What an Auditor Looks for in an ISO 45001 Compliant Legal Register

As an auditor with over 10 years experience, I am often asked what do I look for in a legal register? Your legal register is one of the first documents an ISO 45001 auditor will ask to see — and one of the easiest places to lose points if it isn’t maintained properly. Clause 6.1.3 requires organisations to identify and have access to the legal and other requirements relevant to their occupational health and safety management system, and to keep this information up to date. In practice, auditors treat the legal register as a litmus test for the whole management system: if it’s weak, they’ll assume other processes are too.

Here’s what auditors actually check, and how to make sure your register holds up.

1. Coverage: Is It Actually Complete?

Auditors will cross-reference your register against your organisation’s activities, sites, and hazards. They’re looking for gaps such as:

  • Legislation relevant to specific plant, equipment, or processes (e.g. LOLER for lifting equipment, PUWER for work equipment, DSEAR if flammable substances are present)
  • Jurisdiction-specific law where you operate across multiple regions — for example, differences between Great Britain, Northern Ireland, the Isle of Man, and the Republic of Ireland
  • Sector-specific regulations, not just generic Health and Safety law
  • Environmental legislation where it overlaps with Occupational Health and Safety risk (waste, emissions, COMAH)

A register that only lists headline Acts (Health and Safety at Work etc. Act 1974, Management of Health and Safety at Work Regulations 1999) without the supporting regulations underneath will be flagged immediately.

ISO 45001 Legal Register

ISO 45001 Legal Register: What auditors look for

2. Currency: Is It Kept Up to Date?

This is the single most common nonconformity auditors raise. They will ask:

  • What is your process for identifying new, amended, or revoked legislation?
  • How often is the register reviewed, and who owns that review?
  • Can you show evidence of the last update (version control, revision log, sign-off)?

Auditors are wary of registers that look identical year to year — it signals no active monitoring process exists. A dated revision history, or a subscription to a legislation-update service, is strong evidence here.

3. Evaluation of Compliance: Not Just a List

ISO 45001 doesn’t just require you to identify legal requirements — clause 9.1.2 requires you to evaluate compliance against them. Auditors will look for:

  • A clear compliance status against each legal requirement (compliant / partially compliant / non-compliant)
  • Evidence linking each requirement to how compliance is demonstrated (a policy, procedure, permit, inspection record, or training log)
  • A defined frequency for compliance evaluation, separate from the register review itself

A register with no compliance column, or one where every line simply says “compliant” with no supporting evidence, will draw scrutiny.

4. Traceability and Accessibility

Auditors will trace a sample of legal requirements through your system to check they’re not just sitting in a spreadsheet nobody uses. Typical questions:

  • Is this requirement referenced in a risk assessment, procedure, or work instruction?
  • Do relevant staff know this requirement applies to their role?
  • Is the register accessible to those who need it — not locked away with one person?

This is where many organisations fall down: the register exists, but there’s no visible link between it and day-to-day operational control.

5. Ownership and Process

Beyond the document itself, auditors assess the process behind it. Expect questions such as:

  • Who is responsible for monitoring legislative change?
  • What’s the escalation route when a new legal requirement is identified — how does it get actioned, and by when?
  • Is legal compliance a standing item in management review, per clause 9.3?

A register maintained by one person with no documented process, and no visibility at management review, suggests the requirement is being met on paper only.

6. Format Doesn’t Matter — Function Does

ISO 45001 doesn’t mandate a specific format for the legal register. Auditors don’t care whether it’s a spreadsheet, database, or software module — they care whether it functions as a live compliance tool. That said, a well-structured register typically includes:

AspectPurpose
Legislation title & referenceIdentification
JurisdictionApplicability
Summary of requirementInterpretation
Applicability to the organisationRelevance
Compliance statusEvaluation
Evidence/referenceTraceability
Date reviewed / next reviewCurrency
OwnerAccountability

Getting Audit-Ready

If you’re preparing for an ISO 45001 audit (or surveillance visit), the fastest way to strengthen your legal register is to:

  1. Run a gap analysis against your current activities and sites
  2. Add a compliance-status column if you don’t already have one
  3. Establish a documented, evidenced review cycle
  4. Make sure the register is referenced in risk assessments and management review minutes

A legal register that’s actively maintained, evidenced, and embedded in operational decisions is one of the strongest signals of a mature management system — and one of the quickest wins in an audit.

If you need a bespoke legal register or you would like your existing register reviewed, please contact one of our team.