What Clause 6.1.3 Is Actually Asking
Clause 6.1.3 of ISO 45001 sits within the planning section of the standard, and its job is straightforward in principle: your organisation must determine and have access to the legal requirements and other requirements that apply to your OH&S hazards and risks. Simple enough on paper. In practice, this clause trips up more organisations than almost any other in the standard.
On this page
The requirement is not just to have a list of laws. It goes further. You need to determine how those requirements apply to your organisation, communicate them to workers, take them into account when establishing and maintaining your OH&S management system, and evaluate compliance against them. That is a lot of work hanging off a single clause, and auditors will probe every part of it.
This article walks through what Clause 6.1.3 actually requires, what auditors look for when they review it, the most common failures organisations make, and how to build a legal register that genuinely supports your OH&S system rather than sitting in a drawer gathering dust.
The Two Categories: Legal Requirements and Other Requirements
The clause uses the phrase legal requirements and other requirements, and it is worth being precise about what each category includes.
Legal Requirements
Legal requirements are the obligations that flow from legislation, regulations, codes, and enforceable standards. In Australia, this includes:
- The Work Health and Safety Act in each jurisdiction (the model WHS Act applies in most states and territories, with Western Australia and Victoria having their own legislation)
- Work Health and Safety Regulations in each jurisdiction
- Codes of practice issued under WHS legislation, which are not technically mandatory but are treated as setting the benchmark for what is reasonably practicable
- Industry specific legislation such as the Dangerous Goods Act, Radiation Safety Act, or Mines Safety legislation depending on your sector
- Local government requirements that apply to your site or operations
- Licence conditions and permit requirements
One point that catches organisations out is the jurisdictional complexity of Australian WHS law. If you operate across multiple states, you may have different legal obligations in each. A legal register built only around the jurisdiction of your head office will be incomplete if you have workers elsewhere.
Other Requirements
Other requirements are the non legislative obligations your organisation has chosen to accept or that apply through agreements. These include:
- Industry codes and standards you have committed to follow
- Collective agreements and enterprise bargaining agreements that include OH&S provisions
- Contractual requirements from clients or principal contractors
- Voluntary commitments made in your OH&S policy
- Requirements from parent companies or corporate standards
- Standards adopted as part of your management system, such as guidance from Safe Work Australia
The distinction matters because auditors will ask you to show that you have captured both categories. Organisations that only list legislation often miss contractual requirements entirely, particularly where they work on client sites or under principal contractor arrangements.
Exemplar Global Recognised Training ProviderRTP No. 310970What the Clause Requires You to Do With the Information
Identifying the requirements is only the first step. Clause 6.1.3 sets out several additional obligations that organisations frequently overlook.
Determine How Requirements Apply
You cannot simply list a piece of legislation and consider the job done. The clause requires you to determine how each requirement applies to your organisation. This means understanding which parts of the legislation are relevant to your specific hazards, activities, and workers, and what you actually need to do to comply.
For example, the WHS Regulations contain specific requirements for managing risks from plant, confined spaces, working at heights, hazardous chemicals, and many other hazards. A construction company needs to work through which of those requirements apply to its specific activities and document what compliance looks like in practice. A generic reference to the WHS Regulations without that analysis does not satisfy the clause.
Take Requirements Into Account When Building the OHSMS
The requirements you identify must actually shape your management system. Your hazard identification process, risk controls, procedures, training programmes, and monitoring activities should all be traceable back to the legal and other requirements that drive them. If a requirement is listed in your register but has no visible influence on how you operate, an auditor will question whether you have genuinely taken it into account.
Communicate Requirements to Workers
Workers need to understand the requirements that apply to their work. This does not mean every worker needs to read the full text of the WHS Act, but they should understand the obligations that are relevant to what they do, the controls that are in place to meet those obligations, and why those controls matter. This connects directly to Clause 7.3 on awareness.
Evaluate Compliance
Clause 9.1.2 of ISO 45001 requires you to evaluate compliance with legal and other requirements at planned intervals. That evaluation needs to be documented and the results need to go into your management review. The legal register is the starting point for that evaluation, which is why keeping it current matters so much.
Building a Legal Register That Actually Works
Most organisations use a legal register or compliance obligations register to meet the requirements of Clause 6.1.3. The structure of that register matters, and a poorly designed one will create more problems than it solves.
What the Register Should Capture
A functional legal register should record, at a minimum:
- The name and reference of each legal requirement or other requirement
- The jurisdiction or source it comes from
- The specific obligations it creates for your organisation
- Which parts of your operations, processes, or hazards it applies to
- The controls or procedures in place to meet it
- Who is responsible for monitoring compliance
- The date it was last reviewed and the current compliance status
Some organisations add a column for the relevant clause of ISO 45001 to make auditing easier. That is a useful addition, but it is not required by the standard.
Keeping the Register Current
This is where most organisations fall down. A legal register that was accurate when it was created in 2021 but has not been updated since is a liability, not an asset. Legislation changes. New regulations are introduced. Codes of practice are revised. Licence conditions change when you add new activities or equipment.
You need a defined process for monitoring changes to applicable legislation and other requirements, and that process needs to be documented. The process should assign responsibility to a specific person or role, set a frequency for checking relevant sources, and include a mechanism for updating the register when changes occur.
In practice, this might mean subscribing to legislative update services, monitoring Safe Work Australia publications, checking with your industry association, or using a compliance software platform. The method matters less than the fact that it is systematic and documented.
Connecting the Register to Your System
A legal register that sits in isolation is not enough. Auditors will look for evidence that the requirements in your register are reflected in your procedures, risk assessments, training records, and operational controls. If your register lists requirements for working at heights but your procedures for working at heights make no reference to those requirements, you have a gap.
The most effective approach is to cross reference your legal register with your hazard register, your procedures, and your training matrix. That way, when a legal requirement changes, you can quickly identify which procedures and training need to be updated as well.
What Auditors Look For Under Clause 6.1.3
When an auditor reviews your compliance with Clause 6.1.3, they are looking for evidence across several areas. Understanding what they want to see will help you prepare effectively.
Completeness of the Register
Auditors will check whether your register covers the full scope of your operations and all relevant jurisdictions. They will look for obvious omissions. If you work with hazardous chemicals and your register does not include the relevant dangerous goods legislation, that is a finding. If you have workers in Queensland and New South Wales but your register only references New South Wales legislation, that is a finding.
Auditors will also check that other requirements are captured, not just legislation. Missing contractual obligations or voluntary commitments that are referenced in your OH&S policy are common gaps.
Evidence That Requirements Are Applied
It is not enough to have a list. Auditors will trace requirements from your register through to your procedures, risk assessments, and controls. They will ask workers whether they understand the requirements that apply to their work. They will look for evidence that the requirements have genuinely shaped how you operate.
Currency of the Register
Auditors will check when the register was last reviewed and whether it reflects current legislation. They will ask about your process for monitoring legislative change. If you cannot demonstrate a systematic approach to keeping the register current, expect a nonconformity.
Compliance Evaluation Results
Under Clause 9.1.2, you need to evaluate compliance at planned intervals. Auditors will look for evidence of those evaluations. If your register shows a requirement but there is no record of a compliance evaluation against it, that is a gap. The evaluation results should also be visible in your management review records.
Common Nonconformities Against Clause 6.1.3
Having audited organisations across a range of industries and jurisdictions, the following are the most frequently raised nonconformities against this clause.
- The register is out of date. This is the most common finding. Organisations build a register during implementation and then do not maintain it. Legislation changes and the register does not.
- The register covers legislation but not other requirements. Contractual obligations, enterprise agreement provisions, and voluntary commitments are frequently missing.
- No process for monitoring legislative change. The organisation cannot demonstrate how it finds out about changes to applicable legislation.
- Requirements are not reflected in procedures or controls. The register lists obligations that have no visible effect on how the organisation operates.
- Workers cannot explain the requirements that apply to their work. Awareness is insufficient, particularly for workers in high risk roles.
- Multi jurisdictional gaps. Organisations operating in more than one state or territory only capture requirements from one jurisdiction.
- No documented compliance evaluation. The organisation has a register but cannot show evidence of periodic compliance evaluation against it.
If you are preparing for a certification audit or surveillance audit, reviewing your register against each of these points before the auditor arrives is time well spent. For a deeper look at how auditors approach this clause during an audit, see our article on Auditing the Legal Register Under ISO 45001 Clause 6.1.3.
How Clause 6.1.3 Connects to the Rest of the Standard
Clause 6.1.3 does not operate in isolation. It connects to several other parts of ISO 45001 in ways that auditors will follow.
The requirements you identify under Clause 6.1.3 feed into your hazard identification and risk assessment under Clause 6.1.2. They inform your operational controls under Clause 8.1. They drive the training and awareness requirements under Clauses 7.2 and 7.3. They are the basis for your compliance evaluation under Clause 9.1.2. And the results of that evaluation go into your management review under Clause 9.3.
This means that a weak legal register creates weaknesses throughout your system. Auditors auditing ISO 45001 understand this and will often use the legal register as a starting point for tracing conformity through multiple clauses. For a broader view of how auditing occupational health and safety works in practice, the article on Auditing Occupational Health and Safety Under ISO 45001 covers the full picture.
Practical Tips for Quality and Safety Managers
If you are responsible for maintaining your organisation's OH&S management system, here are some practical steps to strengthen your compliance with Clause 6.1.3.
Start With a Scope Review
Before reviewing your register, confirm the scope of your OH&S management system. The legal requirements you need to capture are those that apply within that scope. If your scope has changed since the register was last built, the register needs to reflect that.
Use a Structured Review Process
Set a defined schedule for reviewing your register. For most organisations, an annual review is the minimum, with a process for capturing changes between scheduled reviews. Document the review, including who conducted it, what sources were checked, and what changes were made.
Assign Clear Ownership
Someone needs to own the legal register. That person needs to understand the legislative landscape relevant to your operations and have the time and resources to keep the register current. In larger organisations, this might be split across functions, with the WHS manager owning OH&S legislation and legal counsel owning other regulatory obligations.
Test Worker Awareness
Do not wait for an auditor to discover that your workers cannot explain the requirements that apply to their work. Build this into your internal audit programme. Ask workers in high risk roles what they understand about the legal obligations that govern their work. The answers will tell you whether your communication and training are effective.
Link the Register to Your Procedures
For each requirement in your register, identify the procedure, control, or training programme that gives effect to it. If you cannot find one, that is a gap that needs to be addressed. This cross referencing also makes it much easier to manage change when legislation is updated.
Understanding how this clause connects to the broader planning requirements of ISO 45001 is also valuable. The article on Risks and Opportunities in ISO 45001: Clause 6.1.1 Explained provides useful context for how Clause 6.1.3 fits within the planning framework.
Exemplar Global Recognised Training ProviderRTP No. 310970A Note on ISO 14001 and the Parallel Requirement
If your organisation also holds or is pursuing ISO 14001 certification, you will recognise the parallel structure. ISO 14001 has its own compliance obligations clause at 6.1.3, which covers environmental legal requirements and other requirements. The concepts are essentially the same, though the specific legislation and obligations will differ.
Many organisations maintain a combined compliance obligations register that covers both OH&S and environmental requirements. This can work well, particularly if you have an integrated management system, but you need to make sure the register is clearly structured so that OH&S and environmental requirements can each be identified and evaluated separately. For a detailed look at how the environmental version of this requirement works, see our article on Compliance Obligations in ISO 14001:2026: What Clause 6.1.3 Covers.
Building Auditor Competence Around Clause 6.1.3
If you are an internal auditor or aspiring lead auditor, Clause 6.1.3 is a clause worth spending time on. It is substantive, it connects to multiple other clauses, and it requires you to understand the legislative landscape relevant to the organisation you are auditing.
When auditing this clause, your preparation should include reviewing the legal register before the audit, identifying the key legislation that applies to the organisation's sector and jurisdiction, and planning questions that will test not just whether the register exists but whether it is current, complete, and genuinely integrated into the system.
On site, you should be sampling procedures and controls to verify they reflect the requirements in the register. You should be asking workers about their awareness of relevant obligations. And you should be looking for evidence of the compliance evaluation process, including records of when it was last conducted and what the results were.
This kind of clause specific, evidence based auditing is exactly what Audit Workshop training develops. Our ISO 45001 internal auditor and lead auditor courses cover how to audit each clause of the standard in a practical, evidence focused way, drawing on real audit scenarios rather than just explaining what the standard says. If you are looking to build genuine competence in auditing occupational health and safety management systems, the training is designed for practitioners who want to do the work properly.













