Do I really need a legislation register?

A legislation register is a critical component of any robust corporate governance framework. In an increasingly complex regulatory landscape, organisations must actively track, evaluate, and fulfil their legal obligations. Integrating a centralised legal register into your management system ensures continuous compliance, mitigates operational risk, and satisfies the rigorous requirements of international standards like ISO 9001, ISO 14001, and ISO 45001 (previously OHSAS 18001).

auditor with clipboard
A legislation register with ensure your business is prepared for change

The Strategic Value of a Legislation Register in ISO Management Systems

Modern corporate governance demands a proactive approach to regulatory risk. Organisations can no longer afford to treat legal compliance as an afterthought or a reactive exercise. To achieve long-term commercial resilience, executive leadership must embed a structured legislation register directly into the core of their business management frameworks.

A legislation register—often referred to as a legal register—is a comprehensive database that identifies, organises, and monitors all statutory, regulatory, and contractual obligations applicable to an organisation’s operations. Far from being a static document, it serves as a dynamic compliance anchor that protects businesses from litigation, financial penalties, and reputational damage.

For enterprises operating under international management standards, maintaining this register is not merely a best practice; it is a foundational requirement.

Aligning Legal Registers with ISO Standards

International standards established by the International Organisation for Standardisation (ISO) place significant emphasis on compliance management. A well-maintained legislation register serves as definitive evidence that an organisation understands and actively manages its legal landscape.

1. ISO 9001: Quality Management Systems (QMS)

While ISO 9001 focuses primarily on consistently meeting customer expectations and enhancing satisfaction, it explicitly intersects with statutory and regulatory mandates. Clause 1.1 states that the standard applies to organisations needing to demonstrate their ability to consistently provide products and services that meet both customer and applicable statutory and regulatory requirements.

A legislation register ensures that the legal parameters governing product safety, consumer protection, and industry-specific manufacturing laws are clearly defined and mapped to operational quality controls.

2. ISO 14001: Environmental Management Systems (EMS)

Under ISO 14001, the management of environmental compliance obligations is a strict, mandatory requirement. Clause 6.1.3 demands that organisations determine and have access to the compliance obligations related to their environmental aspects. Furthermore, Clause 9.1.2 requires planned evaluations of compliance status.

An environmental legislation register provides the exact framework needed to track complex rules concerning emissions, waste disposal, hazardous material handling, and resource consumption. Without it, verifying adherence during a third-party ISO audit is virtually impossible.

3. ISO 18001 / ISO 45001: Occupational Health and Safety (OH&S)

Historically, OHSAS 18001 set the global benchmark for workplace safety, requiring organisations to identify and access applicable legal requirements. This standard has since been succeeded and elevated by ISO 45001, which maintains an even stricter focus on legal frameworks. Clause 6.1.3 of the modern OH&S standard requires the systematic determination of legal and other requirements, while Clause 9.1.2 mandates periodic compliance evaluations.

A safety-focused legislation register tracks building regulations, machine guarding standards, personal protective equipment (PPE) mandates, and workers’ compensation laws, fundamentally reducing workplace incidents and liability.

Core Operational Benefits of a Centralised Legal Register

  • Risk Mitigation: Isolates potential compliance breaches before they result in punitive fines, operational shutdowns, or executive prosecution. Valued by regulatory bodies such as the Health and Safety Executive, the Environment Agency and others.
  • Streamlined Auditing: Provides internal and external auditors with immediate, organised, and verifiable evidence of regulatory adherence.
  • Operational Continuity: Centralises specialised regulatory knowledge, ensuring corporate compliance protocols survive leadership transitions or personnel changes.
  • Proactive Adaptability: Establishes a systematic review cycle that alerts management to upcoming legislative adjustments, giving operations ample time to adapt.

Best Practices for Execution

An effective legislation register must transcend a simple list of titles. To deliver true corporate utility, it should include:

  • Specific Granularity: Reference exact sections, clauses, and amendments relevant to the business.  Ensure the register entries are relevant to your business, off the shelf update services may not provide this level of detail.
  • Process Mapping: Link every legal requirement directly to an internal policy, operating procedure, or specific asset.
  • Assigned Accountability: Designate a qualified internal owner responsible for monitoring each piece of legislation.
  • Evidence Log: Maintain a digital audit trail proving when compliance was last evaluated and verified.
  • Maintain the register: once your register is in place, ensure that it is regularly maintained and updated.  Laws and regulations change and your business must be aware and plan for such changes.

Conclusion

A legislation register is an indispensable component of successful ISO 9001, ISO 14001, and ISO 45001 management systems. By transforming legal compliance from an administrative burden into an organised asset, organisations safeguard their operational integrity, validate their commitment to corporate responsibility, and build a sustainable foundation for international commercial growth.

Need Help Implementing This?

If you require expert assistance preparing or maintaining a legal register for your business, please reach out to the Ashbrooke advisory team today.

Managing Home Workers’ Health & Safety: An Employer’s Guide

As an employer, you hold the exact same legal health and safety responsibilities for remote staff working at home as you do for on-site office workers. According to the Health and Safety Executive (HSE) guidelines, these duties extend to all long-term home workers, hybrid staff splitting time with the office, and temporary home workers managing short-term restrictions. While risks are typically low, proactive management protects your business and your people.

Female worker at home using laptop
Are your employees safe working at home?

Identifying Key Areas of Remote Work Risk

What are the primary hazards when staff work from home? While remote environments are generally low risk, the HSE outlines three specific categories employers must address:

  • Mental well being: Stress, isolation, and poor mental health.
  • Ergonomics: Improper use of display screen equipment (DSE).
  • Physical Space: Hazards within the immediate working environment.

Conducting a Remote Worker Risk Assessment

Do employers need to visit staff homes?

In most cases, employers do not need to physically visit a home to complete a risk assessment, provided they can ensure a healthy setup remotely. However, a physical visit may be required under certain circumstances:

  • To accommodate a worker with a disability or specific medical requirement.
  • If the work activity introduces severe hazards, such as specialised machinery, tools, or chemicals.

Practical steps for remote risk discovery

To effectively assess your work-from-home team without entering their properties, utilise these direct strategies:

  • Distribute digital self-assessment questionnaires and home configuration checklists.
  • Schedule mandatory phone or video consultations to talk through setups individually.
  • Outline clear parameters regarding the type of work being performed and the duration of the tasks.

Note: If your risk assessment highlights a need for corrective action or specialised equipment, your workers cannot be financially charged for these.

What if a home is unsafe for remote work?

If an employer determines that a home is not a suitable work environment and reasonably practicable protective measures cannot be implemented, alternative arrangements must be mutually agreed upon. This includes providing dedicated workspace inside the office or arranging another safe, local work location.

Managing Employee Stress and Mental Health at Home

Remote working can place unique psychological demands on your staff. Deprived of day-to-day social contact, remote employees are highly vulnerable to isolation, which can trigger severe pressure or aggravate pre-existing mental health conditions.

Practical ways to combat remote isolation

Because it is harder to recognise behavioural symptoms of stress without face-to-face interaction, employers should integrate structured checkpoints:

  • Open Dialogue: Talk openly with employees about stress, and actively involve them in building your corporate stress risk assessments.
  • Frequent Contact: Build in regular keep-in-touch meetings via one-to-one phone check-ins and accessible team video calls.
  • Occupational Support: Frequently remind remote staff of available mental health resources, corporate counselling, or employee assistance programs.

Promoting a Healthy Work-Life Balance

Remote staff frequently work longer hours, leading to severe burnout. employers should regularly audit workloads and training needs to ensure timelines remain realistic. Actively encourage your remote workforce to take structured screen breaks, use their allocated annual leave, and log off completely without feeling an obligation to monitor emails outside of normal working hours.

Complying with DSE Regulations at Home

Employers must protect remote workers from the physical strains associated with laptops and desktop computers under the Display Screen Equipment (DSE) regulations.

Streamlining the DSE assessment

If the regulations apply to your staff, a dedicated DSE assessment must be executed for both their home setup and office workstation. Employees can complete these as self-assessments once they are given proper training.

Your primary objectives are to ensure:

  • Workers can easily achieve a comfortable, sustainable, and ergonomically sound posture.
  • All hardware, peripherals, and equipment provided are fully functional and safe.

Employees do not necessarily require specialised office-grade furniture if their personal setups are ergonomically sound. However, if an individual’s personal furniture is inadequate, the employer must bridge the gap. Risks must be reduced so far as “reasonably practicable”—meaning you must balance the level of real risk against the cost, time, and trouble of the control measures.

Ensuring a Safe Physical Working Environment

Employers must take reasonable steps to verify that the home working environment itself is physically safe.

Electrical equipment and cable safety

While you are only legally liable for the specific electrical assets your company provides, you must ensure they are operated safely. Instruct workers to perform routine visual checks on sockets, plugs, and leads for signs of damage. Additionally, provide explicit guidance on the fire hazards associated with overloaded extension cables.

Mitigating slips, trips, and falls

Provide your team with practical advice on how to keep their immediate workspace clear of hazards. Remote workspaces should remain clear of floor obstructions, un-mopped spillages, and trailing equipment wires.

Emergency procedures and lone working

Ensure your remote team knows precisely what to do during an emergency. Supply them with a protocol document outlining emergency contact numbers, and maintain an updated emergency contact registry for every remote employee in case they become uncontactable. For staff operating with zero direct supervision, review the specialised lone-working safety tools hosted directly by the HSE.

How to report a home-based accident under RIDDOR

Not every home accident is a workplace incident. An injury or illness is only reportable under the Reporting of Injuries, Diseases and Dangerous Occurrences Regulations (RIDDOR) if it directly stems from:

  1. The specific work activity being carried out.
  2. The specialised equipment provided by the employer to complete that work.

Detailed reference criteria to evaluate home injuries can be found via the official health and safety portals.


Need Help Implementing This?

If you require expert assistance executing compliant risk assessments, DSE audits, or updated remote worker policies for your business, please reach out to the Ashbrooke advisory team today.