The short answer
bizSAFE is a five-step programme run by Singapore's Workplace Safety and Health Council. Level 1 is a three-hour course for your CEO or a board director. Level 2 is a two-day course for the person who will run your risk assessments. Level 3 — the level almost everyone actually needs — is an independent audit proving you genuinely do risk management, and it is the first level that lasts three years rather than six months. Level 4 is a four-day course for a management-system champion, and bizSAFE STAR requires a certified management system under SS 651 or ISO 45001.
Applying is free. The money goes on training and on the Level 3 audit, both bought from independent providers rather than from the Council. And the single most useful thing to understand before you start is that Level 3 is not a paperwork exercise: the auditor walks your workplace, interviews your staff and checks whether the controls written in your risk assessments actually exist. The rest of this page is what that means in practice.
How this page is sourced
Every requirement below is taken from the Workplace Safety and Health Council's own bizSAFE pages, from the Ministry of Manpower, from the current text of the Workplace Safety and Health (Risk Management) Regulations on Singapore Statutes Online, or from the official bizSAFE Level 3 Risk Management Audit Checklist itself — revision V3.3, in effect from 1 July 2026 — all read in September 2026. Where a figure is not officially published, this page says so rather than guessing. Programme rules change; confirm anything you are about to spend money on with the WSH Council.
What bizSAFE actually is
bizSAFE is a capability-building programme, not a licence and not a law. It is run by the Workplace Safety and Health Council and supported by the Ministry of Manpower, and MOM describes it as "a nationally recognised capability building programme designed to help companies build workplace safety and health capabilities". Companies work through five recognised steps — bizSAFE Level 1, 2, 3, 4 and bizSAFE STAR — each one evidenced by a certificate issued by the Council.
The distinction that matters most is between the programme and the duties underneath it. bizSAFE is voluntary. The risk management it certifies is not. The Workplace Safety and Health (Risk Management) Regulations place hard legal duties on every employer, self-employed person and principal in every workplace in Singapore, whether or not that company has ever heard of bizSAFE. Regulation 3 requires a risk assessment. Regulation 4 requires you to eliminate foreseeable risk so far as is reasonably practicable and, where you cannot, to minimise it and implement safe work procedures. Regulation 5 requires you to keep the records and to hand them to the Commissioner when asked. Regulation 7 requires review at least once every three years.
So the honest way to describe bizSAFE is this: it is a structured, externally verified way of demonstrating that you are doing something you are already legally required to do. That framing is worth holding on to, because it changes how you approach Level 3. You are not building a system for the auditor. You are showing an auditor the system the law already expects you to have.
One piece of the programme is law in its own right. Completing the Top Executive WSH Programme — the Level 1 course — is a legal requirement for the CEO or board director of companies in the higher-risk sectors, which MOM identifies as Construction, Manufacturing, Marine, and Transport & Storage, with effect from 1 March 2024. If you are in one of those sectors, the Level 1 course is not optional, even though the Level 1 certificate is.
The legal duties in plain terms
Because the Level 3 audit is measured against them, it is worth knowing the four duties precisely. Under the current Regulations you must:
- Conduct a risk assessment for the safety and health risks posed to anyone who may be affected by your undertaking in the workplace (regulation 3). Since 1 January 2025 the same duty has applied to platform operators in respect of their platform workers.
- Eliminate, then control (regulation 4). Take all reasonably practicable steps to eliminate foreseeable risk; where that is not reasonably practicable, implement reasonably practicable measures to minimise it plus safe work procedures to control it. The Regulations name the measures: substitution, engineering control, administrative control, and provision and use of suitable personal protective equipment — in that order of preference. You must also specify the roles and responsibilities of the people implementing them.
- Keep records, for not less than three years (regulation 5). You must maintain a record of the risk assessment and of the measures and safe work procedures implemented, submit it to the Commissioner when required, and retain it for at least three years.
- Review at least once every three years (regulation 7) — and additionally whenever any bodily injury occurs as a result of exposure to a hazard in the workplace, or whenever there is a significant change in work practices or procedures.
Regulation 8 attaches real penalties. Contravening the duty to assess or to control risk carries a fine of up to $50,000, or imprisonment for up to two years, or both. Failing to keep and produce records, to inform people of the risks, or to review the assessment carries up to $20,000 or two years, rising to $50,000 for a repeat offender. Failing specifically to retain records for three years carries up to $10,000, and up to $20,000 or six months for a repeat offender. Those are the numbers in the current text of the Regulations as at September 2026.
Why companies pursue it
Two reasons, and it is worth being clear-eyed about which one is driving you. The first is commercial: the WSH Council states that a bizSAFE certificate "will help you to expand your business opportunities as it is often a key requirement for contracts and tenders". That is the Council's own characterisation, and it matches what most Singapore SMEs experience — the request for a bizSAFE certificate arrives from a client or a main contractor, not from a regulator.
The second reason is the one that survives the contract. Working through Level 3 forces a company to write down what its people actually do, identify what could hurt them, decide who fixes what by when, and then prove the fix happened. Companies that treat it as a box to tick get a certificate. Companies that treat it as a first proper pass at their own operations usually find several things they did not know were true about their own worksites.
The Council also runs the bizSAFE Marketplace, a free directory where certified companies list their products and services so buyers can find "a company that has Risk Management Capabilities to be your business partner or contractor". Your details are added automatically when a level is approved. It is a small benefit, but it is a real one, and a surprising number of certified companies never realise they are listed.
What we cannot tell you — because it is not published as a single official rule — is exactly which buyers mandate which level. You will find plenty of consultants asserting that particular statutory boards require Level 3 for all tenders. That may well be true of specific tenders, but we could not verify it as a general published requirement from a primary source, so we are not going to assert it. The reliable version is the Council's: bizSAFE is often a key requirement for contracts and tenders, and the level demanded is set by the buyer. If a client is asking you for bizSAFE, ask them which level and by when, because the answer determines whether you need three weeks or three months.
The levels, one by one
The programme runs Level 1, Level 2, Level 3, Level 4 and bizSAFE STAR. You do not have to climb them in order: the Council's own wording is that "though bizSAFE is structured as a 5-step programme, your company may apply for a level directly as long as it meets the level's requirements". What follows is what each level recognises, what you have to do to get it, and how long it lasts.
bizSAFE Level 1 — the top management course
Level 1 recognises that your company is aware of its legal obligations under the WSH Act and is able to develop a WSH policy. It is achieved by one person: your CEO or a board director attends the Top Executive WSH Programme (TEWP), a three-hour programme delivered in person or online, covering the legal responsibilities of top executives under the WSH Act and how to develop a WSH policy.
Who attends: the CEO or a board director. This is not delegable for bizSAFE purposes. Non-CEOs and non-directors may attend the TEWP, but the Certificate of Attendance they receive cannot be used to apply for bizSAFE certification — only the Certificate of Completion issued to a CEO or board director can.
Portability: the Certificate of Completion follows the person. A participant can use it to apply for bizSAFE Level 1 even after joining another company.
If your CEO leaves: the newly appointed top management must attend the programme as soon as possible to maintain your company's bizSAFE status.
Validity: six months from the approval date, and not renewable once it expires.
That six-month, non-renewable validity is the fact people find hardest to believe, and it is worth pausing on. Level 1 is deliberately built as a starting point rather than a destination — the Council's position is that companies should progress to Level 3 and above. If you need a certificate that stays valid, Level 1 is not it.
bizSAFE Level 2 — the Risk Management Champion
Level 2 recognises that your company has a trained Risk Management (RM) Champion who knows how to facilitate and mobilise the relevant employees in developing a risk management plan and conducting risk assessments. Again it is achieved by one person's training, not by an inspection of your workplace.
Your RM Champion qualifies by holding one of the following: the Risk Management Course issued between November 2007 and December 2013; a WSQ Statement of Attainment for "Develop Risk Management Implementation Plan" (course code MF-COM-402E-1); a WSQ Statement of Attainment for "Workplace Safety and Health Control Measures" (course code WPH-WSH-4075-1.1); WSH-related qualifications acceptable to MOM; or a registered WSH Officer licence with MOM.
The course: two days, through an approved training provider. Participants receive a WSQ Statement of Attainment.
Subsidies: the Council notes you may be eligible for government training subsidies for WSQ courses, and says to enquire with the training provider directly to check.
Portability: as with Level 1, the qualification follows the person — if you took the course in a previous job, you can use that Statement of Attainment provided you are the RM Champion for your current company.
Validity: six months from the approval date, and not renewable once it expires. If your RM Champion leaves, the newly appointed champion must attend the course as soon as possible to maintain your status.
Do not skip the Level 2 course just because the Level 2 certificate expires quickly. The Level 3 audit checklist explicitly asks the auditor to verify that your risk assessment team leaders hold this qualification or an accepted equivalent — so the training is a practical prerequisite for passing Level 3, even though applying for the Level 2 certificate is not.
bizSAFE Level 3 — the Risk Management audit
This is the level that matters, and the level that changes in kind rather than degree. Levels 1 and 2 certify that individuals were trained. Level 3 recognises that your company has conducted risk assessments for every work activity and process in your workplace, in compliance with the requirements in the WSH (Risk Management) Regulations — and an independent auditor has to verify it.
To achieve it you engage an Auditing Organisation (AO) registered with the Ministry of Manpower to provide WSH auditing services to conduct a Risk Management Implementation Audit against the bizSAFE Level 3 Risk Management Audit Checklist. MOM only registers auditing organisations that are first accredited by the Singapore Accreditation Council under its criteria CT 17, so the chain of approval runs SAC accreditation, then MOM registration, then your audit. Both MOM and the Council publish lists of registered organisations; use them rather than a search engine.
The audit: based on the Level 3 Risk Management Audit Checklist, examining the implementation of your risk management plan. The Council indicates the audit typically runs from half a day to two days depending on the organisation.
The report: comprises an audit report cover page, the audit checklist and the audit highlights. It is valid for three years from the audit date — but only reports with at least six months of validity remaining are accepted for a bizSAFE application.
The conflict-of-interest rule: your consultancy organisation and your auditing organisation must be separate and independent. Applications are rejected if both come from the same company, or if the consultancy and auditing are arranged as a package.
Validity: three years from the approval date where you qualify via the audit report.
There are alternative routes that remove the need to engage an AO. A company holding SCAL's Singapore List of Trade Subcontractors (SLOTS) membership certificate together with its Safety & Green Management Assessment Scheme (SgMA) certificate does not need a separate RM audit; nor does a healthcare institution holding a Joint Commission International certificate; nor does a Responsible Care Award winner. Where you qualify by one of those routes, the bizSAFE certificate's validity follows that certificate instead — SLOTS and JCI set their own expiry dates (and must have at least three months of validity left when you apply), while a Responsible Care Award gives two years from the date of the award.
bizSAFE Level 4 — the management system champion
Level 4 is widely misunderstood, so here is the precise position: it recognises that your WSH Management System (WSHMS) Champion is equipped with the knowledge and skills to develop and implement a robust management system. It is a training milestone, not a system audit. Nobody audits your management system to award Level 4.
You qualify by meeting one Level 3 requirement and one Level 4 requirement. The Level 3 requirement is whichever route you used above — the Risk Management Audit Report, or SLOTS plus SgMA, or JCI, or a Responsible Care Award. The Level 4 requirement is one of: a WSQ Statement of Attainment for "Develop a Workplace Safety and Health Management System (WSHMS) Implementation Plan" (MF-COM-403E-1); a WSQ Statement of Attainment for "Workplace Safety and Health System Management" (WPH-WSH-4086-1.1); WSH-related qualifications acceptable to MOM; or a registered WSH Officer licence with MOM.
The course: four days, aimed at supervisors and above, covering how to implement a robust WSHMS. Participants receive a WSQ Statement of Attainment, and government training subsidies may be available.
If your champion leaves: the newly appointed WSHMS Champion should attend the course to maintain your company's bizSAFE status.
Validity: three years from the approval date where the Level 3 component is a Risk Management Audit Report; otherwise it tracks the SLOTS, JCI or Responsible Care expiry as at Level 3.
bizSAFE STAR — the certified management system
STAR is the top of the programme, and it is the only level that requires a genuinely certified management system. It recognises that your WSHMS identifies, manages and controls workplace risks or hazards in compliance with the WSH Act and international standards such as ISO 45001.
With effect from 1 April 2021, you must submit one of the following certifications together with a Risk Management Audit Report: a Singapore Standard SS 651:2019 certificate; an ISO 45001:2018 certificate issued by a certification body accredited by the Singapore Accreditation Council; or an ISO 45001:2018 certificate issued by a certification body accredited by an accreditation body recognised under a Mutual Recognition Arrangement.
Two details do a lot of work here. The first is "together with a Risk Management Audit Report" — an ISO 45001 certificate on its own is not enough for STAR; the RM audit is still required alongside it. The second is accreditation: it is not sufficient that a certification body issued you an ISO 45001 certificate. That body must be accredited by SAC or by an MRA-recognised accreditation body. Since 1 April 2021 the Council has not accepted OHSAS 18001 or non-accredited ISO 45001 certification. If you are buying ISO 45001 certification partly in order to reach bizSAFE STAR, verify the certification body's accreditation before you sign, not after.
STAR validity is tagged to the validity of the underlying SS 651 or ISO 45001 certificate — so your bizSAFE status and your management-system certification expire together, which is at least easy to diarise. If you are heading in this direction, our guide to ISO 45001 beyond the certificate covers what the standard asks for in practice.
What the Level 3 audit actually looks for
The Level 3 Risk Management audit is not a document review. The official checklist marks each question with the method the auditor must use — DR for document review, IP for interview personnel, PI for physical inspection — and a large share of the questions require interviews or a walk through your workplace, not just a file. The phrase "interview 3 employees" appears again and again. An auditor who only reads your folder is not following the checklist.
The audit is measured against two reference standards: the WSH (Risk Management) Regulations and the Code of Practice on Workplace Safety and Health Risk Management. The current checklist is revision V3.3, in effect from 1 July 2026. It is organised into five sections, plus a set of audit highlights and a prescribed interview sheet.
Section 1 — Policy
One question, and it catches people. The auditor checks that your WSH policy is up to date, signed by the current CEO or top management within the top three tiers, and communicated within the company — and then interviews three employees to verify they know where to retrieve the policy and what it means to them. A policy signed by a CEO who left two years ago fails. A policy nobody can find fails. The auditor also checks that the CEO or top management attended the Level 1 workshop.
Section 2 — Preparation
Two questions covering who does the risk assessment and what it covers. First, the auditor verifies that your appointed risk assessment team leaders are competent — holding the Level 2 RM course, or the WSQ "Develop Risk Management Implementation Plan", or an accepted equivalent — and that enough team leaders and members have been appointed for the company's work activities. Second, they check you have an inventory of work activities covering routine, non-routine and new activities, and then walk the worksite to validate it. A list that omits half of what you actually do is the most common failure point in this section, and a walkthrough finds it quickly.
Section 3 — The risk assessments themselves
This is the largest section, eleven questions deep, and the auditor works from a sample — typically checking three risk assessments per question. They look for a risk register that is readily available and maintained at the workplace, and for each work activity, the top three hazards including at least one health hazard, cross-checked against your accident, injury, reportable incident and near-miss records.
Then the coverage questions, which are where modern bizSAFE differs most from the version people remember:
- 1.Hazard categories. Physical, mechanical, electrical, chemical, biological and psychosocial hazards considered where applicable.
- 2.Terrorism, disease outbreak and mental well-being. The auditor checks three risk assessments for evidence that you have updated your risk management processes to account for terrorism threats, infectious disease outbreaks and transmission, and mental well-being. This is a distinct, explicit checklist question — not an optional extra.
- 3.Work organisation factors. Excessive workload, prolonged working hours, inadequate training, inadequate acclimatisation to hot environments, and alienated sub-groups of employees who could be at risk of self-radicalisation.
- 4.Personal health-risk factors. Physical fitness, chronic disease, conditions affecting safety-critical work, pregnancy, smoking, and medication or alcohol misuse — considered where applicable.
- 5.Everyone affected. Contractors and visitors included, not just your own employees.
- 6.Reasonable risk levels. The auditor assesses whether severity and likelihood have been reasonably determined, and asks your RA team to explain how they decide them. Blanket "low" ratings across a worksite invite exactly this question.
- 7.Upstream control. Do the control measures focus on elimination, substitution and engineering control — rather than defaulting to PPE and a briefing? The auditor then walks the workplace to verify the upstream controls are actually implemented on site.
- 8.Named owners and due dates. Each control measure must specify who implements it and by when, and the auditor interviews those people to check they know about their own appointment and deadline.
- 9.Manager approval. Completed risk assessments must be approved by the manager of the work activity — area, functional or activity manager — and the auditor interviews that manager about their approval criteria.
Read item 8 and item 9 together and you have the essence of the whole audit. It is not enough for a control to be written down. A named person has to know it is theirs, a named manager has to have approved it, and the auditor will talk to both of them. Risk assessments produced by a consultant and signed off in bulk fall apart at precisely this point, because the people named in them have never seen them.
Section 4 — Implementation
Eight questions, and this is the section conducted mostly on your feet. The auditor asks a manager whether the risk control implementation plan is followed through and whether a procedure exists for tracking implementation status, then walks the workplace to inspect one completed and one ongoing control. They interview three implementation persons about their plans. They check for evidence that controls were assessed for effectiveness after implementation, comparing accident and injury records before and after where applicable.
They check that risk assessments are easily available to employees — by asking three employees to show the auditor how they access the correct one on site. They check hazard awareness through briefing records, noticeboards, signage and a further three interviews. They ask for the safe work procedures covering your three highest-risk activities, and interview a manager, a supervisor and a worker at the workstation to see whether the procedure is genuinely used. And they check the controls addressing the possibility of a terrorism threat, including whether employees can explain the SGSecure tenets — "Run, Hide, Tell" and "Press, Tie, Tell" — and your lockdown procedure.
Section 5 — Review
One question for every applicant: is there a procedure to review and revise risk assessments, and do the RM team and top management know the criteria — at least once every three years, on any bodily injury resulting from exposure to a hazard, or on a significant change in work practices or procedures? That is the statutory test from regulation 7, asked directly of your people.
Renewal applicants face five further questions, which is why renewal is not merely a repeat of the first audit. The auditor checks that reviews actually happened within three years (noting that "where practicable, RA should be reviewed annually"); that risk assessments were revised after injuries, testing this against your accident, incident, near-miss and dangerous occurrence records; that they were revised after significant changes in the last three years; that they were revised when new information emerged on emerging WSH risks, terrorism, disease outbreak or mental well-being; and that changes were communicated and consulted with internal and external stakeholders across all functions and levels — verified by interviewing three employees about whether they knew the assessment had changed.
The audit highlights
Beyond the five sections, the checklist carries a set of audit highlights targeting national problem areas: vehicular safety, machinery safety, slips, trips and falls, work at height, and health promotion. Each is answered Yes, No or Not Applicable, and each has its own walkthrough and interview. Machinery safety looks for effective guarding and a lock-out tag-out procedure before maintenance. Work at height looks for a Fall Prevention Plan customised to your site and secure anchorage points, with workers asked where they hook their harness. Health promotion looks for at least one programme addressing the health risks in your own risk register and one general health and mental well-being programme.
New since 1 January 2026
Risk Management implementation audits now include verification checks on speed limiters installed in lorries. The WSH Council states that, as part of a bizSAFE application or renewal, companies without speed limiters in any of their lorries would not be able to complete a satisfactory RM audit from 1 January 2026 onwards. The checklist asks the auditor to collect evidence — an invoice or inspection report from the vehicle inspection centre — alongside your driver fatigue management programme and workplace traffic management. If you operate lorries, resolve this before you book the audit rather than discovering it during one.
What you need to have, and how long to allow
The auditor works from evidence you attach to the report, so the practical question is what has to exist before they arrive. Working from the checklist's own "supporting evidence" column, here is what gets attached to a Level 3 audit report.
- Your WSH policy, current and signed by the sitting CEO or top management, plus the CEO's Level 1 training certificate.
- Training certificates for every risk assessment or RM team leader.
- The inventory of work activities — routine, non-routine and new.
- The risk register, including a photograph showing it is available and maintained at the workplace.
- The individual risk assessments themselves, with the relevant considerations highlighted, plus the document explaining how you determine severity and likelihood.
- Accident, injury, reportable incident and near-miss records — used to cross-check that your top hazards are the real ones.
- Safe work procedures for your highest-risk activities.
- Implementation plans, records of post-implementation effectiveness evaluation, and photographs of completed and ongoing controls.
- Communication and consultation evidence — briefing attendance records, meeting minutes, staff dialogues, noticeboard messages, emails to stakeholders.
- Your emergency response plan and evidence of security implementation, plus the completed interview checklists.
- For renewals: records of changes in the last three years and the corresponding revised risk assessments, plus meeting minutes showing review and approval.
On timing, only one figure is officially published: the Council asks you to allow 10 working days for processing from the date of submission. Everything before that is under your control and takes considerably longer. A realistic sequence, assuming you are starting from a genuinely low base, looks like this.
- 1.Get your people trained. The CEO's three-hour TEWP and your RM Champion's two-day course, booked through approved training providers. Course availability, not course length, is usually what sets the date.
- 2.Build the inventory of work activities. Everything your company does, including the non-routine and the seasonal. Do this before writing a single risk assessment, because the inventory defines the scope of all of them.
- 3.Write the risk assessments with the people who do the work. This is the long pole and it cannot be usefully compressed. Each needs hazards, severity and likelihood, controls weighted upstream, a named implementation owner, a due date and manager approval.
- 4.Actually implement the controls, and record that you did. Photographs, completion records, and an assessment of whether the control worked. The audit checks implementation on site, so controls that exist only on paper are found on the walkthrough.
- 5.Communicate and brief. Employees must be able to find the risk assessments, explain the hazards and controls for their own work, and describe what to do in an emergency. Keep the attendance records.
- 6.Engage an MOM-registered auditing organisation — separate and independent from any consultant you used — and run the audit, half a day to two days.
- 7.Close every finding before applying. The checklist cover page carries the instruction in capitals: do not submit the bizSAFE application until all findings are closed.
- 8.Submit and allow 10 working days. The e-certificate and logo are emailed to your senior management representative, and your details are added to the bizSAFE Marketplace.
One more thing the Council flags at application stage: onsite verification inspections are carried out by Auxiliary Enforcement Officers to check whether the auditing organisation followed the checklist and was sufficiently stringent. If those checks find problems with the audit, the company may have to re-conduct it, and processing then exceeds 10 working days. That is an additional reason to choose an auditing organisation on rigour rather than on price.
What it costs
The one cost that is officially published is zero: the WSH Council states that "it is free to apply for bizSAFE recognition". There is no application fee at any level. What costs money is everything you have to buy in order to qualify — the training courses and, from Level 3, the Risk Management audit.
The Council does not publish prices for either, and neither will we. Training is delivered by approved training providers who set their own fees, and audits are carried out by independent auditing organisations who quote their own. There is no official national price for bizSAFE certification, so any single figure you are given is one provider's commercial quote rather than a published rate. Get quotes from two or three organisations and compare what is actually included — particularly whether the audit fee covers the follow-up needed to close findings.
Two things are worth asking about explicitly. The first is government training subsidies: the Council states you may be eligible for subsidies on the WSQ courses and directs you to enquire with the training provider, so ask before you book rather than after. The second is the conflict-of-interest rule described above — a package deal that bundles consultancy with auditing is cheaper precisely because it is not permitted, and it will cost you the application.
Renewal, expiry and what happens when you lapse
Renewal applications should be submitted two months before your company's bizSAFE status expires. For Level 3 and above that means working backwards: the audit has to be booked, conducted and its findings closed before that submission date, not before the expiry date. Auditing organisations get busy, and a renewal left until the final month is a renewal that lapses.
The validity rules differ by level and by route, so the table below is worth keeping. Note especially that Level 1 and Level 2 are not renewable once they expire — the route back is to qualify at whatever level you can now meet.
Level 1: six months from approval. Not renewable once expired.
Level 2: six months from approval. Not renewable once expired.
Level 3 (via RM Audit Report): three years from the approval date. The audit report itself is valid three years from the audit date, and must have at least six months left to run when you apply.
Level 3 or 4 (via SLOTS + SgMA, or JCI): tracks that certificate's expiry, and the certificate needs at least three months of validity when you apply.
Level 3 or 4 (via Responsible Care Award): two years from the date of the award.
Level 4 (via RM Audit Report): three years from the approval date.
bizSAFE STAR: tagged to the validity of your SS 651 or ISO 45001 certificate.
There is a second, quieter way to lapse that has nothing to do with dates. Your bizSAFE status depends on the current holders of certain roles being qualified. If the CEO or top management changes, the newly appointed top management must attend the Level 1 programme as soon as possible to maintain your status. If the RM Champion leaves, the newly appointed champion must attend the Level 2 course. If the WSHMS Champion leaves, the same applies at Level 4. A resignation, in other words, can put your certification at risk months before the certificate expires — which is a good argument for having more than one trained person.
Why companies fail or stall
Almost none of it is exotic. The pattern is consistent, and every item below maps to something specific in the checklist or the programme rules rather than to bad luck.
- The consultant also did the audit. The single cleanest rejection. Consultancy and auditing must be separate and independent organisations, and applications are rejected where they are the same company or arranged as a package.
- Risk assessments nobody who does the work has seen. The checklist repeatedly sends the auditor to interview three employees, three implementation persons, the approving manager, a supervisor and a worker at the workstation. Documents written in an office and never discussed on site fail those interviews regardless of how good the documents are.
- The inventory of work activities is incomplete. The auditor validates it by walking the worksite. Non-routine work, maintenance, seasonal activity and anything done by contractors are the usual omissions.
- Controls exist on paper but not in the workplace. The auditor inspects one completed and one ongoing control. This is the difference between a risk assessment and risk management, and it is checked physically.
- Everything defaults to PPE. The checklist explicitly asks whether controls focus on upstream control — elimination, substitution, engineering. A register in which every control is a helmet, a sign and a toolbox talk reads as a register that has not really engaged with the hazard.
- Terrorism, disease outbreak and mental well-being are not addressed. These are distinct, explicit checklist questions with their own evidence requirements, and companies working from an older mental model of bizSAFE routinely miss them.
- The WSH policy is signed by a former CEO. One question, easily fixed, frequently failed.
- Applying with findings still open. The instruction not to submit until every finding is closed is printed on the audit report cover page.
- The audit report has gone stale. Three years' validity from the audit date, but it must have six months remaining when you apply. Companies that audit early and apply late lose the report.
- Renewal evidence was never generated. Renewal asks for proof that assessments were revised after incidents and after significant changes over the past three years. If nobody updated a risk assessment in three years, that evidence cannot be created retrospectively — a three-year-old register that has never changed is itself the finding.
The through-line is that Level 3 is checking a live process, not a folder. A company that runs risk management continuously walks into the audit with the evidence already sitting there. A company that starts three weeks out is trying to manufacture, in three weeks, a record of three years of behaviour — and the renewal questions are designed to detect exactly that.
Where we come in
Teammate App is our product, so treat this section as what it is. Level 3 and above turn on documented risk assessments, named owners with due dates, evidence that controls were implemented and reviewed, communication records, and a register an auditor can be shown on the day — kept current for three years and demonstrably revised after incidents and changes. That is the kind of record-keeping our platform exists to manage: 15 modules covering risks, audits, actions, training, contractors, assets and documents, aligned to ISO 45001, 9001 and 14001, with our own ISMS certified to ISO/IEC 27001:2022 by Telarc under JAS-ANZ accreditation, and customer data hosted in Australia on AWS Sydney.
What software cannot do is make you certified. bizSAFE is awarded by the WSH Council on the strength of training your people attend and an audit an independent MOM-registered organisation conducts. Teammate App is not bizSAFE-certified, endorsed or approved, and no system can guarantee a result that depends on what an auditor finds when they walk your site and talk to your staff. A records system helps you keep the evidence and keep it current. The work it evidences is still yours.
Questions we get asked
Is bizSAFE compulsory in Singapore?
bizSAFE itself is not a legal requirement — it is a capability-building programme run by the Workplace Safety and Health Council, and no law says a company must hold a bizSAFE certificate. Two things complicate that answer, though. The first is that the WSH Council states plainly that a bizSAFE certificate is "often a key requirement for contracts and tenders", so for a great many companies it is commercially unavoidable even though it is legally optional. The second is that the underlying duties are compulsory: the Workplace Safety and Health (Risk Management) Regulations require every employer, self-employed person and principal to conduct risk assessments, keep the records for at least three years and review them at least once every three years, whether or not you ever apply for bizSAFE. And one specific piece of the programme is itself law — completing the Top Executive WSH Programme is a legal requirement for the CEO or Board Director of companies in the higher-risk sectors, which MOM identifies as Construction, Manufacturing, Marine and Transport & Storage.
Do I have to do Level 1 and Level 2 before Level 3?
No. The WSH Council's own wording is that "though bizSAFE is structured as a 5-step programme, your company may apply for a level directly as long as it meets the level's requirements". You can go straight to Level 3 if you can meet what Level 3 asks for. In practice most companies still take the courses in order, because the Level 2 course is what teaches the person who will build the risk assessments the auditor is going to read — and the Level 3 audit checklist specifically asks the auditor to check that your risk assessment team leaders hold the Level 2 qualification or an accepted equivalent. So the sequence is useful even though it is not mandatory. What you can skip is the paperwork of applying for the Level 1 and Level 2 certificates themselves, which is a reasonable choice given both expire in six months and neither can be renewed.
How long is a bizSAFE certificate valid for?
It depends sharply on the level, and the difference surprises people. bizSAFE Level 1 and Level 2 certificates are each valid for six months from the approval date, and the WSH Council states they are "not renewable once it expires". Level 3 and Level 4 certificates based on a Risk Management Audit Report are valid for three years from the approval date. bizSAFE STAR validity is tagged to the validity of the underlying SS 651 or ISO 45001 certificate. Where a company qualifies through an alternative route, the certificate follows that route's expiry instead — a SCAL SLOTS or JCI certificate sets the date, and a Responsible Care Award gives two years from the date of the award. Renewal applications should be submitted two months before your bizSAFE status expires.
How much does bizSAFE cost?
Applying for bizSAFE is free — the WSH Council states that "it is free to apply for bizSAFE recognition". The costs sit in the two things you have to buy to qualify: the training courses your people attend, and the Risk Management audit at Level 3 and above. The Council does not publish a price for either, because both are supplied by independent organisations — approved training providers set their own course fees, and MOM-registered auditing organisations quote their own audit fees. So anyone quoting you a definitive national price for bizSAFE certification is quoting their own price, not an official one. Get quotes from two or three providers, and ask the training provider directly about government training subsidies for the WSQ courses, which the Council says you may be eligible for.
What is the difference between bizSAFE Level 4 and bizSAFE STAR?
The gap between them is bigger than the names suggest, and this is the most commonly misunderstood part of the programme. bizSAFE Level 4 is fundamentally a training milestone: it recognises that your WSH Management System Champion has been trained to develop and implement a management system, and you qualify by holding one Level 3 requirement plus one Level 4 requirement — typically your Risk Management Audit Report plus a four-day WSQ Statement of Attainment. Nobody audits your management system to award Level 4. bizSAFE STAR is where the management system is genuinely certified: since 1 April 2021 you must submit either a Singapore Standard SS 651:2019 certificate or an ISO 45001:2018 certificate — issued by a certification body accredited by the Singapore Accreditation Council, or by an accreditation body recognised under a Mutual Recognition Arrangement — together with a Risk Management Audit Report. So Level 4 says your champion knows how to build the system; STAR says an accredited certification body has audited the system you built.
Can our safety consultant also carry out the bizSAFE audit?
No, and this is one of the fastest ways to have an application rejected. The WSH Council requires that "to avoid conflict of interest, your consultancy organisation and auditing organisation must be separate and independent", and states that applications will be rejected if the consultancy and the auditing come from the same company, or if the consultancy and auditing are arranged as a package. A bundled offer of "we will set up your risk management and audit it too" is therefore not a shortcut — it is a rejected application with the money already spent. If a provider offers you one, that tells you something about how closely they read the programme rules. Engage a consultant if you want help, and engage a separate auditing organisation that is registered with MOM to provide WSH auditing services.
What happens if our bizSAFE certificate expires?
For Level 3 and above, an expired certificate means you are no longer listed as holding that status, which matters mainly because clients and main contractors check it. The remedy is a fresh Risk Management audit and a new application, which is why the Council asks for renewals two months before expiry — you need the audit booked, conducted and its findings closed before that date, not after it. Level 1 and Level 2 are different and stricter: those certificates are not renewable once they expire, so the route back is to qualify again at whichever level you can now meet. There is also a practical trap in the timing rules at Level 3: your Risk Management Audit Report is valid for three years from the audit date, but the WSH Council will only accept a report that still has at least six months of validity left when you apply. A report you sat on for two and a half years is no longer usable.
Written by the Teammate App team. This is general guidance on the bizSAFE programme and is not legal advice. bizSAFE is administered by the Workplace Safety and Health Council; Teammate App has no affiliation with the Council or the Ministry of Manpower, and nothing here is endorsed by either. The programme requirements, validity periods, course codes and application rules above are taken from the WSH Council's own bizSAFE pages and FAQ at tal.sg, from the Ministry of Manpower at mom.gov.sg, and from the official bizSAFE Level 3 Risk Management Audit Checklist (revision V3.3, in effect from 1 July 2026), all read in September 2026. The statutory duties and penalties are taken from the current text of the Workplace Safety and Health (Risk Management) Regulations on Singapore Statutes Online. Course fees and audit fees are not published by the Council and are not stated here. Programme rules change — confirm current requirements with the WSH Council before acting on anything on this page. Teammate App is our own product and is identified as such above.
