What is an EHS legal register and why does it matter?

Everyone in EHS is expected to have a legal register, but few are taught how to build one. Here is what it is, what it should contain, what ISO 14001 and ISO 45001 expect, and how to keep it current.

Published
Length
8 min read
Two colleagues reviewing documents at a desk with a book titled The Law in the foreground

In short

An EHS legal register is a structured record of the environmental, health and safety legislation that applies to your operations and the specific obligations it creates. A useful register answers four questions at any moment: what applies to us, what it requires, whether we are doing it, and whether we can prove it.

Key takeaways

  • A legal register translates legislation into specific, verifiable obligations — it is not just a list of laws.
  • Compliance status, evidence, and actions are where most registers fall short.
  • ISO 14001 and ISO 45001 expect a register that is current, owned, evaluated on a cycle, and backed by evidence.
  • Site-specific permit and licence conditions often carry the most risk and never appear in generic templates.
  • Continuous monitoring only helps when each change is interpreted against your own obligations.

If you work in environmental, health and safety compliance, the legal register is something everyone is expected to have but few are ever taught to build or maintain. It is often inherited: a spreadsheet passed from one EHS Manager to the next, updated when someone remembers, and properly reviewed only in the weeks before an audit.

That worked, more or less, when regulation moved slowly. It no longer does. Legislation changes throughout the year, auditors expect traceability rather than tidy lists, and leadership asks questions a static document cannot answer.

An EHS legal register is a structured record of the environmental, health and safety legislation that applies to your operations — and, crucially, the specific obligations that legislation places on you.

It is not simply a list of laws. A regulation might run to eighty pages, but the obligations it creates for your business might be five specific, verifiable requirements. The register is where that translation lives: what you must do, at which sites, for which activities, and how compliance is shown.

A well-maintained register answers four questions at any moment: What applies to us? What does it require us to do? Are we doing it? Can we prove it? If it can only answer the first, it is a reference document, not a compliance tool.

Formats vary between organisations and industries, but a well-built register typically covers:

  • Applicable legislation — acts, regulations, statutory instruments, permits, and licence conditions, including amendments and commencement dates
  • Plain-language obligations — what each piece of legislation requires, written so operational teams can understand it without legal training
  • Site and activity mapping — which obligations apply to which sites, processes, and activities
  • Compliance status — whether each obligation is currently met, when it was last assessed, and by whom
  • Evidence — records, certificates, monitoring data, training logs, and documents that show compliance in practice
  • Actions — what needs to happen where gaps exist, who owns each action, and the deadline

Usually in the last three items. A list of legislation tells an auditor what you know about. Linked evaluations, evidence, and actions show what you actually do about it — and that is what audit preparation rests on.

For organisations certified, or working towards certification, to ISO 14001 (environmental management) or ISO 45001 (occupational health and safety), the register is not optional housekeeping. Both standards require you to determine applicable legal requirements, maintain access to them, take them into account in the management system, and periodically evaluate compliance against them.

Certification auditors look for more than the register’s existence. They want to see that it is current, that someone owns it, that compliance evaluations happen on a defined cycle, that evidence supports those evaluations, and that non-compliances generate corrective actions tracked to closure.

A register last updated eighteen months ago, with no linked evidence, is one of the most common audit findings in certified organisations — precisely because a static document drifts so easily.

Why do site-specific obligations matter?

Two organisations in the same industry rarely share identical obligations. Two sites in the same organisation can differ too: one holds an environmental permit with bespoke conditions, another stores chemicals above a regulatory threshold, a third operates equipment that triggers specific inspection and certification requirements.

A generic, off-the-shelf register misses this. Permit, planning, and licence conditions are often where the most significant risk sits, because they are unique to you and will never appear in a template. They are also what a regulator is most likely to check.

A practical test: pick one site and ask whether your register reflects the specific conditions of its permits and licences, not just the general legislation behind them. If it does not, start there.

EHS legislation changes throughout the year: new regulations, amendments, revised guidance, updated standards, and changed permit conditions. A register reviewed annually can be out of date within weeks, and the gap only shows when something goes wrong or an auditor asks an unexpected question.

That is why continuous regulatory monitoring has become the expected standard. The goal is not just an alert that something changed — most teams already drown in alerts. It is understanding what the change means for your obligations: which register entries are affected, whether current controls still meet the requirement, and what action is needed. Monitoring without interpretation moves the workload; it does not reduce it.

Most EHS teams managing registers manually run into the same difficulties, however capable they are:

  • Currency — keeping pace with change across every relevant framework competes with operational priorities
  • Interpretation — turning legislation into operational requirements takes expertise and time
  • Fragmentation — the register, evidence, and actions sit in different files, drives, and inboxes, so every audit becomes an assembly exercise
  • Ownership — when responsibility is unclear or rests on one person, updates stop when that person is busy, on leave, or gone
  • Audit preparation — evaluations and evidence are assembled in a scramble before an inspection instead of being kept up to date

Is this a competence problem?

No. These problems reflect tooling that was never designed for the job, not a lack of competence. Recognising that is usually the first step towards fixing it.

Dedicated software addresses these challenges structurally rather than through more effort. It keeps obligations, compliance evaluations, evidence, and actions connected in one place; supports ongoing monitoring so changes are reviewed in the context of your obligations; makes ownership explicit with named owners and visible deadlines; and keeps the traceability from obligation to source legislation to evidence that auditors expect.

The result is not guaranteed compliance — no software can honestly promise that, and any vendor who does should prompt caution. Good software provides visibility and control: a clear, current picture of what applies, how you are performing, and what needs attention next. The compliance decisions remain yours.

Envaira treats the legal register as the foundation of compliance and EHS work. Registers are built from your operational profile — sites, activities, permits, and jurisdiction — with obligations summarised in plain language and linked to source legislation.

Technology supports regulatory monitoring and obligation mapping at scale, and qualified people review and sign off. Evidence, evaluations, and corrective actions stay connected to the obligations they relate to, so audit preparation is part of the year’s work rather than the fortnight before an inspection.

Frequently asked questions

Is an EHS legal register a legal requirement?

In most jurisdictions no single law says you must keep a legal register. However, organisations are expected to know and comply with applicable legislation, and ISO 14001 and ISO 45001 both require access to applicable legal requirements and periodic compliance evaluation. A legal register is the recognised, practical way to meet those expectations — and usually the first thing auditors ask to see.

How often should a legal register be updated?

Best practice is continuous monitoring rather than a fixed review cycle. Legislation changes throughout the year, so a register maintained through ongoing monitoring stays closer to reality than one reviewed annually or quarterly. Periodic full reviews still add value as a quality check.

Who should own the legal register?

The EHS, HSE, or Compliance Manager typically owns the register overall, but individual obligations work best with named owners close to the relevant activity. Clear ownership at obligation level, with deadlines and visibility, is one of the strongest signs of a register that stays current.

General information only — not legal advice. Confirm obligations with qualified counsel or your regulatory team.

Keep reading

Related resources

Get new resources in your inbox

New guides, articles and case studies on regulatory change, EHS and compliance, sent roughly once a month.

We’ll use your details to respond to your request as explained in our Privacy Policy. Marketing emails are optional, and you can unsubscribe at any time.