If you are working towards ISO 45001 certification, or maintaining it, one of the most common sticking points during audits is the legal register. It sounds like a simple document — a list of laws that apply to your business — but auditors consistently find registers that are either incomplete, out of date, or too vague to demonstrate real compliance.
This article breaks down exactly what a compliant legal register needs to contain, why it matters, and how to keep it audit-ready.
What Is a Legal Register?
A legal register (sometimes called a “legal and other requirements register”) is a structured record of all the health and safety laws, regulations, codes of practice, and other obligations that apply to your organisation’s activities, products, and services.
Under ISO 45001, Clause 6.1.3 requires organisations to determine and have access to up-to-date legal requirements and other requirements relevant to their occupational health and safety management system (OH&S MS), and to keep this information current. The register is how you evidence that you have done this.
Why It Matters More Than It Looks
A legal register is not just a compliance checkbox. It is the foundation your OH&S management system is built on — it drives your risk assessments, your operational controls, your training needs, and your internal audit criteria. If the register is wrong or incomplete, everything built on top of it is at risk too.
Auditors will typically test the register in two directions:
- Top-down — picking an activity or hazard on site and checking the relevant legislation is listed.
- Bottom-up — picking an entry in the register and asking how it is being met in practice.
If either direction breaks down, it is usually flagged as a non-conformity.
Core Elements Every Entry Should Include
While the exact format can vary, a robust legal register entry should contain the following information for each requirement:
- Legislation or requirement title — the specific act, regulation, code of practice, standard, or other obligation (e.g. industry code, insurer requirement, client contractual clause).
- Reference number or citation — the official identifier so it can be traced back to source.
- Jurisdiction — which country, state, or region it applies to, especially important for multi-site organisations.
- Summary of the requirement — a plain-language description of what the law actually requires, avoiding a copy-paste of dense legal text. This is often where expert consultants can be beneficial in interpreting the law to your business operations.
- Applicability — why and how this requirement applies to your specific operations, sites, or activities. Generic entries (“Health and Safety at Work Act applies to all businesses”) are a common audit finding.
- Compliance status — a clear statement of whether you currently comply, partially comply, or are working towards compliance. This is particularly useful when first implementing ISO 45001.
- Evidence of compliance — links or references to the specific procedures, records, permits, certificates, or controls that demonstrate compliance.
- Responsible person or role — who owns the register and is accountable for maintaining compliance.
- Review date and frequency — when it was last checked and when it is next due for review.
- Source of update information — how you monitor for changes (e.g. legislation update service, trade body bulletin, government gazette, etc.).
- Date of last legislative change — useful for showing the register reflects the current version of the law, not an outdated one.
Beyond Statutory Law: “Other Requirements”
ISO 45001 explicitly extends beyond legislation to “other requirements.” These are easy to miss but often specifically probed by auditors. They may include:
- Industry codes of practice and guidance documents
- Client or contractual health and safety requirements
- Relevant insurance provider conditions
- Corporate group standards (for multi-site or multinational organisations)
- Voluntary agreements or membership scheme conditions
- Permits, licences, and consents tied to specific sites or activities
If your register only lists statutory legislation and ignores these, it will not fully meet the clause requirement.
How to Structure the Register
There is no single structure that every register must follow, and it is often determined by the type, size or nature of the organisation itself. Most organisations use a spreadsheet, text document or a dedicated compliance software tool. Common groupings include:
- General health and safety legislation
- Fire safety
- Environmental (where it overlaps with H&S, e.g. hazardous substances)
- Sector-specific legislation (construction, manufacturing, healthcare, etc.)
- Equipment and machinery
- Chemical and hazardous substances
- Transport and vehicles
- Welfare and employment law touching on H&S
Structuring it makes the register easier to cross-reference against your risk assessments and operational controls, procedures and much faster to navigate during an audit.
Keeping It Live: Review and Monitoring
A legal register is only useful if it stays current. ISO 45001 requires that this information be kept up to date, so your process needs to show:
- A defined review frequency (many organisations review quarterly, with a full review annually)
- A named responsible person for monitoring legislative changes, this can be a representative in the organisation but could also be an external consultant
- A method for capturing changes (legal update subscription services are common, as manually tracking government publications is unreliable)
- A record of how changes were assessed and, where relevant, actioned (updated risk assessments, new controls, revised training)
Common Mistakes to Avoid
- Treating it as a one-off exercise. Registers built once for certification and never revisited are one of the most frequent non-conformities.
- Copying generic templates without tailoring. A register that does not reflect your actual sites, activities, and hazards will not withstand scrutiny.
- No link to evidence. Listing a requirement without showing how it is actually met leaves a gap between the register and reality.
- Missing “other requirements.” Focusing only on statute law and ignoring client, insurer, or industry obligations.
- No ownership. Without a named responsible person, updates tend to fall through the cracks.
Final Thoughts
A well-built legal register does more than satisfy Clause 6.1.3 — it becomes a working tool that keeps your entire OH&S management system grounded in what the law and your other obligations actually require. Getting the structure right from the start, and building in a genuine review cycle, is what separates a register that passes audit from one that merely exists on paper.
If you would like support building or auditing your legal register as part of your ISO 45001 journey, get in touch with our team for a consultation.