Legal Register
ISO 45001 asks for three things you cannot fake in an audit: identify the legal obligations that apply to your organisation, evaluate whether you comply with each one, and keep it current as the law changes. The Legal Register does all three in one module — built from a questionnaire about your actual business, proposed by AI, and confirmed by a human before anything is recorded.
Note
The Legal Register is a QuickInspect module. Creating, evaluating, and archiving entries is restricted to your safety organisation; everyone else reads the register. The AI suggestion feature counts against your company's monthly AI budget.
Start with your business, not a template
Before the register can propose anything, it needs to know who you are. The business profile questionnaire asks for:
- Country — the jurisdiction whose body of law applies
- Industry sector — Construction, Manufacturing, Chemical, Logistics & Transport, Energy, Facility Management, Healthcare, Offices & Services, or Other
- Company size — the band that decides which thresholds bite
- Business activities — work at height, hot work, confined spaces, electrical work, machinery operation, manual handling, vehicle fleet, warehousing, laboratory work, welding, demolition, maintenance, office and screen work
- Hazard indicators — and each one names the norm it triggers: hazardous substances stored points at TRGS 510, contractors on site at DGUV Vorschrift 1 coordination, shift or night work at the Working Time Act (ArbZG), young workers or trainees at JArbSchG, company vehicles at DGUV Vorschrift 70
The questionnaire is the grounding. Change the profile, and the suggestions change with it.
AI proposes — you decide
Suggest entries (AI) sends that profile to a Gemini model, which matches it against the applicable body of law: laws, ordinances, technical rules, DGUV regulations, and EU directives.
The call genuinely takes up to two minutes — this is a full analysis, not a lookup — and nothing is written to your register while it runs.
What comes back is a proposal. Every suggested entry shows:
- Its norm type and jurisdiction (Law, Ordinance, Technical Rule, DGUV Regulation, EU Regulation…)
- A link to the official source — gesetze-im-internet.de, EUR-Lex, and the like
- A grounding reference naming the framework it belongs to
- A rationale quoting your own questionnaire answers — for example "The company states that contractors are regularly on site"
Uncheck anything that doesn't apply to you. Entries only enter the register when you press Create. Accepted entries stay marked AI suggested so their provenance is never lost.
Prefer to start by hand? A catalogue of 15 DE/EU starter norms — ArbSchG, ArbStättV, BetrSichV, GefStoffV, ArbMedVV, ASiG and more — is one tap away in the create form.
Evaluate, don't just list
A list of norms proves nothing. Each entry carries two judgments you set directly on the record:
- Applicability — Under Evaluation, Applicable, or Not Applicable
- Compliance — Not Evaluated, Compliant, or Non-Compliant
Both are one tap, and both are stamped with who decided and when, so the evaluation itself becomes the audit evidence. Free-text notes sit alongside each judgment for the reasoning behind it.
Add the responsible person, a periodic review interval, and an optional regulatory framework to tie the entry into a standard you report against.
Non-compliant is not a resting state
Mark an entry Non-Compliant and the register will not let it sit there. The entry shows "Action required — none linked" with a Create action button, and the same red Action required chip appears on its card in the list.
The gap becomes a corrective action with an owner, a due date, and a place on the hierarchy of controls — something you can actually close.
Link the proof to the obligation
Every entry can carry linked records that show how you comply:
- Risk assessments
- Hazardous materials
- Permits to work
- Trainings
- Plus the corrective actions created through the non-compliance gate
When an auditor asks how you comply with the Maternity Protection Act, the answer is already attached to the entry.
Scoped for larger organisations
In an enterprise tenant, obligations differ by site and by unit. Bind to scope attaches an entry to an org unit, a project, or leaves it company-wide, and the list gains scope filter chips alongside search, compliance, and applicability filters.
The register itself deliberately stays company-wide: the filters narrow your view, never your obligation. A legal duty does not disappear because someone filtered it out.
Enterprise tenants can also keep scoped business profiles — a separate questionnaire per org unit or project — so a chemical plant and a head office get different suggestions from the same company.
The law moves — so does the register
Switch on Monitor for legal updates on an entry, and a monthly scan watches that norm for changes.
When something shifts, the register:
- shows a "Legal changes detected — N entries need review" banner at the top of the list
- marks the entry with an Update flagged chip
- opens the entry with a Legal change detected card explaining what changed in plain language
- keeps it flagged until a human presses Acknowledge
Retire, don't delete
Entries you no longer track are archived — hidden from the everyday view but preserved for the audit trail, reachable any time via the Archived filter. Permanent deletion is only possible on an already-archived entry, behind an explicit confirmation.
Related
- Risk Assessment — the assessments you link as compliance evidence
- Hazardous Materials — REACH/GefStoffV obligations tracked in the register
- Permit to Work — permits linked to the norms that require them
- Training & Competency — the trainings that satisfy instruction duties