What this is
What is a legal and other requirements register?
What is a legal and other requirements register?
It is the controlled list of every statutory, regulatory, permit and voluntary obligation applying to a site, with the parts of each instrument that actually bite and the evidence that demonstrates compliance. "Other requirements" is the deliberate second half: customer contracts, scheme rules and public commitments sit alongside statute. It is master data, so it is maintained rather than raised.
What is the difference between a legal register and a compliance evaluation?
The register says what applies to you; the evaluation says whether you currently meet it. Both standards separate these into cl.6.1.3 and cl.9.1.2, and conflating them is the commonest structural error. Compliance Status and Last Evaluated here summarise the latest evaluation, but the evaluation itself belongs in the Compliance Evaluation Record.
What does a compliance obligation cover beyond the law?
ISO 14001 uses "compliance obligations" to cover mandatory legal requirements and the voluntary obligations an organisation has chosen to adopt. Once adopted, a voluntary commitment is auditable in the same way as a statute. The Type field keeps the distinction visible, so a customer requirement is never quietly upgraded into law and a permit condition is never downgraded into guidance.
Scope
When is a legal and other requirements register required?
This register is the master data layer for the compliance programme. Every other compliance template draws from it or writes back to it, so work done in the wrong template contaminates the source of truth for everything downstream.
Use this template when
- Standing up a management system and establishing the compliance baseline for a site
- Adding an obligation after a permit is granted, varied or a new customer requirement is accepted
- Recording which sections of an instrument apply to this site and why, in Applicable Parts and Why It Applies
- Assigning a named owner and an evidence location to each obligation
- The annual currency review that refreshes Last Reviewed, Next Review Due and the Register health counts
Do not use it for
- Compliance Evaluation Record, which carries the periodic test of whether you actually comply and the findings that come out of it.
- Compliance Obligation Assessment, which works through a single obligation in depth and decides what you must do to meet it.
- Regulatory Change Record, which handles a change in law from awareness through to implementation and only then updates this register.
- Environmental Permit Register, which holds permit numbers, expiry dates and variation history at a level of detail this register only summarises.
- Standards and Clause Register, which holds the clause structure of certification standards that entries here reference through Clause ID.
Compliance mapping
Which ISO 45001 cl.6.1.3 requirements does this satisfy?
The register carries obligations under both the safety and environmental management system standards, which use near-identical wording at cl.6.1.3. The mapping below ties each requirement to the section of this template that satisfies it.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 45001 cl.6.1.3 | Determine and have access to up-to-date legal requirements and other requirements applicable to hazards, OH&S risks and the OH&S management system | Requirements |
| ISO 14001 cl.6.1.3 | Determine compliance obligations, how they apply to the organisation, and take them into account when establishing the environmental management system | Requirements |
| ISO 45001 cl.5.3 | Assign responsibility and authority for relevant roles within the management system | Requirements |
| ISO 45001 cl.9.1.2 | Establish processes for evaluating compliance and determine the frequency at which compliance is evaluated | Requirements |
| ISO 14001 cl.9.1.2 | Maintain knowledge and understanding of compliance status | Register health |
| ISO 45001 cl.9.3 | Management review to consider the extent to which legal and other requirements are fulfilled | Register health |
What it does not cover
- An instrument title with no Applicable Parts, which shows the register was assembled rather than determined, and leaves the site no way to know what it must do.
- An entry with no Owner, which means no authority was assigned under cl.5.3 and the obligation will only surface again at audit.
- Evidence Identified set to No and left there, which is an admission that compliance cannot be demonstrated, recorded and then not actioned.
- A Review Frequency of None set, which breaks cl.9.1.2 directly, since the frequency of compliance evaluation must be determined rather than left implicit.
- Horizon Scanning In Place answered Informal, which usually means one person reads a newsletter and nothing is captured when they are on leave or leave the business.
Global
Legal and Other Requirements Register requirements by country
The Jurisdiction field offers Federal, Provincial, Municipal, Customer country and International, which reflects a federated regulatory structure rather than one national code. Three settings account for most of the trouble.
Canada Labour Code Part II and the provincial occupational health and safety acts, such as Ontario's Occupational Health and Safety Act
Occupational health and safety is provincial for most employers, with federal jurisdiction reserved for federally regulated sectors including interprovincial transport, banking and telecommunications.
A multi-site register cannot hold one national safety row. The same hazard is governed by different instruments province to province, and a transport operation may sit under federal rules while the warehouse next door does not.
Occupational Safety and Health Act of 1970, OSHA standards at 29 CFR Part 1910, and state plans approved under section 18 of the Act
Federal OSHA standards set a floor; approved state plans may impose requirements at least as effective, and often stricter.
Registers built from the federal CFR alone understate obligations in state-plan states. Applicable Parts should cite the state standard where one supersedes, not the federal section it replaces.
Directive 89/391/EEC on measures to encourage improvements in the safety and health of workers, and Directive 2010/75/EU on industrial emissions
Directives are transposed into national law by each member state, which sets the detail, the thresholds and the enforcement mechanism.
Citing the directive is not enough for a site audit. The enforceable requirement is the national transposition, and the permit conditions issued under it are where compliance is actually tested.
How to complete it
How to complete a legal and other requirements register, step by step
Filling in the fields is mechanical. Four judgement calls decide whether the register survives a certification audit or a regulator visit.
One row per statute is too coarse and one row per sub-clause is unmaintainable. The workable unit is an obligation a single owner can be held to and a single body of evidence can demonstrate. If Applicable Parts runs to a paragraph, or Owner would need to be two people, split the row.
Compliance Evidence Location should point at output, not policy. A procedure describing what you intend to do is not evidence that you did it; the completed record, calibration certificate, training matrix entry or monitoring result is. Where the artefact is another template in the library, name it in Templates Or Records That Demonstrate It.
The template scores Quarterly and Annually equally, deliberately: the standard prescribes no period, only that the period is determined and justified. Obligations where Consequence Of Breach is Prohibition, Prosecution or Loss of certification should not sit on a two-year cycle simply because they have been stable.
Requirements With An Owner, Requirements With Evidence Identified and Never Evaluated are what make the register auditable rather than decorative. Inflating them to protect a currency percentage destroys the only management signal it produces, and the gap surfaces the moment an auditor samples three rows at random.
What auditors find
Most common legal and other requirements register findings
These findings recur when registers are examined by a certification body or regulator, with the clause each is raised against and the fix that closes it.
| Finding | Clause | What fixes it |
|---|---|---|
| Register lists instruments but does not state how they apply to the organisation | ISO 14001 cl.6.1.3 | Populate Applicable Parts and Why It Applies for every row, then reject any new entry that cannot answer both. |
| No evidence that the register has been reviewed since certification | ISO 45001 cl.6.1.3 | Set Next Review Due at each review and drive the annual cycle from it; Last Reviewed and Reviewed By together give the audit trail. |
| Compliance evaluation frequency not determined | ISO 45001 cl.9.1.2 | Eliminate every None set in Review Frequency, and record the justification for the interval chosen where it exceeds a year. |
| Obligations identified with no assigned responsibility | ISO 45001 cl.5.3 | Make Owner mandatory in practice as well as configuration, and report Requirements With An Owner against Requirements On Register at management review. |
| Changes in legal requirements not reflected in the management system | ISO 14001 cl.6.1.3 | Name a Source Of Updates and set Horizon Scanning In Place to Yes with a defined subscription or adviser; raise a Regulatory Change Record for each change captured. |
| Known non-compliances recorded but no corrective action raised | ISO 45001 cl.10.2 | Where Compliance Status is Non compliant, set Action Required to Yes and record the CAPA ID and Action Owner rather than leaving the row as a note. |
Case in point
Case in point: the permit condition nobody owned
A distribution site held a discharge consent for its interceptor outfall. The register carried the environmental permitting regulations as a single row: Type Regulation, Applicable Parts blank, Owner recorded as "Site Services". The permit's own sampling frequency and limit appeared nowhere, because the row described the enabling regulation rather than the condition attached to the site.
Sampling lapsed for eleven months after the contractor's scope was renegotiated. Nobody noticed, because no individual held the obligation and the register showed a green row. The finding at the regulator's visit was not the missed samples; it was that the organisation had no mechanism to know they were required. The fix was three rows instead of one, each with a permit condition in Applicable Parts, a named Owner, and the sampling record named in Compliance Evidence Location.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
3 sections
- Reference
- CMP-009
- Archetype
- Register
- Record ID
- LEG-2026-000
- Scoring
- Currency percent
- Direction
- High is good
- Singleton
- No
- Basis
- ISO 45001 cl.6.1.3, ISO 14001 cl.6.1.3
- Links
- Links Site, Clause Register
- Tags
- Compliance, Master data
- Sections
- 3
- Fields
- 40
- Follow up fields
- 3
- Repeating sections
- 1
- Links out
- 3
Header
8 fieldsRegister ID*
Auto sequence. Format LRR-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Last Reviewed*
Reviewed By*
Next Review Due*
A List Of Titles Is Not A Register
Naming a regulation proves nothing. The register must say which parts apply here, who owns them, and where the evidence of compliance lives.
Requirements
Repeats15 fieldsRequirement Title*
Type*
Statute, regulation, permit condition, code of practice, customer requirement, certification scheme or voluntary commitment.
Jurisdiction*
Applicable Parts*
The specific sections that apply to this site, not the whole instrument.
Why It Applies
Domain*
Owner*
Compliance Evidence Location*
Evidence Identified*
- Yes3 pts
- Partly1 pt
- No0 pts
Templates Or Records That Demonstrate It
Clause ID
Links to FDN-009 Clause ID
Last Evaluated
Compliance Status*
- Compliant3 pts
- Partially compliant1 pt
- Non compliant0 pts
Consequence Of Breach*
- Advisory3 pts
- Fine1 pt
- Prohibition0 pts
- Prosecution0 pts
- Loss of certification0 pts
Review Frequency*
- Quarterly3 pts
- Annually3 pts
- Every 2 years1 pt
- None set0 pts
Register health
17 fieldsRequirements On Register*
Requirements With An Owner*
Requirements With Evidence Identified*
Evaluated Within Frequency*
Never Evaluated*
Known Non Compliances*
Horizon Scanning In Place*
Somebody has to watch for changes. Subscriptions, trade associations or legal updates all work if somebody reads them.
- Yes3 pts
- Informal1 pt
- No0 pts
Source Of Updates
Changes Captured This Period
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Compliance Lead*
Signature*
Site Manager*
Second Signature*
CMP-009 · record IDs look like LEG-2026-000 · Links Site, Clause Register
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
A register decays through neglect rather than error, and the work that keeps it alive sits with the teams that own the obligations.
Owns the register itself: entry lifecycle, review dates, ownership assignment and the currency measures that feed management review.
Supplies the environmental half: permits, discharge consents and waste obligations, feeding rows that reference the permit and waste registers for detail.
Supplies the occupational health and safety obligations and holds the risk assessments and records that most safety rows nominate as evidence.

Watches for rows past their review frequency, unowned entries and evidence gaps, drafts the updates, and holds every write for approval before it touches the register.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Meet KnowComply→Glossary
Legal and Other Requirements Register definitions and key terms
- Compliance obligation
- The ISO 14001 term covering both mandatory legal requirements and voluntary obligations the organisation has adopted, such as customer or scheme requirements.
- Applicable parts
- The specific sections, schedules or conditions of an instrument that bind this site, as distinct from the instrument as a whole.
- Horizon scanning
- The standing arrangement by which forthcoming or newly published legal changes are detected: a subscription service, trade association, adviser, regulator alert or certification body.
- Evaluation of compliance
- The periodic test under cl.9.1.2 of whether an obligation is actually being met, producing a compliance status and, where needed, a corrective action.
- Currency percent
- The register health measure used here: the proportion of entries with an owner, identified evidence and an evaluation within their stated frequency. High is good.
FAQ
Frequently asked questions about legal and other requirements register
How often must a legal register be reviewed?+
Neither standard sets a period; both require the information to be kept up to date, which in practice means an annual full review plus event-driven updates as changes are captured. Next Review Due carries the commitment; the per-entry Review Frequency governs evaluation intervals separately.
Should customer and certification requirements sit in the same register as law?+
Yes. Both standards use "and other requirements" or "compliance obligations" precisely to bring them in scope. The Type field keeps them distinguishable, which matters because consequence differs sharply: a statute breach risks prosecution, a scheme breach loss of certification.
Does every entry need an evidence location?+
Every entry that applies to the site does. Evidence Identified is scored across Yes, Partly and No so partial coverage stays visible. A No is acceptable as a temporary honest state, not as a permanent one.
How does this register relate to the Compliance Evaluation Record?+
The register is the population; the evaluation record is the test applied to it. Last Evaluated and Compliance Status summarise the most recent evaluation so the register reads on its own, but the evidence and findings live in the evaluation record.
Can the register be held per site or must it be corporate?+
It is held per site, with Site and Site ID linked to the site register, and corporate obligations entered against each site they bind. That duplicates rows but keeps ownership and evidence local, which is what an auditor sampling at a site will ask for.
What happens when an obligation is retired?+
Retire the row rather than deleting it, and record the change through a Regulatory Change Record where a withdrawal is the cause. Deletion breaks the audit trail and makes it impossible to show why the register no longer covers something a previous audit saw.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Environmental Management
Compliance Evaluation Record
Records the periodic evaluation of whether you actually comply with each obligation
Waste Stream Register
Lists every waste stream produced on site, with its classification, container and disposal route
Waste Transfer Record
Records waste leaving site, including type, quantity, carrier and destination
Hazardous Waste Record
Records generation, storage and disposal of hazardous waste
Waste Area Inspection
Checks waste storage areas for correct segregation, labelling, containment and housekeeping
Waste Contractor Audit
Audits a waste contractor's permits, vehicles and destination facilities
More in Legal Register
Compliance Obligation Assessment
Assesses how each legal requirement applies to you and what you do to meet it
Compliance Evaluation Record
Records the periodic evaluation of whether you actually comply with each obligation
Regulatory Change Record
Records a change in law or regulation and what it means for you
Regulatory Inspection Record
Records a visit by a regulator, including what was inspected, what was said and any orders issued

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 45001:2018 cl.6.1.3 Determination of legal requirements and other requirements
- ISO 14001:2015 cl.6.1.3 Compliance obligations
- ISO 45001:2018 cl.9.1.2 Evaluation of compliance
- Occupational Safety and Health Act of 1970, section 18 (state plans); OSHA standards at 29 CFR Part 1910
- Council Directive 89/391/EEC on measures to encourage improvements in the safety and health of workers at work
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.