Most facilities that come to me for R2v3 help aren't fixing a broken environmental management system. They don't have one yet. They've got a scrap metal contract, a data destruction process that mostly works, and a filing cabinet with the occasional inspection report in it — but nothing that ties those pieces together into what R2v3 calls an Environmental, Health, and Safety Management System, or EHSMS.
That's Core Requirement 2 of the R2v3 standard, and it's the one requirement that touches every other part of the certification. Get it wrong and the auditor doesn't just flag CR2 — they start pulling on threads in data security, focus materials handling, and downstream due diligence, because the EHSMS is supposed to be the thing that catches those problems before an outsider does.
Here's how to build one from a blank page, in the order that actually works on a facility floor rather than the order it appears in the standard's table of contents.
What R2v3 Core Requirement 2 Actually Asks For
R2v3 Core Requirement 2 does not require a facility to hold ISO 14001 or ISO 45001 certification. It requires a documented management system that covers the same policy-to-management-review cycle those two ISO standards use, whether or not the facility ever seeks outside certification to either one. If you already hold ISO 14001 or ISO 45001, that certificate is useful supporting evidence — but it doesn't automatically satisfy the R2-specific pieces, like the risk assessment covering R2 Focus Materials.
The elements R2v3 expects, and where they map to the ISO clauses most auditors reference when they write findings, look like this:
| EHSMS Element (R2v3 CR2) | Nearest ISO Clause | What a From-Scratch Facility Has to Produce |
|---|---|---|
| EHS Policy | ISO 14001:2015 §5.2 / ISO 45001:2018 §5.2 | Signed, dated policy statement, communicated to every worker on site |
| Legal and Other Requirements | ISO 14001:2015 §6.1.3 | A legal register naming the RCRA, OSHA, and state permits that apply to this specific site |
| Risk Assessment | ISO 14001:2015 §6.1.2 / ISO 45001:2018 §6.1.2 | A process-by-process hazard and aspect log, not a generic downloaded template |
| Objectives, Targets, and Programs | ISO 14001:2015 §6.2 | Written targets tied to the risk assessment, each with an owner and a date |
| Competence, Training, Awareness | ISO 14001:2015 §7.2–7.3 | Training records tied to job role, refreshed on a set schedule |
| Operational Control / Documentation | ISO 14001:2015 §7.5, §8.1 | Written procedures for each R2 process step, under document control |
| Emergency Preparedness and Response | ISO 14001:2015 §8.2 | A written plan, tested at least annually, with drill records to prove it |
| Monitoring and Measurement | ISO 14001:2015 §9.1.1 | Calibration records, inspection logs, tracked performance data |
| Internal Audit | ISO 14001:2015 §9.2 | A completed internal audit covering every EHSMS element before the certification body shows up |
| Management Review | ISO 14001:2015 §9.3 | Meeting minutes showing leadership actually reviewed performance and made decisions |
Ten elements. Every one of them has to exist before the Stage 2 audit, and — this is the part facilities miss — most of them need a track record behind them, not just a document with today's date on it.
Step 1: Write the EHS Policy First, and Get It Signed
The policy is short — usually a page — but it sets the boundaries for everything downstream. It should commit the facility to legal compliance, pollution prevention, worker safety, and continual improvement, and it should say who's responsible for making that happen.
R2v3 follows the ISO convention here: top management signs it. That means the general manager or owner, not the EHS coordinator who drafted it. Auditors look for that signature specifically because it's their evidence that leadership owns the system rather than delegating it entirely and never looking at it again.
Step 2: Build the Legal and Other Requirements Register Before You Do Anything Else
This step gets skipped or rushed constantly, and it shouldn't, because everything else in the EHSMS points back to it. The register has to name the specific regulations that apply to this facility:
- RCRA hazardous waste generator status under 40 CFR Part 262
- OSHA general industry standards under 29 CFR 1910
- State extended producer responsibility obligations, if the facility handles covered electronics
- Any local air, water, or wastewater discharge permits tied to the site's specific operations
A generic list of "applicable regulations" copied from a template doesn't hold up. The auditor wants to see that someone at the facility actually determined the facility's generator status, actually checked which state EPR laws apply to the states it ships into, and actually pulled the local permit conditions. For more on what R2v3's EHSMS requirement covers in full, see our breakdown of the environmental, health, and safety management requirements.
Step 3: Do the Risk Assessment Like You Mean It
A risk assessment written before the facility has mapped its own process flow isn't a risk assessment — it's a guess with a document number attached. The right way to build this from scratch is to walk the facility floor, station by station, and ask two questions at each one: what environmental aspect does this step create (dust, wastewater, air emissions, hazardous waste), and what hazard does it present to the people working it (lead exposure at CRT breaking, laceration risk at manual disassembly, forklift traffic in the yard)?
Under ISO 14001:2015 clause 6.1.2, an environmental aspect only counts as documented if the facility can show how it identified the aspect and evaluated its significance. "We generate scrap metal" isn't an aspect statement an auditor will accept. "Manual disassembly of CRT monitors generates leaded glass requiring management as R2 Focus Material and hazardous waste under state generator rules" is.
This is also where R2 Focus Materials get folded into the broader risk picture rather than treated as a side project. Batteries, CRT glass, and mercury-containing lamps are examples, not the full list — R2v3 Appendix B defines the complete, enumerated set of Focus Materials, and the risk assessment needs to check the facility's actual material streams against that full list, not just the familiar few. If you haven't already built out that piece, it's worth doing alongside the general risk assessment rather than after it.
Step 4: Set Objectives, Targets, and a Program to Hit Them
Once the risk assessment exists, objectives should fall out of it almost automatically: reduce the volume of CRT glass in on-site storage, cut the number of near-miss incidents at the shredder line, get hazardous waste manifests filed within the regulatory deadline every time instead of most of the time. Each objective needs an owner, a number, and a date — not "improve safety culture," which no auditor can verify and no employee can act on.
Step 5: Build Competence and Training Around the Roles, Not Around a Generic Course
R2v3 wants training tied to what a specific job actually does. The person operating the shredder needs different training than the person doing data destruction verification, who needs different training than the person managing the hazardous waste storage area. Build a training matrix that lists each role, the training it requires, and the refresh interval, then keep the records that prove it happened. A stack of certificates with no matrix behind them looks like training happened once, not that it's managed.
Step 6: Turn Process Steps Into Written Procedures Under Document Control
Every process the facility runs — intake, sorting, data destruction, focus materials handling, shipping — needs a written procedure describing how it's actually done, not how it's supposed to be done in theory. These procedures need version control: a revision number, a date, an approval signature, and a defined way for outdated copies to get pulled from the floor when a new version is issued.
This is also where the EHSMS intersects with R2v3's broader documentation expectations — the policy, the risk assessment, the training matrix, and the procedures all need to live inside one coherent document control system rather than existing as separate one-off files scattered across different people's drives.
Step 7: Write the Emergency Preparedness and Response Plan, Then Actually Test It
The plan needs to cover the realistic emergencies for an electronics recycling site: fire, chemical spill, battery thermal event, medical emergency, and severe weather if the region calls for it. Writing the plan is the easy half. R2v3 expects it tested — a drill, at minimum annually — with records showing what happened, what didn't work, and what got fixed afterward. A plan that's never been run through a drill is a plan nobody has confirmed will actually work when it matters.
Step 8: Monitor Performance and Run the Internal Audit Before the Real One
Monitoring means calibrated equipment, inspection logs, and tracked data against the objectives set in Step 4. The internal audit is where a facility finds out, in a controlled setting, whether the EHSMS actually holds together. R2v3 requires an internal audit before every certification and surveillance cycle, and that audit has to actually touch the EHSMS elements — the policy, the risk assessment, the training records — not just walk the floor and check that bins are labeled.
Facilities building from scratch often run their first internal audit too early, before there's enough operating history to audit against. Give the system enough real operating history to show it's actually running, not just documented — training logs, monitoring data, at least one corrective action — before the internal audit, so there's something substantive to review.
Step 9: Close the Loop With Management Review
Management review is where leadership looks at everything the system produced — internal audit results, incidents, objective progress, legal compliance status — and makes decisions about what changes. Minutes from this meeting need to show actual discussion and actual decisions, not a signature on a summary someone else wrote. This is the element auditors use to judge whether the whole EHSMS is a living system or a binder that gets updated once a year right before the audit.
Do You Need ISO 14001 or ISO 45001 Certification to Pass R2v3?
No. This is one of the most common points of confusion for facilities building an EHSMS for the first time. R2v3 borrows the structure of ISO 14001 and ISO 45001 — the policy-plan-do-check-act cycle — without requiring the formal ISO certificate. A facility can build every element on this list, run it well, and pass its R2v3 audit without ever engaging an ISO certification body.
Where it gets more nuanced: if a facility already holds ISO 14001 and/or ISO 45001 certification, that certification can reduce the audit burden, because the certification body can rely on the existing ISO audit trail for elements that overlap. It doesn't eliminate the need for R2-specific pieces like Focus Materials risk assessment, which sits outside what a general ISO 14001 audit would typically cover.
Building In-House vs. Bringing in Outside Help
Some facilities build the entire EHSMS themselves. Others bring in a consultant to write the framework and hand off the operating records to staff. Both paths work — the right choice depends on internal bandwidth and how familiar the team already is with management system documentation.
| Factor | Building In-House | Working With a Consultant |
|---|---|---|
| Time to a workable first draft | Slower — usually built around other job duties | Faster — dedicated focus on the documents |
| Familiarity with ISO/R2v3 clause mapping | Learned during the build | Already established going in |
| Risk of missing an element the auditor flags | Higher on a first build | Can be lower, depending on the consultant's R2v3-specific experience |
| Ongoing ownership after certification | Stays entirely internal | Internal, with the framework already in place |
Whichever path a facility takes, the system still has to be run by the people on the floor after it's written. Consultants can build the framework; they can't generate the training records and monitoring data that prove the system is alive. If you want a second set of eyes on where your EHSMS stands before the certification body sees it, our R2 audit preparation service walks through exactly this kind of gap analysis.
Common Mistakes Facilities Make Building an EHSMS From Scratch
The same handful of problems show up again and again. The risk assessment gets written from a template instead of a floor walk, and it misses a material stream entirely. The legal register lists regulations in general terms instead of naming the specific permit numbers and generator status that apply to that site. Training records exist but aren't tied to a matrix, so nobody can prove the right person got the right training. And the internal audit gets run the week before the real audit, with no operating history behind the system it's supposed to be checking.
Every one of these is fixable with time, not money. The EHSMS doesn't need to be elaborate. It needs to be specific to the facility that wrote it, and it needs a few months of real records behind it before an outside auditor ever sees it.
Frequently Asked Questions
How long does it take to build an R2v3 EHSMS from scratch? The standard doesn't set a fixed timeline. In practice, the risk assessment and legal register take the longest, since they require walking every process step rather than filling out a template. Plan for enough operating history to show the system is actually running, not just documented — training logs, monitoring data, a completed internal audit — before the Stage 2 audit, since a document with no history behind it draws scrutiny.
Can one document cover both environmental and health and safety, or does R2v3 require separate systems? R2v3 combines them into a single EHSMS by design. One integrated system addressing environmental aspects and safety hazards side by side satisfies Core Requirement 2 — most facilities find that easier to run than duplicating policy, training, and audit structures across two separate systems.
What happens if the certification body finds gaps in the EHSMS at Stage 2? Gaps become nonconformities that have to be closed with corrective action, either before certification is issued or on a defined timeline for minor findings. The elements most commonly cited are an incomplete risk assessment that misses a material stream, and an internal audit that wasn't finished before the Stage 2 visit.
Last updated: 2026-09-18
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.