How Do Businesses Keep Up With Health, Safety and Environmental Law?

The usual answer is a legal register: a list of the health, safety and environmental law that applies to them, what each piece requires, who is responsible and evidence of how they comply. It is reviewed on a set cycle so changes in the law get picked up and it is the document ISO 45001 and ISO 14001 auditors ask for under clauses 6.1.3 and 9.1.2.
You do not need one by law. You do need to comply with the law and for anything beyond a very small business it is difficult to demonstrate that without some form of register.
Why keeping up is harder than it looks
UK health and safety law is not one document. It is the Health and Safety at Work etc. Act 1974 plus a large body of regulations, many with their own approved codes of practice and guidance, layered with sector specific rules and, increasingly, environmental and fire requirements that sit alongside.
It also changes. Not dramatically and not often, but enough that a register written three years ago and never revisited will contain things that have been amended or replaced.
The practical problem for most businesses is not finding the law. It is knowing which parts of it apply to them and proving they have thought about it.
What goes in a legal register
A workable register has a row for each applicable requirement and columns for:
- The legislation, with its full title and year
- What it requires, in a sentence or two, in plain language
- Why it applies to you, linked to an activity, site or substance
- Who is responsible for it
- How you comply, with a reference to the document, record or control that evidences it
- Date last reviewed and the outcome of that review
That last pair is the one people leave out and it is the one an auditor will look for.
If you work to ISO 45001 or ISO 14001, the register should also cover other requirements you have signed up to, such as client contract conditions, industry codes of practice or approved supplier scheme criteria. They are not law, but you are held to them in the same way. ISO 14001 calls all of this together your compliance obligations.
Where to look for changes
- legislation.gov.uk for the primary source, but check the note at the top of each page, as some amendments are listed but not yet written into the text
- HSE's website, particularly the guidance and news pages for your sector
- Your trade body, which usually translates changes into what they mean in practice
- Your insurer or broker, who often circulate updates
- Sector specific regulators, where they apply to you
The trap is relying on a single newsletter and assuming silence means nothing has changed.
How often to review it
Set a cycle and stick to it. Annually is the common baseline for a full review, with a lighter check every quarter or six months for higher risk or more heavily regulated businesses.
Review it out of cycle whenever:
- You start a new activity, process or substance
- You move into a new site or sector
- You take on different types of client or contract
- Something significant changes in the law
Evaluating compliance is the other half
Listing the law is the easy part. Clause 9.1.2 of both ISO 45001 and ISO 14001 requires you to evaluate compliance with it, at a planned frequency and to retain the results. ISO 14001 also expects you to keep an up to date understanding of your compliance status, not just a record from the last review.
In practice that means going through the register and asking, for each requirement, how do we know we are complying and what is the evidence. That question is usually where gaps show up and it is much better to find them yourself than to have an inspector find them.
How TalkHSE helps
TalkHSE includes a legal register that keeps your applicable requirements, the person responsible and the evidence of compliance in one place, with review dates so the evaluation actually happens rather than slipping. Because it sits alongside your risk assessments, COSHH assessments, documents and actions, the evidence you point to is the live record in the system rather than a document reference that may or may not still be accurate.
Where a review turns up a gap, it can be raised as a tracked action with an owner and a due date.
Frequently asked questions
Is a legal register a legal requirement?
No. Complying with the law is the requirement. A register is the usual way of demonstrating you know what applies to you, and ISO 45001 and ISO 14001 effectively require one through clauses 6.1.3 and 9.1.2.
Who should maintain the legal register?
Whoever is responsible for health, safety and environmental compliance, with input from the people who own each area. It should not be written by someone with no visibility of the operation.
How often should a legal register be reviewed?
At least annually as a baseline, more often in higher risk or heavily regulated sectors and immediately whenever activities or the law change.
What is the difference between a legal register and a compliance evaluation?
The register lists what applies to you. The evaluation is the exercise of checking whether you are actually complying with each item and recording the result.
Does a small business need a legal register?
It is not required. For a very small, low risk business, knowing and meeting your duties may be enough. Once you have multiple sites, activities or client audits, a register quickly becomes the easiest way to stay on top of it.
More Articles


