Knowella

Compliance Obligation Assessment

The register names the law. This assessment decides whether it actually applies here, and what closes the gap if it doesn't. The recurring failure is skipping the basis for that decision: a site marks a requirement Yes or No with no reasoning written down, so months later nobody can tell whether the judgement was reasoned or guessed, and an unpermitted activity surfaces via a regulator rather than the compliance lead.

KnowComplyAssessmentCMP-010Pinned in navigation41 fields across 4 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 45001 cl.6.1.3
Workspace
KnowComply
Form type
Assessment
Completed by
Carried out by the compliance lead
Raised
When the register is built, and again after material change

The short version

  • This assessment turns a named legal requirement into a tested applicability decision, a stated obligation and a controls-versus-evidence gap check, not a restatement of what the register already says.
  • Applies To This Site needs a written Basis For The Decision. Ticking Yes or No without it is the pattern that produces an unpermitted activity nobody can explain later.
  • Currently Below Threshold and Would Apply If We Grow are different questions. A site just under a headcount or throughput trigger with no answer to the second is one hiring round from a breach nobody planned for.
  • Gap Identified and Consequence Of Breach are independent judgements. Closing higher-consequence gaps first, not the easiest ones, is the point of asking both.

What this is

What is a compliance obligation assessment?

What is a compliance obligation assessment?

It is the record that turns one line of the legal register into a tested judgement: whether a requirement applies here, on what basis, what it obliges, whether a control already meets it, and what closes any gap. The register lists the law; this assessment decides what it means on site.

What is the difference between 'currently below threshold' and 'would apply if we grow'?

Currently Below Threshold records where the site sits today against a trigger. Would Apply If We Grow is forward-looking: whether a plausible change in scale would cross it. A requirement that does not bind today can bind next quarter, so the two are asked separately.

How is Gap Identified different from Consequence Of Breach?

Gap Identified is factual: does a control exist and does evidence back it up. Consequence Of Breach is a severity judgement, from Advisory to Loss Of Certification. A small gap can carry a severe consequence, or the reverse; one field alone misprioritises the queue.

Scope

When is a compliance obligation assessment required?

This assessment is the applicability-and-gap step in a larger governance programme. Using it to list requirements, record a periodic compliance check, or log a change in the law itself overlaps the wrong neighbouring template.

Use this template when

  • A requirement has just been added to the legal register and nobody has decided whether or how it applies to this site
  • A site, process, headcount or throughput has materially changed and a prior applicability decision needs re-testing
  • A new record is needed; each one gets its own ID in the form COA2-2026-000
  • A permit, notification, monitoring or reporting obligation needs its control checked against the evidence backing it
  • A gap has been found and needs a documented consequence, priority and, where warranted, a linked action

Do not use it for

  • Legal and Other Requirements Register, which lists every law, regulation, permit and commitment; this assessment tests one entry rather than building the list.
  • Compliance Evaluation Record, the periodic check of whether the site still complies with an obligation already assessed, not the first-time applicability call.
  • Regulatory Change Record, which captures a change in the law itself; this assessment runs after that record triggers a re-test.
  • Environmental Permit Register, which tracks a permit and its conditions once confirmed required; this only decides a permit is needed and links out once it exists.
  • Anything outside KnowComply, which belongs in the workspace that owns that process

Compliance mapping

Which ISO 45001 cl.6.1.3 requirements does this satisfy?

ISO 45001 cl.6.1.3 requires not just identifying applicable requirements but determining how they apply and keeping that current. This assessment carries the determination, not merely echoes the register.

ClauseRequirementWhere it lands
ISO 45001 cl.6.1.3Legal and other requirements determined, traceable to the site and requirement coveredHeader
ISO 45001 cl.6.1.3Applicability assessed and the basis for the decision documentedApplicability
ISO 45001 cl.6.1.3Thresholds or triggers tracked, including proximity to the triggerApplicability
ISO 45001 cl.6.1.3The specific obligation identified, such as a permit, notification, monitoring or reporting dutyObligations
ISO 45001 cl.6.1.3Where a permit is the obligation, status tracked against whether one is required and whether heldObligations
ISO 45001 cl.6.1.3Existing controls evaluated against the requirement, with evidence availability recordedCurrent position
ISO 45001 cl.6.1.3Gaps graded by consequence and priority, and the requirement confirmed added to the registerCurrent position
ISO 45001 cl.6.1.3A review date set so the determination is re-tested, not assumed to hold indefinitelyCurrent position

What it does not cover

  • Legal and Other Requirements Register, the master list this assessment tests one entry from; it does not itself decide applicability.
  • Compliance Evaluation Record, the periodic check that the site still meets an obligation already assessed here as applicable.
  • Regulatory Change Record, which captures what changed in the law and prompts a re-run, but does not carry the applicability decision itself.
  • Environmental Permit Register, where a confirmed permit and its conditions live once Permit Held moves past Applied For; this record only flags that one is needed.
  • Corrective and Preventive Action, the referenced action record once a gap is raised with Action Required set to Yes; the CAPA ID here is a link, not the plan.

Global

Compliance Obligation Assessment requirements by country

ISO 45001 sets the duty to assess; the regulator that issued the underlying law sets what it obliges and how a missed threshold bites. These three positions carry the most exposure from a wrong threshold or permit judgement.

United States

OSHA General Duty Clause; EPA permitting thresholds administered federally or delegated to states

Many US obligations are threshold-triggered by headcount, chemical quantity or emissions rate; below-threshold operations owe nothing under that rule until they cross it.

A site marked Currently Below Threshold with no answer to Would Apply If We Grow is exposed the moment growth crosses that line, often before the assessment is re-run.

United Kingdom

Health and Safety at Work etc. Act 1974; Environment Agency permitting under the Environmental Permitting Regulations

UK enforcement bodies expect a current legal register and a traceable basis for applicability, not a static list built once and never revisited.

Basis For The Decision left blank is what an inspector tests: not whether the right law is named, but whether the site can explain the ruling.

International

ISO 45001:2018 cl.6.1.3; ISO 14001:2015 cl.6.1.3 for environmental obligations assessed the same way

Both standards treat legal and other requirements as live inputs, requiring the organisation to know how each applies, not only that it exists.

A decision with no stated basis, or a gap with no consequence rating, reads at audit as identified but not actually determined.

How to complete it

How to complete a compliance obligation assessment, step by step

Most of this assessment is straightforward once someone sits with the requirement. These four calls are where a rushed answer quietly creates exposure that surfaces later.

Write the basis, not just the answer

Applies To This Site is the visible choice, but Basis For The Decision makes it defensible. A one-line reason tied to the actual activity beats a blank field when someone not in the room later reviews the judgement.

Treat proximity to a threshold as a live risk

Currently Below Threshold scores well, but Margin To Threshold and Would Apply If We Grow carry the real judgement. A site at 90 percent of a headcount trigger with no growth answer is one contract win from an unprepared requirement.

Separate 'permit required' from 'permit held'

A requirement can be correctly flagged as needing a permit while the permit itself is still Applied For or missing; reporting on the identification alone hides the exposure in the second field.

Grade the gap by consequence, not effort to fix

Gap Priority and Consequence Of Breach should drive sequencing together. A quick fix rated Advisory should not queue ahead of a harder gap rated Prohibition or Loss Of Certification; easiest-first is a habit, not a risk basis.

What auditors find

Most common compliance obligation assessment findings

Sitting between the register and the evidence, this record's recurring problems are less about missing fields and more about answers that look complete but were never reasoned through.

FindingClauseWhat fixes it
Applies To This Site answered without a completed Basis For The Decision.ISO 45001 cl.6.1.3Make the basis field mandatory in practice; reject determinations that give a choice with no reasoning.
Currently Below Threshold marked Yes with no entry in Margin To Threshold, so proximity is invisible.ISO 45001 cl.6.1.3Require a margin figure for threshold-based requirements, and flag any margin inside a defined buffer.
Would Apply If We Grow left unanswered on requirements tied to headcount, volume or throughput.ISO 45001 cl.6.1.3Treat this field as required wherever Thresholds Or Triggers is populated, and re-run the assessment when growth plans are confirmed.
Permit Or Licence Required marked Yes with Permit Held left blank rather than tracked to Applied For or No.ISO 45001 cl.6.1.3Block closure until Permit Held carries a current answer, and link the Permit Register ID once one is issued.
Gap Identified marked Yes with Consequence Of Breach recorded as Advisory regardless of actual exposure.ISO 45001 cl.6.1.3Require the rating to reflect the instrument's real enforcement powers, not a default low setting.
Added To Register left as No after the assessment is marked Complete.ISO 45001 cl.6.1.3Treat Added To Register as a gate before status can move to Complete.

Case in point

Case in point: the threshold nobody watched

A site assessed a wastewater discharge notification requirement as not applicable, since volume sat below the regulatory trigger. Applies To This Site was recorded as No, Currently Below Threshold as Yes, and Margin To Threshold was left blank. Would Apply If We Grow was answered No, reasoning that production had been flat for two years.

A new production line added eight months later pushed discharge volume past the trigger within the first quarter. With no margin recorded there was no baseline, and the growth question had been answered from a stale assumption rather than the capital plan already under discussion. The notification obligation was missed until a routine regulator visit flagged it.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

41fields
4 sections
Reference
CMP-010
Archetype
Assessment
Record ID
COA2-2026-000
Scoring
Compliance percent
Direction
High is good
Singleton
No
Basis
ISO 45001 cl.6.1.3
Links
Links Legal Register
Tags
Compliance, Assessment
Sections
4
Fields
41
Follow up fields
4
Repeating sections
0
Links out
4
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

10 fields
Text

Assessment ID*

Generated on save

Auto sequence. Format COA-2026-000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Date & Time

Date and Time*

Users

Completed By*

Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Text

Requirement Title*

Text

Register ID

OptionalLinked

Links to CMP-009 Register ID

Users

Assessed By*

Info

Decide Applicability Deliberately

Assuming a regulation does not apply is how sites end up with an unpermitted activity. Write down why it does or does not apply, so the judgement can be checked later.

Applicability

6 fields
Single Choice

Applies To This Site*

YesNoPartly
Text

Basis For The Decision*

Text

Thresholds Or Triggers

Optional

Many requirements apply above a quantity, headcount or throughput. Record where we sit against it.

Single Choice

Currently Below Threshold

OptionalScored
  • Yes3 pts
  • Marginal1 pt
  • No0 pts
Text

Margin To Threshold

Optional
Single Choice

Would Apply If We Grow

OptionalScored
  • No3 pts
  • Yes1 pt

Obligations

8 fields
Multi Choice

Obligation Type*

Permit or licence, notification, monitoring, record keeping, training, reporting, or a physical standard.

Permit or licenceNotificationMonitoringRecord keepingTrainingReportingPhysical standard
Text

Deadlines Or Frequencies

Optional
Single Choice

Permit Or Licence Required*

Scored
  • No3 pts
  • Yes1 pt
Single Choice

Permit Held

OptionalScored
  • Yes3 pts
  • Applied for1 pt
  • No0 pts
Text

Permit Register ID

OptionalLinked

Links to ENV-039 Register ID

Single Choice

Reporting Obligation*

Scored
  • None3 pts
  • Annual2 pts
  • Quarterly2 pts
  • On event1 pt
Text

Reporting Deadline

Optional
Single Choice

Responsible Person Named*

Scored
  • Yes3 pts
  • No0 pts

Current position

17 fields
Text

Controls In Place

Optional
Single Choice

Evidence Available*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Gap Identified*

Scored
  • No3 pts
  • Yes0 pts
Text

Gap Detail

OptionalShows if Gap Identified equals Yes
Single Choice

Consequence Of Breach*

Scored
  • Advisory3 pts
  • Fine1 pt
  • Prohibition0 pts
  • Prosecution0 pts
  • Loss of certification0 pts
Single Choice

Gap Priority*

Scored

How urgent closing the gap is. Separate from the priority of any action raised below.

  • Low3 pts
  • Medium1 pt
  • High0 pts
  • Critical0 pts
Single Choice

Legal Advice Sought

Optional
YesNot neededNo
Single Choice

Added To Register*

Scored
  • Yes3 pts
  • No0 pts
Date & Time

Review Date*

Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Users

Assessed By*

Signature

Signature*

Users

Compliance Lead*

Signature

Second Signature*

CMP-010 · record IDs look like COA2-2026-000 · Links Legal Register

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The basis for applicability and the threshold margin are exactly what gets skipped under time pressure. Keeping them visible is where the agent workspaces earn their place.

KnowComply

Holds the obligation assessment against the legal register, flags applicability decisions missing a stated basis, and tracks gaps through to a closed CAPA.

KnowEnviro

Watches permit-triggered obligations, surfacing any Permit Or Licence Required marked Yes where Permit Held has not progressed past Applied For.

KnowSafe

Cross-checks threshold-based requirements against headcount and activity changes, flagging a site approaching a trigger before it crosses one unassessed.

Ella
Ella

Coordinates the crew, rolls open gaps and overdue reviews into one view, and holds every write for your approval before it touches a record.

This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.

Meet KnowComply→

Glossary

Compliance Obligation Assessment definitions and key terms

Applicability
Whether a specific legal or other requirement binds this site's actual activity, scale or location, as distinct from whether it exists in general law.
Threshold
A quantity, headcount or throughput measure above which a requirement takes effect; many obligations stay inactive until a site crosses one.
Obligation type
The specific duty a requirement creates once applicable: a permit, notification, monitoring, record keeping, training, reporting, or a physical standard.
Gap
A shortfall between what a requirement obliges and what the site's current controls and evidence actually demonstrate.
Consequence of breach
The severity of exposure if a gap stays open, ranging from an advisory notice through fines and prohibition to loss of certification.

FAQ

Frequently asked questions about compliance obligation assessment

Who should complete a compliance obligation assessment?+

The compliance lead, drawing on input from whoever operates the process. It is only as reliable as the person answering Basis For The Decision actually understanding the activity, not just the regulation.

When does a requirement need reassessment?+

When the register is first built, whenever the task, area or population assessed materially changes, and whenever a Regulatory Change Record flags that the law has moved.

What if a requirement clearly does not apply?+

Record Applies To This Site as No with a stated Basis For The Decision. A clear no is legitimate; a no with no reasoning later looks like the requirement was simply overlooked.

Does this record replace the legal register?+

No. CMP-009 is the master list of requirements; this assessment is where one entry gets tested, obligated and, if a gap exists, tracked to closure.

What happens after a gap is identified?+

Consequence Of Breach and Gap Priority are recorded, Action Required is set, and a CAPA reference added where warranted. The gap should also be reflected back on the register.

Can the compliance obligation assessment template be changed?+

Yes. Every field, option, score and conditional rule is editable, and links to the register, permit and CAPA records come with it. Most teams install it as is, run it for a cycle, then adjust.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO 45001:2018 clause 6.1.3, Legal requirements and other requirements
  • ISO 14001:2015 clause 6.1.3, Compliance obligations
  • OSHA General Duty Clause, Section 5(a)(1), Occupational Safety and Health Act
  • Environmental Permitting (England and Wales) Regulations 2016

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.