Comprehensive Corporate Compliance Calendar Operating Manual
A compliance calendar should function as a live control framework across company secretarial, tax, employment, data, contracts, licences and disputes. Static due-date lists become unreliable when entity classification, notifications, employee count, transaction structure or financial-year events change. The calendar should therefore store the legal trigger and evidence requirement, not only the final date.
This section treats the topic as a legal-operations system. The aim is to identify the business trigger, legal rule, responsible owner, required evidence, escalation path and completion proof so the company can manage legal risk consistently rather than through isolated emails.
1. Compliance universe
Business and legal issue. Map every statute, licence, contract and internal policy that can create an obligation for each entity and location. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
2. Entity-specific applicability
Business and legal issue. Different subsidiaries, LLPs, branches and establishments may have different filing and labour obligations. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
3. Event-based obligations
Business and legal issue. Director changes, allotments, charges, office changes, borrowings, incidents and transactions can trigger filings outside annual cycles. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
4. Periodic obligations
Business and legal issue. Board meetings, annual filings, returns, payroll and recurring registers should be tracked by formula and owner. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
5. Threshold-based obligations
Business and legal issue. Employee count, turnover, borrowings, capital or sector thresholds can activate new duties and should be monitored. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
6. Contractual obligations
Business and legal issue. Renewal, termination notice, insurance, guarantee, audit and price-review dates belong in the same risk framework. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
7. Companies Act board meetings
Business and legal issue. Board cadence and action-item closure should be tracked alongside agenda, minutes and approvals. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
8. Director disclosures
Business and legal issue. Conflict, interest and other director-related disclosures should have periodic reminders and evidence of receipt. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
9. Related-party transactions
Business and legal issue. Approvals and documentation should be tracked before the transaction proceeds, not reconstructed during audit. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
10. Loans/guarantees/investments
Business and legal issue. Corporate finance actions should be checked for statutory and internal approval requirements. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
11. Annual return
Business and legal issue. The tracker should store the statutory trigger and calculated filing date, together with form status and proof. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
12. Financial statements
Business and legal issue. AGM-linked filing obligations should be recalculated from the actual event and current rule position. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
13. Charge registration
Business and legal issue. Borrowings secured by company assets may create time-sensitive registration obligations. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
14. Beneficial ownership
Business and legal issue. Ownership changes and disclosures should be monitored where applicable rather than addressed only during diligence. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
15. GST returns
Business and legal issue. The calendar should reflect registration type, turnover, scheme and current notification rather than generic monthly assumptions. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
16. GST notices
Business and legal issue. Show-cause, scrutiny and recovery communications require separate response deadlines from routine returns. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
17. Input tax credit controls
Business and legal issue. Reconciliation and vendor-default issues should be visible to finance and legal where they create material exposure. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
18. POSH committee
Business and legal issue. Constitution, tenure, vacancies, training and annual reporting should be separately tracked. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
19. POSH complaints
Business and legal issue. Complaint timelines and confidentiality should be handled in a restricted tracker rather than the general compliance sheet. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
20. Employment documentation
Business and legal issue. Appointment, policy acknowledgments, contractor documentation and exit records should have standard control points. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
21. Social security
Business and legal issue. PF/ESI and other applicable social-security obligations should be assigned to payroll/HR with escalation for notices or disputes. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
22. Shops and establishments
Business and legal issue. State-specific registration, renewal and record requirements should be tracked for each office location. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
23. Contract labour
Business and legal issue. Principal-employer and contractor obligations require clear responsibility and periodic evidence where applicable. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
24. Data protection
Business and legal issue. Privacy notices, vendor terms, retention and incident processes should be tracked according to provisions actually in force. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
25. Cybersecurity incidents
Business and legal issue. Statutory, contractual and insurer notification windows should be mapped before an incident occurs. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
26. Insurance renewals
Business and legal issue. D&O, cyber, property and professional policies should be renewed with claim-notification conditions visible. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
27. Financing covenants
Business and legal issue. Lender certificates, ratios, consents and litigation notifications should be included as contractual compliance. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
28. Licence renewals
Business and legal issue. Sector, local, trade, food, environmental or other licences should be tracked by entity and location. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
29. IP renewals
Business and legal issue. Trademark, domain, licence and software renewal dates should be included where commercially material. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
30. Litigation deadlines
Business and legal issue. Hearing, filing, limitation, compliance and payment dates should be visible in a separate legal-matters layer. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
31. Legal notices
Business and legal issue. Every received notice should have a response date, owner, business facts and approval path. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
32. Board reporting
Business and legal issue. High-risk overdue compliance should escalate to senior management or the board rather than remain in an operational spreadsheet. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
33. Evidence of completion
Business and legal issue. Every closed item should link to an acknowledgment, receipt, SRN, signed minute, training record or other proof. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
34. 30-60-90 day review
Business and legal issue. Monthly review should look ahead rather than merely report overdue items. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
35. Risk scoring
Business and legal issue. Penalty, business interruption, director exposure, revenue impact and reputation can determine escalation priority. Management should understand the commercial consequence of the obligation or decision before counsel recommends a response. Legal risk should be translated into choices such as proceed, renegotiate, remediate, escalate, obtain approval or stop the activity. This makes the advice useful to business teams and prevents legal from becoming a purely reactive review function.
Evidence and ownership. The company should maintain the source document, responsible department, legal owner, due date and objective evidence of completion. Where the matter spans legal, finance, HR, IT, CS or operations, assign one accountable owner and record dependencies. Missing ownership is a major cause of missed deadlines even when the legal rule itself is understood correctly.
Workflow and escalation. Routine items can use templates and standard approvals; non-standard, high-value or regulated issues should escalate. Define thresholds in advance wherever possible. The retainer or OGC should not silently make commercial decisions that belong to management. Instead, it should identify the legal consequence, available options, recommended control and the level of authority required to approve residual risk.
Reporting and closure. Open issues should appear on the appropriate tracker until there is proof of completion: filed form, executed agreement, board approval, payment, settlement, training record, regulator response or another clear closure document. A completed legal task should leave a reliable audit trail so that diligence, board review or later litigation does not depend on memory.
Legal-operations checklist
- Entity map
- Applicable-law map
- Trigger formula
- Owner
- Reviewer
- Calculated date
- Evidence link
- Risk rating
- Escalation date
- 30-60-90 review
- Notification update process
Management questions
- Which obligations are entity-specific?
- Which are triggered by events rather than dates?
- Who owns evidence of completion?
- What changes when turnover or employee count changes?
- Which contract obligations can cause revenue loss?
- What overdue item needs board visibility?
Final operating principle
Good legal operations turn obligations and advice into repeatable controls. The organisation should be able to identify what is due, who owns it, what evidence proves completion, what risk remains open and what decision management must make. That discipline is more valuable than a long list of laws with no operating responsibility.