ISO 45001 and Legal Compliance: Navigating OHS Legislation with Confidence

Occupational health and safety legislation is complex. The UK Health and Safety at Work etc. Act 1974, US OSHA regulations, Australian Work Health and Safety Act, EU directives—each jurisdiction mandates different requirements, different penalty levels, and different enforcement approaches. For organisations operating across multiple jurisdictions, navigating legal requirements is daunting.

Clause 6.1.3 of ISO 45001 requires you to “determine and have access to the applicable legal and other requirements related to its OH&S hazards.” This isn’t merely compliance exercise. Demonstrating that you’ve systematically identified and understood applicable legal requirements is the foundation of due diligence—your legal protection if an incident occurs or regulatory investigation begins.

This guide explores legal compliance requirements across major jurisdictions, how to build an effective legal register, how to keep requirements current, and how ISO 45001 certification demonstrates due diligence to regulators and courts.

Understanding Clause 6.1.3: “Determine and Have Access to” Legal Requirements

The wording is precise. “Determine” means you must actively identify applicable requirements rather than passively hoping they’ll appear. “Have access to” means you must maintain current information about requirements, not possess outdated knowledge. This clause requires ongoing effort, not one-time identification.

The scope is “applicable legal and other requirements related to its OH&S hazards.” This means: any legislation, regulation, or code applying to your organisation’s operations (based on your jurisdiction, industry, and specific processes). “Other requirements” can include contractual requirements (customers specifying OH&S standards), industry consensus standards, and voluntary certifications your organisation pursues.

The requirement is evaluated in Clause 9.1.2, which mandates compliance evaluation—assessing whether you’re actually meeting the legal requirements you’ve identified. Many organisations identify legal requirements but fail to evaluate whether they’re complying, which is precisely the due diligence gap that regulators target during investigations.

Global OHS Legislative Landscape

Major jurisdictions have established OHS legislation frameworks:

United Kingdom — Health and Safety at Work etc. Act 1974 (HSWA) is foundational legislation. It imposes general duties on employers to ensure health and safety of employees and others affected by their business. It applies to all organisations regardless of size. Regulation enforcement is through the Health and Safety Executive (HSE), which has authority to issue improvement notices, prohibition notices, and refer matters for prosecution. Serious breaches can result in substantial fines and director liability. The Health and Safety at Work Act (Northern Ireland) Order 1978 applies in Northern Ireland. The HSWA explicitly recognises management system-based approaches; ISO 45001 certification provides evidence of systematic compliance.

Australia — Work Health and Safety Act 2011 applies federally and has been adopted in all states with minor variations. The WHS Act imposes duties on “persons conducting a business or undertaking” (PCBUs), employees, and others. It requires PCBUs to identify hazards, assess risks, and implement control measures. The legislation mandates particular controls for certain hazards (machinery, hazardous substances, high-risk work). Enforcement is through Work Health and Safety regulators in each state. Serious breaches can result in significant fines and director/officer liability. The legislation explicitly permits use of management system standards as a control mechanism; ISO 45001 demonstrates systematic compliance.

United States — Occupational Safety and Health Act (OSHA) 1970 applies federally. It requires employers to provide workplaces “free from recognised hazards.” Specific standards apply to industries and hazards (construction, machinery, chemicals, electrical, etc.). Enforcement is through Occupational Safety and Health Administration. Penalties for serious violations can be substantial. Some states have additional regulations (California has additional requirements). OSHA recognises safety management systems; ISO 45001 certification can be mentioned in regulatory interactions, though OSHA doesn’t formally recognise ISO 45001 as substituting for OSHA compliance.

European Union — Framework Directive 89/391/EEC establishes general principles of prevention and employer duties. Individual directives address specific hazards (machinery, chemical safety, physical agents). Member states implement directives through national legislation. The UK’s HSW Act largely implements EU requirements; other EU countries have their own implementation. The EU emphasises risk assessment, hierarchy of controls, and continuous improvement—very aligned with ISO 45001’s philosophy.

Building and Maintaining an Effective Legal Register

A legal register systematically documents applicable legal requirements, their implications, and your compliance approach. An effective register includes: requirement description (what the law requires), applicable to your organisation (yes/no with explanation), jurisdiction and source (UK HSWA Clause 2(1), US OSHA 1910.147, etc.), control measures you’ve implemented (how you comply), responsible person (who ensures ongoing compliance), and review date (when to update).

How to Develop an Initial Legal Register — Start with hazard identification. For each significant hazard, identify applicable legal requirements in your jurisdiction. For example, if your organisation operates machinery, identify machinery regulations and guarding requirements. If you handle chemicals, identify chemical safety requirements. If you work at height, identify fall protection requirements. This exercise links hazards to legal requirements rather than attempting to list all possible legal requirements (which would be overwhelming).

Second, identify cross-cutting requirements applicable to all organisations: general duty of care, competence requirements for people doing safety-critical work, incident reporting requirements, and legal register/risk register requirements. Third, identify industry-specific requirements and any legal requirements specific to your location (some regions have additional requirements).

The output is a legal register document (spreadsheet or database) listing requirements and your compliance approach. Many organisations structure this with columns for: jurisdiction, requirement description, our applicable context, current control/procedure, responsible owner, review date. Start simple—add detail as you understand requirements better.

Keeping Legal Registers Current — This is the challenging part. Legislation changes. US OSHA updates standards, Australian WHS regulators issue new guidance, UK HSE publishes new enforcement expectations. Many organisations develop legal registers but fail to maintain them, resulting in compliance gaps when legislation changes.

Effective maintenance requires: assigning one person responsibility for monitoring legislative changes (safety manager, compliance officer, or external legal advisor), using regulatory monitoring services (many provide alerts when relevant legislation changes), conducting annual legal register review during management review to identify legislative changes affecting your organisation, and updating procedures when legal requirements change. Some organisations use external legal consultants to monitor changes; others subscribe to regulatory databases that alert to changes. Regardless of approach, systematic monitoring is essential.

Compliance Evaluation: Knowing Whether You Actually Comply

Identifying legal requirements is step one. Evaluating whether you comply is step two—and it’s often neglected. Many organisations can list legal requirements but haven’t objectively assessed whether they’re actually complying.

Clause 9.1.2 requires compliance evaluation as part of management review. Effective evaluation includes: reviewing audit findings addressing legal compliance, examining incidents to assess whether they represent legal compliance failures, monitoring regulatory authority interactions, and when significant legal requirements exist, conducting specific compliance audits.

For example, if your legal register specifies that machinery must have guarding meeting specific standards, compliance evaluation should include: walking through your facility verifying that guards are in place, evaluating whether guards meet the required standard (through inspection or engineering verification), assessing whether guards are maintained, and documenting findings. This goes beyond documenting that a policy exists—it verifies that your actual machines have required guards.

Compliance evaluation often reveals gaps. When gaps are found, your system requires: identifying why the gap exists (inadequate resources, lack of knowledge, competing priorities, systemic failure), determining whether gap represents legal violation or merely system improvement opportunity, implementing corrective actions to address the gap, and reassessing to confirm closure. Documentation of this process is your legal protection—if regulators investigate, you can demonstrate that you’re actively identifying and addressing compliance gaps.

ISO 45001 Versus Legal Compliance: Which Is Stronger?

ISO 45001 and legal compliance are complementary but distinct. Legal compliance meets mandatory minimum requirements—you must comply with applicable laws or face enforcement. ISO 45001 goes beyond legal minimums in many areas. Your legal register might specify that you “must provide guards on machinery” (legal requirement). ISO 45001 requires you to assess machinery hazards and implement proportionate controls—which might involve engineered guarding systems exceeding legal minimums, regular maintenance ensuring guards remain effective, or complete hazard elimination (choosing different machinery without the hazard).

A common misunderstanding: “If we’re ISO 45001 certified, we’re legally compliant.” This is not necessarily true. ISO 45001 certification demonstrates you have a management system, but certification doesn’t automatically mean you’re complying with specific legal requirements. A certified organisation that fails to identify an applicable legal requirement could be in legal violation. Certification is evidence of systematic approach but not guarantee of legal compliance.

Conversely, legal compliance doesn’t mean ISO 45001 certification. An organisation can legally comply (meeting all legal requirements) without ISO 45001 certification. However, systematic management system (like ISO 45001) makes continuous compliance more achievable and provides evidence of due diligence.

Best practice combines both: legal compliance as minimum requirement, ISO 45001 as framework for systematic improvement beyond legal minimums. When doing this successfully, legal compliance becomes natural outcome of systematic hazard management rather than separate exercise.

Due Diligence: Why Legal Compliance Matters

In regulatory investigations following serious incidents, organisations are typically investigated on two dimensions: did the incident happen (fact), and did the organisation do due diligence to prevent it (legal responsibility). An organisation that can demonstrate: systematic legal requirement identification, documented compliance evaluation, responsive corrective action when gaps were found, and ongoing management of legal requirements typically fares significantly better in investigation outcomes than an organisation claiming ignorance of legal requirements.

Due diligence is also important in civil litigation. If an injured worker sues your organisation, evidence of systematic OH&S management including legal compliance efforts substantially reduces liability. Courts recognise that organisations making genuine effort to identify and comply with legal requirements deserve more favourable outcomes than organisations being negligent.

Beyond investigation and litigation, demonstrating due diligence affects insurance. Insurers assess your legal compliance practices—organisations with documented legal registers and compliance evaluation receive more favourable insurance terms than those without systematic approach.

Navigating Jurisdictional Complexity for Multinational Organisations

Organisations operating across multiple countries face significant complexity. UK operations must comply with UK HSWA and any specific regulations (machinery directives, construction regulations). Australian operations must comply with WHS Act and state-specific regulations. US operations must comply with OSHA and any state-specific regulations. Each jurisdiction has different legal requirements, different enforcement approaches, and different penalty levels.

Effective approach for multinational organisations: establish a global legal compliance framework (common management system structure), identify requirements applicable in each jurisdiction, assign responsibility for legal compliance monitoring and evaluation in each location, and periodically review consistency across locations. Some requirements will be similar across jurisdictions (hazard assessment, incident investigation, emergency preparedness); some will be jurisdiction-specific (specific machinery standards, specific chemical regulations). Your legal register should distinguish between global requirements and jurisdiction-specific requirements.

Language is another complication. If operations occur in non-English-speaking countries, legal requirements are in local language and must be understood and implemented correctly. This often requires local legal expertise or external advisors familiar with local legislation.

Using Regulatory Databases and External Monitoring

Manually monitoring legislative changes is impractical. Many external services provide regulatory monitoring and alerts:

UK — HSE publishes updated guidance regularly; legal updates services (LexisNexis, Thomson Reuters) provide alerts when relevant legislation changes.

Australia — Work Health and Safety regulators publish updates and guidance; Australian Safety Community platform provides resources.

US — OSHA website publishes new standards and guidance; legal update services provide OSHA change alerts.

EU — EU OSHA (European Agency for Safety and Health at Work) publishes updates; national regulators publish implementation of EU directives.

Cost of external monitoring services ranges from £500-£3,000 annually depending on breadth of coverage. For organisations where legal compliance is complex or operations span multiple jurisdictions, external monitoring services are valuable investment—they reduce burden on internal staff and ensure systematic awareness of legal changes.

FAQ

How do we know if we’ve identified all applicable legal requirements?

Start with your hazard register. For each significant hazard, identify relevant legal requirements. Then identify cross-cutting requirements (applicable to all organisations): general duty of care, competence requirements, incident reporting. Then check industry-specific regulations, location-specific regulations, and any contractual requirements (customer specifications). No approach identifies absolutely all requirements, but systematic process catches most. Annual legal register review identifies requirements you initially missed. If your organisation enters a new jurisdiction or industry, conduct fresh legal requirements analysis for that new area.

How often should we review our legal register?

At minimum, annual review during management review. If you use external regulatory monitoring, review updates as alerts arrive (could be quarterly or more frequently depending on legislative activity in your jurisdiction). When operations change (new facility, new process, new equipment type), review legal requirements for those new areas. When incidents occur, evaluate whether they reveal previously unidentified legal compliance gaps.

What if we discover we’re not complying with a legal requirement?

Immediately assess the severity and scope of non-compliance. If it’s serious (major safety hazard with worker exposure), implement interim controls urgently. Determine root cause (lack of knowledge, inadequate resources, system failure). Develop corrective action addressing both the immediate gap and the systemic cause. Document what you found, why it happened, and how you fixed it. This documentation is your legal protection—demonstrating responsive action when gaps are discovered. Don’t ignore compliance gaps hoping regulators won’t notice; address them proactively.

Does ISO 45001 certification guarantee legal compliance?

No. ISO 45001 certification demonstrates you have a management system, but certification doesn’t automatically mean you’re complying with specific legal requirements. An organisation could be ISO 45001 certified but failing to comply with a specific legal requirement if that requirement wasn’t identified or implemented. ISO 45001 is a framework supporting legal compliance; proper implementation includes systematic legal requirement identification and evaluation. Certification is evidence of systematic approach, not guarantee of compliance.

How do we handle requirements from different jurisdictions that conflict?

This occasionally occurs. Where requirements conflict, choose the most stringent approach (meet the higher requirement, which will satisfy both jurisdictions). Document the conflict and your decision. For example, if UK machinery regulations require specific guarding and US regulations require more protective guarding, implement US-level protection at all facilities (satisfying both). When genuinely unable to comply with conflicting requirements, legal advice is warranted to understand your actual obligations.

What’s the penalty for non-compliance with legal requirements?

Penalties vary dramatically by jurisdiction and severity. UK: from prohibition notices (stopping work) to fines up to £20 million or imprisonment. Australia: from improvement notices to fines up to £3+ million for serious breaches. US OSHA: from citations with fines (serious violations up to $15,000+, willful violations up to $156,000+) to criminal prosecution. Beyond formal penalties, non-compliance can result in: civil liability (injured workers suing), reputational damage, insurance implications, and regulatory scrutiny on future operations.

Can we rely on our certification body to ensure we’re legally compliant?

No. Your certification body audits compliance with ISO 45001 standard, not compliance with every applicable legal requirement (though auditors check that you have legal register and evaluate compliance). You remain responsible for identifying and complying with legal requirements. Certification doesn’t transfer legal responsibility to the certification body.

Conclusion: Legal Compliance as Continuous Responsibility

Occupational health and safety legislation is complex and evolving. The only constant is change—regulations are updated, new hazards are recognised, and expectations for due diligence increase. ISO 45001 Clause 6.1.3 requires you to systematically identify and understand applicable legal requirements. Clause 9.1.2 requires you to evaluate whether you’re complying.

This is not one-time exercise. It’s continuous responsibility: maintaining current knowledge of legal requirements in your jurisdiction, evaluating compliance, identifying gaps, implementing corrective actions, and demonstrating due diligence through documentation. Organisations that take this responsibility seriously gain substantial legal protection and regulatory credibility. Organisations treating legal compliance as secondary to other pressures expose themselves to enforcement action, civil liability, and reputational damage.

The investment required—assigning responsibility for legal compliance monitoring, maintaining a legal register, conducting periodic compliance evaluation—is modest compared to the potential cost of non-compliance. More importantly, organisations that systematically understand and comply with legal requirements are typically the organisations with the strongest safety culture and best operational performance. Legal compliance isn’t burden—it’s foundation.

Uncertain about your legal compliance obligations? Contact us for a comprehensive legal requirement assessment and legal register development tailored to your jurisdiction and operations.