Your GPC signal was detected and honored.

New

CRA: new EU requirements for software and connected products

Skip to content
AmpliFlow
  • Tools
    Leadership & ProcessesStrategic management
    • Management SystemEverything in one place
    • ProcessesVisualize workflows
    • Management ReviewStructured meetings
    • GoalsSet and track goals
    • ProjectsRun projects in your management system
    • PolicyPolicies and guidelines
    • NewsInternal communication
    • PagesIntranet and knowledge base
    Deviations & RisksHandle the unexpected
    • DeviationsReport and resolve
    • ImprovementsContinual improvement
    • ActionsTrack actions
    • RisksIdentify and mitigate
    • Crisis ManagementBe prepared
    Documents & AuditsControl documents and audits
    • DocumentsVersion control
    • ChecklistsDigital checklists
    • AuditsPlan and execute
    • ReportsInsights and follow-up
    • AI ToolsBuilt-in AI and agents
    • Custom ListsStructured data
    • Year WheelVisual annual planning
    People & CompetenceCompetence and development
    • CompetenceMap competencies
    • Competency MatrixVisualize competency gaps
    • TrainingPlan training
    • Employee ReviewsStructured dialogues
    • Work EnvironmentHealth and safety
    External RequirementsSuppliers and regulations
    • SuppliersAssess and follow up
    • Legal RequirementsTrack regulations
    • Customer RequirementsCustomer specifications
    • StakeholdersMap stakeholders
    • Environmental AspectsEnvironmental impact
    View all tools
  • Solutions
    By industryTailored for your business
    • Manufacturing
    • Construction
    • Food & Beverage
    • IT & Tech
    • Logistics
    • Staffing
    By roleSee how AmpliFlow helps you as...
    • CEO
    • Quality Manager
    • IT Manager
    • Management Team
    By situationWhere are you in your journey?
    • StartupBuilding from scratch
    • Scale-upGrowing fast
    • EstablishedWant to professionalize
    • EnterpriseComplex organization
    • Pre-audit crunchFirst audit approaching
    • Replace old systemsThe file move costs nothing extra
    View all solutions
  • ISO
    ISO standardsFor visitors who know what they need
    • ISO 9001Quality and improvement
    • ISO 14001Environmental work and follow-up
    • ISO 27001Information security and controls
    • ISO 45001OHS, risks, and actions
    • ISO 22000Food safety and HACCP
    • ISO 42001AI governance and responsibility
    Several standards at once?Why many teams choose AmpliFlow
    • Integrated management systemRun ISO 9001, 14001, 27001, and 45001 in one platform
    • Already certifiedBring existing certifications into one working system
    • Book a callSee how several standards work together
    Cover of the e-book ISO 9001, 14001 and 45001Free e-bookEverything you need to understand the requirements and achieve certification.Download for free
    View all standards
  • Articles
    Read and learnNew content and practical guides
    • Latest articlesInsights on ISO and management systems
    • ISO guidesStep-by-step help for practical work
    Product updatesSee what has changed in AmpliFlow
    • ChangelogNew features and improvements
    View all articles
  • Contact
LabsSupport
EN/SV
Menu
  • Leadership & Processes
    • Management System
    • Processes
    • Management Review
    • Goals
    • Projects
    • Policy
    • News
    • Pages
    Deviations & Risks
    • Deviations
    • Improvements
    • Actions
    • Risks
    • Crisis Management
    Documents & Audits
    • Documents
    • Checklists
    • Audits
    • Reports
    • AI Tools
    • Custom Lists
    • Year Wheel
    People & Competence
    • Competence
    • Competency Matrix
    • Training
    • Employee Reviews
    • Work Environment
    External Requirements
    • Suppliers
    • Legal Requirements
    • Customer Requirements
    • Stakeholders
    • Environmental Aspects
    View all tools
  • By industry
    • Manufacturing
    • Construction
    • Food & Beverage
    • IT & Tech
    • Logistics
    • Staffing
    By role
    • CEO
    • Quality Manager
    • IT Manager
    • Management Team
    By situation
    • Startup
    • Scale-up
    • Established
    • Enterprise
    • Pre-audit crunch
    • Replace old systems
    View all solutions
  • ISO standards
    • ISO 9001
    • ISO 14001
    • ISO 27001
    • ISO 45001
    • ISO 22000
    • ISO 42001
    Several standards at once?
    • Integrated management system
    • Already certified
    • Book a call
    View all standards
  • Read and learn
    • Latest articles
    • ISO guides
    Product updates
    • Changelog
    View all articles
  • Contact
E-book: ISO 9001, 14001 & 45001LabsSupport
EN/SV
ISO 14001 cl. 6.1.3 - ISO 45001 cl. 6.1.3 - ISO 9001 cl. 4.2 - ISO 27001 cl. 4.2

Do you know which compliance obligations apply to you?

Compliance obligations affect ownership, risks, ways of working, and decisions. AmpliFlow gathers laws, regulations, authority directives, permit conditions, and contractual requirements so you know what applies, who owns it, and what needs follow-up.

Book a demoWhat counts as a compliance obligation?

Companies managing compliance obligations with AmpliFlow

LUCOKey RelocationI-TechFridayDoxaHedared Sand & Betong
What counts as a compliance obligation?

More than just laws

Compliance obligations include requirements your organisation must follow or has committed to follow. The six categories show examples. You need to assess which requirements apply to you and how they affect your operations.

Laws and regulations

Swedish Work Environment Act, Environmental Code, Planning and Building Act (PBL), Cybersecurity Act, tobacco legislation

Authority regulations

AFS provisions (Swedish Work Environment Authority), regulations from the Swedish Environmental Protection Agency, Swedish Food Agency and MCF (formerly MSB)

Permits and licences

Environmental permits, driving permits, food business registration, permit conditions

EU legislation

NIS2 Directive, GDPR, AI Act, DORA, Machinery Directive

Contractual requirements

Customer contract requirements, procurement requirements, supplier requirements, framework agreements

Industry requirements

Industry agreements, certification scheme requirements (BRC, FSSC), voluntary commitments

The challenge

Most organisations lack a working register

Identifying and managing compliance obligations is a requirement in all four ISO standards. But the value appears when requirements guide ownership, risks, and everyday decisions.

No central register

Legal requirements live in spreadsheets, emails, binders, and in key people's heads. Nobody has the complete picture.

Unclear what actually applies

You know requirements exist. But you haven't done a systematic applicability assessment. That makes it hard to know what should guide the work.

Nobody owns it formally

Everyone knows roughly who monitors what - until that person leaves. Responsibility for compliance obligations needs to be formally assigned and documented.

The register is never current

Laws change, new regulations arrive, permits renew. Without an active process, the register falls behind quickly.

What the standards require

Four standards, one core requirement

All four ISO standards require identifying and managing compliance obligations. One register covers them all.

Bild
ISO 14001:2015Clause 6.1.3

Compliance obligations

Determine and have access to compliance obligations related to environmental aspects. Determine how they apply and take them into account in the management system.

ISO 45001:2018Clause 6.1.3

Legal requirements and other requirements

Determine and have access to up-to-date legal requirements and other requirements applicable to the organization's hazards and OH&S risks.

ISO 9001:2015Clause 4.2

Interested party requirements

Determine relevant requirements of interested parties, including applicable statutory and regulatory requirements for products and services.

ISO 27001:2022Clause 4.2

Interested party requirements

Determine requirements of interested parties relevant to information security, including legal, regulatory, and contractual obligations.

The solution

The register that makes requirements useful

AmpliFlow gives you a central register for all compliance obligations with structure for identification, applicability assessment, ownership, and follow-up.

1

Central register for all compliance obligations

Gather laws, regulations, permit conditions, and contractual requirements in one place. Categorize by subject area: environment, health and safety, information security, quality.

2

Applicability assessment for each requirement

Document whether it applies, how you are affected, and how you comply. That makes requirements easier to use in ISO work and ongoing follow-up.

3

Responsible person with traceability

Each compliance obligation gets an owner. Clear accountability: the right person monitors the right area, with name and date recorded.

4

Live register with status management

Mark requirements as new, amended, applied, or repealed. Import existing registers via bulk import. Export for audits.

Book a demo
Everyday work

When a requirement changes, you should know what it affects

With AmpliFlow, you see whether the requirement applies, who owns it, how you meet it, and which actions need follow-up.

That turns the register into decision support, not just a list you open when someone asks for it.

Next step

Make requirements useful in daily work

The register is the starting point. Once you know what applies, requirements can connect to risks, environmental work, and customer commitments.

01Risk ManagementWhen a requirement creates uncertainty, assess the risk, choose the action, and follow up ownership.Open tool02Environmental AspectsConnect environmental requirements to the activities that affect emissions, waste, and resource use.Open tool03Customer RequirementsKeep legal obligations, contract requirements, and customer-specific requirements connected without losing the full picture.Open tool
The platform

One platform that keeps the business connected

Start where the need is highest. Add more parts as the business grows, without creating new silos or losing context.

01

Build the foundation

Gather the structure that guides the business so people can find the right way of working and use the same platform every day.

  • Management system
  • Process mapping
  • Pages
  • Policy
02

Run work and follow-up

Keep projects, goals, meetings, and reporting together so leadership can see what is happening without side systems.

  • Projects
  • Objective management
  • Management review
  • Management team work
03

Catch risks and improvements

Turn day-to-day signals into actions that someone owns, follows up, and closes in one shared flow.

  • Risk management
  • Nonconformities
  • Actions
  • Improvements
04

Keep evidence and external requirements together

Bring documents, checklists, suppliers, legal requirements, and competence into one place so follow-up and audits get easier.

  • Document control
  • Checklists
  • Legal requirements
  • Competency matrix

Choose the tools you need

Processes, goals, projects, risks, documents, people, and external requirements live in the same platform. Start where the need is highest, then expand without adding new silos.

18 tools selected

Common from the start
Can be added

Management

✓
Management system

Collect policies, processes and procedures

Common from the start
✓
Management review

Follow up results, risks, objectives and decisions

Common from the start
✓
Management team work

Structured meetings with follow-up

Can be added
✓
Process mapping

Show how ways of working connect

Common from the start

Governance & objectives

✓
Objective management

Set and follow up objectives

Common from the start
✓
Projects

Run implementation with owners and deadlines

Can be added
✓
Policy

Publish direction, rules and ownership

Common from the start
✓
News

Internal communication with acknowledgement

Can be added
✓
Pages

Knowledge base for guidelines and decisions

Common from the start
✓
Stakeholder analysis

Map expectations and requirements

Common from the start

Risks & nonconformities

✓
Nonconformities

Report, analyze and address

Common from the start
✓
Improvements

Continual improvement and PDCA

Common from the start
✓
Actions

Follow up actions with owner and deadline

Common from the start
✓
Risk management

Identify, assess and treat risks

Common from the start
✓
Crisis management

Crisis plans and quick activation

Can be added

Documents & data

✓
Document control

Versioning and approvals

Common from the start
✓
Checklists

Digital controls for procedures and audits

Can be added
✓
Internal audit

Plan and run audits

Common from the start
✓
Reports

Insights and follow-up

Common from the start
✓
Custom lists

Structured registers and databases

Can be added
✓
Year wheel

Visual annual planning

Can be added

AI features in AmpliFlow

✓
AI tools

Built-in AI, Berget and agents in the management system

Can be added

People

✓
Competence management

Define competence by role

Common from the start
✓
Competency matrix

Who can and may do what

Common from the start
✓
Training plan

Plan and follow up training

Can be added
✓
Employee reviews

Structured development conversations

Can be added

External requirements

✓
Supplier management

Evaluate and monitor suppliers

Common from the start
✓
Customer requirements

Capture and manage customer requirements

Can be added
✓
Legal requirements

Track laws and external requirements

Common from the start
✓
Environmental aspects

Map environmental impact

Can be added
✓
Work environment

Risk assessments and safety rounds

Can be added
FAQ

Questions about the compliance obligations register

What is the difference between legal requirements and compliance obligations?
Compliance obligations is the broader term ISO 14001 (clause 6.1.3) uses. It includes laws and regulations but also authority directives, permit conditions, contractual requirements from customers, and voluntary commitments your organisation has made. The register in AmpliFlow covers all of these, not just legislation.
Which subject area should I choose?
AmpliFlow has eight predefined subject areas: Environment, Health and Safety, Information Security, Quality, Energy, Finances, Product Safety, and Other. They map directly to the ISO standards you are certified against. A requirement can belong to multiple subject areas.
How do we meet ISO 14001 requirement 6.1.3?
Clause 6.1.3 requires you to determine which compliance obligations apply, how they apply, and to take them into account in the management system. The register in AmpliFlow gives you the structure: identification, applicability assessment, responsible person, and status, so requirements can be followed up in the work.
Can we import an existing legislation register?
Yes, via bulk import. Export the register for audit reports or backup too. All fields are supported in the import: subject area, status, applicability, responsible person, how we meet the requirement.
Does AmpliFlow monitor legal changes automatically?
AmpliFlow gives you a structured register for documenting and following up compliance obligations. For automatic monitoring of legal changes, we recommend combining it with an external monitoring service that sends notifications when laws change.
Does this apply to all ISO standards we are certified against?
Yes. ISO 14001 (6.1.3), ISO 45001 (6.1.3), ISO 9001 (4.2), and ISO 27001 (4.2) all require identifying and managing compliance obligations. One register covers all standards, categorized by subject area.
Get started

Talk to an AmpliFlow expert

Book a demo and we will show you how to get compliance obligations, ownership, and follow-up into the same system as the rest of your management work.

AmpliFlow

Newsletter

Get the latest news and tips on quality management directly to your inbox.

Products

  • All tools
  • Management System
  • Process Mapping
  • Risk Management
  • Deviation Management
  • Document Management
  • Labs

Resources

  • Articles & insights
  • Changelog
  • Solutions
  • ISO Standards
  • ISO 9001 - Quality
  • ISO 14001 - Environment
  • ISO 45001 - Health & Safety
  • ISO 27001 - Information Security
  • ISO 22000 - Food Safety
  • ISO 42001 - AI Management System
  • Free e-book

Company

  • About us
  • Contact
  • Partner
  • Support
  • Give feedback

Legal

  • Privacy policy
  • Terms of service

Other

  • Campaigns
  • Accessibility
  • How we use AI
  • Security
  • GDPR & Data Protection

Contact us

Emailinfo@ampliflow.com

The content on this website is for informational purposes only and does not constitute legal advice. AmpliFlow is not a law firm. Consult a qualified lawyer for advice tailored to your specific situation.

© 2026 AmpliFlow. All rights reserved.

Svenska