What is a legal register, and does your company need one?
A legal register lists the legal requirements binding your organisation, with an assessment of compliance for each. Building one is straightforward; keeping it current is not. An out-of-date register is worse than none, because it is relied upon.
A legal register records the environmental, energy and sustainability obligations applicable to an organisation, the source of each, how compliance is evaluated, and by whom. Management system standards including ISO 14001 require organisations to determine and have access to applicable compliance obligations and to evaluate compliance periodically. The hard part is maintenance: obligations change, and a register is only useful if it changes with them.
What belongs in one
For each obligation: what it is, the instrument it comes from with a link to the primary source, which entities and sites it applies to, what it requires in practice, who owns it, how compliance is evaluated, when it was last checked, and what changed at the last review.
The last two fields are often missing, and they determine whether an entry is trustworthy. An entry with no verification date is an assertion.
Why registers go stale
Where this usually goes wrong
Registers are rarely built badly; they decay. Between late 2025 and mid-2026: CSRD scope was cut by roughly 85–90%, CSDDD's penalty rule changed from a 5% floor to a 3% ceiling and its application moved to 2029, EUDR was postponed a second time, CBAM's certificate sales moved to 2027, ETS2 slipped to 2028, and the SEC's climate rules were proposed for rescission.
A register built in early 2025 and not maintained may be wrong on all six. Nothing in it may look wrong — that is the difficulty.
Maintaining a register
A named owner per obligation, a review cadence that reflects how fast that area is moving, a primary source link on every entry so a change can be checked at source rather than through commentary, and a change log so that what moved is visible rather than overwritten.
Regimes in active reform need re-checking quarterly. Settled regimes can go annually. A single cadence for everything over-services the stable and under-services the volatile.
In order
- Scope the organisationEntities, sites, markets and products — the same four tests as any applicability assessment.
- Identify obligationsWith a link to the primary source for each. Commentary is not a source.
- Assess applicabilityPer entity and per site, not organisation-wide.
- Assign ownersA named person per obligation, not a department.
- Record how compliance is evaluatedThe evidence, and where it is stored.
- Set review cadences by volatilityQuarterly for regimes in reform, annually for settled ones.
Questions people actually ask
- Does ISO 14001 require a legal register?
- It requires an organisation to determine and have access to its compliance obligations, and to evaluate compliance periodically. A register is the usual way to demonstrate that, though the standard does not use the term.
- How often should a legal register be reviewed?
- By volatility rather than on a single cadence. Regimes in active reform — most EU sustainability law in 2026 — warrant quarterly review; settled regimes can be annual.
- What makes a legal register unreliable?
- Entries with no primary source link and no verification date. Both are needed to tell whether an entry is still true; without them a register is a list of assertions.
Still not sure what binds you?
XG tracks obligations like these across 119 jurisdictions.