Skip to main content
Rules Mate

Building a compliance obligations register: artefacts, owners and review cadence

Rules Mate Editorial6 min read

What belongs in an Australian compliance obligations register: minimum fields, a named owner per row, review cadence, and the evidence auditors ask to see.

What an obligations register is

An obligations register is a controlled list of every legal, regulatory, licence and contractual requirement that binds the entity, with a named owner, a citation to the source instrument, the control that satisfies it, and a date the entry was last verified. It is the spine of a compliance program: policies, monitoring plans, board reports and incident triage all reference back to it.

It is not a copy of the legislation, and it is not a to-do list. A register answers four questions on every row — what applies to us, who is accountable, how do we satisfy it, and when did we last check that answer is still correct.

Australian regulators rarely mandate a register in those words. What they mandate is the outcome the register produces. ACNC Governance Standard 3 requires a registered charity to comply with Australian laws — a duty that is unevidenced without a list of which laws the charity has identified. AFS licensees carry the general obligations in section 912A of the Corporations Act 2001, including adequate risk management systems. The recognised management-system standard for compliance is AS ISO 37301:2021 Compliance management systems — Requirements with guidance for use, which is paywalled through Standards Australia and is cited here by name only.

Rules Mate publishes the underlying corpus at /obligations, and the obligation finder and the Compliance Fingerprint both produce a starting shortlist for a given entity profile. Those are inputs. The register is the artefact you own, maintain and hand to an auditor.

The fields an auditor expects to see

Every row should carry the same fields, because an incomplete row is the one that gets tested. The minimum set:

FieldWhat it holdsWhy an auditor asks
Obligation IDStable internal referenceLets policies, controls and incidents cite the row
Obligation summaryOne sentence, plain EnglishShows the business understood the duty, not just copied a heading
Source instrumentAct, regulation, rule, licence condition, code, contract clauseDistinguishes law from voluntary commitment
JurisdictionCommonwealth, state or territory, or multipleSurfaces the state-by-state duties that get missed
TriggerWho or what brings it into scope (turnover, headcount, activity, licence)Explains why it applies to this entity
Accountable ownerA named role, not a teamRemoves the "everyone assumed someone else" defence
Control referencePolicy, procedure or system that satisfies itLinks the duty to the thing that discharges it
Evidence typeThe artefact produced (lodgement receipt, register entry, training record)Tells the tester what to sample
FrequencyEvent-driven, monthly, quarterly, annualDrives the calendar
Next due or next reviewA real dateMakes the register actionable
Last verifiedDate the wording and applicability were last checked against sourceSeparates a maintained register from a stale one
StatusIn place, gap, remediating, not applicable with reason"Not applicable" without a reason is a finding

The two fields most often missing are last verified and not applicable with reason. Both matter because an auditor is testing the maintenance process, not the spreadsheet.

Artefacts, owners and cadence

A register does not stand alone. It sits inside a small set of artefacts, each with an owner and a cadence:

ArtefactTypical ownerCadenceEvidence produced
Obligations registerCompliance lead (or CFO in a small business)Reviewed quarterly, full refresh annuallyDated version, change log
Compliance calendarSame owner, operated by finance or opsContinuous; reviewed at each quarter endCompleted lodgement records
Policy suitePolicy owner per documentReview cycle set per policy, commonly annual to biennialApproved policy with version history
Monitoring and assurance planCompliance leadAnnual plan, quarterly executionTest papers, results, issues raised
Incident and breach registerCompliance leadContinuousIncident records, notification evidence
Board compliance reportCompliance lead, tabled by the accountable executiveEach board meetingBoard pack, minute
Regulatory change logCompliance leadMonthly intake, quarterly assessmentAssessed change entries

The compliance calendar generator turns the frequency column into dated obligations, and /deadlines tracks the fixed national dates that apply regardless of entity profile. The 2026-27 compliance calendar sets out the recurring federal dates in one place.

Building the first version without boiling the ocean

Start with scope, not with law. Write down what the business actually does — the services sold, the data held, the people engaged, the premises operated, the money moved, the goods imported, the licences held. Each of those is a doorway into a regime.

Then work in four passes:

  1. Entity-level duties. Company registration, director duties and director ID, annual review, financial reporting, tax registrations and lodgements, employment record-keeping, work health and safety primary duty.
  2. Activity-triggered duties. Licensing, industry codes, product safety, privacy, anti-money laundering, environmental approvals, import and export controls.
  3. Threshold-triggered duties. Regimes that switch on at a revenue, headcount, emissions or asset threshold — climate reporting, modern slavery statements, payroll tax, gender equality reporting.
  4. Contractual duties. Customer contracts, funding agreements, franchise and supply agreements, insurance conditions. These are enforceable obligations and belong in the same register. A contract register feeds this pass.

Mark every row you cannot resolve as a gap rather than deleting it. A register with twelve open gaps and named owners is stronger evidence of a functioning program than a tidy register with silent omissions.

Keeping the register current

A register decays from the day it is signed. The maintenance mechanism is a regulatory change intake, run monthly:

  • Monitor sources — regulator updates, the Federal Register of Legislation, state gazettes, industry association bulletins, and the Rules Mate changelog.
  • Log each change with a date received, the instrument, and a first-pass impact call.
  • Assess material changes against the register: does a row need new wording, a new control, a new owner, or a new date?
  • Record the assessment outcome even where the answer is "no change required". Auditors test the negative decisions.

Set the register review as a standing quarterly item, with a full annual refresh where every row's last verified date is renewed against the source.

The evidence trail that survives an audit

Evidence is the artefact a third party can inspect without your commentary. For a register, that means:

  • Version history. Dated versions, with a change log showing what moved and who approved it.
  • Approval record. A minute or file note recording that the accountable body reviewed and accepted the register.
  • Traceability. Each row links to the control document and, where the obligation is periodic, to the completed evidence for the last cycle.
  • Retention. Keep register versions for at least the period that applies to the underlying records. Many Australian corporate and tax records carry a seven-year retention expectation; work health and safety incident records carry their own statutory minimum.

Storing the register in a spreadsheet is acceptable if version control is real. Storing it in a spreadsheet that is emailed around and edited without a change log is the finding.

Common failure modes

  • Team ownership. "Finance" is not an owner. Name a role.
  • Copying statutory text. A register full of quoted sections shows nobody translated the duty into an operational control.
  • No "not applicable" reasoning. Exclusions carry more audit risk than inclusions.
  • Register and calendar drift apart. If the calendar contains dates the register does not know about, one of them is wrong.
  • No linkage to incidents. When something goes wrong, the incident record should cite the obligation ID it touched. Without that link, trend analysis is impossible.
  • Annual-only review in a fast-moving regime. Where an entity sits inside a regime that is actively changing — anti-money laundering, privacy, climate reporting — quarterly is the floor.

Once the register exists, the next two artefacts follow directly: a risk register that sits alongside it, and a policy suite built to be auditable.

Frequently asked

Is a compliance obligations register legally required in Australia?

There is no single Australian law that says 'you must keep an obligations register' for all entities. The register is the practical means of evidencing duties that are mandated — for example the ACNC Governance Standard requiring charities to comply with Australian laws, the adequate risk management systems duty on AFS licensees under section 912A of the Corporations Act 2001, and prudential requirements on APRA-regulated entities. In sectors with a mandated program (anti-money laundering, critical infrastructure risk management), a documented view of applicable obligations is effectively unavoidable.

How often should an obligations register be reviewed?

A quarterly review with an annual full refresh is the common baseline. Entities operating in regimes undergoing active reform should treat quarterly as the minimum and run a monthly regulatory change intake, so that new or amended instruments are assessed against the register within weeks rather than at year end.

Who should own the register in a business without a compliance team?

Ownership of the register as an artefact usually sits with the CFO, company secretary or general manager. Ownership of individual rows should be distributed to the role that actually performs the control — payroll for withholding and reporting duties, the operations manager for licensing and safety, the head of technology for security controls. A single person owning every row is a sign the register is not operational.

What is the difference between an obligations register and a compliance calendar?

The register records what applies and who is accountable; the calendar records when each recurring item is due and whether it was completed. The calendar is generated from the frequency and due-date fields in the register. If the two disagree, one has not been maintained.

Should contractual obligations sit in the same register as legal obligations?

Yes, provided the source field distinguishes them. Contractual commitments — funding agreement conditions, customer security requirements, franchise obligations, insurance policy conditions — are enforceable and frequently more onerous than the statutory floor. Keeping them in a separate list is how organisations miss them.

Related

Related reading