Why your EHS legal register is a compliance liability — and how to fix it
Most organisations have an EHS legal register. Far fewer have one that works. Why registers drift, what it costs, and what an effective register looks like.
- Published
- Length
- 8 min read

In short
The most common legal register failure is not a missing register but one that no longer reflects current law. An effective register defines scope, maps legislation to specific obligations, records evidenced compliance status, names owners, and is reviewed on a documented cycle.
Key takeaways
- A register is only as valuable as its accuracy; an out-of-date one gives false assurance.
- The usual failure is the lack of a process to keep the register current — ownership, review cycles, and evidence.
- Compliance status must be assessed and evidenced, not assumed. Identifying legislation is only the start.
- At scale, manual processes depend on individuals and cannot produce the audit trail regulators and certifiers expect.
- Legal register management is a governance function and deserves the same rigour as other risk management.
Why do EHS legal registers fail?
On paper, the legal register is one of the most important documents in a compliance programme. It defines the obligations an organisation must meet, underpins ISO 14001, ISO 45001, and ISO 50001 management systems, and is usually the first document an auditor or regulator requests. In practice, it is often one of the most neglected.
The common failure is not the absence of a register but a register that no longer reflects current law. Regulations are introduced and amended, thresholds are revised, and enforcement priorities shift. A register accurate two years ago may hold dozens of inaccuracies today, especially across multiple jurisdictions or busy regulatory sectors.
What causes a legal register to go out of date?
The causes are well understood:
- Manual updates that depend on individuals monitoring regulatory sources, which is rarely done consistently
- No formal ownership — the register sits in a shared drive with nobody clearly accountable
- Organisational change — restructuring, site expansions, or new operational scope never reflected in the register
- Point-in-time thinking — the register was built as a project, not designed as a living document
What is the business impact of an out-of-date legal register?
It is tempting to treat this as a documentation gap. It is a compliance risk with direct business consequences.
- Regulatory risk — organisations unaware of an obligation cannot assess whether they meet it; enforcement action typically follows failures like this rather than deliberate non-compliance
- Audit failure — ISO audits examine whether obligations are identified, compliance assessed, and evidence kept; gaps put certification at risk, which matters where certification is a client or procurement requirement
- Financial exposure — boards and senior leaders are increasingly expected to show adequate compliance governance, and personal liability for directors and officers can become a consideration
- Reputational risk — a failure linked to not identifying applicable legislation is hard to defend publicly
What does a well-managed EHS legal register look like?
An effective register is a structured record of the specific obligations that apply, the sites or activities they relate to, current compliance status, and the evidence behind it. Registers that hold up under scrutiny share five traits:
- Clearly defined scope — it maps to what the organisation actually does and where, not a generic template; a site handling hazardous waste has different obligations from one that does not
- Legislation mapped to specific obligations — relevant sections, articles, or requirements, the activities they relate to, and the standard required, not just a reference to an Act or Directive
- Assessed and evidenced status — compliant, partially compliant, non-compliant, or not yet assessed, with supporting evidence attached
- Named owners — an individual or function accountable for each obligation and its status
- Regular, documented review — at least annually, more often for high-risk obligations or during significant regulatory change
What are the most common legal register mistakes?
Even organisations with structured programmes make the same errors:
- Using a generic template without tailoring it to your activities, sites, and jurisdictions — which gives false assurance
- Treating identification as compliance — listing that a regulation applies without establishing what it requires or whether it is met
- Relying on one person to keep it current — so monitoring stops when they change role, take leave, or are busy; document the process, not the person
- Treating the register as a certification requirement — updated just before audits and ignored in between
- No change history — without a record of what changed, when, who reviewed it, and what action followed, you cannot show you responded to regulatory change
How does technology support legal register management?
Maintaining a register manually across sites, jurisdictions, and regulatory domains is time-consuming, needs specialist knowledge, and is not resilient to organisational change — which is why registers fall behind. Compliance management platforms help with:
- Regulatory monitoring — reducing dependence on individuals scanning official journals, government websites, and industry publications
- Impact assessment — a structured workflow, not an email chain, for deciding what a change means for operations
- Obligation management — each requirement mapped to sites, activities, and owners, with status and evidence on the obligation record
- Faster evidence retrieval — when an auditor or regulator asks about a specific requirement, the evidence is already linked to it
Is fixing the legal register a technology decision?
Not primarily. It is a governance decision: recognising that the current approach carries risk the organisation chooses to reduce. Technology makes the process sustainable; qualified people still make the judgements and sign off.
A useful test: if a regulator asked today for evidence of compliance with one specific obligation at one specific site, how quickly could you produce it — and how sure are you that the obligation is still current?
Frequently asked questions
How often should an EHS legal register be reviewed?
At least annually, and more often for high-risk obligations or during significant regulatory change. The most resilient approach combines continuous regulatory monitoring with a documented periodic review, so the register stays current between formal reviews.
What is the difference between identifying legislation and assessing compliance?
Identifying legislation establishes that a regulation applies. Assessing compliance establishes what it requires in practice, whether the organisation meets it, and what evidence supports that conclusion. A register that stops at identification is a list, not a compliance position.
Is a spreadsheet enough to manage a legal register?
For a single site with stable obligations and a disciplined owner, it can work. Risks grow with scale, regulatory change, and staff turnover — particularly around version control, evidence, and audit trail.
General information only — not legal advice. Confirm obligations with qualified counsel or your regulatory team.


