rulesmate.com.au — Compliance reference
https://rulesmate.com.au/insights/compliance-obligations-register-artefacts-owners-cadence
Printed 28 August 2026
Building a compliance obligations register: artefacts, owners and review cadence
What belongs in an Australian compliance obligations register: minimum fields, a named owner per row, review cadence, and the evidence auditors ask to see.
What an obligations register is
An obligations register is a controlled list of every legal, regulatory, licence and contractual requirement that binds the entity, with a named owner, a citation to the source instrument, the control that satisfies it, and a date the entry was last verified. It is the spine of a compliance program: policies, monitoring plans, board reports and incident triage all reference back to it.
It is not a copy of the legislation, and it is not a to-do list. A register answers four questions on every row — what applies to us, who is accountable, how do we satisfy it, and when did we last check that answer is still correct.
Australian regulators rarely mandate a register in those words. What they mandate is the outcome the register produces. ACNC Governance Standard 3 requires a registered charity to comply with Australian laws — a duty that is unevidenced without a list of which laws the charity has identified. AFS licensees carry the general obligations in section 912A of the Corporations Act 2001, including adequate risk management systems. The recognised management-system standard for compliance is AS ISO 37301:2021 Compliance management systems — Requirements with guidance for use, which is paywalled through Standards Australia and is cited here by name only.
Rules Mate publishes the underlying corpus at /obligations, and the obligation finder and the Compliance Fingerprint both produce a starting shortlist for a given entity profile. Those are inputs. The register is the artefact you own, maintain and hand to an auditor.
The fields an auditor expects to see
Every row should carry the same fields, because an incomplete row is the one that gets tested. The minimum set:
| Field | What it holds | Why an auditor asks |
|---|---|---|
| Obligation ID | Stable internal reference | Lets policies, controls and incidents cite the row |
| Obligation summary | One sentence, plain English | Shows the business understood the duty, not just copied a heading |
| Source instrument | Act, regulation, rule, licence condition, code, contract clause | Distinguishes law from voluntary commitment |
| Jurisdiction | Commonwealth, state or territory, or multiple | Surfaces the state-by-state duties that get missed |
| Trigger | Who or what brings it into scope (turnover, headcount, activity, licence) | Explains why it applies to this entity |
| Accountable owner | A named role, not a team | Removes the "everyone assumed someone else" defence |
| Control reference | Policy, procedure or system that satisfies it | Links the duty to the thing that discharges it |
| Evidence type | The artefact produced (lodgement receipt, register entry, training record) | Tells the tester what to sample |
| Frequency | Event-driven, monthly, quarterly, annual | Drives the calendar |
| Next due or next review | A real date | Makes the register actionable |
| Last verified | Date the wording and applicability were last checked against source | Separates a maintained register from a stale one |
| Status | In place, gap, remediating, not applicable with reason | "Not applicable" without a reason is a finding |
The two fields most often missing are last verified and not applicable with reason. Both matter because an auditor is testing the maintenance process, not the spreadsheet.
Artefacts, owners and cadence
A register does not stand alone. It sits inside a small set of artefacts, each with an owner and a cadence:
| Artefact | Typical owner | Cadence | Evidence produced |
|---|---|---|---|
| Obligations register | Compliance lead (or CFO in a small business) | Reviewed quarterly, full refresh annually | Dated version, change log |
| Compliance calendar | Same owner, operated by finance or ops | Continuous; reviewed at each quarter end | Completed lodgement records |
| Policy suite | Policy owner per document | Review cycle set per policy, commonly annual to biennial | Approved policy with version history |
| Monitoring and assurance plan | Compliance lead | Annual plan, quarterly execution | Test papers, results, issues raised |
| Incident and breach register | Compliance lead | Continuous | Incident records, notification evidence |
| Board compliance report | Compliance lead, tabled by the accountable executive | Each board meeting | Board pack, minute |
| Regulatory change log | Compliance lead | Monthly intake, quarterly assessment | Assessed change entries |
The compliance calendar generator turns the frequency column into dated obligations, and /deadlines tracks the fixed national dates that apply regardless of entity profile. The 2026-27 compliance calendar sets out the recurring federal dates in one place.
Building the first version without boiling the ocean
Start with scope, not with law. Write down what the business actually does — the services sold, the data held, the people engaged, the premises operated, the money moved, the goods imported, the licences held. Each of those is a doorway into a regime.
Then work in four passes:
- Entity-level duties. Company registration, director duties and director ID, annual review, financial reporting, tax registrations and lodgements, employment record-keeping, work health and safety primary duty.
- Activity-triggered duties. Licensing, industry codes, product safety, privacy, anti-money laundering, environmental approvals, import and export controls.
- Threshold-triggered duties. Regimes that switch on at a revenue, headcount, emissions or asset threshold — climate reporting, modern slavery statements, payroll tax, gender equality reporting.
- Contractual duties. Customer contracts, funding agreements, franchise and supply agreements, insurance conditions. These are enforceable obligations and belong in the same register. A contract register feeds this pass.
Mark every row you cannot resolve as a gap rather than deleting it. A register with twelve open gaps and named owners is stronger evidence of a functioning program than a tidy register with silent omissions.
Keeping the register current
A register decays from the day it is signed. The maintenance mechanism is a regulatory change intake, run monthly:
- Monitor sources — regulator updates, the Federal Register of Legislation, state gazettes, industry association bulletins, and the Rules Mate changelog.
- Log each change with a date received, the instrument, and a first-pass impact call.
- Assess material changes against the register: does a row need new wording, a new control, a new owner, or a new date?
- Record the assessment outcome even where the answer is "no change required". Auditors test the negative decisions.
Set the register review as a standing quarterly item, with a full annual refresh where every row's last verified date is renewed against the source.
The evidence trail that survives an audit
Evidence is the artefact a third party can inspect without your commentary. For a register, that means:
- Version history. Dated versions, with a change log showing what moved and who approved it.
- Approval record. A minute or file note recording that the accountable body reviewed and accepted the register.
- Traceability. Each row links to the control document and, where the obligation is periodic, to the completed evidence for the last cycle.
- Retention. Keep register versions for at least the period that applies to the underlying records. Many Australian corporate and tax records carry a seven-year retention expectation; work health and safety incident records carry their own statutory minimum.
Storing the register in a spreadsheet is acceptable if version control is real. Storing it in a spreadsheet that is emailed around and edited without a change log is the finding.
Common failure modes
- Team ownership. "Finance" is not an owner. Name a role.
- Copying statutory text. A register full of quoted sections shows nobody translated the duty into an operational control.
- No "not applicable" reasoning. Exclusions carry more audit risk than inclusions.
- Register and calendar drift apart. If the calendar contains dates the register does not know about, one of them is wrong.
- No linkage to incidents. When something goes wrong, the incident record should cite the obligation ID it touched. Without that link, trend analysis is impossible.
- Annual-only review in a fast-moving regime. Where an entity sits inside a regime that is actively changing — anti-money laundering, privacy, climate reporting — quarterly is the floor.
Once the register exists, the next two artefacts follow directly: a risk register that sits alongside it, and a policy suite built to be auditable.
Frequently asked
Is a compliance obligations register legally required in Australia?
There is no single Australian law that says 'you must keep an obligations register' for all entities. The register is the practical means of evidencing duties that are mandated — for example the ACNC Governance Standard requiring charities to comply with Australian laws, the adequate risk management systems duty on AFS licensees under section 912A of the Corporations Act 2001, and prudential requirements on APRA-regulated entities. In sectors with a mandated program (anti-money laundering, critical infrastructure risk management), a documented view of applicable obligations is effectively unavoidable.
How often should an obligations register be reviewed?
A quarterly review with an annual full refresh is the common baseline. Entities operating in regimes undergoing active reform should treat quarterly as the minimum and run a monthly regulatory change intake, so that new or amended instruments are assessed against the register within weeks rather than at year end.
Who should own the register in a business without a compliance team?
Ownership of the register as an artefact usually sits with the CFO, company secretary or general manager. Ownership of individual rows should be distributed to the role that actually performs the control — payroll for withholding and reporting duties, the operations manager for licensing and safety, the head of technology for security controls. A single person owning every row is a sign the register is not operational.
What is the difference between an obligations register and a compliance calendar?
The register records what applies and who is accountable; the calendar records when each recurring item is due and whether it was completed. The calendar is generated from the frequency and due-date fields in the register. If the two disagree, one has not been maintained.
Should contractual obligations sit in the same register as legal obligations?
Yes, provided the source field distinguishes them. Contractual commitments — funding agreement conditions, customer security requirements, franchise obligations, insurance policy conditions — are enforceable and frequently more onerous than the statutory floor. Keeping them in a separate list is how organisations miss them.
Related
Related reading
Australian compliance calendar 2026–2027: every deadline you need
A month-by-month list of every major Australian compliance deadline for 2026 and 2027 — tax, super, AML, privacy, climate, WHS, modern slavery. Free .ics download.
ASX Corporate Governance Council Principles and Recommendations (4th Edition)
The 4th edition of the ASX Corporate Governance Principles took effect for financial years starting on or after 1 January 2020 with 8 Principles and 35 recommendations, disclosed under Listing Rule 4.10.3 on an 'if not, why not' basis.
Obligations register vs risk register: how the two connect and why you need both
An obligations register records what the law requires; a risk register records what could go wrong. How the two link, who owns each, and why you need both.
Writing a compliance policy that survives an audit: structure, approval and version control
Structure, approval record and version control that make an Australian compliance policy auditable — plus the document-hierarchy mistakes that draw findings.
Obligations covered
© Rules Mate · Source citations at the end · Information current as at 28 August 2026
Printed from https://rulesmate.com.au/insights/compliance-obligations-register-artefacts-owners-cadence