Knowledge base

Building an Effective Compliance Obligations Register

The compliance obligations register is one of the key documents auditors carefully review during an ISO 14001 audit. However, it is also one of the documents organisations often prepare incorrectly. Here’s a simple guide to creating a clear, effective, and audit-ready register.

Neha Dvivedi · ١٦ أغسطس ٢٠٢٦

A compliance obligations register is one of the most important documents in an ISO 14001 Environmental Management System. Auditors often review it carefully. However, many organizations create a register that is simply a list of environmental laws and does not clearly show how those requirements apply to their operations.

Here is a simple way to build a useful and audit-ready register.

1. What is a Compliance Obligation?

Compliance obligations generally fall into two categories:

Legal Requirements

These are requirements that the organisation must follow by law, such as:

• National, state and local environmental laws

• Rules and regulations

• Environmental permits and licences

• Consents and authorisations

• Court or regulatory orders

Other Requirements

These are requirements that the organisation has voluntarily agreed to follow, such as:

• Customer contractual requirements

• Industry codes or standards

• Company or group policies

• Agreements with local communities

• Environmental commitments made publicly or in tenders

Both types should be included in the register. A common mistake is to include only legal requirements.

2. Build the Register Around Your Activities

Do not start by simply making a list of environmental laws.

Instead, start by looking at what your organisation actually does and then identify the requirements that apply to those activities.

For example, ask:

• Do we discharge wastewater?

• Do we release emissions into the air?

• Do we store chemicals above specified quantities?

• Do we generate hazardous waste?

• Do we use or sell packaging?

• Do we manufacture or import products with end-of-life responsibilities?

• Do we extract or use groundwater?

• Do we operate equipment that requires specific permission or authorisation?

For every activity that applies, identify the relevant compliance requirements and supporting documents, such as permits, licences, consents, registrations or authorisations.

3. What Should Each Entry Include?

Each requirement in the register should clearly mention:

• Specific compliance obligation

• Law, regulation or other document creating the obligation

• Site, department or activity to which it applies

• Relevant permit, licence, consent or registration number

• Date issued and expiry date

• Conditions that must be followed

• How compliance will be checked and how often

• Date of the last compliance evaluation

• Result of the evaluation

• Person responsible for managing the requirement

This level of detail makes the register more than just a list of laws.

An auditor should be able to select any requirement from the register and ask, “Show me the evidence that you are complying with this.”

4. Pay Special Attention to Permit Conditions

Having a valid environmental permit does not automatically mean that the organisation is fully compliant.

A permit may include several conditions, such as:

• Wastewater discharge limits

• Monitoring requirements

• Testing frequency

• Reporting deadlines

• Record-keeping requirements

• Operational restrictions

An organisation may have a valid permit but still fail to meet one of its conditions—for example, by missing a required monitoring or reporting deadline.

Therefore, the register should clearly identify the individual conditions that need to be monitored.

5. Compliance Evaluation Is a Separate Activity

ISO 14001 requires organisations to periodically evaluate whether they are meeting their compliance obligations and keep records of the results.

This is different from an internal audit.

A practical approach is to schedule a compliance review where the responsible person goes through each requirement and checks:

• Is the requirement currently being met?

• What evidence supports compliance?

• Are there any gaps?

• What action is required?

The review should produce a dated record showing the compliance status of each requirement.

An annual review may satisfy the basic requirement, but quarterly reviews can help identify issues earlier, such as a permit that is approaching expiry.

6. Keep the Register Updated

Environmental laws and requirements can change, so the register should be reviewed regularly.

The organisation should also review the register whenever there is a significant operational change, such as:

• A new process

• A new raw material or chemical

• A new site

• A new product

• A change in production activity

These changes may introduce new environmental obligations.

7. Common Problems Auditors Find

Some frequent issues include:

1. The register lists environmental laws but does not include the organisation's actual permits, licences and authorisations.

2. Permit conditions are not separately identified or evaluated.

3. Permit expiry dates are not monitored, resulting in expired or outdated approvals.

4. Compliance evaluation is not performed as a separate, documented activity.

5. Customer requirements and other voluntary commitments are missing.

6. No responsible person is assigned, so nobody is accountable for monitoring or renewing the requirement.

Key Takeaway

A good ISO 14001 compliance obligations register should answer three simple questions:

What do we need to comply with?

How do we know we are complying?

Who is responsible for ensuring continued compliance?

When the register is linked to actual activities, permits, conditions, evidence, review dates and responsible people, it becomes a practical management tool—not just an audit document.

What this covers

See how this looks as a working system

Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO 14001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.

Ask us about this

Tell us what is being asked of you and by whom.

What are you looking for?

We reply within one working day. Your details stay with our consultants.

More reading

All articles