Boards: legal compliance checklist with owners, schedules and evidence

Directors reviewing a board compliance schedule

This checklist sets out the minimum baseline for legal compliance every organisation should verify now, covering governance, filings, employment, data protection, health and safety, and insurance. Use it to assign owners and set a date for an annual compliance review. Treat any gap you find as urgent, not optional, and document who closed it and when.

Table of Contents

Work through this in order. Each line has a suggested owner and how often it needs revisiting.

  • Governance: confirm director duties are understood and minuted. Owner: company secretary. Annually.
  • Filings: check confirmation statement and accounts deadlines at Companies House. Owner: finance director. Ongoing.
  • Payroll: verify PAYE registration and auto-enrolment status. Owner: HR lead. Quarterly.
  • Right-to-work: check documentation is on file for every employee. Owner: HR lead. At hire and renewal.
  • Data protection: confirm ICO registration and a current record of processing. Owner: data protection lead. Annually.
  • Health and safety: check risk assessments are dated and a written policy exists if you employ five or more people. Owner: office/site manager. Annually or after incident.
  • Licences and insurance: confirm employers’ liability cover and any sector permits are active. Owner: operations lead. At renewal.

The most common trap is treating these as one-off tasks rather than a compliance officer’s recurring brief. Late filing, missed auto-enrolment, and incorrect right-to-work checks are among the most frequent failures regulators flag, and all three are avoidable with a simple calendar.

Company filings and governance

Companies House expects a confirmation statement at least once every 12 months and annual accounts within statutory deadlines, alongside notification of any officer changes within 14 days. Directors remain personally responsible for these filings even when an accountant or company secretary handles the paperwork.

Beyond filings, directors owe statutory duties under the Companies Act 2006, sections 171 to 177, and these duties are personal and cannot be delegated. Boards should be able to show they exercised independent judgement, not simply rubber-stamped management proposals. Good minute-taking helps here: record that the board considered the relevant statutory factors, and note any dissent or concern in the members’ own words rather than smoothing it into a bland summary.

From 18 November 2025, identity verification for directors became mandatory under the Economic Crime and Corporate Transparency Act, with transitional reporting duties running until enforcement tightens by November 2026. Put verification status on the board agenda until that transition closes. Keep a folder of evidence: signed minutes, going-concern assessments, and a note of when directors’ and officers’ insurance was last reviewed. Our corporate governance checklist covers the documentary detail in more depth.

Employment obligations and payroll

Register with HMRC for PAYE before your first employee is paid; this is a legal requirement, not a formality, and it needs to happen before the first payroll run, not after. First-time employers must also meet auto-enrolment duties and pay minimum pension contributions for eligible staff.

Right-to-work checks are non-negotiable for every hire, and DBS checks apply where the role involves vulnerable groups or regulated activity. Every employee also needs a written statement of particulars, covering pay, hours, and notice periods, from day one of employment.

Recordkeeping trips up more employers than the rules themselves. Payslips, P60s, and P11Ds for benefits in kind all have specific retention and issue deadlines, and HMRC penalties apply for missing them. Build a simple calendar: payroll registration at setup, right-to-work checks at hire, pension enrolment reviewed quarterly, and year-end documents issued on schedule. Auto-enrolment failures and incorrect right-to-work paperwork are two of the most common compliance gaps inspectors find, and both are simple to prevent with a checklist rather than memory.

Data protection and privacy under UK GDPR

Maintain a record of processing activities and a privacy notice that states your lawful basis for handling personal data. This is the single document the ICO asks for first in any enquiry, and it should list what data you hold, why, and how long you keep it.

Data processing agreements need to be in place with every third party that handles personal data on your behalf, and your breach response process should specify who decides whether a breach is reportable to the ICO within the 72-hour window. Staff training on data handling should happen at induction and refresh periodically, not once and never again.

Subject access requests have statutory response timelines, and your retention schedule should be written down, not just followed by habit. Keep a simple evidence log of when each of these was last checked; that log is what shows an inspector the system works, not just that it exists on paper.

Health, safety and workplace duties

Risk assessments need to be dated, specific to your actual work activities, and reviewed after any incident or major change. A written health and safety policy is a legal requirement once you employ five or more people, though maintaining one regardless of size is sound practice for demonstrating compliance.

First aid provision, fire safety checks, and an accident log all need to be current, and certain injuries or dangerous occurrences must be reported under RIDDOR. Remote and off-site staff still fall under your duty of care, so risk assessments should cover home working setups too. These records are what protect you if a regulator ever asks how an incident was handled.

Contracts, licences and sector obligations

Review your core supplier and customer contracts for renewal dates, termination notice periods, and any clauses that have quietly expired. A single missed notice period can lock you into another year of an unwanted agreement.

Keep a central register of every licence, permit, and regulatory permission your business holds, with renewal dates flagged well in advance. If your sector touches anti-money laundering rules, environmental permitting, or regulated professional services, flag those contracts for specialist review rather than treating them as standard paperwork. Assign one person to own the licence register; when ownership is shared across departments, renewals get missed. Our guide to essential legal documents sets out what a complete contract file should contain.

Insurance and risk management

Check that employers’ liability, public liability, and (where relevant) professional indemnity and directors’ and officers’ cover all meet current limits, not the limits set when the policy was first taken out. Cover that made sense three years ago may be inadequate now if headcount or turnover has grown.

Internal controls matter as much as the policy documents. A conflict-of-interest register and a standard approval template for significant decisions create a paper trail regulators respect, because they show judgement was exercised consistently rather than case by case. Escalate any coverage gap to your broker or legal adviser rather than waiting for renewal.

Implementing the checklist: ownership, cadence and templates

A checklist only works if someone owns each line and a date forces the review. Structure it like this:

  1. Monthly: payroll and right-to-work spot checks, owned by HR.
  2. Quarterly: pension contributions, licence register, and contract renewal dates, owned by operations.
  3. Annually: full governance review, data protection audit, and insurance limits, owned by the board or company secretary.
  4. Trigger-based: any new activity, incident, or law change gets an immediate targeted review, not a wait for the next scheduled cycle.

An annual full review combined with these trigger checks prevents the slow drift that catches most organisations out. Keep three living documents: an evidence log, a register of who owns what, and an incident response checklist ready before you need it.

Pro Tip: Add a standing “compliance status” line to every board pack, even when there is nothing to report. A regulator or auditor reads a consistent record far more favourably than a perfect one that only appears when there is a problem.

Why trust this compliance checklist

. This checklist draws on statutory duties under the Companies Act 2006, current ICO guidance, and ECCTA reporting requirements, translated into the evidence auditors and regulators actually ask to see.

Ali Legal Ltd helps boards and managers turn this checklist into working practice, through fixed-fee governance reviews and document packs covering the corporate law essentials most businesses need in place.

Financial compliance beyond payroll

PAYE and pension duties cover only part of your financial compliance picture. VAT registration becomes mandatory once taxable turnover crosses the current threshold, and once registered, you need a system for quarterly returns, not a scramble at deadline.

Corporation tax filing runs on its own calendar, separate from VAT and payroll, and penalties for late filing compound the longer they run. If your organisation trades internationally, transfer pricing and withholding tax obligations may apply even to relatively modest cross-border arrangements, and these are easy to miss because they rarely appear on a standard compliance template.

Keep a single financial compliance calendar rather than treating VAT, corporation tax, and payroll as three separate systems run by three separate people with no shared visibility. When one deadline slips, it is usually because nobody owned the whole picture, only their slice of it. Regulatory penalties scale with the type of failure: HMRC late-filing penalties, Companies House fines, and in serious data cases, ICO fines running up to £17.5 million or 4% of turnover. That penalty range alone justifies a routine review rather than an annual scramble.

If your business has grown recently, or moved into new markets, revisit your VAT registration status specifically. Growth often pushes turnover across the threshold quietly, and the first sign of a problem is usually a penalty notice rather than an internal flag.

Financial compliance beyond payroll — overview diagram

Consumer protection compliance

Advertising standards apply the moment you make a public claim about a product or service, and the rules are stricter than most non-specialists assume. Claims about pricing, availability, and product performance all need to be capable of substantiation, not just plausible-sounding.

Product safety regulations vary by sector, but the general principle holds across all of them: you are responsible for defects even when a third-party manufacturer produced the item, if you are the one selling it under your brand or through your platform. Keep records of safety testing, supplier certifications, and any recall procedures your sector requires, because these are the first documents a trading standards enquiry will ask to see.

Consumer contracts also carry specific requirements around cancellation rights, clear pricing, and pre-contract information, particularly for anything sold online or at a distance. A contract that reads well internally can still fail these requirements if it was drafted without consumer law specifically in mind.

Review consumer-facing terms and marketing claims together, not separately, because a claim in an advert that contradicts a term in the contract is exactly the kind of inconsistency regulators look for. Assign someone to check new marketing material against your actual contractual terms before it goes live, not after a complaint arrives.

Intellectual property considerations

Trademark registration protects your brand name, logo, and any distinctive product naming, but only in the jurisdictions where you register it. A registered mark in one country offers no protection elsewhere, which matters as soon as you trade across borders or expand into new markets.

Copyright exists automatically the moment original work is created, so a copyright notice is not what creates protection, it simply puts others on notice of your claim. What matters more in practice is having a system for tracking which works you own outright, which are licensed, and which were created by contractors under terms that may or may not have assigned rights to you.

Infringement monitoring is often the piece organisations skip entirely. Set a recurring check, at minimum quarterly, for unauthorised use of your trademarks online, and keep a record of any enforcement action taken, since a pattern of inaction can weaken your position if a dispute ever escalates. Where IP sits at the centre of your business value, whether that is a product design, a brand, or proprietary content, treat the monitoring and renewal calendar with the same seriousness as your insurance schedule.

Where to check the primary sources

Verify current rules directly at Gov, Companies House, the ICO, HMRC and HSE. Seek legal advice before acting on any grey area.

What this checklist gets right that most guides miss

Most compliance checklists treat every line item as equally urgent, which is exactly backwards. The evidence here points to a smaller set of failure modes doing most of the damage: late Companies House filings, missed auto-enrolment, and incomplete data protection records. Get those three right and you have closed off the majority of realistic enforcement risk.

Three priority business compliance risks

The conventional advice tends to stop at “know the rules.” That is not where organisations actually fail. They fail on ownership: nobody assigned to a task, no date forcing a review, no record proving the check happened. A risk assessment that exists but was never dated is barely different, in a regulator’s eyes, from no risk assessment at all.

If you take one thing from this checklist, make it this: assign a named owner to every line, set a review date now, and put compliance status on every board agenda even when there is nothing new to report. That single habit, more than any individual clause you get right, is what separates organisations that pass scrutiny from those that scramble after the fact.

— Panagiotis

Get help putting this checklist into practice

Reading a checklist is the easy part. Turning it into signed policies, dated evidence, and a working review calendar is where most in-house teams run short on time, and that is exactly where Ali Legal Ltd steps in with fixed-fee governance reviews rather than open-ended hourly billing.

Ali Legal Ltd

Ali Legal Ltd works with company directors, boards, and compliance officers to translate statutory duties into practical documentation, from board minute templates to director identity verification tracking under the current ECCTA transition. If your organisation has grown, taken on new directors, or simply never had its governance structure reviewed by a solicitor, our corporate law guidance sets out exactly what a properly documented compliance file should contain. Get in touch through our contact page to arrange a fixed-fee compliance review and put dates against every item on this checklist before your next board meeting.

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

Sources

Looking for immediate assistance?


© Ali Legal Ltd 2026. All Rights Reserved
crossmenuchevron-down