ISO 14001 Regulatory Watch: Our Tips to Optimize It

This article explains ISO 14001 regulatory monitoring, a process of identifying and updating legal and other obligations essential for a company's compliance and sustainability.

Marie Faucon
Consultante HSE
Publication : 
09.10.2020
Table of Contents
Request a demo

The ISO 14001 standard requires companies to identify the requirements applicable to their activities and to regularly update this information. This update process is commonly referred to as ISO 14001 Regulatory Monitoring. This regulatory monitoring obligation, present in ISO 14001, is also included in the ISO 45001, ISO 50001, and MASE standards.

Understanding the Requirements of ISO 14001

The ISO 14001 standard requires organizations (companies, local authorities, etc.) to identify the requirements applicable to their environmental aspects. Specifically, for a company, this involves listing the environmental texts applicable to its activities in the broadest sense, and extracting the requirements that concern it. By 'requirement,' we mean the parts of the text (chapters, articles, a sentence within an article, etc.) that constitute a mandatory obligation.

The ISO 14001 standard even recommends using the term 'compliance obligations' instead of the concept of requirements, as found in ISO 45001.

These compliance obligations can stem from legal requirements, such as the Environmental Code, but also from voluntarily undertaken requirements, such as environmental performance commitments made to local residents, associations, or clients.

ISO 14001 Regulatory Monitoring: Implementation

In line with the scope defined for the environmental management system, the following steps should be taken:

Step 1: Compile a list of applicable texts and identify the requirements to be met

To carry out this work, it is necessary to list the applicable texts based on activities, equipment, and products. Precise knowledge of the site is essential for quality work. For facilities subject to ICPE legislation, particular attention should be paid to identifying legal texts. Once the applicable texts have been collected, a detailed analysis of them must be carried out to extract/identify the truly applicable requirements.

Step 2: Perform ISO 14001 regulatory monitoring

Monitoring involves updating the information gathered in Step 1 based on regulatory changes, voluntarily undertaken commitments, and company developments (changes in activities). To perform this operation, it is necessary to access a significant number of monitoring sources. For example: Legifrance, the official bulletins of the Ministry of Ecological Transition, and their websites should be utilized. Generally, in the field of environmental protection and preservation (water, air, soil, waste, noise, ICPE, biodiversity, etc.), it is necessary to consult about twenty monitoring sources.

We advise you to review monitoring sources, such as the official gazette, daily or at least weekly, to select applicable texts. This action should primarily enable the identification of major texts with immediate applicability. The subsequent phase, which involves an in-depth analysis of the texts and their detailed impacts on your site, can then be carried out on a monthly or even quarterly basis.

Given the volume of data to be handled, more and more companies are turning to tools and/or services that enhance efficiency and ensure process reliability. They provide permanent access to up-to-date information, commented on by specialists.

Regulatory Monitoring: Key Points for Effective Implementation

  • Identifying monitoring sources: This preliminary work is essential and must be carried out rigorously; otherwise, the company might fail to identify a high-stakes compliance obligation that applies to it. The reputational or financial consequences can therefore be significant.
  • Understanding the company's activities, products, and services: Monitoring must be adapted to the company's context and specificities. It is crucial to accurately distinguish between immediately applicable requirements and future legal obligations.
  • Data access: Given the number of applicable requirements to identify and keep up to date. On average, in the ISO 14001 domain, a company must comply with approximately 1000 requirements (compliance obligations), and nearly 20% of these requirements change annually. It is therefore essential to have reliable and robust tools to manage this data effectively.
  • The organizational structure: Regulatory monitoring requires legal and technical expertise. It must be carried out rigorously and regularly. Identifying 'draft' texts, whether at European or national levels, is also a factor companies should not overlook.
  • Text analysis: This phase is crucial and must be carried out carefully. This analysis should allow for:
      • understanding the meaning of regulations when dealing with legislative texts,
      • concretely identifying the impacts for the company,
      • determining immediate actions to implement for compliance or strategic directions to consider.
  • Choosing external solutions: If using external software and/or service providers, it is essential to have direct access to the sources (texts) and thus be able to consult the original legal obligation to avoid inaccuracies or imperfect interpretations.

To learn more about the ISO 14001 regulatory monitoring / ISO 45001 / ISO 50001, we invite you to consult our white paper « how to effectively carry out your HSE regulatory monitoring?»

ISO 45001: Standard for occupational health and safety management systems
MASE: Company Safety Improvement Manual
ICPE: Installations Classified for Environmental Protection