Our own servers in Europe · GDPR · Support in your language

Regulatory compliance

Legal requirements, tracked one by one

Register which regulations apply to you, get an alert when they change, and periodically evaluate whether you meet them. Regulatory compliance stops living in the quality manager's head and becomes a live, auditable register.

What compliance means in practice

Regulatory compliance demands three things that are rarely written down: knowing which rules apply to the activity, finding out when those rules change, and periodically checking whether they are actually being met. The ISO standards ask for this explicitly — ISO 14001 in clause 9.1.2, ISO 45001 in its own — and yet that knowledge usually lives in the quality manager's head. Kimobox turns it into a register with an owner, evidence and a last-evaluated date.

Content reviewed on

Evaluation of compliance
ISO 14001:2015, clause 9.1.2 Requires periodic evaluation of legal requirements and retention of the evidence
Certifiable compliance standard
ISO 37301:2021 Replaced ISO 19600:2014, which was non-certifiable guidance
Criminal compliance in Spain
Art. 31 bis of the Criminal Code An effective organisation and management model can exempt the legal person from liability
Tax compliance
UNE 19602:2019 Spanish reference for tax compliance management systems
Whistleblowing channel
Law 2/2023 Mandatory from 50 employees; 1 December 2023 deadline for 50-249

Legal requirements register

What law, regulation or standard applies to you, for which activity and since when.

Alerts on regulatory changes

We notify you when a change in the law affects a requirement you've registered.

Periodic evaluation

Scheduled review of whether each requirement is met, with supporting evidence.

Auditable history

Who evaluated it, when and with what evidence, ready for an auditor or inspector.

What it tracks


From a regulatory change to a compliance report

  • Register of legal and other requirements by activity and site
  • Validity period and owner for each requirement
  • Automatic alert on relevant regulatory changes
  • Periodic evaluation of the compliance level
  • Supporting evidence attached per requirement
  • Compliance report for the management review
REGISTER OF LEGAL REQUIREMENTS REQUIREMENT VALIDITY OWNER STATUS GDPR · record of processing Yearly Quality UP TO DATE H&S · prevention plan Yearly H&S UP TO DATE Fleet roadworthiness test 05/10 Fleet REVIEW Environmental permit 22/09 Quality EXPIRING REGULATORY CHANGE DETECTED Official gazette 12/09 affects "Environmental permit" · review pending VALIDITY · OWNER · EVIDENCE · ALL IN ONE LIVING REGISTER

Real examples


Where legislation tracking breaks down

Industry with an environmental permit

A change in discharge limits

Before The amendment is published and nobody sees it until the enforcement notice arrives. The authorised values had been out of date for eight months.

After The requirement is registered with its source rule and its review date. When it changes, an evaluation task is raised with an owner and a deadline.

Multi-entity group

Which rules apply to which site

Before A single group-wide list that does not distinguish whether the site has more than twenty workers or handles hazardous waste.

After Applicable requirements by site and activity. Each manager sees only their own and its compliance status, not a list of two hundred rules.

Services · certification audit

Evaluation of compliance without evidence

Before The company states it complies with everything, but there is no record of when it was checked or by whom. The auditor raises a nonconformity.

After Each requirement holds its last evaluation, with date, owner, conclusion and supporting document. The evidence exists before anyone asks for it.

Vocabulary


Compliance without empty jargon

Evaluation of compliance
Periodic, documented verification of whether a requirement is met. ISO 14001 and ISO 45001 require it expressly, with the evidence retained.
ISO 37301
The international standard for compliance management systems, published in 2021 and certifiable. It replaced ISO 19600:2014, which offered guidelines only.
Organisation and management model
The set of supervision and control measures which, under art. 31 bis of the Spanish Criminal Code, can exempt a legal person from criminal liability if effective and supervised.
Compliance function
The unit with autonomous powers of initiative and control charged with overseeing how the model works. Its real independence is what a court examines.

Frequently asked questions


What people ask us before getting started

Do you monitor regulatory changes for me?

We track regulatory changes tied to the requirements you've registered and alert you; it doesn't replace legal advice.

Does it work for any industry?

Yes, the requirements register adapts to your activity, covering both general and sector-specific regulation.

Does it connect to quality non-conformities?

Yes, an unmet requirement can open a non-conformity or corrective action in the same system.

Which standard requires evaluating legal compliance?

ISO 14001:2015 requires it expressly in clause 9.1.2, and ISO 45001:2018 does the same in its own. Both require periodic evaluation of compliance and retention of the evidence.

Is ISO 19600 still current?

No. ISO 19600:2014 was non-certifiable guidance and was replaced by ISO 37301:2021, which is certifiable and states its content as requirements. If your system still refers to 19600, it is worth revisiting.

How does this relate to criminal compliance?

Art. 31 bis of the Spanish Criminal Code allows a legal person to be exempted from liability where an effective organisation and management model exists, adopted before the offence and supervised by a body with autonomous powers. A living register of requirements and evaluations is part of that effectiveness.

Is a whistleblowing channel required?

Yes, for employers with fifty or more workers. Spanish Law 2/2023 requires it, with a 1 December 2023 deadline for those with between fifty and 249 people, and specific acknowledgement and response deadlines.

Can it be run by site?

Yes, and that is the sensible approach. Applicable requirements differ between a fifteen-person site and a plant with an environmental permit. Each owner sees their own, not a general list of two hundred rules.

Show us which regulation is keeping you up at night

We'll show you the module running with data similar to yours.

Request a demo

Sources


Where each figure comes from

References to the official text in force. If a standard is revised, this page is updated and the review date says so.

  1. ISO 37301:2021 — Compliance management systems. Requirements with guidance for use ISO · April 2021
  2. Organic Law 10/1995, Spanish Criminal Code, art. 31 bis BOE-A-1995-25444 · Consolidated text
  3. Law 2/2023 on the protection of persons who report regulatory breaches BOE-A-2023-4513 · 21 February 2023
  4. Boletin Oficial del Estado Spanish Official Gazette · Published daily

Regulatory compliance software: legal requirements and regulatory tracking

Kimobox's regulatory compliance module centralizes the register of legal and other requirements applicable to your activity, with validity period, owner and compliance evidence per requirement.

Regulatory change tracking alerts you when a new law or regulation affects a registered requirement, and the periodic evaluation leaves an auditable history ready for a management review or an inspection.