Health & Safety Legal Register vs Compliance Audit: What is the Difference?

If you have been told you need a “legal register” and separately advised to commission a “compliance audit,” you could be forgiven for wondering whether these are two names for the same thing. They are not — and understanding the difference matters, because most organisations that fall foul of a health and safety enforcement notice have one of these two documents in place but not the other.

This article explains what each one actually does, how they work together, and which one your organisation needs first.

The short answer

A health and safety legal register identifies which legal requirements apply to your organisation. A compliance audit (or compliance evaluation) tells you whether you are actually meeting them.

One is a map. The other is a health check against that map. You need both, but they answer different questions, and confusing them is one of the most common gaps we find when we review a client’s health and safety management system.

Health and safety consultant reviewing legal register documentation

What is a legal register?

A legal register is a structured record of the health and safety legislation, regulations, approved codes of practice, and other legal requirements that apply to your organisation’s specific activities, sites, and operations.

A good legal register will typically:

  • List each applicable piece of legislation (for example, the Management of Health and Safety at Work Regulations, COSHH, the Work at Height Regulations, or sector-specific rules)
  • Summarise what that legislation requires of your organisation
  • Identify which parts of your business or which activities the requirement applies to
  • Identify the controls in place to meet the legal requirements
  • Be reviewed and updated as legislation changes or your operations evolve

Crucially, a legal register is a document of applicability. It answers the question: “What law applies to us, and what does it say we must do?” It does not, by itself, tell you whether you are doing it.

What is a compliance audit or evaluation?

A compliance audit takes the requirements identified in the legal register (or an equivalent framework) and tests them against reality. It asks: “Are we actually meeting this requirement, in practice, today?”

A compliance audit typically involves:

  • Site visits and observation of actual working practices
  • Review of documentation, records, and evidence (permits, training records, inspection logs, risk assessments)
  • Interviews with staff, supervisors, and duty holders
  • Gap analysis against each legal requirement
  • A findings report ranking non-conformities by risk and urgency
  • Recommendations and an action plan to close the gaps

Where the legal register is a snapshot of obligations, the compliance audit is a live assessment of performance. It is the difference between having a checklist and actually checking the boxes — and finding out, in evidence-based detail, which ones you cannot honestly tick yet.

Legal Register

  • Records applicable legislation for the organisation

  • Sets the bench mark for compliance

  • Must be regularly reviewed & updated

  • Identifies controls in place

  • Bespoke to the organisation

  • Can be one jurisdiction or more

Compliance Audit

  • Identifies if you actually meet the legal requirements

  • Assesses at a specific point in time

  • Site visits, observations & staff interviews

  • Review of documentation, records, etc.

  • Gap analysis

  • Recommendations & action plan

Why the difference matters

We regularly see organisations that have invested in one of these tools and assumed it covers the other. Both mistakes carry real risk.

Legal register without an audit: You know what the law requires, but nobody has verified whether it’s happening on the ground. This is common where a legal register was purchased as a subscription product or generated once and filed away. It creates a false sense of security — the document exists, so the box feels ticked, but there is no evidence of actual conformance if an inspector, insurer, or regulator asks for it.

Audit without a legal register: You get a snapshot of current practice, but without a clear, maintained baseline of what should apply, the audit scope is often built from generic checklists or the auditor’s working knowledge rather than your organisation’s specific legal exposure. Gaps in obligations you did not know applied to you can be missed entirely.

Used together, the legal register defines the scope of what to check, and the audit provides the evidence of whether you are meeting it. This combination is also what regulators, insurers, and courts expect to see when assessing whether an organisation exercised due diligence — a legal register with no corroborating evidence of compliance checking is a weak defence in an enforcement case or civil claim.

How they fit into a health and safety management system

Think of it as a three-stage cycle:

  1. Identify — the legal register captures every applicable requirement
  2. Evaluate — the compliance audit tests current practice against each requirement
  3. Act — a corrective action plan closes the gaps the audit identifies, and the cycle repeats on a review schedule

This mirrors the “Plan-Do-Check-Act” approach that underpins recognised health and safety management standards such as ISO 45001 and HSG65. A legal register alone only covers “Plan.” Without the “Check” stage — the audit — you have no mechanism to confirm the plan is working.

Which do you need first?

If your organisation does not currently have a legal register, that is the logical starting point — you cannot meaningfully audit compliance against requirements you have not formally identified.

If you already have a legal register but it has not been tested against actual site practice in the last 12 months, a compliance audit should be your next step. An out-of-date or unverified register can quietly become a liability rather than an asset.

Get a clear picture of your legal exposure and compliance status

Many organisations discover during an audit that gaps have existed for months or years without anyone noticing — often because the legal register and the audit process were never properly connected.

If you are not sure whether your current legal register is complete, whether your last audit was thorough enough, or where to start with either, we can help. We carry out legal register development, gap analysis, and full compliance audits tailored to your sector and operations, with a clear, prioritised action plan at the end of it — not just a list of problems. We have experience in a variety of sectors to meet your needs.

Get in touch to arrange a no-obligation discussion about your current legal register or compliance status, and we will tell you honestly where your priorities should be.