Evaluation of compliance with legal requirements — 9.1.2

2 minOrg ownerCompliance manager

A clause many read only halfway: they record their legal requirements and stop there. But 9.1.2 does not ask for a list — it asks for a periodic evaluation of how far you comply with each requirement, and a retained result of that evaluation.

The two pieces

What it isWhere
The requirement — what binds you: a regulation, an instruction, a licensing condition, with its regulatory referenceCompliance requirements
The evaluation — a dated act of checking: do we comply?Compliance checklists, each with a completion date
The violation — what the evaluation foundViolations, with severity and deadline

The requirement is written once; the evaluation repeats. That is what "periodic" means in the clause.

Record the requirement with its reference

The regulatory reference field is not decoration: it is what turns a line from an opinion into an obligation. Write it as it reads (the regulation's name and article number) — that is what an auditor will compare against.

The mandatory flag separates what binds you legally from what you adopt voluntarily — and the metrics hold you to the mandatory ones only.

Three metrics now read the register

As of today the register is read on the compliance board:

  • The requirements register is not empty — the first threshold.
  • Every mandatory requirement was evaluated inside the window — one year by default. An empty register never turns green, and a mandatory requirement with no completed evaluation inside the window pulls the clause down.
  • Open legal violations — how many findings remain unresolved.

Completion is read from the completion date, not from a status label: a date is a fact, a label is an opinion.

And its effect on the management review

The minutes now carry a section called "Evaluation of compliance with legal requirements", showing exactly what top management needs to see: the mandatory requirements not evaluated during the period — not a list of what was done. Alongside it, the count of open violations.

Practical advice: start with ten real requirements whose source you know, and actually evaluate them — better than a hundred copied lines nobody ever opened. Auditors measure depth, not length.

Where to find it: sidebar → Compliance → Compliance requirements, Checklists and Violations.

More in this collection