What this is
What is the difference between an external issue and an internal issue in this review?
What is the difference between an external issue and an internal issue in this review?
An external issue originates outside the organisation's control — regulatory environment, market pressure, climate factors. An internal issue originates within it — organisational change, culture, asset condition. ISO 45001 cl.4.1 requires both, because either can change what the system needs to cover.
When does an interested party's expectation become a compliance obligation?
The moment the organisation decides, explicitly or by pattern of behaviour, that it will meet the expectation. A customer's audit requirement starts as an expectation; once accepted, an auditor treats it as binding regardless of legal force. Becomes A Compliance Obligation makes that a deliberate decision, not a default.
Why does a context review feed the objectives and legal register rather than standing alone?
Context and interested parties determine whether the system's scope, objectives and obligations are still correct. A review that identifies a new obligation but doesn't route it into the Legal Register has identified a risk and done nothing with it.
Scope
When is a context and interested parties review required?
This review sets the boundaries other records operate inside. It is not the place to log a specific obligation, run the management review meeting, or track an indicator — those belong on their own templates and this one feeds them.
Use this template when
- The annual review interval has arrived and senior management needs to reassess the organisation's context
- A trigger event has occurred — new regulation, acquisition, restructure, serious incident — that could change what the system needs to cover
- A new interested party has emerged, or an existing one's expectations have shifted
- The scope of the management system needs to be checked against what the organisation currently does
- Objectives or the legal register need a documented trigger explaining a revisit outside their normal cycle
Do not use it for
- Management Review Record, which records the periodic review by senior leadership across performance, risk, resources and improvement — this review is one input to that meeting, not the meeting itself.
- Management Review Action Log, which tracks actions arising from management review through to closure, not the context that prompted them.
- Performance Indicator Report, which reports measured leading and lagging indicators, a different kind of input than context and stakeholder expectations.
- Legal and Other Requirements Register, where an accepted obligation is actually logged — this review only decides one exists and points to the register entry.
- Management System Objectives, which holds the objectives themselves; this review only flags whether they still fit the current context.
Compliance mapping
Which ISO 45001 cl.4.1 requirements does this satisfy?
ISO 45001 cl.4.1 and cl.4.2 require determining the organisation's context and interested parties' needs and expectations. The form's sections map onto that structure, with a final section deciding what the findings mean for scope and objectives.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 45001 cl.4.1 | Determine external issues relevant to the organisation's purpose and OHS management system | External issues |
| ISO 45001 cl.4.1 | Determine internal issues relevant to the organisation's purpose and OHS management system | Internal issues |
| ISO 45001 cl.4.2 | Determine interested parties relevant to the system and their needs and expectations | Interested parties |
| ISO 45001 cl.4.2 | Determine which of those needs and expectations become compliance obligations | Interested parties |
| ISO 45001 cl.7.4 / cl.5.4 | Consult and communicate with workers and other interested parties | Interested parties |
| ISO 45001 cl.4.3 | Determine system scope, considering the issues and parties identified above | Impact on the system |
| ISO 45001 cl.6.2 | Confirm OHS objectives remain consistent with the organisation's context | Impact on the system |
| ISO 45001 cl.9.3 | Provide context and interested party findings as an input to management review | Impact on the system |
What it does not cover
- Interested Party entries that have not changed in three consecutive annual reviews, suggesting the list is copied forward rather than reassessed against who actually has a stake now.
- Becomes A Compliance Obligation, which is marked No for an expectation the organisation is visibly already meeting in practice, leaving a real obligation untracked in the legal register.
- Scope Of The System Still Correct, which is marked Yes without cross-checking against a known internal change — a new site, an acquisition — recorded elsewhere in the same review.
- Currently Meeting Expectation, which is marked Partly or No with no Gap Detail and no Action Required, leaving a known shortfall with no path to close it.
- Engagement Method, which is marked None for a party whose expectations materially affect the system, meaning the organisation is guessing at what that party wants rather than asking.
Global
Context and Interested Parties Review requirements by country
The context clause is jurisdiction-agnostic, but the interested parties it forces the organisation to name — regulators, unions, certification bodies — carry different weight by location.
EU Corporate Sustainability Due Diligence Directive
Customer and investor parties increasingly bring supply-chain due diligence and ESG disclosure expectations that previously fell outside an OHS system's context.
An EU-linked site's Market And Customer Pressures field should be checked for ESG-driven obligations a safety-focused review would otherwise miss.
OSHA General Duty Clause and state plan variations
Regulators carry different weight across US states with their own OSHA-approved state plans, some imposing requirements beyond federal OSHA.
Regulatory Environment entries for US sites need to name the specific state plan in force, not just federal OSHA, or the review understates what regulators expect.
Health and Safety at Work etc. Act 1974, s.2(6)
The statutory duty to consult employees or their representatives gives the Workers category a legal engagement requirement, not just a best-practice one.
A UK site marking Engagement Method as None or Correspondence for Workers may be falling short of the statutory duty, not merely a weak choice.
How to complete it
How to complete a context and interested parties review, step by step
The fields are mostly free text and single-choice picks. The judgement is in what gets accepted as real, and what gets waved through as unchanged.
Becomes A Compliance Obligation is the pivotal decision here. Marking it No because the expectation isn't legally enforceable misses the point — an auditor treats an accepted customer requirement as binding regardless of legal force.
A list unchanged across several cycles should be treated as a finding in itself. The call is actively asking who is missing — a new major customer, a union that formed — not confirming existing names are still accurate.
Scope Change Required and New Objectives Proposed can be marked Yes and left without a next step. The review only works when a Yes results in a routed change, not an acknowledgement alone.
Fields like Labour Market Factors are free text, easy to fill with a vague generality. The call is writing it specifically enough that next year's reviewer can tell whether it changed.
What auditors find
Most common context and interested parties review findings
Patterns that show up when several years of this review are read side by side, rather than assessed one year at a time.
| Finding | Clause | What fixes it |
|---|---|---|
| The Interested Parties list is identical, entry for entry, across three or more annual reviews | ISO 45001 cl.4.2 | Require the reviewer to actively confirm or revise each entry against the current stakeholder landscape, rather than letting prior entries carry forward. |
| External issues text is generic enough to apply to any site in the sector, with no reference specific to this period | ISO 45001 cl.4.1 | Ask for one concrete, dated example per field — a specific regulatory change, a named customer pressure — so the entry is falsifiable, not boilerplate. |
| Becomes A Compliance Obligation is marked No for expectations the organisation demonstrably already treats as binding | ISO 45001 cl.4.2 | Cross-check any No against current contracts and audit findings; an expectation already met in practice should usually be marked accepted. |
| Scope Of The System Still Correct is marked Yes in the same review where Internal Issues describes a new site or acquisition | ISO 45001 cl.4.3 | A described organisational change should force Scope Of The System Still Correct to be re-justified, not defaulted to Yes. |
| Currently Meeting Expectation is marked Partly or No repeatedly for the same party with no Gap Detail and no linked action | ISO 45001 cl.10.2 | Require Gap Detail and an Action Required decision whenever the answer is not Yes, so a shortfall cannot persist unrecorded. |
| Next Review Due dates drift later each cycle, or the review runs well past due with no note explaining the delay | ISO 45001 cl.4.1 | Flag any review completed past a defined margin — a late context review means the system may be working from a stale picture of its environment. |
Case in point
Case in point: the obligation nobody had accepted
A manufacturer's context review had listed 'Customers' as an interested party every year since certification, with Their Needs And Expectations reading 'on-time delivery and quality' unchanged for four cycles. Two years earlier, its largest customer's renewed contract quietly added a clause requiring annual supplier ESG disclosure. Nobody updated the entry, because the clause arrived through procurement, not the person compiling the review.
When that customer's audit team asked for the disclosure the following year, the organisation had no record the expectation existed, no Becomes A Compliance Obligation decision, and nothing in the Legal Register. The review had been completed on schedule every year — Scope Correct, Objectives Relevant, all Yes — while the one expectation that mattered had never been revisited.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
5 sections
- Reference
- CMP-017
- Archetype
- Review
- Record ID
- CIP-2026-000
- Scoring
- Not scored
- Direction
- n/a
- Singleton
- No
- Basis
- ISO 45001 cl.4.1
- Links
- Links Site; feeds Objectives
- Tags
- Governance, Context
- Sections
- 5
- Fields
- 46
- Follow up fields
- 3
- Repeating sections
- 1
- Links out
- 4
Header
10 fieldsReview ID*
Auto sequence. Format CIP-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Period Covered*
Reviewed By*
Participants
Who Cares And What Do They Want
Interested parties are not an abstract clause. They are the regulator, the customer, the neighbour and the workforce, each with expectations that become obligations if you accept them.
External issues
6 fieldsRegulatory Environment
Market And Customer Pressures
Supply Chain Factors
Labour Market Factors
Difficulty recruiting changes everything from training load to fatigue risk.
Technology Changes
Climate And Environmental Factors
Internal issues
6 fieldsOrganisational Changes
Capability And Resource Position
Culture And Engagement
Infrastructure And Asset Condition
Financial Position Affecting The System
Recent Incidents Shaping Priorities
Interested parties
Repeats8 fieldsInterested Party*
Workers, unions, regulators, customers, consumers, suppliers, contractors, neighbours, insurers, certification bodies or owners.
Their Needs And Expectations*
Becomes A Compliance Obligation*
Once you accept an expectation, an auditor will treat it as binding. Decide deliberately.
- No3 pts
- Yes1 pt
Added To Legal Register
- Yes3 pts
- No0 pts
Register ID
Links to CMP-009 Register ID
Currently Meeting Expectation*
- Yes3 pts
- Partly1 pt
- No0 pts
Gap Detail
Engagement Method*
- Formal consultation3 pts
- Meetings3 pts
- Survey2 pts
- Correspondence1 pt
- None0 pts
Impact on the system
16 fieldsScope Of The System Still Correct*
- Yes3 pts
- Needs change1 pt
Scope Change Required*
- No3 pts
- Yes1 pt
Risks And Opportunities Updated*
- Yes3 pts
- No0 pts
Objectives Still Relevant*
- Yes3 pts
- Partly1 pt
- No0 pts
New Objectives Proposed*
- Yes3 pts
- No1 pt
Objectives ID
Links to CMP-025 Objectives ID
Feeds Management Review*
Next Review Due*
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Compliance Lead*
Signature*
Site Manager*
Second Signature*
CMP-017 · record IDs look like CIP-2026-000 · Links Site; feeds Objectives
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
Writing the review is straightforward. Noticing which party quietly changed what it expects, and routing that into the legal register before it becomes a gap, is the work that slips.
Holds the review against the legal register and objectives it feeds, flags interested party entries unchanged for years, and routes accepted obligations into the register automatically.
Surfaces contractor and supplier expectations — audit clauses, insurance requirements — that often arrive through procurement rather than through the compliance team compiling this review.
Feeds climate and environmental factors and regulator-driven ESG expectations into External issues, so the review reflects live tracking rather than a generic annual paragraph.

Coordinates the crew across workspaces, rolls completion and exceptions into one view, and holds every write for your approval before it touches a record.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Meet KnowComply→Glossary
Context and Interested Parties Review definitions and key terms
- Interested party
- Any person or organisation that can affect, be affected by, or perceive itself affected by the management system — workers, regulators, customers, neighbours, insurers and certification bodies.
- Compliance obligation
- A requirement the organisation must or has chosen to comply with, drawn from legal requirements and from accepted interested party expectations.
- Scope of the management system
- The defined boundary of what the OHS management system covers — which sites, activities and processes fall inside it.
- Context of the organisation
- The combination of external and internal issues relevant to the organisation's purpose that affect its intended OHS outcomes.
- Trigger event
- An occurrence outside the normal review cycle — an acquisition, a new regulation, a serious incident — significant enough to warrant reassessing context early.
FAQ
Frequently asked questions about context and interested parties review
What is the context and interested parties review template based on?+
It is built against ISO 45001 cl.4.1, requiring the organisation to determine external and internal issues relevant to its purpose, alongside cl.4.2's requirement to identify interested parties and their expectations.
What sections does the review contain?+
Five sections: Header, External issues, Internal issues, Interested parties, and Impact on the system — 46 fields, 25 required, with Interested parties repeating for each party identified.
How often is a context and interested parties review raised?+
Yearly by default, and after any trigger event — a new regulation, an acquisition, a serious incident — that could change the organisation's context before the next scheduled review is due.
Why isn't this template scored?+
Its value is in the judgement calls it records, not a percentage. A well-reasoned decision that nothing needs to change is as valid an outcome as a scope revision.
What happens after an interested party's expectation is accepted as an obligation?+
It should be logged in the Legal and Other Requirements Register, using the Register ID field on this form to link the two records, so the obligation is tracked going forward.
Can the template be changed?+
Yes. Every field and conditional rule is editable, and the links to the legal register and objectives templates come with it. Most teams install it as is, run it for a cycle, then adjust which issues and parties they track by name.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Management System Governance
Legal and Other Requirements Register
Lists every law, regulation, permit and commitment that applies to your operation
Compliance Obligation Assessment
Assesses how each legal requirement applies to you and what you do to meet it
Compliance Evaluation Record
Records the periodic evaluation of whether you actually comply with each obligation
Regulatory Change Record
Records a change in law or regulation and what it means for you
Regulatory Inspection Record
Records a visit by a regulator, including what was inspected, what was said and any orders issued
Management Review Record
Records the periodic review of the management system by senior leadership, covering performance, risks, resources and improvement
More in Management Review
Management Review Record
Records the periodic review of the management system by senior leadership, covering performance, risks, resources and improvement
Management Review Action Log
Tracks the actions arising from management review through to closure
Performance Indicator Report
Reports the leading and lagging indicators for the management system over a period

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 45001:2018 cl.4.1 — Understanding the organization and its context
- ISO 45001:2018 cl.4.2 — Understanding the needs and expectations of workers and other interested parties
- ISO 45001:2018 cl.4.3 — Determining the scope of the OHS management system
- Health and Safety at Work etc. Act 1974, s.2(6) — duty to consult employees
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.