Skip to main content
Skip to main content

Guide

What is a legal register — and do you need one?

A legal register lists the legal requirements binding your organisation, with an assessment of compliance for each. Building one is straightforward; keeping it current is not. An out-of-date register is worse than none, because it is relied upon.

Last verified 2 August 2026Our EI can make mistakes — check important info.
In short

A legal register records the environmental, energy and sustainability obligations applicable to an organisation, the source of each, how compliance is evaluated, and by whom. Management system standards including ISO 14001 require organisations to determine and have access to applicable compliance obligations and to evaluate compliance periodically. The hard part is maintenance: obligations change, and a register is only useful if it changes with them.

Why do registers go stale?

Registers are rarely built badly; they decay. Between late 2025 and mid-2026: CSRD scope was cut by roughly 85–90%, CSDDD's penalty rule changed from a 5% floor to a 3% ceiling and its application moved to 2029, EUDR was postponed a second time, CBAM's certificate sales moved to 2027, ETS2 slipped to 2028, and the SEC's climate rules were proposed for rescission.

A register built in early 2025 and not maintained may be wrong on all six. Nothing in it may look wrong — that is the difficulty.

Maintaining a register

A named owner per obligation, a review cadence that reflects how fast that area is moving, a primary source link on every entry so a change can be checked at source rather than through commentary, and a change log so that what moved is visible rather than overwritten.

Regimes in active reform need re-checking quarterly. Settled regimes can go annually. A single cadence for everything over-services the stable and under-services the volatile.

In order

  1. Scope the organisationEntities, sites, markets and products — the same four tests as any applicability assessment.
  2. Identify obligationsWith a link to the primary source for each. Commentary is not a source.
  3. Assess applicabilityPer entity and per site, not organisation-wide.
  4. Assign ownersA named person per obligation, not a department.
  5. Record how compliance is evaluatedThe evidence, and where it is stored.
  6. Set review cadences by volatilityQuarterly for regimes in reform, annually for settled ones.

Questions people actually ask

Does ISO 14001 require a legal register?
It requires an organisation to determine and have access to its compliance obligations, and to evaluate compliance periodically. A register is the usual way to demonstrate that, though the standard does not use the term.
How often should a legal register be reviewed?
By volatility rather than on a single cadence. Regimes in active reform — most EU sustainability law in 2026 — warrant quarterly review; settled regimes can be annual.
What makes a legal register unreliable?
Entries with no primary source link and no verification date. Both are needed to tell whether an entry is still true; without them a register is a list of assertions.
Carolina Ramirez

Next step

Talk to Carolina about Legal registers explained

Carolina Ramirez ESG Expert in Latin America

XG tracks 850 regulations across 119 jurisdictions.

30 minutes · a consultant who knows this file

What this usually takes

Audit & Disclosure Readiness

Disclosure regimes are judged on evidence rather than intent. XG reviews documentation, maps it to the framework and finds the gaps before an assurance provider does — XG does not author or submit the final report.

Still not sure what binds you?

XG tracks obligations like these across 119 jurisdictions.

XG Regulation Register · 850 regulations · 119 jurisdictions