Our own servers in Europe · GDPR · Support in your language

Module 1 of 4 · Regulatory compliance · Block 1

Identifying applicable legal requirements

The first step isn't compliance, it's knowing what to comply with: identifying the legal, regulatory and other requirements that apply to each activity and site.

Content reviewed on

General and sector-specific regulation

Requirements that apply to any company (labor, tax, data protection) and those specific to the sector (food, industrial, healthcare).

Other types of requirements

Voluntary commitments, client demands or codes of conduct the organization chooses to meet even when not mandatory.

By activity and site

The same requirement may apply to one site and not another, depending on the activity carried out at each.

What an auditor usually asks for

  • List of general regulation applicable to the company
  • List of sector-specific regulation applicable to the activity
  • Other types of requirements identified and documented
  • Requirements assigned to the corresponding activity and site

How to cover identifying requirements in Kimobox

  1. 1Register each legal requirement as a record with its source and scope.
  2. 2Link each requirement to the activity or site it applies to.
  3. 3Classify requirements as mandatory or other types.

Every legal requirement becomes a live record, not a note on the quality manager's computer.

See Kimobox's regulatory compliance

Where each figure comes from

References to the official text in force. If a standard is revised, this page is updated and the review date says so.

  1. ISO 14001:2015, clause 9.1.2 (evaluation of compliance) ISO · 2015 ed.
  2. Boletin Oficial del Estado Spanish Official Gazette · Published daily
  3. ISO 37301:2021 — Compliance management systems ISO · April 2021