What this is
What is a compliance obligation assessment?
What is a compliance obligation assessment?
It is the record that turns one line of the legal register into a tested judgement: whether a requirement applies here, on what basis, what it obliges, whether a control already meets it, and what closes any gap. The register lists the law; this assessment decides what it means on site.
What is the difference between 'currently below threshold' and 'would apply if we grow'?
Currently Below Threshold records where the site sits today against a trigger. Would Apply If We Grow is forward-looking: whether a plausible change in scale would cross it. A requirement that does not bind today can bind next quarter, so the two are asked separately.
How is Gap Identified different from Consequence Of Breach?
Gap Identified is factual: does a control exist and does evidence back it up. Consequence Of Breach is a severity judgement, from Advisory to Loss Of Certification. A small gap can carry a severe consequence, or the reverse; one field alone misprioritises the queue.
Scope
When is a compliance obligation assessment required?
This assessment is the applicability-and-gap step in a larger governance programme. Using it to list requirements, record a periodic compliance check, or log a change in the law itself overlaps the wrong neighbouring template.
Use this template when
- A requirement has just been added to the legal register and nobody has decided whether or how it applies to this site
- A site, process, headcount or throughput has materially changed and a prior applicability decision needs re-testing
- A new record is needed; each one gets its own ID in the form COA2-2026-000
- A permit, notification, monitoring or reporting obligation needs its control checked against the evidence backing it
- A gap has been found and needs a documented consequence, priority and, where warranted, a linked action
Do not use it for
- Legal and Other Requirements Register, which lists every law, regulation, permit and commitment; this assessment tests one entry rather than building the list.
- Compliance Evaluation Record, the periodic check of whether the site still complies with an obligation already assessed, not the first-time applicability call.
- Regulatory Change Record, which captures a change in the law itself; this assessment runs after that record triggers a re-test.
- Environmental Permit Register, which tracks a permit and its conditions once confirmed required; this only decides a permit is needed and links out once it exists.
- Anything outside KnowComply, which belongs in the workspace that owns that process
Compliance mapping
Which ISO 45001 cl.6.1.3 requirements does this satisfy?
ISO 45001 cl.6.1.3 requires not just identifying applicable requirements but determining how they apply and keeping that current. This assessment carries the determination, not merely echoes the register.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 45001 cl.6.1.3 | Legal and other requirements determined, traceable to the site and requirement covered | Header |
| ISO 45001 cl.6.1.3 | Applicability assessed and the basis for the decision documented | Applicability |
| ISO 45001 cl.6.1.3 | Thresholds or triggers tracked, including proximity to the trigger | Applicability |
| ISO 45001 cl.6.1.3 | The specific obligation identified, such as a permit, notification, monitoring or reporting duty | Obligations |
| ISO 45001 cl.6.1.3 | Where a permit is the obligation, status tracked against whether one is required and whether held | Obligations |
| ISO 45001 cl.6.1.3 | Existing controls evaluated against the requirement, with evidence availability recorded | Current position |
| ISO 45001 cl.6.1.3 | Gaps graded by consequence and priority, and the requirement confirmed added to the register | Current position |
| ISO 45001 cl.6.1.3 | A review date set so the determination is re-tested, not assumed to hold indefinitely | Current position |
What it does not cover
- Legal and Other Requirements Register, the master list this assessment tests one entry from; it does not itself decide applicability.
- Compliance Evaluation Record, the periodic check that the site still meets an obligation already assessed here as applicable.
- Regulatory Change Record, which captures what changed in the law and prompts a re-run, but does not carry the applicability decision itself.
- Environmental Permit Register, where a confirmed permit and its conditions live once Permit Held moves past Applied For; this record only flags that one is needed.
- Corrective and Preventive Action, the referenced action record once a gap is raised with Action Required set to Yes; the CAPA ID here is a link, not the plan.
Global
Compliance Obligation Assessment requirements by country
ISO 45001 sets the duty to assess; the regulator that issued the underlying law sets what it obliges and how a missed threshold bites. These three positions carry the most exposure from a wrong threshold or permit judgement.
OSHA General Duty Clause; EPA permitting thresholds administered federally or delegated to states
Many US obligations are threshold-triggered by headcount, chemical quantity or emissions rate; below-threshold operations owe nothing under that rule until they cross it.
A site marked Currently Below Threshold with no answer to Would Apply If We Grow is exposed the moment growth crosses that line, often before the assessment is re-run.
Health and Safety at Work etc. Act 1974; Environment Agency permitting under the Environmental Permitting Regulations
UK enforcement bodies expect a current legal register and a traceable basis for applicability, not a static list built once and never revisited.
Basis For The Decision left blank is what an inspector tests: not whether the right law is named, but whether the site can explain the ruling.
ISO 45001:2018 cl.6.1.3; ISO 14001:2015 cl.6.1.3 for environmental obligations assessed the same way
Both standards treat legal and other requirements as live inputs, requiring the organisation to know how each applies, not only that it exists.
A decision with no stated basis, or a gap with no consequence rating, reads at audit as identified but not actually determined.
How to complete it
How to complete a compliance obligation assessment, step by step
Most of this assessment is straightforward once someone sits with the requirement. These four calls are where a rushed answer quietly creates exposure that surfaces later.
Applies To This Site is the visible choice, but Basis For The Decision makes it defensible. A one-line reason tied to the actual activity beats a blank field when someone not in the room later reviews the judgement.
Currently Below Threshold scores well, but Margin To Threshold and Would Apply If We Grow carry the real judgement. A site at 90 percent of a headcount trigger with no growth answer is one contract win from an unprepared requirement.
A requirement can be correctly flagged as needing a permit while the permit itself is still Applied For or missing; reporting on the identification alone hides the exposure in the second field.
Gap Priority and Consequence Of Breach should drive sequencing together. A quick fix rated Advisory should not queue ahead of a harder gap rated Prohibition or Loss Of Certification; easiest-first is a habit, not a risk basis.
What auditors find
Most common compliance obligation assessment findings
Sitting between the register and the evidence, this record's recurring problems are less about missing fields and more about answers that look complete but were never reasoned through.
| Finding | Clause | What fixes it |
|---|---|---|
| Applies To This Site answered without a completed Basis For The Decision. | ISO 45001 cl.6.1.3 | Make the basis field mandatory in practice; reject determinations that give a choice with no reasoning. |
| Currently Below Threshold marked Yes with no entry in Margin To Threshold, so proximity is invisible. | ISO 45001 cl.6.1.3 | Require a margin figure for threshold-based requirements, and flag any margin inside a defined buffer. |
| Would Apply If We Grow left unanswered on requirements tied to headcount, volume or throughput. | ISO 45001 cl.6.1.3 | Treat this field as required wherever Thresholds Or Triggers is populated, and re-run the assessment when growth plans are confirmed. |
| Permit Or Licence Required marked Yes with Permit Held left blank rather than tracked to Applied For or No. | ISO 45001 cl.6.1.3 | Block closure until Permit Held carries a current answer, and link the Permit Register ID once one is issued. |
| Gap Identified marked Yes with Consequence Of Breach recorded as Advisory regardless of actual exposure. | ISO 45001 cl.6.1.3 | Require the rating to reflect the instrument's real enforcement powers, not a default low setting. |
| Added To Register left as No after the assessment is marked Complete. | ISO 45001 cl.6.1.3 | Treat Added To Register as a gate before status can move to Complete. |
Case in point
Case in point: the threshold nobody watched
A site assessed a wastewater discharge notification requirement as not applicable, since volume sat below the regulatory trigger. Applies To This Site was recorded as No, Currently Below Threshold as Yes, and Margin To Threshold was left blank. Would Apply If We Grow was answered No, reasoning that production had been flat for two years.
A new production line added eight months later pushed discharge volume past the trigger within the first quarter. With no margin recorded there was no baseline, and the growth question had been answered from a stale assumption rather than the capital plan already under discussion. The notification obligation was missed until a routine regulator visit flagged it.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
4 sections
- Reference
- CMP-010
- Archetype
- Assessment
- Record ID
- COA2-2026-000
- Scoring
- Compliance percent
- Direction
- High is good
- Singleton
- No
- Basis
- ISO 45001 cl.6.1.3
- Links
- Links Legal Register
- Tags
- Compliance, Assessment
- Sections
- 4
- Fields
- 41
- Follow up fields
- 4
- Repeating sections
- 0
- Links out
- 4
Header
10 fieldsAssessment ID*
Auto sequence. Format COA-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Requirement Title*
Register ID
Links to CMP-009 Register ID
Assessed By*
Decide Applicability Deliberately
Assuming a regulation does not apply is how sites end up with an unpermitted activity. Write down why it does or does not apply, so the judgement can be checked later.
Applicability
6 fieldsApplies To This Site*
Basis For The Decision*
Thresholds Or Triggers
Many requirements apply above a quantity, headcount or throughput. Record where we sit against it.
Currently Below Threshold
- Yes3 pts
- Marginal1 pt
- No0 pts
Margin To Threshold
Would Apply If We Grow
- No3 pts
- Yes1 pt
Obligations
8 fieldsObligation Type*
Permit or licence, notification, monitoring, record keeping, training, reporting, or a physical standard.
Deadlines Or Frequencies
Permit Or Licence Required*
- No3 pts
- Yes1 pt
Permit Held
- Yes3 pts
- Applied for1 pt
- No0 pts
Permit Register ID
Links to ENV-039 Register ID
Reporting Obligation*
- None3 pts
- Annual2 pts
- Quarterly2 pts
- On event1 pt
Reporting Deadline
Responsible Person Named*
- Yes3 pts
- No0 pts
Current position
17 fieldsControls In Place
Evidence Available*
- Yes3 pts
- Partly1 pt
- No0 pts
Gap Identified*
- No3 pts
- Yes0 pts
Gap Detail
Consequence Of Breach*
- Advisory3 pts
- Fine1 pt
- Prohibition0 pts
- Prosecution0 pts
- Loss of certification0 pts
Gap Priority*
How urgent closing the gap is. Separate from the priority of any action raised below.
- Low3 pts
- Medium1 pt
- High0 pts
- Critical0 pts
Legal Advice Sought
Added To Register*
- Yes3 pts
- No0 pts
Review Date*
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Assessed By*
Signature*
Compliance Lead*
Second Signature*
CMP-010 · record IDs look like COA2-2026-000 · Links Legal Register
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The basis for applicability and the threshold margin are exactly what gets skipped under time pressure. Keeping them visible is where the agent workspaces earn their place.
Holds the obligation assessment against the legal register, flags applicability decisions missing a stated basis, and tracks gaps through to a closed CAPA.
Watches permit-triggered obligations, surfacing any Permit Or Licence Required marked Yes where Permit Held has not progressed past Applied For.
Cross-checks threshold-based requirements against headcount and activity changes, flagging a site approaching a trigger before it crosses one unassessed.

Coordinates the crew, rolls open gaps and overdue reviews into one view, and holds every write for your approval before it touches a record.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Meet KnowComply→Glossary
Compliance Obligation Assessment definitions and key terms
- Applicability
- Whether a specific legal or other requirement binds this site's actual activity, scale or location, as distinct from whether it exists in general law.
- Threshold
- A quantity, headcount or throughput measure above which a requirement takes effect; many obligations stay inactive until a site crosses one.
- Obligation type
- The specific duty a requirement creates once applicable: a permit, notification, monitoring, record keeping, training, reporting, or a physical standard.
- Gap
- A shortfall between what a requirement obliges and what the site's current controls and evidence actually demonstrate.
- Consequence of breach
- The severity of exposure if a gap stays open, ranging from an advisory notice through fines and prohibition to loss of certification.
FAQ
Frequently asked questions about compliance obligation assessment
Who should complete a compliance obligation assessment?+
The compliance lead, drawing on input from whoever operates the process. It is only as reliable as the person answering Basis For The Decision actually understanding the activity, not just the regulation.
When does a requirement need reassessment?+
When the register is first built, whenever the task, area or population assessed materially changes, and whenever a Regulatory Change Record flags that the law has moved.
What if a requirement clearly does not apply?+
Record Applies To This Site as No with a stated Basis For The Decision. A clear no is legitimate; a no with no reasoning later looks like the requirement was simply overlooked.
Does this record replace the legal register?+
No. CMP-009 is the master list of requirements; this assessment is where one entry gets tested, obligated and, if a gap exists, tracked to closure.
What happens after a gap is identified?+
Consequence Of Breach and Gap Priority are recorded, Action Required is set, and a CAPA reference added where warranted. The gap should also be reflected back on the register.
Can the compliance obligation assessment template be changed?+
Yes. Every field, option, score and conditional rule is editable, and links to the register, permit and CAPA records come with it. Most teams install it as is, run it for a cycle, then adjust.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Management System Governance
Legal and Other Requirements Register
Lists every law, regulation, permit and commitment that applies to your operation
Compliance Evaluation Record
Records the periodic evaluation of whether you actually comply with each obligation
Regulatory Change Record
Records a change in law or regulation and what it means for you
Regulatory Inspection Record
Records a visit by a regulator, including what was inspected, what was said and any orders issued
Management Review Record
Records the periodic review of the management system by senior leadership, covering performance, risks, resources and improvement
Management Review Action Log
Tracks the actions arising from management review through to closure
More in Legal Register
Legal and Other Requirements Register
Lists every law, regulation, permit and commitment that applies to your operation
Compliance Evaluation Record
Records the periodic evaluation of whether you actually comply with each obligation
Regulatory Change Record
Records a change in law or regulation and what it means for you
Regulatory Inspection Record
Records a visit by a regulator, including what was inspected, what was said and any orders issued

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 45001:2018 clause 6.1.3, Legal requirements and other requirements
- ISO 14001:2015 clause 6.1.3, Compliance obligations
- OSHA General Duty Clause, Section 5(a)(1), Occupational Safety and Health Act
- Environmental Permitting (England and Wales) Regulations 2016
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.