Just as ISO 45001 places the legal register at the centre of an Occupational Health and Safety audit, ISO 14001 auditors treat the environmental legal register the same way. Clause 6.1.3 requires organisations to identify and have access to legal and other requirements related to their environmental aspects, and clause 9.1.2 requires ongoing evaluation of compliance against them. As an auditor with over 10 years experience, I am often asked what I look for when auditing a legal register. In this article I will explain what makes a compliant legal register. A weak legal register is often the first sign an auditor uses to question the rest of the environmental management system.
Here’s what they actually look for.
1. Coverage: Does It Match Your Environmental Aspects?
Auditors will cross-check your register against your aspects and impacts register, looking for gaps such as:
- Legislation tied to specific activities — waste production and disposal, trade effluent, emissions to air, water abstraction or discharge, storage of hazardous substances
- Permits and licences (environmental permits, waste carrier licences, discharge consents) and the conditions attached to them
- Jurisdiction-specific law where you operate across multiple regions — for example, differences between Great Britain, Northern Ireland, the Isle of Man, and the Republic of Ireland
- Producer responsibility obligations (packaging waste, WEEE, batteries) where relevant
If your register lists only headline legislation (Environmental Protection Act 1990, Environmental Permitting Regulations) without the specific conditions and secondary regulations that actually apply to your sites, auditors will flag it as incomplete.
2. Currency: Is It Actively Monitored?
This is the most common nonconformity raised against environmental legal registers. Auditors will ask:
- What process identifies new, amended, or revoked environmental legislation?
- How often is the register reviewed, and who is accountable for it?
- Can you evidence the last review — version history, revision log, sign-off dates?
A register that hasn’t changed in years, despite known regulatory activity in your sector, signals there’s no active horizon-scanning process. Subscribing to a legislation-update service or newsletter is strong, tangible evidence here.
Is your ISO 14001 legal register compliant?
3. Evaluation of Compliance: Beyond the List
ISO 14001 clause 9.1.2 requires evaluation of compliance, not just identification of requirements. Auditors will look for:
- A compliance status against each requirement (compliant / partially compliant / non-compliant)
- Evidence supporting that status — permit conditions met, monitoring data, waste transfer notes, inspection records
- A defined frequency for compliance evaluation, distinct from the general register review
Registers where every entry is simply marked “compliant” with no supporting evidence are a red flag, especially for permitted activities where conditions carry monitoring or reporting obligations.
4. Traceability Into Operational Control
Auditors will sample specific legal requirements and trace them through the system to confirm they’re operationally embedded, not just listed. Expect questions like:
- Is this requirement reflected in an operational control procedure, permit condition tracker, or monitoring schedule?
- Do the people responsible for the activity know the legal requirement applies to them?
- Is evidence of compliance readily retrievable — not just asserted?
A legal register that exists in isolation from operational procedures and permit management is a common weak point.
5. Ownership and Process
Auditors assess the process behind the register as much as the document itself:
- Who is responsible for monitoring legislative and permit changes?
- What’s the escalation route when a new requirement is identified, and how quickly is it actioned?
- Is legal compliance status reviewed at management review, per clause 9.3?
A register maintained informally by one person, with no visibility at management review, suggests the requirement is being satisfied on paper rather than in practice.
6. Format Doesn’t Matter — Function Does
ISO 14001 doesn’t specify a register format. Auditors care whether it functions as a live compliance tool, not what it’s built in. A well-structured register typically includes:
| Aspect | Purpose |
| Legislation/permit reference | Identification |
| Jurisdiction | Applicability |
| Summary of requirement | Interpretation |
| Related environmental aspect | Relevance |
| Compliance status | Evaluation |
| Evidence/reference | Traceability |
| Date reviewed / next review | Currency |
| Owner | Accountability |
Getting Audit-Ready
To strengthen your environmental legal register ahead of an ISO 14001 audit or surveillance visit:
- Cross-check the register against your current aspects and impacts assessment
- Add or refine a compliance-status column with linked evidence
- Establish and evidence a documented review cycle
- Ensure the register connects visibly to permit management, monitoring schedules, and management review minutes
An environmental legal register that’s actively maintained, evidenced, and embedded in operational decisions is one of the clearest signs of a mature EMS — and one of the fastest wins ahead of an audit.
If you need a bespoke legal register or you want your existing register reviewed, please contact one of our team.