What an Auditor Looks for in an ISO 45001 Compliant Legal Register

As an auditor with over 10 years experience, I am often asked what do I look for in a legal register? Your legal register is one of the first documents an ISO 45001 auditor will ask to see — and one of the easiest places to lose points if it isn’t maintained properly. Clause 6.1.3 requires organisations to identify and have access to the legal and other requirements relevant to their occupational health and safety management system, and to keep this information up to date. In practice, auditors treat the legal register as a litmus test for the whole management system: if it’s weak, they’ll assume other processes are too.

Here’s what auditors actually check, and how to make sure your register holds up.

1. Coverage: Is It Actually Complete?

Auditors will cross-reference your register against your organisation’s activities, sites, and hazards. They’re looking for gaps such as:

  • Legislation relevant to specific plant, equipment, or processes (e.g. LOLER for lifting equipment, PUWER for work equipment, DSEAR if flammable substances are present)
  • Jurisdiction-specific law where you operate across multiple regions — for example, differences between Great Britain, Northern Ireland, the Isle of Man, and the Republic of Ireland
  • Sector-specific regulations, not just generic Health and Safety law
  • Environmental legislation where it overlaps with Occupational Health and Safety risk (waste, emissions, COMAH)

A register that only lists headline Acts (Health and Safety at Work etc. Act 1974, Management of Health and Safety at Work Regulations 1999) without the supporting regulations underneath will be flagged immediately.

ISO 45001 Legal Register

ISO 45001 Legal Register: What auditors look for

2. Currency: Is It Kept Up to Date?

This is the single most common nonconformity auditors raise. They will ask:

  • What is your process for identifying new, amended, or revoked legislation?
  • How often is the register reviewed, and who owns that review?
  • Can you show evidence of the last update (version control, revision log, sign-off)?

Auditors are wary of registers that look identical year to year — it signals no active monitoring process exists. A dated revision history, or a subscription to a legislation-update service, is strong evidence here.

3. Evaluation of Compliance: Not Just a List

ISO 45001 doesn’t just require you to identify legal requirements — clause 9.1.2 requires you to evaluate compliance against them. Auditors will look for:

  • A clear compliance status against each legal requirement (compliant / partially compliant / non-compliant)
  • Evidence linking each requirement to how compliance is demonstrated (a policy, procedure, permit, inspection record, or training log)
  • A defined frequency for compliance evaluation, separate from the register review itself

A register with no compliance column, or one where every line simply says “compliant” with no supporting evidence, will draw scrutiny.

4. Traceability and Accessibility

Auditors will trace a sample of legal requirements through your system to check they’re not just sitting in a spreadsheet nobody uses. Typical questions:

  • Is this requirement referenced in a risk assessment, procedure, or work instruction?
  • Do relevant staff know this requirement applies to their role?
  • Is the register accessible to those who need it — not locked away with one person?

This is where many organisations fall down: the register exists, but there’s no visible link between it and day-to-day operational control.

5. Ownership and Process

Beyond the document itself, auditors assess the process behind it. Expect questions such as:

  • Who is responsible for monitoring legislative change?
  • What’s the escalation route when a new legal requirement is identified — how does it get actioned, and by when?
  • Is legal compliance a standing item in management review, per clause 9.3?

A register maintained by one person with no documented process, and no visibility at management review, suggests the requirement is being met on paper only.

6. Format Doesn’t Matter — Function Does

ISO 45001 doesn’t mandate a specific format for the legal register. Auditors don’t care whether it’s a spreadsheet, database, or software module — they care whether it functions as a live compliance tool. That said, a well-structured register typically includes:

AspectPurpose
Legislation title & referenceIdentification
JurisdictionApplicability
Summary of requirementInterpretation
Applicability to the organisationRelevance
Compliance statusEvaluation
Evidence/referenceTraceability
Date reviewed / next reviewCurrency
OwnerAccountability

Getting Audit-Ready

If you’re preparing for an ISO 45001 audit (or surveillance visit), the fastest way to strengthen your legal register is to:

  1. Run a gap analysis against your current activities and sites
  2. Add a compliance-status column if you don’t already have one
  3. Establish a documented, evidenced review cycle
  4. Make sure the register is referenced in risk assessments and management review minutes

A legal register that’s actively maintained, evidenced, and embedded in operational decisions is one of the strongest signals of a mature management system — and one of the quickest wins in an audit.

If you need a bespoke legal register or you would like your existing register reviewed, please contact one of our team.

The Difference Between Generic and Bespoke Legal Registers

Why a one-size-fits-all approach to legal compliance leaves organisations exposed — and what a register built around your actual operations gives you instead.

If your organisation is subject to health, safety, or environmental law — and almost every organisation is — you need a legal register. It’s the document that tells you which legislation applies to your operations, what it requires of you, and whether you’re actually compliant. But not all legal registers are built the same way, and the difference between a generic template and a bespoke register isn’t cosmetic. It’s the difference between a document that looks like due diligence and one that actually protects your organisation.

What Is a Legal Register?

A legal register is a structured record of the laws, regulations, and codes of practice that apply to an organisation, typically covering health and safety, environmental, and related compliance obligations. It’s a cornerstone requirement of recognised management system standards, including ISO 9001, ISO 45001 and ISO 14001, and it’s usually the first document an auditor or regulator asks to see. On paper, every legal register looks similar: a list of legislation, a summary of requirements, a compliance status. In practice, how that list is built determines whether the register is a genuinely useful management tool or a box-ticking exercise.

The Trouble With Generic Legal Registers

Generic legal registers are typically off-the-shelf templates or subscription database exports, built to cover an entire sector or industry in one document. They’re inexpensive, quick to obtain, and easy to see the appeal of — but that convenience comes at a real cost:

  • They list legislation that may have nothing to do with your actual activities, sites, or risk profile, burying the requirements that genuinely matter under dozens that don’t.
  • They rarely reflect the specific jurisdictions, licences, or permits your organisation holds, particularly for organisations operating across Great Britain, Northern Ireland, the Isle of Man, or the Republic of Ireland, where legal frameworks diverge significantly.
  • They’re built for updating on a fixed schedule rather than in response to your organisation’s changes — a new site, a new process, a new piece of equipment — so they drift out of date the moment your operations move.
  • They describe legal duties in abstract terms, without translating them into what compliance actually looks like for your sites, your equipment, and your people.
  • They offer no meaningful gap analysis — you’re left to work out for yourself whether you actually comply with each requirement.

The result is a register that satisfies the letter of the audit requirement — “yes, we have a legal register” — without doing the job a legal register exists to do: giving your organisation a clear, current, accurate picture of its legal exposure.

Bespoke vs generic legal register, which is best?
Photo courtesy of Pixabay tumisu-audit

A bespoke legal register demonstrates to auditors that you actually know your legal obligations.

Why a Bespoke Legal Register Is the Only Register Worth Having

A bespoke legal register is built from the ground up around your organisation: your sites, your activities, your industry sector, your jurisdictions, and your risk profile. Rather than starting from a generic list and hoping it fits, it starts from your operations and identifies exactly which legislation applies — and, critically, what that legislation actually requires you to do about it. The advantages compound quickly:

  • Relevance: every entry has a direct line to something your organisation actually does, so nothing important gets lost in noise that doesn’t apply to you.
  • Accuracy across jurisdictions: legislation is mapped to the specific jurisdiction — GB, NI, Isle of Man, or ROI — that each site operates under, rather than treated as a single homogeneous “UK law” list.
  • A genuine compliance status: each requirement is assessed against evidence from your organisation, so you know — not guess — where you stand, and where the gaps are.
  • Built-in gap analysis and action planning: a bespoke register doesn’t just flag non-compliance, it gives you a prioritised route to closing it.
  • Living, current content: as legislation changes or your organisation changes — a new site, a new process, an amended regulation — the register is updated to reflect it, so it never becomes a snapshot of a moment that’s already passed.
  • Audit and due diligence confidence: a bespoke register demonstrates, to auditors, regulators, insurers, and clients, that your organisation understands and manages its legal obligations — not that it purchased a document that says it does.

In short: a generic register tells you what the law says. A bespoke register tells you what the law means for you — and whether you’re meeting it.

FEATURES

Generic Legal Register

Bespoke Legal Register


Identifies only relevant laws


Focused on the actual business


Relevant and easy to understand


A practical management tool


Includes sector specific requirements


Demonstrates that you understand your obligations

The Bottom Line

A legal register is only as valuable as its accuracy and relevance to your organisation. A generic template can create a false sense of security — the appearance of compliance without the substance of it — and that gap tends to surface at the worst possible moment: during an incident investigation, a regulatory visit, or a client’s due diligence review. A bespoke legal register, developed and maintained by health and safety professionals who understand your sector and your sites, is an investment in genuine legal certainty, not just a document for the audit file.

If your organisation is currently relying on a generic register — or doesn’t have one at all — talk to us about building a bespoke legal register tailored to your operations, sites, and jurisdictions. It’s the foundation every other part of your compliance management sits on, and it’s worth getting right.

Do Small Businesses Need a Health and Safety Legal Register?

A clear look at legal obligations, business size, and why proportionate compliance matters.

It is a question we hear often from small business owners: “Do I really need a health and safety legal register? Surely that’s something only for large companies with big compliance teams.” It’s an understandable assumption, but it is not correct. Legal obligations in health and safety law are not switched on by company size — they are triggered by what a business actually does, where it does it, and the risks that activity creates. A five-person joinery workshop and a five-hundred-person office may face entirely different legal duties, regardless of which one has more employees on the payroll.

In this article, we look at why the size of a business is the wrong starting point for thinking about legal compliance, and why a well-designed legal register — far from being a burden reserved for large organisations — can be one of the most practical and cost-effective tools a small business ever puts in place.

What Is a Health and Safety Legal Register?

A legal register is a structured record of the health and safety (and often environmental) legislation, regulations, and approved codes of practice that apply to a specific organisation. Rather than listing every law in existence, it identifies the ones that are actually relevant to that business’s operations, sites, and activities, and sets out what needs to be done to remain compliant with each one.

Done properly, a legal register becomes a single point of reference that tells a business owner or manager, at a glance: which laws apply to us, what each one requires, how we currently meet that requirement, and where any gaps exist.

Legal Obligations Depend on Circumstances, Not Company Size

This is the point worth dwelling on, because it is the one most often misunderstood. UK health and safety legislation is largely activity-based and risk-based rather than headcount-based. The Health and Safety at Work etc. Act 1974 and its supporting regulations apply to employers and the self-employed alike, and the specific duties that follow are shaped by factors such as:

  • The nature of the work being carried out (for example, construction, food handling, manual handling, or working with hazardous substances)
  • The premises involved and who else might be affected — employees, contractors, visitors, or members of the public
  • Whether specific hazards are present, such as asbestos, fire risk, electrical systems, or work at height
  • Sector-specific rules that apply regardless of business size, such as food safety, licensing, or environmental permitting requirements

A single self-employed trades person using a ladder has duties under the Work at Height Regulations. A two-person catering business has duties under food hygiene and allergen legislation. A small manufacturer using solvents has duties under COSHH. None of these obligations disappear because the business is small — in some cases, a smaller business with fewer resources to manage risk may need to pay closer attention, not less.

In other words, the question is never really “is my business big enough for this to matter?” The question is “what do we actually do, and what does the law say about doing it safely?” A legal register is simply the tool that answers that question clearly and keeps the answer up to date as legislation changes.

Why Small Businesses Benefit from a Concise, Proportionate Register

Recognising that legal duties apply regardless of size is only half the picture. The other half is that how a small business meets those duties can, and should, look very different from how a large organisation meets them. A 200-page legal register modelled on a multinational’s compliance framework is not only unnecessary for a small business — it is actively counterproductive. It gets opened once, filed away, and forgotten.

Do small businesses need a health and safety legal register?

A legal register should be proportionate to your business activities

A register that is built specifically for a small business, scaled to its real activities and risks, tends to work far better in practice. This is why:

1. It Stays Usable

A concise register lists only the legislation that genuinely applies to that business’s operations. Instead of an overwhelming, generic checklist, the owner or manager is left with a short, relevant list they can actually refer to — and act on — day to day.

2. It Reflects the Business as It Really Operates

A bespoke register is built around the specific sites, equipment, substances, and work activities involved, rather than a one-size-fits-all industry template. This means it captures the obligations that matter and does not waste time on ones that do not.

3. It Makes Gaps Visible

Because it is proportionate rather than padded out, a well-built register makes it far easier to spot where compliance is solid and where attention is needed — an outdated risk assessment, a missing policy, a licence due for renewal — without those gaps being buried in irrelevant detail.

4. It Demonstrates Due Diligence

In the event of an incident, an inspection, or a client or insurer asking about compliance arrangements, a maintained legal register is tangible evidence that the business has identified its obligations and is actively managing them. For a small business without a dedicated compliance function, this matters a great deal.

5. It Supports Growth Without Starting from Scratch

As a small business takes on new work, new premises, or new equipment, a legal register built with the right structure can be updated and expanded rather than rebuilt. This means compliance grows alongside the business instead of becoming a sudden, overwhelming project further down the line.

Building a Register That Fits Your Business

The most effective legal registers for small businesses share a few common features: they are reviewed and updated regularly to reflect legislative change, they are written in plain language rather than legal jargon, they link each legal requirement to a clear action or evidence of compliance, and they are proportionate — covering what applies, in appropriate detail, without unnecessary bulk.

This is where working with a health and safety consultancy adds real value. Rather than adapting a generic template, a consultancy can assess your specific activities and premises, identify the legislation that genuinely applies, and build a register that is both legally sound and genuinely usable by your team.

The Bottom Line

Health and safety law does not ask how many people are on your payroll before it applies to you — it asks what risks your work creates. That means every business, regardless of size, has legal obligations worth identifying and managing properly. For small businesses, the smart response is not to ignore this reality, nor to adopt a compliance framework built for a much larger organisation. It’s to build a legal register that is concise, proportionate, and tailored to how the business actually operates — one that gets used, kept current, and genuinely supports safer, more compliant day-to-day operations.

If you are unsure which legal requirements apply to your business, or you would like help building a legal register that is proportionate to your size and sector, our team can help you get a clear, practical picture of your obligations.

What Happens if Your Legal Register is Out of Date?

A legislation register—or legal register—serves as the compliance anchor of an organisation’s corporate governance structure and management system. Designed to identify, organise, and monitor all statutory duties and regulatory obligations applicable to an organisation’s operations, it acts as the baseline for legal adherence. However, maintaining a legal register is not a one-time administrative task; it requires active upkeep to retain its utility.

The key risk of an outdated legal register is that it gives executive management a false picture of the organisation’s true legal obligations and actual compliance level. While an outdated register may not immediately lead to criminal prosecution, relying on obsolete legal information creates subtle, compounding vulnerabilities across operational management, internal auditing, and ISO management systems.

Understanding the operational consequences of an outdated legal register highlights why static compliance documents fail to protect modern enterprises.


1. Missing Critical Legislative Changes and Statutory Amendments

Health, safety, and environmental statutory frameworks across Great Britain, Northern Ireland, the Isle of Man, and the Republic of Ireland are in constant motion. Regulators and parliaments amend existing legislation far more frequently than they enact entirely new primary Acts.

When a legal register is not updated regularly, the following issues occur:

  • Unrecorded Statutory Amendments: An entry in a register may list the correct title of an Act or Regulation, yet remain silently out of date because an amending statutory instrument altered a exposure threshold, broadened a legal definition, or moved a mandatory reporting deadline.
  • Retaining Revoked Legislation: Failing to remove repealed or revoked legislation creates unnecessary administrative clutter. This wastes valuable time during internal checks and misleads staff into enforcing duties that no longer exist under law.
  • Overlooking Updated Regulatory Guidance: Regulators such as the Health and Safety Executive (HSE) and the Environment Agency (EA) frequently update Approved Codes of Practice (ACOPs) and guidance documents. Although guidance is not always statutory law, it defines the legal benchmark expected by courts and enforcement inspectors. Missing these updates leaves operational procedures aligned with obsolete standards.

2. Flawed Compliance Assessments and Distorted Evaluations

Under international management standards such as ISO 14001 (Clause 9.1.2) and ISO 45001 (Clause 9.1.2), organisations must conduct periodic evaluations of their legal compliance status. A compliance evaluation tests operational reality against the parameters documented in the legal register.

If the underlying legal register contains out-of-date information, any subsequent compliance assessment becomes fundamentally flawed. Evaluating site practices against superseded statutory requirements generates inaccurate compliance scores. Managers receive reports indicating complete compliance, unaware that newly enacted statutory duties, altered discharge limits, or updated permit conditions have gone completely unassessed.


3. Failure to Identify New Obligations from Business Triggers

Legislative updates represent only one side of legal register maintenance; internal organisational changes represent the other. Updating a register solely on an annual schedule inevitably causes the document to lag behind internal operational developments.

A failure to execute trigger-based reviews means that routine commercial changes generate unmanaged legal exposure:

  • New Equipment and Machinery: Installing new plant or lifting machinery introduces obligations under the Provision and Use of Work Equipment Regulations 1998 (PUWER) or the Lifting Operations and Lifting Equipment Regulations 1998 (LOLER).
  • New Chemical Substances: Introducing new raw materials or cleaning agents can trigger the Control of Substances Hazardous to Health Regulations 2002 (COSHH) or REACH obligations.
  • Premises and Physical Footprint: Moving to new sites or altering existing buildings brings different fire safety orders, planning consents, and building regulations into scope.
  • Environmental Permit Variations: Varied abstraction consents, modified trade effluent limits, or altered waste classifications must be entered into the register the moment they are granted.
  • Cross-Border Expansion: Expanding operations into a new jurisdiction—such as moving from Great Britain into Northern Ireland or the Republic of Ireland—introduces an entirely separate body of legal requirements rather than a variation of existing rules.

Without a system that links operational changes directly to legal register reviews, new legal duties remain unidentified and unmanaged.


4. Incorrect Regulatory Risk and Misleading Executive Confidence

Executive leadership relies on corporate compliance reporting to evaluate organisational risk and allocate resources effectively.

An outdated legal register distorts this governance feedback loop. It provides leadership with a false sense of security, leading executives to believe that all statutory liabilities are isolated and controlled. In reality, unmonitored regulatory shifts accumulate quietly. This distorted view of regulatory risk can lead management to allocate compliance budgets in error, bypass necessary operational controls, or omit vital safety training.


5. Third-Party Audit Findings and ISO Non-Conformities

For organisations certified to ISO 9001, ISO 14001, or ISO 45001, the legal register is one of the most rigorously examined elements during third-party certification and surveillance audits.

Third-party auditors routinely evaluate legal registers using two distinct approaches:

  1. Top-Down Auditing: The auditor inspects a physical aspect or hazard on site (such as a chemical store, timber workshop, or waste area) and checks whether the corresponding statutory requirements and permit conditions are correctly detailed in the legal register.
  2. Bottom-Up Auditing: The auditor selects a specific entry within the legal register and requests live physical evidence demonstrating how that requirement is fulfilled on the ground.

If an auditor discovers that a register lacks recent legislative amendments, omits applicable permit conditions, or references revoked statutes, a formal non-conformity will be raised against Clause 6.1.3. Treating the legal register as a static, one-time exercise remains one of the most frequent causes of ISO audit failures.


6. Difficulty Demonstrating Legal Compliance and Due Diligence

Maintaining compliance requires more than listing statutory titles; it demands clear evidence of active oversight. A defensible legal register entries should link each statutory clause directly to an internal operating procedure, an assigned internal owner, and a verifiable evidence log.

If a regulatory inspector from the Health and Safety Executive (HSE) or Environment Agency (EA) inspects a site, or if an insurer evaluates an operational claim, an outdated register fails to demonstrate due diligence. Presenting a static document that has not been updated or audited within the preceding twelve months demonstrates a breakdown in compliance governance, making it difficult to prove that the business actively manages its statutory duties.


7. Breakdown of the Plan-Do-Check-Act Management Framework

Recognised management system frameworks—such as ISO 45001 and HSG65—operate on a continuous Plan-Do-Check-Act (PDCA) cycle.

Plan do check act. Legal register out of date?
Plan do check act cycle

The legal register forms the core foundation of the Plan stage. It defines what the organisation must comply with. If the Plan stage relies on obsolete statutory parameters:

  • Operational controls (Do) are built around incorrect standards.
  • Compliance audits (Check) evaluate performance against out-of-date criteria.
  • Corrective actions (Act) fail to address actual legal exposure.

When the legal register is disconnected from live operational checks, the entire management system fails to function as intended.


Establishing an Effective Legal Register Review Protocol

To prevent a legal register from becoming out of date, organisations should implement a dual-track review process:

  • Scheduled Legislative Reviews: Establish a fixed review schedule (typically quarterly) to monitor legislative changes, new statutory instruments, and updated regulator guidance across all operating jurisdictions.
  • Trigger-Based Internal Reviews: Integrate legal register review checklists directly into corporate change-management processes. Any change in business activities, premises, machinery, chemical usage, or environmental permits should prompt an immediate review.
  • Accountability and Audit Trails: Assign clear internal ownership for every entry and maintain a detailed audit trail showing when each requirement was last evaluated.

By pairing scheduled legislative monitoring with internal change management, executive leadership can ensure that the legal register remains an accurate, defensible reflection of the organisation’s legal duties.  To get help with your legal register, please contact one of our team.

What Does an ISO 45001 Legal Register Need to Contain?

If you are working towards ISO 45001 certification, or maintaining it, one of the most common sticking points during audits is the legal register. It sounds like a simple document — a list of laws that apply to your business — but auditors consistently find registers that are either incomplete, out of date, or too vague to demonstrate real compliance.

This article breaks down exactly what a compliant legal register needs to contain, why it matters, and how to keep it audit-ready.

What Is a Legal Register?

A legal register (sometimes called a “legal and other requirements register”) is a structured record of all the health and safety laws, regulations, codes of practice, and other obligations that apply to your organisation’s activities, products, and services.

Under ISO 45001, Clause 6.1.3 requires organisations to determine and have access to up-to-date legal requirements and other requirements relevant to their occupational health and safety management system (OH&S MS), and to keep this information current. The register is how you evidence that you have done this.

Legal register
Is your legal register up to date?

Why It Matters More Than It Looks

A legal register is not just a compliance checkbox. It is the foundation your OH&S management system is built on — it drives your risk assessments, your operational controls, your training needs, and your internal audit criteria. If the register is wrong or incomplete, everything built on top of it is at risk too.

Auditors will typically test the register in two directions:

  • Top-down — picking an activity or hazard on site and checking the relevant legislation is listed.
  • Bottom-up — picking an entry in the register and asking how it is being met in practice.

If either direction breaks down, it is usually flagged as a non-conformity.

Core Elements Every Entry Should Include

While the exact format can vary, a robust legal register entry should contain the following information for each requirement:

  1. Legislation or requirement title — the specific act, regulation, code of practice, standard, or other obligation (e.g. industry code, insurer requirement, client contractual clause).
  2. Reference number or citation — the official identifier so it can be traced back to source.
  3. Jurisdiction — which country, state, or region it applies to, especially important for multi-site organisations.
  4. Summary of the requirement — a plain-language description of what the law actually requires, avoiding a copy-paste of dense legal text.  This is often where expert consultants can be beneficial in interpreting the law to your business operations.
  5. Applicability — why and how this requirement applies to your specific operations, sites, or activities. Generic entries (“Health and Safety at Work Act applies to all businesses”) are a common audit finding.
  6. Compliance status — a clear statement of whether you currently comply, partially comply, or are working towards compliance.  This is particularly useful when first implementing ISO 45001.
  7. Evidence of compliance — links or references to the specific procedures, records, permits, certificates, or controls that demonstrate compliance.
  8. Responsible person or role — who owns the register and is accountable for maintaining compliance.
  9. Review date and frequency — when it was last checked and when it is next due for review.
  10. Source of update information — how you monitor for changes (e.g. legislation update service, trade body bulletin, government gazette, etc.).
  11. Date of last legislative change — useful for showing the register reflects the current version of the law, not an outdated one.

Beyond Statutory Law: “Other Requirements”

ISO 45001 explicitly extends beyond legislation to “other requirements.” These are easy to miss but often specifically probed by auditors. They may include:

  • Industry codes of practice and guidance documents
  • Client or contractual health and safety requirements
  • Relevant insurance provider conditions
  • Corporate group standards (for multi-site or multinational organisations)
  • Voluntary agreements or membership scheme conditions
  • Permits, licences, and consents tied to specific sites or activities

If your register only lists statutory legislation and ignores these, it will not fully meet the clause requirement.

How to Structure the Register

There is no single structure that every register must follow, and it is often determined by the type, size or nature of the organisation itself.  Most organisations use a spreadsheet, text document or a dedicated compliance software tool. Common groupings include:

  • General health and safety legislation
  • Fire safety
  • Environmental (where it overlaps with H&S, e.g. hazardous substances)
  • Sector-specific legislation (construction, manufacturing, healthcare, etc.)
  • Equipment and machinery
  • Chemical and hazardous substances
  • Transport and vehicles
  • Welfare and employment law touching on H&S

Structuring it makes the register easier to cross-reference against your risk assessments and operational controls, procedures and much faster to navigate during an audit.

Keeping It Live: Review and Monitoring

A legal register is only useful if it stays current. ISO 45001 requires that this information be kept up to date, so your process needs to show:

  • A defined review frequency (many organisations review quarterly, with a full review annually)
  • A named responsible person for monitoring legislative changes, this can be a representative in the organisation but could also be an external consultant
  • A method for capturing changes (legal update subscription services are common, as manually tracking government publications is unreliable)
  • A record of how changes were assessed and, where relevant, actioned (updated risk assessments, new controls, revised training)

Common Mistakes to Avoid

  • Treating it as a one-off exercise. Registers built once for certification and never revisited are one of the most frequent non-conformities.
  • Copying generic templates without tailoring. A register that does not reflect your actual sites, activities, and hazards will not withstand scrutiny.
  • No link to evidence. Listing a requirement without showing how it is actually met leaves a gap between the register and reality.
  • Missing “other requirements.” Focusing only on statute law and ignoring client, insurer, or industry obligations.
  • No ownership. Without a named responsible person, updates tend to fall through the cracks.

Final Thoughts

A well-built legal register does more than satisfy Clause 6.1.3 — it becomes a working tool that keeps your entire OH&S management system grounded in what the law and your other obligations actually require. Getting the structure right from the start, and building in a genuine review cycle, is what separates a register that passes audit from one that merely exists on paper.

If you would like support building or auditing your legal register as part of your ISO 45001 journey, get in touch with our team for a consultation.

Health & Safety Legal Register vs Compliance Audit: What is the Difference?

If you have been told you need a “legal register” and separately advised to commission a “compliance audit,” you could be forgiven for wondering whether these are two names for the same thing. They are not — and understanding the difference matters, because most organisations that fall foul of a health and safety enforcement notice have one of these two documents in place but not the other.

This article explains what each one actually does, how they work together, and which one your organisation needs first.

The short answer

A health and safety legal register identifies which legal requirements apply to your organisation. A compliance audit (or compliance evaluation) tells you whether you are actually meeting them.

One is a map. The other is a health check against that map. You need both, but they answer different questions, and confusing them is one of the most common gaps we find when we review a client’s health and safety management system.

Health and safety consultant reviewing legal register documentation

What is a legal register?

A legal register is a structured record of the health and safety legislation, regulations, approved codes of practice, and other legal requirements that apply to your organisation’s specific activities, sites, and operations.

A good legal register will typically:

  • List each applicable piece of legislation (for example, the Management of Health and Safety at Work Regulations, COSHH, the Work at Height Regulations, or sector-specific rules)
  • Summarise what that legislation requires of your organisation
  • Identify which parts of your business or which activities the requirement applies to
  • Identify the controls in place to meet the legal requirements
  • Be reviewed and updated as legislation changes or your operations evolve

Crucially, a legal register is a document of applicability. It answers the question: “What law applies to us, and what does it say we must do?” It does not, by itself, tell you whether you are doing it.

What is a compliance audit or evaluation?

A compliance audit takes the requirements identified in the legal register (or an equivalent framework) and tests them against reality. It asks: “Are we actually meeting this requirement, in practice, today?”

A compliance audit typically involves:

  • Site visits and observation of actual working practices
  • Review of documentation, records, and evidence (permits, training records, inspection logs, risk assessments)
  • Interviews with staff, supervisors, and duty holders
  • Gap analysis against each legal requirement
  • A findings report ranking non-conformities by risk and urgency
  • Recommendations and an action plan to close the gaps

Where the legal register is a snapshot of obligations, the compliance audit is a live assessment of performance. It is the difference between having a checklist and actually checking the boxes — and finding out, in evidence-based detail, which ones you cannot honestly tick yet.

Legal Register

  • Records applicable legislation for the organisation

  • Sets the bench mark for compliance

  • Must be regularly reviewed & updated

  • Identifies controls in place

  • Bespoke to the organisation

  • Can be one jurisdiction or more

Compliance Audit

  • Identifies if you actually meet the legal requirements

  • Assesses at a specific point in time

  • Site visits, observations & staff interviews

  • Review of documentation, records, etc.

  • Gap analysis

  • Recommendations & action plan

Why the difference matters

We regularly see organisations that have invested in one of these tools and assumed it covers the other. Both mistakes carry real risk.

Legal register without an audit: You know what the law requires, but nobody has verified whether it’s happening on the ground. This is common where a legal register was purchased as a subscription product or generated once and filed away. It creates a false sense of security — the document exists, so the box feels ticked, but there is no evidence of actual conformance if an inspector, insurer, or regulator asks for it.

Audit without a legal register: You get a snapshot of current practice, but without a clear, maintained baseline of what should apply, the audit scope is often built from generic checklists or the auditor’s working knowledge rather than your organisation’s specific legal exposure. Gaps in obligations you did not know applied to you can be missed entirely.

Used together, the legal register defines the scope of what to check, and the audit provides the evidence of whether you are meeting it. This combination is also what regulators, insurers, and courts expect to see when assessing whether an organisation exercised due diligence — a legal register with no corroborating evidence of compliance checking is a weak defence in an enforcement case or civil claim.

How they fit into a health and safety management system

Think of it as a three-stage cycle:

  1. Identify — the legal register captures every applicable requirement
  2. Evaluate — the compliance audit tests current practice against each requirement
  3. Act — a corrective action plan closes the gaps the audit identifies, and the cycle repeats on a review schedule

This mirrors the “Plan-Do-Check-Act” approach that underpins recognised health and safety management standards such as ISO 45001 and HSG65. A legal register alone only covers “Plan.” Without the “Check” stage — the audit — you have no mechanism to confirm the plan is working.

Which do you need first?

If your organisation does not currently have a legal register, that is the logical starting point — you cannot meaningfully audit compliance against requirements you have not formally identified.

If you already have a legal register but it has not been tested against actual site practice in the last 12 months, a compliance audit should be your next step. An out-of-date or unverified register can quietly become a liability rather than an asset.

Get a clear picture of your legal exposure and compliance status

Many organisations discover during an audit that gaps have existed for months or years without anyone noticing — often because the legal register and the audit process were never properly connected.

If you are not sure whether your current legal register is complete, whether your last audit was thorough enough, or where to start with either, we can help. We carry out legal register development, gap analysis, and full compliance audits tailored to your sector and operations, with a clear, prioritised action plan at the end of it — not just a list of problems. We have experience in a variety of sectors to meet your needs.

Get in touch to arrange a no-obligation discussion about your current legal register or compliance status, and we will tell you honestly where your priorities should be.

How to Identify Which Health & Safety Legislation Applies to Your Business

UK health and safety law is not a single rule book that every business follows in the same way. Instead, it’s a layered system: the Health and Safety at Work etc. Act 1974 (HSWA) sets out broad duties that apply to almost every employer, while dozens of more specific regulations — made under that Act — only apply depending on what your business actually does. Many owners and managers assume that because they have done a general risk assessment, they are covered. In practice, working out your full legal obligations means looking closely at your activities, equipment, premises and workforce, not just your industry label.

This article walks through the main factors that determine which UK regulations apply to your business, so you can build an accurate picture of your legal duties rather than relying on guesswork.

Start with the general duties under HSWA 1974

The Health and Safety at Work etc. Act 1974 is the foundation of UK health and safety law. It places a general duty on employers to ensure, so far as is reasonably practicable, the health, safety and welfare of their employees, and to protect others — such as contractors, visitors and the public — who may be affected by their work. The Act also places duties on the self-employed and on those in control of premises.

HSWA rarely tells you exactly what to do in a given situation. Instead, it is supported by a wide range of secondary legislation — mostly Statutory Instruments enforced by the Health and Safety Executive (HSE) or your local authority — that add specific, practical requirements. Identifying which of these regulations apply to you depends on several interacting factors.

Houses of Parliament, London

Factor 1: The nature of your work activities

The single biggest driver of applicability is what your business actually does day to day. UK regulations are often built around specific hazards or types of work, meaning two businesses in the same broad sector can have quite different legal obligations depending on the tasks involved. Common examples include:

Each of these activities brings its own dedicated regulations into scope, separate from the general HSWA duties.

Factor 2: The substances and materials you work with

If your business handles chemicals, dust, fumes, biological agents or other hazardous substances, the Control of Substances Hazardous to Health Regulations 2002 (COSHH) is likely to apply — regardless of your sector. This is not limited to obviously “industrial” settings; hairdressers, cleaners, print shops, laboratories and even offices using certain equipment can fall within scope. Applicability depends on the substance itself, how it is used and stored, and the level of exposure risk — not on your business type. Where lead or asbestos are involved specifically, separate dedicated regulations apply on top of COSHH.

Factor 3: Equipment and machinery in use

The Provision and Use of Work Equipment Regulations 1998 (PUWER) generally applies wherever machinery, tools or equipment are used for work — from industrial plant to a simple stepladder or a piece of office equipment. Where lifting equipment is involved (hoists, forklifts, lifts), the Lifting Operations and Lifting Equipment Regulations 1998 (LOLER) also applies, and pressure systems bring in the Pressure Systems Safety Regulations 2000. The trigger here is the presence and use of the equipment itself, not the sector you operate in.

Factor 4: Your premises and how they are used

The type of premises you occupy, and how they are used, brings separate legislation into play:

A business operating from a warehouse, a shop, a construction site or a shared office block may each face different obligations relating to the physical environment, even where their core work activity is otherwise similar.

Factor 5: The size and structure of your business

Some duties scale with headcount. Under the Management of Health and Safety at Work Regulations 1999, employers with five or more employees must record significant findings of their risk assessments in writing and have a written health and safety policy. Businesses below that threshold still carry the same underlying legal duty to manage risk — they simply have lighter documentary requirements. Separately, if you employ anyone, you are generally required to hold Employers’ Liability Insurance under the Employers’ Liability (Compulsory Insurance) Act 1969, with limited exemptions.

Factor 6: Who is affected by your work

UK legislation does not only protect your direct employees. HSWA and related regulations also require you to consider contractors, visitors, and members of the public affected by your activities. This is particularly relevant if you:

  • Invite the public onto your premises (retail, hospitality, leisure)
  • Send staff to work on other organisations’ sites
  • Manage shared workspaces where multiple employers’ activities interact

The Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013 (RIDDOR) also applies broadly here — requiring certain injuries, diseases and dangerous occurrences to be reported to the HSE, regardless of whether the person affected was an employee.

Factor 7: Your sector-specific regulatory regime

Certain industries carry their own dedicated regulatory frameworks layered on top of general health and safety law, including:

  • Construction — CDM Regulations 2015
  • Agriculture — regulations covering machinery guarding, livestock handling and pesticides
  • Food businesses — food hygiene regulations sit alongside (not instead of) health and safety law
  • Healthcare — additional infection control and clinical waste regulations
  • Transport and logistics — drivers’ hours rules and vehicle-specific regulations

These sector-specific rules typically sit alongside general legislation like HSWA and the Management Regulations, rather than replacing them.

Factor 8: Enforcement authority and regional variation

In Great Britain, enforcement is split between the HSE (typically for higher-risk sectors like construction, manufacturing and agriculture) and local authorities (typically for offices, retail and hospitality) — it is worth knowing which applies to your business, as this affects who you report incidents to and who may inspect your premises. Note also that Northern Ireland has its own health and safety legislative framework, enforced by the Health and Safety Executive for Northern Ireland (HSENI), which mirrors but is legally separate from GB law. Businesses operating across the UK should check they are not assuming GB regulations automatically extend to Northern Ireland.

Putting it together: a practical approach

Rather than trying to memorise every regulation that might apply, it is more effective to map your business against these factors systematically:

  1. List your work activities — every task carried out by staff, not just the “main” job.
  2. List the substances, equipment and materials involved in each activity.
  3. Map your premises types and how each is used, including shared or third-party sites.
  4. Check your headcount against the five-employee threshold for written documentation.
  5. Identify who else is affected — contractors, visitors, the public.
  6. Check for sector-specific regimes relevant to your industry.
  7. Confirm your enforcing authority (HSE or local authority) and whether Northern Ireland rules apply.

Working through this list will usually surface a shortlist of applicable regulations that goes well beyond HSWA’s general duties alone. Because legislation is periodically updated, it is worth revisiting this exercise whenever your activities, premises or workforce change significantly — and consulting a qualified health and safety adviser or solicitor if you are uncertain how a specific regulation applies to your circumstances.

Getting this right is not just about compliance for its own sake. Understanding exactly which legislation applies to your business is the foundation for building risk assessments, policies and training that address the hazards your people actually face — rather than a generic checklist that misses what matters most.

Determining which legislation is applicable in your business can be complicated and time consuming, although the Health and Safety Executive acknowledges that businesses need to identify the laws relevant to their particular industry and activities.

We identify the health & safety legislation relevant to your specific activities and produce a bespoke legislation register.  We can also provide a regular update service so that you can focus on running your business.  If you would like a quotation or more information about the services we offer, please contact us.

Do I really need a legislation register?

A legislation register is a critical component of any robust corporate governance framework. In an increasingly complex regulatory landscape, organisations must actively track, evaluate, and fulfil their legal obligations. Integrating a centralised legal register into your management system ensures continuous compliance, mitigates operational risk, and satisfies the rigorous requirements of international standards like ISO 9001, ISO 14001, and ISO 45001 (previously OHSAS 18001).

auditor with clipboard
A legislation register with ensure your business is prepared for change

The Strategic Value of a Legislation Register in ISO Management Systems

Modern corporate governance demands a proactive approach to regulatory risk. Organisations can no longer afford to treat legal compliance as an afterthought or a reactive exercise. To achieve long-term commercial resilience, executive leadership must embed a structured legislation register directly into the core of their business management frameworks.

A legislation register—often referred to as a legal register—is a comprehensive database that identifies, organises, and monitors all statutory, regulatory, and contractual obligations applicable to an organisation’s operations. Far from being a static document, it serves as a dynamic compliance anchor that protects businesses from litigation, financial penalties, and reputational damage.

For enterprises operating under international management standards, maintaining this register is not merely a best practice; it is a foundational requirement.

Aligning Legal Registers with ISO Standards

International standards established by the International Organisation for Standardisation (ISO) place significant emphasis on compliance management. A well-maintained legislation register serves as definitive evidence that an organisation understands and actively manages its legal landscape.

1. ISO 9001: Quality Management Systems (QMS)

While ISO 9001 focuses primarily on consistently meeting customer expectations and enhancing satisfaction, it explicitly intersects with statutory and regulatory mandates. Clause 1.1 states that the standard applies to organisations needing to demonstrate their ability to consistently provide products and services that meet both customer and applicable statutory and regulatory requirements.

A legislation register ensures that the legal parameters governing product safety, consumer protection, and industry-specific manufacturing laws are clearly defined and mapped to operational quality controls.

2. ISO 14001: Environmental Management Systems (EMS)

Under ISO 14001, the management of environmental compliance obligations is a strict, mandatory requirement. Clause 6.1.3 demands that organisations determine and have access to the compliance obligations related to their environmental aspects. Furthermore, Clause 9.1.2 requires planned evaluations of compliance status.

An environmental legislation register provides the exact framework needed to track complex rules concerning emissions, waste disposal, hazardous material handling, and resource consumption. Without it, verifying adherence during a third-party ISO audit is virtually impossible.

3. ISO 18001 / ISO 45001: Occupational Health and Safety (OH&S)

Historically, OHSAS 18001 set the global benchmark for workplace safety, requiring organisations to identify and access applicable legal requirements. This standard has since been succeeded and elevated by ISO 45001, which maintains an even stricter focus on legal frameworks. Clause 6.1.3 of the modern OH&S standard requires the systematic determination of legal and other requirements, while Clause 9.1.2 mandates periodic compliance evaluations.

A safety-focused legislation register tracks building regulations, machine guarding standards, personal protective equipment (PPE) mandates, and workers’ compensation laws, fundamentally reducing workplace incidents and liability.

Core Operational Benefits of a Centralised Legal Register

  • Risk Mitigation: Isolates potential compliance breaches before they result in punitive fines, operational shutdowns, or executive prosecution. Valued by regulatory bodies such as the Health and Safety Executive, the Environment Agency and others.
  • Streamlined Auditing: Provides internal and external auditors with immediate, organised, and verifiable evidence of regulatory adherence.
  • Operational Continuity: Centralises specialised regulatory knowledge, ensuring corporate compliance protocols survive leadership transitions or personnel changes.
  • Proactive Adaptability: Establishes a systematic review cycle that alerts management to upcoming legislative adjustments, giving operations ample time to adapt.
Legal register flow chart

Best Practices for Execution

An effective legislation register must transcend a simple list of titles. To deliver true corporate utility, it should include:

  • Specific Granularity: Reference exact sections, clauses, and amendments relevant to the business.  Ensure the register entries are relevant to your business, off the shelf update services may not provide this level of detail.
  • Process Mapping: Link every legal requirement directly to an internal policy, operating procedure, or specific asset.
  • Assigned Accountability: Designate a qualified internal owner responsible for monitoring each piece of legislation.
  • Evidence Log: Maintain a digital audit trail proving when compliance was last evaluated and verified.
  • Maintain the register: once your register is in place, ensure that it is regularly maintained and updated.  Laws and regulations change and your business must be aware and plan for such changes.

Conclusion

A legislation register is an indispensable component of successful ISO 9001, ISO 14001, and ISO 45001 management systems. By transforming legal compliance from an administrative burden into an organised asset, organisations safeguard their operational integrity, validate their commitment to corporate responsibility, and build a sustainable foundation for international commercial growth.

Need Help Implementing This?

If you require expert assistance preparing or maintaining a legal register for your business, please reach out to the Ashbrooke advisory team today.

Managing Home Workers’ Health & Safety: An Employer’s Guide

As an employer, you hold the exact same legal health and safety responsibilities for remote staff working at home as you do for on-site office workers. According to the Health and Safety Executive (HSE) guidelines, these duties extend to all long-term home workers, hybrid staff splitting time with the office, and temporary home workers managing short-term restrictions. While risks are typically low, proactive management protects your business and your people.

Female worker at home using laptop
Are your employees safe working at home?

Identifying Key Areas of Remote Work Risk

What are the primary hazards when staff work from home? While remote environments are generally low risk, the HSE outlines three specific categories employers must address:

  • Mental well being: Stress, isolation, and poor mental health.
  • Ergonomics: Improper use of display screen equipment (DSE).
  • Physical Space: Hazards within the immediate working environment.

Conducting a Remote Worker Risk Assessment

Do employers need to visit staff homes?

In most cases, employers do not need to physically visit a home to complete a risk assessment, provided they can ensure a healthy setup remotely. However, a physical visit may be required under certain circumstances:

  • To accommodate a worker with a disability or specific medical requirement.
  • If the work activity introduces severe hazards, such as specialised machinery, tools, or chemicals.

Practical steps for remote risk discovery

To effectively assess your work-from-home team without entering their properties, utilise these direct strategies:

  • Distribute digital self-assessment questionnaires and home configuration checklists.
  • Schedule mandatory phone or video consultations to talk through setups individually.
  • Outline clear parameters regarding the type of work being performed and the duration of the tasks.

Note: If your risk assessment highlights a need for corrective action or specialised equipment, your workers cannot be financially charged for these.

What if a home is unsafe for remote work?

If an employer determines that a home is not a suitable work environment and reasonably practicable protective measures cannot be implemented, alternative arrangements must be mutually agreed upon. This includes providing dedicated workspace inside the office or arranging another safe, local work location.

Managing Employee Stress and Mental Health at Home

Remote working can place unique psychological demands on your staff. Deprived of day-to-day social contact, remote employees are highly vulnerable to isolation, which can trigger severe pressure or aggravate pre-existing mental health conditions.

Practical ways to combat remote isolation

Because it is harder to recognise behavioural symptoms of stress without face-to-face interaction, employers should integrate structured checkpoints:

  • Open Dialogue: Talk openly with employees about stress, and actively involve them in building your corporate stress risk assessments.
  • Frequent Contact: Build in regular keep-in-touch meetings via one-to-one phone check-ins and accessible team video calls.
  • Occupational Support: Frequently remind remote staff of available mental health resources, corporate counselling, or employee assistance programs.

Promoting a Healthy Work-Life Balance

Remote staff frequently work longer hours, leading to severe burnout. employers should regularly audit workloads and training needs to ensure timelines remain realistic. Actively encourage your remote workforce to take structured screen breaks, use their allocated annual leave, and log off completely without feeling an obligation to monitor emails outside of normal working hours.

Complying with DSE Regulations at Home

Employers must protect remote workers from the physical strains associated with laptops and desktop computers under the Display Screen Equipment (DSE) regulations.

Streamlining the DSE assessment

If the regulations apply to your staff, a dedicated DSE assessment must be executed for both their home setup and office workstation. Employees can complete these as self-assessments once they are given proper training.

Your primary objectives are to ensure:

  • Workers can easily achieve a comfortable, sustainable, and ergonomically sound posture.
  • All hardware, peripherals, and equipment provided are fully functional and safe.

Employees do not necessarily require specialised office-grade furniture if their personal setups are ergonomically sound. However, if an individual’s personal furniture is inadequate, the employer must bridge the gap. Risks must be reduced so far as “reasonably practicable”—meaning you must balance the level of real risk against the cost, time, and trouble of the control measures.

Ensuring a Safe Physical Working Environment

Employers must take reasonable steps to verify that the home working environment itself is physically safe.

Electrical equipment and cable safety

While you are only legally liable for the specific electrical assets your company provides, you must ensure they are operated safely. Instruct workers to perform routine visual checks on sockets, plugs, and leads for signs of damage. Additionally, provide explicit guidance on the fire hazards associated with overloaded extension cables.

Mitigating slips, trips, and falls

Provide your team with practical advice on how to keep their immediate workspace clear of hazards. Remote workspaces should remain clear of floor obstructions, un-mopped spillages, and trailing equipment wires.

Emergency procedures and lone working

Ensure your remote team knows precisely what to do during an emergency. Supply them with a protocol document outlining emergency contact numbers, and maintain an updated emergency contact registry for every remote employee in case they become uncontactable. For staff operating with zero direct supervision, review the specialised lone-working safety tools hosted directly by the HSE.

How to report a home-based accident under RIDDOR

Not every home accident is a workplace incident. An injury or illness is only reportable under the Reporting of Injuries, Diseases and Dangerous Occurrences Regulations (RIDDOR) if it directly stems from:

  1. The specific work activity being carried out.
  2. The specialised equipment provided by the employer to complete that work.

Detailed reference criteria to evaluate home injuries can be found via the official health and safety portals.


Need Help Implementing This?

If you require expert assistance executing compliant risk assessments, DSE audits, or updated remote worker policies for your business, please reach out to the Ashbrooke advisory team today.

Second Fine in Under a Year Devastates Packaging Manufacturer

A plastic packaging manufacturer has been fined for the second time in less than a year after a worker suffered a severe crush injury when their hand was drawn into the rollers of an unguarded laminating machine at its site in Telford.

Reflex Flexible Packaging Limited was sentenced in November 2025 after an employee died when he became trapped in an unguarded machine at the company’s site in Langley Mill, Derbyshire. This latest case relates to a separate incident on 17 January 2025, at the company’s Telford premises, when a worker suffered serious injuries while cleaning an unguarded machine.

The machine and the rag caught between two in-running rollers
The machine and the rag caught between two in-running rollers

The worker, a laminator operative and shift supervisor employed by the company, was injured while cleaning a laminator machine at the company’s premises on Halesfield, Telford.

The worker was cleaning the machine’s unguarded rollers using rags after a production run had finished. As they cleaned the machine, a rag became caught between two in-running rollers and pulled their left hand into the nip point between them. Their hand was drawn into the machine up to the wrist.

A colleague immediately activated the emergency stop, allowing the worker to free their hand from the unguarded machine. They were taken to hospital with a severe crush injury. The worker underwent two operations on their left hand, spent four nights in hospital and later required physiotherapy to rebuild strength in the injured hand.

An investigation by the Health and Safety Executive (HSE) found that Reflex Flexible Packaging Limited had failed to ensure effective measures were in place to prevent access to the dangerous moving parts of the laminating machine. The machine was unguarded and presented a danger.

The company had failed to provide a fixed guard to prevent access to the in-running nip point between the rollers during cleaning operations. The HSE investigation also revealed that the company’s risk assessment and safe system of work were not suitable and sufficient. The cleaning operation had not been properly assessed and the risk of a worker being drawn into the machine during cleaning had not been identified. The safe system of work also failed to provide clear instructions regarding the use of the foot pedal to rotate the rollers during the cleaning process.

Photo of signage put in place following the incident.
Photo of signage put in place following the incident

HSE guidance states that employers must take effective measures to prevent access to dangerous parts of machinery. Where access to dangerous parts is foreseeable, employers should follow the hierarchy of control measures set out in the Provision and Use of Work Equipment Regulations 1998, giving priority to engineering controls such as fixed guarding wherever reasonably practicable.

Risk assessments should consider not only normal production activities, but also tasks such as cleaning, maintenance and repair where dangerous parts may become accessible to workers.

Work Equipment Guidance

The Provision and Use of Work Equipment Regulations 1998, often abbreviated to PUWER, place duties on people and companies who own, operate or have control over work equipment. PUWER also places responsibilities on businesses and organisations whose employees use work equipment, whether owned by them or not.  PUWER requires that equipment provided for use at work is:

  • suitable for the intended use
  • safe for use, maintained in a safe condition and inspected to ensure it is correctly installed and does not subsequently deteriorate
  • used only by people who have received adequate information, instruction and training
  • accompanied by suitable health and safety measures, such as protective devices and controls. These will normally include guarding, emergency stop devices, adequate means of isolation from sources of energy, clearly visible markings and warning devices
  • used in accordance with specific requirements, for mobile work equipment and power presses

Some work equipment is subject to other health and safety legislation in addition to PUWER. For example, lifting equipment must also meet the requirements of the Lifting Operations and Lifting Equipment Regulations 1998 (LOLER), pressure equipment must meet the Pressure Systems Safety Regulations 2000 and personal protective equipment must meet the Personal Protective Equipment at Work Regulations 1992 (PPE).

If your business or organisation uses work equipment or is involved in providing work equipment for others to use (e.g. for hire), you must manage the risks from that equipment. This means you must:

  • ensure the equipment is constructed or adapted to be suitable for the purpose it is used or provided for
  • take account of the working conditions and health and safety risks in the workplace when selecting work equipment
  • ensure work equipment is only used for suitable purposes
  • ensure work equipment is maintained in an efficient state, in efficient working order and in good repair
  • where a machine has a maintenance log, keep this up to date
  • where the safety of work equipment depends on the manner of installation, it must be inspected after installation and before being put into use
  • where work equipment is exposed to deteriorating conditions liable to result in dangerous situations, it must be inspected to ensure faults are detected in good time so the risk to health and safety is managed
  • ensure that all people using, supervising or managing the use of work equipment are provided with adequate, clear health and safety information. This will include, where necessary, written instructions on its use and suitable equipment markings and warnings
  • ensure that all people who use, supervise or manage the use of work equipment have received adequate training, which should include the correct use of the equipment, the risks that may arise from its use and the precautions to take
  • where the use of work equipment is likely to involve a specific risk to health and safety (eg woodworking machinery), ensure that the use of the equipment is restricted to those people trained and appointed to use it
  • take effective measures to prevent access to dangerous parts of machinery. Unguarded machinery parts can present a danger, This will normally be by fixed guarding but where routine access is needed, interlocked guards (sometimes with guard locking) may be needed to stop the movement of dangerous parts before a person can reach the danger zone. Where this is not possible, such as with the blade of a circular saw, it must be protected as far as possible and a safe system of work used. These protective measures should follow the hierarchy laid down in PUWER regulation 11(2) and the PUWER Approved Code of Practice and guidance or, for woodworking machinery, the Safe use of woodworking machinery: Approved Code of Practice and guidance
  • take measures to prevent or control the risks to people from parts and substances falling or being ejected from work equipment, or the rupture or disintegration of work equipment
  • ensure that the risks from very hot or cold temperatures from the work equipment or the material being processed or used are managed to prevent injury
  • ensure that work equipment is provided with appropriately identified controls for starting, stopping and controlling it, and that these control systems are safe
  • where appropriate, provide suitable means of isolating work equipment from all power sources (including electric, hydraulic, pneumatic and gravitational energy)
  • ensure work equipment is stabilised by clamping or otherwise to avoid injury
  • take appropriate measures to ensure maintenance operations on work equipment can be carried out safely while the equipment is shut down, without exposing people undertaking maintenance operations to risks to their health and safety

When providing new work equipment for use at work, you must ensure it conforms with the essential requirements of any relevant product supply law (for new machinery this means the Supply of Machinery (Safety) Regulations 2008). You must check it:

  • has appropriate conformity marking and is labelled with the manufacturer’s details 
  • comes with a Declaration of Conformity
  • is provided with instructions in English
  • is free from obvious defects – and that it remains so during its working life

If you require health, safety or environmental advice for your business, please contact one of the Ashbrooke team.