with legal requirements. These meetings can serve as a platform for addressing questions and concerns.
  8. Ensure that senior management is actively involved in communicating the importance of OH&S legal requirements and other relevant requirements. Their support sets a strong example for the entire organization.
  9. Tailor communication to different employee groups. For example, specific legal requirements may apply to certain departments or job roles, so ensure that information is relevant to the audience.
  10. Establish channels for employees to provide feedback or seek clarification on OH&S legal requirements. Encourage open communication and address questions promptly.
  11. Implement a system to track and monitor compliance with OH&S legal requirements and other relevant requirements. This can include regular audits, inspections, and reporting mechanisms.
  12. Integrate OH&S legal requirements and compliance procedures into your organization’s policies and procedures. Make sure employees have easy access to these documents.
  13. Collaborate with external experts or consultants when needed to help interpret and communicate complex OH&S legal requirements effectively.
  14. If your organization has a diverse workforce, ensure that OH&S legal requirements and other relevant information are communicated in multiple languages as needed.
  15. Incorporate OH&S legal requirements into your organization’s emergency response plans, ensuring that employees understand their roles in case of emergencies.

3) The organization must take these legal requirements and other requirements into account when establishing, implementing, maintaining and continually improving its OH&S management system.

When establishing an Occupational Health and Safety (OH&S) management system, it’s imperative for the organization to consider and integrate relevant legal requirements and other applicable requirements. Here’s how to do it effectively:

  1. Identify and compile a comprehensive list of OH&S legal requirements that are applicable to your organization. This should include local, state, national, and international regulations, as well as industry-specific standards and codes of practice.
  2. Assess which of these legal requirements are directly applicable to your organization’s activities, products, services, and processes. Not all requirements may be relevant, so focus on those that directly impact your operations.
  3. Maintain well-organized records of these legal requirements. This documentation should be accessible and regularly updated to reflect changes in regulations.
  4. Integrate the applicable legal requirements into your organization’s OH&S policies, procedures, and processes. Ensure that employees are aware of and understand these requirements as they relate to their roles.
  5. Conduct a risk assessment to identify potential hazards and risks associated with non-compliance with OH&S legal requirements. Use this assessment to prioritize compliance efforts.
  6. Develop and deliver training programs to educate employees about the OH&S legal requirements that apply to their specific job functions. Ensure that employees understand their roles in compliance.
  7. Implement a system for ongoing monitoring of changes in OH&S legal requirements. Regularly review your compliance status and update your processes as necessary.
  8. Conduct regular audits or assessments to verify compliance with OH&S legal requirements. These audits should also evaluate the effectiveness of your OH&S management system in addressing these requirements.
  9. Establish clear communication channels to inform employees and stakeholders about OH&S legal requirements and compliance efforts. This includes reporting compliance status to senior management and relevant authorities as required.
  10. Foster a culture of continuous improvement by using feedback mechanisms to capture insights from employees, audits, and incident investigations. Use this feedback to enhance your compliance processes.
  11. Ensure that your organization is prepared to respond promptly to any legal changes that may require immediate action, such as new safety regulations or reporting requirements.
  12. Consult legal counsel or OH&S experts when interpreting and applying complex legal requirements to ensure that your organization’s actions align with regulatory expectations.
  13. Document and report compliance efforts regularly to demonstrate adherence to OH&S legal requirements to regulatory agencies, clients, or other relevant stakeholders as required.

By taking these steps, your organization can establish an effective OH&S management system that is designed to meet legal requirements and ensure a safe and healthy workplace. Compliance with OH&S legal requirements should be a fundamental aspect of your organization’s operations and culture.

The organization shall maintain and retain documented information on its legal requirements and other requirements and shall ensure that it is updated to reflect any changes.

  1. Legal Requirements Register:
    • One of the fundamental documents you’ll need is a register or list of all relevant legal requirements that apply to your organization’s OH&S. This register should include laws, regulations, and other legal obligations at local, regional, national, and international levels. It should be regularly updated to reflect any changes in legal requirements.
  2. Other Requirements Register:
    • In addition to legal requirements, you should maintain a register or list of other requirements that apply to your organization’s OH&S. These may include industry-specific standards, customer-specific requirements, and internal policies and procedures. Like the legal requirements register, this should also be kept up to date.
  3. Documented Information:
    • You should have documented information that describes how your organization determines and evaluates compliance with legal and other requirements. This could include procedures, policies, or guidelines that detail the process for identifying, reviewing, and addressing these requirements.
  4. Records of Compliance Evaluations:
    • Keep records of compliance evaluations, including any assessments, audits, inspections, or reviews conducted to ensure compliance with legal and other requirements. These records should demonstrate how your organization assessed and addressed compliance gaps.
  5. Evidence of Updates:
    • Maintain evidence of how your organization keeps up to date with changes in legal requirements and other requirements. This might include subscription records to relevant publications, notifications of regulatory changes, or attendance at industry conferences where changes are discussed.
  6. Training Records:
    • Document records of employee training related to legal and other requirements. This demonstrates that employees are aware of and understand their responsibilities regarding compliance.
  7. Communication Records:
    • Keep records of how your organization communicates information about legal and other requirements to employees and relevant stakeholders. This can include meeting minutes, email communications, or announcements.
  8. Change Management Records:
    • Maintain records of changes made to processes, procedures, or policies as a result of updates to legal and other requirements. This includes documenting the reasons for changes and who was responsible for making them.
  9. Retention of Records:
    • Ensure that all these records are retained for the required duration, which should be defined based on your organization’s policies and applicable legal and regulatory requirements.

Updating the documented information to reflect changes in legal or other requirements is a critical part of maintaining compliance with ISO 45001:2018 and ensuring the safety of your organization’s operations. Here are steps to update the documented information effectively:

  1. Develop a clear and documented process for monitoring and updating the Legal Requirements Register. Assign responsibility for this process to a specific individual or team within your organization.
  2. Schedule regular reviews of legal and other requirements. Depending on the nature of your industry and the pace of regulatory changes, this could be monthly, quarterly, or annually. The frequency should ensure timely updates.
  3. Identify sources of information for tracking changes in legal and other requirements. These sources may include government websites, industry associations, regulatory authorities, newsletters, and legal publications.
  4. Consider subscribing to legal monitoring services or regulatory alert services that can provide timely updates on changes to legal requirements. These services can streamline the process of staying informed.
  5. Clearly define who within your organization is responsible for monitoring changes. This could be a dedicated compliance officer, legal counsel, or another relevant department or role.
  6. When changes to legal or other requirements are identified, document them systematically. Include details such as the date of the change, a summary of the change, the source of the change (e.g., a specific law or regulation), and any relevant citations.
  7. Assess how each change in legal or other requirements affects your organization’s operations, processes, and policies. Determine if any actions or updates are necessary to maintain compliance.
  8. Update the Legal Requirements Register with the information about the changed requirements. Make sure to include the effective date of the change, the specific sections or clauses affected, and any actions taken to address the change.
  9. Communicate the changes to relevant stakeholders within your organization. This may include safety officers, management, and employees who need to be aware of these changes to ensure compliance.
  10. Provide training and awareness programs to educate employees about the updated legal and other requirements that apply to their roles. Ensure that they understand how these changes impact their work.
  11. Document the entire process of monitoring and updating the Legal Requirements Register. Include records of reviews, assessments, and actions taken in response to changes.
  12. Regularly evaluate and improve your process for monitoring and updating the Legal Requirements Register. Seek feedback from those involved to identify areas for enhancement.
  13. Retain historical information in the Legal Requirements Register to provide a comprehensive record of changes over time. This can be valuable for audits and compliance verification.

Procedure: Determination of Legal Requirements and Other Requirements in OH&S MS

Objective: To establish a systematic process for identifying, assessing, and maintaining legal requirements and other requirements relevant to the organization’s Occupational Health and Safety Management System (OH&S MS).

Scope: This procedure applies to all employees and relevant stakeholders responsible for OH&S compliance within the organization.

Responsibilities:

  • OH&S Manager: Overall responsibility for overseeing the determination and management of legal requirements and other requirements.
  • Compliance Team: Responsible for conducting reviews, assessments, and maintaining the Legal Requirements Register.
  • Department Heads/Managers: Responsible for providing input and ensuring compliance within their respective departments.
  • Training and Awareness Coordinators: Responsible for employee training and awareness related to legal and other requirements.

Procedure Steps:

1. Identification of Legal Requirements and Other Requirements

The Compliance Team regularly monitors and reviews sources of legal and other requirements, which may include but are not limited to:

  • Government legislation at local, regional, national, and international levels.
  • Industry-specific standards, codes, and guidelines.
  • Customer contracts and agreements.
  • Internal policies and procedures.
  • Best practices and recommendations from recognized organizations.

The Compliance Team identifies the applicable legal and other requirements and compiles a list for review.

2. Review and Assessment

The Compliance Team conducts a thorough review and assessment of each identified requirement, considering the following:

  • Relevance and applicability to the organization’s operations.
  • Potential OH&S risks and impacts.
  • Compliance obligations, timelines, and reporting requirements.

For legal requirements, the Compliance Team consults with legal counsel or experts as needed to ensure accurate interpretation and understanding.

3. Documentation and Record-Keeping

All identified legal and other requirements are documented and recorded in the Legal Requirements Register.

4. Communication and Training

  • The Compliance Team communicates relevant legal and other requirements to department heads and managers, ensuring they are aware of their responsibilities for compliance.
  • Training and Awareness Coordinators organize training sessions to educate employees on the implications and requirements of relevant legal and other requirements applicable to their roles.

5. Compliance Monitoring

  • The Compliance Team continuously monitors changes in legal and other requirements through ongoing research, subscriptions, and notifications.
  • When changes are identified, the Compliance Team assesses their impact on the organization’s OH&S MS.

6. Updating the Legal Requirements Register

The Compliance Team updates the Legal Requirements Register to reflect any changes in legal and other requirements. Updates should include:

  • The effective date of the change.
  • A summary of the change.
  • Relevant sections or clauses affected.
  • Actions taken to ensure compliance.

7. Reporting

Periodic reports on compliance with legal and other requirements are prepared and shared with relevant stakeholders, including senior management.

8. Records Retention

All records related to the determination of legal requirements and other requirements, including reviews, assessments, and updates, are retained as per the organization’s document retention policy.

9. Continuous Improvement

The OH&S Manager ensures that the process for determining legal requirements and other requirements is regularly reviewed for effectiveness and efficiency, with any necessary improvements implemented.

Example of legal requirement register in OH&S

Legal Requirements Register for Occupational Health and Safety (OH&S)

Legal RequirementDescriptionApplicabilityEffective DateResponsibilityStatusActions Taken
[Insert Regulation/Standard Name]A brief description of the legal requirement, including relevant sections or clauses.List the specific areas or departments within your organization to which this requirement applies.The date when the legal requirement came into effect.Name or department responsible for monitoring compliance with this requirement.Ongoing/Compliant/Non-compliantDescribe any actions taken to ensure compliance, such as policy updates, training programs, or safety measures.
[Example: OSHA 29 CFR 1910.134 – Respiratory Protection]This standard outlines requirements for respiratory protection programs.All departments involving work that requires respiratory protection.[Date]EH&S DepartmentOngoingUpdated respiratory protection policies and conducted employee training.
[Insert Next Legal Requirement][Description][Applicability][Date][Responsibility][Status][Actions Taken]
[Insert Another Legal Requirement][Description][Applicability][Date][Responsibility][Status][Actions Taken]

Notes:

  1. The “Legal Requirement” column should include the name and reference number of the regulation or standard.
  2. The “Description” column should provide a concise summary of what the requirement entails.
  3. The “Applicability” column specifies which parts of your organization are affected by the requirement.
  4. The “Effective Date” indicates when the requirement became applicable.
  5. The “Responsibility” column lists the person or department responsible for monitoring and ensuring compliance.
  6. The “Status” column tracks the current compliance status (e.g., Ongoing, Compliant, Non-compliant).
  7. The “Actions Taken” column outlines any actions your organization has taken to meet the requirement.

Leave a Reply