Compliance documents / Risk and compliance

Risk registers that are actually kept up to date.

Hazard registers, risk assessments and legal registers built around your work, with clear ratings, controls and owners, as spreadsheets or live in Optimax Comply.

The requirement

Auditors and clients will ask to see your registers.

Every ISO standard requires you to identify risks and act on them, and every head contractor expects to see a current hazard register. Most small businesses have risks scattered across emails, old spreadsheets and people's heads. We bring them into clear registers with consistent ratings, practical controls and named owners, so you can show exactly how risk is managed.

Who this is for

  • Your risks, hazards or compliance obligations are recorded in inconsistent places.
  • A client, audit or management system asks for current risk documentation.
  • A project needs an assessment that reflects its tasks, interfaces and conditions.
  • You need clearer ownership and review of controls and open actions.

Registers we prepare

RegisterUsed for
Hazard registerWorkplace and site WHS hazards (ISO 45001)
Risk and opportunity registerBusiness risks and opportunities, required by ISO 9001, 45001 and 14001
Legal and other requirements registerLaws, regulations and client obligations you must meet
Environmental aspects and impacts registerEnvironmental risks of your activities (ISO 14001)
Project risk registerRisks on a specific project or contract
Information security risk registerInformation and data risks (ISO 27001)
The outputs

What you get.

Structured registers and assessment records based on your activities and available evidence.

  • A register built for your business, project or activity
  • Risks and hazards with causes and consequences
  • A risk matrix (usually 5×5) calibrated to your business
  • Controls using the hierarchy of control, with owners and due dates
  • Review dates and triggers, so the register stays current
Spreadsheet or live register

Keep your registers live in Optimax Comply.

Spreadsheets go out of date. In Optimax Comply, your hazard register uses a built-in 5×5 risk matrix, your team can report hazards from their phone with photos, and any hazard can be escalated to an incident or a corrective action in one click. Overdue reviews trigger automatic reminders.

Explore Optimax Comply
The method

How it works.

01.

Agree the purpose and boundaries

We confirm the type of register or assessment, users, scope and any required client or management system format.

02.

Gather operational information

We review work activities, existing records, requirements and input from the people who understand the work.

03.

Identify and assess

We document relevant risks or hazards and apply the agreed assessment method using the information available.

04.

Set out controls and actions

We record existing and proposed controls, responsible owners and follow-up actions for review by your team.

05.

Validate and maintain

Your managers confirm the ratings and controls, and we issue the register, or set it up in Optimax Comply.

The difference

Why Optimax.

Registers that satisfy auditors and actually get used.

  • Built for your work. Risks drawn from your activities, sites and people, not a generic list.
  • Consistent ratings. A risk matrix calibrated to your business, so ratings mean the same thing across every register.
  • Clear ownership. Every control and action has an owner and a due date.
  • ISO-ready. Registers structured to meet ISO 9001, 45001 and 14001 requirements, and ready to run in Optimax Comply.
Questions

The practical details.

What kinds of registers can you prepare?

Hazard registers, risk and opportunity registers, legal registers, environmental aspects registers, project risk registers and information security risk registers.

Do you use a 5×5 risk matrix?

Usually, yes. It's the most common approach and what most auditors and clients expect. We calibrate the likelihood and consequence scales to your business, so the ratings are meaningful.

Can a register cover workplace hazards and business risks?

We usually keep them separate, because they're assessed differently and used by different people. They follow the same format, so they're easy to read together.

Who is responsible for approving the assessment?

Your managers. They know the work, so they confirm the ratings and controls before the register is issued.

How often should a risk register be reviewed?

At least annually, and whenever something changes: new work, new equipment, new sites or after an incident. We build review dates and triggers into every register.

What information should we send for a quote?

The type of register, your business or project scope, number of sites or activities, any required template, and your deadline.

Need a register for an audit or client?

Tell us which register, what it covers and when you need it. We'll send a quote, usually the same day.

Request a quoteWe reply within one business day.
Request a quote