Author: Aswad Aziz

  • Emergency Response Plan Malaysia: Practical Workplace Checklist

    Emergency Response Plan Malaysia: Practical Workplace Checklist

    An Emergency Response Plan (ERP) is useful only when people understand it and can act under pressure. A document copied from another factory may overlook the hazards, layout, contractors and emergency resources that matter most at your site.

    Identify credible emergencies first

    Use the workplace risk assessment to identify realistic events: fire, serious injury, chemical spill, gas release, vehicle collision, confined-space emergency or loss of essential utilities. Consider neighbouring premises, operating hours and employees who need assistance during evacuation.

    Define clear roles and authority

    Assign an incident controller, emergency coordinators, floor wardens, first aiders and technical response roles as relevant. Describe who raises the alarm, calls emergency services, shuts down operations, accounts for people and authorises re-entry. Deputies matter: a plan must still work when the usual person is absent.

    Five components every plan should address

    1. Detection and alarm: How an emergency is recognised and communicated, including alternative communication methods.
    2. Evacuation and assembly: Safe routes, assembly arrangements, visitor and contractor accountability.
    3. Immediate controls: Site-specific equipment isolation and response actions performed only by trained, authorised people.
    4. External coordination: Emergency service contact, site access and incident information.
    5. Recovery: Re-entry approval, incident records, replacement of used equipment and lessons learned.

    Chemical spill example

    For a spill, first identify the material and consult the current Safety Data Sheet. Isolate the area and prevent exposure. Only trained, properly equipped responders should attempt containment within their capability. Escalate spills that exceed response resources or involve uncertain exposure or reactivity; never instruct untrained workers to approach an unknown substance.

    Practice through drills and tabletop exercises

    A drill should test decisions and coordination rather than simply achieving a fast evacuation time. Observe alarm recognition, communication failures, crowd control, headcount and response time. Record corrective actions, assign owners and retest where needed.

    Management checklist

    • Are emergency scenarios linked to actual risks?
    • Are roles, contact details and routes current?
    • Can contractors and visitors receive the alarm?
    • Do responders have suitable equipment and competence?
    • Have significant drill findings been closed and verified?

    Book a practical ERP workshop

    See Emergency Response and Crisis Management programmes, including tabletop drills and scenario-based exercises, or request a customised briefing.

    References and scope

    Review applicable duties under Act 514 and the relevant fire, chemical, building, industry and local authority requirements. This checklist is guidance, not a universal statutory ERP format.

  • Incident Investigation Malaysia: Beyond 5 Whys and Blame

    Incident Investigation Malaysia: Beyond 5 Whys and Blame

    When a workplace incident occurs, the purpose of an investigation is to prevent recurrence—not simply identify someone to blame. A useful investigation explains what happened, why controls failed and what needs to change.

    Start with response and evidence

    First protect people, make the area safe and activate emergency arrangements. Follow applicable internal and statutory notification requirements; investigate without delaying urgent reporting. Secure relevant photos, equipment conditions, permit records, maintenance data and witness accounts. Keep personal information confidential.

    Build a factual timeline

    Separate confirmed facts from assumptions. What was the intended job? What changed? What barriers were expected? Which were missing, ineffective or bypassed? Cross-check observations against documents and interviews.

    Use 5 Whys carefully

    The 5 Whys method is a useful prompt for exploring causal chains, not proof of a single root cause. For example: a pedestrian entered a forklift route. Why? The designated crossing was blocked. Why? Materials were temporarily stored there. Why? Storage arrangements were not reassessed after a layout change. Investigators must verify each statement and consider alternative causal paths such as supervision, visibility and traffic segregation.

    Look at systems, not labels

    “Carelessness” and “human error” alone rarely explain an event sufficiently. Examine task design, equipment, competence, instructions, maintenance, time pressure, communication, barriers and organisational decisions. A fishbone diagram or barrier analysis can organise hypotheses, but findings must be supported by evidence.

    Make corrective actions measurable

    • Prioritise stronger engineering or elimination controls where practicable.
    • Assign an owner, target date and verification method.
    • Check whether the action controls the original exposure.
    • Share applicable lessons without disclosing confidential personal details.

    What should an investigation report contain?

    Document scope, incident description, evidence, chronology, causal analysis, contributing conditions, immediate corrections, longer-term controls, responsible persons and close-out verification. Use a review date to test effectiveness.

    Common mistake: training as the only action

    Retraining may be appropriate if competence genuinely contributed to the event, but it cannot fix defective equipment, poor layout or missing barriers. The corrective action should match the demonstrated causal mechanism.

    Training and advisory support

    Aswad Aziz facilitates practical case-based incident investigation training for supervisors and HSE teams, including evidence matrices and causal analysis exercises. Discuss a customised programme.

    References

    Malaysia Occupational Safety and Health Act 1994 (Act 514); applicable notification rules and your employer’s approved investigation procedure. Investigations and statutory reporting are separate obligations.

  • HIRARC Malaysia: A Practical Step-by-Step Risk Assessment Guide

    HIRARC Malaysia: A Practical Step-by-Step Risk Assessment Guide

    HIRARC stands for Hazard Identification, Risk Assessment and Risk Control. In Malaysia, the DOSH HIRARC Guidelines (2008) provide a recognised methodology. The point is not to produce a large spreadsheet: it is to prevent harm by making work-related risks visible and controls effective.

    Step 1: Define the activity precisely

    A line reading “warehouse operation” is too broad. Break it into tasks such as forklift unloading, reversing into a storage bay, battery charging and pedestrian crossings. Include non-routine conditions such as maintenance, contractor activities and changes to the layout.

    Step 2: Identify hazards and who may be harmed

    Visit the work area and consult people doing the task. Consider moving vehicles, suspended loads, chemical exposure, noise, manual handling, falls and loss of energy control. Include visitors and contractors who may be exposed, not just direct employees.

    Step 3: Assess the risk

    Evaluate severity and likelihood using your organisation’s approved method and the DOSH guidance. A risk score can help prioritise; it should not replace professional judgement. Severe potential consequences may warrant stronger controls even when an event is considered unlikely.

    Step 4: Select controls using the hierarchy

    Prefer elimination, substitution and engineering controls where reasonably practicable before relying primarily on administrative controls and personal protective equipment. For forklift–pedestrian conflict, barriers and route separation are typically stronger than a warning poster alone.

    Step 5: Assign ownership and verify

    A usable HIRARC entry identifies the control, person accountable and verification method. “Stay alert” is difficult to audit. “Pedestrian gate stays closed while forklift loading is underway; supervisor checks before each loading shift” is observable and testable.

    Worked example: forklift and pedestrian crossing

    Task Hazard Possible harm Example control
    Reverse forklift Vehicle/pedestrian interface Crush injury Segregated route, barrier, designated crossing and visibility controls

    Document the initial risk using the approved matrix, implement controls, then reassess residual risk. Do not claim the task is safe solely because the numerical rating decreased; verify the actual arrangements at the worksite.

    When should HIRARC be reviewed?

    Revisit the assessment after incidents or near misses, new equipment, process changes, changes in workforce or site layout, or when controls prove ineffective. Regular planned review is also good practice. Involve the workforce and brief changed controls before the next task.

    Common HIRARC errors

    • Using the same generic risk register across dissimilar work areas.
    • Describing injuries as hazards rather than identifying hazardous sources or situations.
    • Listing PPE as the only control when higher-order controls are possible.
    • Leaving action owners, verification and reassessment blank.

    Is HIRARC legally required?

    Section 18B of Act 514 requires risk assessment and implementation of necessary controls. It does not prescribe that every organisation must use a document titled “HIRARC” in all circumstances. DOSH’s HIRARC guidance offers one practical approach to meeting the risk assessment duty.

    Want participants to complete a real task-based exercise rather than only learn definitions? View the HIRARC training programme or request a workplace-based workshop.

    Official references

    Example controls require validation against the actual worksite and approved risk assessment procedure.

  • OSH Coordinator Malaysia: Who Must Appoint One and What They Do

    OSH Coordinator Malaysia: Who Must Appoint One and What They Do

    If you operate an SME in Malaysia, one common question is: Do we need an OSH Coordinator (OSH-C)? The answer depends on the number of employees at the workplace and whether the site falls into a category requiring a Safety and Health Officer (SHO).

    Who must appoint an OSH Coordinator?

    Section 29A(1) of the Occupational Safety and Health Act 1994 (Act 514) requires an employer to appoint one of its employees as an OSH Coordinator if it employs five or more employees at a workplace that is not within a gazetted class of workplace under Section 29(1). Section 29A(3) recognises an employer that has already appointed an SHO at that workplace as meeting the coordinator appointment requirement.

    The threshold refers to employees at the place of work; assess each actual workplace and verify applicable circumstances rather than assuming a company-wide headcount answers every question.

    OSH Coordinator versus Safety and Health Officer

    An OSH Coordinator helps coordinate occupational safety and health matters at a workplace. A Safety and Health Officer is a different statutory role with specific appointment and registration requirements. An employee does not become a registered SHO merely by completing an OSH-C course.

    Importantly, appointing a coordinator does not transfer the employer’s underlying duty to provide a safe and healthy workplace.

    Practical responsibilities for an OSH Coordinator

    The statute gives the OSH-C a coordinating purpose, while the employer must define actual duties appropriate to the site. A useful scope could include:

    • Coordinating hazard reports, inspections and HIRARC reviews.
    • Tracking corrective actions and escalating overdue high-risk items.
    • Maintaining a practical record of safety briefings and workplace instruction.
    • Helping to coordinate emergency arrangements and drills.
    • Supporting incident information collection without prejudging causes.
    • Reporting trends and barriers to management for decisions.

    Five steps for an SME to implement the role

    1. Confirm applicability: Check headcount, workplace classification and existing SHO arrangements.
    2. Make a written appointment: Define the coordinator’s authority, reporting line and time allocation.
    3. Provide suitable learning: Select training that includes workplace examples and practical exercises.
    4. Create a small action register: Record risk, action, person responsible, due date and closure evidence.
    5. Review monthly: Ask management to resolve blocked actions and provide resources.

    Common mistakes

    The first is treating the appointment letter as the finished OSH system. The second is asking one employee to carry every safety duty without authority, budget or management support. The third is copying a generic HIRARC without examining actual jobs. The solution is a manageable routine: inspect, discuss, assign, verify and improve.

    Frequently asked questions

    Does a company with fewer than five workers have no OSH duties?

    No. The Section 29A appointment threshold does not remove other applicable duties under the Act, including obligations relating to workplace safety and risk assessment.

    Is OSH-C training the same as becoming a SHO?

    No. The roles and legal requirements differ. Training supports capability but must not be misrepresented as SHO registration.

    For employers building a functioning OSH-C programme, practical HIRARC and safety management training can be combined with workplace coaching. Discuss the site needs with Aswad Aziz.

    Official reference

    DOSH: Occupational Safety and Health Act 1994 (Act 514), particularly Sections 15, 18B, 29 and 29A. Check the latest gazetted provisions for your workplace.

    General guidance, reviewed October 2026; not a replacement for a site-specific regulatory determination.

  • OSHA Malaysia 2024 Amendments: What Employers Must Do

    OSHA Malaysia 2024 Amendments: What Employers Must Do

    Malaysia’s Occupational Safety and Health (Amendment) Act 2022 took effect on 1 June 2024. Although people often call these the “OSHA 2024 amendments”, the governing legislation remains the Occupational Safety and Health Act 1994 (Act 514), as amended. For employers, the important question is not whether a policy file exists but whether actual workplace risks are assessed and controlled.

    Five requirements employers should review

    1. Assess workplace risks and implement controls

    Section 18B places a duty on employers, self-employed persons and principals to conduct a risk assessment for people who may be affected by their undertaking. Where controls are needed, they must be implemented. An unsigned HIRARC template is not a substitute for inspecting the task, consulting workers and verifying that controls work.

    2. Clarify the principal–contractor interface

    Section 18A addresses the duties of principals toward contractors and other specified people, subject to its statutory scope. Review who controls access, permits, equipment, simultaneous operations and emergency arrangements. Contracts should not create gaps in operational responsibilities.

    3. Check the right safety appointment

    Under Section 29A, an employer with five or more employees at a workplace outside the classes requiring a Safety and Health Officer under Section 29(1) must appoint an employee as its OSH Coordinator. Where a Safety and Health Officer has already been appointed at that workplace, Section 29A provides a deemed-compliance provision. Verify the relevant gazetted workplace category before deciding which arrangement applies.

    4. Maintain employee consultation and competence

    Training should address real exposures, operating procedures, supervision and practical understanding. Review the separate Safety and Health Committee requirements under Section 30 where applicable. A training attendance sheet alone does not demonstrate that a worker can operate a high-risk task safely.

    5. Keep evidence of implementation

    Maintain risk assessments, control action records, training and authorisation records, equipment checks, incident follow-up and documented reviews. Evidence should reflect what is happening on site—not just the date the file was prepared.

    What happens if an employer breaches Section 18B?

    Under Section 19, a conviction for contravening specified general duties, including Section 18B, can result in a fine of up to RM500,000, imprisonment for up to two years, or both. The precise offence and outcome depend on the facts and enforcement process.

    A simple employer action plan

    1. Map your sites, headcount and applicable statutory appointments.
    2. Review activities with material risks, including contractors and non-routine work.
    3. Check whether assessments identify workable controls with named owners.
    4. Observe the job to verify controls, competency and emergency readiness.
    5. Track gaps to closure and schedule reassessment after changes.

    Frequently asked questions

    Is the legal amendment called OSHA 2024?

    The change commonly described that way is the Occupational Safety and Health (Amendment) Act 2022, effective 1 June 2024.

    Does every company need a full-time Safety and Health Officer?

    No. The statutory Safety and Health Officer requirement depends on gazetted classes of workplaces; Section 29A addresses qualifying workplaces outside those classes. Do not confuse an OSH Coordinator with a registered Safety and Health Officer.

    Need practical support? Explore HIRARC, incident investigation and emergency response programmes or request a training discussion with Aswad Aziz, HRD Corp Accredited Trainer.

    Official references

    Information current to October 2026. This article is general training guidance, not a site-specific legal opinion. Verify current laws, regulations and gazetted requirements for your workplace.

  • ISO 45001 Internal Audit Malaysia: Practical Workplace Checklist

    ISO 45001 Internal Audit Malaysia: Practical Workplace Checklist

    An ISO 45001 internal audit should test whether the occupational health and safety management system works where the job happens—not just whether a procedure exists in a folder. In Malaysia, effective auditing also checks how statutory duties, site hazards, workers and contractors are managed.

    Plan the audit around risk

    ISO 45001:2018 Clause 9.2 addresses internal audits. Set criteria, scope, methods and an audit programme that considers the importance of processes, changes and previous audit results. Keep objectivity and impartiality. High-risk work deserves proportionate attention rather than simply equal audit hours for every department.

    Five evidence streams worth reviewing

    1. Leadership: How does management allocate resources, address critical risks and remove barriers?
    2. Risk assessment: Do HIRARC and task assessments reflect the actual equipment, conditions and controls?
    3. Competence: Can workers and contractors explain and demonstrate task-critical controls?
    4. Operational control: Are permit-to-work, isolation, lifting and emergency arrangements applied on site?
    5. Improvement: Are incident actions completed and checked for effectiveness?

    Follow one real work activity

    For example, sample a conveyor maintenance job. Trace the process from risk assessment to the isolation plan, instructions, worker authorisation and work completion. Interview the people doing the job, review evidence and observe safe practice. Never create an unsafe situation merely to gather audit evidence.

    Write findings that people can act on

    A strong nonconformity identifies the specific requirement, objective evidence and the difference between them. “Three maintenance records had no evidence of isolation verification required by procedure X” is much more actionable than “poor safety culture”. Separate verified findings from assumptions, opportunities and positive practices.

    Check corrective action effectiveness

    Training alone will not fix a missing isolation point or a permit system that is impossible to follow. Identify the cause of the finding, assign an owner, implement suitable controls and verify them after implementation. ISO 45001 Clause 10.2 addresses incidents, nonconformity and corrective action.

    Practical checklist

    • Confirm scope, criteria, sampling approach and auditor independence.
    • Review incidents, objectives, previous findings and changes.
    • Sample both documents and actual worksite practice.
    • Agree accountable owners and realistic closure dates.
    • Report themes to management and test lasting effectiveness.

    Explore ISO 45001 / ISO 14001 Awareness and Internal Audit programmes, or request a practical audit workshop.

    References

    ISO 45001:2018 Clauses 9.2 and 10.2 (consult licensed standard text); DOSH Malaysia. Certification and statutory legal compliance are distinct requirements.