Does the Environmental Permitting Regulations apply to my business?

If your business handles waste, discharges to water or air, runs industrial plant, or stores certain materials, the answer may well be yes. The Environmental Permitting (England and Wales) Regulations 2016 (EPR) are among the most widely applicable environmental laws in the UK, and many businesses are caught by them without realising it. Operating a regulated activity without the right permit or exemption is a criminal offence, so it’s worth checking before the regulator asks.

What are the Environmental Permitting Regulations?

The environmental permitting regulations bring several previously separate regimes under a single permitting system. Rather than applying for different licences for waste, industrial emissions and water pollution, operators deal with one framework, overseen by the Environment Agency (EA) in England, Natural Resources Wales (NRW) in Wales, or the local authority for certain lower-risk activities.

The core rule is simple: if you carry out a “regulated facility” activity, you need an environmental permit, or you must qualify for an exemption or exclusion.

Do the Environmental Permitting Regulations Apply to You?

Does your business require an environmental permit?

Which activities are regulated?

The regulations cover a broad range of activities. The main categories are:

  • Installations: industrial processes with the potential to pollute air, water or land, such as chemical manufacture, metal processing, intensive farming, food and drink production above certain thresholds, and waste incineration.
  • Waste operations: treating, storing, recovering or disposing of waste, including scrap metal yards, skip hire, vehicle dismantlers, waste transfer stations and composting sites.
  • Mobile plant: equipment used to treat or recover waste on different sites, such as mobile crushers.
  • Water discharge activities: releasing trade effluent or other liquids to surface water, sewers in some circumstances, or groundwater.
  • Groundwater activities: discharges or activities that could pollute groundwater.
  • Medium combustion plants and specified generators: boilers, engines and generators within certain thermal-input ranges, including standby generators used for grid services.
  • Solvent emission activities: processes using organic solvents above set thresholds, such as printing, coating and dry cleaning.
  • Radioactive substances activities: keeping or using radioactive materials, or disposing of radioactive waste.
  • Mining waste operations: managing waste from mineral extraction.

Do I need a permit, an exemption, or nothing at all?

Being in a regulated sector doesn’t automatically mean a full permit. There are usually three outcomes.

1. A bespoke permit. Higher-risk or complex sites typically need a tailored permit with site-specific conditions, monitoring and reporting requirements.

2. A standard rules permit. For lower-risk, well-understood activities, the regulator publishes fixed sets of conditions. These are quicker and cheaper to obtain, but you must be able to meet every rule.

3. An exemption or exclusion. Some low-risk activities, such as certain types of waste storage, reuse or recovery, don’t need a permit but may need to be registered, and must stay within strict limits on waste type, quantity and how it’s handled. Exceeding those limits can take you out of the exemption and into unpermitted operation.

A common mistake is assuming an exemption applies without checking the conditions. Quantity limits, storage time limits and waste codes all matter.

Common situations where businesses get caught out

  • A manufacturer storing or treating waste on site beyond exemption limits
  • A builder or groundworks firm processing or crushing waste soil or rubble
  • A site with a large boiler or generator that reaches medium combustion plant thresholds
  • A business discharging site drainage or process water to a watercourse or soakaway
  • A company taking over a site and assuming the previous permit transfers automatically
  • Businesses that only use a waste carrier and assume permitting isn’t their concern, without checking the duty of care and whether the receiving site is permitted

What if I’m not in England or Wales?

Environmental permitting is devolved, so the rules differ:

If you operate across more than one jurisdiction, you can’t assume one approach fits every site.

What are the consequences of getting it wrong?

Operating a regulated facility without a permit, or breaching permit conditions, is a criminal offence. Penalties can include an unlimited fine and, in serious cases, imprisonment. The regulator can also issue enforcement or suspension notices, require remediation, and pursue cost recovery. Beyond the legal risk, non-compliance can affect insurance, contracts, funding and your reputation with customers who ask about environmental credentials.

How to check whether the EPR apply to you

  1. List your activities. Include not just your main process, but storage, treatment of waste, drainage, heating and power plant.
  2. Check the thresholds. Many activities only become regulated above a certain quantity, capacity or thermal input.
  3. Identify your waste streams. Know what you produce, how much, how long it’s kept, and where it goes.
  4. Check for existing permits or exemptions. Confirm they are current, cover what you actually do, and that you’re meeting every condition.
  5. Get an independent view. A competent adviser can spot gaps you may not see from the inside.

How we can help

Working out whether the EPR apply is rarely as simple as ticking a box. Our team can review your operations, identify regulated activities, advise on whether you need a permit or qualify for an exemption, and support you through applications and ongoing compliance. Get in touch for an initial conversation about your site.

This article is general guidance and not legal advice. Requirements depend on your activities, location and circumstances.

What an Auditor Looks for in an ISO 14001 Compliant Legal Register

Just as ISO 45001 places the legal register at the centre of an Occupational Health and Safety audit, ISO 14001 auditors treat the environmental legal register the same way. Clause 6.1.3 requires organisations to identify and have access to legal and other requirements related to their environmental aspects, and clause 9.1.2 requires ongoing evaluation of compliance against them. As an auditor with over 10 years experience, I am often asked what I look for when auditing a legal register. In this article I will explain what makes a compliant legal register. A weak legal register is often the first sign an auditor uses to question the rest of the environmental management system.

Here’s what they actually look for.

1. Coverage: Does It Match Your Environmental Aspects?

Auditors will cross-check your register against your aspects and impacts register, looking for gaps such as:

  • Legislation tied to specific activities โ€” waste production and disposal, trade effluent, emissions to air, water abstraction or discharge, storage of hazardous substances
  • Permits and licences (environmental permits, waste carrier licences, discharge consents) and the conditions attached to them
  • Jurisdiction-specific law where you operate across multiple regions โ€” for example, differences between Great Britain, Northern Ireland, the Isle of Man, and the Republic of Ireland
  • Producer responsibility obligations (packaging waste, WEEE, batteries) where relevant

If your register lists only headline legislation (Environmental Protection Act 1990, Environmental Permitting Regulations) without the specific conditions and secondary regulations that actually apply to your sites, auditors will flag it as incomplete.

2. Currency: Is It Actively Monitored?

This is the most common nonconformity raised against environmental legal registers. Auditors will ask:

  • What process identifies new, amended, or revoked environmental legislation?
  • How often is the register reviewed, and who is accountable for it?
  • Can you evidence the last review โ€” version history, revision log, sign-off dates?

A register that hasn’t changed in years, despite known regulatory activity in your sector, signals there’s no active horizon-scanning process. Subscribing to a legislation-update service or newsletter is strong, tangible evidence here.

ISO 14001 Legal Register: What Auditors Look For

Is your ISO 14001 legal register compliant?

3. Evaluation of Compliance: Beyond the List

ISO 14001 clause 9.1.2 requires evaluation of compliance, not just identification of requirements. Auditors will look for:

  • A compliance status against each requirement (compliant / partially compliant / non-compliant)
  • Evidence supporting that status โ€” permit conditions met, monitoring data, waste transfer notes, inspection records
  • A defined frequency for compliance evaluation, distinct from the general register review

Registers where every entry is simply marked “compliant” with no supporting evidence are a red flag, especially for permitted activities where conditions carry monitoring or reporting obligations.

4. Traceability Into Operational Control

Auditors will sample specific legal requirements and trace them through the system to confirm they’re operationally embedded, not just listed. Expect questions like:

  • Is this requirement reflected in an operational control procedure, permit condition tracker, or monitoring schedule?
  • Do the people responsible for the activity know the legal requirement applies to them?
  • Is evidence of compliance readily retrievable โ€” not just asserted?

A legal register that exists in isolation from operational procedures and permit management is a common weak point.

5. Ownership and Process

Auditors assess the process behind the register as much as the document itself:

  • Who is responsible for monitoring legislative and permit changes?
  • What’s the escalation route when a new requirement is identified, and how quickly is it actioned?
  • Is legal compliance status reviewed at management review, per clause 9.3?

A register maintained informally by one person, with no visibility at management review, suggests the requirement is being satisfied on paper rather than in practice.

6. Format Doesn’t Matter โ€” Function Does

ISO 14001 doesn’t specify a register format. Auditors care whether it functions as a live compliance tool, not what it’s built in. A well-structured register typically includes:

AspectPurpose
Legislation/permit referenceIdentification
JurisdictionApplicability
Summary of requirementInterpretation
Related environmental aspectRelevance
Compliance statusEvaluation
Evidence/referenceTraceability
Date reviewed / next reviewCurrency
OwnerAccountability

Getting Audit-Ready

To strengthen your environmental legal register ahead of an ISO 14001 audit or surveillance visit:

  1. Cross-check the register against your current aspects and impacts assessment
  2. Add or refine a compliance-status column with linked evidence
  3. Establish and evidence a documented review cycle
  4. Ensure the register connects visibly to permit management, monitoring schedules, and management review minutes

An environmental legal register that’s actively maintained, evidenced, and embedded in operational decisions is one of the clearest signs of a mature EMS โ€” and one of the fastest wins ahead of an audit.

If you need a bespoke legal register or you want your existing register reviewed, please contact one of our team.

What an Auditor Looks for in an ISO 45001 Compliant Legal Register

As an auditor with over 10 years experience, I am often asked what do I look for in a legal register? Your legal register is one of the first documents an ISO 45001 auditor will ask to see โ€” and one of the easiest places to lose points if it isn’t maintained properly. Clause 6.1.3 requires organisations to identify and have access to the legal and other requirements relevant to their occupational health and safety management system, and to keep this information up to date. In practice, auditors treat the legal register as a litmus test for the whole management system: if it’s weak, they’ll assume other processes are too.

Here’s what auditors actually check, and how to make sure your register holds up.

1. Coverage: Is It Actually Complete?

Auditors will cross-reference your register against your organisation’s activities, sites, and hazards. They’re looking for gaps such as:

  • Legislation relevant to specific plant, equipment, or processes (e.g. LOLER for lifting equipment, PUWER for work equipment, DSEAR if flammable substances are present)
  • Jurisdiction-specific law where you operate across multiple regions โ€” for example, differences between Great Britain, Northern Ireland, the Isle of Man, and the Republic of Ireland
  • Sector-specific regulations, not just generic Health and Safety law
  • Environmental legislation where it overlaps with Occupational Health and Safety risk (waste, emissions, COMAH)

A register that only lists headline Acts (Health and Safety at Work etc. Act 1974, Management of Health and Safety at Work Regulations 1999) without the supporting regulations underneath will be flagged immediately.

ISO 45001 Legal Register

ISO 45001 Legal Register: What auditors look for

2. Currency: Is It Kept Up to Date?

This is the single most common nonconformity auditors raise. They will ask:

  • What is your process for identifying new, amended, or revoked legislation?
  • How often is the register reviewed, and who owns that review?
  • Can you show evidence of the last update (version control, revision log, sign-off)?

Auditors are wary of registers that look identical year to year โ€” it signals no active monitoring process exists. A dated revision history, or a subscription to a legislation-update service, is strong evidence here.

3. Evaluation of Compliance: Not Just a List

ISO 45001 doesn’t just require you to identify legal requirements โ€” clause 9.1.2 requires you to evaluate compliance against them. Auditors will look for:

  • A clear compliance status against each legal requirement (compliant / partially compliant / non-compliant)
  • Evidence linking each requirement to how compliance is demonstrated (a policy, procedure, permit, inspection record, or training log)
  • A defined frequency for compliance evaluation, separate from the register review itself

A register with no compliance column, or one where every line simply says “compliant” with no supporting evidence, will draw scrutiny.

4. Traceability and Accessibility

Auditors will trace a sample of legal requirements through your system to check they’re not just sitting in a spreadsheet nobody uses. Typical questions:

  • Is this requirement referenced in a risk assessment, procedure, or work instruction?
  • Do relevant staff know this requirement applies to their role?
  • Is the register accessible to those who need it โ€” not locked away with one person?

This is where many organisations fall down: the register exists, but there’s no visible link between it and day-to-day operational control.

5. Ownership and Process

Beyond the document itself, auditors assess the process behind it. Expect questions such as:

  • Who is responsible for monitoring legislative change?
  • What’s the escalation route when a new legal requirement is identified โ€” how does it get actioned, and by when?
  • Is legal compliance a standing item in management review, per clause 9.3?

A register maintained by one person with no documented process, and no visibility at management review, suggests the requirement is being met on paper only.

6. Format Doesn’t Matter โ€” Function Does

ISO 45001 doesn’t mandate a specific format for the legal register. Auditors don’t care whether it’s a spreadsheet, database, or software module โ€” they care whether it functions as a live compliance tool. That said, a well-structured register typically includes:

AspectPurpose
Legislation title & referenceIdentification
JurisdictionApplicability
Summary of requirementInterpretation
Applicability to the organisationRelevance
Compliance statusEvaluation
Evidence/referenceTraceability
Date reviewed / next reviewCurrency
OwnerAccountability

Getting Audit-Ready

If you’re preparing for an ISO 45001 audit (or surveillance visit), the fastest way to strengthen your legal register is to:

  1. Run a gap analysis against your current activities and sites
  2. Add a compliance-status column if you don’t already have one
  3. Establish a documented, evidenced review cycle
  4. Make sure the register is referenced in risk assessments and management review minutes

A legal register that’s actively maintained, evidenced, and embedded in operational decisions is one of the strongest signals of a mature management system โ€” and one of the quickest wins in an audit.

If you need a bespoke legal register or you would like your existing register reviewed, please contact one of our team.

What UK Waste Laws Apply to Small Businesses?

If you run a small business in the UK, you might assume that waste regulations are something only large industrial operators need to worry about. That assumption is both common and costly. Recent enforcement data suggests that 90% of organisations currently breaking waste law are SMEs with 0 to 50 employees. Whether you are a sole trader, a home-based business, or a limited company with a handful of staff, the legal duty of care for waste applies to you from the moment your business produces its first bag of rubbish.

This article breaks down the core UK waste laws that apply to small businesses, explains what has changed recently, and outlines the practical steps you need to take to stay compliant.

The Foundation: Duty of Care Under the Environmental Protection Act 1990

The cornerstone of UK waste law is Section 34 of the Environmental Protection Act 1990, which imposes a legal “duty of care” on anyone who produces, imports, keeps, stores, transports, treats, or disposes of controlled waste. This duty is not limited to large corporations. It extends explicitly to landlords, home-based businesses, sole traders, and small and medium-sized enterprises.

In practical terms, the duty of care requires you to take all reasonable steps to ensure your waste is stored safely and securely and is only transferred to an authorised person or business. You must not dump trade waste at household recycling centres or in domestic bins. You must use a licensed waste carrier, and you must complete and retain a Waste Transfer Note (WTN) for every transfer of non-hazardous waste. These records must be kept for a minimum of two years and can be inspected by council or Environment Agency officers at any time.

Failure to comply is not a minor administrative matter. Councils across the UK are actively issuing Fixed Penalty Notices and Section 34 enforcement notices. In one recent four-month campaign in Northamptonshire, 55 formal warning notices and 16 Fixed Penalty Notices were issued for offences including duty of care breaches.

Simpler Recycling: New Separation Requirements

From 31 March 2025, new rules under the Separation of Waste (England) Regulations 2025 require businesses in England to separate recyclable materials into distinct waste streams. The core materials that must be segregated are paper and card, metal, plastic, and glass. Food waste must also be collected separately.

There is some flexibility built into the system. Metal, glass, and plastic may be collected together in a combined stream if your waste contractor offers that option, and food waste can be collected alongside garden waste.

Crucially, micro-firms with fewer than 10 full-time equivalent employees are temporarily exempt from these separation requirements until 31 March 2027. If your business has 10 or more employees, however, you should already be compliant. The Environment Agency has also introduced a cost-recovery charging scheme of ยฃ118 per hour for regulatory work connected to non-compliance, meaning that an inspection finding you in breach could result in a direct bill for the time the regulator spends investigating you.

Hazardous Waste: Stricter Rules, Even for Tiny Quantities

If your business produces any hazardous waste, the regulatory burden increases significantly. Hazardous waste includes items such as waste chemicals, fluorescent light tubes, used solvents, asbestos, waste oils, batteries, and certain electrical equipment.

Even a couple of batteries or a single tube of adhesive falls within the scope of strict legal requirements. You must keep hazardous waste separate from non-hazardous waste and must not mix different types of hazardous waste together. You must complete a hazardous waste consignment note when the waste is removed from your premises, and you must keep consignment notes for three years.

If your business produces, holds, or removes 500kg or more of hazardous waste in any 12-month period, you must register your premises with the Environment Agency (or the relevant devolved regulator). Some premises are exempt if they produce less than 200kg in a year. Fines for producing or holding hazardous waste from unregistered premises can reach ยฃ5,000.

Packaging Waste: The Extended Producer Responsibility Regime

The Producer Responsibility Obligations (Packaging and Packaging Waste) Regulations 2024โ€”commonly referred to as pEPRโ€”came into force on 1 January 2026 and have significantly widened the scope of packaging waste obligations.

Under the previous regime, only businesses with a turnover above ยฃ2 million that handled more than 50 tonnes of packaging were caught. Under pEPR, the threshold has dropped. Small businesses with an annual turnover of over ยฃ1 million that imported or supplied over 25 tonnes of packaging in the last calendar year are now classified as “small producers” and must register with the relevant regulator and submit annual data on their packaging volumes.

Businesses with a turnover below ยฃ1 million and packaging tonnage below 25 tonnes are exempt from data collection and reporting obligations. Those with a turnover between ยฃ1 million and ยฃ2 million and packaging tonnage between 25 and 50 tonnes must register and report, but they are currently exempt from paying waste disposal fees and buying Packaging Recovery Notes (PRNs).

If your business sells packaged goods online, distributes empty packaging, or imports packaged products, you should check whether you meet the “producer” definition under pEPR.

Digital Waste Tracking: What Is Changing

The UK is moving away from paper-based duty of care records towards a mandatory Digital Waste Tracking (DWT) service. The mandatory roll out was originally scheduled for April 2027 but has been delayed by six months to October 2027 to give operators, particularly SMEs, more time to prepare.

Phase One of the service, which applies to waste received at permitted facilities, began in October 2026. Phase Two will extend the system to waste carriers, brokers, and dealers who arrange or transport waste movements. In the interim, you must continue to maintain robust paper or digital duty of care records. These remain legally required until DWT becomes mandatory.

Devolved Differences: Scotland, Wales, and Northern Ireland

Waste policy is devolved, which means the rules vary depending on where your business operates.

Scotland: The Waste (Scotland) Regulations 2012 require all businesses to separate glass, metal, plastics, paper, and cardboard for recycling. Food businesses producing more than 5kg of food waste per week must present it for separate collection, and disposing of food waste into the sewer via a macerator is illegal in most areas.

Wales: Since 6 April 2024, all workplaces in Wales have been required to separate paper and card, glass, metal, plastic, cartons, food waste (where 5kg or more is produced per week), small waste electrical and electronic equipment (sWEEE), and unsold textiles for collection. The Welsh regulations apply regardless of business size, with no micro-firm exemption.

Northern Ireland: Businesses in Northern Ireland are subject to the duty of care under the Environmental Protection Act 1990 and must use registered waste carriers. Digital Waste Tracking will also apply across Northern Ireland as part of the UK-wide roll out.

Practical Steps for Compliance

If you run a small business, the following checklist will help you stay on the right side of the law:

1. Confirm you have a licensed waste carrier. Ask to see their waste carrier registration number and verify it with the Environment Agency or SEPA.

2. Retain Waste Transfer Notes. Keep them for at least two years for non-hazardous waste and three years for hazardous waste consignment notes.

3. Separate your recyclables. If you have 10 or more employees, you must already be segregating paper, card, metal, plastic, glass, and food waste.

4. Check your packaging obligations. If your turnover exceeds ยฃ1 million and you handle more than 25 tonnes of packaging annually, register as a small producer under pEPR.

5. Store waste securely. Prevent waste from escaping, causing litter, or attracting pests.

6. Never use household waste services for business waste. This is a common breach that councils are actively enforcing.

7. Compile a register of legal obligations for your business so you know what you have to do.

How a Consultancy Can Help

Waste compliance is not static. The regulatory landscape is shifting rapidly, with Simpler Recycling, pEPR, and Digital Waste Tracking all phasing in over the coming years. For small businesses without a dedicated compliance team, keeping track of these changes can feel overwhelming.

A specialist consultancy can help you audit your current waste arrangements, identify gaps in your duty of care documentation, advise on separation requirements, and prepare your business for the transition to digital tracking. The cost of getting it wrongโ€”whether through Fixed Penalty Notices, Environment Agency cost-recovery charges, or reputational damageโ€”far outweighs the cost of getting it right.

The Difference Between Generic and Bespoke Legal Registers

Why a one-size-fits-all approach to legal compliance leaves organisations exposed โ€” and what a register built around your actual operations gives you instead.

If your organisation is subject to health, safety, or environmental law โ€” and almost every organisation is โ€” you need a legal register. It’s the document that tells you which legislation applies to your operations, what it requires of you, and whether you’re actually compliant. But not all legal registers are built the same way, and the difference between a generic template and a bespoke register isn’t cosmetic. It’s the difference between a document that looks like due diligence and one that actually protects your organisation.

What Is a Legal Register?

A legal register is a structured record of the laws, regulations, and codes of practice that apply to an organisation, typically covering health and safety, environmental, and related compliance obligations. It’s a cornerstone requirement of recognised management system standards, including ISO 9001, ISO 45001 and ISO 14001, and it’s usually the first document an auditor or regulator asks to see. On paper, every legal register looks similar: a list of legislation, a summary of requirements, a compliance status. In practice, how that list is built determines whether the register is a genuinely useful management tool or a box-ticking exercise.

The Trouble With Generic Legal Registers

Generic legal registers are typically off-the-shelf templates or subscription database exports, built to cover an entire sector or industry in one document. They’re inexpensive, quick to obtain, and easy to see the appeal of โ€” but that convenience comes at a real cost:

  • They list legislation that may have nothing to do with your actual activities, sites, or risk profile, burying the requirements that genuinely matter under dozens that don’t.
  • They rarely reflect the specific jurisdictions, licences, or permits your organisation holds, particularly for organisations operating across Great Britain, Northern Ireland, the Isle of Man, or the Republic of Ireland, where legal frameworks diverge significantly.
  • They’re built for updating on a fixed schedule rather than in response to your organisation’s changes โ€” a new site, a new process, a new piece of equipment โ€” so they drift out of date the moment your operations move.
  • They describe legal duties in abstract terms, without translating them into what compliance actually looks like for your sites, your equipment, and your people.
  • They offer no meaningful gap analysis โ€” you’re left to work out for yourself whether you actually comply with each requirement.

The result is a register that satisfies the letter of the audit requirement โ€” “yes, we have a legal register” โ€” without doing the job a legal register exists to do: giving your organisation a clear, current, accurate picture of its legal exposure.

Bespoke vs generic legal register, which is best?
Photo courtesy of Pixabay tumisu-audit

A bespoke legal register demonstrates to auditors that you actually know your legal obligations.

Why a Bespoke Legal Register Is the Only Register Worth Having

A bespoke legal register is built from the ground up around your organisation: your sites, your activities, your industry sector, your jurisdictions, and your risk profile. Rather than starting from a generic list and hoping it fits, it starts from your operations and identifies exactly which legislation applies โ€” and, critically, what that legislation actually requires you to do about it. The advantages compound quickly:

  • Relevance: every entry has a direct line to something your organisation actually does, so nothing important gets lost in noise that doesn’t apply to you.
  • Accuracy across jurisdictions: legislation is mapped to the specific jurisdiction โ€” GB, NI, Isle of Man, or ROI โ€” that each site operates under, rather than treated as a single homogeneous “UK law” list.
  • A genuine compliance status: each requirement is assessed against evidence from your organisation, so you know โ€” not guess โ€” where you stand, and where the gaps are.
  • Built-in gap analysis and action planning: a bespoke register doesn’t just flag non-compliance, it gives you a prioritised route to closing it.
  • Living, current content: as legislation changes or your organisation changes โ€” a new site, a new process, an amended regulation โ€” the register is updated to reflect it, so it never becomes a snapshot of a moment that’s already passed.
  • Audit and due diligence confidence: a bespoke register demonstrates, to auditors, regulators, insurers, and clients, that your organisation understands and manages its legal obligations โ€” not that it purchased a document that says it does.

In short: a generic register tells you what the law says. A bespoke register tells you what the law means for you โ€” and whether you’re meeting it.

FEATURES

Generic Legal Register

Bespoke Legal Register


Identifies only relevant laws


Focused on the actual business


Relevant and easy to understand


A practical management tool


Includes sector specific requirements


Demonstrates that you understand your obligations

The Bottom Line

A legal register is only as valuable as its accuracy and relevance to your organisation. A generic template can create a false sense of security โ€” the appearance of compliance without the substance of it โ€” and that gap tends to surface at the worst possible moment: during an incident investigation, a regulatory visit, or a client’s due diligence review. A bespoke legal register, developed and maintained by health and safety professionals who understand your sector and your sites, is an investment in genuine legal certainty, not just a document for the audit file.

If your organisation is currently relying on a generic register โ€” or doesn’t have one at all โ€” talk to us about building a bespoke legal register tailored to your operations, sites, and jurisdictions. It’s the foundation every other part of your compliance management sits on, and it’s worth getting right.

Do Small Businesses Need an Environmental Legal Register?

A clear look at environmental obligations, business size, and why proportionate compliance matters.

It is a question we hear often from small business owners: โ€œDo I really need an environmental legal register? Surely that’s something only for large industrial companies with dedicated environmental teams.โ€ It’s an understandable assumption, but it is not correct. Environmental legal obligations are not switched on by company size โ€” they are triggered by what a business actually does, what it produces, discharges, or stores, and where it operates. A small print shop and a large logistics depot may face entirely different environmental duties, regardless of which one employs more people.

In this article, we look at why the size of a business is the wrong starting point for thinking about environmental compliance, and why a well-designed environmental legal register โ€” far from being a burden reserved for large organisations โ€” can be one of the most practical and cost-effective tools a small business ever puts in place.

What Is an Environmental Legal Register?

An environmental legal register is a structured record of the environmental legislation, regulations, permits, and approved codes of practice that apply to a specific organisation. Rather than listing every environmental law in existence, it identifies the ones that are actually relevant to that business’s operations, sites, and activities, and sets out what needs to be done to remain compliant with each one.

Done properly, an environmental legal register becomes a single point of reference that tells a business owner or manager, at a glance: which environmental laws apply to us, what each one requires, how we currently meet that requirement, and where any gaps exist.

Environmental Obligations Depend on Circumstances, Not Company Size

This is the point worth dwelling on, because it is the one most often misunderstood. UK environmental legislation is largely activity-based and impact-based rather than headcount-based. Duties under legislation such as the Environmental Protection Act 1990, the Environmental Permitting (England and Wales) Regulations, and waste, water, and packaging regulations apply to any business whose activities create the relevant impact โ€” regardless of size. The specific duties that follow are shaped by factors such as:

  • The nature of the business’s processes (for example, use of chemicals, fuel storage, vehicle fleets, or manufacturing by-products)
  • The waste the business produces and how it’s stored, transported, and disposed of
  • Whether emissions to air, land, or water are involved, even at a small scale
  • Sector-specific rules that apply regardless of business size, such as packaging producer responsibility, WEEE, or discharge consents

A single-van courier business has duties around fuel storage and vehicle emissions. A small print shop has duties under waste and hazardous substances regulations for inks and solvents. A two-person mobile car valeting business has duties around wastewater discharge. None of these obligations disappear because the business is small โ€” in some cases, a smaller business with fewer resources to manage environmental risk may need to pay closer attention, not less.

In other words, the question is never really โ€œis my business big enough for this to matter?โ€ The question is โ€œwhat do we actually do, and what does environmental law say about doing it responsibly?โ€ An environmental legal register is simply the tool that answers that question clearly and keeps the answer up to date as legislation changes.

environmental legal register for small business.

An environmental legal register for small business should be proportionate.

Why Small Businesses Benefit from a Concise, Proportionate Register

Recognising that environmental duties apply regardless of size is only half the picture. The other half is that how a small business meets those duties can, and should, look very different from how a large organisation meets them. A 200-page environmental legal register modelled on a multinational’s compliance framework is not only unnecessary for a small business โ€” it’s actively counterproductive. It gets opened once, filed away, and forgotten.

A register that is built specifically for a small business, scaled to its real activities and environmental impacts, tends to work far better in practice. This is why:

1. It Stays Usable

A concise register lists only the environmental legislation that genuinely applies to that business’s operations. Instead of an overwhelming, generic checklist, the owner or manager is left with a short, relevant list they can actually refer to โ€” and act on โ€” day to day.

2. It Reflects the Business as It Really Operates

A bespoke register is built around the specific sites, processes, substances, and waste streams involved, rather than a one-size-fits-all industry template. This means it captures the obligations that matter and doesn’t waste time on ones that don’t.

3. It Makes Gaps Visible

Because it is proportionate rather than padded out, a well-built register makes it far easier to spot where compliance is solid and where attention is needed โ€” an expired waste carrier’s licence, a missing duty of care record, a permit due for renewal โ€” without those gaps being buried in irrelevant detail.

4. It Demonstrates Due Diligence

In the event of an environmental incident, a regulator visit, or a client, landlord, or insurer asking about environmental compliance arrangements, a maintained legal register is tangible evidence that the business has identified its obligations and is actively managing them. For a small business without a dedicated environmental function, this matters a great deal.

5. It Supports Growth Without Starting from Scratch

As a small business takes on new processes, new premises, or new materials, an environmental legal register built with the right structure can be updated and expanded rather than rebuilt. This means compliance grows alongside the business instead of becoming a sudden, overwhelming project further down the line.

Building a Register That Fits Your Business

The most effective environmental legal registers for small businesses share a few common features: they are reviewed and updated regularly to reflect legislative change, they are written in plain language rather than legal jargon, they link each legal requirement to a clear action or evidence of compliance, and they are proportionate โ€” covering what applies, in appropriate detail, without unnecessary bulk.

This is where working with a health and safety and environmental consultancy adds real value. Rather than adapting a generic template, a consultancy can assess your specific activities and premises, identify the environmental legislation that genuinely applies, and build a register that is both legally sound and genuinely usable by your team.

The Bottom Line

Environmental law does not ask how many people are on your payroll before it applies to you โ€” it asks what impact your work creates. That means every business, regardless of size, has environmental obligations worth identifying and managing properly. For small businesses, the smart response is not to ignore this reality, nor to adopt a compliance framework built for a much larger organisation. It is to build an environmental legal register that is concise, proportionate, and tailored to how the business actually operates โ€” one that gets used, kept current, and genuinely supports safer, more compliant, more sustainable day-to-day operations.

If you are unsure which environmental requirements apply to your business, or you would like help building a legal register that is proportionate to your size and sector, our team can help you get a clear, practical picture of your obligations.

Do Small Businesses Need a Health and Safety Legal Register?

A clear look at legal obligations, business size, and why proportionate compliance matters.

It is a question we hear often from small business owners: โ€œDo I really need a health and safety legal register? Surely that’s something only for large companies with big compliance teams.โ€ It’s an understandable assumption, but it is not correct. Legal obligations in health and safety law are not switched on by company size โ€” they are triggered by what a business actually does, where it does it, and the risks that activity creates. A five-person joinery workshop and a five-hundred-person office may face entirely different legal duties, regardless of which one has more employees on the payroll.

In this article, we look at why the size of a business is the wrong starting point for thinking about legal compliance, and why a well-designed legal register โ€” far from being a burden reserved for large organisations โ€” can be one of the most practical and cost-effective tools a small business ever puts in place.

What Is a Health and Safety Legal Register?

A legal register is a structured record of the health and safety (and often environmental) legislation, regulations, and approved codes of practice that apply to a specific organisation. Rather than listing every law in existence, it identifies the ones that are actually relevant to that business’s operations, sites, and activities, and sets out what needs to be done to remain compliant with each one.

Done properly, a legal register becomes a single point of reference that tells a business owner or manager, at a glance: which laws apply to us, what each one requires, how we currently meet that requirement, and where any gaps exist.

Legal Obligations Depend on Circumstances, Not Company Size

This is the point worth dwelling on, because it is the one most often misunderstood. UK health and safety legislation is largely activity-based and risk-based rather than headcount-based. The Health and Safety at Work etc. Act 1974 and its supporting regulations apply to employers and the self-employed alike, and the specific duties that follow are shaped by factors such as:

  • The nature of the work being carried out (for example, construction, food handling, manual handling, or working with hazardous substances)
  • The premises involved and who else might be affected โ€” employees, contractors, visitors, or members of the public
  • Whether specific hazards are present, such as asbestos, fire risk, electrical systems, or work at height
  • Sector-specific rules that apply regardless of business size, such as food safety, licensing, or environmental permitting requirements

A single self-employed trades person using a ladder has duties under the Work at Height Regulations. A two-person catering business has duties under food hygiene and allergen legislation. A small manufacturer using solvents has duties under COSHH. None of these obligations disappear because the business is small โ€” in some cases, a smaller business with fewer resources to manage risk may need to pay closer attention, not less.

In other words, the question is never really โ€œis my business big enough for this to matter?โ€ The question is โ€œwhat do we actually do, and what does the law say about doing it safely?โ€ A legal register is simply the tool that answers that question clearly and keeps the answer up to date as legislation changes.

Why Small Businesses Benefit from a Concise, Proportionate Register

Recognising that legal duties apply regardless of size is only half the picture. The other half is that how a small business meets those duties can, and should, look very different from how a large organisation meets them. A 200-page legal register modelled on a multinational’s compliance framework is not only unnecessary for a small business โ€” it is actively counterproductive. It gets opened once, filed away, and forgotten.

Do small businesses need a health and safety legal register?

A legal register should be proportionate to your business activities

A register that is built specifically for a small business, scaled to its real activities and risks, tends to work far better in practice. This is why:

1. It Stays Usable

A concise register lists only the legislation that genuinely applies to that business’s operations. Instead of an overwhelming, generic checklist, the owner or manager is left with a short, relevant list they can actually refer to โ€” and act on โ€” day to day.

2. It Reflects the Business as It Really Operates

A bespoke register is built around the specific sites, equipment, substances, and work activities involved, rather than a one-size-fits-all industry template. This means it captures the obligations that matter and does not waste time on ones that do not.

3. It Makes Gaps Visible

Because it is proportionate rather than padded out, a well-built register makes it far easier to spot where compliance is solid and where attention is needed โ€” an outdated risk assessment, a missing policy, a licence due for renewal โ€” without those gaps being buried in irrelevant detail.

4. It Demonstrates Due Diligence

In the event of an incident, an inspection, or a client or insurer asking about compliance arrangements, a maintained legal register is tangible evidence that the business has identified its obligations and is actively managing them. For a small business without a dedicated compliance function, this matters a great deal.

5. It Supports Growth Without Starting from Scratch

As a small business takes on new work, new premises, or new equipment, a legal register built with the right structure can be updated and expanded rather than rebuilt. This means compliance grows alongside the business instead of becoming a sudden, overwhelming project further down the line.

Building a Register That Fits Your Business

The most effective legal registers for small businesses share a few common features: they are reviewed and updated regularly to reflect legislative change, they are written in plain language rather than legal jargon, they link each legal requirement to a clear action or evidence of compliance, and they are proportionate โ€” covering what applies, in appropriate detail, without unnecessary bulk.

This is where working with a health and safety consultancy adds real value. Rather than adapting a generic template, a consultancy can assess your specific activities and premises, identify the legislation that genuinely applies, and build a register that is both legally sound and genuinely usable by your team.

The Bottom Line

Health and safety law does not ask how many people are on your payroll before it applies to you โ€” it asks what risks your work creates. That means every business, regardless of size, has legal obligations worth identifying and managing properly. For small businesses, the smart response is not to ignore this reality, nor to adopt a compliance framework built for a much larger organisation. It’s to build a legal register that is concise, proportionate, and tailored to how the business actually operates โ€” one that gets used, kept current, and genuinely supports safer, more compliant day-to-day operations.

If you are unsure which legal requirements apply to your business, or you would like help building a legal register that is proportionate to your size and sector, our team can help you get a clear, practical picture of your obligations.

Would you like a free copy of our health and safety and environmental legal register checklist for UK operations?

What Happens if Your Legal Register is Out of Date?

A legislation registerโ€”or legal registerโ€”serves as the compliance anchor of an organisationโ€™s corporate governance structure and management system. Designed to identify, organise, and monitor all statutory duties and regulatory obligations applicable to an organisationโ€™s operations, it acts as the baseline for legal adherence. However, maintaining a legal register is not a one-time administrative task; it requires active upkeep to retain its utility.

The key risk of an outdated legal register is that it gives executive management a false picture of the organisationโ€™s true legal obligations and actual compliance level. While an outdated register may not immediately lead to criminal prosecution, relying on obsolete legal information creates subtle, compounding vulnerabilities across operational management, internal auditing, and ISO management systems.

Understanding the operational consequences of an outdated legal register highlights why static compliance documents fail to protect modern enterprises.


1. Missing Critical Legislative Changes and Statutory Amendments

Health, safety, and environmental statutory frameworks across Great Britain, Northern Ireland, the Isle of Man, and the Republic of Ireland are in constant motion. Regulators and parliaments amend existing legislation far more frequently than they enact entirely new primary Acts.

When a legal register is not updated regularly, the following issues occur:

  • Unrecorded Statutory Amendments: An entry in a register may list the correct title of an Act or Regulation, yet remain silently out of date because an amending statutory instrument altered a exposure threshold, broadened a legal definition, or moved a mandatory reporting deadline.
  • Retaining Revoked Legislation: Failing to remove repealed or revoked legislation creates unnecessary administrative clutter. This wastes valuable time during internal checks and misleads staff into enforcing duties that no longer exist under law.
  • Overlooking Updated Regulatory Guidance: Regulators such as the Health and Safety Executive (HSE) and the Environment Agency (EA) frequently update Approved Codes of Practice (ACOPs) and guidance documents. Although guidance is not always statutory law, it defines the legal benchmark expected by courts and enforcement inspectors. Missing these updates leaves operational procedures aligned with obsolete standards.

2. Flawed Compliance Assessments and Distorted Evaluations

Under international management standards such as ISO 14001 (Clause 9.1.2) and ISO 45001 (Clause 9.1.2), organisations must conduct periodic evaluations of their legal compliance status. A compliance evaluation tests operational reality against the parameters documented in the legal register.

If the underlying legal register contains out-of-date information, any subsequent compliance assessment becomes fundamentally flawed. Evaluating site practices against superseded statutory requirements generates inaccurate compliance scores. Managers receive reports indicating complete compliance, unaware that newly enacted statutory duties, altered discharge limits, or updated permit conditions have gone completely unassessed.


3. Failure to Identify New Obligations from Business Triggers

Legislative updates represent only one side of legal register maintenance; internal organisational changes represent the other. Updating a register solely on an annual schedule inevitably causes the document to lag behind internal operational developments.

A failure to execute trigger-based reviews means that routine commercial changes generate unmanaged legal exposure:

  • New Equipment and Machinery: Installing new plant or lifting machinery introduces obligations under the Provision and Use of Work Equipment Regulations 1998 (PUWER) or the Lifting Operations and Lifting Equipment Regulations 1998 (LOLER).
  • New Chemical Substances: Introducing new raw materials or cleaning agents can trigger the Control of Substances Hazardous to Health Regulations 2002 (COSHH) or REACH obligations.
  • Premises and Physical Footprint: Moving to new sites or altering existing buildings brings different fire safety orders, planning consents, and building regulations into scope.
  • Environmental Permit Variations: Varied abstraction consents, modified trade effluent limits, or altered waste classifications must be entered into the register the moment they are granted.
  • Cross-Border Expansion: Expanding operations into a new jurisdictionโ€”such as moving from Great Britain into Northern Ireland or the Republic of Irelandโ€”introduces an entirely separate body of legal requirements rather than a variation of existing rules.

Without a system that links operational changes directly to legal register reviews, new legal duties remain unidentified and unmanaged.


4. Incorrect Regulatory Risk and Misleading Executive Confidence

Executive leadership relies on corporate compliance reporting to evaluate organisational risk and allocate resources effectively.

An outdated legal register distorts this governance feedback loop. It provides leadership with a false sense of security, leading executives to believe that all statutory liabilities are isolated and controlled. In reality, unmonitored regulatory shifts accumulate quietly. This distorted view of regulatory risk can lead management to allocate compliance budgets in error, bypass necessary operational controls, or omit vital safety training.


5. Third-Party Audit Findings and ISO Non-Conformities

For organisations certified to ISO 9001, ISO 14001, or ISO 45001, the legal register is one of the most rigorously examined elements during third-party certification and surveillance audits.

Third-party auditors routinely evaluate legal registers using two distinct approaches:

  1. Top-Down Auditing: The auditor inspects a physical aspect or hazard on site (such as a chemical store, timber workshop, or waste area) and checks whether the corresponding statutory requirements and permit conditions are correctly detailed in the legal register.
  2. Bottom-Up Auditing: The auditor selects a specific entry within the legal register and requests live physical evidence demonstrating how that requirement is fulfilled on the ground.

If an auditor discovers that a register lacks recent legislative amendments, omits applicable permit conditions, or references revoked statutes, a formal non-conformity will be raised against Clause 6.1.3. Treating the legal register as a static, one-time exercise remains one of the most frequent causes of ISO audit failures.


6. Difficulty Demonstrating Legal Compliance and Due Diligence

Maintaining compliance requires more than listing statutory titles; it demands clear evidence of active oversight. A defensible legal register entries should link each statutory clause directly to an internal operating procedure, an assigned internal owner, and a verifiable evidence log.

If a regulatory inspector from the Health and Safety Executive (HSE) or Environment Agency (EA) inspects a site, or if an insurer evaluates an operational claim, an outdated register fails to demonstrate due diligence. Presenting a static document that has not been updated or audited within the preceding twelve months demonstrates a breakdown in compliance governance, making it difficult to prove that the business actively manages its statutory duties.


7. Breakdown of the Plan-Do-Check-Act Management Framework

Recognised management system frameworksโ€”such as ISO 45001 and HSG65โ€”operate on a continuous Plan-Do-Check-Act (PDCA) cycle.

Plan do check act. Legal register out of date?
Plan do check act cycle

The legal register forms the core foundation of the Plan stage. It defines what the organisation must comply with. If the Plan stage relies on obsolete statutory parameters:

  • Operational controls (Do) are built around incorrect standards.
  • Compliance audits (Check) evaluate performance against out-of-date criteria.
  • Corrective actions (Act) fail to address actual legal exposure.

When the legal register is disconnected from live operational checks, the entire management system fails to function as intended.


Establishing an Effective Legal Register Review Protocol

To prevent a legal register from becoming out of date, organisations should implement a dual-track review process:

  • Scheduled Legislative Reviews: Establish a fixed review schedule (typically quarterly) to monitor legislative changes, new statutory instruments, and updated regulator guidance across all operating jurisdictions.
  • Trigger-Based Internal Reviews: Integrate legal register review checklists directly into corporate change-management processes. Any change in business activities, premises, machinery, chemical usage, or environmental permits should prompt an immediate review.
  • Accountability and Audit Trails: Assign clear internal ownership for every entry and maintain a detailed audit trail showing when each requirement was last evaluated.

By pairing scheduled legislative monitoring with internal change management, executive leadership can ensure that the legal register remains an accurate, defensible reflection of the organisation’s legal duties.ย  To get help with your legal register, please contact one of our team.

How Often Should a Legal Register Be Updated?

How often should a legal register be updated? There is no single answer that fits every organisation, but there is a wrong answer: updating it once a year and hoping nothing important happened in between. A legal register is only useful if it reflects the law as it standsย today, and the law โ€” along with your business โ€” rarely stands still.

The honest answer is that a legal register needs two update cycles running side by side: a scheduled review (commonly quarterly) to catch legislative change, and a trigger-based review that fires whenever something changes inside your own organisation. Below is what should prompt each type of update, and why skipping either one leaves gaps.

Scheduled reviews: keeping pace with legislative change

Health and safety and environmental law changes constantly across every jurisdiction โ€” Great Britain, Northern Ireland, the Isle of Man and the Republic of Ireland all move independently, and a register built for one will not automatically cover another. A quarterly review is the practical minimum for most organisations; higher-risk sectors (chemicals, waste, construction, food) often benefit from monthly monitoring. Each cycle should specifically check for:

New legislation

Acts, regulations and statutory instruments do not announce themselves. New legislation should be added to the register as soon as it is in force (or, where lead time allows, flagged ahead of its commencement date so you are not scrambling to comply on day one).

Amendments to existing legislation

Legislation is amended far more often than it is replaced outright โ€” a threshold changed, a definition widened, a deadline moved. If your register only lists the original instrument, it is quietly out of date the moment an amending regulation takes effect, even though the entry still “looks” current.

Repealed and revoked legislation

Just as important as adding new law is removing what no longer applies. A register cluttered with revoked instruments does not just look untidy โ€” it wastes audit time and can mislead someone into thinking a duty still exists when it is been withdrawn.

New guidance

Approved Codes of Practice, Health and Safety Executive (HSE) and Environment Agency (EA) guidance, and equivalent guidance from Northern Ireland, the Isle of Man and Ireland’s regulators are not always legally binding, but they set the standard regulators and courts expect you to meet. Guidance updates should be tracked alongside the legislation they relate to.

Is your legal register regularly reviewed or just left on a shelf?

Trigger-based reviews: keeping pace with your own business

Legislative monitoring only tells half the story. The other half is recognising when something inside your organisation changes the law you are subject to. These triggers should prompt an immediate register review, not wait for the next scheduled cycle:

  • Changes in business activitiesย โ€” a new process, service line, or way of working can bring entirely new legal duties into scope.
  • New premisesย โ€” different buildings mean different building regulations, fire safety duties, planning conditions and local authority requirements.
  • New equipmentย โ€” new plant or machinery can trigger PUWER, LOLER, pressure systems, or work equipment regulations that weren’t previously relevant.
  • New chemicals or substancesย โ€” introducing a new substance can pull in COSHH, REACH, CLP, or storage and transport requirements, and may affect permit conditions.
  • Changes to environmental permitsย โ€” a varied permit, a new abstraction or discharge consent, or a change in waste classification all need reflecting in the register the moment they’re granted or amended.
  • Changes to applicable jurisdictionsย โ€” opening a site, taking on contracts, or employing staff in a new jurisdiction (say, expanding from Great Britain into Northern Ireland or the Republic of Ireland) means an entirely separate body of law applies, not a variation on the one you already have.

Building both cycles into one process

The most effective legal registers treat these two review types as complementary, not alternatives:

  1. Set a fixed scheduleย (quarterly is a sensible default) for legislative monitoring across every jurisdiction you operate in.
  2. Build a trigger checklistย into change-management processes โ€” procurement, facilities, HR and operations should all know to flag the business changes listed above.
  3. Assign ownershipย so it is clear whose job it is to action each type of update, not just who compiles the register.
  4. Keep an audit trailย of when the register was reviewed and what changed, which matters as much to auditors and regulators as the register’s content itself.

The bottom line

A legal register updated only once a year, on a fixed date, will always be behind โ€” both the law and the business move faster than that. Pair a quarterly (or more frequent) legislative review with a trigger-based process for internal change, and the register stays what it is meant to be: an accurate, defensible record of what applies to you right now.

Keeping a legal register current across multiple jurisdictions is exactly what our quarterly legislation updates are designed to support โ€” get in touch to find out how we can help.

What Does an ISO 14001 Legal Register Need to Contain?

If you are working towards ISO 14001 certification, or maintaining it, the legal register is one of the areas auditors return to again and again. As with its ISO 45001 counterpart, it looks straightforward on paper โ€” a list of environmental laws that apply to your business โ€” but in practice it is one of the most common sources of non-conformities.

This article follows on from our piece on the ISO 45001 legal register, and covers the environmental equivalent: what a compliant ISO 14001 legal register needs to contain, why it matters, and how to keep it audit-ready.

What Is a Legal Register Under ISO 14001?

A legal register for ISO 14001 (referred to in the standard as โ€œcompliance obligationsโ€) is a structured record of all the environmental laws, regulations, permits, consents, and other obligations that apply to your organisationโ€™s activities, products, and services.

Clause 6.1.3 of ISO 14001:2026 requires organisations to determine and have access to up-to-date compliance obligations related to its environmental aspects, to determine how these apply to the organisation, and to keep this information current. The register is how you evidence that this has been done.

It is worth noting that ISO 14001 deliberately moved away from the term โ€œlegal registerโ€ in favour of โ€œcompliance obligationsโ€ to reflect that the scope is broader than statute law โ€” but in practice, most organisations (and most auditors) still refer to it as the legal register, and we will use both terms here.

Why It Matters More Than It Looks

Just as with an OH&S legal register, this document is not a compliance checkbox โ€” it is the foundation your environmental management system (EMS) is built on. It drives your aspects and impacts assessment, your operational controls, your monitoring and measurement programme, and your internal audit criteria. If the register is wrong or incomplete, everything built on top of it is at risk too.

Auditors will typically test the register in two directions:

  • Top-down โ€” picking an environmental aspect (e.g. a waste stream, an emission point, a chemical store) and checking the relevant legislation is listed.
  • Bottom-up โ€” picking an entry in the register and asking how it is being met in practice, such as through a permit condition or monitoring record.

If either direction breaks down, it is usually flagged as a non-conformity.

Core Elements Every Entry Should Include

While the exact format can vary, a robust legal register entry should contain the following information for each requirement:

  1. Legislation or requirement title โ€” the specific act, regulation, permit, licence, or other obligation (e.g. environmental permit condition, corporate group standard, client contractual clause).
  2. Reference number or citation โ€” the official identifier so it can be traced back to source.
  3. Jurisdiction โ€” which country, state, or region it applies to, especially important for multi-site organisations with different permit regimes.
  4. Summary of the requirement โ€” a plain-language description of what the law or permit condition actually requires, avoiding a copy-paste of dense legal text. This is often where expert consultants can be beneficial in interpreting the requirement for your business operations.
  5. Applicability โ€” why and how this requirement applies to your specific sites, processes, or environmental aspects. Generic entries (โ€œEnvironmental Protection Act applies to all businessesโ€) are a common audit finding.
  6. Compliance status โ€” a clear statement of whether you currently comply, partially comply, or are working towards compliance. Particularly useful when first implementing ISO 14001.
  7. Evidence of compliance โ€” links or references to the specific permits, monitoring data, procedures, or records that demonstrate compliance.
  8. Responsible person or role โ€” who owns the register and is accountable for maintaining compliance.
  9. Review date and frequency โ€” when it was last checked and when it is next due for review.
  10. Source of update information โ€” how you monitor for changes (e.g. legislation update service, environmental regulator bulletin, trade body alert).
  11. Date of last legislative change โ€” useful for showing the register reflects the current version of the law or permit, not an outdated one.

Beyond Statutory Law: โ€œOther Requirementsโ€

Like ISO 45001, ISO 14001 explicitly extends beyond legislation to other compliance obligations the organisation has to, or chooses to, meet. These are easy to miss but often specifically probed by auditors. In an environmental context, they may include:

  • Environmental permits, licences, and consents (waste, water discharge, emissions to air)
  • Industry codes of practice and sector environmental guidance
  • Client or contractual environmental requirements
  • Corporate group environmental standards (for multi-site or multinational organisations)
  • Voluntary agreements, industry schemes, or accreditation body conditions
  • Producer responsibility obligations (e.g. packaging, WEEE, battery regulations)

If your register only lists statutory legislation and ignores these, it will not fully meet the clause requirement.

Your ISO 14001 legal register must include obligations as well as legislation
Your ISO 14001 legal register must include obligations as well as legislation

How to Structure the Register

There is no single structure every register must follow, and it is often shaped by the size, sector, and complexity of the organisation. Most organisations use a spreadsheet, a document, or a dedicated compliance software tool. Common groupings for an ISO 14001 register include:

  • General environmental legislation
  • Waste management and disposal
  • Water and effluent discharge
  • Air emissions
  • Hazardous and chemical substances
  • Energy and resource use
  • Sector-specific legislation (construction, manufacturing, healthcare, etc.)
  • Packaging and producer responsibility

Structuring it this way makes the register easier to cross-reference against your aspects and impacts register and operational controls, and much faster to navigate during an audit.

Keeping It Live: Review and Monitoring

A legal register is only useful if it stays current. ISO 14001 requires that this information be kept up to date, so your process needs to show:

  • A defined review frequency (many organisations review quarterly, with a full review annually)
  • A named responsible person for monitoring legislative and permit changes โ€” this can be an internal representative or an external consultant
  • A method for capturing changes (legal update subscription services are common, as manually tracking regulator publications is unreliable)
  • A record of how changes were assessed and, where relevant, action taken (updated aspects and impacts assessments, new controls, revised monitoring)

Common Mistakes to Avoid

  • Treating it as a one-off exercise. Registers built once for certification and never revisited are one of the most frequent non-conformities.
  • Copying generic templates without tailoring. A register that does not reflect your actual sites, processes, and environmental aspects will not withstand scrutiny.
  • No link to evidence. Listing a requirement without showing how it is actually met leaves a gap between the register and reality.
  • Missing permit conditions. Focusing only on primary legislation and overlooking the specific conditions attached to site permits and licences.
  • No ownership. Without a named responsible person, updates tend to fall through the cracks.

Do I Need a Legal Register for ISO 14001 Certification?

Yes. A legal register (compliance obligations register) is a mandatory requirement of Clause 6.1.3 and is one of the first documents an auditor will ask to see, both at initial certification and at every surveillance audit. Without one, an organisation cannot demonstrate it has identified and is managing its environmental compliance obligations, which is a core requirement of the standard.

Final Thoughts

A well-built legal register does more than satisfy Clause 6.1.3 โ€” it becomes a working tool that keeps your entire environmental management system grounded in what the law, your permits, and your other obligations actually require. Getting the structure right from the start, and building in a genuine review cycle, is what separates a register that passes audit from one that merely exists on paper.

If you are managing both standards together, it is worth reading this alongside our companion article on the ISO 45001 legal register โ€” many organisations choose to maintain a single combined register covering both health and safety and environmental obligations, provided it clearly distinguishes between the two.

If you would like support building or auditing your legal register as part of your ISO 14001 journey, get in touch with our team for a consultation.