What this is
What is the difference between the legal register and a compliance evaluation record?
What is the difference between the legal register and a compliance evaluation record?
The Legal and Other Requirements Register (CMP-009) lists what applies to you. This record checks, requirement by requirement, whether you actually meet each one, against evidence you can name. A register with no evaluation history is a list of obligations, not a compliance position.
What counts as evidence being 'current' rather than just 'adequate'?
Adequate means the evidence, if genuine, would satisfy the requirement — a permit, a certificate, a training record. Current means it hasn't lapsed. A requirement can have adequate evidence that is no longer current, which the form scores separately for that reason.
What does 'self reported' mean on this record?
It marks whether a non-compliance was disclosed to the regulator before being discovered externally. Regulators routinely treat voluntary disclosure as mitigating in enforcement decisions, which is why the field carries its own score rather than folding into general compliance status.
Scope
When is a compliance evaluation record required?
This record is the evaluation step in the legal register lifecycle. Using it to build or amend the register itself, or to assess how a single requirement applies before you've decided you're subject to it, produces evidence that reads as work done at the wrong stage.
Use this template when
- A scheduled or ad-hoc evaluation of compliance against the legal register is due for a site, area, or process
- You need to demonstrate to an auditor or regulator that compliance is checked against evidence, not assumed from the register
- A prior evaluation flagged gaps and this cycle needs to show whether the trend is improving, stable, or worsening
- A management review is coming up and this record needs to exist to feed it
- A linked record needs this one to exist: it links to the Legal Register and feeds CAPA
Do not use it for
- Legal and Other Requirements Register, which lists every law, regulation, permit and commitment that applies — build and maintain the list there, evaluate against it here.
- Compliance Obligation Assessment, which works out how a single requirement applies and what you do to meet it, before it's a routine evaluation cycle.
- Regulatory Change Record, which captures a change in law and its impact, rather than a scheduled check against requirements already on the register.
- Environmental Aspects Register, which is about environmental aspects and impacts, not legal obligations and their evidence.
- Anything outside KnowComply, which belongs in the workspace that owns that process
Compliance mapping
Which ISO 45001 cl.9.1.2 requirements does this satisfy?
The record maps to the evaluation-of-compliance clause common to ISO management system standards, with the corrective action and management review clauses picked up by its linked fields.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 45001 cl.9.1.2 | The organisation shall evaluate compliance with legal requirements and other requirements, and take action if needed. | Requirements evaluated |
| ISO 14001 cl.9.1.2 | The equivalent environmental evaluation-of-compliance requirement, where the domain checked is environmental rather than occupational. | Header |
| ISO 45001 cl.9.1.2(c) | The organisation shall retain documented information as evidence of the compliance evaluation results. | Summary |
| ISO 45001 cl.9.1.2(b) | The organisation shall maintain knowledge and understanding of its compliance status. | Summary |
| ISO 45001 cl.10.2 | Nonconformities identified during evaluation shall be corrected and their cause addressed. | Requirements evaluated |
| ISO 45001 cl.9.3 | Management review shall consider the results of evaluation of compliance with legal requirements. | Summary |
| ISO 45001 cl.7.5.3 | Documented information required by the management system shall be controlled, including retention and traceability to source records. | Related records |
What it does not cover
- Evaluating the register instead of the obligations, which confirms the list still exists but proves nothing about whether any requirement on it is actually being met.
- Marking Compliant with a vague Evidence Reviewed entry, which satisfies the required field without satisfying the clause, and is indistinguishable from a guess when someone checks.
- Recording Evidence Adequate as Yes while Evidence Current is Out of date, which means the requirement was met once but there is no proof it still is.
- Leaving Non Compliance Detail blank when Compliance Status is Non compliant, which turns the record into an admission with no description of what actually failed.
- Closing the evaluation with Action Required set to No against an open non-compliance, which contradicts the record's own compliance status field and won't survive a second look.
Global
Compliance Evaluation Record requirements by country
The evaluation is standard-driven, but what 'compliant' means underneath it depends on where the site sits and which regulator has standing.
Health and Safety at Work etc. Act 1974, plus sector regulations such as COSHH
The HSE expects a documented, periodic compliance check as evidence that 'so far as is reasonably practicable' is being actively managed, not asserted.
A site that can only produce the register itself, with no evaluation history, looks materially weaker in an HSE investigation than one with a dated evaluation trail and named evidence.
OSHA General Duty Clause (29 U.S.C. §654) and applicable state-plan equivalents
OSHA enforcement distinguishes a known hazard left unaddressed from one genuinely outside management's knowledge; this record is direct evidence of which applies.
Self-reporting a gap ahead of an OSHA inspection, evidenced by this record's own field for it, is treated materially more favourably than the same gap being found first by an inspector.
Framework Directive 89/391/EEC, transposed into each member state's national legislation
Member states implement the underlying obligation differently, so a group operating across EU sites cannot rely on one evaluation cycle proving compliance everywhere.
The Domain and Site fields exist so a multi-site evaluation can be filtered and rolled up per jurisdiction rather than reported as one undifferentiated percentage.
How to complete it
How to complete a compliance evaluation record, step by step
Filling in the fields is mechanical. The judgement calls that decide whether the finished record would survive scrutiny sit underneath it.
A named document with a date and reference the evaluator actually opened counts. A process description, a verbal assurance, or a link nobody opened does not, even though all three fit the same free-text field.
A procedure that exists on paper but isn't followed on the floor is not compliant, even though the document itself would satisfy Evidence Adequate. The evaluator judges practice against paper, which the form can't do for them.
Whole site, single area, single process, or all sites carries real consequences: a narrow scope can show a clean compliance percentage while leaving the rest of the site unchecked, unless the scope field is honest.
Trend Versus Last Evaluation scores Stable the same whether nothing has changed because everything is genuinely under control, or because nobody has looked hard enough to find the gaps. Only the evaluator knows which one applies.
What auditors find
Most common compliance evaluation record findings
The failure modes below are the ones an auditor or a second reviewer catches most often, mapped to the clause they undermine and the fix that holds up.
| Finding | Clause | What fixes it |
|---|---|---|
| Evidence Reviewed filled with a generic phrase like 'on file' or 'ongoing' | ISO 45001 cl.9.1.2(c) | Require a document name, reference number, and date in Evidence Reviewed before the line can be marked Compliant. |
| Compliance Status marked Compliant while Evidence Adequate is Partly | ISO 45001 cl.9.1.2 | Cap Compliance Status at Partially compliant whenever Evidence Adequate is anything other than Yes, and flag the contradiction. |
| Non Compliant status recorded with no CAPA ID raised | ISO 45001 cl.10.2 | Block the record from Complete status until every Non compliant line carries a CAPA ID. |
| Trend Versus Last Evaluation marked Improving with no prior evaluation to compare against | ISO 45001 cl.9.1.2(b) | Require a linked prior Record ID before Trend can be set to anything other than a first-evaluation default. |
| Regulator Notified Where Required left as a default answer rather than a decision | Applicable notification duty under the relevant sector regulation | Force an explicit Yes, No or Not required selection, naming which regulator and route applied. |
| Next Evaluation Due set further out than the site's own stated review cycle | ISO 45001 cl.9.1.2 | Validate Next Evaluation Due against the frequency committed to in the Legal Register. |
Case in point
Case in point: the permit that was compliant on paper for three years
A site ran a clean annual evaluation for three cycles, each one marking its discharge permit Compliant with Evidence Reviewed reading 'permit on file.' Nobody had opened the permit itself, which had expired fourteen months earlier during a renewal backlog at the regulator. The gap surfaced only when an inspection asked for the current permit number.
The fix wasn't a new field, it was enforcing what the existing ones already asked for: Evidence Reviewed had to name the permit number and expiry date, and Evidence Current had to be checked against that date rather than assumed. The next cycle caught two more requirements with the same pattern before an inspector did.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
4 sections
- Reference
- CMP-011
- Archetype
- Record
- Record ID
- CER2-2026-000
- Scoring
- Compliance percent
- Direction
- High is good
- Singleton
- No
- Basis
- ISO 45001 cl.9.1.2
- Links
- Links Legal Register; feeds CAPA
- Tags
- Compliance, Evaluation
- Sections
- 4
- Fields
- 43
- Follow up fields
- 4
- Repeating sections
- 1
- Links out
- 3
Header
10 fieldsRecord ID*
Auto sequence. Format CER-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Period Covered*
Evaluated By*
Scope*
Evaluate, Do Not Assume
Periodic evaluation of compliance is an explicit clause in every management system standard, and one of the most commonly failed. Check each obligation against actual evidence.
Requirements evaluated
Repeats11 fieldsRequirement*
Domain*
Owner*
Evidence Reviewed*
Evidence Adequate*
- Yes3 pts
- Partly1 pt
- No0 pts
Evidence Current*
- Yes3 pts
- Out of date0 pts
Compliance Status*
- Compliant3 pts
- Partially compliant1 pt
- Non compliant0 pts
Non Compliance Detail
Self Reported
Self reporting a breach is almost always treated more favourably than being found out.
- Yes3 pts
- Not required3 pts
- No0 pts
CAPA ID
Links to FDN-014 CAPA ID
Target Date
Related records
1 fieldLegal Register ID
The register this evaluation was carried out against.
Links to CMP-009 Register ID
Summary
21 fieldsRequirements Evaluated*
Fully Compliant*
Compliance Percent*
Partially Compliant*
Non Compliant*
Not Evaluated*
Evidence Gaps Found*
Compliant with no evidence is indistinguishable from non compliant when somebody asks.
Trend Versus Last Evaluation*
- Improving3 pts
- Stable2 pts
- Worsening0 pts
Highest Consequence Gap
All Non Compliances Have Actions*
- Yes3 pts
- Partly1 pt
- No0 pts
Regulator Notified Where Required*
- Yes3 pts
- Not required3 pts
- No0 pts
Feeds Management Review*
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Next Evaluation Due*
Compliance Lead*
Signature*
Site Manager*
Second Signature*
CMP-011 · record IDs look like CER2-2026-000 · Links Legal Register; feeds CAPA
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The form is the easy part. Keeping the legal register current, chasing evidence from requirement owners, and rolling gaps into CAPA and management review is the work that actually slips.
Holds the legal register and every evaluation cycle against it, flags requirements overdue for a check, and keeps the CAPA trail linked back to the line that raised it.
Surfaces the occupational health and safety requirements this evaluation checks against, and feeds any resulting non-compliance into the incident and action workflow it already owns.
Carries the permit, discharge and emissions data an environmental evaluation line needs, so Evidence Reviewed can point at a live record rather than a remembered file.

Coordinates the crew, rolls completion and exceptions into one view, and holds every write for your approval before it touches a record.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Meet KnowComply→Glossary
Compliance Evaluation Record definitions and key terms
- Legal register
- The master list of every law, regulation, permit and commitment that applies to a site, maintained separately from any single evaluation of it.
- Compliance evaluation
- The periodic, evidence-based check of whether each requirement on the register is actually being met, as distinct from listing the requirement itself.
- CAPA
- Corrective and Preventive Action — the linked record raised whenever a non-compliance is found, carrying the reference Action Required expects.
- Self-reporting
- Disclosing a known non-compliance to the regulator before it is found through inspection, generally treated as a mitigating factor in enforcement.
- Management review
- The periodic senior review of the system's performance, which this record feeds via its Feeds Management Review field.
FAQ
Frequently asked questions about compliance evaluation record
How is a compliance evaluation record different from an internal audit?+
An internal audit checks the management system against a standard's clauses generally. This record checks specifically against the legal register, requirement by requirement, with named evidence rather than a general conformance judgement.
Who should complete a compliance evaluation record?+
The compliance lead runs it, but evidence for each requirement usually comes from whoever owns that requirement day to day, recorded against the Owner field on each evaluated line.
What happens if evidence can't be located for a requirement?+
Evidence Adequate should be marked No or Partly rather than left pending, since a requirement with no findable evidence is functionally the same as one not being met when a regulator asks.
Does every non-compliance need its own CAPA?+
Yes. The summary expects All Non Compliances Have Actions to be answered honestly, and a Non compliant line with no CAPA ID is the most common reason this record fails a second review.
How does this record feed management review?+
Feeds Management Review marks it for inclusion, and the compliance percentage, trend, and highest consequence gap fields are what a review actually looks at rather than the individual lines.
Can the scope of an evaluation be narrower than the whole site?+
Yes, Scope allows whole site, single area, single process, or all sites, but a narrower scope should be stated honestly rather than used to produce a cleaner percentage than the site as a whole would earn.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Environmental Management
Legal and Other Requirements Register
Lists every law, regulation, permit and commitment that applies to your operation
Waste Stream Register
Lists every waste stream produced on site, with its classification, container and disposal route
Waste Transfer Record
Records waste leaving site, including type, quantity, carrier and destination
Hazardous Waste Record
Records generation, storage and disposal of hazardous waste
Waste Area Inspection
Checks waste storage areas for correct segregation, labelling, containment and housekeeping
Waste Contractor Audit
Audits a waste contractor's permits, vehicles and destination facilities
More in Legal Register
Legal and Other Requirements Register
Lists every law, regulation, permit and commitment that applies to your operation
Compliance Obligation Assessment
Assesses how each legal requirement applies to you and what you do to meet it
Regulatory Change Record
Records a change in law or regulation and what it means for you
Regulatory Inspection Record
Records a visit by a regulator, including what was inspected, what was said and any orders issued

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 45001:2018 cl.9.1.2 — Evaluation of compliance
- ISO 14001:2015 cl.9.1.2 — Evaluation of compliance
- ISO 45001:2018 cl.10.2 — Incident, nonconformity and corrective action
- Health and Safety at Work etc. Act 1974 (UK)
- OSHA General Duty Clause, 29 U.S.C. §654
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.