77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
List of hazardous substances: Excel template for free and what it really has to deliver
Hazardous Substances & Occupational Health

List of hazardous substances: Excel template for free and what it really has to deliver

3 September 202613 min readBy Stefan Möller
CIVAC

An Excel template for the list of hazardous substances saves you getting started. However, it only meets Section 6 GefStoffV if all mandatory information is recorded in a structured manner. This article provides the legally compliant field list and the migration path to the audit-proof solution.

According to Section 6 Paragraph 12 of the Hazardous Substances Ordinance (GefStoffV), every employer must keep a list of all hazardous substances used in the company. The list is a mandatory part of the risk assessment and is required for every audit by the professional association, the trade inspectorate or in the REACH compliance check. If it is missing, there is a risk of fines according to Section 22 ChemG of up to 50,000 euros.

Excel templates meet this requirement if the mandatory fields are complete and the document is versioned, dated and signed. This article shows the legally compliant mandatory fields, provides a free column structure and describes the point at which a spreadsheet is no longer operationally viable and audit-proof solutions take over.

Key Takeaways

  • Section 6 paragraph 12 GefStoffV requires at least seven mandatory pieces of information per hazardous substance, including name, classification, quantity range and work areas.
  • An Excel template is legally permissible as long as versioning, dating and the obligation to update are documented within three months of the change.
  • If you have around 50 different hazardous substances or several locations, migrating to a central platform is worthwhile because Excel version drift becomes an audit risk.

What Section 6 GefStoffV requires as a minimum content

The Hazardous Substances Ordinance requires in Section 6 Paragraph 12 a list of all hazardous substances used in the company, in which reference is made to the respective safety data sheets. The minimum information is listed in the regulation itself and is specified in TRGS 400.

Mandatory fields are: name of the hazardous substance, classification according to CLP Regulation (EC) No. 1272/2008 or dangerous properties, quantity ranges used per calendar year, work areas in which the hazardous substance is used, and reference to the respective safety data sheet. These five fields are the absolute minimum.

The TRGS 400 adds four fields that are also expected in practice by regulatory authorities: CAS number or substance identification, H and P phrases, storage class according to TRGS 510 and intended use. If you add these, you get nine columns, which should be included in every free Excel template.

Certain material groups require additional fields. Carcinogenic, germ cell mutagenic or reproductively toxic (KMR) substances in categories 1A and 1B require a separate exposure list in accordance with Section 14 Paragraph 3 GefStoffV. Biological substances according to BioStoffV are recorded in a separate directory.

You can find an overview of all officer roles that are responsible for hazardous substance topics on the CIVAC role page for hazardous substances officer. The operational maintenance of the directory is typically carried out by the hazardous substances officer in coordination with occupational safety specialists and plant management.

The nine columns of a legally compliant Excel template

A pragmatic, legally compliant Excel template has nine columns plus a header block. Column A: sequential number for unique reference. Column B: Name of the hazardous substance (trade name plus chemical name, if different). Column C: CAS number or EC number. Column D: Classification according to CLP, with hazard classes and categories.

Column E: H-phrases and P-phrases, separated by commas. Column F: Quantity range per year (range, not point value, e.g. 50 to 100 kg). Column G: Storage class according to TRGS 510. Column H: Work areas or rooms in which the substance is used. Column I: Reference to the current safety data sheet (file path, version, date).

The header block above the table contains: company, location, responsible hazardous substances officer, creation date, last update, version. This metadata is audit-relevant. Without documented versioning, the directory is not considered audit-proof.

Additional columns depending on the industry: exposure class for KMR substances, AGW value (workplace limit value) according to TRGS 900, biological limit value according to TRGS 903, commercial storage according to BetrSichV, quantity thresholds according to the Major Accident Ordinance for substances subject to reporting.

The free templates from large manufacturers such as BG RCI, DGUV or professional association for wood and metal usually contain these nine mandatory columns. They are generally usable, but must be adapted to your specific industry. Predefined drop-down lists for classifications reduce typos during maintenance.

Sources for free templates and their suitability

Several official bodies offer free Excel templates for the list of hazardous substances. The best known are the trade association for raw materials and the chemical industry (BG RCI), the DGUV, the hazardous substances information system GESTIS and individual state environmental offices. These templates meet the minimum requirements and can be used across all industries.

BG RCI offers a GHS-compliant template with 13 columns that also covers P and H phrases, storage class and protective measures. It is sufficient for industrial companies and comes close to DGUV information 213-034. It can be oversized for crafts and trade.

GESTIS fabric database does not offer a direct Excel template, but does offer the option of exporting fabric information in a structured manner. From this you can put together your own template, which is fed with current material data. Advantage: automatic comparison with the relevant database. Disadvantage: high initial effort.

Commercial templates from consulting providers are often of high quality, but rarely free. Some open source initiatives, such as the OSCi project, provide free-to-use Excel templates that are useful as a starting point, but need to be updated manually on a regular basis as CLP or TRGS requirements change.

A common mistake: A template is set up once and then left untouched for two years while the CLP classifications or TRGS values ​​change. Audit-proof, documented, § 6-proof only works with a documented update routine, at least annually or with every new substance intake.

Care routine: Who updates what and when?

The operational maintenance of the list of hazardous substances requires clear responsibility. The hazardous substances officer is usually responsible, in coordination with the occupational safety specialist. In smaller companies without a designated representative, the management or a delegated person takes on the task.

The update deadline according to Section 6 Paragraph 12 GefStoffV is immediately in the event of changes. In supervisory practice, authorities accept a maximum delay of three months, with documented reasons. Longer gaps lead to complaints and, in repeated cases, to fines.

Triggers for an update are: inclusion of a new hazardous substance (immediately), elimination of a substance (within 30 days), change in classification by the manufacturer (within 30 days after the SDB update), change in the quantity ranges or work areas (within 90 days), annual full update as a mandatory routine.

The annual full update includes: Comparison All safety data sheets are up to date (often two-year-old SDBs in circulation), comparison of CAS numbers, checking of the CLP classification against GESTIS, updating of the quantity ranges from the purchasing system, checking of work area assignments after physical changes at the location.

Proof of care is provided through documented reviews. This routine is stored as an audit template in the CIVAC Workspace: care plan, escalation levels, responsible persons, automatic reminders before the deadline expires. Deadline begins as soon as we become aware of it. Anyone who doesn't recognise the trigger will face a fine.

When Excel reaches its limits

An Excel template operationally carries up to 30 to 50 different hazardous substances and a location. In addition, typical problems arise: version drift between local copies, simultaneous editing without conflict resolution, lack of rights assignment, weak audit trail and loss of the single source of truth.

The first stumbling block is version drift. In multi-location setups, the template is copied, maintained locally and three months later three different master versions exist. In the event of an unannounced trade inspection audit, you must be able to show the current version immediately. The auditor calls, the evidence is ready.

The second stumbling block is the safety data sheet management. Excel only refers via file path, but does not check whether the SDB is actually current and not older than three years. SDBs according to REACH Regulation Art. 31 must be updated by the manufacturer when changes are made, which you must actively monitor.

Stumbling block three is access control. Who can read the directory, who can change it, who can delete it? Excel without SharePoint or structured permissions does not provide clean roles. An audit question about four-eye care cannot then be answered reliably.

Stumbling block four is the audit trail. Wer hat wann welchen Eintrag geändert? Excel provides a limited change history that can be lost every time you save it as a new file. Auditors require complete traceability for at least three years, in regulated sectors up to ten years.

Migration path: From Excel to central platform

The migration from an Excel template to a central platform should be carried out in a structured manner in four phases. Phase 1: Consolidation. You collect all existing Excel versions, identify the most current one per location, compare and create a consolidated master.

Phase 2: Cleanup. From the consolidated master, you remove all substances that are no longer used (often 15 to 25 percent of the entries), update CLP classifications against GESTIS and check that the safety data sheets are up to date. This phase typically uncovers significant data quality gaps.

Phase 3: Import into the platform. The cleaned data is imported in a structured manner. In the CIVAC Workspace, this is done via bulk upload with validation against the mandatory fields according to Section 6 GefStoffV. Missing mandatory fields are reported before import, which ensures data quality.

Phase 4: Connection to operational processes. Purchasing automatically reports new materials into the system. SDS updates from manufacturers are monitored. Annual reviews are stored as appointments in the workspace. Reporting line to the hazardous substances officer and the management is shown.

The operational duration of a migration for a medium-sized company with 80 to 150 hazardous substances is four to six weeks. An external appointment of a hazardous materials officer can take over this process parallel to the migration and cushion the bottleneck of internal capacity.

Example structure: What is written where in the entry

A complete entry in the list of hazardous substances is more than just one line. Typically, two areas arise for each substance: master data and context of use. Master data remains stable over the lifespan of the substance, context of use changes more frequently.

Master data includes: serial number, trade name, chemical name, CAS number, EC number, manufacturer, CLP classification, H-phrases, P-phrases, AGW value according to TRGS 900, biological limit value, storage class according to TRGS 510. This data comes from the safety data sheet and should be referenced there

Context of use includes: work areas, activities, quantity range per year, storage location, protective measures, responsible persons, last risk assessment, level of training. This data comes from operations and is documented in the risk assessment.

Linking both areas is crucial. A substance can be used in multiple work areas and in different quantities. In Excel, this leads to multiple rows per substance with redundancies in the master data. In a relational platform, master and usage data are kept separately and brought together for reporting.

The clean separation of both levels is a prerequisite for reporting to supervisory authorities, REACH audits or the professional association. The appointment certificate, signed, filed, verifiable. Without structured data, each report costs days instead of hours.

Risk of fines and typical audit findings

Violations of § 6 GefStoffV are punished with fines of up to 50,000 euros in accordance with § 22 paragraph 1 number 2 of the Chemicals Act, and in serious cases up to 100,000 euros. If the health of employees is intentionally endangered, additional criminal offenses apply according to Sections 222 and 229 of the German Criminal Code.

Typical findings from the trade inspectorate are: directory is completely missing (often in small businesses), directory is out of date (longer than a year without an update), mandatory fields are incomplete (missing CAS numbers, missing quantity ranges), no link to safety data sheets, no versioning visible.

The professional association also checks for consistency in content mit der Gefährdungsbeurteilung. If a substance is in the list but has not been evaluated in the GBU, this is an independent finding according to Section 6 Paragraph 1 GefStoffV. Conversely: GBU refers to substances that are missing from the list.

REACH audits by market surveillance authorities also check whether the substances included in the list are relevant in the SVHC context (Substances of Very High Concern) and whether the communication obligations according to Article 33 of the REACH Regulation have been fulfilled. Companies often fail here due to a lack of substance identification.

In an emergency, authorities combine several findings to form an overall complaint with a list of defects and a deadline for rectification. Anyone who misses the deadline risks being banned from operating the affected activities. Others run compliance like a filing cabinet. We run it like software.

From Excel sheets to verifiable compliance

An Excel template is a pragmatic start and is legally sufficient for small businesses with few hazardous substances. However, it does not replace a structured care routine, a reporting line or a revision-proof audit trail. As soon as you manage more than 30 substances or several locations, it is worth migrating to a central platform.

CIVAC is a compliance platform and officer-as-a-service. Licence the workspace for your internal representatives, or have our representatives order it. The workspace maintains the hazardous substances directory as a structured database with mandatory field validation, SDB connection, versioning and audit trail for at least ten years.

In the workspace model, your own hazardous substances officer maintains the data in the platform instead of in Excel. Templates for GBU, annual reviews and training certificates are stored. The EU data residence in the ISO 27001:2022-certified ISMS also meets data protection requirements according to Art. 32 GDPR.

In the officer-as-a-service model, CIVAC appoints an external hazardous substances officer who takes over operational maintenance, carries out training and represents the supervisory authorities in the audit. Appointment certificate within two working days, instead of two to six weeks of searching.

Both models start with an inventory of your current directory and a gap analysis against § 6 GefStoffV and TRGS 400. Turn reading into a mandate. Write to info@civac.de or use the contact form on civac.de for a structured initial discussion.

FAQ

Is an Excel template for the list of hazardous substances legally permissible?

Yes, Section 6 GefStoffV does not prescribe a specific technical solution. An Excel template is permitted provided that all mandatory information is included, the versioning is recognizable and the update is documented. However, as soon as the amount of data increases or multiple locations are involved, Excel becomes operationally risky.

Which fields are mandatory in the list of hazardous substances?

Minimum requirements according to § 6 GefStoffV are: name of the hazardous substance, dangerous properties or CLP classification, quantity ranges, work areas and reference to the safety data sheet. TRGS 400 adds CAS number, H and P phrases, storage class and intended use as good practice. A total of nine fields are recommended.

How often does the list of hazardous substances have to be updated?

Immediately in the event of changes, in supervisory practice a maximum of three months. In addition, an annual full update is recommended. Triggers are: new substances, eliminated substances, changes to the CLP classification, changes to the working areas or quantities, new safety data sheets from the manufacturer.

What fines are there if the directory is missing or incorrect?

According to Section 22 of the Chemicals Act, fines of up to 50,000 euros can be imposed, and in serious cases up to 100,000 euros. If employees are endangered, additional criminal offenses apply under Sections 222 and 229 of the Criminal Code. Auditors also assess gaps as an overall deficiency in the risk assessment in accordance with Section 6 Paragraph 1 GefStoffV.

Who is responsible for care in the company?

The employer is responsible. Operationally, care is usually delegated to the hazardous substances officer, in coordination with the occupational safety specialist. In small businesses without a named representative, the management or an expressly appointed person takes on the task.

At what level of material is it worth switching from Excel to a platform?

Erfahrungswert: ab 30 bis 50 unterschiedlichen Gefahrstoffen oder ab dem zweiten Standort lohnt die Migration. Above this size, operational maintenance in Excel becomes prone to errors due to version drift, lack of access control and weak audit trails. A central platform reduces compliance risks and significantly speeds up annual maintenance.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles