Guide

What actually goes in a safety management system

Twelve live elements beats forty documents nobody opens.

A plain-English breakdown of what a work health and safety management system needs to contain, what an auditor is really checking, and how we build it — as interactive process flows rather than management plans, so the visual people and the detailed people are working off the same system.

The twelve elements

01

Policy and commitment

One page, signed, dated. What the business commits to and who is accountable. It is the shortest document in the system and the first one an auditor opens.

02

Roles and responsibilities

Who does what, by name or position. Most systems fail here quietly — everything is 'management shall' and nobody is actually holding it.

03

Hazard identification and risk assessment

A live register covering the work you actually do. Assessed, controlled, dated, reviewed when something changes. Not a generic list copied from a pack.

04

Controls and safe work procedures

SWMS, JSAs, work instructions — written in the language your crew uses. If a new starter can't follow it on their first day, it isn't a control.

05

Consultation with workers

Toolbox talks, meetings, issue resolution. This is a legal duty under WHS law, not a nice-to-have, and it needs a record showing it happened.

06

Training and competency

Licences, tickets, inductions, refresher dates. Held somewhere you can produce them in five minutes, with expiry dates that alert someone before they lapse.

07

Contractors, plant and equipment

Who you let on site and what they bring. Prequalification, insurances, plant registers, inspection and service records. The most common gap we find.

08

Incident reporting and investigation

Near misses as well as injuries. Reported, investigated to a cause, corrective action assigned to a person with a due date, and closed out.

09

Emergency and rescue planning

Site specific, not a generic evacuation page. Where rope access is used, the rescue plan (rope access) has to be real and practised.

10

Records and document control

Current versions, superseded ones archived, and everything retrievable. A system nobody can find records in is the same as no system.

11

Monitoring and measurement

Inspections, audits, a handful of numbers you actually watch. Two or three meaningful measures beat a dashboard nobody reads.

12

Review and improvement

A scheduled look at whether any of it is working, with changes made and recorded. This is the element that separates a live system from a filing cabinet.

The short answer

A safety management system is how you manage risk, written down. That is it. It is not a folder, not a licence, not a certificate on the wall.

If you strip it back, every system has to answer four questions. What could hurt someone here? What are we doing about it? How do we know it is being done? What happens when it isn't? Everything in the list below exists to answer one of those.

Twelve elements, not forty documents

The most common mistake in a small to medium business is buying comprehensiveness. A vendor cannot know what you need, so they give you everything — and now you are maintaining documents for work you have never done.

Build the twelve elements below for the work you actually do. A tight system covering your real risks will beat a bloated one every time, in an audit and on site.

We build process flows, not management plans

Here is where we do it differently. Most systems arrive as management plans and procedures — a wall of text describing work that is actually a sequence of steps. Nobody reads it. They ask the bloke next to them instead.

WorkVault builds the same elements as interactive process flows. Flo, the process mapper, asks the qualifying questions and draws the job as a map: the steps in order, who owns each one, where the risk sits, what has to be checked and what record drops out the end. Click a step and the detail is right there — the procedure, the form, the standard behind it, the training required.

That covers both modalities at once. The visual people follow the flow and never open a document. The detailed people drill in and get everything they want. Same system, no second version, and nothing sitting in a folder waiting to go stale.

It also fixes the audit problem. A flow shows the control and the record in the same place, so you can answer 'show me how this works' by opening the map instead of hunting through a manual.

What an auditor is actually checking

Not your manual. They will read it, but they are grading implementation. The question behind every question is: is this system alive?

That is why they go for the registers, the dates, the closed-out actions and the training records. If your risk assessments were all reviewed in the same week two years ago, they have their answer before lunch. Documents show intent. Records show it happened.

How to actually build it

Start from the work, not from a template. Walk the job. List what your people do. For each activity, find where someone could get hurt, write the control the way the crew would describe it, and build the record that proves it was done.

Do that for your highest-risk activities first and you will have a working system in weeks. Do it by downloading a template pack and you will still be reformatting someone else's procedures in six months.

Where ISO 9001 and 45001 fit

You do not need to be certified. But structuring the system to ISO 45001 for safety and ISO 9001 for quality costs you nothing extra at build time and saves you a rewrite later.

Even if you never certify, it means the system stands up to a client prequalification, an insurer's review or a bad day — and those are far more likely than an audit.

Let the technology do the administration

The reason most small business systems go stale is that nobody owns them. There is no full time WHS coordinator, so the system lands on whoever is least busy.

Fair Dinkum WorkVault is the answer to that. It is seeded with 20+ years of quality and safety documentation and puts an agent behind each element above — Sherlock on hazards and investigations, Flo on procedures and flows, Fred on plant and maintenance, Gary on training, Harry on audits and inspections, Rod and Rachel on emergency response, Peter on the management review. You drive it, they prompt you. Either way the system describes your operation, because your operation built it.

Common questions

What is a safety management system?
How you manage risk, written down. Not a folder and not a certificate — the policies, controls, records and responsibilities that keep people safe and prove it.
What elements does it need?
The twelve above. Policy, roles, risk assessment, controls, consultation, training, contractors and plant, incidents, emergency and rescue, records, monitoring, review.
How do you develop one?
Start from the work. Walk the job, list the activities, write the control the way your crew would say it, build the record that proves it happened. Highest risk first.
Do we need ISO 45001 certification?
No, but build to it anyway. It costs nothing extra up front and means the system survives a prequalification, an insurer review or a serious incident.
Plans and procedures, or process flows?
Flows. The steps of the job, who owns each one, where the risk is and what record comes out. Click a step for the procedure, form and standard behind it — visual and detailed in the one system.

Build the system around your work

Fair Dinkum WorkVault prompts you through every element above and builds it out as interactive process flows, underpinned by ISO 9001 and ISO 45001 frameworks.