The current ISO standards require that the organisation must be compliant without explicitly specifying which areas of legislation it relates to. Although all organisations must be legal the practical outcome for external surveillance visits is that it gives the auditor a free rein on which areas t consider in their audit plan.
As part of the internal audit programme we now include a compliance check which largely covers the requirements of the ISO 140001 and ISO 45001 standards and identifies areas that the external auditor may stray into.
