Skip to main content
Category: Compliance Program Frameworks

Compliance Obligations Register

Also known as: COR, Obligations Register, Compliance Register, Regulatory Compliance Obligations Register
Simply put

A compliance obligations register is a central record that lists all the laws, regulations, standards, and internal policies an organization must follow. It typically identifies each requirement and who is responsible for it, giving the organization a single reference point for understanding what it needs to comply with. It is one documentation tool within a broader compliance program and does not by itself ensure compliance; its usefulness depends on how well it is maintained and used.

Formal definition

A compliance obligations register is a structured, centralized repository documenting the legal, regulatory, contractual, and internal-policy obligations applicable to an organization, along with attributes such as the responsible owner and, in some implementations, requirements for assessing, recording, and reporting breaches of those obligations. It functions as a compliance artifact concerned with adherence to defined external and internal requirements rather than with values-based ethical judgment, and it supports obligation identification and mapping across applicable regulations, laws, and standards. As a single documentation component, it is distinct from other program elements such as risk assessments, monitoring and auditing functions, training modules, and whistleblower channels, and it does not substitute for them. Specific structure, required fields, and any breach-reporting duties vary by jurisdiction, sector, and applicable law; organizations should confirm binding requirements against primary sources and qualified legal counsel. This entry is educational and not a substitute for professional advice.

Why it matters

Organizations of any size operate under a web of overlapping legal, regulatory, contractual, and internal-policy requirements, and without a consolidated view of those requirements it becomes difficult to demonstrate that each one is understood, assigned, and being addressed. A compliance obligations register is intended to give the organization a single reference point for what it must comply with, so that obligations are not tracked informally across disconnected spreadsheets, individual memories, or departmental silos. As a robust obligations register supports a firm's ability to fully understand all applicable regulations, laws, and standards and their requirements, it can reduce the risk that an obligation is overlooked simply because no one had visibility into it.

The register also matters because it clarifies accountability. By recording the person responsible for each obligation, it helps ensure that requirements have named owners rather than remaining unassigned. In some implementations, the register is used not only to identify obligations but also to assess, record, and report breaches of those obligations, which can support an organization's ability to detect and respond to gaps in a structured way. It is important to be clear, however, that maintaining a register does not by itself guarantee compliance or provide legal protection; its value depends entirely on how accurately it is populated and how consistently it is kept current and used.

Because the specific structure, required fields, and any breach-reporting duties vary by jurisdiction, sector, and applicable law, a register is best understood as one documentation tool that supports a compliance program rather than as a stand-alone assurance of compliance. Organizations should confirm binding requirements against primary sources and qualified legal counsel, and should not treat the register as a substitute for risk assessments, monitoring and auditing, training, or reporting channels.

Who it's relevant to

Compliance officers and ethics program managers
These readers rely on the register as a central reference for understanding the full scope of obligations the organization must follow and for confirming that each has an assigned owner. It supports their ability to map requirements across applicable regulations, laws, and standards, though they should treat it as one documentation component within a broader program rather than as evidence of compliance in itself.
Legal and audit teams
Legal and audit functions use the register to identify which legal, regulatory, and contractual obligations apply and, in some implementations, to assess, record, and report breaches. Because required fields and any breach-reporting duties vary by jurisdiction, sector, and applicable law, these teams are typically responsible for confirming binding requirements against primary sources and providing the qualified legal judgment the register itself cannot supply.
Obligation owners across the business
Individuals or roles named as responsible for specific obligations use the register to know precisely what they are accountable for. Clear ownership within the register helps ensure requirements are not left unassigned, but the underlying compliance work still depends on how consistently each owner acts on and maintains their entries.
Learning and development staff
L&D staff can reference the register to understand which obligations exist so that related training can be aligned to real requirements. It is important to note that a register is distinct from training modules and does not satisfy training obligations on its own; the two are separate program elements that support one another.

Inside COR

Obligation Source
The origin of each obligation, distinguishing external mandatory sources (applicable laws and regulations within a given jurisdiction) from internal policy commitments and voluntarily adopted standards. Because obligations vary by jurisdiction, the register should record which authority or instrument imposes each entry.
Obligation Description
A clear statement of what the obligation actually requires, drawn from the primary source. Where a requirement is jurisdiction-specific, the description should note that it does not apply universally rather than implying a blanket obligation.
Mandatory vs. Voluntary Classification
An indicator of whether the entry reflects a binding legal or regulatory duty, an internal policy commitment, or a voluntary or certifiable framework the organization has chosen to adopt. Voluntary commitments should not be recorded as if they carry the force of law.
Ownership and Accountability
The person, role, or function responsible for meeting and maintaining each obligation. This links the register to the broader compliance program rather than treating the register itself as the program.
Applicability and Scope
The business units, geographies, or activities to which each obligation applies, including any assumptions the applicability depends on and any conditions that limit the obligation's reach.
Status and Review Information
Records of current compliance status, evidence references, review dates, and change history, supporting the ongoing monitoring function. This is administrative tracking and does not by itself demonstrate compliance effectiveness.

Common questions

Answers to the questions practitioners most commonly ask about COR.

Does maintaining a compliance obligations register mean our organization has a complete compliance program?
No. A compliance obligations register is one component of a larger compliance management system, not the system itself. It catalogs the external and internal obligations an organization must meet, but it does not by itself deliver training, conduct risk assessments, operate whistleblower channels, or perform monitoring and auditing. The register supports these functions by identifying what must be complied with, but the surrounding processes that assign ownership, control, and verify adherence are what make a program operational. Treating the register as equivalent to a program overstates its role.
Is a compliance obligations register the same thing as a code of conduct or a policy library?
No, these are distinct. A compliance obligations register records the underlying obligations that arise from laws, regulations, standards, and voluntary commitments, along with their sources and applicability. A code of conduct is a values- and expectations-based document directed at employee behavior, and a policy library holds the internal rules an organization adopts. The register may map obligations to the policies or code provisions that address them, but the register itself is a structured inventory of requirements rather than the guidance or rules an organization issues to its people.
Who should own and maintain the compliance obligations register?
Ownership generally sits with the compliance function, but effective maintenance depends on collaboration across legal, risk, audit, and the business units that hold specific obligations. Many organizations assign an overall custodian responsible for the register's structure and integrity, while designating obligation owners accountable for the accuracy of individual entries. Because the precise allocation of responsibility varies by organizational structure and by local legal requirements, arrangements involving regulatory interpretation should be confirmed with qualified legal counsel. This entry is educational and not a substitute for professional advice.
How often should a compliance obligations register be reviewed and updated?
Review frequency depends on the volatility of the applicable regulatory environment and the organization's risk profile, so no single interval fits all cases. Registers are commonly reviewed on a periodic schedule and also updated on a triggered basis when regulations change, when the organization enters new jurisdictions or activities, or when internal policies are revised. Establishing both a routine cadence and clear change triggers is generally regarded as supporting a current register, though the effectiveness of any approach depends on how consistently it is implemented.
What information should each entry in the register capture?
Entries typically identify the obligation, its source and jurisdiction, its applicability to the organization, the assigned owner, and links to the policies, controls, or processes intended to address it. Some organizations also record review dates and status indicators. The aim is to make each obligation traceable from its source through to the mechanism meant to satisfy it. Because obligations differ in scope and because some are jurisdiction-specific rather than universally applicable, entries should reflect what the underlying source actually requires rather than a generalized restatement.
How does the register connect to other parts of the compliance program?
The register functions as a reference point that other program elements draw on. Risk assessments can prioritize obligations captured in the register; training can be designed around the obligations most relevant to particular roles; and monitoring and auditing can test whether controls tied to specific obligations are operating. The register itself does not perform these activities, but by providing a structured inventory of what must be complied with, it is intended to support their design and coordination. The strength of these connections depends on how the register is integrated in practice.

Common misconceptions

A compliance obligations register constitutes a compliance program.
The register is one component that catalogs obligations. A broader program also includes elements such as risk assessment, a code of conduct, training, whistleblower channels, and monitoring and auditing. Maintaining a register does not satisfy those other functions or guarantee compliance.
Every entry in the register is a legally binding requirement.
A well-constructed register separates mandatory external obligations from internal policy commitments and voluntarily adopted standards. Voluntary or certifiable frameworks do not carry the force of law, and obligations may be jurisdiction-specific rather than universal.
Having a complete register provides legal protection or proves the program is effective.
A register may support demonstrating diligence, but it does not by itself guarantee legal protection or prevent misconduct. Effectiveness depends on how obligations are implemented, monitored, and acted upon in context.

Best practices

Record the primary source and issuing authority for each obligation, and confirm details against those primary sources rather than relying on summaries.
Clearly classify each entry as mandatory, internal policy, or voluntary, and note where an obligation is jurisdiction-specific so it is not applied more broadly than it should be.
Assign a named owner or responsible function to each obligation to connect the register to accountable action within the wider compliance program.
Schedule periodic reviews and maintain a change history so the register stays current as laws, regulations, and internal policies evolve.
Treat the register as one input to monitoring and auditing, not as evidence of compliance in itself, and validate status against actual controls and evidence.
Involve qualified legal counsel where obligations touch matters that vary by local law or require legal interpretation, treating register entries as educational rather than as legal advice.