The Difference Between Generic and Bespoke Legal Registers

Why a one-size-fits-all approach to legal compliance leaves organisations exposed — and what a register built around your actual operations gives you instead.

If your organisation is subject to health, safety, or environmental law — and almost every organisation is — you need a legal register. It’s the document that tells you which legislation applies to your operations, what it requires of you, and whether you’re actually compliant. But not all legal registers are built the same way, and the difference between a generic template and a bespoke register isn’t cosmetic. It’s the difference between a document that looks like due diligence and one that actually protects your organisation.

What Is a Legal Register?

A legal register is a structured record of the laws, regulations, and codes of practice that apply to an organisation, typically covering health and safety, environmental, and related compliance obligations. It’s a cornerstone requirement of recognised management system standards, including ISO 9001, ISO 45001 and ISO 14001, and it’s usually the first document an auditor or regulator asks to see. On paper, every legal register looks similar: a list of legislation, a summary of requirements, a compliance status. In practice, how that list is built determines whether the register is a genuinely useful management tool or a box-ticking exercise.

The Trouble With Generic Legal Registers

Generic legal registers are typically off-the-shelf templates or subscription database exports, built to cover an entire sector or industry in one document. They’re inexpensive, quick to obtain, and easy to see the appeal of — but that convenience comes at a real cost:

  • They list legislation that may have nothing to do with your actual activities, sites, or risk profile, burying the requirements that genuinely matter under dozens that don’t.
  • They rarely reflect the specific jurisdictions, licences, or permits your organisation holds, particularly for organisations operating across Great Britain, Northern Ireland, the Isle of Man, or the Republic of Ireland, where legal frameworks diverge significantly.
  • They’re built for updating on a fixed schedule rather than in response to your organisation’s changes — a new site, a new process, a new piece of equipment — so they drift out of date the moment your operations move.
  • They describe legal duties in abstract terms, without translating them into what compliance actually looks like for your sites, your equipment, and your people.
  • They offer no meaningful gap analysis — you’re left to work out for yourself whether you actually comply with each requirement.

The result is a register that satisfies the letter of the audit requirement — “yes, we have a legal register” — without doing the job a legal register exists to do: giving your organisation a clear, current, accurate picture of its legal exposure.

Bespoke vs generic legal register, which is best?
Photo courtesy of Pixabay tumisu-audit

A bespoke legal register demonstrates to auditors that you actually know your legal obligations.

Why a Bespoke Legal Register Is the Only Register Worth Having

A bespoke legal register is built from the ground up around your organisation: your sites, your activities, your industry sector, your jurisdictions, and your risk profile. Rather than starting from a generic list and hoping it fits, it starts from your operations and identifies exactly which legislation applies — and, critically, what that legislation actually requires you to do about it. The advantages compound quickly:

  • Relevance: every entry has a direct line to something your organisation actually does, so nothing important gets lost in noise that doesn’t apply to you.
  • Accuracy across jurisdictions: legislation is mapped to the specific jurisdiction — GB, NI, Isle of Man, or ROI — that each site operates under, rather than treated as a single homogeneous “UK law” list.
  • A genuine compliance status: each requirement is assessed against evidence from your organisation, so you know — not guess — where you stand, and where the gaps are.
  • Built-in gap analysis and action planning: a bespoke register doesn’t just flag non-compliance, it gives you a prioritised route to closing it.
  • Living, current content: as legislation changes or your organisation changes — a new site, a new process, an amended regulation — the register is updated to reflect it, so it never becomes a snapshot of a moment that’s already passed.
  • Audit and due diligence confidence: a bespoke register demonstrates, to auditors, regulators, insurers, and clients, that your organisation understands and manages its legal obligations — not that it purchased a document that says it does.

In short: a generic register tells you what the law says. A bespoke register tells you what the law means for you — and whether you’re meeting it.

FEATURES

Generic Legal Register

Bespoke Legal Register


Identifies only relevant laws


Focused on the actual business


Relevant and easy to understand


A practical management tool


Includes sector specific requirements


Demonstrates that you understand your obligations

The Bottom Line

A legal register is only as valuable as its accuracy and relevance to your organisation. A generic template can create a false sense of security — the appearance of compliance without the substance of it — and that gap tends to surface at the worst possible moment: during an incident investigation, a regulatory visit, or a client’s due diligence review. A bespoke legal register, developed and maintained by health and safety professionals who understand your sector and your sites, is an investment in genuine legal certainty, not just a document for the audit file.

If your organisation is currently relying on a generic register — or doesn’t have one at all — talk to us about building a bespoke legal register tailored to your operations, sites, and jurisdictions. It’s the foundation every other part of your compliance management sits on, and it’s worth getting right.

What Happens if Your Legal Register is Out of Date?

A legislation register—or legal register—serves as the compliance anchor of an organisation’s corporate governance structure and management system. Designed to identify, organise, and monitor all statutory duties and regulatory obligations applicable to an organisation’s operations, it acts as the baseline for legal adherence. However, maintaining a legal register is not a one-time administrative task; it requires active upkeep to retain its utility.

The key risk of an outdated legal register is that it gives executive management a false picture of the organisation’s true legal obligations and actual compliance level. While an outdated register may not immediately lead to criminal prosecution, relying on obsolete legal information creates subtle, compounding vulnerabilities across operational management, internal auditing, and ISO management systems.

Understanding the operational consequences of an outdated legal register highlights why static compliance documents fail to protect modern enterprises.


1. Missing Critical Legislative Changes and Statutory Amendments

Health, safety, and environmental statutory frameworks across Great Britain, Northern Ireland, the Isle of Man, and the Republic of Ireland are in constant motion. Regulators and parliaments amend existing legislation far more frequently than they enact entirely new primary Acts.

When a legal register is not updated regularly, the following issues occur:

  • Unrecorded Statutory Amendments: An entry in a register may list the correct title of an Act or Regulation, yet remain silently out of date because an amending statutory instrument altered a exposure threshold, broadened a legal definition, or moved a mandatory reporting deadline.
  • Retaining Revoked Legislation: Failing to remove repealed or revoked legislation creates unnecessary administrative clutter. This wastes valuable time during internal checks and misleads staff into enforcing duties that no longer exist under law.
  • Overlooking Updated Regulatory Guidance: Regulators such as the Health and Safety Executive (HSE) and the Environment Agency (EA) frequently update Approved Codes of Practice (ACOPs) and guidance documents. Although guidance is not always statutory law, it defines the legal benchmark expected by courts and enforcement inspectors. Missing these updates leaves operational procedures aligned with obsolete standards.

2. Flawed Compliance Assessments and Distorted Evaluations

Under international management standards such as ISO 14001 (Clause 9.1.2) and ISO 45001 (Clause 9.1.2), organisations must conduct periodic evaluations of their legal compliance status. A compliance evaluation tests operational reality against the parameters documented in the legal register.

If the underlying legal register contains out-of-date information, any subsequent compliance assessment becomes fundamentally flawed. Evaluating site practices against superseded statutory requirements generates inaccurate compliance scores. Managers receive reports indicating complete compliance, unaware that newly enacted statutory duties, altered discharge limits, or updated permit conditions have gone completely unassessed.


3. Failure to Identify New Obligations from Business Triggers

Legislative updates represent only one side of legal register maintenance; internal organisational changes represent the other. Updating a register solely on an annual schedule inevitably causes the document to lag behind internal operational developments.

A failure to execute trigger-based reviews means that routine commercial changes generate unmanaged legal exposure:

  • New Equipment and Machinery: Installing new plant or lifting machinery introduces obligations under the Provision and Use of Work Equipment Regulations 1998 (PUWER) or the Lifting Operations and Lifting Equipment Regulations 1998 (LOLER).
  • New Chemical Substances: Introducing new raw materials or cleaning agents can trigger the Control of Substances Hazardous to Health Regulations 2002 (COSHH) or REACH obligations.
  • Premises and Physical Footprint: Moving to new sites or altering existing buildings brings different fire safety orders, planning consents, and building regulations into scope.
  • Environmental Permit Variations: Varied abstraction consents, modified trade effluent limits, or altered waste classifications must be entered into the register the moment they are granted.
  • Cross-Border Expansion: Expanding operations into a new jurisdiction—such as moving from Great Britain into Northern Ireland or the Republic of Ireland—introduces an entirely separate body of legal requirements rather than a variation of existing rules.

Without a system that links operational changes directly to legal register reviews, new legal duties remain unidentified and unmanaged.


4. Incorrect Regulatory Risk and Misleading Executive Confidence

Executive leadership relies on corporate compliance reporting to evaluate organisational risk and allocate resources effectively.

An outdated legal register distorts this governance feedback loop. It provides leadership with a false sense of security, leading executives to believe that all statutory liabilities are isolated and controlled. In reality, unmonitored regulatory shifts accumulate quietly. This distorted view of regulatory risk can lead management to allocate compliance budgets in error, bypass necessary operational controls, or omit vital safety training.


5. Third-Party Audit Findings and ISO Non-Conformities

For organisations certified to ISO 9001, ISO 14001, or ISO 45001, the legal register is one of the most rigorously examined elements during third-party certification and surveillance audits.

Third-party auditors routinely evaluate legal registers using two distinct approaches:

  1. Top-Down Auditing: The auditor inspects a physical aspect or hazard on site (such as a chemical store, timber workshop, or waste area) and checks whether the corresponding statutory requirements and permit conditions are correctly detailed in the legal register.
  2. Bottom-Up Auditing: The auditor selects a specific entry within the legal register and requests live physical evidence demonstrating how that requirement is fulfilled on the ground.

If an auditor discovers that a register lacks recent legislative amendments, omits applicable permit conditions, or references revoked statutes, a formal non-conformity will be raised against Clause 6.1.3. Treating the legal register as a static, one-time exercise remains one of the most frequent causes of ISO audit failures.


6. Difficulty Demonstrating Legal Compliance and Due Diligence

Maintaining compliance requires more than listing statutory titles; it demands clear evidence of active oversight. A defensible legal register entries should link each statutory clause directly to an internal operating procedure, an assigned internal owner, and a verifiable evidence log.

If a regulatory inspector from the Health and Safety Executive (HSE) or Environment Agency (EA) inspects a site, or if an insurer evaluates an operational claim, an outdated register fails to demonstrate due diligence. Presenting a static document that has not been updated or audited within the preceding twelve months demonstrates a breakdown in compliance governance, making it difficult to prove that the business actively manages its statutory duties.


7. Breakdown of the Plan-Do-Check-Act Management Framework

Recognised management system frameworks—such as ISO 45001 and HSG65—operate on a continuous Plan-Do-Check-Act (PDCA) cycle.

Plan do check act. Legal register out of date?
Plan do check act cycle

The legal register forms the core foundation of the Plan stage. It defines what the organisation must comply with. If the Plan stage relies on obsolete statutory parameters:

  • Operational controls (Do) are built around incorrect standards.
  • Compliance audits (Check) evaluate performance against out-of-date criteria.
  • Corrective actions (Act) fail to address actual legal exposure.

When the legal register is disconnected from live operational checks, the entire management system fails to function as intended.


Establishing an Effective Legal Register Review Protocol

To prevent a legal register from becoming out of date, organisations should implement a dual-track review process:

  • Scheduled Legislative Reviews: Establish a fixed review schedule (typically quarterly) to monitor legislative changes, new statutory instruments, and updated regulator guidance across all operating jurisdictions.
  • Trigger-Based Internal Reviews: Integrate legal register review checklists directly into corporate change-management processes. Any change in business activities, premises, machinery, chemical usage, or environmental permits should prompt an immediate review.
  • Accountability and Audit Trails: Assign clear internal ownership for every entry and maintain a detailed audit trail showing when each requirement was last evaluated.

By pairing scheduled legislative monitoring with internal change management, executive leadership can ensure that the legal register remains an accurate, defensible reflection of the organisation’s legal duties.  To get help with your legal register, please contact one of our team.

How Often Should a Legal Register Be Updated?

How often should a legal register be updated? There is no single answer that fits every organisation, but there is a wrong answer: updating it once a year and hoping nothing important happened in between. A legal register is only useful if it reflects the law as it stands today, and the law — along with your business — rarely stands still.

The honest answer is that a legal register needs two update cycles running side by side: a scheduled review (commonly quarterly) to catch legislative change, and a trigger-based review that fires whenever something changes inside your own organisation. Below is what should prompt each type of update, and why skipping either one leaves gaps.

Scheduled reviews: keeping pace with legislative change

Health and safety and environmental law changes constantly across every jurisdiction — Great Britain, Northern Ireland, the Isle of Man and the Republic of Ireland all move independently, and a register built for one will not automatically cover another. A quarterly review is the practical minimum for most organisations; higher-risk sectors (chemicals, waste, construction, food) often benefit from monthly monitoring. Each cycle should specifically check for:

New legislation

Acts, regulations and statutory instruments do not announce themselves. New legislation should be added to the register as soon as it is in force (or, where lead time allows, flagged ahead of its commencement date so you are not scrambling to comply on day one).

Amendments to existing legislation

Legislation is amended far more often than it is replaced outright — a threshold changed, a definition widened, a deadline moved. If your register only lists the original instrument, it is quietly out of date the moment an amending regulation takes effect, even though the entry still “looks” current.

Repealed and revoked legislation

Just as important as adding new law is removing what no longer applies. A register cluttered with revoked instruments does not just look untidy — it wastes audit time and can mislead someone into thinking a duty still exists when it is been withdrawn.

New guidance

Approved Codes of Practice, Health and Safety Executive (HSE) and Environment Agency (EA) guidance, and equivalent guidance from Northern Ireland, the Isle of Man and Ireland’s regulators are not always legally binding, but they set the standard regulators and courts expect you to meet. Guidance updates should be tracked alongside the legislation they relate to.

Is your legal register regularly reviewed or just left on a shelf?

Trigger-based reviews: keeping pace with your own business

Legislative monitoring only tells half the story. The other half is recognising when something inside your organisation changes the law you are subject to. These triggers should prompt an immediate register review, not wait for the next scheduled cycle:

  • Changes in business activities — a new process, service line, or way of working can bring entirely new legal duties into scope.
  • New premises — different buildings mean different building regulations, fire safety duties, planning conditions and local authority requirements.
  • New equipment — new plant or machinery can trigger PUWER, LOLER, pressure systems, or work equipment regulations that weren’t previously relevant.
  • New chemicals or substances — introducing a new substance can pull in COSHH, REACH, CLP, or storage and transport requirements, and may affect permit conditions.
  • Changes to environmental permits — a varied permit, a new abstraction or discharge consent, or a change in waste classification all need reflecting in the register the moment they’re granted or amended.
  • Changes to applicable jurisdictions — opening a site, taking on contracts, or employing staff in a new jurisdiction (say, expanding from Great Britain into Northern Ireland or the Republic of Ireland) means an entirely separate body of law applies, not a variation on the one you already have.

Building both cycles into one process

The most effective legal registers treat these two review types as complementary, not alternatives:

  1. Set a fixed schedule (quarterly is a sensible default) for legislative monitoring across every jurisdiction you operate in.
  2. Build a trigger checklist into change-management processes — procurement, facilities, HR and operations should all know to flag the business changes listed above.
  3. Assign ownership so it is clear whose job it is to action each type of update, not just who compiles the register.
  4. Keep an audit trail of when the register was reviewed and what changed, which matters as much to auditors and regulators as the register’s content itself.

The bottom line

A legal register updated only once a year, on a fixed date, will always be behind — both the law and the business move faster than that. Pair a quarterly (or more frequent) legislative review with a trigger-based process for internal change, and the register stays what it is meant to be: an accurate, defensible record of what applies to you right now.

Keeping a legal register current across multiple jurisdictions is exactly what our quarterly legislation updates are designed to support — get in touch to find out how we can help.

The Essential Guide to Environmental Permit Management Systems

Executive Summary

An environmental permit management system provides a structured framework of procedures to minimise pollution risks from permitted activities.

For regulated waste management, mining, or installation facilities, maintaining a written management system is a regulatory requirement.

This document outlines statutory compliance frameworks, risk assessments, site planning, and operational records to satisfy Environment Agency expectations.

Regulatory context and application requirements

1. Regulatory Context and Application Requirements – Environmental permit management system

The scope and submission requirements depend on the nature of the application.

Moreover, the complexity of site operations determines the system needs, including • Environmental permit management system.

Additionally, Standard Rules permits the – Environmental permit management system.

  • Risk Identification: Specific operational risks are pre-determined within generic risk assessments.
  • Submission Protocol: You do not need to submit the system documentation during the application phase.
  • Deployment Deadline: The complete management system must be fully operational prior to commencing site activities.
  • Regulatory Assessment: Documentation is typically evaluated during the pre-operation site inspection by an Environment Agency officer.
  • Combustible Waste Provision: Standard rules applications involving combustible waste storage require the concurrent submission of a robust Fire Prevention Plan (FPP).
Man sampling water

We manage bespoke permits through the environmental permit management system.

  • Risk Identification: Operational hazards must be explicitly identified via a site-specific risk assessment.
  • Submission Protocol: A comprehensive summary of the management system must be included as part of the formal application pack.
  • Water & Groundwater Exemptions: Standalone water discharge or groundwater activity applications (Forms B6.5 or B6.6) do not require advance submission of the management system summary, but the system must be fully implemented prior to operation.

2. Certified Environmental Management System (EMS) Standards. Additionally, they align with the environmental permit management system to meet regulatory requirements.

For large-scale or high-risk facilities, such as industrial installations and hazardous waste processing operations, the Environment Agency favours these systems.

Moreover, they are part of the environmental permit management system and are built around recognised international frameworks.

Utilising an independently verified system enhances regulatory confidence and can reduce inspections under the OPRA methodology.

As part of the environmental permit management system, operators must state if their system is modelled on accredited standards. Additionally, they should indicate whether it is modelled on any listed standards.

Note: Accredited certification (verified by UKAS) demonstrates robust governance, but it does not absolve the operator of liability.

However, this does not absolve the operator of liability for individual permit breaches within the environmental permit management system.

3. Site Infrastructure and Spatial Planning Requirements are addressed within the environmental permit management system.

Operators must compile scaled, detailed site plans showing where permits and exemptions take place within the environmental permit management system. Additionally, high-risk or complex sites frequently require multiple standalone drawings to fulfil regulatory requirements.

Core infrastructure components (Waste, Installations, and Mining) are central to the environmental permit management system.

Site plans for the management system must clearly mark the locations of the following assets.

Additionally, this relates to the environmental permit management system.

  • Structural Assets: Buildings, treatment facilities, incinerators, silos, and perimeter security fencing.
  • Hazardous Storage: Containment areas for oils, fuel tanks, chemical bunds, and raw waste stock.
  • Emergency Equipment: Spill kits, absorbents, and critical emergency response machinery.
  • Logistics Access: Dedicated entry and exit pathways for emergency service vehicles.
  • Pollution Control Points: Environmental monitoring stations, sampling points, and inspection manholes.
  • Effluent Infrastructure: Trade effluent or sewage treatment plants and final discharge outfalls.
  • Historical Liabilities: Any parcels of land with known or suspected historical ground contamination.

Additionally, mapping of drainage and utilities supports the environmental permit management system for regulatory compliance.

Drainage networks require precise colour-coding and directional labelling. Additionally, implementing an environmental permit management system supports consistent labelling and compliance.

  • Foul and Combined Drainage: Must be marked clearly in red.
  • Surface Water Drainage: Must be marked clearly in blue.
  • Flow Mechanics: Plans must display water flow direction, discharge connection points (to sewer, soak-away, or watercourse), manhole covers, interceptor tanks, and isolating stop/diverter valves.
  • Utility Routing: Main inlets and distribution paths for mains water, gas, and electricity must be charted, with explicit positioning of water stop taps and utility isolation switches.

Additionally, standalone water discharge and groundwater activities are managed under the environmental permit management system.

Furthermore, for point-source water and groundwater authorisations, the site plan must isolate within the environmental permit management system.

  • The wastewater treatment infrastructure.
  • Statutory sample collection and monitoring points.
  • Mitigation infrastructure and environmental emergency equipment.
  • The defined surface water outlet or groundwater infiltration system.
  • The designated field boundaries for land-spreading activities (where applicable).

4. Operational Control Plans and Specific Sub-Systems for the environmental permit management system.

A compliant management system breaks down site operations into distinct phases.

Additionally, start-up, normal operation, and shut-down are the phases for the environmental permit management system.

Operators must identify the environmental risks associated with each sub-process and outline specific mitigation actions.

Waste storage plans are integral to the environmental permit management system and ensure safe, compliant operations.

Waste facility operators must document an explicit waste storage strategy detailing.

In addition, this record should be maintained in the environmental permit management system.

  • Maximum storage duration thresholds for every distinct waste streams.
  • Control measures to prevent emissions during extended storage.
  • Absolute volume limits and maximum pile heights for all stored materials.
  • Waste identification procedures and strict segregation protocols for incompatible materials.
  • Pre-acceptance and acceptance procedures to prevent the receipt of unpermitted waste.

The environmental permit management system manages Fire Prevention Plans (FPP).

Facilities storing combustible waste must submit a standalone, robust Fire Prevention Plan detailing prevention, detection, containment, and mitigation measures.

Within the environmental permit management system, the Environment Agency assesses these plans stringently against hourly review rates.

Consequently, failing to secure approval on initial submission significantly elevates regulatory costs.

Site Condition Reports (SCR) relate to the environmental permit management system.

For installations, waste operations, and mining permits, a Site Condition Report must be maintained throughout the lifecycle of the permit. This document logs historical spills, baseline land/groundwater data, and evidence verifying effectiveness in the environmental permit management system. It serves as the primary legal benchmark when applying to surrender a permit.

Standalone Environmental Management Documents cover the environmental permit management system and its related compliance.

Depending on site risks, the Environment Agency will require separate, standalone document submissions for individual environmental vectors.

Consequently, this enables the environmental permit management system to support distinct internal specialist reviews.

  • Odour Management Plan (OMP)
  • Emissions Management Plan (EMP)
  • Noise and Vibration Management Plan (NVMP)
  • Pests Management Plan (PMP)

5. Additionally, Contingency, Emergency, and Climate Change Resilience within the environmental permit management system.

Accident prevention and risk mitigation are essential in the environmental permit management system.

Operators must maintain emergency contingency frameworks that assess the likelihood and consequences of unexpected disruptions.

Additionally, the system must outline proactive preventative actions and emergency response procedures for environmental permit management system.

  • Core equipment breakdowns or sudden utility failures.
  • Enforced or emergency facility shutdowns.
  • Vandalism, security breaches, and deliberate damage.
  • Fires, flash flooding, and severe weather anomalies.

Emergency documentation must include formal accident logging forms, emergency contact directories, and a transparent review schedule. Additionally, operators should actively engage local emergency services and verify flood warning registrations within the environmental permit management system.

Cyber security protocols are essential and an environmental permit management system can support compliance and business continuity.

Modern waste infrastructure and environmental monitoring systems rely heavily on automated computer control systems. Additionally, operators must integrate risk controls aligned with NCSC guidelines to protect software in the environmental permit management system.

Climate Change Adaptation Strategy supports the environmental permit management system to enhance resilience.

In accordance with UK climate projections, operators must evaluate the long-term impact of severe weather shifts on permit compliance. Additionally, these shifts are relevant to the environmental permit management system.

  • Short-to-Medium Term: Operational processes must show resilience against a 2°C global mean temperature rise by 2050.
  • Long-Term Asset Planning: For long-lifecycle facilities, operators must evaluate potential risks up to a 4°C temperature rise by 2100.
  • Methodology: Risk assessments should leverage ISO 14090:2019 standards and the Environment Agency’s industry sector examples for climate adaptation.

6. Corporate Governance, Training, and Audits

Moreover, staff competence and training infrastructure supports operational effectiveness in the environmental permit management system.

For the environmental permit management system, compliance with the permit requires adequate resource allocation and clearly defined operational roles. Additionally, operators must establish formal procedures.

  • Assign and document individual technical competence responsibilities.
  • Verify external contractor credentials and internal staff qualifications.
  • Maintain central registries of regulatory certifications, safety inductions, and refresher training.

Public Information Provisions outline the environmental permit management system.

Waste and installation permits carry a statutory obligation.

Maintain a clearly visible, weatherproof notice board at the site entrance as part of the environmental permit management system.

The board must display:

  • The registered permit holder’s corporate name.
  • A designated 24/7 emergency contact name and phone number.
  • Explicit confirmation that the facility is regulated by the Environment Agency.
  • The unique environmental permit reference number.
  • Statutory Environment Agency contact numbers: General Enquiries (03708 506506) and the Incident Hotline (0800 807060).

7. Record keeping, auditing, and system reviews support environmental permit management system.

This statutory record retention checklist applies to the environmental permit management system.

Operators must maintain structured archives documenting the active execution of the permit management system. Critical records include:

  • Current and historical environmental permits and legal variations.
  • Comprehensive risk assessments and secondary management plans (e.g., Mops).
  • Detailed calibration records for environmental monitoring and sampling equipment.
  • Logs of all internal compliance checks, audit findings, and remedial actions.
  • Formal complaints ledgers detailing root-cause investigations and resolution outcomes.

Waste Transfer Log Obligations

For every incoming delivery of waste material, operators must capture and preserve the following metrics:

  • Absolute quantity (verified weight or volume).
  • The statutory six-digit List of Waste (LoW) Code.
  • Origin location and complete corporate identity of the waste producer.
  • Date and time of arrival on site.
  • The original generation date (mandatory for odorous or putrescible waste streams).
  • Detailed containment logs for any rejected or quarantined materials.

Mandatory System Review Triggers

A permit management system is a dynamic document. It must be updated immediately upon the occurrence of any of the following events:

  • Technical modifications to onsite machinery, infrastructure, or operational capacities.
  • The submission of an application to vary the existing environmental permit.
  • Post-incident reviews following a site accident, permit breach, or formal complaint.
  • The introduction of new environmental controls to mitigate an emerging risk.

8. Site Closure and Permit Surrender

Environmental permits cannot be abandoned unilaterally when operations cease. Legal obligations remain active until the Environment Agency formally approves a Permit Surrender Application.

For landfills and Category A mining waste facilities, a transitional period of site closure applies. During this phase, operators must maintain active emissions monitoring regimes and submit final site closure updates via the Site Condition Report, proving conclusively that the land and groundwater have been returned to a satisfactory state.

Technical Support and Consultancy

Developing, implementing, and defending a regulatory management system requires specialist technical oversight. For bespoke assistance with permit applications, Fire Prevention Plans, or standalone environmental management documents, contact our regulatory advisory team for professional consultation.

Do I really need a legislation register?

A legislation register is a critical component of any robust corporate governance framework. In an increasingly complex regulatory landscape, organisations must actively track, evaluate, and fulfil their legal obligations. Integrating a centralised legal register into your management system ensures continuous compliance, mitigates operational risk, and satisfies the rigorous requirements of international standards like ISO 9001, ISO 14001, and ISO 45001 (previously OHSAS 18001).

auditor with clipboard
A legislation register with ensure your business is prepared for change

The Strategic Value of a Legislation Register in ISO Management Systems

Modern corporate governance demands a proactive approach to regulatory risk. Organisations can no longer afford to treat legal compliance as an afterthought or a reactive exercise. To achieve long-term commercial resilience, executive leadership must embed a structured legislation register directly into the core of their business management frameworks.

A legislation register—often referred to as a legal register—is a comprehensive database that identifies, organises, and monitors all statutory, regulatory, and contractual obligations applicable to an organisation’s operations. Far from being a static document, it serves as a dynamic compliance anchor that protects businesses from litigation, financial penalties, and reputational damage.

For enterprises operating under international management standards, maintaining this register is not merely a best practice; it is a foundational requirement.

Aligning Legal Registers with ISO Standards

International standards established by the International Organisation for Standardisation (ISO) place significant emphasis on compliance management. A well-maintained legislation register serves as definitive evidence that an organisation understands and actively manages its legal landscape.

1. ISO 9001: Quality Management Systems (QMS)

While ISO 9001 focuses primarily on consistently meeting customer expectations and enhancing satisfaction, it explicitly intersects with statutory and regulatory mandates. Clause 1.1 states that the standard applies to organisations needing to demonstrate their ability to consistently provide products and services that meet both customer and applicable statutory and regulatory requirements.

A legislation register ensures that the legal parameters governing product safety, consumer protection, and industry-specific manufacturing laws are clearly defined and mapped to operational quality controls.

2. ISO 14001: Environmental Management Systems (EMS)

Under ISO 14001, the management of environmental compliance obligations is a strict, mandatory requirement. Clause 6.1.3 demands that organisations determine and have access to the compliance obligations related to their environmental aspects. Furthermore, Clause 9.1.2 requires planned evaluations of compliance status.

An environmental legislation register provides the exact framework needed to track complex rules concerning emissions, waste disposal, hazardous material handling, and resource consumption. Without it, verifying adherence during a third-party ISO audit is virtually impossible.

3. ISO 18001 / ISO 45001: Occupational Health and Safety (OH&S)

Historically, OHSAS 18001 set the global benchmark for workplace safety, requiring organisations to identify and access applicable legal requirements. This standard has since been succeeded and elevated by ISO 45001, which maintains an even stricter focus on legal frameworks. Clause 6.1.3 of the modern OH&S standard requires the systematic determination of legal and other requirements, while Clause 9.1.2 mandates periodic compliance evaluations.

A safety-focused legislation register tracks building regulations, machine guarding standards, personal protective equipment (PPE) mandates, and workers’ compensation laws, fundamentally reducing workplace incidents and liability.

Core Operational Benefits of a Centralised Legal Register

  • Risk Mitigation: Isolates potential compliance breaches before they result in punitive fines, operational shutdowns, or executive prosecution. Valued by regulatory bodies such as the Health and Safety Executive, the Environment Agency and others.
  • Streamlined Auditing: Provides internal and external auditors with immediate, organised, and verifiable evidence of regulatory adherence.
  • Operational Continuity: Centralises specialised regulatory knowledge, ensuring corporate compliance protocols survive leadership transitions or personnel changes.
  • Proactive Adaptability: Establishes a systematic review cycle that alerts management to upcoming legislative adjustments, giving operations ample time to adapt.
Legal register flow chart

Best Practices for Execution

An effective legislation register must transcend a simple list of titles. To deliver true corporate utility, it should include:

  • Specific Granularity: Reference exact sections, clauses, and amendments relevant to the business.  Ensure the register entries are relevant to your business, off the shelf update services may not provide this level of detail.
  • Process Mapping: Link every legal requirement directly to an internal policy, operating procedure, or specific asset.
  • Assigned Accountability: Designate a qualified internal owner responsible for monitoring each piece of legislation.
  • Evidence Log: Maintain a digital audit trail proving when compliance was last evaluated and verified.
  • Maintain the register: once your register is in place, ensure that it is regularly maintained and updated.  Laws and regulations change and your business must be aware and plan for such changes.

Conclusion

A legislation register is an indispensable component of successful ISO 9001, ISO 14001, and ISO 45001 management systems. By transforming legal compliance from an administrative burden into an organised asset, organisations safeguard their operational integrity, validate their commitment to corporate responsibility, and build a sustainable foundation for international commercial growth.

Need Help Implementing This?

If you require expert assistance preparing or maintaining a legal register for your business, please reach out to the Ashbrooke advisory team today.

Risk Management in the UK

Risk management is a critical aspect of any business or organisation, and in the UK, it is taken very seriously. The UK has a robust framework for risk management, guided by various institutions and regulations that ensure businesses can identify, assess, and mitigate risks effectively.

The Institute of Risk Management (IRM) is a leading body in the UK that provides internationally recognised qualifications, training, and research in risk management. Their commitment to developing risk management professionals is evident through their extensive resources and events that cater to enhancing skills and knowledge in the field.

The UK government also plays a significant role in establishing risk management principles. The “Orange Book” is a guidance document published by the Government Finance Function and HM Treasury, which lays out the concepts and processes for risk management in government organizations. It complements other publications, such as the “Green Book”, which offers advice on appraisal and evaluation.

Moreover, the Management of Health and Safety at Work Regulations 1999 outlines the minimum requirements for risk assessment in the workplace. It mandates the identification of potential hazards, the evaluation of the likelihood and severity of harm, and the implementation of measures to control or eliminate risks.

The private sector in the UK is also bustling with companies specialising in risk management. These organisations offer a range of services, from consultancy to software solutions, helping businesses navigate the complexities of risk in various industries.

Risk management

In conclusion, risk management in the UK is a multifaceted discipline supported by a strong institutional framework, government regulations, and a dynamic private sector. Whether it’s for public or private entities, the resources and expertise available within the UK provide a solid foundation for managing risks and safeguarding the interests of stakeholders.  With the right approach and tools, organisations can turn risks into opportunities for growth and resilience.

Risk Management Top 10 for 2024

Common Risks Faced by UK Businesses: Navigating the Challenges of 2024

In the ever-evolving landscape of the business world, UK companies face a myriad of risks that can impact their operations and bottom line. As we delve into 2024, it is crucial for businesses to stay informed about the potential challenges they may encounter. Here’s an overview of the common risks that UK businesses are currently facing:

Cyber Incidents

Cybersecurity remains a top concern for UK businesses, with cyber incidents such as cybercrime, IT network disruptions, malware, ransomware, and data breaches leading the list of risks. The sophistication of cyber threats continues to grow, with hackers leveraging new technologies to exploit vulnerabilities. The rise of artificial intelligence (AI)-powered attacks has made it imperative for businesses to bolster their cyber defences and remain vigilant against these evolving threats

Business Interruption

Business interruption, including supply chain disruptions, holds the second spot on the risk list. The UK’s recent history with Brexit and the COVID-19 pandemic has highlighted the importance of business resilience. Companies must navigate import/export costs, cash-flow challenges, staff shortages, and the ripple effects of global events on their supply chains.

Natural Catastrophes

Climbing up the risk ladder, natural catastrophes such as storms, floods, earthquakes, and wildfires pose significant threats. Extreme weather events underscore the need for robust disaster recovery plans and insurance coverage to mitigate the financial and operational impacts of such incidents.

Shortage of Skilled Workforce

The scarcity of skilled professionals is a growing concern, affecting businesses’ ability to maintain productivity and innovation. This risk calls for strategic workforce planning and investment in training and development to bridge the skills gap.

Climate Change

The physical, operational, and financial risks associated with global warming continue to be a pressing issue. With climate change moving up the risk rankings, businesses must integrate sustainability into their core strategies and adapt to the changing regulatory landscape.

Political Risks and Violence

Political instability, terrorism, and civil unrest can disrupt business operations and pose security challenges. Companies must be prepared to respond to political risks and ensure the safety of their assets and personnel.

Legislative and Regulatory Changes

Changes in legislation and regulation, such as tariffs, economic sanctions, and protectionism, can have far-reaching effects on businesses. Staying abreast of legal developments and maintaining compliance is essential for operating within the law.

Macro-economic Developments

Economic shifts, including inflation, deflation, and monetary policies, can alter the business landscape. Organizations must be agile and ready to adjust their strategies in response to macro-economic changes.

New Technologies

The advent of new technologies brings both opportunities and risks. Innovations like AI, autonomous vehicles, and the Metaverse can transform industries, but they also introduce new challenges that businesses must navigate.

Market Developments

Lastly, market developments such as intensified competition, mergers and acquisitions, and market fluctuations require businesses to be competitive and adaptable to sustain growth and success.

In conclusion, UK businesses must adopt a proactive approach to risk management, staying informed and prepared for the diverse range of risks they face. By understanding these common risks and implementing effective strategies to address them, businesses can enhance their resilience and secure a competitive edge in the marketplace.

Risk Management in practice

Managing risk is a critical aspect of business strategy, especially in a dynamic and interconnected global economy. In the UK, businesses face a variety of risks that can impact their operations, reputation, and bottom line. Understanding these risks and implementing strategies to manage them is essential for business resilience and success.

Cyber Incidents

Cyber incidents top the list of risks for UK businesses in 2024, as they did in the previous year. The digital landscape is constantly evolving, and with it, the nature of cyber threats. Businesses must stay vigilant against cybercrime, IT network disruptions, malware, ransomware, and data breaches. Investing in robust cybersecurity measures, employee training, and incident response plans is crucial. Regularly updating IT infrastructure and adopting best practices for data protection can mitigate the risk of cyber incidents.

Business Interruption

Business interruption, including supply chain disruptions, remains a significant concern. The UK’s recent history with Brexit and the COVID-19 pandemic has highlighted the importance of business continuity planning. Companies should assess their supply chain vulnerabilities and develop strategies to ensure operational resilience. This may include diversifying suppliers, stockpiling critical inventory, and establishing alternative logistics arrangements.

Natural Catastrophes

The emergence of natural catastrophes as a top risk reflects the increasing frequency and severity of extreme weather events. Businesses should evaluate their exposure to natural disasters and consider insurance coverage as part of their risk management strategy. Additionally, developing disaster recovery plans and investing in infrastructure that can withstand extreme conditions are proactive steps businesses can take.

Shortage of Skilled Workforce

A shortage of skilled workers can hinder a business’s ability to grow and compete. To address this risk, companies should invest in training and development programs, foster a culture of continuous learning, and explore new recruitment channels. Building partnerships with educational institutions and offering apprenticeships or internships can also help bridge the skills gap.

Climate Change

The risks associated with climate change, such as physical, operational, and financial impacts, are increasingly recognized by UK businesses. Adopting sustainable practices, reducing carbon footprint, and integrating Environmental Social Governance (ESG) criteria into business operations can not only manage risk but also create opportunities for innovation and growth.

Political Risks and Violence

Political instability, terrorism, and other forms of political risk can have sudden and profound effects on businesses. Companies should monitor political developments and have contingency plans in place. Risk transfer mechanisms, such as political risk insurance, can provide financial protection against such uncertainties.

Legislative and Regulatory Changes

Changes in legislation and regulation, including tariffs and economic sanctions, can disrupt business activities. Staying informed about regulatory changes and engaging with policymakers can help businesses anticipate and adapt to new requirements. Compliance programs and legal counsel can ensure that businesses navigate these changes effectively.

Macro-economic Developments

Economic conditions such as inflation, deflation, and monetary policies can impact business performance. Businesses should conduct regular economic analyses and scenario planning to prepare for macro-economic shifts. Diversifying revenue streams and maintaining financial flexibility can provide a buffer against economic turbulence.

New Technologies

The advent of new technologies, including AI and the Metaverse, presents both opportunities and risks. Businesses should evaluate the potential impact of emerging technologies on their operations and industry. Investing in research and development and staying ahead of technological trends can turn these risks into competitive advantages.

Market Developments

Finally, market developments such as intensified competition and market fluctuations require businesses to be agile and responsive. Conducting market research, fostering innovation, and maintaining strong customer relationships can help businesses stay competitive in a changing market landscape.

Conclusion

In conclusion, managing risk is an ongoing process that requires attention, resources, and strategic thinking. By understanding the top risks facing UK businesses and taking proactive steps to address them, companies can build resilience and position themselves for long-term success.

If you require risk management advice for your business, please contact one of the Ashbrooke team.

All you need to know about permit management systems

If you operate a waste management facility your environmental permit requires you to have a written management system in place and in this article all you need to know about permit management systems, we explain what you need. A management system is simply a set of procedures describing what you will do to minimise the risk of pollution from the activities covered by your environmental permit.

If you have a waste permit that was granted before 6 April 2008 that does not require you to have a working plan or management system, you will still need to manage and operate your waste activity in line with a written management system.  If you are applying for:

  • a standard rules permit, the risks are identified in the generic risk assessment
  • a bespoke permit, you will have identified the risks by carrying out your risk assessment
All you need to know about permit management systems
ISO 14001, BS 8555, EMAS: Which system is best for your business?

All you need to know about permit management systems

Your risk assessment will be part of your management system.  You must submit a summary of your management system as part of your application if you are applying for a bespoke permit. You do not need to do this if you submit a B6.5 or B6.6 application form for a standalone water discharge or a groundwater activity, but you must have your management system in place before you start operating.

You do not have to submit a summary of your management system if you are applying for standard rules permits, but you must have your management system in place before you start operating.  Your management system will normally be reviewed on the pre-operation site visit by an officer from the Environment Agency.

Where you are applying for a standard rules permit for waste activities and plan to store combustible waste, you will need to submit a fire prevention plan as part of your application.  Our consultants can provide advice and support in developing a fire prevention plan and have successfully submitted many plans on behalf of clients which have been approved by the Environment Agency.  If you require advice and support with your fire prevention plan, please contact one of the Ashbrooke team.

Once you are operating you must implement your management system, or you will be in breach of your permit.

What to put in your permit management system and how to organise it

The amount of information you will need in your management system will depend on how complicated and risky your activities are.  If your permit is for low-risk activities, for example a small sewage treatment works, your management system can be simple.  If you have a number of permits they may be covered by an overall management system. You may carry out certain things in the same way at different permitted sites and you may also have site specific procedures.

You need to be able to explain to the regulator what happens at each site and which parts of the overall management system apply to each facility. For example, at some sites you may need to show you are carrying out additional measures to prevent pollution because they are nearer to sensitive locations than others.  Our consultants recently supported a client who was near to a site of special scientific interest (SSSI) which required additional measures in both the management system and the fire prevention plan. 

How to develop your permit management system

You can develop and maintain your own management system or use an environmental management system scheme or standard.

If you have a larger site or carry out a more complex activity (like installations and waste operations dealing with hazardous waste), the Environment Agency prefers management systems based on a recognised standard and independently checked by an accredited body.

An environmental management system may be certified against a standard such as ISO 14001. The organisation or individual carrying out certification may be accredited by a National Accreditation Body such as the UK Accreditation Service (UKAS).

Using an accredited certified management system is not a guarantee that you will meet all of your permit conditions. You are still responsible for implementing your system effectively and making sure you comply with each permit condition.  This is where our consultants can provide value to your operations in ensuring that any system is relevant to your permit operation and is efficient and effective. 

However, the independent checks carried out for an accredited certified scheme or standard should result in greater confidence in your management system, and in your management of compliance. This may lead to fewer checks from the Environment Agency under the operator and performance risk assessment methodology (OPRA).  Independent inspections and audits will also provide some assurance to the company board and senior managers that procedures are implemented and being followed in practice.

When applying for an environmental permit you will need to detail on the application form if you are using any of the following as the basis for your management system:

Prepare your permit site infrastructure plan

If you are applying for a permit for a standalone water discharge activity or a point source standalone groundwater activity, you only need to read the section on ‘Water discharge and groundwater activity’.

Your management system must include a plan of your site, drawn to scale.  The plan must highlight where you do the activities covered by your permits (and any exemptions you have registered).  The plan can become incredibly detailed as the regulator lists all the features which must be included.  Often you may need to produce a number of plans in order to include all the features that are required. 

Waste, installations and mining waste permits

So far in this article, all you need to know about permit management systems, we have looks at the general requirements of a system.  However, there are some specific requirements for waste installations and mining permits.  In these cases your plan must also show any:

  • buildings, and other main constructions, like treatment plants, incinerators, storage silos and security fences
  • storage facilities for hazardous materials like oil and fuel tanks, chemical stores, waste materials
  • location of items for use in accidents and emergencies, like absorbants for chemical spills
  • entrances and exits that can be used by emergency services
  • points designed to control pollution, for example inspection or monitoring points
  • trade effluent or sewage effluent treatment plants
  • effluent discharge points
  • land that you believe is contaminated, for example areas of your site that have previously been used for industrial purposes

Permit sites near vulnerable locations

Your plan must also show areas particularly vulnerable to pollution that are on or near to your site, for example:

  • rivers or streams
  • groundwater used for drinking water
  • residential, commercial or industrial premises
  • areas where wildlife is vulnerable or protected

Use the Environment Agency’s risk assessment guide to help you think about areas that are vulnerable to pollution.  If having read this all you need to know about permit management systems article you are unsure what to include, our consultants can provide further advice and support. 

Drainage

The plan must show your foul and combined drainage facilities marked in red and your surface water drainage, facilities marked in blue.

It must also show:

  • the direction of flow of the water in the drain
  • the location of discharge points to the sewer, watercourse or soakaway
  • the location of manhole covers and drains
  • the location of stop and diverter valves and interceptors

Water, gas, electricity

Your plan must show the location of mains water, gas and electricity supplies on your site, including:

  • the mains water stop tap
  • gas and electric isolating valves and switches
  • the routes for gas, electricity and water supplies around your site – electric wiring and gas and water pipes must be labelled on the plan

Water discharge and groundwater activity

If you are applying for a permit for a standalone water discharge activity or a point source standalone groundwater activity your site plan must show:

  • your wastewater treatment plant
  • monitoring points – the locations from which you will take samples to check for contaminants or pollutant substances as required by your permit
  • the location of emergency equipment
  • the location of any mitigation measures referred to in your management system
  • the outlet to surface water (standalone water discharges only)
  • the infiltration system (standalone groundwater activity only)

If you are applying for a permit for a standalone groundwater activity where you are land spreading, your site plan must show:

  • the field locations for spreading
  • monitoring points – the locations from which you will check your discharge for contaminants or pollutant substances as required by your permit
  • the location of emergency equipment
  • the locations of any pollutant storage areas linked to your permit

Permit site operations

As a permit holder, you must break down the operations that will be carried out on your site during start up, normal operation and shut down, into a list of activities and processes, for example unloading waste, storing waste, incinerating waste.

For waste, mining waste, and installations, you should list the wastes that will be produced by each activity or process.

Finally, list the steps you will take to prevent or minimise risks to the environment from each activity or process and type of waste. Be specific about the actions you will carry out to do this.

For water discharge and point source groundwater activities, this will normally be the operation of a wastewater treatment works or effluent treatment equipment that is part of your activity and included in the permit.

If you manage, treat or dispose of waste

If you are a waste operator you must include a waste storage plan that states:

  • the longest amount of time that you will store each type of waste
  • how you will make sure you will not exceed these time limits – you need to consider your emissions when deciding how long you can store types of waste for
  • the maximum amount of each type of waste you will store in terms of volume
  • the maximum height of each storage pile on site
  • how you will identify the specific types of waste you are storing
  • how you will separate different types of waste if required, for example how far apart you will keep waste types that cannot be mixed
  • how you will make sure your site only takes waste that your permit allows you to store

Fire prevention plans

If you need a permit for waste activities and you plan to store combustible waste, you will need to write a fire prevention plan and submit it with your application. This must explain how you would prevent fire at your site or manage risks from fire if one occurs.  You should note that following the increase in waste facility fires in recent years, the Environment Agency has significantly strengthened its guidance on fire prevention plans and any plan submitted for approval must be robust. 

The regulator also charged an assessment fee per hour where existing permit operators need to produce a fire prevention plan.  If plans are not approved on the first submission, the costs can increase significantly as the regulator re-assesses each version submitted for approval. 

Our consultants can provide advice and support in developing a fire prevention plan and have successfully submitted many plans on behalf of clients which have been approved by the Environment Agency.  If you require advice and support with your fire prevention plan please contact one of the Ashbrooke team.

Site and equipment maintenance plan

You need a plan for how you will maintain the infrastructure of your site and any machinery.

You must maintain any machinery according to the manufacturers’ or suppliers’ recommendations (for example, following the instructions and guidelines of any manuals that came with your equipment).  The maintenance plan is also referred to as a maintenance schedule.

You will need to record each time you carry out maintenance, for example, each time you check the calibration of monitoring equipment to make sure it meets the manufacturer’s recommendations.  Records can be specific to the equipment, on a daily or weekly checklist or for very small operations, you could record maintenance tasks in a site diary.

Contingency plans

You need a plan for how you will minimise the impact on the environment of any:

  • breakdowns
  • enforced shutdowns
  • any other changes in normal operations, for example due to extreme weather

Accident prevention and management plan

You need a plan for dealing with any incidents or events that could result in a pollution or where you are not able to comply with your permit.  The plan must identify potential accidents, for example:

  • equipment breakdowns
  • enforced shutdowns
  • fires
  • vandalism
  • flooding
  • any other incident which causes an unexpected change to normal operations, such as extreme weather

For each potential incident, it must also state the:

  • likelihood of the accident happening
  • consequences of the accident happening
  • measures you’ll take to avoid the accident happening
  • measures you’ll take to minimise the impact if the accident does happen

Your accident plan must also say how you will record, investigate and respond to accidents or breaches of your permit.

Your accident plan must also include:

  • the date it was reviewed
  • when it will next be reviewed
  • a list of emergency contacts and how to reach them
  • a list of substances stored at your site, and your storage facilities
  • forms to record accidents on

Consider taking the following actions, if you think they are relevant to the operations you carry out at your site:

Online security: protect your business

You can take some simple steps to protect your business against online security threats. Good online security will help make sure your business does not cause pollution. Any pollution that does occur is your responsibility as the permit holder.

See the National Cyber Security Centre website for guidance about online security which is becoming an increased risk for many businesses. This will be particularly important where you have waste processing or environmental monitoring equipment controlled by computers. 

Contact information for the public

If you have a waste or an installation permit, you must display a notice board at or near the site entrance telling the public about the site. It must include:

  • the permit holder’s name (company name at least)
  • an emergency contact name and telephone number
  • a statement that the site is permitted by the Environment Agency
  • the permit number
  • Environment Agency telephone number 03708 506506 and the incident hotline 0800 807060 (or another number we subsequently tell you about in writing)

A notice board is optional for other permits and will depend on whether you consider that the public will need to see emergency contact information at your site.

A changing climate to consideration

The Met Office climate projections for the UK suggest that we can expect:

  • higher average temperatures – particularly in summer and winter
  • more heat waves and hot days
  • rising sea levels
  • changes in rainfall patterns and intensity
  • more storms

It is important you consider if a changing climate could affect your operations, including how this might affect your ability to comply with your permit.

Plan for negative climate impacts on how you operate now, during and after any transition to net zero. Include the associated risks to local communities and the environment. These impacts and risks may change over the lifetime of the activity.

Plan for the impacts of multiple events, such as supply chain failure and extreme weather, happening at the same time.

Plan to complete changes to ensure your operations remain resilient at stages along a climate projection of at least a 2°C global mean temperature rise by 2050. Do this by following and regularly updating your climate change risk assessment. Also, assess what further requirements may be necessary along a projected 4°C rise by 2100. You do not need to assess risks or plan actions beyond the end of the life of your activity.

To anticipate and prevent risks to local communities and to the environment, plan to test the effectiveness of your:

  • actions
  • policies
  • procedures
  • assessments

Finally, plan timely reviews and revisions in response to new information or learning.  Use the adapting to climate change: industry sector examples for your risk assessment when developing or reviewing your management system. You may also wish to follow or adopt ISO 14090:2019 and associated standards to help you to do this.

Complaints procedure

You need a procedure that records:

  • any complaints you receive in relation to activities covered by your permit (for example complaints from neighbours about noise, odour or dust from your site)
  • how you investigate those complaints
  • any actions taken as a result of complaints

Managing staff competence and training records

You need to have enough staff and resources to make sure the site is run effectively in order to comply with your permit.  Your management system needs to explain who is responsible for what procedures and who is technically competent.

For each of your managers, staff and contractors make a list of any roles they carry out that relate to activities covered by your permit.  You will also need a procedure to:

  • check your staff and contractors have taken the training or qualifications required for the work they do
  • record any training, refresher training or qualifications taken by your staff or contractors

If you have a permit for a waste, mining waste or installations permit you also need to look at legal operator and competence requirements.  Our consultants can provide on site training for staff on all aspects of environmental permit compliance and ISO 14001 requirements.  If you require training advice and support, please contact one of our team.

Keeping records

You must keep any records required by your permit. In some cases, the permit will tell you how long to keep a record for. Otherwise, you must consider how long you’ll need to keep different records for (and write this in your management system).  You must keep records to show how your management system is being implemented in line with the requirements of your permit and this guide.  You need to keep:

  • permits issued to the site
  • other legal requirements
  • your risk assessment
  • all management system plans
  • any plans required by the application or permit depending on your type of activity (for example odour management plan at waste sites)
  • all operating procedures
  • staff competence and training (for example qualifications, courses attended)
  • emissions and any other monitoring undertaken (for example water samples)
  • compliance checks, findings of investigation and actions taken
  • complaints made, findings of investigation and actions taken
  • audits of management system, findings (reports) and actions taken
  • management reviews and changes made to the management system
  • where applicable, certification audit reports and any actions carried out

You also need to include copies of your plans with your management system if:

  • your permit requires you to implement an approved plan
  • you have been asked to do this because there’s a problem at your site

If you manage, treat or dispose of waste

If you are a waste operator you must record the following for each delivery of waste to your site:

  • its quantity (weight or volume)
  • its List of Waste (LoW) Code
  • its origin (for example, the location the waste sent from)
  • the identity of the producer of the waste (for example the company name)
  • the date the waste arrives at your site
  • the date the waste was first produced, if the waste is likely to cause odour
  • any quarantined materials that are part of the delivery, and what you did with them

You must also:

Waste, mining waste or installations

If you have a permit for waste, mining waste or installations you will need to have a site condition report to record the condition of land or quality of groundwater on your site.

Keep this up to date through the life of your permit and include the following information:

  • details of any historic spills or contamination (incidents that took place before you began operating) and what was done in response to those incidents
  • evidence of the effectiveness of any measures you have taken to protect land or groundwater since you started operating

If you want to cancel (surrender) your permit, you will need to show you have taken the necessary measures to avoid any pollution risk from your activities.

You also need to show that you have returned the site to a satisfactory state. This means that the condition of land and groundwater has not deteriorated as a result of your activities.  Our consultants can provide advice and support drafting site condition plans for permit applications as well as updating condition plans for site permit surrenders.  If you require site condition plan advice and support, please contact one of our team.

Individual subject management plans

Sites for waste, mining waste or installations may have to include the following plans:

It is also worth noting that the Environment Agency when assessing the above plans, may use different officers to assess each individual plan.  Therefore, the Agency will require odour, emissions, noise and pest plans to be separate standalone documents. Unfortunately, this does result in duplication and additional work. 

Agency permit application assessment officers could be based anywhere in England and will often not be familiar with the local area around your site, so it is important to include all relevant details. 

Jacksons can provide advice and support in drafting these types of management plans for permit applications and permit modifications.  If you require advice and support, please contact one of our team.

Review your permit management system

You must have a procedure for checking you are complying with your permit, procedures and management system. Record what checks are carried out, who did them and what action was taken.

You must review and update your management system:

  • when you make changes to your site, operations or equipment that affect the activities covered by your permit, for example if you install a new boiler
  • whenever you apply to change (‘vary’) your permit
  • after any accident, complaint or breach of your permit
  • if you encounter a new environmental problem or issue, and have implemented new control measures to control it

If you have ISO 14001, then it is a requirement to carry out a management review at set periods, often annually, in order to review your environmental objectives, the results of internal and external audits, etc.

You must keep a record of changes to your management system, particularly major changes such as:

  • a change to the maximum amount of waste stored on your site
  • a new noise screen
  • new waste treatment equipment, for example a Trommel
  • implementation of new control measures

The Environment Agency may also review your management system and make recommendations for improvements after any accident, permit breach or other incident. It may also ask you to improve your management system if it thinks you have not identified or minimised risks from pollution.  Our consultants have considerable experience in liaising with the Environment Agency on behalf of clients regarding environmental permit issues. 

Site closure

It is no longer possible to simply hand your environmental permit back when you stop operating.  You must submit an application to surrender your permit to the Environment Agency.  You will have a period of site closure from when you stop operating until you are able to cancel (surrender) your permit if you have a permit for a:

  • landfill
  • category A mining waste facility

During this time, you will need to continue to monitor emissions from your site.

You will need to submit the site closure parts of the site condition report when you stop operating.

Make sure people understand what you do

Your staff must have access to and understand any sections of the management system that deal with activities they carry out. It is up to you how you do this, for example whether you print the system out, or provide electronic copies.

You must be able to show the Environment Agency your management system if asked. If you have an overarching management system for a number of sites, you can provide both:

  • an overview or summary of the whole system
  • copies of the sections that relate to the activity type or aspect of the management system that the Environment Agency has asked about

Consider whether you need to provide information to interested parties such as neighbours and your local community to explain how you manage your activities to comply with your permit.

Conclusion

If you operate a waste management facility your environmental permit requires you to have a written management system in place and in this article all you need to know about permit management systems, we explain what you need. A management system is simply a set of procedures describing what you will do to minimise the risk of pollution from the activities covered by your environmental permit.

If you are applying for an environmental permit, you will need to detail on the application form if you are using any of the recognised standards as the basis for your management system.  If you have a larger site or carry out a more complex activity (like installations and waste operations dealing with hazardous waste), the Environment Agency prefers management systems based on a recognised standard and independently checked by an accredited body.

The management system must include all the elements detailed in the Environment Agency’s guidance as well as separate plans and drawings to support the permit application. If you require advice and support with your permit application or modification, please contact one of the Ashbrooke team.

Safe Systems of Work

A lack of safe systems of work resulted in a cargo handling company being fined after the employee was fatally crushed at a container park in Portsmouth.

On 25 August 2017, Mr Mieczyslaw Tadeusz Siwak, a 34-year-old father-of-one, was working for Portico Shipping Limited (formerly MMD (Shipping Services) Limited) on the night shift in the container park. His job was to connect refrigerated container units to electrical supplies, which his colleague had lifted into position for him using a container stacker vehicle. It was during one of these manoeuvres that Mr Siwak was fatally crushed between two containers.

An investigation by the Health and Safety Executive (HSE) found that the company routinely failed to provide adequate supervision of operatives and drivers working on the night shift to ensure safe systems of work were followed. This included failure to use safe walkways to segregate pedestrians from vehicles and the safe operation of container stackers by driving with shipping containers in the raised position to allow visibility.

Portico Shipping Limited of Guildhall Square, Portsmouth, Hampshire pleaded guilty to breaching Section 2(1) of the Health & Safety at Work etc. Act 1974. At Portsmouth Magistrates’ Court the company was fined £200,000 and ordered to pay costs of £15,631.61.

“Safe systems of work should be in place on sites with moving vehicles to prevent pedestrians coming into contact with traffic or moving machinery. When moving containers by container stacker, the load should be transported as low as possible whilst maintaining full line of sight.

“Supervisors must be given the necessary instruction and training to implement the safe systems of work and manage hazards during operation processes.

“This tragic incident was entirely preventable had the correct safety management procedures and supervision been in place at the site.”

HSE inspector Rebecca Lumb

Safe Systems of Work

A formal management system or framework can help you manage health and safety and ensure that you have safe systems of work in place – the decision whether to use a recognised management system is up to employers and it is not a requirement of the HSE. Examples include:

National and international standards such as:

  • ISO 45001:2018 Occupational health and safety management systems – Requirements with guidance for use
  • BS EN ISO 9001:2015 Quality management system

in-house standards, procedures or codes

sector-specific frameworks such as the:

  • Energy Institute’s High-level framework for process safety management
  • Chemical Industries Association’s Responsible Care framework

Although the language and methodology vary, the key actions can usually be traced back to Plan, Do, Check, Act methodology.

safe systems of work
Is a certified management system right for your business?

HSE Position on ISO 45001

ISO 45001 is an international standard for health and safety at work developed by national and international standards committees independent of government.  Introduced in March 2018, it replaced the current standard (BS OHSAS 18001) which will be withdrawn. Businesses had a three-year period to move from the old standard to the new one.

Businesses are not required by law to implement ISO 45001 or other similar management standards, but they can help provide a structured framework for ensuring a safe and healthy workplace.

If your organisation is small or low-risk, you will probably be able to demonstrate effective risk management without a formal management system. A simpler and less bureaucratic approach may be more appropriate such as that outlined in HSE’s guidance on health and safety made simple.

Implementing ISO 45001 may help your organisation demonstrate compliance with health and safety law. But, in some respects, it goes beyond what the law requires, so consider carefully whether to adopt it.

If your organisation already has a developed health and safety management structure, or you are familiar with other management standards, it may be straightforward for you to adopt ISO 45001. However, if your organisation is small, with less formal management processes, you may find it difficult to interpret what the standard asks for or gauge what proportionate implementation looks like.  This may particularly be the case if you are adopting management standards to meet supply chain requirements of customers or contracting bodies.

The HSE has expressed concern about the practical implementation of the standard, including audit and certification, and whether it can be easily tailored to work effectively for organisations of all sizes and levels of complexity in a way that’s in proportion to the risks they must control.

Contracting bodies and customers should therefore ask themselves whether the supplier really needs certification to 45001, or whether they can demonstrate competence in managing health and safety using other means.

Compliance with health and safety law

HSE inspectors continue to rely on a wide range of evidence and observations when assessing an organisation’s compliance with health and safety law, not just whether they claim to meet the ISO 45001 standard or not.  The HSE’s guide on managing for health and safety (HSG 65) may help your organisation as it provides a clear process-based approach to risk management. However, adopting a formalised management system approach, whether HSG65 or ISO 45001, may not be the most appropriate model for your businesses, particularly if it is small or low-risk.

Certification

Your organisation can apply the standard to your activities (in full, or in part) to help provide evidence of good health and safety management, and improvements made, without getting certification. However, you can only claim to conform to the standard if it is implemented fully.

Audit

To implement ISO 45001 in a proportionate way, auditors or certifiers should understand that it needs to be (i) tailored to an organisation’s size and level of complexity, and (ii) in proportion to the risks.  You should ensure that any auditor or certifier you use has evidence that they are competent to a recognised standard.  The certification body should be accredited by either the United Kingdom Accreditation Service (UKAS) for ISO 45001 or an equivalent accretion body that is member of the European Cooperation for Accreditation (EA) or the International Accreditation Forum (IAF).

Documentation

Businesses should try to keep health and safety documents functional and concise, with the emphasis on their effectiveness rather than sheer volume of paperwork.  Focusing too much on the formal documentation of a health and safety management system will distract you from addressing the human elements of its implementation – the focus becomes the process of the system itself rather than actually controlling risks.

Attitudes and behaviours

Effectively managing for health and safety and having safe systems of work is not just about having a management or safety management system. The success of whatever process or system is in place still hinges on the attitudes and behaviours of people in the organisation (this is sometimes referred to as the ‘safety culture’).

The HSE has published Are you doing what you need to do? Which provides examples of what positive health and safety attitudes and behaviours will look like in the workplace. On the other hand, the examples provided of ‘What it looks like when done badly or not at all’ could indicate underlying cultural issues which employers should address.

Our health, safety and environmental consultants have experience in implementing management systems into client operations including ISO 9001, ISO 14001 and ISO 45001.  If your business needs advice and support with your management system, please contact one of the Ashbrooke team.

TCM attendance changes

The Environment Agency has published the results of a consultation on TCM attendance changes.  The Environment Agency consulted with stakeholders to hear their views on proposed options and changes to the attendance requirements for technically competent managers (TCMs).

The consultation explained:

  • how the current technical competence attendance requirements work
  • options for proposed changes to the methods of calculating TCM attendance and other proposed changes to the attendance requirements
  • proposed implementation timescales

The responses to the TCM attendance changes consultation will help shape a second, more detailed consultation.  This will provide further details for option 1: attendance linked to charge bands, and other rules associated with the attendance requirements for technically competent managers.  The EA aim to publish the next consultation in summer 2023.

The EA received a broad range of views which will help develop guidance on the attendance requirements for technically competent managers.  The EA received 75 responses to the consultation:

  • 32 from site operators and companies with permits
  • 18 from trade associations and other organisations and groups
  • 12 from consultants
  • 5 from local authorities
  • 8 from individuals and members of the public

Those responding generally agreed that new guidance was needed to explain the attendance requirements for TCMs and provided views on the 3 options preferred for calculating the attendance requirements:

  • option 1: attendance linked to charge bands – 36%
  • option 2: standard baseline attendance for all waste facilities – 16%
  • option 3: tailored baseline attendance for waste operations and waste installations – 30.67%
  • no preference – 14.67%
  • Two respondents (2.67%) did not provide an answer to this question.

Many of those responding highlighted the potential for environmental benefits should TCM attendance increase at poor performing sites. However, the extent of this benefit would depend on the specific circumstances. Approximately 75% of those responding supported the adjustment of the attendance requirement based on operator performance, with those in deteriorating or poor compliance bands requiring increased TCM attendance.

TCM attendance changes
Changes proposed to TCM attendance requirements at waste sites

Some of those responding stated that applying attendance requirements for the Environmental Services Association (ESA)/Energy & Utility (EU) Skills technical competence scheme would undermine the purpose of this scheme, but there was general support for other proposals on the 48 hour attendance cap, 24 hour operations, multiple regulated facilities and mothballed sites.

For permit transfers, some respondents highlighted situations where transfers were ‘administrative’ and in those instances they did not support previously agreed TCM attendance requirements reverting back to those required by the guidance.

For closed landfills nearly 40% of respondents agreed with the proposals, whilst 50% did not have a view. The Environment Agency concluded that it anticipate the majority of the 50% who did not have a view do not operate activities involving closed landfills.

Most of those who responded did not have a view on the proposals for mobile plant attendance requirements. Around one third supported the proposals on mobile plant and less than 10% disagreed.

Nearly half of respondents supported a 12 month implementation period for the new guidance. Because, for example, this would give operators time to understand the new guidance and train or recruit additional TCMs if required.

The Agency received a broad range of views which will help develop the attendance requirements for TCMs guidance and it intends to launch the next consultation in summer 2023. It will include further details of the favoured option and other proposed changes to the attendance requirements.

Operators who apply for an environmental permit for a waste operation must be members of (and comply with) a government approved technical competency scheme. Most existing waste environmental permit holders must also comply with a government approved technical competency scheme through the conditions in their permits.

For operators that show competence through the scheme run by the Chartered Institution of Wastes Management and Waste Management Industry Training and Advisory Board, the Environment Agency requires that sites have nominated technically competent manager(s) on site for a specified amount of time each week – this is called the attendance requirement.

The Environment Agency used to calculate attendance requirements using the OPRA risk appraisal guidance. However, except for the sections relating to attendance levels for technically competent managers, this guidance has been withdrawn.

The Agency is now considering changes to the requirements for attendance by TCMs at environmental permit sites. If you require environmental advice or support for your business, please contact one of the Ashbrooke team.