Back to Home
Business Operations

Accidental non-compliance is the default: how to build a one-page obligations register

Statutory obligations are scattered across platforms nobody consolidates for you. Here is how to build a one-page obligations register in an hour, why alerts must land on a named person, and why you keep your own copy of anything a third party lodges for you.

13Labs Team25 July 20268 min read
compliancesmall business operationsprocess designrecord keepingaustralian business

Contents

What is an obligations register and why does a small business need one?

An obligations register is a single list of every statutory and contractual deadline your business has, with six columns: obligation, source, frequency, owner, evidence location, and lead time. It takes about an hour to build. It works because it moves compliance out of one person's head and into a document anyone can read.

Why does compliance quietly fall over in small businesses?

Nothing dramatic happens. A person leaves, a licence renewal notice goes to an inbox nobody reads, and a lodgement gets missed by three weeks. The business only finds out when a penalty notice arrives. The structural problem is that the information is not in one place. Bruce Billson, the Australian Small Business and Family Enterprise Ombudsman, put it this way to a parliamentary inquiry, as reported by Accountants Daily: "And, unbelievably, this information is currently not easily available in one place. Insolvency information is scattered across multiple platforms, which makes it difficult to find and easy to miss potentially critical information. This may result in accidental non-compliance." That is insolvency specifically, but the shape is the same across employment, tax, licensing and industry regulation. Your obligations sit with the ATO, your state regulator, a licensing body, your insurer, your landlord, and your franchisor. None of them talk to each other. None of them owe you a consolidated view. So the default state of a small business is accidental non-compliance. Not because owners are careless, but because there is no system that holds the whole picture. The register is that system. It is the cheapest one you will ever build.

Why can't you just ring the regulator when you're unsure?

Because you cannot always get through. This is an anecdotal complaint rather than a measured statistic, but it is worth planning around. From r/AusFinance: "I tried ringing the ATO to inquire but after layers of prompts the automated system simply declared they were too busy and hung up. Not even a queue or callback request." Treat that as a design constraint rather than a grievance. If the authoritative source is unreachable on the day you need it, then the work of finding the answer has to happen once, in advance, and be written down. That is exactly what the register does. You do the research when you are calm, record where the answer came from, and stop re-litigating it every quarter. It also changes what you do when you finally do get through. Whatever you are told, you record it in the register with the date and the reference number. The next person who asks the question does not have to sit on hold again.

What goes in the six columns?

Obligation: a plain-language description, not the legislative name, because people act on things they understand. Source: the specific page, clause or agreement it comes from, which stops arguments about whether it is real. Frequency: monthly, quarterly, annual or event-triggered, which determines how the reminder is scheduled. Owner: one named person, not a team, because ownership diffused across a team is no ownership. Evidence location: where the proof of lodgement lives, which turns "we did it" into "here it is". Lead time: how many days before the due date work starts. Lead time is the column most people skip and the one that does the actual work. A BAS due on the 28th does not become a task on the 28th. If reconciliation takes five working days, the task starts on the 21st. Write the lead time down once and every future reminder is correct. Event-triggered obligations deserve their own rows. New employee onboarding, a vehicle added to the fleet, a contractor engaged, a director change. These have no calendar date, so they never appear in a compliance calendar unless you write them in.

Why must the reminder land on a person and not a shared inbox?

Because a shared inbox is a place where responsibility goes to die. Everyone assumes someone else has it. Nobody is embarrassed when it lapses. The alert should go to a named individual, by a channel that person actually reads, with a due date attached. If your team lives in a chat tool, send it there and mention the person. If they live in email, send it to their personal address. The test is simple: if the obligation is missed, exactly one person should be able to say "that was mine." A common objection is that naming an owner creates a single point of failure. It does, and you handle that with a backup owner column and a quarterly review of the register, not by making the obligation everybody's job. A shared inbox does not remove the single point of failure. It just hides it. The other half is the escalation. If the owner has not marked the obligation complete by the due date, a second alert goes to whoever runs the business. That escalation is the part that makes the register real rather than decorative.

Why keep your own copy of records a third party lodges for you?

Because their process can fail without telling you, and you carry the consequence. As one poster on r/auslaw wrote: "This rant stems from my own CPD compliance being entirely at the whim of a third-party." The thread described providers batch-uploading attendance via spreadsheet, where a single error stops the entire batch loading. The practitioner is compliant in fact and non-compliant on the record, and finds out later. The rule that follows applies far beyond CPD. Your accountant lodges your BAS. Your broker renews your insurance. Your payroll provider files super. Your training provider reports your certifications. In every one of those cases, you keep your own copy of the confirmation, filed where the register says it lives. It is not distrust. It is that the third party's system has no obligation to be your system of record. The evidence location column is where this becomes a habit rather than an intention. Bookkeepers feel this most acutely, sitting between several parties at once. As one described the role on r/Bookkeeping, in a United States context but with a structure Australian bookkeepers will recognise: "I'm the coordination hub between an accountant, a financial advisor, a law firm that handles some bill-pay support, and the owners". When one person is the integration layer between three outside firms and the owners, the register is the only thing that survives them taking leave.

How do you build the register in an hour?

Open a spreadsheet. Six columns. Then work through these prompts and add a row for each answer. What did we lodge or renew in the last twelve months? Check the bank statements and the accountant's emails. What licences, registrations and insurances do we hold? Every one has an expiry. What do our contracts require, such as reporting to a franchisor, a client, a landlord or a lender? What happens when a person joins or leaves, covering superannuation choice, TFN declaration, final pay and access removal? What does our industry regulator require that a generic accountant would not know about? What have we been penalised or warned about before? You will not get it complete on the first pass. Aim for the twenty rows that matter, then add rows as things surface. An incomplete register beats no register by a wide margin. Once the rows exist, the reminders are mechanical. A shared calendar with invitations to the named owner is enough to start. Your accounting software may already surface some tax dates, though it only knows about the obligations it can see, so it is a partial input rather than the register itself.

When is it worth automating the register?

Once the spreadsheet has been running for a quarter and the rows have stopped changing much. Automating before that means encoding a process you have not finished designing. The automation is unglamorous. Read the register, calculate the trigger date from the due date minus the lead time, send an alert to the owner, wait for a completion response, escalate if nothing comes back, log the evidence link. That is it. The value is not in the tooling. It is in the fact that somebody in the business understands the register well enough to change it when the rules change, because the rules will change. This is where most compliance software disappoints. It automates its own view of your obligations, not yours, and the moment your business has an unusual obligation the system has no row for it. A register you own, in a format you can edit, with an alert flow someone in-house built, does not have that ceiling.

Frequently asked questions

**How long does an obligations register take to build?** About an hour for the first pass covering the twenty obligations that matter most. Expect to add rows over the following months as event-triggered obligations surface. It is a living document, so completeness on day one is not the goal. **Should the register live in a spreadsheet or dedicated software?** Start in a spreadsheet. It is editable by anyone, requires no licence, and survives software changes. Move to a database or a tool only after the columns have stabilised and the number of rows makes the spreadsheet unwieldy. **Who should own the obligations register itself?** One named person, usually the owner or the office manager, with a nominated backup. The register owner is responsible for the document existing and being reviewed quarterly. Individual row owners are responsible for their own obligations. **What if our accountant already tracks our deadlines?** Your accountant tracks the obligations they can see, which is mostly tax and reporting. Licensing, insurance, employment and contractual obligations usually sit outside their scope. Keep your own register and treat their calendar as one input to it. **Does the register replace professional advice?** No. It records what you have been advised, where the advice came from, and when. That makes future conversations with your accountant or lawyer shorter, because you are not rebuilding the context each time. **Which obligations are easiest to leave out of a compliance calendar?** Event-triggered ones. Anything without a fixed calendar date, such as onboarding a new employee, engaging a contractor, or changing a director. They never appear on a compliance calendar by themselves, so they need explicit rows in the register with the trigger written out.

Sources

Reddit quotes are reproduced verbatim and attributed to the subreddit only: r/AusFinance, r/auslaw, r/Bookkeeping. The quotation on scattered insolvency information is Bruce Billson, Australian Small Business and Family Enterprise Ombudsman, giving evidence to a parliamentary inquiry, as reported by Accountants Daily: "Small business calls for overhaul of insolvency laws", accountantsdaily.com.au. No statistics are cited in this article and no client examples are used.

Build the reminder flow with your own team

buildAutomation trains two or three of your existing staff to design, build and own the systems behind your obligations register, so the alerts keep working after we leave and nobody is stuck on a retainer. Tell us what you are tracking and we will scope it with you.

Enquire about buildAutomation