6. Planning
6.1 Actions to Address Risks and Opportunities
6.1.1 General
Planning sits on top of the work done in clause 4. Context findings, interested-party expectations and the agreed scope feed into a list of OH&S risks and opportunities that the system has to manage. Skip that linkage and the plan is built on assumption rather than evidence.
What planning has to deliver:
Actions are designed to:
- Move the system toward its intended OH&S outcomes
- Prevent or reduce things going wrong — incidents, exposure, ill health
- Drive measurable improvement over time
Actions are built into existing processes — change control, project gates, work-permit systems — not run as a parallel safety project
Effectiveness is verified after the fact, with the evidence kept on file
Two risk lenses, not one:
OH&S risk to workers (the obvious one) and risk to the management system itself — competence gaps, document drift, supervisor turnover, missed regulatory updates. Both lenses are needed; planning that only covers operational hazard risk misses the slow failures that erode the system between audits.
OH&S risk to workers (the obvious one) and risk to the management system itself — competence gaps, document drift, supervisor turnover, missed regulatory updates. Both lenses are needed; planning that only covers operational hazard risk misses the slow failures that erode the system between audits.
6.1.2 Hazard Identification and Assessment of Risks and Opportunities
Hazard identification has to be a routine, structured exercise — not a once-a-year workshop. It runs continuously, looks at routine work and non-routine situations, and accounts for human factors and changes in conditions. The output feeds the risk register and the controls hierarchy.
Comprehensive Hazard Identification
The hazard identification process pulls from a wide set of sources:
a
Work organisation and social factors — workload, shift patterns, fatigue, bullying, harassment, victimisation — plus leadership style and prevailing culture
b
Routine and non-routine work, drawing in hazards from:
- Infrastructure, plant, equipment, raw materials, substances and the physical workplace
- The full lifecycle of products and services — design, R&D, testing, manufacturing, assembly, construction, delivery, maintenance, disposal
- Human factors and ergonomics
- The way the work itself is carried out
c
Past incidents — internal and at peer sites — including their root causes and any emergency events
d
Credible emergency scenarios
e
Everyone exposed to the workplace:
- Workers, contractors, visitors and any other persons on site
- Neighbours and other parties in the vicinity who could be affected
- Own workers operating at sites the organisation does not control
f
Design and surrounding factors:
- The design of work areas, processes, plant, equipment, procedures and work organisation — and how well these fit the people doing the work
- Off-site events caused by the organisation's own activities
- Off-site events outside the organisation's control that can still cause harm on site (severe weather, neighbouring operations, civil unrest)
g
Planned and unplanned changes — to the organisation, its operations, processes or to the OH&S management system itself (links to 8.1.3)
h
New information about hazards — research, regulator alerts, supplier safety data, sector incident bulletins
OH&S Risk Assessment and Evaluation
Two assessments run in parallel:
1
Risk from each identified hazard — rated against the controls already in place and how effective they actually are (not how effective they're meant to be)
2
Risk to the management system itself — gaps in competence, document control, supervision, monitoring or improvement processes that could undermine OH&S delivery
Risk Assessment Methodology:
Organizations should establish a consistent methodology for assessing OH&S risks, considering:
- Likelihood: The probability of the hazard causing harm
- Severity: The potential consequences if harm occurs
- Exposure: How often and for how long workers are exposed to the hazard
- Number of Workers: How many people could be affected
- Existing Controls: Effectiveness of current control measures
OH&S Opportunities
Opportunities are the flip side of risk. Planned changes — new plant, new processes, automation, restructure — open windows to design hazards out rather than retrofit controls. The opportunity assessment captures these moments and turns them into improvement actions.
Examples of OH&S Opportunities:
- Adapting work, work organization or work environment to workers (rather than workers to work)
- Implementing new technologies or processes that improve worker safety
- Redesigning workspaces to eliminate hazards at source
- Improving worker competence through enhanced training programs
- Enhancing worker consultation and participation mechanisms
- Improving emergency preparedness and response capabilities
- Implementing predictive maintenance to prevent equipment failures
Documentation and Worker Participation
What has to be on file:
Documented methodology and results for hazard identification, risk assessment and opportunity assessment — kept current as the workplace changes
Evidence that workers — including non-managerial workers — were consulted and involved, not just shown the final risk register after the fact
6.1.3 Determination of Legal Requirements and Other Requirements
Every applicable legal duty and other obligation is identified, current, and tied back to the hazards, risks and processes it controls. In South African operations that means the OHS Act, Mine Health and Safety Act, COIDA, sector regulations and any conditions attached to permits, EAs or licenses to operate. "Other requirements" includes group standards, client SHE specifications, sector codes and collective agreements.
Legal Requirements Identification
1
A process for identifying and accessing the legal requirements that apply to the organisation's hazards and OH&S system
2
A clear interpretation of how each requirement translates into action on site — generic legal lists without context fail audit
3
Those requirements feed back into how the system is set up, run and improved
4
A maintained legal register, accessible to the people who need it
5
A defined update cycle so changes — new regulations, amendments, section 54 directives — flow into the register and into operational controls
Types of Legal Requirements:
- National/Federal Laws: Occupational health and safety acts, workers' compensation laws
- Regulations and Standards: Specific regulations for hazards (e.g., confined spaces, hazardous substances)
- Industry-Specific Requirements: Mining safety codes, construction regulations, healthcare standards
- Local/Municipal Requirements: Building codes, fire safety requirements, environmental permits
- Permit and License Conditions: Operating permits, certificates of fitness, licenses to operate equipment
- Court Orders and Legal Judgments: Compliance orders, enforcement notices
Other Requirements
Examples of Other Requirements:
- Organizational Requirements: Company policies, group standards, corporate OH&S requirements
- Contractual Requirements: Customer specifications, supplier agreements, insurance requirements
- Voluntary Standards: ISO standards, industry codes of practice, best practice guidelines
- Agreements with Workers: Collective bargaining agreements, OH&S commitments to workers
- Community Commitments: Agreements with local communities, stakeholder expectations
Workers feed the legal register:
The people doing the work know whether the regulator's rule actually translates on site or whether the procedure built around it is unworkable. Their input shapes both compliance interpretation and the practical controls that follow.
The people doing the work know whether the regulator's rule actually translates on site or whether the procedure built around it is unworkable. Their input shapes both compliance interpretation and the practical controls that follow.
Legal Compliance Management Best Practices:
- Establish a legal register or compliance calendar
- Assign responsibility for monitoring regulatory changes
- Subscribe to regulatory update services or alerts
- Conduct regular compliance audits
- Provide training on applicable legal requirements
- Document compliance evidence and records
- Review legal requirements during management review
6.1.4 Planning Action
Findings from hazard identification, risk assessment, opportunity analysis, legal review and emergency scenario work all converge here — into a defined set of actions with owners, timeframes and effectiveness checks. Those actions are built into the existing operational processes, not parked in a standalone safety improvement plan.
Hierarchy of Controls
Controls are selected top-down through the hierarchy — never starting at PPE:
1
Elimination: Remove the hazard completely
2
Substitution: Replace with something safer
3
Engineering Controls: Isolate people from the hazard (guards, barriers, ventilation)
4
Administrative Controls: Change the way people work (procedures, training, job rotation)
5
Personal Protective Equipment (PPE): Protect the worker with PPE (last resort)
Hierarchy of Controls - Practical Examples:
- Elimination: Remove manual lifting by automating the process; eliminate hazardous chemical by changing the process
- Substitution: Replace toxic solvent with water-based alternative; use mechanical lift instead of manual handling
- Engineering Controls: Install machine guards; provide local exhaust ventilation; install safety interlocks
- Administrative Controls: Implement safe work procedures; rotate workers to limit exposure; provide training
- PPE: Safety glasses, hearing protection, respirators, safety boots (when other controls insufficient)
PPE is the last line, not the first answer:
A control plan that leans on PPE as the primary defence will not pass an ISO 45001 audit and won't survive an incident investigation. PPE only carries the load when higher-level controls aren't feasible, or as a bridge while engineering controls are being installed.
A control plan that leans on PPE as the primary defence will not pass an ISO 45001 audit and won't survive an incident investigation. PPE only carries the load when higher-level controls aren't feasible, or as a bridge while engineering controls are being installed.
Planning Requirements
Weigh available technology, sector best practice, and operational and financial constraints when selecting controls
Look for opportunities to adapt the work and the work environment to the worker — not the other way around
Wire the actions into existing business processes (procurement, project gates, change control, MOC)
Define how effectiveness will be tested once the control is in place
Keep documented records of the planning logic — what was considered, what was selected, and why
6.2 OH&S Objectives and Planning to Achieve Them
6.2.1 OH&S Objectives
Objectives are set at the levels and functions where they can drive performance — corporate, site, department, sometimes team. Together they show how the organisation intends to maintain the OH&S system and improve outcomes year on year.
An objective qualifies when it:
a
Lines up with the OH&S policy
b
Can be measured — or at least credibly evaluated for progress
c
Reflects applicable legal and other requirements
d
Is informed by the risk and opportunity assessment and by worker input
e
Has a monitoring mechanism behind it
f
Is communicated to the people who have to deliver it
g
Is reviewed and refreshed as conditions change
Examples of OH&S Objectives:
- Leading Indicators: Achieve 100% completion of planned safety inspections; 95% participation in safety training; zero high-risk findings in audits
- Lagging Indicators: Zero fatalities; reduce lost-time injury frequency rate by 20%; reduce days away from work by 15%
- Hazard-Specific: Eliminate confined space entry through process redesign; reduce noise exposure below 85 dB across all work areas
- System Improvement: Implement behavior-based safety program in all departments; achieve 90% worker participation in hazard reporting
- Compliance: Maintain zero regulatory non-compliances; achieve ISO 45001 certification by Q4
6.2.2 Planning to Achieve OH&S Objectives
Each objective needs a delivery plan that answers:
a
The action — what is actually going to be done
b
Resources — people, budget, equipment, time
c
Owner — a named accountable person, not a department
d
Deadline
e
Indicators and the method that will be used to evaluate the result
f
How the action plugs into the organisation's existing business processes — capital plans, training calendars, maintenance routines, performance reviews
What gets documented:
The objectives themselves and the plans for achieving them — under document control
Specific actions, accountable owners, timelines and success measures
Updates as objectives are met, missed or superseded by changes in context
SMART OH&S Objectives:
Ensure objectives are:
- Specific: Clearly defined and unambiguous
- Measurable: Can be quantified or performance evaluated
- Achievable: Realistic given available resources and constraints
- Relevant: Aligned with OH&S policy and risk priorities
- Time-bound: Have clear deadlines or timeframes