Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

The ISO 14001 Register — guide from Governance Docs

The ISO 14001 Registers: Aspects, Impacts and Compliance Obligations

Ask ten environmental managers what an ISO 14001 register is and you will get two
answers, because there are two. The environmental aspects and impacts register and
the compliance obligations register (still widely called the legal register) are
different documents doing different jobs. This guide covers what each must contain under the 2026
edition, and how auditors test them.

Which ISO 14001 register do you mean?

Neither ISO 14001 register is named as such by the standard. Clause 6.1 requires you to determine the environmental aspects of your activities, products and
services and the impacts associated with them, and separately to determine your compliance
obligations. Neither is called a “register” by the standard — ISO asks for documented
information, and the register is simply the form the industry has settled on.

That matters practically, because it means the format is yours to choose but the content is not.
A spreadsheet is fine. A spreadsheet missing the evaluation step is not.

The first ISO 14001 register: environmental aspects and impacts

This ISO 14001 register is the analytical core of the EMS, and everything downstream derives from it. Each row should
carry:

  • Activity, product or service, and the site or process it belongs to.
  • Operating condition — normal, abnormal (start-up, shutdown, maintenance),
    and reasonably foreseeable emergency situations. The 2026 edition sharpened the expectation that
    emergency situations with environmental impacts are considered explicitly, so a register covering
    only normal running is now an easier finding to raise.
  • Environmental aspect — the element that interacts with the environment
    (a discharge, an emission, a resource use).
  • Environmental impact — the resulting change (contamination, depletion,
    habitat loss). Aspect and impact are separate columns; collapsing them is the most common structural
    weakness.
  • Life cycle stage. The 2026 edition puts more weight on the life cycle
    perspective, so a register that stops at your own gate — ignoring raw materials, transport,
    customer use and end of life — no longer reflects the standard.
  • Significance evaluation against criteria you have defined and documented in
    advance, not invented per row.
  • Significant? A clear yes or no, because significance is what drives objectives
    and operational controls.
  • Controls in place, and the link to the procedure or objective that manages it.
  • Review trigger — the date or event that forces reassessment.

Both registers, already built to the 2026 edition.

The ISO 14001 Toolkit includes the aspects and impacts register with a documented significance methodology and life cycle columns, plus the compliance obligations register with evaluation fields — 65+ documents written to ISO 14001:2026.

Explore the ISO 14001 Toolkit →

The second ISO 14001 register: compliance obligations

The 2015 edition replaced “legal and other requirements” with compliance
obligations
, and the wider term is deliberate: it covers mandatory legal requirements
and the voluntary commitments you have chosen to be bound by — customer contracts,
industry codes, group policies, planning conditions, permit terms. Registers that list only statutes
are incomplete by design.

Each entry needs the obligation identified specifically — the duty that
binds you, not just the name of the Act — the activity or aspect it applies to, the owner, how
compliance is evaluated, when it was last evaluated, the result, and the evidence. That evaluation
column is the difference between a register and a reading list, because clause 9.1 requires you to
evaluate compliance and retain the results. Knowing the law exists is not compliance evaluation.

How auditors test an ISO 14001 register

  • They pick a significant aspect and follow it. Is there an objective, an
    operational control, a competence requirement, a monitoring result? If significance leads nowhere,
    the evaluation is decorative.
  • They pick an obligation and ask for the last evaluation and its evidence.
  • They look for the emergency and abnormal rows, and for the life cycle stages
    beyond your own operations.
  • They check the date. An ISO 14001 register untouched since before a site change, a new
    process or a new permit is a finding regardless of how good it looks.
  • They ask who owns it. A register maintained by one person that nobody else has
    read is a document, not a management system.

Keeping the ISO 14001 register alive

Both registers decay, and the compliance obligations one decays fastest because the law moves
without telling you. Subscribe to a legal update service or assign the monitoring explicitly, and
tie review to events as well as dates: a new process, a new site, a new permit, a new supplier, or a
change under the new clause 6.3 should all trigger a look. An annual review cycle on its own will
always be running behind.

See also our guides to the
ISO 14001 mandatory documents and the
ISO 14001:2026 transition.

References

More on ISO 14001

All of these are covered by the ISO 14001 Toolkit, written to the 2026 fourth edition. For background see ISO 14001 compliance, or browse the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.