Knowella

Compliance Evaluation Record

Most legal registers get built once and otherwise left alone. The recurring failure is treating the register itself as proof of compliance: a requirement is listed, nobody checks it against live evidence, and the assumption quietly hardens into fact until an inspector or a customer audit asks for the document that was never actually reviewed.

KnowComplyRecordCMP-011Pinned in navigation43 fields across 4 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 45001 cl.9.1.2
Workspace
KnowComply
Form type
Record
Review trigger
Yearly at minimum, per site or scope
Completed by
Compliance lead, evidence checked against the legal register

The short version

  • This record is the periodic check that each obligation on the legal register is actually being met, evidenced line by line rather than assumed from the register's existence.
  • It runs at least yearly, is carried out by the compliance lead, and every non-compliant or partially compliant line is expected to carry a CAPA reference before the record closes.
  • The template holds 43 fields across four sections, with the Requirements evaluated section repeating once per obligation checked.
  • Scoring rolls up to a single compliance percentage where high is good, but the more diagnostic fields are evidence gaps found and whether every non-compliance has an action.

What this is

What is the difference between the legal register and a compliance evaluation record?

What is the difference between the legal register and a compliance evaluation record?

The Legal and Other Requirements Register (CMP-009) lists what applies to you. This record checks, requirement by requirement, whether you actually meet each one, against evidence you can name. A register with no evaluation history is a list of obligations, not a compliance position.

What counts as evidence being 'current' rather than just 'adequate'?

Adequate means the evidence, if genuine, would satisfy the requirement — a permit, a certificate, a training record. Current means it hasn't lapsed. A requirement can have adequate evidence that is no longer current, which the form scores separately for that reason.

What does 'self reported' mean on this record?

It marks whether a non-compliance was disclosed to the regulator before being discovered externally. Regulators routinely treat voluntary disclosure as mitigating in enforcement decisions, which is why the field carries its own score rather than folding into general compliance status.

Scope

When is a compliance evaluation record required?

This record is the evaluation step in the legal register lifecycle. Using it to build or amend the register itself, or to assess how a single requirement applies before you've decided you're subject to it, produces evidence that reads as work done at the wrong stage.

Use this template when

  • A scheduled or ad-hoc evaluation of compliance against the legal register is due for a site, area, or process
  • You need to demonstrate to an auditor or regulator that compliance is checked against evidence, not assumed from the register
  • A prior evaluation flagged gaps and this cycle needs to show whether the trend is improving, stable, or worsening
  • A management review is coming up and this record needs to exist to feed it
  • A linked record needs this one to exist: it links to the Legal Register and feeds CAPA

Do not use it for

  • Legal and Other Requirements Register, which lists every law, regulation, permit and commitment that applies — build and maintain the list there, evaluate against it here.
  • Compliance Obligation Assessment, which works out how a single requirement applies and what you do to meet it, before it's a routine evaluation cycle.
  • Regulatory Change Record, which captures a change in law and its impact, rather than a scheduled check against requirements already on the register.
  • Environmental Aspects Register, which is about environmental aspects and impacts, not legal obligations and their evidence.
  • Anything outside KnowComply, which belongs in the workspace that owns that process

Compliance mapping

Which ISO 45001 cl.9.1.2 requirements does this satisfy?

The record maps to the evaluation-of-compliance clause common to ISO management system standards, with the corrective action and management review clauses picked up by its linked fields.

ClauseRequirementWhere it lands
ISO 45001 cl.9.1.2The organisation shall evaluate compliance with legal requirements and other requirements, and take action if needed.Requirements evaluated
ISO 14001 cl.9.1.2The equivalent environmental evaluation-of-compliance requirement, where the domain checked is environmental rather than occupational.Header
ISO 45001 cl.9.1.2(c)The organisation shall retain documented information as evidence of the compliance evaluation results.Summary
ISO 45001 cl.9.1.2(b)The organisation shall maintain knowledge and understanding of its compliance status.Summary
ISO 45001 cl.10.2Nonconformities identified during evaluation shall be corrected and their cause addressed.Requirements evaluated
ISO 45001 cl.9.3Management review shall consider the results of evaluation of compliance with legal requirements.Summary
ISO 45001 cl.7.5.3Documented information required by the management system shall be controlled, including retention and traceability to source records.Related records

What it does not cover

  • Evaluating the register instead of the obligations, which confirms the list still exists but proves nothing about whether any requirement on it is actually being met.
  • Marking Compliant with a vague Evidence Reviewed entry, which satisfies the required field without satisfying the clause, and is indistinguishable from a guess when someone checks.
  • Recording Evidence Adequate as Yes while Evidence Current is Out of date, which means the requirement was met once but there is no proof it still is.
  • Leaving Non Compliance Detail blank when Compliance Status is Non compliant, which turns the record into an admission with no description of what actually failed.
  • Closing the evaluation with Action Required set to No against an open non-compliance, which contradicts the record's own compliance status field and won't survive a second look.

Global

Compliance Evaluation Record requirements by country

The evaluation is standard-driven, but what 'compliant' means underneath it depends on where the site sits and which regulator has standing.

United Kingdom

Health and Safety at Work etc. Act 1974, plus sector regulations such as COSHH

The HSE expects a documented, periodic compliance check as evidence that 'so far as is reasonably practicable' is being actively managed, not asserted.

A site that can only produce the register itself, with no evaluation history, looks materially weaker in an HSE investigation than one with a dated evaluation trail and named evidence.

United States

OSHA General Duty Clause (29 U.S.C. §654) and applicable state-plan equivalents

OSHA enforcement distinguishes a known hazard left unaddressed from one genuinely outside management's knowledge; this record is direct evidence of which applies.

Self-reporting a gap ahead of an OSHA inspection, evidenced by this record's own field for it, is treated materially more favourably than the same gap being found first by an inspector.

European Union

Framework Directive 89/391/EEC, transposed into each member state's national legislation

Member states implement the underlying obligation differently, so a group operating across EU sites cannot rely on one evaluation cycle proving compliance everywhere.

The Domain and Site fields exist so a multi-site evaluation can be filtered and rolled up per jurisdiction rather than reported as one undifferentiated percentage.

How to complete it

How to complete a compliance evaluation record, step by step

Filling in the fields is mechanical. The judgement calls that decide whether the finished record would survive scrutiny sit underneath it.

What counts as evidence 'reviewed', not just referenced

A named document with a date and reference the evaluator actually opened counts. A process description, a verbal assurance, or a link nobody opened does not, even though all three fit the same free-text field.

Whether a documented but unenforced control is compliant

A procedure that exists on paper but isn't followed on the floor is not compliant, even though the document itself would satisfy Evidence Adequate. The evaluator judges practice against paper, which the form can't do for them.

How wide to set the evaluation scope

Whole site, single area, single process, or all sites carries real consequences: a narrow scope can show a clean compliance percentage while leaving the rest of the site unchecked, unless the scope field is honest.

When a stable trend is actually stagnation

Trend Versus Last Evaluation scores Stable the same whether nothing has changed because everything is genuinely under control, or because nobody has looked hard enough to find the gaps. Only the evaluator knows which one applies.

What auditors find

Most common compliance evaluation record findings

The failure modes below are the ones an auditor or a second reviewer catches most often, mapped to the clause they undermine and the fix that holds up.

FindingClauseWhat fixes it
Evidence Reviewed filled with a generic phrase like 'on file' or 'ongoing'ISO 45001 cl.9.1.2(c)Require a document name, reference number, and date in Evidence Reviewed before the line can be marked Compliant.
Compliance Status marked Compliant while Evidence Adequate is PartlyISO 45001 cl.9.1.2Cap Compliance Status at Partially compliant whenever Evidence Adequate is anything other than Yes, and flag the contradiction.
Non Compliant status recorded with no CAPA ID raisedISO 45001 cl.10.2Block the record from Complete status until every Non compliant line carries a CAPA ID.
Trend Versus Last Evaluation marked Improving with no prior evaluation to compare againstISO 45001 cl.9.1.2(b)Require a linked prior Record ID before Trend can be set to anything other than a first-evaluation default.
Regulator Notified Where Required left as a default answer rather than a decisionApplicable notification duty under the relevant sector regulationForce an explicit Yes, No or Not required selection, naming which regulator and route applied.
Next Evaluation Due set further out than the site's own stated review cycleISO 45001 cl.9.1.2Validate Next Evaluation Due against the frequency committed to in the Legal Register.

Case in point

Case in point: the permit that was compliant on paper for three years

A site ran a clean annual evaluation for three cycles, each one marking its discharge permit Compliant with Evidence Reviewed reading 'permit on file.' Nobody had opened the permit itself, which had expired fourteen months earlier during a renewal backlog at the regulator. The gap surfaced only when an inspection asked for the current permit number.

The fix wasn't a new field, it was enforcing what the existing ones already asked for: Evidence Reviewed had to name the permit number and expiry date, and Evidence Current had to be checked against that date rather than assumed. The next cycle caught two more requirements with the same pattern before an inspector did.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

43fields
4 sections
Reference
CMP-011
Archetype
Record
Record ID
CER2-2026-000
Scoring
Compliance percent
Direction
High is good
Singleton
No
Basis
ISO 45001 cl.9.1.2
Links
Links Legal Register; feeds CAPA
Tags
Compliance, Evaluation
Sections
4
Fields
43
Follow up fields
4
Repeating sections
1
Links out
3
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

10 fields
Text

Record ID*

Generated on save

Auto sequence. Format CER-2026-000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Date & Time

Date and Time*

Users

Completed By*

Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Text

Period Covered*

Users

Evaluated By*

Single Choice

Scope*

Whole siteSingle areaSingle processAll sites
Info

Evaluate, Do Not Assume

Periodic evaluation of compliance is an explicit clause in every management system standard, and one of the most commonly failed. Check each obligation against actual evidence.

Requirements evaluated

Repeats11 fields
Text

Requirement*

Single Choice

Domain*

SafetyFood safetyQualityEnvironmentalOccupational healthEngineeringWarehouseTransport
Users

Owner*

Text

Evidence Reviewed*

Single Choice

Evidence Adequate*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Evidence Current*

Scored
  • Yes3 pts
  • Out of date0 pts
Single Choice

Compliance Status*

Scored
  • Compliant3 pts
  • Partially compliant1 pt
  • Non compliant0 pts
Text

Non Compliance Detail

OptionalShows if Compliance Status not equals Compliant
Single Choice

Self Reported

OptionalScored

Self reporting a breach is almost always treated more favourably than being found out.

  • Yes3 pts
  • Not required3 pts
  • No0 pts
Text

CAPA ID

OptionalLinked

Links to FDN-014 CAPA ID

Date & Time

Target Date

Optional

Related records

1 field
Text

Legal Register ID

OptionalLinked

The register this evaluation was carried out against.

Links to CMP-009 Register ID

Summary

21 fields
Numeric Answer

Requirements Evaluated*

Numeric Answer

Fully Compliant*

Scored
Numeric Answer

Compliance Percent*

Scored
Numeric Answer

Partially Compliant*

Scored
Numeric Answer

Non Compliant*

Scored
Numeric Answer

Not Evaluated*

Scored
Numeric Answer

Evidence Gaps Found*

Scored

Compliant with no evidence is indistinguishable from non compliant when somebody asks.

Single Choice

Trend Versus Last Evaluation*

Scored
  • Improving3 pts
  • Stable2 pts
  • Worsening0 pts
Text

Highest Consequence Gap

Optional
Single Choice

All Non Compliances Have Actions*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Regulator Notified Where Required*

Scored
  • Yes3 pts
  • Not required3 pts
  • No0 pts
Checkbox

Feeds Management Review*

Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Date & Time

Next Evaluation Due*

Users

Compliance Lead*

Signature

Signature*

Users

Site Manager*

Signature

Second Signature*

CMP-011 · record IDs look like CER2-2026-000 · Links Legal Register; feeds CAPA

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The form is the easy part. Keeping the legal register current, chasing evidence from requirement owners, and rolling gaps into CAPA and management review is the work that actually slips.

KnowComply

Holds the legal register and every evaluation cycle against it, flags requirements overdue for a check, and keeps the CAPA trail linked back to the line that raised it.

KnowSafe

Surfaces the occupational health and safety requirements this evaluation checks against, and feeds any resulting non-compliance into the incident and action workflow it already owns.

KnowEnviro

Carries the permit, discharge and emissions data an environmental evaluation line needs, so Evidence Reviewed can point at a live record rather than a remembered file.

Ella
Ella

Coordinates the crew, rolls completion and exceptions into one view, and holds every write for your approval before it touches a record.

This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.

Meet KnowComply→

Glossary

Compliance Evaluation Record definitions and key terms

Legal register
The master list of every law, regulation, permit and commitment that applies to a site, maintained separately from any single evaluation of it.
Compliance evaluation
The periodic, evidence-based check of whether each requirement on the register is actually being met, as distinct from listing the requirement itself.
CAPA
Corrective and Preventive Action — the linked record raised whenever a non-compliance is found, carrying the reference Action Required expects.
Self-reporting
Disclosing a known non-compliance to the regulator before it is found through inspection, generally treated as a mitigating factor in enforcement.
Management review
The periodic senior review of the system's performance, which this record feeds via its Feeds Management Review field.

FAQ

Frequently asked questions about compliance evaluation record

How is a compliance evaluation record different from an internal audit?+

An internal audit checks the management system against a standard's clauses generally. This record checks specifically against the legal register, requirement by requirement, with named evidence rather than a general conformance judgement.

Who should complete a compliance evaluation record?+

The compliance lead runs it, but evidence for each requirement usually comes from whoever owns that requirement day to day, recorded against the Owner field on each evaluated line.

What happens if evidence can't be located for a requirement?+

Evidence Adequate should be marked No or Partly rather than left pending, since a requirement with no findable evidence is functionally the same as one not being met when a regulator asks.

Does every non-compliance need its own CAPA?+

Yes. The summary expects All Non Compliances Have Actions to be answered honestly, and a Non compliant line with no CAPA ID is the most common reason this record fails a second review.

How does this record feed management review?+

Feeds Management Review marks it for inclusion, and the compliance percentage, trend, and highest consequence gap fields are what a review actually looks at rather than the individual lines.

Can the scope of an evaluation be narrower than the whole site?+

Yes, Scope allows whole site, single area, single process, or all sites, but a narrower scope should be stated honestly rather than used to produce a cleaner percentage than the site as a whole would earn.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO 45001:2018 cl.9.1.2 — Evaluation of compliance
  • ISO 14001:2015 cl.9.1.2 — Evaluation of compliance
  • ISO 45001:2018 cl.10.2 — Incident, nonconformity and corrective action
  • Health and Safety at Work etc. Act 1974 (UK)
  • OSHA General Duty Clause, 29 U.S.C. §654

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.