Internal and external context
Covers the applicable regulatory framework, organizational culture and sector factors that affect noncompliance risk.
Compliance obligations
Identifying legal, contractual and voluntary obligations, with their source and the owner tracking them.
Scope of the system
Defines which areas, processes and locations the compliance management system covers.
What an auditor usually asks for
- An up-to-date compliance obligations register
- A list of interested parties with their expectations
- A compliance system scope statement
- A process map flagging noncompliance risks
How to cover context in Kimobox
- 1Log compliance obligations as a versioned register in Kimobox.
- 2Log interested parties and their compliance expectations.
- 3Draw the process map flagging the noncompliance risk of each process.
Every compliance obligation stays linked to the process that must meet it, not in a separate list.
Where each figure comes from
References to the official text in force. If a standard is revised, this page is updated and the review date says so.
- ISO 37301:2021 — Compliance management systems. Requirements with guidance for use ISO · April 2021
- Ley 2/2023 on the protection of persons who report regulatory breaches BOE-A-2023-4513 · 21 February 2023
- ISO 37001:2016 — Anti-bribery management systems ISO · 2016 ed.