Building a Legal Register of Compliance Obligations
Legal Register in Brief
- Document the legal and other requirements applicable to the organisation
- Assign each requirement to an owner who tracks compliance
- Review periodically and on legislative change
What is a Legal Register and Why Does Your Organisation Need One?
A legal register lists every piece of legislation that applies to what an organisation does - employing people, occupying premises, running equipment, processing data, producing waste, supplying products and so on. For each entry it records what the law requires, how the organisation complies and how relevant the obligation is to its operations.
Most management system standards expect this. ISO 14001 Clause 6.1.3 and ISO 45001 Clause 6.1.3 both require organisations to determine and have access to their compliance obligations. ISO 9001 reaches the same point through Clauses 4.2 (interested parties) and 8.2.2 (requirements for products and services), since regulators are interested parties whose requirements have to be understood. ISO 27001 Annex A clause 5.31 covers identification of legal, statutory, regulatory and contractual requirements relevant to information security.
A legal register is also the obvious answer to the audit question of "how do you know which laws apply to you?" - which comes up under all four major ISO standards (9001, 14001, 45001 and 27001).
What Goes into a Legal Register
A useful legal register covers more than just titles of Acts. It needs enough detail that someone reading it understands what each piece of legislation requires of the organisation and where the evidence of compliance lives. The categories below work well for most organisations.
The starting point for a legal register is the activities your organisation actually does. There is no point listing offshore drilling regulations if you run a software company. Walk through what the business does day-to-day - who you employ, what premises you occupy, what equipment you operate, what data you handle, what you sell - and the relevant legislation flows from that.
For each entry, record three things: what the law requires in plain language, what your organisation does to comply, and how relevant the obligation is. If you cannot fill in those three columns for an entry, you do not yet understand the obligation well enough to claim compliance.
One of the more common mistakes I see is treating the legal register as an isolated document - a one-off task done at certification, then ignored. It works far better as a living reference - reviewed as part of management review, updated by the H&S adviser after an HSE webinar, checked by the compliance lead whenever a new contract requires evidence of legal compliance. The register is meant to be used, not just produced.
Folk get scared of legal registers because they think they need to read every Act of Parliament. You don't. Start with what you know - you employ people, you have a building, you hold customer data, you produce something - and the legislation flows from each of those. Then you review it once a year and add anything new. That is most of the job.
When I audit a legal register I look for three things. First, that it actually reflects what the organisation does - not a generic template lifted from somewhere. Second, that the compliance column points to a policy, a record, a procedure, or a named role rather than a vague statement. Third, that it has been reviewed recently and the review is recorded.
I also expect the register to mention how the organisation finds out about new or changed legislation. A subscription service, a regulator newsletter, a trade body update - any reasonable mechanism works, but there has to be one.
The biggest weakness I see is registers built once, certified against, and never opened again. The legislation column drifts out of date, the compliance column refers to procedures that have since been replaced, and the reviewer column shows a date three years ago. That is a finding waiting to happen, and easy enough to put right.
Categorising Legislation
For most organisations, categorising legislation makes the register easier to use and review. A common structure is:
- Company - corporate governance, taxation, insurance and statutory record-keeping (Companies Act 2006, Corporation Tax Act, Employers' Liability (Compulsory Insurance) Act 1969)
- Employment - everything covering staff (Equality Act 2010, Working Time Regulations, National Minimum Wage Act, Modern Slavery Act 2015, Immigration Act 2016)
- Health and Safety - Health and Safety at Work Act 1974, COSHH, RIDDOR, the Regulatory Reform (Fire Safety) Order 2005 and so on
- Environmental - Environment Act 2021, Environmental Protection Act 1990, packaging and waste regulations
- Equipment - PUWER, LOLER, Pressure Systems Safety Regulations, Electricity at Work Regulations
- Data and Privacy - UK GDPR, Data Protection Act 2018, Data (Use and Access) Act 2025, Privacy and Electronic Communications Regulations 2003
- Financial and Corporate - Bribery Act 2010, Fraud Act 2006, Economic Crime and Corporate Transparency Act 2023, Consumer Rights Act 2015
- Specific - sector-specific legislation that does not fit elsewhere (Food Safety, FORS, Drivers' Hours and Tachographs Regulations)
Marking each entry as Pertinent, Relevant or Irrelevant helps focus attention. Pertinent items affect daily operations and need active management. Relevant items apply to the organisation but rarely come up. Irrelevant items are recorded so it is clear they have been considered and ruled out, which is useful when an auditor asks.
International Context
The legislation in this article is UK-focused. Organisations operating outside the UK need to identify the equivalent regulations in their own jurisdictions - for example, the EU GDPR rather than UK GDPR for data protection in the EU, OSHA standards rather than the Health and Safety at Work Act in the US, or the Workplace Health and Safety Act in Australia. The register format works the same regardless of jurisdiction; only the entries change.
Multi-jurisdiction organisations sometimes run a single register with a "country" column or a separate register per country. Either approach is fine as long as the obligations are clearly attributable to the relevant operations.
Keeping the Register Up to Date
Laws change. New regulations come in, existing ones are amended, others are repealed. The most common cause of a non-conformity in this area is a register that has not been reviewed in two years and still cites superseded legislation.
An effective approach is a periodic review built into the management calendar - typically annually as a minimum, or alongside management review. Between formal reviews, anyone responsible for a business area should flag legal changes they become aware of, so the register stays current rather than relying on a once-a-year catch-up.
In the UK, sources of legislative updates include the Health and Safety Executive (HSE) for H&S, the Environment Agency for environmental, the Information Commissioner's Office (ICO) for data protection, ACAS and gov.uk for employment, and trade bodies for sector-specific changes. A subscription to a legal update service is the most efficient option for organisations with a wide compliance footprint.
Practical Advice
The most reliable way to set up and maintain a legal register is to start from a register that has the common UK legislation already populated, then tailor the entries and add anything sector-specific. Building one from a blank spreadsheet usually means missing obligations.
The documents below give you both options. ER9 is the full version with detailed compliance entries; F-IMS27 is a simpler version for smaller organisations or those building from scratch. Either works for any standard's audit.
| alphaZ document | How to use it |
|---|---|
| ER9 Legal Register | The fuller version of the legal register with extensive UK legislation already populated across all categories. Tailor the entries to your operations and remove anything that does not apply. |
| F-IMS27 Legal Register | A simpler version of the legal register suitable for smaller organisations or those preferring a leaner template. Same structure, fewer pre-populated entries. |
| F-IMS22 Interested Parties Register | Records regulators and enforcement bodies as interested parties whose requirements feed into the legal register. Sits alongside the legal register and references it. |
| F-IMS23 Opportunities and Risks Register | Captures compliance risk - where a legal obligation creates a significant risk that needs active management, the register records the risk and the controls in place. |
| ISO 9001/14001/45001 IMS Toolkit | Full integrated management system toolkit including the legal register, registers for interested parties and risks, and the policies and procedures that satisfy the compliance obligations identified in the register. |
Note: subscribers to alphaZ documents can download all of the documents above as part of the subscription.
Frequently Asked Questions
ISO 9001 does not list a "legal register" by name as required documented information. It does require organisations to determine the requirements of interested parties (Clause 4.2) and statutory and regulatory requirements applicable to products and services (Clause 8.2.2). A legal register is the most practical way to evidence both. ISO 14001 and ISO 45001 are explicit: Clause 6.1.3 of each requires the organisation to determine and have access to its compliance obligations and to maintain documented information about them.
Annually as a minimum is the common standard, often timed to coincide with management review. Significant legislative changes - for example the Data (Use and Access) Act 2025 commencing in February 2026 - should trigger an out-of-cycle update rather than waiting for the annual review. The review date and reviewer should be recorded on the register itself so the audit trail is visible.
The IMS lead, quality manager, compliance manager or equivalent typically owns the register as a whole. Individual entries often have separate technical owners - the H&S adviser owns the safety entries, HR owns the employment entries, the data protection officer or IT lead owns the data and privacy entries. Centralised ownership with distributed input is the usual pattern, and works well as long as the technical owners are clearly identified for each entry.
It can be useful to include legislation that has been considered and ruled out, marked as Irrelevant. This shows that the organisation has thought about it rather than overlooked it. A common example is sector-specific legislation that an auditor might expect to see considered - food hygiene regulations for a non-food business, ionising radiation regulations for a non-medical business. Keeping these on the register with a brief note of why they do not apply pre-empts the audit question.
This is a labelling convention rather than a legal classification. Pertinent items affect day-to-day operations and need active management - the Health and Safety at Work Act for any employer, UK GDPR for any organisation processing personal data. Relevant items apply but rarely come up in operations - the Modern Slavery Act 2015 for organisations below the £36 million turnover threshold, for example, where the organisation supports the principles but is not required to publish a statement. Irrelevant items have been considered and do not apply. Other organisations use Critical/Applicable/Not Applicable or similar wording - the labels matter less than using them consistently.
UK Legislation
The cross-cutting legislation most legal registers cover is wide-ranging. Examples of frequently-cited entries include:
- Health and Safety at Work etc. Act 1974
- Equality Act 2010
- Companies Act 2006
- Bribery Act 2010
- Modern Slavery Act 2015
- Environment Act 2021
- Data Protection Act 2018 and UK GDPR
- Data (Use and Access) Act 2025
- Economic Crime and Corporate Transparency Act 2023
- Consumer Rights Act 2015
