Knowella

Legal and Other Requirements Register

The failure mode is almost never a missing law. It is a register of correct instrument titles with nothing behind them: no note of which sections bite at this site, no named owner, no pointer to the record that proves compliance, and a last-reviewed date two certification cycles old. Auditors do not test whether you can name the regulation. They test whether you know which part applies and can produce the evidence.

KnowComplyRegisterCMP-009Pinned in navigation40 fields across 3 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 45001 cl.6.1.3, ISO 14001 cl.6.1.3
Workspace
KnowComply
Form type
Register
Review trigger
At least annually, and on any entry added, changed or retired
Completed by
Compliance lead, countersigned by the site manager

The short version

  • A register entry that names an instrument without naming its applicable parts is not a compliance obligation; it is a bibliography line, and it fails cl.6.1.3 on scope.
  • Every entry needs a named owner. Ownership by department is ownership by nobody, which is why the Owner field is a user reference rather than free text.
  • The register only holds up under audit if each entry points at the record that demonstrates compliance. Evidence Identified is scored for exactly that reason.
  • Horizon scanning decays first. A register with no named source of updates is accurate on the day it is built and degrading from the next morning.

What this is

What is a legal and other requirements register?

What is a legal and other requirements register?

It is the controlled list of every statutory, regulatory, permit and voluntary obligation applying to a site, with the parts of each instrument that actually bite and the evidence that demonstrates compliance. "Other requirements" is the deliberate second half: customer contracts, scheme rules and public commitments sit alongside statute. It is master data, so it is maintained rather than raised.

What is the difference between a legal register and a compliance evaluation?

The register says what applies to you; the evaluation says whether you currently meet it. Both standards separate these into cl.6.1.3 and cl.9.1.2, and conflating them is the commonest structural error. Compliance Status and Last Evaluated here summarise the latest evaluation, but the evaluation itself belongs in the Compliance Evaluation Record.

What does a compliance obligation cover beyond the law?

ISO 14001 uses "compliance obligations" to cover mandatory legal requirements and the voluntary obligations an organisation has chosen to adopt. Once adopted, a voluntary commitment is auditable in the same way as a statute. The Type field keeps the distinction visible, so a customer requirement is never quietly upgraded into law and a permit condition is never downgraded into guidance.

Scope

When is a legal and other requirements register required?

This register is the master data layer for the compliance programme. Every other compliance template draws from it or writes back to it, so work done in the wrong template contaminates the source of truth for everything downstream.

Use this template when

  • Standing up a management system and establishing the compliance baseline for a site
  • Adding an obligation after a permit is granted, varied or a new customer requirement is accepted
  • Recording which sections of an instrument apply to this site and why, in Applicable Parts and Why It Applies
  • Assigning a named owner and an evidence location to each obligation
  • The annual currency review that refreshes Last Reviewed, Next Review Due and the Register health counts

Do not use it for

  • Compliance Evaluation Record, which carries the periodic test of whether you actually comply and the findings that come out of it.
  • Compliance Obligation Assessment, which works through a single obligation in depth and decides what you must do to meet it.
  • Regulatory Change Record, which handles a change in law from awareness through to implementation and only then updates this register.
  • Environmental Permit Register, which holds permit numbers, expiry dates and variation history at a level of detail this register only summarises.
  • Standards and Clause Register, which holds the clause structure of certification standards that entries here reference through Clause ID.

Compliance mapping

Which ISO 45001 cl.6.1.3 requirements does this satisfy?

The register carries obligations under both the safety and environmental management system standards, which use near-identical wording at cl.6.1.3. The mapping below ties each requirement to the section of this template that satisfies it.

ClauseRequirementWhere it lands
ISO 45001 cl.6.1.3Determine and have access to up-to-date legal requirements and other requirements applicable to hazards, OH&S risks and the OH&S management systemRequirements
ISO 14001 cl.6.1.3Determine compliance obligations, how they apply to the organisation, and take them into account when establishing the environmental management systemRequirements
ISO 45001 cl.5.3Assign responsibility and authority for relevant roles within the management systemRequirements
ISO 45001 cl.9.1.2Establish processes for evaluating compliance and determine the frequency at which compliance is evaluatedRequirements
ISO 14001 cl.9.1.2Maintain knowledge and understanding of compliance statusRegister health
ISO 45001 cl.9.3Management review to consider the extent to which legal and other requirements are fulfilledRegister health

What it does not cover

  • An instrument title with no Applicable Parts, which shows the register was assembled rather than determined, and leaves the site no way to know what it must do.
  • An entry with no Owner, which means no authority was assigned under cl.5.3 and the obligation will only surface again at audit.
  • Evidence Identified set to No and left there, which is an admission that compliance cannot be demonstrated, recorded and then not actioned.
  • A Review Frequency of None set, which breaks cl.9.1.2 directly, since the frequency of compliance evaluation must be determined rather than left implicit.
  • Horizon Scanning In Place answered Informal, which usually means one person reads a newsletter and nothing is captured when they are on leave or leave the business.

Global

Legal and Other Requirements Register requirements by country

The Jurisdiction field offers Federal, Provincial, Municipal, Customer country and International, which reflects a federated regulatory structure rather than one national code. Three settings account for most of the trouble.

Canada

Canada Labour Code Part II and the provincial occupational health and safety acts, such as Ontario's Occupational Health and Safety Act

Occupational health and safety is provincial for most employers, with federal jurisdiction reserved for federally regulated sectors including interprovincial transport, banking and telecommunications.

A multi-site register cannot hold one national safety row. The same hazard is governed by different instruments province to province, and a transport operation may sit under federal rules while the warehouse next door does not.

United States

Occupational Safety and Health Act of 1970, OSHA standards at 29 CFR Part 1910, and state plans approved under section 18 of the Act

Federal OSHA standards set a floor; approved state plans may impose requirements at least as effective, and often stricter.

Registers built from the federal CFR alone understate obligations in state-plan states. Applicable Parts should cite the state standard where one supersedes, not the federal section it replaces.

European Union

Directive 89/391/EEC on measures to encourage improvements in the safety and health of workers, and Directive 2010/75/EU on industrial emissions

Directives are transposed into national law by each member state, which sets the detail, the thresholds and the enforcement mechanism.

Citing the directive is not enough for a site audit. The enforceable requirement is the national transposition, and the permit conditions issued under it are where compliance is actually tested.

How to complete it

How to complete a legal and other requirements register, step by step

Filling in the fields is mechanical. Four judgement calls decide whether the register survives a certification audit or a regulator visit.

How far to decompose an instrument

One row per statute is too coarse and one row per sub-clause is unmaintainable. The workable unit is an obligation a single owner can be held to and a single body of evidence can demonstrate. If Applicable Parts runs to a paragraph, or Owner would need to be two people, split the row.

What counts as evidence, not intent

Compliance Evidence Location should point at output, not policy. A procedure describing what you intend to do is not evidence that you did it; the completed record, calibration certificate, training matrix entry or monitoring result is. Where the artefact is another template in the library, name it in Templates Or Records That Demonstrate It.

Setting Review Frequency against consequence, not convenience

The template scores Quarterly and Annually equally, deliberately: the standard prescribes no period, only that the period is determined and justified. Obligations where Consequence Of Breach is Prohibition, Prosecution or Loss of certification should not sit on a two-year cycle simply because they have been stable.

Being honest in the Register health counts

Requirements With An Owner, Requirements With Evidence Identified and Never Evaluated are what make the register auditable rather than decorative. Inflating them to protect a currency percentage destroys the only management signal it produces, and the gap surfaces the moment an auditor samples three rows at random.

What auditors find

Most common legal and other requirements register findings

These findings recur when registers are examined by a certification body or regulator, with the clause each is raised against and the fix that closes it.

FindingClauseWhat fixes it
Register lists instruments but does not state how they apply to the organisationISO 14001 cl.6.1.3Populate Applicable Parts and Why It Applies for every row, then reject any new entry that cannot answer both.
No evidence that the register has been reviewed since certificationISO 45001 cl.6.1.3Set Next Review Due at each review and drive the annual cycle from it; Last Reviewed and Reviewed By together give the audit trail.
Compliance evaluation frequency not determinedISO 45001 cl.9.1.2Eliminate every None set in Review Frequency, and record the justification for the interval chosen where it exceeds a year.
Obligations identified with no assigned responsibilityISO 45001 cl.5.3Make Owner mandatory in practice as well as configuration, and report Requirements With An Owner against Requirements On Register at management review.
Changes in legal requirements not reflected in the management systemISO 14001 cl.6.1.3Name a Source Of Updates and set Horizon Scanning In Place to Yes with a defined subscription or adviser; raise a Regulatory Change Record for each change captured.
Known non-compliances recorded but no corrective action raisedISO 45001 cl.10.2Where Compliance Status is Non compliant, set Action Required to Yes and record the CAPA ID and Action Owner rather than leaving the row as a note.

Case in point

Case in point: the permit condition nobody owned

A distribution site held a discharge consent for its interceptor outfall. The register carried the environmental permitting regulations as a single row: Type Regulation, Applicable Parts blank, Owner recorded as "Site Services". The permit's own sampling frequency and limit appeared nowhere, because the row described the enabling regulation rather than the condition attached to the site.

Sampling lapsed for eleven months after the contractor's scope was renegotiated. Nobody noticed, because no individual held the obligation and the register showed a green row. The finding at the regulator's visit was not the missed samples; it was that the organisation had no mechanism to know they were required. The fix was three rows instead of one, each with a permit condition in Applicable Parts, a named Owner, and the sampling record named in Compliance Evidence Location.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

40fields
3 sections
Reference
CMP-009
Archetype
Register
Record ID
LEG-2026-000
Scoring
Currency percent
Direction
High is good
Singleton
No
Basis
ISO 45001 cl.6.1.3, ISO 14001 cl.6.1.3
Links
Links Site, Clause Register
Tags
Compliance, Master data
Sections
3
Fields
40
Follow up fields
3
Repeating sections
1
Links out
3
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

8 fields
Text

Register ID*

Generated on save

Auto sequence. Format LRR-2026-000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Date & Time

Last Reviewed*

Users

Reviewed By*

Date & Time

Next Review Due*

Info

A List Of Titles Is Not A Register

Naming a regulation proves nothing. The register must say which parts apply here, who owns them, and where the evidence of compliance lives.

Requirements

Repeats15 fields
Text

Requirement Title*

Single Choice

Type*

Statute, regulation, permit condition, code of practice, customer requirement, certification scheme or voluntary commitment.

StatuteRegulationPermit conditionCode of practiceCustomer requirementCertification schemeVoluntary commitment
Single Choice

Jurisdiction*

FederalProvincialMunicipalCustomer countryInternational
Text

Applicable Parts*

The specific sections that apply to this site, not the whole instrument.

Text

Why It Applies

Optional
Single Choice

Domain*

SafetyFood safetyQualityEnvironmentalOccupational healthEngineeringWarehouseTransport
Users

Owner*

Text

Compliance Evidence Location*

Single Choice

Evidence Identified*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Text

Templates Or Records That Demonstrate It

Optional
Text

Clause ID

OptionalLinked

Links to FDN-009 Clause ID

Date & Time

Last Evaluated

Optional
Single Choice

Compliance Status*

Scored
  • Compliant3 pts
  • Partially compliant1 pt
  • Non compliant0 pts
Single Choice

Consequence Of Breach*

Scored
  • Advisory3 pts
  • Fine1 pt
  • Prohibition0 pts
  • Prosecution0 pts
  • Loss of certification0 pts
Single Choice

Review Frequency*

Scored
  • Quarterly3 pts
  • Annually3 pts
  • Every 2 years1 pt
  • None set0 pts

Register health

17 fields
Numeric Answer

Requirements On Register*

Numeric Answer

Requirements With An Owner*

Scored
Numeric Answer

Requirements With Evidence Identified*

Scored
Numeric Answer

Evaluated Within Frequency*

Scored
Numeric Answer

Never Evaluated*

Scored
Numeric Answer

Known Non Compliances*

Scored
Single Choice

Horizon Scanning In Place*

Scored

Somebody has to watch for changes. Subscriptions, trade associations or legal updates all work if somebody reads them.

  • Yes3 pts
  • Informal1 pt
  • No0 pts
Single Choice

Source Of Updates

Optional
Subscription serviceTrade associationLegal adviserRegulator alertsCertification body
Numeric Answer

Changes Captured This Period

Optional
Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Users

Compliance Lead*

Signature

Signature*

Users

Site Manager*

Signature

Second Signature*

CMP-009 · record IDs look like LEG-2026-000 · Links Site, Clause Register

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

A register decays through neglect rather than error, and the work that keeps it alive sits with the teams that own the obligations.

KnowComply

Owns the register itself: entry lifecycle, review dates, ownership assignment and the currency measures that feed management review.

KnowEnviro

Supplies the environmental half: permits, discharge consents and waste obligations, feeding rows that reference the permit and waste registers for detail.

KnowSafe

Supplies the occupational health and safety obligations and holds the risk assessments and records that most safety rows nominate as evidence.

Ella
Ella

Watches for rows past their review frequency, unowned entries and evidence gaps, drafts the updates, and holds every write for approval before it touches the register.

This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.

Meet KnowComply→

Glossary

Legal and Other Requirements Register definitions and key terms

Compliance obligation
The ISO 14001 term covering both mandatory legal requirements and voluntary obligations the organisation has adopted, such as customer or scheme requirements.
Applicable parts
The specific sections, schedules or conditions of an instrument that bind this site, as distinct from the instrument as a whole.
Horizon scanning
The standing arrangement by which forthcoming or newly published legal changes are detected: a subscription service, trade association, adviser, regulator alert or certification body.
Evaluation of compliance
The periodic test under cl.9.1.2 of whether an obligation is actually being met, producing a compliance status and, where needed, a corrective action.
Currency percent
The register health measure used here: the proportion of entries with an owner, identified evidence and an evaluation within their stated frequency. High is good.

FAQ

Frequently asked questions about legal and other requirements register

How often must a legal register be reviewed?+

Neither standard sets a period; both require the information to be kept up to date, which in practice means an annual full review plus event-driven updates as changes are captured. Next Review Due carries the commitment; the per-entry Review Frequency governs evaluation intervals separately.

Should customer and certification requirements sit in the same register as law?+

Yes. Both standards use "and other requirements" or "compliance obligations" precisely to bring them in scope. The Type field keeps them distinguishable, which matters because consequence differs sharply: a statute breach risks prosecution, a scheme breach loss of certification.

Does every entry need an evidence location?+

Every entry that applies to the site does. Evidence Identified is scored across Yes, Partly and No so partial coverage stays visible. A No is acceptable as a temporary honest state, not as a permanent one.

How does this register relate to the Compliance Evaluation Record?+

The register is the population; the evaluation record is the test applied to it. Last Evaluated and Compliance Status summarise the most recent evaluation so the register reads on its own, but the evidence and findings live in the evaluation record.

Can the register be held per site or must it be corporate?+

It is held per site, with Site and Site ID linked to the site register, and corporate obligations entered against each site they bind. That duplicates rows but keeps ownership and evidence local, which is what an auditor sampling at a site will ask for.

What happens when an obligation is retired?+

Retire the row rather than deleting it, and record the change through a Regulatory Change Record where a withdrawal is the cause. Deletion breaks the audit trail and makes it impossible to show why the register no longer covers something a previous audit saw.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO 45001:2018 cl.6.1.3 Determination of legal requirements and other requirements
  • ISO 14001:2015 cl.6.1.3 Compliance obligations
  • ISO 45001:2018 cl.9.1.2 Evaluation of compliance
  • Occupational Safety and Health Act of 1970, section 18 (state plans); OSHA standards at 29 CFR Part 1910
  • Council Directive 89/391/EEC on measures to encourage improvements in the safety and health of workers at work

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.