Why your EHS legal register is a compliance liability — and how to fix it

Most organisations have an EHS legal register. Far fewer have one that works. Why registers drift, what it costs, and what an effective register looks like.

Published
Length
8 min read
Close-up of a deep crack running through a concrete plaza, with modern buildings blurred in the background

In short

The most common legal register failure is not a missing register but one that no longer reflects current law. An effective register defines scope, maps legislation to specific obligations, records evidenced compliance status, names owners, and is reviewed on a documented cycle.

Key takeaways

  • A register is only as valuable as its accuracy; an out-of-date one gives false assurance.
  • The usual failure is the lack of a process to keep the register current — ownership, review cycles, and evidence.
  • Compliance status must be assessed and evidenced, not assumed. Identifying legislation is only the start.
  • At scale, manual processes depend on individuals and cannot produce the audit trail regulators and certifiers expect.
  • Legal register management is a governance function and deserves the same rigour as other risk management.

On paper, the legal register is one of the most important documents in a compliance programme. It defines the obligations an organisation must meet, underpins ISO 14001, ISO 45001, and ISO 50001 management systems, and is usually the first document an auditor or regulator requests. In practice, it is often one of the most neglected.

The common failure is not the absence of a register but a register that no longer reflects current law. Regulations are introduced and amended, thresholds are revised, and enforcement priorities shift. A register accurate two years ago may hold dozens of inaccuracies today, especially across multiple jurisdictions or busy regulatory sectors.

The causes are well understood:

  • Manual updates that depend on individuals monitoring regulatory sources, which is rarely done consistently
  • No formal ownership — the register sits in a shared drive with nobody clearly accountable
  • Organisational change — restructuring, site expansions, or new operational scope never reflected in the register
  • Point-in-time thinking — the register was built as a project, not designed as a living document

It is tempting to treat this as a documentation gap. It is a compliance risk with direct business consequences.

  • Regulatory risk — organisations unaware of an obligation cannot assess whether they meet it; enforcement action typically follows failures like this rather than deliberate non-compliance
  • Audit failure — ISO audits examine whether obligations are identified, compliance assessed, and evidence kept; gaps put certification at risk, which matters where certification is a client or procurement requirement
  • Financial exposure — boards and senior leaders are increasingly expected to show adequate compliance governance, and personal liability for directors and officers can become a consideration
  • Reputational risk — a failure linked to not identifying applicable legislation is hard to defend publicly

An effective register is a structured record of the specific obligations that apply, the sites or activities they relate to, current compliance status, and the evidence behind it. Registers that hold up under scrutiny share five traits:

  • Clearly defined scope — it maps to what the organisation actually does and where, not a generic template; a site handling hazardous waste has different obligations from one that does not
  • Legislation mapped to specific obligations — relevant sections, articles, or requirements, the activities they relate to, and the standard required, not just a reference to an Act or Directive
  • Assessed and evidenced status — compliant, partially compliant, non-compliant, or not yet assessed, with supporting evidence attached
  • Named owners — an individual or function accountable for each obligation and its status
  • Regular, documented review — at least annually, more often for high-risk obligations or during significant regulatory change

Even organisations with structured programmes make the same errors:

  • Using a generic template without tailoring it to your activities, sites, and jurisdictions — which gives false assurance
  • Treating identification as compliance — listing that a regulation applies without establishing what it requires or whether it is met
  • Relying on one person to keep it current — so monitoring stops when they change role, take leave, or are busy; document the process, not the person
  • Treating the register as a certification requirement — updated just before audits and ignored in between
  • No change history — without a record of what changed, when, who reviewed it, and what action followed, you cannot show you responded to regulatory change

Maintaining a register manually across sites, jurisdictions, and regulatory domains is time-consuming, needs specialist knowledge, and is not resilient to organisational change — which is why registers fall behind. Compliance management platforms help with:

  • Regulatory monitoring — reducing dependence on individuals scanning official journals, government websites, and industry publications
  • Impact assessment — a structured workflow, not an email chain, for deciding what a change means for operations
  • Obligation management — each requirement mapped to sites, activities, and owners, with status and evidence on the obligation record
  • Faster evidence retrieval — when an auditor or regulator asks about a specific requirement, the evidence is already linked to it

Not primarily. It is a governance decision: recognising that the current approach carries risk the organisation chooses to reduce. Technology makes the process sustainable; qualified people still make the judgements and sign off.

A useful test: if a regulator asked today for evidence of compliance with one specific obligation at one specific site, how quickly could you produce it — and how sure are you that the obligation is still current?

Frequently asked questions

How often should an EHS legal register be reviewed?

At least annually, and more often for high-risk obligations or during significant regulatory change. The most resilient approach combines continuous regulatory monitoring with a documented periodic review, so the register stays current between formal reviews.

What is the difference between identifying legislation and assessing compliance?

Identifying legislation establishes that a regulation applies. Assessing compliance establishes what it requires in practice, whether the organisation meets it, and what evidence supports that conclusion. A register that stops at identification is a list, not a compliance position.

Is a spreadsheet enough to manage a legal register?

For a single site with stable obligations and a disciplined owner, it can work. Risks grow with scale, regulatory change, and staff turnover — particularly around version control, evidence, and audit trail.

General information only — not legal advice. Confirm obligations with qualified counsel or your regulatory team.

Keep reading

Related resources

  • Two colleagues reviewing documents at a desk with a book titled The Law in the foreground
    ArticleLegal Registers

    What is an EHS legal register and why does it matter?

    Everyone in EHS is expected to have a legal register, but few are taught how to build one. Here is what it is, what it should contain, what ISO 14001 and ISO 45001 expect, and how to keep it current.

    · 8 min readRead article
  • Scientist reviewing samples in a laboratory
    Case studyLegal Registers

    Less noise. More confidence in what actually applies.

    How a pharmaceutical manufacturer simplified its EHS legal register, reduced the time spent assessing compliance and gained greater confidence in its legal requirements.

    · 4 min readRead case study
  • Open-plan office with desk workstations, planters and bright ceiling lighting
    Case studyLegal Registers

    Compliance doesn’t need to be complicated

    How an office-based organisation created a simple, proportionate way to maintain its legal register and support ongoing ISO compliance.

    · 4 min readRead case study

Get new resources in your inbox

New guides, articles and case studies on regulatory change, EHS and compliance, sent roughly once a month.

We’ll use your details to respond to your request as explained in our Privacy Policy. Marketing emails are optional, and you can unsubscribe at any time.