A compliance register is a centralized document where a business tracks every legal, regulatory, and contractual obligation that applies to its operations, along with the person responsible for each one, its current status, review deadlines, and the evidence proving the obligation is being met. No single statute uses the phrase “compliance register,” but multiple frameworks across financial services, data privacy, workplace safety, and healthcare either require the underlying recordkeeping or reward it heavily when things go wrong. Federal prosecutors evaluating whether a corporate compliance program actually works look first at documentation of this kind.
What Belongs in a Compliance Register
A useful register does more than list laws. It connects each obligation to a person, a status, a deadline, and the evidence proving the obligation is being met. Each entry typically carries these fields:
- Obligation identifier. A reference code linking the entry to its source, whether that’s a section of the Code of Federal Regulations, a GDPR article, or an industry standard. This makes the register searchable and auditable.
- Description in plain language. A brief explanation of what the obligation actually requires in practice. “Submit electronic injury records by March 2” is useful. A pasted block of regulatory text is not.
- Applicable business unit. Which team or department the obligation affects — human resources, finance, IT, logistics.
- Designated owner. The specific person accountable for meeting the obligation. Shared ownership is no ownership.
- Compliance status. Whether the company currently meets the requirement, needs remediation, or is under review. This field is the register’s pulse.
- Review frequency and next review date. How often the entry needs re-evaluation and when the next check is due.
- Linked internal policy. The company policy or procedure that addresses the obligation, so an auditor can trace from the law to the company’s response in one step.
- Evidence pointer. A reference to the documentation that proves compliance — training completion records, access control logs, vulnerability scan results, policy approvals, change management records.
During an audit, claiming “we follow this rule” accomplishes nothing without evidence behind it. Mapping proof directly to each obligation means your team can produce documentation on demand rather than searching through scattered files when a regulator comes knocking.
Figuring Out Which Obligations Apply
The hardest part of building a register isn’t the format. It’s identifying which laws, regulations, and standards actually apply to your operations. Most organizations undercount on the first pass because different departments face different regulatory landscapes and no single person has visibility into all of them.
A practical approach works through layers:
- Legislation and regulations. Start with the laws governing your industry, the jurisdictions where you operate, and the types of data you handle. An organization with employees in the EU faces GDPR obligations that a purely domestic U.S. company might not.
- Industry standards. Many sectors have mandatory standards beyond what the law explicitly requires. Some are voluntary but expected by customers, partners, or insurers.
- Contractual obligations. Vendor agreements, partnership contracts, and customer terms frequently contain compliance requirements that don’t come from any government but are legally binding nonetheless.
- Internal policies. Your own policies create obligations too. If your privacy policy promises a certain data handling practice, failing to follow through is both a regulatory risk and a credibility problem.
- Subject matter experts. Bring in specialists for areas like environmental compliance, export controls, or tax law. Internal teams routinely miss obligations that fall outside their core expertise.
The Department of Justice specifically evaluates whether a compliance program evolves based on changes in the business, the industry, and the regulatory environment.1U.S. Department of Justice. Evaluation of Corporate Compliance Programs Organizations that monitor proposed legislation and agency guidance proactively can prepare before new obligations take effect, rather than scrambling after the deadline passes.
Which Laws Push You Toward Keeping One
The requirement to maintain compliance records emerges from overlapping mandates. Depending on your industry, one or more of these will apply directly.
Financial Services
In the United Kingdom, the Financial Conduct Authority requires firms to maintain robust governance arrangements with clearly defined reporting lines and effective processes for identifying and monitoring risks.2Financial Conduct Authority. SYSC 4.1 General Requirements In the United States, the SEC requires investment advisers to maintain detailed books and records under rules implementing the Investment Advisers Act. The 2025 adjusted fine for a non-fraud recordkeeping violation starts at roughly $11,800 per act for an individual and about $118,200 per act for a firm, climbing to over $1.18 million per act when fraud causes substantial losses.3SEC. Adjustments to Civil Monetary Penalty Amounts The SEC can also censure a firm, suspend its registration for up to twelve months, or revoke it entirely for willful violations or supervisory failures.4GovInfo. 15 USC 80b-3 – Investment Advisers Registration and Penalties
Data Privacy
The EU’s General Data Protection Regulation requires every data controller and processor to maintain a written record of processing activities, including the purposes of processing, categories of personal data handled, categories of recipients, and a description of security measures.5General Data Protection Regulation. General Data Protection Regulation Article 30 – Records of Processing Activities Violating this obligation can trigger fines of up to €10 million or 2% of worldwide annual turnover, whichever is higher.6GDPR. Article 83 – General Conditions for Imposing Administrative Fines
Workplace Safety
In the U.S., employers with more than ten employees must keep injury and illness records under OSHA regulations unless they operate in a specifically exempted low-hazard industry. These records must be retained for five years following the calendar year they cover.7eCFR. 29 CFR Part 1904 – Recording and Reporting Occupational Injuries and Illnesses Employers in high-hazard industries with 100 or more employees must also submit these records electronically through OSHA’s Injury Tracking Application. OSHA uses submitted data to target workplaces for inspection.
Healthcare
Covered entities under HIPAA must maintain written policies and procedures, document all required actions and designations, and retain that documentation for six years from the date of creation or the date it was last in effect, whichever is later.8eCFR. 45 CFR 164.530 – Administrative Requirements Healthcare organizations that fail to report required information accurately and on time face civil penalties of up to $1 million as adjusted annually.9Centers for Medicare & Medicaid Services. Audits and Penalties for Open Payments Reporting Entities
How a Register Changes What Regulators Do
A well-maintained register can meaningfully change what happens when something goes wrong. The Department of Justice evaluates corporate compliance programs by asking three questions: Is the program well designed? Is it applied in good faith with adequate resources? Does it work in practice? Prosecutors assess whether a company documented its risk assessments, maintained accessible policies tailored to identified risks, provided role-specific training, and kept records of monitoring and investigations. Documentation must be sufficient to demonstrate the program was actually implemented, not just sitting on a shelf.1U.S. Department of Justice. Evaluation of Corporate Compliance Programs A register that maps each obligation to its owner, its status, and its supporting evidence answers those questions on the spot.
The Federal Sentencing Guidelines add a mechanical incentive. Under the organizational guidelines, an effective compliance and ethics program is a mitigating factor that directly reduces a company’s culpability score at sentencing. To qualify, the organization must establish standards and procedures to prevent and detect criminal conduct, assign high-level personnel to oversee the program, conduct periodic risk assessments, and provide training throughout the organization.10United States Sentencing Commission. USSG 8B2.1 – Effective Compliance and Ethics Program The Commission has extended this reduction to organizations of all sizes.11United States Sentencing Commission. The Organizational Sentencing Guidelines
Beyond civil fines, federal law creates personal criminal liability for tampering with records. Under Sarbanes-Oxley, an executive who knowingly certifies a financial report that doesn’t meet disclosure requirements faces up to $1 million in fines and 10 years in prison; if the certification is willful, the maximum jumps to $5 million and 20 years.12Office of the Law Revision Counsel. 18 USC 1350 – Failure of Corporate Officers to Certify Financial Reports A separate provision targets anyone who destroys or falsifies records to obstruct a federal investigation and carries up to 20 years in prison. It applies broadly to any record connected to a matter within federal jurisdiction, not just financial statements.13Office of the Law Revision Counsel. 18 USC 1519 – Destruction, Alteration, or Falsification of Records in Federal Investigations If an executive knows the company’s obligations aren’t being tracked and a regulator later opens an investigation, the absence of records can look a lot like concealment.
Scoring and Prioritizing Entries
Not every obligation carries the same weight. An overdue workplace safety filing that could trigger an OSHA inspection and a minor internal policy acknowledgment two weeks behind schedule are not equivalent risks, and your team shouldn’t treat them that way.
Most organizations use a risk matrix that scores each obligation on two dimensions: the likelihood of a violation occurring and the financial or operational impact if it does. The simplest version uses qualitative scales (low, medium, high) for each factor. Organizations with more data can assign numerical values, multiplying threat probability by vulnerability and impact to produce a risk priority number. Either approach works as long as it produces a clear ranking that drives resource allocation.
Factors that push an obligation higher in priority include the size of potential fines, the likelihood of regulatory inspection in that area, whether a violation could result in criminal liability, and how visible the failure would be to customers or the public. Residual risk matters too. After accounting for the controls already in place, some obligations still carry meaningful exposure, and those are the ones that deserve additional investment.
Spreadsheet or GRC Platform
Organizations just starting out typically build their register in a spreadsheet with customized columns for each field. For a small company with a manageable number of obligations, this works well enough and costs nothing beyond the setup time. The register needs to be searchable, filterable by business unit and status, and accessible to everyone who owns an obligation.
Spreadsheets break down as the count grows. Manual updates introduce errors, version control becomes a headache when multiple people edit the same file, and there’s no built-in way to send automated reminders when a review deadline approaches. Organizations tracking hundreds of obligations across multiple jurisdictions often find the maintenance time exceeds the cost of dedicated software.
Governance, risk, and compliance platforms centralize register data in one system, automate review reminders, generate audit-ready reports, and provide dashboards showing compliance status in real time. They scale more easily as the business adds obligations, teams, or geographic reach. The tradeoff is cost and implementation time. For mid-size and larger organizations, the efficiency gains typically justify the investment. For a ten-person startup tracking two dozen obligations, a well-structured spreadsheet reviewed on a regular schedule is perfectly adequate.
Keeping the Register Current
A register that reflects last year’s regulatory environment is worse than useless because it creates a false sense of confidence. The update process needs a defined schedule, clear ownership, and a reporting mechanism that reaches leadership.
A quarterly review cycle is common practice. Every 90 days, the compliance team evaluates whether new legislation has been enacted, whether existing obligations have changed, and whether business changes — new markets, new products, acquisitions — have introduced new regulatory requirements. When a new obligation is identified, the compliance officer adds it to the register, assigns an owner, and sets the initial review date.
Each update cycle should produce a summary for executive management that highlights new obligations added, entries where the status changed from compliant to needs-remediation, and any approaching deadlines. A formal sign-off by the chief compliance officer creates an audit trail showing the organization was actively monitoring its obligations rather than waiting for a regulator to point out gaps.
The flip side of a diligent register is a neglected one. A register full of entries marked “needs remediation” for months on end, or one that hasn’t been updated since a major regulatory change, tells regulators that the company saw its problems and chose not to fix them. That is harder to defend than not having a register at all, because it demonstrates awareness without action. A compliance register is both a shield and a mirror: it protects you when you have been diligent, and it reflects exactly how much you have neglected when you haven’t.