← Insights

Compliance

Knowing every obligation you are actually on the hook for

July 2026 · 6 min read

Every organisation carries a stack of obligations it never chose: data protection, health and safety, employment law, financial reporting, environmental rules, information security commitments in customer contracts. The striking thing about compliance failures is how rarely they come from not knowing an obligation exists. Far more often, the obligation was known, was handled once, and then slipped - a review that never happened, a rule that changed while nobody was watching, a control that quietly stopped being maintained.

An obligations register is the antidote to slippage. It is not a filing cabinet of regulations. It is a live list of what you must do, who is responsible for each, and when each one next needs looking at.

A policy is not an obligation

It is worth being precise here, because the two get muddled. An obligation is an external requirement - something a law, a regulation, a standard or a contract compels you to do. A policy is your internal response to it, the rule you write to meet the requirement. UK GDPR is an obligation; your data protection policy is a policy. The Health and Safety at Work Act is an obligation; your safety arrangements are the policy.

The obligation is what you owe the outside world. The policy is how you have decided to pay it. A register of one is not a register of the other.

This matters because you can have a perfectly good policy for an obligation whose review has lapsed, or an obligation with no clear owner and no evidence at all. Tracking policies tells you about your documents. Tracking obligations tells you about your exposure. You need both, but the obligations view is the one that answers "what are we actually on the hook for, and are we meeting it?"

What each row needs to carry

A useful obligations register captures a small, disciplined set of fields for every entry.

Grouping by compliance area is quietly powerful. Sorted that way, the register shows you where your obligations cluster and where a single owner is carrying more than is wise. It turns a flat list into a map of exposure.

Let the status decide itself

The engine of the register is the same one that makes any good compliance tool trustworthy: the review dates compute. From the last review date and the review frequency, next review and days remaining are arithmetic, and a status can then flag green Current, amber Due soon and red Overdue on its own. This is what "direction-aware" means in practice - the register decides the state for you rather than relying on someone to remember, which is the control that always eventually fails.

The value is that "is anything overdue?" becomes a colour rather than an investigation. You open the register before a compliance review and the amber and red rows are already sorted to the top. Nothing depends on a person recalling that the annual fire risk assessment is due, or that a contractual security commitment needs re-checking this quarter.

The register an auditor can follow

A flat table of obligations with no dates and no owners tells an auditor very little, and worse, it tells them you are not really managing the obligations - just listing them. A register that carries an owner, a control, an evidence reference and a live review status tells the opposite story. Pick any row, and you can name who is responsible, what meets the requirement, where the proof is, and when it was last checked. That is the difference between having obligations and managing them, and it is exactly the difference an assessor is trained to notice.

Build it once, keep the review dates honest, and the question that keeps compliance managers awake - "is there something we are meant to be doing that has quietly lapsed?" - stops being a worry and becomes a page you can read at a glance.

Every obligation in one place, reviews flagged

Obligation to source to owner to control, grouped by compliance area, with Next Review and Days Left computing themselves and status flagging Overdue and Due soon on its own - plus an evidence reference column and a live dashboard. A tool to organise your own compliance, not legal advice.

Get the Compliance Obligations Register on Etsy

Never miss a guide

New articles and templates, straight to your inbox. Plus a free tool to start.

By subscribing you consent to receive emails from Axiom. Your address is stored with Kit, our email provider, and never shared. Unsubscribe any time via the link in every email. Privacy policy.