Regulatory compliance in OSH

Compliance with occupational health and safety regulations is the ongoing process by which an organization identifies its applicable occupational health and safety obligations, integrates them into its management practices, and demonstrates their effective implementation. It involves more than just having documentation: it requires preventing risks, assigning responsibilities, implementing measures, consulting with workers, and reviewing the system when conditions change.

In short

Compliance with occupational health OSH management system (OSHMS) regulations transforms applicable legal obligations into verifiable preventative measures within the organization’s actual operations. Effective OHS compliance requires understanding the regulations, implementing them, maintaining sufficient evidence, and correcting any deviations identified.

Content
  1. What does regulatory compliance in occupational safety and health entail?
  2. Actual compliance, documentation and certification
  3. How it is applied in practice
  4. Traceability and useful evidence
  5. Practical example
  6. Non-compliance, corrections and responsibilities
  7. Regulatory framework in Spain and the European Union
  8. Related concepts
  9. On the blog
  10. References

A–Z dictionary →

What does regulatory compliance in occupational safety and health entail?

In Spain, the starting point is the right of workers to effective protection and the corresponding duty of employers to provide that protection. Law 31/1995 requires integrating prevention into the company, adopting the necessary measures, and maintaining ongoing monitoring and improvement. Therefore, compliance is not simply about passing a single inspection; it means keeping obligations under control throughout the entire business cycle.

The specific scope depends on the activity, positions, equipment, personnel involved, the size and organization of the company, competition with other businesses, and the characteristics of the exposed individuals. In addition to the general framework, specific provisions regarding workplaces, equipment, chemical agents, noise, screens, construction, or other risks may apply. The regulatory inventory must reflect this reality and be updated as it changes.

Actual compliance, documentation and certification

It is useful to distinguish three related, but not interchangeable, levels:

  • Legal compliance: effective execution of applicable obligations and protection achieved in practice.
  • Preventive documentation: organized evidence of actions such as the prevention plan, risk assessment , planning, health controls in the legally admissible terms and the list of accidents and occupational diseases required by law.
  • Certification: voluntary assessment against a management system standard, such as ISO 45001 , when the organization decides to adopt it.

A complete file does not compensate for a nonexistent or ineffective measure. Similarly, a certification does not replace legislation nor does it guarantee that each specific obligation will be met. The documentation must be proportionate, up-to-date, and allow for the reconstruction of what was decided, who acted, when it was verified, and what result was obtained.

How it is applied in practice

A compliance operating cycle can be organized as follows:

  1. Determine the context: centers, activities, staff, contracts, equipment, substances and particularly sensitive groups.
  2. Identify requirements: general regulations, specific provisions, agreements and other commitments assumed by the organization.
  3. Translate them into controls: responsible party, activity, deadline, resources, expected evidence and acceptance criteria for each obligation.
  4. Integrate them into the processes: purchasing, maintenance, changes, hiring, training, emergencies and coordination of business activities .
  5. Execute and record: preserve reliable evidence without making recording an end in itself.
  6. Verify effectiveness: inspections, indicators, consultation with workers, monitoring of planning and, where appropriate, audit.
  7. Correct and update: investigate damage and incidents, close deviations, and review the system in response to technical, organizational, or legal changes.

Management retains the duty of protection even if it uses designated workers or an occupational health and safety service . The responsibilities must be clear, and the designated workers must have the necessary authority and resources.

Traceability and useful evidence

Traceability allows linking an obligation to the risk it addresses, the measure taken, and subsequent verification. Useful evidence includes identification, date, scope, responsible party, outcome, and change control. Examples of evidence include an approved assessment, equipment delivery and verification records, consultation minutes, hygiene measurements , closed maintenance orders, or verification of the effectiveness of corrective action.

Law 31/1995 establishes preventive documentation that must be prepared and kept available for the labor authority. This does not authorize the indiscriminate collection of health data: monitoring must respect privacy, dignity, and confidentiality, and access to health information is limited. A digital system can facilitate versioning, expiration, and auditing, but it requires governance of permissions, data quality, and proper storage.

Practical example

A company is implementing a new automated production line. Before its commissioning, the operations manager informs the safety system of the change. The risk assessment, equipment compliance and operating conditions, guards, lockout/tagout procedures, maintenance, human-machine interaction, and emergency procedures are reviewed. These measures are incorporated into a plan with assigned responsibilities and deadlines; employee representatives are consulted, and exposed personnel receive training.

After startup, the operation of the controls is verified and any incidents are recorded. An internal inspection reveals that a cleaning procedure requires approaching a hazardous area. The organization doesn’t simply add an instruction: it redesigns the task, implements a safe procedure, updates the risk assessment, and verifies its effectiveness. This connection between requirement, risk, control, and verification demonstrates effective compliance.

Non-compliance, corrections and responsibilities

A deviation can consist of an unidentified obligation, an outdated assessment, an expired measure, insufficient training, or a control that exists on paper but fails in practice. Its scope must be analyzed, the immediate risk identified, the cause determined, and a verifiable corrective action assigned. Priorities are set by the risk to people, not just by ease of documentation.

Non-compliance by employers can lead to administrative liability and, depending on the case, criminal and civil liability for damages. The consolidated text of the Law on Infringements and Sanctions in the Social Order classifies preventive infringements as minor, serious, and very serious. The purpose of the internal system should not be limited to avoiding sanctions: it must offer effective protection, provide early warning of harm, and allow management and employee representatives to be aware of relevant deviations.

Regulatory framework in Spain and the European Union

Law 31/1995 establishes the general duty of protection, the principles of preventive action, the integration of prevention , assessment and planning, information, consultation, training, health surveillance, and documentation. Royal Decree 39/1997 develops the preventive organization, the plan, the assessment, the planning, and the regulatory audits in the cases provided for. Specific regulations complete this framework according to the risk or activity.

In the European Union, Directive 89/391/EEC establishes the general principles and employer responsibility for safety and health in all aspects related to work; specific directives set out additional minimum requirements. ISO 45001:2018 provides a voluntary framework for managing occupational safety and health risks and opportunities , legal requirements, and continual improvement. The ILO’s ILO-OSH 2001 guidelines provide another voluntary international model. None of these supersede applicable national or European legal obligations.

Related concepts

On the blog

References

  1. Official State Gazette. Law 31/1995, of November 8, on Occupational Risk Prevention (consolidated text). 1995. Official source
  2. Official State Gazette. Royal Decree 39/1997, of January 17, Regulation of Prevention Services (consolidated text). 1997. Official source
  3. Official State Gazette. Royal Legislative Decree 5/2000, consolidated text of the Law on Infringements and Sanctions in the Social Order. 2000. Official source
  4. National Institute for Occupational Safety and Health. Technical guide for integrating occupational risk prevention into the company’s general management system. 2015. Official source
  5. European Union. Directive 89/391/EEC on the introduction of measures to encourage improvements in the safety and health of workers. 1989. Official source
  6. ISO. ISO 45001:2018 — Occupational health and safety management systems. 2018. Official source
  7. International Labour Organization. Guidelines on occupational safety and health management systems, ILO-OSH 2001. 2001. Official source

Editorial information

Publication date: August 29, 2026 .

Editorial Manager: Sabentis Editorial Team .

Editorial review by Pablo Rodríguez LinkedIn

Executive Vice President of the ORP International Foundation and Chief Financial Officer of Sabentis.

Request a Demo

Discover all that Sabentis can do for your organization.

Try Sabentis

request a demo
stars 5
GetApp Software Advice Capterra