What does regulatory compliance in occupational safety and health entail?
In Spain, the starting point is the right of workers to effective protection and the corresponding duty of employers to provide that protection. Law 31/1995 requires integrating prevention into the company, adopting the necessary measures, and maintaining ongoing monitoring and improvement. Therefore, compliance is not simply about passing a single inspection; it means keeping obligations under control throughout the entire business cycle.
The specific scope depends on the activity, positions, equipment, personnel involved, the size and organization of the company, competition with other businesses, and the characteristics of the exposed individuals. In addition to the general framework, specific provisions regarding workplaces, equipment, chemical agents, noise, screens, construction, or other risks may apply. The regulatory inventory must reflect this reality and be updated as it changes.
Actual compliance, documentation and certification
It is useful to distinguish three related, but not interchangeable, levels:
- Legal compliance: effective execution of applicable obligations and protection achieved in practice.
- Preventive documentation: organized evidence of actions such as the prevention plan, risk assessment , planning, health controls in the legally admissible terms and the list of accidents and occupational diseases required by law.
- Certification: voluntary assessment against a management system standard, such as ISO 45001 , when the organization decides to adopt it.
A complete file does not compensate for a nonexistent or ineffective measure. Similarly, a certification does not replace legislation nor does it guarantee that each specific obligation will be met. The documentation must be proportionate, up-to-date, and allow for the reconstruction of what was decided, who acted, when it was verified, and what result was obtained.
How it is applied in practice
A compliance operating cycle can be organized as follows:
- Determine the context: centers, activities, staff, contracts, equipment, substances and particularly sensitive groups.
- Identify requirements: general regulations, specific provisions, agreements and other commitments assumed by the organization.
- Translate them into controls: responsible party, activity, deadline, resources, expected evidence and acceptance criteria for each obligation.
- Integrate them into the processes: purchasing, maintenance, changes, hiring, training, emergencies and coordination of business activities .
- Execute and record: preserve reliable evidence without making recording an end in itself.
- Verify effectiveness: inspections, indicators, consultation with workers, monitoring of planning and, where appropriate, audit.
- Correct and update: investigate damage and incidents, close deviations, and review the system in response to technical, organizational, or legal changes.
Management retains the duty of protection even if it uses designated workers or an occupational health and safety service . The responsibilities must be clear, and the designated workers must have the necessary authority and resources.
Traceability and useful evidence
Traceability allows linking an obligation to the risk it addresses, the measure taken, and subsequent verification. Useful evidence includes identification, date, scope, responsible party, outcome, and change control. Examples of evidence include an approved assessment, equipment delivery and verification records, consultation minutes, hygiene measurements , closed maintenance orders, or verification of the effectiveness of corrective action.
Law 31/1995 establishes preventive documentation that must be prepared and kept available for the labor authority. This does not authorize the indiscriminate collection of health data: monitoring must respect privacy, dignity, and confidentiality, and access to health information is limited. A digital system can facilitate versioning, expiration, and auditing, but it requires governance of permissions, data quality, and proper storage.
Practical example
A company is implementing a new automated production line. Before its commissioning, the operations manager informs the safety system of the change. The risk assessment, equipment compliance and operating conditions, guards, lockout/tagout procedures, maintenance, human-machine interaction, and emergency procedures are reviewed. These measures are incorporated into a plan with assigned responsibilities and deadlines; employee representatives are consulted, and exposed personnel receive training.
After startup, the operation of the controls is verified and any incidents are recorded. An internal inspection reveals that a cleaning procedure requires approaching a hazardous area. The organization doesn’t simply add an instruction: it redesigns the task, implements a safe procedure, updates the risk assessment, and verifies its effectiveness. This connection between requirement, risk, control, and verification demonstrates effective compliance.
Non-compliance, corrections and responsibilities
A deviation can consist of an unidentified obligation, an outdated assessment, an expired measure, insufficient training, or a control that exists on paper but fails in practice. Its scope must be analyzed, the immediate risk identified, the cause determined, and a verifiable corrective action assigned. Priorities are set by the risk to people, not just by ease of documentation.
Non-compliance by employers can lead to administrative liability and, depending on the case, criminal and civil liability for damages. The consolidated text of the Law on Infringements and Sanctions in the Social Order classifies preventive infringements as minor, serious, and very serious. The purpose of the internal system should not be limited to avoiding sanctions: it must offer effective protection, provide early warning of harm, and allow management and employee representatives to be aware of relevant deviations.
Regulatory framework in Spain and the European Union
Law 31/1995 establishes the general duty of protection, the principles of preventive action, the integration of prevention , assessment and planning, information, consultation, training, health surveillance, and documentation. Royal Decree 39/1997 develops the preventive organization, the plan, the assessment, the planning, and the regulatory audits in the cases provided for. Specific regulations complete this framework according to the risk or activity.
In the European Union, Directive 89/391/EEC establishes the general principles and employer responsibility for safety and health in all aspects related to work; specific directives set out additional minimum requirements. ISO 45001:2018 provides a voluntary framework for managing occupational safety and health risks and opportunities , legal requirements, and continual improvement. The ILO’s ILO-OSH 2001 guidelines provide another voluntary international model. None of these supersede applicable national or European legal obligations.
