Our own servers in Europe · GDPR · Support in your language

Module 1 of 7 · ISO 37301 · Clause 4

Context of the organization

The compliance system starts by mapping which legal, regulatory and voluntary obligations apply to the organization, and who has a stake in meeting them.

Content reviewed on

Internal and external context

Covers the applicable regulatory framework, organizational culture and sector factors that affect noncompliance risk.

Compliance obligations

Identifying legal, contractual and voluntary obligations, with their source and the owner tracking them.

Scope of the system

Defines which areas, processes and locations the compliance management system covers.

What an auditor usually asks for

  • An up-to-date compliance obligations register
  • A list of interested parties with their expectations
  • A compliance system scope statement
  • A process map flagging noncompliance risks

How to cover context in Kimobox

  1. 1Log compliance obligations as a versioned register in Kimobox.
  2. 2Log interested parties and their compliance expectations.
  3. 3Draw the process map flagging the noncompliance risk of each process.

Every compliance obligation stays linked to the process that must meet it, not in a separate list.

See how the process map works in Kimobox

Where each figure comes from

References to the official text in force. If a standard is revised, this page is updated and the review date says so.

  1. ISO 37301:2021 — Compliance management systems. Requirements with guidance for use ISO · April 2021
  2. Ley 2/2023 on the protection of persons who report regulatory breaches BOE-A-2023-4513 · 21 February 2023
  3. ISO 37001:2016 — Anti-bribery management systems ISO · 2016 ed.