Exemplar Global Certified Courses from USD 119. Ending Soon!

Auditing Compliance Obligations: Verifying the Legal Register Is Current

AW

Team @ Audit Workshop

13 min read
Auditing Compliance Obligations: Verifying the Legal Register Is Current

Why the Legal Register Is One of the Most Audited Documents in an EMS

When auditors sit down to review an environmental management system under ISO 14001, the legal register is almost always on the sampling list. It is not because auditors enjoy reading legislation. It is because a stale or incomplete legal register is one of the most reliable indicators that a compliance programme is not functioning as intended.

Clause 6.1.3 of ISO 14001:2015 requires organisations to determine and have access to their compliance obligations, which include legal requirements and other requirements the organisation has chosen to adopt. The 2026 revision of the standard strengthens this further, placing greater emphasis on how organisations identify, access, and respond to changes in these obligations. If you want to understand what those changes mean in practice, the ISO 14001:2026 transition guide covers the key shifts you need to know before the April 2029 deadline.

This article is about the audit side of that requirement. Specifically, how you verify that a legal register is genuinely current, how you gather evidence that the organisation is actually meeting its obligations, and where the most common gaps appear.

What Clause 6.1.3 Actually Requires

Before walking into an audit, it helps to be precise about what the standard demands. Clause 6.1.3 asks organisations to:

  • Determine the legal requirements and other requirements that apply to their environmental aspects
  • Determine how these requirements apply to the organisation
  • Take these requirements into account when establishing, implementing, maintaining, and continually improving the EMS
  • Maintain documented information on their compliance obligations

That last point is critical from an audit perspective. The standard requires documented information, which means you have something concrete to examine. But the document itself is only the starting point. What you are really testing is whether the organisation understands what applies to it, keeps that understanding current, and translates it into operational controls.

A legal register that was last reviewed two years ago and has not been updated since a major regulatory change is not evidence of a functioning compliance programme. It is evidence of a compliance programme that exists on paper but may not be working in practice.

Starting the Audit: Document Review Before the Site Visit

Good preparation makes the on-site audit far more productive. Before you arrive, request a copy of the legal register and any documented procedure for how it is maintained. Review both before the audit begins.

What to Look for in the Register Itself

When reviewing the legal register, check for the following:

  • Does it cover the full range of environmental aspects identified in the aspects and impacts register? There should be a logical connection between what the organisation does and what legislation applies.
  • Does it include specific legislation and regulations rather than just broad categories? A register that lists environmental legislation as a single line item tells you very little.
  • Does it include permit conditions, licence obligations, and consent requirements, not just Acts and Regulations?
  • Does it include other requirements such as industry codes of practice, contractual environmental obligations, and voluntary commitments the organisation has made?
  • When was each entry last reviewed or confirmed as current?
  • Is there a review date for the register as a whole, and has that date been met?

A well-maintained register will have specific legislative references, a brief description of what each requirement obliges the organisation to do, the relevant environmental aspect it connects to, the operational control or procedure that addresses it, and a record of when it was last verified as current.

Checking the Procedure for Maintaining the Register

The register is only as good as the process behind it. Look for a documented procedure or process description that explains how the organisation identifies new or changed requirements, who is responsible for updating the register, and how often reviews occur.

A common weakness here is a procedure that describes a review frequency, such as annually, but where the actual review history shows it has not happened on schedule. That gap between stated intent and actual practice is exactly what auditors are looking for.

On-Site Audit: Testing Whether the Register Is Genuinely Current

Document review tells you what the organisation says it does. The on-site audit tests whether that is actually happening. There are several practical techniques for this.

Ask About Recent Regulatory Changes

One of the most direct tests is to ask the environmental manager or whoever owns the register about recent changes to environmental legislation in their jurisdiction. In Australia, this might include changes to state-based environment protection legislation, updates to the National Pollutant Inventory reporting thresholds, or amendments to water licence conditions.

If the person responsible for the register is unaware of a significant regulatory change that occurred in the past twelve months, that is a meaningful finding. It suggests the organisation does not have an effective process for monitoring legislative changes.

A useful follow-up question is to ask them to walk you through how they found out about the last change to the register and what they did as a result. The answer will tell you whether the process is systematic or whether updates happen by accident.

Cross-Reference the Register Against the Aspects and Impacts Assessment

Pull out the aspects and impacts register and compare it against the legal register. For each significant environmental aspect, there should be corresponding legal requirements identified. If the organisation has identified stormwater discharge as a significant aspect but the legal register makes no reference to the relevant state environment protection policy or discharge licence conditions, that is a gap worth pursuing.

This cross-referencing approach is particularly effective because it tests the logical integrity of the EMS rather than just the completeness of individual documents. For a deeper look at how auditors approach the aspects and impacts assessment itself, the article on what auditors check in an ISO 14001 aspects and impacts assessment provides useful context.

Verify Permit and Licence Conditions Are Captured

Many organisations focus their legal register on Acts and Regulations and overlook the specific conditions attached to their environmental licences and permits. These conditions are often more operationally specific than the legislation itself and are frequently the source of nonconformities.

Ask to see the current environmental licence or permit and compare its conditions against the legal register. Check whether each condition is captured and whether there is a corresponding operational control. If the licence requires monthly discharge monitoring and reporting, is that obligation reflected in the register and in the monitoring programme?

Check the Monitoring and Measurement Programme

Clause 9.1.2 of ISO 14001 requires organisations to evaluate their compliance with legal requirements. The monitoring and measurement programme should be designed, at least in part, around the obligations in the legal register. If the register lists a requirement to monitor stack emissions quarterly but the monitoring records show it has not been done, you have both a clause 6.1.3 issue and a clause 9.1.2 issue.

This connection between the legal register and the compliance evaluation process is one of the most important audit trails in an EMS. The article on auditing compliance evaluation in ISO 14001 goes into more detail on how to audit clause 9.1.2 effectively.

Common Nonconformities in Legal Register Audits

After conducting hundreds of external audits across Australia and other regions, certain patterns emerge consistently. These are the most frequent findings in this area.

The Register Has Not Been Updated After a Regulatory Change

This is the most common finding. Environmental legislation changes regularly, particularly at the state level in Australia. Organisations that rely on an annual review cycle often miss changes that occur between reviews. The fix is not just to update the register but to implement a process for monitoring legislative changes on an ongoing basis, such as subscribing to regulatory update services or setting up alerts through the relevant environment protection authority website.

The Register Lists Legislation but Not Specific Obligations

A register that says Environment Protection Act 2017 (Vic) without specifying which sections apply and what they require the organisation to do is not particularly useful. The auditor cannot verify compliance from that level of detail, and neither can the organisation. Specific obligations need to be articulated clearly enough that an operational manager can understand what is required of them.

Permit Conditions Are Missing or Incomplete

As noted above, licence and permit conditions are frequently omitted or only partially captured. This is especially common when permits have been amended and the register was not updated to reflect the new conditions.

No Clear Ownership or Review Accountability

When asked who is responsible for maintaining the register, the answer is sometimes vague or contested. Without clear ownership, reviews tend to slip. The register needs an identified owner, a defined review frequency, and records showing that reviews have actually occurred.

The Register Does Not Include Other Requirements

ISO 14001 requires organisations to capture not just legal requirements but also other requirements they subscribe to. This includes industry association codes of practice, contractual requirements from major customers related to environmental performance, and voluntary commitments made in the environmental policy. These are frequently missing from registers that focus only on legislation.

Writing Findings Related to the Legal Register

When you identify a gap in the legal register during an audit, how you write the finding matters. A finding that simply states the legal register is not current does not give the organisation enough information to address root cause.

A stronger finding will identify the specific gap, reference the clause requirement, and describe the evidence that led to the finding. For example: the legal register does not include the licence conditions issued under the relevant state environment protection legislation, specifically the conditions relating to discharge monitoring frequency and reporting obligations. The current licence, issued in March 2024, includes three conditions not reflected in the register or in the monitoring programme. This does not conform with clause 6.1.3, which requires documented information on compliance obligations to be maintained.

That kind of specificity gives the organisation something to act on and makes the finding defensible if challenged. For more guidance on writing findings that hold up, the article on how to write audit findings that stand up to challenge is worth reading.

Grading the Finding: Minor or Major?

Not every gap in a legal register warrants a major nonconformity. The grading depends on the nature and extent of the gap and the risk it represents.

A major nonconformity is generally appropriate when the legal register is so out of date or incomplete that the organisation cannot demonstrate it has identified its compliance obligations, or when there is evidence of actual non-compliance with a legal requirement as a result of the gap.

A minor nonconformity is more appropriate when the register is substantially complete but has isolated gaps, such as a single permit condition that has not been captured, or when the review process exists but has slipped slightly behind schedule.

An observation or opportunity for improvement might be appropriate when the register is current and complete but could be structured more effectively to support operational use.

The key question is whether the gap represents a systemic failure of the compliance identification process or an isolated lapse in an otherwise functioning system.

Auditing the Legal Register Under ISO 14001:2026

The 2026 revision of ISO 14001 brings some changes that affect how compliance obligations are managed and therefore how they should be audited. The revised standard places greater emphasis on the connection between compliance obligations and the broader context of the organisation, including the needs and expectations of interested parties.

Under the 2026 edition, auditors should expect to see a more explicit connection between the legal register and the organisation's understanding of its context. Regulators are interested parties, and their requirements are a significant part of the external context. If the organisation's context analysis does not acknowledge the regulatory environment in which it operates, that is a gap worth noting.

The 2026 edition also strengthens the link between compliance obligations and environmental objectives. Objectives should, where appropriate, reflect the organisation's legal obligations. If the organisation has a licence condition requiring it to reduce a particular discharge parameter, that obligation should be visible somewhere in the objective-setting process.

Practical Tips for Auditors

A few practical points worth keeping in mind when auditing legal registers:

  • Do your own research before the audit. Look up the relevant state environment protection legislation and any recent amendments. If you know a significant change occurred in the past year, you can test specifically whether the organisation is aware of it.
  • Ask to speak with the person who actually maintains the register, not just the person who manages the EMS at a senior level. The operational reality of how the register is kept current is often more visible at the working level.
  • Check whether the register is accessible to the people who need it. Clause 6.1.3 requires the organisation to have access to its compliance obligations. A register locked in a folder that operational staff cannot find or use is not meeting that requirement in spirit.
  • Look for evidence of the last review, such as a review date, meeting minutes, or an email trail. The absence of any evidence that a review has occurred is itself a finding.
  • Do not confuse a current register with a compliant organisation. The register is evidence of identification. Compliance evaluation under clause 9.1.2 is where you test whether the obligations are actually being met.

Building Auditor Competence in Environmental Compliance

Auditing compliance obligations effectively requires a combination of ISO knowledge and environmental regulatory awareness. An auditor who does not understand how environmental licensing works in Australia, or who is unfamiliar with the structure of state-based environment protection legislation, will struggle to identify gaps that a more experienced auditor would spot immediately.

This is one of the reasons that ISO 14001 internal auditor training is worth investing in properly. Understanding the standard's requirements at a clause level is necessary but not sufficient. Auditors also need enough environmental regulatory literacy to ask the right questions and recognise when an answer does not add up.

At Audit Workshop, the ISO 14001 internal auditor and lead auditor courses are built around practical audit scenarios, not just clause-by-clause theory. Dilawar Laghari, who has conducted over 500 external certification audits across Australia and internationally, designed the courses to reflect what actually happens during an audit, including how to approach compliance obligations, aspects and impacts, and the full audit trail from legal register to monitoring records. If you are preparing to audit an EMS or want to sharpen your skills in this area, the ISO 14001 internal auditor guide is a good place to start before enrolling in a course.

Frequently Asked Questions

A legal register is a documented record of the legal requirements and other obligations that apply to an organisation's environmental aspects. Under ISO 14001 clause 6.1.3, it should include applicable legislation and regulations, permit and licence conditions, and any other requirements the organisation has committed to, such as industry codes of practice or contractual environmental obligations. Each entry should be specific enough to identify what the organisation is required to do, not just which law applies.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2015 Lead Auditor Training Course
20+ enrolled
View Details
Exemplar Global certified
ISO 9001:2015 Lead Auditor Training Course badge
ISO 9001:2015 Lead Auditor

Quality Management Systems (QMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
USD 249USD 789
ISO 45001:2018 Lead Auditor Training Course
15+ enrolled
View Details
Exemplar Global certified
ISO 45001:2018 Lead Auditor Training Course badge
ISO 45001:2018 Lead Auditor

Occupational Health and Safety Management Systems (OHSMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
USD 249USD 789
ISO 14001:2026 Lead Auditor Training Course
10+ enrolled
View Details
Exemplar Global certified
ISO 14001:2026 Lead Auditor Training Course badge
ISO 14001:2026 Lead Auditor

Environmental Management Systems (EMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
USD 249USD 789
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Access to self-coaching assessment
  • Access to webinars, events, and online resources
Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Instant Certificate

Download your digital certificate the moment you complete the course.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.