Saaksh
Blog
How-to8 September 2026·9 min read·Saaksh

The ISO 14001 and 45001 document register: what you must actually keep

Both standards dropped the old requirement to write a procedure for everything, which is exactly why teams now lose track of what is genuinely mandatory. A clause-by-clause register of the documented information ISO 14001:2015 and ISO 45001:2018 require, split into what you maintain and what you retain, and how it doubles as BRSR evidence.

How-to
SSaaksh

Both standards did something helpful in their current editions and then created a new problem by doing it. ISO 14001:2015 and ISO 45001:2018 dropped the old obligation to write a documented procedure for nearly everything, replacing it with a shorter list of documented information that must be kept. That was a genuine simplification. It also means teams now routinely lose track of what is actually mandatory, and either over-document out of anxiety or discover a gap during a surveillance audit.

This is the register: clause by clause, split into what you maintain and what you retain, and with a note on how the same evidence feeds a BRSR filing.

Key takeaways

  • 01Maintain means a living, version-controlled document. Retain means a record of something that happened, which is not edited afterwards. Auditors test the two differently.
  • 02ISO 14001:2015 requires seven maintained documents and seven categories of retained records.
  • 03ISO 45001:2018 shares the management-system scaffolding and adds the OH&S-specific items: consultation and participation, hazard identification, procurement and contractor control, and incident investigation.
  • 04The same register is among the strongest BRSR evidence a company has: the environmental side feeds Principle 6, the safety side feeds Principle 3.

Maintain versus retain

Both standards use the two words deliberately and the distinction is the thing most registers get wrong.

Maintain means a document that is kept current: the policy, the scope, the aspects register. It has a version, an owner and a review date, and an auditor will check that it reflects the organisation as it is now.

Retain means a record of something that occurred: an audit result, a training certificate, a monitoring reading. It is not revised after the fact, and an auditor will check completeness and traceability rather than currency.

Build the register with a column for which of the two applies to each item. It changes how each is stored and reviewed.

ISO 14001:2015, documents to maintain

ClauseDocumented information
4.3Scope of the environmental management system
5.2Environmental policy
6.1.2Environmental aspects, and the criteria used to determine significance
6.1.3Compliance obligations
6.2Environmental objectives and the plans to achieve them
8.1Information needed to have confidence that processes are carried out as planned (operational control)
8.2Emergency preparedness and response

ISO 14001:2015, records to retain

ClauseRecord
7.2Evidence of competence: training, skills, experience, qualifications
7.4Evidence of communications, internal and external
9.1Results of monitoring, measurement, analysis and evaluation
9.1.2Results of the evaluation of compliance
9.2The internal audit programme and the audit results
9.3Results of management review
10.2Nature of nonconformities, actions taken, and the results of corrective action

The two auditors ask for first

The compliance obligations register (6.1.3) and the evaluation of compliance records (9.1.2). They are also the two most commonly out of date, because they depend on tracking regulatory change rather than on anything the site does day to day.

ISO 45001:2018, what it adds

The management-system scaffolding is structurally the same: scope, policy, objectives, competence, communications, monitoring, internal audit, management review, nonconformity. That shared structure is what makes an integrated register practical. The additions are the occupational health and safety specifics:

  • Worker consultation and participation (5.4). Evidence that workers and, where they exist, their representatives were consulted, not merely informed. Committee minutes, consultation records, attendance.
  • Hazard identification and risk assessment (6.1.2). The methodology and criteria as maintained documents, and the assessments themselves as records.
  • Eliminating hazards and reducing risk (8.1.2). Evidence that the hierarchy of controls was applied, rather than jumping straight to personal protective equipment.
  • Procurement, contractors and outsourcing (8.1.4). How OH&S requirements are imposed on contractors and suppliers, and evidence they were applied. In Indian manufacturing this is frequently the weakest area, and it is also exactly where BRSR Principle 3 asks about contractor safety.
  • Emergency preparedness and response (8.2), including drill records.
  • Incident investigation (10.2). Investigation records, findings, and corrective actions taken.

Running one register for both

Where a site is certified to both, the shared clauses should produce one document, not two near-identical ones that drift apart. In practice that means a combined policy, one scope statement covering both systems, a single competence and training record set, one internal audit programme covering both, and one management review that addresses both agendas.

Keep separate only what is genuinely standard-specific: the environmental aspects register and compliance obligations on one side, hazard identification and consultation records on the other. A register that shows which items are shared and which are specific is the artefact that makes an integrated audit go smoothly.

Why this register is BRSR evidence

This is the part most teams miss, and it is worth raising with a client in the kickoff meeting. A company certified to ISO 14001 and 45001 has already built much of the evidence trail BRSR asks for, and it is sitting in a system nobody thought to point at the filing.

  • The compliance obligations register and evaluation of compliance records map onto Principle 6 environmental compliance disclosures, and onto Principle 1 on fines and penalties.
  • The monitoring and measurement records are the source data for Principle 6 energy, water, waste and emissions, and they usually already carry the meter-level granularity an assurer wants.
  • The incident and investigation records feed Principle 3 safety disclosures directly.
  • The competence and training records feed Principle 3 training disclosures and Principle 1 training on the principles.
  • The consultation and participation records support Principle 3 and Principle 4 stakeholder engagement.

That last point is the practical takeaway: an ISO-certified client is usually much further along on BRSR than the client believes. Our free gap analysis cross-references what a company already files and documents against all 108 BRSR fields, which is the fastest way to find out how much of the work is already done.

Frequently asked questions

What documents are mandatory under ISO 14001:2015?
The documents you maintain are the EMS scope (4.3), the environmental policy (5.2), environmental aspects and impacts (6.1.2), compliance obligations (6.1.3), environmental objectives and the plans to achieve them (6.2), operational control information (8.1) and emergency preparedness and response (8.2). The records you retain cover competence (7.2), communications (7.4), monitoring and measurement results (9.1), compliance evaluation (9.1.2), the internal audit programme and results (9.2), management review outputs (9.3) and nonconformity and corrective action (10.2).
What is the difference between maintaining and retaining documented information?
Both ISO 14001:2015 and ISO 45001:2018 use the two words deliberately. Maintain means a living document that is kept current, such as the policy or the aspects register. Retain means a record of something that happened and is not edited afterwards, such as an audit result or a training record. Auditors check version control on the first and completeness on the second.
What does ISO 45001 require that ISO 14001 does not?
The occupational health and safety additions: evidence of worker consultation and participation, the hazard identification and risk assessment methodology, the process for eliminating hazards and reducing risk, controls over procurement and contractors, and incident investigation records. The management-system scaffolding, scope, policy, objectives, competence, audit and management review, is structurally the same, which is what makes an integrated register practical.
Can an ISO register be used as BRSR evidence?
Yes, and it is one of the strongest sources available. The ISO 14001 aspects register, compliance obligations register and monitoring records feed BRSR Principle 6, and the ISO 45001 incident, training and consultation records feed Principle 3. A company certified to both is usually much further along on BRSR than it realises.

Try Saaksh free

BRSR gap analysis in under 60 seconds. No login, no data leaves your browser.

Start a free report

Stay ahead of the regulation

SEBI, BRSR, CBAM and CCTS moves that matter, plus the newest guides, in your inbox. No spam.

More from the blog