Evaluation of compliance with legal requirements — 9.1.2
A clause many read only halfway: they record their legal requirements and stop there. But 9.1.2 does not ask for a list — it asks for a periodic evaluation of how far you comply with each requirement, and a retained result of that evaluation.
The two pieces
| What it is | Where |
|---|---|
| The requirement — what binds you: a regulation, an instruction, a licensing condition, with its regulatory reference | Compliance requirements |
| The evaluation — a dated act of checking: do we comply? | Compliance checklists, each with a completion date |
| The violation — what the evaluation found | Violations, with severity and deadline |
The requirement is written once; the evaluation repeats. That is what "periodic" means in the clause.
Record the requirement with its reference
The regulatory reference field is not decoration: it is what turns a line from an opinion into an obligation. Write it as it reads (the regulation's name and article number) — that is what an auditor will compare against.
The mandatory flag separates what binds you legally from what you adopt voluntarily — and the metrics hold you to the mandatory ones only.
Three metrics now read the register
As of today the register is read on the compliance board:
- The requirements register is not empty — the first threshold.
- Every mandatory requirement was evaluated inside the window — one year by default. An empty register never turns green, and a mandatory requirement with no completed evaluation inside the window pulls the clause down.
- Open legal violations — how many findings remain unresolved.
Completion is read from the completion date, not from a status label: a date is a fact, a label is an opinion.
And its effect on the management review
The minutes now carry a section called "Evaluation of compliance with legal requirements", showing exactly what top management needs to see: the mandatory requirements not evaluated during the period — not a list of what was done. Alongside it, the count of open violations.
Practical advice: start with ten real requirements whose source you know, and actually evaluate them — better than a hundred copied lines nobody ever opened. Auditors measure depth, not length.
Where to find it: sidebar → Compliance → Compliance requirements, Checklists and Violations.