Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Category: Regulatory Obligations Management

Compliance Register

Also known as: Legal Register, Regulatory Register, Regulatory Compliance Register, Obligations Register, Legal Compliance Register
Simply put

A compliance register is a centralised document or system of record that lists all the laws, regulations, standards, and other obligations an organisation is required to meet. It helps a business keep track of what applies to its operations and understand the requirements attached to each obligation. Many organisations use it as a starting point for managing how they demonstrate that these obligations are being addressed.

Formal definition

A compliance register is a structured record of the external and internal obligations applicable to an organisation's operations, typically capturing relevant laws, regulations, codes, standards, and permits along with their associated requirements. In practice, it often serves as the foundation for mapping obligations through to the controls that address them, thereby supporting the ongoing tracking and management of those controls. Sitting primarily within the compliance pillar of GRC, its structure, scope, and level of detail vary by jurisdiction, sector, and organisation, and it may be maintained as a document or within a dedicated system of record; the register itself is a documentation and tracking instrument rather than a control that modifies risk, and applicability of specific obligations should be verified against the primary legal or regulatory sources.

Why it matters

For most organisations, the practical challenge of compliance begins with a simple but difficult question: which laws, regulations, and standards actually apply to us? A compliance register addresses this by consolidating those obligations into a single structured record, so that the organisation can understand not only what applies but also the specific requirements attached to each item. Without such a record, obligations tend to be tracked informally across departments, spreadsheets, and individual knowledge, which can leave gaps that are difficult to detect until an obligation is missed.

The register also matters because it typically forms the foundation for the rest of a compliance programme. In many frameworks, the register serves as the starting point for mapping obligations through to the controls intended to address them, and then for tracking and managing those controls over time. It is important to note that the register itself is a documentation and tracking instrument rather than a control that modifies risk; its value lies in enabling visibility and structure, not in providing assurance on its own. Applicability of any specific obligation should still be verified against the primary legal or regulatory sources.

Because applicable obligations differ by jurisdiction, sector, and organisation, a compliance register also supports adaptability as an organisation's operations or the regulatory environment change. Maintaining it as a living record can help an organisation demonstrate that it has identified its obligations and is addressing them, though the depth and formality of the register vary considerably in practice.

Who it's relevant to

Compliance Officers
Compliance officers often rely on the register as the authoritative inventory of applicable obligations and their requirements, using it as a starting point for building and maintaining the wider compliance programme. It helps them establish visibility over what the organisation must meet and provides a structured basis for demonstrating that obligations are being addressed.
General Counsel and Legal Teams
Legal teams may maintain or contribute to the register, sometimes referred to as a legal register, to document the laws, regulations, codes, and permits relevant to the organisation's operations. Because determining whether a specific obligation applies can involve legal interpretation, legal input is often important in confirming applicability against primary sources.
Risk Managers
Risk managers use the register as an input for understanding the obligations against which controls are mapped and managed. While the register itself does not modify risk, the visibility it provides over obligations and their associated controls can support broader risk management activities.
Internal Auditors
Internal auditors may reference the register to assess whether an organisation has identified its applicable obligations and whether controls are mapped to them. It can serve as a reference point when testing how obligations are tracked through to the controls intended to address them.

Inside Compliance Register

Obligation Inventory
A structured list of the applicable laws, regulations, standards, and internal policies to which the organization is subject, typically capturing the source instrument and the relevant provision or requirement at a level of granularity useful for assessment.
Ownership and Accountability
Identification of the individual, role, or function accountable for each obligation, often distinguishing the owner responsible for compliance from those who perform related tasks. This supports the governance objective of clear decision rights and accountability.
Applicability and Scope
Information on which entities, jurisdictions, business units, or activities a given obligation applies to, recognizing that applicability commonly varies by jurisdiction, sector, and organization size.
Linked Controls and Measures
References to the controls, policies, procedures, or other measures in place to address each obligation, keeping the register's obligation (what must be done) distinct from the controls (measures that modify the associated compliance risk).
Compliance Status and Assessment
An indication of the current state of adherence for each obligation, which may draw on assessment results, monitoring, or attestations, often noting gaps or open actions where relevant.
Review and Currency Information
Metadata such as last review date, review frequency, and change history, since regulatory requirements and framework language evolve and the register's value depends on being kept current.

Common questions

Answers to the questions practitioners most commonly ask about Compliance Register.

Is a compliance register the same as a risk register?
No, though the two are related and often cross-referenced. A compliance register typically catalogues the external laws, regulations, and internal policies to which an organization is subject, along with the obligations they impose. A risk register, by contrast, records potential events and their effects on objectives, together with assessments and treatments. Compliance failures may be captured as risks within a risk register, but the compliance register itself is generally focused on documenting obligations and adherence status rather than assessing uncertainty against objectives. Organizations sometimes integrate the two, but they serve distinct purposes and should not be conflated.
Does maintaining a compliance register mean an organization is compliant?
Not on its own. A compliance register is a documentation and tracking tool; it records applicable obligations and, in many implementations, the status of measures intended to meet them. Maintaining one supports compliance efforts but does not by itself guarantee that obligations are being met in practice. Actual compliance depends on the effectiveness of underlying controls, the accuracy and currency of the register, and how the organization acts on what it records. A register can also become outdated or incomplete, so its existence should not be treated as evidence of compliance without supporting verification.
What information is typically captured for each entry in a compliance register?
Practices vary by organization and sector, but entries often include the source obligation (such as a specific law, regulation, standard, or internal policy), a summary of the requirement, the jurisdiction or scope to which it applies, an owner or accountable party, associated controls or actions, and a status indication. Many registers also record review dates, evidence references, and links to related risks or incidents. The precise fields should be tailored to the organization's regulatory environment and governance needs, and the level of detail often reflects the complexity and criticality of the obligations involved.
Who should own and maintain the compliance register?
Ownership arrangements vary. In many organizations a compliance function or designated compliance officer maintains the overall register, while accountability for individual obligations is often assigned to the business owners or subject-matter experts closest to the relevant activity. Clear allocation of decision rights and responsibilities is a governance matter, and defining who updates entries, who reviews them, and who escalates gaps helps keep the register reliable. The appropriate model depends on organizational size, structure, and the resources available to the compliance function.
How often should a compliance register be reviewed and updated?
There is no single mandated frequency; appropriate review cadence depends on the volatility of the applicable regulatory environment, the sector, and the organization's risk profile. Many organizations combine periodic scheduled reviews with event-driven updates triggered by regulatory change, new activities, or incidents. Because laws and standards evolve and framework language changes across editions, a mechanism for monitoring regulatory developments typically supports the register's currency. Organizations should verify specific review expectations against any applicable regulatory requirements in their jurisdiction, as these may vary.
How does a compliance register relate to other GRC tools and frameworks?
A compliance register often connects to broader governance, risk, and compliance activities. It may cross-reference the risk register, control libraries, policy repositories, and incident or issue logs, so that obligations, the controls that address them, and any failures can be traced together. Voluntary standards and frameworks addressing compliance management, such as ISO 37301, describe compliance management systems within which such documentation commonly sits, though implementation details and terminology differ across frameworks and organizations. Integration should be designed to fit the organization's existing structures rather than assumed to follow any single prescribed model.

Common misconceptions

A compliance register is the same as a risk register.
The two typically serve different, though related, purposes. A compliance register catalogues obligations arising from external laws, regulations, and internal policies and the organization's adherence to them, whereas a risk register records potential events and their effect on objectives. Compliance obligations may give rise to entries in a risk register, but the artifacts are generally maintained as distinct records addressing different questions.
Listing an obligation in the register, or recording a linked control, demonstrates compliance.
A register documents that an obligation is known and that measures are intended or claimed to address it; it does not, by itself, confirm that those measures operate effectively or that the obligation is met. Establishing actual adherence typically depends on assessment, monitoring, or testing of the associated controls, and the register should not be read as guaranteeing a compliance outcome.
A compliance register is a legal requirement with a standardized, mandated format.
Maintaining a register is widely treated as a leading practice and is referenced in various compliance-management standards and guidance, but whether any specific form of register is legally required, and what it must contain, varies by jurisdiction, sector, and applicable regime. Practitioners should verify specific obligations against the relevant primary sources and, where needed, obtain professional advice.

Best practices

Assign a clearly identified owner to each obligation and distinguish accountability for compliance from responsibility for performing related tasks, reinforcing governance clarity over decision rights.
Record the source instrument and relevant provision for each obligation at a granularity that supports meaningful assessment, and verify specifics such as effective dates against the primary source rather than relying on the register alone.
Keep the obligation itself distinct from the controls linked to it, so that the register does not conflate what must be done with the measures intended to address it.
Establish a defined review frequency and capture review dates and change history, so the register reflects evolving regulatory requirements and framework language.
Support status entries with evidence from assessment, monitoring, or testing rather than treating the presence of a linked control as confirmation that the obligation is met.
Document applicability by jurisdiction, entity, and activity, and flag areas of contested or context-dependent interpretation that may require professional legal advice.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps