Skip to main content
Category: Regulatory Compliance

Compliance Obligation Register

Also known as: Obligations Register, Regulatory Obligations Register, Compliance Register, Compliance Obligations Register
Simply put

A compliance obligation register is a central record that lists the external laws, regulations, and standards an organization must follow, along with the specific requirements each one imposes. It typically also identifies who within the organization is responsible for meeting each obligation. The register helps an organization keep track of what applies to it and stay aware of its compliance duties.

Formal definition

A compliance obligation register is a structured, centralized repository used to identify, organize, and manage the external legal, regulatory, and standards-based obligations applicable to an organization, together with the internal accountabilities attached to them. Entries commonly capture attributes such as the relevant act or regulation, applicable sections of legislation, associated requirements, penalties for non-compliance, and the responsible owner. It supports the ongoing identification, assessment, recording, and reporting of obligations and related breaches. As a compliance artifact, it is distinct from the controls implemented to satisfy obligations and from assurance activities that test those controls; the specific fields, structure, and applicable obligations vary by jurisdiction, industry, and organization. This entry does not address implementation tooling or constitute legal advice.

Why it matters

A compliance obligation register addresses a foundational problem in compliance management: an organization cannot demonstrate adherence to obligations it has not clearly identified. As the volume of external laws, regulations, and standards applicable to an organization grows and changes, a central record helps the organization understand the full scope of what applies to it and the specific requirements each obligation imposes. Without such a consolidated view, obligations may be tracked informally or in dispersed locations, increasing the risk that a requirement is overlooked or that accountability for it is unclear.

The register also supports the assignment of ownership. By identifying who within the organization is responsible for meeting each obligation, it helps convert a general awareness of regulatory duties into specific accountabilities that can be monitored over time. Some registers additionally capture information such as the relevant act or regulation, applicable sections of legislation, and penalties for non-compliance, which can help those responsible understand the significance of each obligation.

It is important to recognize what the register is and is not. It is a record of obligations and accountabilities; it is distinct from the controls an organization implements to satisfy those obligations and from the assurance activities that test whether those controls operate effectively. A well-maintained register can support the identification, assessment, recording, and reporting of obligations and related breaches, but it does not by itself guarantee compliance. Its usefulness depends on keeping it current as applicable obligations change, which vary by jurisdiction, industry, and organization.

Who it's relevant to

Compliance officers
Compliance officers use an obligation register to consolidate the external laws, regulations, and standards that apply to the organization and to track the specific requirements each imposes. It provides a reference point for monitoring compliance duties and for recording and reporting breaches of those obligations.
Obligation owners and accountable business managers
Individuals identified in the register as responsible for meeting particular obligations rely on it to understand what they are accountable for and the requirements attached to each obligation. The register helps translate organization-wide regulatory duties into clearly assigned responsibilities.
Risk managers
Risk managers can use the register's record of applicable obligations, including any noted penalties for non-compliance, to inform their understanding of compliance-related exposures. The register itself is a record of obligations rather than an assessment of controls, so it complements rather than replaces risk and control activities.
Internal auditors and assurance functions
Assurance functions may reference the register to understand the population of obligations the organization has identified when planning or performing their work. Consistent with the independence of assurance activities, auditors evaluate rather than maintain the register and the controls that satisfy the underlying obligations.

Inside Compliance Obligation Register

Obligation source
The originating authority for each entry, such as an applicable law, regulation, regulatory guidance, contractual commitment, industry standard, or internal policy. Sources are typically recorded with enough specificity to trace the obligation back to its origin, though citation detail varies by jurisdiction and sector.
Obligation description
A plain-language statement of what the organization is required to do or refrain from doing. This translates the underlying source into an actionable requirement without substituting for the source text itself.
Applicability scope
The jurisdictions, business units, processes, or activities to which the obligation applies. Because many obligations depend on jurisdiction, industry, and organization size, applicability is commonly qualified rather than treated as universal.
Ownership and accountability
The role, function, or individual accountable for meeting the obligation. In organizations using a three lines model, register ownership commonly sits with first-line management, while a second-line compliance function may maintain the register itself.
Linked controls
References to the controls, policies, standards, or procedures that address each obligation. This distinguishes the obligation (what must be adhered to) from the control (the mechanism intended to achieve adherence).
Status and review cadence
Indicators of current compliance status and the date or trigger for the next review, supporting the register's maintenance as regulations and internal policies change over time.

Common questions

Answers to the questions practitioners most commonly ask about Compliance Obligation Register.

Is a compliance obligation register the same as a risk register?
No. A compliance obligation register catalogues the specific external laws, regulations, and internal policy commitments to which an organization is subject, along with the sources of those requirements. A risk register records identified risks, their assessment, and treatment against objectives. The two are related and often cross-referenced, because non-compliance with an obligation may itself be a source of risk, but they serve different purposes and should not be merged. Conflating them tends to obscure whether an entry describes a requirement the organization must meet or an uncertainty it is managing.
Does maintaining a compliance obligation register mean the organization is compliant?
No. A register is a record of what obligations apply; it does not by itself demonstrate that those obligations are being met. Compliance depends on the controls, activities, and evidence associated with each obligation, which are typically tracked separately or linked from the register. Treating the existence of a register as proof of compliance is a common misconception. The register supports compliance management by identifying and organizing obligations, but assurance over adherence generally requires additional monitoring, testing, and evidence.
Who is typically responsible for maintaining the register?
Responsibility commonly sits with a compliance function operating in a second line role, which coordinates the identification and recording of obligations. However, the ownership of individual obligations often rests with the business or operational areas in the first line that carry out the relevant activities. Practices vary by organization size, structure, and sector, and some organizations distribute maintenance across multiple functions, so the specific allocation should be defined in the organization's governance arrangements rather than assumed.
What information is commonly captured for each obligation?
Entries commonly record the source of the obligation, such as a named law, regulation, standard, or internal policy; a description of the requirement; the applicable jurisdiction or scope; the owner or accountable party; and links to related controls, policies, or evidence. Some registers also note review frequency and status. The precise fields depend on organizational needs and the tooling used, and this entry does not prescribe a particular data model or system.
How often should the register be reviewed and updated?
Review frequency is typically set to reflect the pace of regulatory change and the organization's risk profile, and may combine periodic scheduled reviews with event-driven updates triggered by new or amended laws, regulations, or policies. There is no single universally mandated interval; appropriate cadence varies by jurisdiction, sector, and the volatility of the applicable requirements. Organizations often assign responsibility for horizon scanning to help ensure the register stays current.
How does the register relate to controls and assurance activities?
Obligations in the register are commonly mapped to the controls intended to address them, so that each requirement can be traced to how it is managed. Assurance activities, such as internal audit reviews conducted by a third line function, may use the register to assess whether obligations are identified accurately and whether associated controls operate effectively. It is important to keep the register and the controls it references distinct from the independent assurance performed over them, preserving the objectivity of the assurance function.

Common misconceptions

A compliance obligation register is the same as a risk register.
They are distinct. A compliance obligation register catalogues external and internal requirements the organization is subject to and adheres to, whereas a risk register captures identified uncertainties assessed against objectives, including their likelihood, impact, and treatment. Compliance risk may be recorded in a risk register, but the two artifacts serve different pillars and purposes.
Maintaining the register demonstrates compliance in itself.
The register documents obligations and their linked controls; it does not by itself establish that obligations are being met. Adherence typically depends on the effectiveness of the controls and processes referenced, which are assessed separately. The register is a management tool, not assurance over the underlying controls.
Once built, the register is a static reference.
Obligations change as laws, regulations, contracts, and internal policies evolve, and as the organization's activities and jurisdictions shift. A register is commonly treated as a living record requiring periodic review and update rather than a one-time deliverable.

Best practices

Record the source of each obligation with enough specificity to trace it back to the originating law, regulation, contract, standard, or internal policy.
Assign clear ownership for each obligation, and keep register maintenance distinct from the first-line accountability for meeting the obligation.
Link obligations to the specific controls, policies, standards, or procedures intended to address them, while keeping the obligation and its controls conceptually separate.
Qualify applicability by jurisdiction, business unit, and activity rather than presenting obligations as universally applicable across the organization.
Establish a periodic review cadence and change-triggered updates so the register reflects current legal, regulatory, and policy requirements.
Keep the register distinct from the risk register and from assurance findings, using each artifact for its intended purpose.
Promotional banner for the Penetration Report Template Kit