Who tells you which rules apply? Access to standards and the source of your compliance knowledge

Technical standards are licensed products, and your list of obligations often comes from a supplier or adviser. How to check where your compliance knowledge comes from and who can read it.

Every business that builds, makes, installs, transports or maintains things operates under technical rules: building codes, electrical requirements, product standards, safety rules and customer specifications. The obligation to follow those rules reaches everyone who touches the work, from the owner to the apprentice tightening the last fitting. Yet the documents that contain the rules are often copyrighted products, sold under licence by the seat or by the copy. Everyone is bound by them, but only a few people in a typical business can lawfully read them.

That creates two quiet risks. The first is that the people making day-to-day decisions, such as the supervisor on site or the person checking a load, work from a summary written by someone who once read the document, possibly years ago and from an older edition. The second, and larger, risk is that the business’s list of which rules apply at all often comes from somewhere outside: a document supplier’s subscription bundle, an adviser’s report or a certifier’s checklist. Each of those sources has its own scope, incentives and blind spots.

This article explains why compliance knowledge should be treated as something with a source, an author and an age, how to check where yours comes from, and practical steps for a small business to keep it reliable. It is general information. Confirm your obligations with the relevant authorities and qualified advisers.

Two things you are really relying on

When a business says it complies with a rule, it is relying on two separate things:

  1. The text: access to the actual words of the standard, code or regulation.
  2. The map: knowledge of which documents apply to the business’s activities, in which editions, under which authorities.

Most attention goes to the text: buying the standard, subscribing to a library, keeping copies current. The map is more important and usually less examined. If an obligation never appears on your map, no amount of careful reading of the documents you do hold will reveal it.

Where the text comes from

Many technical standards are sold by standards bodies and their licensed distributors. Licences commonly limit how many people may access a document, how many copies may be made and for how long. Some regulatory instruments and codes are freely available from government, while the standards they reference may not be. Arrangements change, so check the current position for the documents you rely on.

The licence perimeter shapes how knowledge flows through a business. If only one engineer or the owner can read a standard, everyone else works from summaries, procedures or memory. That is not wrong in itself: well-written work instructions are how most businesses turn requirements into practice. The risk is when nobody knows:

  • Which document and edition a work instruction was derived from.
  • Who wrote it, and when.
  • Whether the source document has since changed.

Where the map comes from

Ask how you know which rules apply to your business. The answer usually falls into one of four categories:

Source of the mapWhat you actually holdWhat to do
Someone in your business read the instruments, recorded the documents and editions, and dated itA verified positionMake sure someone owns keeping it current
An adviser, consultant or certifier told youAn opinion limited to the adviser’s briefFind out what the brief covered and excluded
A document supplier’s bundle or subscriptionA product selection, shaped by what that supplier sellsTreat it as a starting point and verify it independently
Nobody can sayNothing reliableStop asserting compliance until the obligation is mapped

None of the external sources is improper. Advisers and suppliers provide valuable services. But each has a scope. A subscription bundle covers the documents that supplier distributes. An adviser’s report covers what they were engaged to review, and their engagement may end at project completion while your obligations continue. A certifier’s checklist covers what they certify. Gaps between scopes are invisible unless you look for them.

Why summaries drift

Work instructions, procedures, checklists and training notes are the real control documents in most businesses. People follow them, not the standard. Summaries drift over time because:

  • The source document is revised, but the summary is not.
  • The summary was written for one situation and reused for another.
  • Small errors or simplifications creep in during copying and updating.
  • The person who wrote it leaves, and nobody knows its basis.

A summary with no recorded source is a hidden liability. When something goes wrong, the first question is often “what did the requirement actually say?” and the second is “why did your procedure say something different?”

Making procedures traceable

The fix for drift is not to make every worker read every standard. It is to make every procedure traceable to its source, so that when the source changes, you know which procedures to review. A source line is a short block at the top or bottom of a procedure that records:

  • Requirement source: the document, clause or section, and edition or amendment.
  • Other inputs: customer specifications, manufacturer instructions, regulator guidance or adviser advice.
  • Prepared by and date.
  • Reviewed by and date.
  • Next review trigger: a date or event.

A source line takes a few minutes to write and makes a procedure far more useful. When an amendment is announced, a search of your procedures for that document shows exactly which ones need review. When a new person takes over a process, they can see where the steps came from and judge whether they still make sense. When an auditor or customer asks how you know a step is right, the answer is on the page.

Manufacturer instructions deserve special mention. Equipment and materials often come with installation, operating and maintenance instructions that a regulator, standard or warranty expects you to follow. These are part of your compliance map, and they change with new models and revisions. Record which version of the instructions a procedure relies on.

Who should hold access

Access to standards and other source documents should follow decision-making, not seniority. A useful test is to list the decisions governed by a requirement, such as selecting a component, accepting a weld, approving a design or signing off an installation, and ask who makes each one. Those people need either access to the source or a procedure that is properly sourced and current.

Sometimes the right answer is to buy additional access for the people who interpret requirements most often. Sometimes it is to invest in better procedures. And sometimes it is to make sure a qualified person reviews particular decisions. What is rarely right is for decisions to depend on an unsourced summary that nobody has reviewed for years.

A compliance source check

A simple audit, done in a spreadsheet, shows how reliable your compliance knowledge really is. For each important obligation your business says it meets, record:

  1. The rule and its publisher: which document contains the requirement, and who publishes it.
  2. Who supplied access to it: a standards distributor, a government website, an adviser.
  3. How you know it applies: one of the four map sources above.
  4. Who can read it: how many people hold access, compared with how many make decisions governed by it.
  5. The derivation chain: for each procedure or checklist that implements the rule, the source document, edition, date and author.
  6. The review trigger: the event that prompts a re-check, such as an amendment notice, a new project or a customer requirement, and who is responsible.
Obligation (illustrative)Map sourceAccess holdersDecision makersProcedure source recorded?Review trigger
Electrical installation requirementsElectrical contractor’s advice14NoNone
Food labelling requirementsOwner read the code12Yes, datedAnnual review and amendment alerts
Lifting equipment inspectionInsurer’s checklist03NoInsurance renewal only

Rows with no recorded source, or with the map coming only from a supplier or nobody, need attention first. Rows where far more people make decisions than can read the source need well-maintained, properly sourced procedures.

A worked example

This is an illustration. A small business transports and installs commercial refrigeration equipment. The owner believes the business is compliant because it subscribes to a standards bundle recommended by a distributor and employs licensed technicians.

Running the source check reveals:

  • The subscription bundle was chosen years ago from the distributor’s recommended list for refrigeration businesses. Nobody has checked what it excludes.
  • Two people can access the standards, but eight technicians and a warehouse supervisor make daily decisions governed by them.
  • The installation checklist used by technicians was written six years ago by a technician who has since left. Nobody knows which edition it was based on.
  • The business’s obligations for refrigerant handling, which involve licensing and record keeping, were learned from a training course rather than from the governing instruments, and nobody has checked for changes since.
  • A customer’s contract requires compliance with a site-specific standard that is not in the bundle at all.

The owner takes four steps. First, the owner asks the distributor in writing what the bundle does not cover, then checks the governing instruments and customer requirements to build a proper list of applicable documents. Second, the owner has a senior technician review the installation checklist against the current documents, adding a source line with document, edition and date. Third, the owner confirms current refrigerant handling requirements with the relevant authority and updates procedures. Fourth, the owner adds a step to project start-up: list the documents each customer contract requires and check they are held.

The business is no more expensive to run, but it now knows what its compliance rests on.

Getting a second view

For your most important obligations, avoid relying on a single source for your map. Options include:

  • Reading the governing instruments yourself, such as regulations and codes, many of which are freely available from government websites.
  • Industry associations, which often track regulatory changes for their sector.
  • Regulator websites and alert services.
  • A second adviser for high-consequence areas.
  • Customer specifications, which can reveal requirements your own map missed.

Differences between sources are useful. They reveal gaps.

How this applies to a small Australian business

Small businesses often rely heavily on outside sources for compliance knowledge: designers, certifiers, licensed trades, industry training and subscription services. That is sensible, but it means the business owner must understand what each source covers. Practical steps:

  • List your obligations, and for each, record how you know it applies.
  • Ask advisers and suppliers what their scope excludes, in writing.
  • Add a source line to every procedure and checklist that implements a requirement: document, edition, date, author.
  • Make sure the people who need requirements can access them or have properly sourced procedures.
  • Set review triggers, such as amendment alerts, new contracts and annual reviews.
  • Keep records of the documents and editions you relied on for each project.

The articles on which edition of a standard applies and when expert advice becomes a liability cover related risks.

Signals worth watching

  • Procedures with no recorded source, author or date.
  • Staff unable to say where a requirement comes from.
  • Obligations first discovered through audits, customer complaints or incidents.
  • Advisers whose engagement has ended but whose advice is still relied on.
  • A subscription or bundle that nobody has reviewed since it was chosen.
  • Amendment notices that arrive but trigger no review.

Common mistakes

  • Treating a subscription as a compliance position, when it is only access to some documents.
  • Assuming an adviser’s report covers everything, when it covers only their brief.
  • Using procedures with no recorded source or date.
  • Letting access follow seniority rather than need.
  • Learning obligations once, through training or a project, and never checking for changes.
  • Discovering obligations from auditors or customers rather than from your own map.

Frequently asked questions

Do we need to buy every standard that might apply? Not necessarily. You need reliable access to the requirements that govern your work, which might come from purchased standards, free government instruments, properly sourced procedures or qualified advisers. What matters is knowing the source and keeping it current.

Can we share a purchased standard with all staff? That depends on the licence terms. Check them, and consider whether a well-sourced procedure is the better tool for most staff.

How often should we review our obligations map? At least annually, plus whenever an amendment is announced, you start work for a new type of customer, or you enter a new product area or market.

Questions to ask

  • Who told us which rules apply to our business, and what did their engagement cover?
  • What has our document supplier confirmed it does not include?
  • How many people can read our critical requirements, and how many make decisions governed by them?
  • For our most important procedures, which document and edition were they derived from, when and by whom?
  • How did we find out the last time an obligation changed, and how long did it take?
  • What would tell us if our obligations map was years out of date?

Bringing it together

Compliance knowledge has a source, an author and an age. Behind every claim to comply sit two things: access to the text of the rules and a map of which rules apply. The map is the more important, and it often comes from a supplier, adviser or certifier whose scope is narrower than your obligations. Check where your map comes from, ask what each source excludes, add source lines to your procedures, make sure the people who make decisions can rely on current requirements, and set triggers for review. A business can be diligent and still be out of date if nobody knows when its picture of the rules was last true.


Source: KEVOS notes. Examples in this article are illustrations. This article is general information, not legal advice. Confirm your obligations with the relevant authorities and qualified advisers.

Need practical engineering, manufacturing or process support? KEVOS can help move the work forward.