Why the Legal Register Is One of the Most Audited Documents in an EMS
When auditors sit down to review an environmental management system under ISO 14001, the legal register is almost always on the sampling list. It is not because auditors enjoy reading legislation. It is because a stale or incomplete legal register is one of the most reliable indicators that a compliance programme is not functioning as intended.
On this page
Clause 6.1.3 of ISO 14001:2015 requires organisations to determine and have access to their compliance obligations, which include legal requirements and other requirements the organisation has chosen to adopt. The 2026 revision of the standard strengthens this further, placing greater emphasis on how organisations identify, access, and respond to changes in these obligations. If you want to understand what those changes mean in practice, the ISO 14001:2026 transition guide covers the key shifts you need to know before the April 2029 deadline.
This article is about the audit side of that requirement. Specifically, how you verify that a legal register is genuinely current, how you gather evidence that the organisation is actually meeting its obligations, and where the most common gaps appear.
What Clause 6.1.3 Actually Requires
Before walking into an audit, it helps to be precise about what the standard demands. Clause 6.1.3 asks organisations to:
- Determine the legal requirements and other requirements that apply to their environmental aspects
- Determine how these requirements apply to the organisation
- Take these requirements into account when establishing, implementing, maintaining, and continually improving the EMS
- Maintain documented information on their compliance obligations
That last point is critical from an audit perspective. The standard requires documented information, which means you have something concrete to examine. But the document itself is only the starting point. What you are really testing is whether the organisation understands what applies to it, keeps that understanding current, and translates it into operational controls.
A legal register that was last reviewed two years ago and has not been updated since a major regulatory change is not evidence of a functioning compliance programme. It is evidence of a compliance programme that exists on paper but may not be working in practice.
Exemplar Global Recognised Training ProviderRTP No. 310970Starting the Audit: Document Review Before the Site Visit
Good preparation makes the on-site audit far more productive. Before you arrive, request a copy of the legal register and any documented procedure for how it is maintained. Review both before the audit begins.
What to Look for in the Register Itself
When reviewing the legal register, check for the following:
- Does it cover the full range of environmental aspects identified in the aspects and impacts register? There should be a logical connection between what the organisation does and what legislation applies.
- Does it include specific legislation and regulations rather than just broad categories? A register that lists environmental legislation as a single line item tells you very little.
- Does it include permit conditions, licence obligations, and consent requirements, not just Acts and Regulations?
- Does it include other requirements such as industry codes of practice, contractual environmental obligations, and voluntary commitments the organisation has made?
- When was each entry last reviewed or confirmed as current?
- Is there a review date for the register as a whole, and has that date been met?
A well-maintained register will have specific legislative references, a brief description of what each requirement obliges the organisation to do, the relevant environmental aspect it connects to, the operational control or procedure that addresses it, and a record of when it was last verified as current.
Checking the Procedure for Maintaining the Register
The register is only as good as the process behind it. Look for a documented procedure or process description that explains how the organisation identifies new or changed requirements, who is responsible for updating the register, and how often reviews occur.
A common weakness here is a procedure that describes a review frequency, such as annually, but where the actual review history shows it has not happened on schedule. That gap between stated intent and actual practice is exactly what auditors are looking for.
On-Site Audit: Testing Whether the Register Is Genuinely Current
Document review tells you what the organisation says it does. The on-site audit tests whether that is actually happening. There are several practical techniques for this.
Ask About Recent Regulatory Changes
One of the most direct tests is to ask the environmental manager or whoever owns the register about recent changes to environmental legislation in their jurisdiction. In Australia, this might include changes to state-based environment protection legislation, updates to the National Pollutant Inventory reporting thresholds, or amendments to water licence conditions.
If the person responsible for the register is unaware of a significant regulatory change that occurred in the past twelve months, that is a meaningful finding. It suggests the organisation does not have an effective process for monitoring legislative changes.
A useful follow-up question is to ask them to walk you through how they found out about the last change to the register and what they did as a result. The answer will tell you whether the process is systematic or whether updates happen by accident.
Cross-Reference the Register Against the Aspects and Impacts Assessment
Pull out the aspects and impacts register and compare it against the legal register. For each significant environmental aspect, there should be corresponding legal requirements identified. If the organisation has identified stormwater discharge as a significant aspect but the legal register makes no reference to the relevant state environment protection policy or discharge licence conditions, that is a gap worth pursuing.
This cross-referencing approach is particularly effective because it tests the logical integrity of the EMS rather than just the completeness of individual documents. For a deeper look at how auditors approach the aspects and impacts assessment itself, the article on what auditors check in an ISO 14001 aspects and impacts assessment provides useful context.
Verify Permit and Licence Conditions Are Captured
Many organisations focus their legal register on Acts and Regulations and overlook the specific conditions attached to their environmental licences and permits. These conditions are often more operationally specific than the legislation itself and are frequently the source of nonconformities.
Ask to see the current environmental licence or permit and compare its conditions against the legal register. Check whether each condition is captured and whether there is a corresponding operational control. If the licence requires monthly discharge monitoring and reporting, is that obligation reflected in the register and in the monitoring programme?
Check the Monitoring and Measurement Programme
Clause 9.1.2 of ISO 14001 requires organisations to evaluate their compliance with legal requirements. The monitoring and measurement programme should be designed, at least in part, around the obligations in the legal register. If the register lists a requirement to monitor stack emissions quarterly but the monitoring records show it has not been done, you have both a clause 6.1.3 issue and a clause 9.1.2 issue.
This connection between the legal register and the compliance evaluation process is one of the most important audit trails in an EMS. The article on auditing compliance evaluation in ISO 14001 goes into more detail on how to audit clause 9.1.2 effectively.
Common Nonconformities in Legal Register Audits
After conducting hundreds of external audits across Australia and other regions, certain patterns emerge consistently. These are the most frequent findings in this area.
The Register Has Not Been Updated After a Regulatory Change
This is the most common finding. Environmental legislation changes regularly, particularly at the state level in Australia. Organisations that rely on an annual review cycle often miss changes that occur between reviews. The fix is not just to update the register but to implement a process for monitoring legislative changes on an ongoing basis, such as subscribing to regulatory update services or setting up alerts through the relevant environment protection authority website.
The Register Lists Legislation but Not Specific Obligations
A register that says Environment Protection Act 2017 (Vic) without specifying which sections apply and what they require the organisation to do is not particularly useful. The auditor cannot verify compliance from that level of detail, and neither can the organisation. Specific obligations need to be articulated clearly enough that an operational manager can understand what is required of them.
Permit Conditions Are Missing or Incomplete
As noted above, licence and permit conditions are frequently omitted or only partially captured. This is especially common when permits have been amended and the register was not updated to reflect the new conditions.
No Clear Ownership or Review Accountability
When asked who is responsible for maintaining the register, the answer is sometimes vague or contested. Without clear ownership, reviews tend to slip. The register needs an identified owner, a defined review frequency, and records showing that reviews have actually occurred.
The Register Does Not Include Other Requirements
ISO 14001 requires organisations to capture not just legal requirements but also other requirements they subscribe to. This includes industry association codes of practice, contractual requirements from major customers related to environmental performance, and voluntary commitments made in the environmental policy. These are frequently missing from registers that focus only on legislation.
Writing Findings Related to the Legal Register
When you identify a gap in the legal register during an audit, how you write the finding matters. A finding that simply states the legal register is not current does not give the organisation enough information to address root cause.
A stronger finding will identify the specific gap, reference the clause requirement, and describe the evidence that led to the finding. For example: the legal register does not include the licence conditions issued under the relevant state environment protection legislation, specifically the conditions relating to discharge monitoring frequency and reporting obligations. The current licence, issued in March 2024, includes three conditions not reflected in the register or in the monitoring programme. This does not conform with clause 6.1.3, which requires documented information on compliance obligations to be maintained.
That kind of specificity gives the organisation something to act on and makes the finding defensible if challenged. For more guidance on writing findings that hold up, the article on how to write audit findings that stand up to challenge is worth reading.
Grading the Finding: Minor or Major?
Not every gap in a legal register warrants a major nonconformity. The grading depends on the nature and extent of the gap and the risk it represents.
A major nonconformity is generally appropriate when the legal register is so out of date or incomplete that the organisation cannot demonstrate it has identified its compliance obligations, or when there is evidence of actual non-compliance with a legal requirement as a result of the gap.
A minor nonconformity is more appropriate when the register is substantially complete but has isolated gaps, such as a single permit condition that has not been captured, or when the review process exists but has slipped slightly behind schedule.
An observation or opportunity for improvement might be appropriate when the register is current and complete but could be structured more effectively to support operational use.
The key question is whether the gap represents a systemic failure of the compliance identification process or an isolated lapse in an otherwise functioning system.
Auditing the Legal Register Under ISO 14001:2026
The 2026 revision of ISO 14001 brings some changes that affect how compliance obligations are managed and therefore how they should be audited. The revised standard places greater emphasis on the connection between compliance obligations and the broader context of the organisation, including the needs and expectations of interested parties.
Under the 2026 edition, auditors should expect to see a more explicit connection between the legal register and the organisation's understanding of its context. Regulators are interested parties, and their requirements are a significant part of the external context. If the organisation's context analysis does not acknowledge the regulatory environment in which it operates, that is a gap worth noting.
The 2026 edition also strengthens the link between compliance obligations and environmental objectives. Objectives should, where appropriate, reflect the organisation's legal obligations. If the organisation has a licence condition requiring it to reduce a particular discharge parameter, that obligation should be visible somewhere in the objective-setting process.
Exemplar Global Recognised Training ProviderRTP No. 310970Practical Tips for Auditors
A few practical points worth keeping in mind when auditing legal registers:
- Do your own research before the audit. Look up the relevant state environment protection legislation and any recent amendments. If you know a significant change occurred in the past year, you can test specifically whether the organisation is aware of it.
- Ask to speak with the person who actually maintains the register, not just the person who manages the EMS at a senior level. The operational reality of how the register is kept current is often more visible at the working level.
- Check whether the register is accessible to the people who need it. Clause 6.1.3 requires the organisation to have access to its compliance obligations. A register locked in a folder that operational staff cannot find or use is not meeting that requirement in spirit.
- Look for evidence of the last review, such as a review date, meeting minutes, or an email trail. The absence of any evidence that a review has occurred is itself a finding.
- Do not confuse a current register with a compliant organisation. The register is evidence of identification. Compliance evaluation under clause 9.1.2 is where you test whether the obligations are actually being met.
Building Auditor Competence in Environmental Compliance
Auditing compliance obligations effectively requires a combination of ISO knowledge and environmental regulatory awareness. An auditor who does not understand how environmental licensing works in Australia, or who is unfamiliar with the structure of state-based environment protection legislation, will struggle to identify gaps that a more experienced auditor would spot immediately.
This is one of the reasons that ISO 14001 internal auditor training is worth investing in properly. Understanding the standard's requirements at a clause level is necessary but not sufficient. Auditors also need enough environmental regulatory literacy to ask the right questions and recognise when an answer does not add up.
At Audit Workshop, the ISO 14001 internal auditor and lead auditor courses are built around practical audit scenarios, not just clause-by-clause theory. Dilawar Laghari, who has conducted over 500 external certification audits across Australia and internationally, designed the courses to reflect what actually happens during an audit, including how to approach compliance obligations, aspects and impacts, and the full audit trail from legal register to monitoring records. If you are preparing to audit an EMS or want to sharpen your skills in this area, the ISO 14001 internal auditor guide is a good place to start before enrolling in a course.













