Knowledge base
Building an Effective Compliance Obligations Register
The compliance obligations register is one of the key documents auditors carefully review during an ISO 14001 audit. However, it is also one of the documents organisations often prepare incorrectly. Here’s a simple guide to creating a clear, effective, and audit-ready register.
Neha Dvivedi · 16 أغسطس 2026
A compliance obligations register is one of the most important documents in an ISO 14001 Environmental Management System. Auditors often review it carefully. However, many organizations create a register that is simply a list of environmental laws and does not clearly show how those requirements apply to their operations.
Here is a simple way to build a useful and audit-ready register.
1. What is a Compliance Obligation?
Compliance obligations generally fall into two categories:
Legal Requirements
These are requirements that the organisation must follow by law, such as:
• National, state and local environmental laws
• Rules and regulations
• Environmental permits and licences
• Consents and authorisations
• Court or regulatory orders
Other Requirements
These are requirements that the organisation has voluntarily agreed to follow, such as:
• Customer contractual requirements
• Industry codes or standards
• Company or group policies
• Agreements with local communities
• Environmental commitments made publicly or in tenders
Both types should be included in the register. A common mistake is to include only legal requirements.
2. Build the Register Around Your Activities
Do not start by simply making a list of environmental laws.
Instead, start by looking at what your organisation actually does and then identify the requirements that apply to those activities.
For example, ask:
• Do we discharge wastewater?
• Do we release emissions into the air?
• Do we store chemicals above specified quantities?
• Do we generate hazardous waste?
• Do we use or sell packaging?
• Do we manufacture or import products with end-of-life responsibilities?
• Do we extract or use groundwater?
• Do we operate equipment that requires specific permission or authorisation?
For every activity that applies, identify the relevant compliance requirements and supporting documents, such as permits, licences, consents, registrations or authorisations.
3. What Should Each Entry Include?
Each requirement in the register should clearly mention:
• Specific compliance obligation
• Law, regulation or other document creating the obligation
• Site, department or activity to which it applies
• Relevant permit, licence, consent or registration number
• Date issued and expiry date
• Conditions that must be followed
• How compliance will be checked and how often
• Date of the last compliance evaluation
• Result of the evaluation
• Person responsible for managing the requirement
This level of detail makes the register more than just a list of laws.
An auditor should be able to select any requirement from the register and ask, “Show me the evidence that you are complying with this.”
4. Pay Special Attention to Permit Conditions
Having a valid environmental permit does not automatically mean that the organisation is fully compliant.
A permit may include several conditions, such as:
• Wastewater discharge limits
• Monitoring requirements
• Testing frequency
• Reporting deadlines
• Record-keeping requirements
• Operational restrictions
An organisation may have a valid permit but still fail to meet one of its conditions—for example, by missing a required monitoring or reporting deadline.
Therefore, the register should clearly identify the individual conditions that need to be monitored.
5. Compliance Evaluation Is a Separate Activity
ISO 14001 requires organisations to periodically evaluate whether they are meeting their compliance obligations and keep records of the results.
This is different from an internal audit.
A practical approach is to schedule a compliance review where the responsible person goes through each requirement and checks:
• Is the requirement currently being met?
• What evidence supports compliance?
• Are there any gaps?
• What action is required?
The review should produce a dated record showing the compliance status of each requirement.
An annual review may satisfy the basic requirement, but quarterly reviews can help identify issues earlier, such as a permit that is approaching expiry.
6. Keep the Register Updated
Environmental laws and requirements can change, so the register should be reviewed regularly.
The organisation should also review the register whenever there is a significant operational change, such as:
• A new process
• A new raw material or chemical
• A new site
• A new product
• A change in production activity
These changes may introduce new environmental obligations.
7. Common Problems Auditors Find
Some frequent issues include:
1. The register lists environmental laws but does not include the organisation's actual permits, licences and authorisations.
2. Permit conditions are not separately identified or evaluated.
3. Permit expiry dates are not monitored, resulting in expired or outdated approvals.
4. Compliance evaluation is not performed as a separate, documented activity.
5. Customer requirements and other voluntary commitments are missing.
6. No responsible person is assigned, so nobody is accountable for monitoring or renewing the requirement.
Key Takeaway
A good ISO 14001 compliance obligations register should answer three simple questions:
What do we need to comply with?
How do we know we are complying?
Who is responsible for ensuring continued compliance?
When the register is linked to actual activities, permits, conditions, evidence, review dates and responsible people, it becomes a practical management tool—not just an audit document.
What this covers
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO 14001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- ISO 14001:2015: Documentation and Compliance Requirements
This guide explains, clause by clause, what ISO 14001:2015 expects an organisation to have in place and what an auditor may ask to see as evidence.
12 سبتمبر 2026
- ISO 14001:2026: Documentation and Compliance Requirements
This guide explains, clause by clause, what ISO 14001:2026 requires and what evidence an auditor may ask to see. It covers 64 requirements across 7 key areas.
12 سبتمبر 2026
- Australia's first assured climate reports are in
259 Group 1 sustainability reports were lodged by May 2026, with limited assurance over Scope 1 and 2 emissions. Groups 2 and 3 follow from July.
12 سبتمبر 2026
