  2. Course Objectives • This course aims to equip participants with the knowledge and skills needed to assess and report on the conformance and effective implementation of an occupational health and safety management system in accordance with ISO 19011. • At the end of this course, participants will be able to: • Describe the responsibilities of an Internal Auditor and describe the role of internal audit in the maintenance and improvement of management systems in accordance with ISO 19011 • Explain the purpose and structure of OHSAS 18001:2007 and explain the principles, process and selected techniques used for the management of occupational health and safety including the significance of these for OH&S auditors.

  3. Course Objectives • At the end of this course, participants will be able to: • Plan and prepare for an internal audit • Gather audit evidence through observation, interview and sampling of documents and records • Write factual audit reports that help to improve the effectiveness of the management system

  4. Course Schedule • Day 1 8:30 Introduction / Course Objectives 9:00 Module 1: Background to OHSAS 18001 9:30 Module 2: Understanding the Requirements of OHSAS 18001:2007 12:00 Lunch Break 1:00 Continuation of Module 2 2:30 Workshop 1 (OHSAS 18001:2007 Requirements) 3:30 Module 3: Introduction to OHSAS 18001 Internal Audit 4:30 Module 4: Auditor Training and Qualification 5:00 Module 5: Planning and Preparation 5:30 End of Day 1

  5. Course Schedule • Day 2 8:30 Day 1 Recap 9:00 Workshop 2 (Audit Program) 10:00 Continuation of Module 5 10:45 Module 6: Conducting the Audit 12:00 Lunch Break 1:00 Workshop 3 (Audit checklist) 2:00 Workshop 4 (Conducting Audit) 3:30 Module 7: Reporting and Follow-up 4:30 Workshop 5 (Evaluating Audit Evidence and Writing Finding Statement) 5:15 Module 8: Conclusion 5:25 Course Evaluation 5:30 End of course


  7. Ad Hoc OH&S Management Systems Standards • 1993 SGS & ISMOL ISO 2000 (now in 3rd, 1998 ed.) • 1997 DNV OHSMS • 1998 BVQI Safety Certification • 1998 (Draft) LRQA SMS 8800 • 1998 (Draft) BSI PAS 088 • 1998 (Draft) AS/NZ 3802 (now a standard) • 1998 (Draft) NSAI SR-320 (now a standard) • 1998 (Draft) AENOR UNE 8900 series (now a standard)

  8. Participants • With OH&S MS documents either published or under development – (including the major Certification Bodies) Project initiated and led by BSI • All National Standards Bodies who had made positive indications at ISO workshop • Organizations

  9. Development of OH&S MS Standards • OHSAS 18001:1999 Occupational Health and Safety Management Systems – Specification was published April 1999 • OHSAS 18002:2000 Occupational Health and Safety Management Systems – Guidelines for the implementation of OHSAS 18001

  10. OHSAS 18001:2007 Revision History • In 2005, the OHSAS Working Group started the process for revising OHSAS 18001:1999 • An initial working draft (WD1) of the revised OHSAS 18001 standard was circulated in January, 2006 for public comment • 500 comments received on WD1 at OHSAS Working Group meeting at Madrid, Spain in October 2006 • Second draft (WD2) was circulated for comment in November, 2006 • OHSAS Working Group met again Shanghai, china in March, 2007. 500+ comments on WD 2 were reviewed • OHSAS 18001:2007 – Released on 1st July 2007 • OHSAS 18002 – Initial Meeting 3rd & 4th July 2007 • OHSAS 18002 – Working Draft 1, November 2007

  11. OHSAS 18001:2007 Revision Objective • Better align it with ISO 9001:2000 and ISO 14001:2004 • Keep the same clauses order and most of the changes of ISO 14001:2004 • Encourage Management Systems integration and possibly increase the interest in OHSAS • More results oriented compared to OHSAS 18001:1999 • Had its elements and definitions refined

  12. Summary of Key Changes • OHSAS 18001 now refers to itself as a standard, not a specification, or document, as in its earlier edition • New definitions have been added, including major ones like “incidents”, “risk”, “risk assessment”, and existing definitions revised (3.9, 3.21, 3.22) • The term “tolerable risk” has been replaced by the term “acceptable risk” (3.1) • The importance of “health” has now been given greater emphasis balanced with “safety” • Focus on occupational safety, not getting distracted with assets, security, etc.

  13. Summary of Key Changes • The definition of the term “hazard” no longer refers to “damage to property or damage to the workplace environment” (3.6) • The term “accident” is now included in the term “incident” (3.9). • The inclusion of behavior, capabilities and other human factors as elements to be considered in the identification of hazards, risk assessment and determination of controls and finally in competence, training and awareness (4.3.1) • A new requirement has been introduced for the consideration of the hierarchy of controls as part of OHS planning (4.3.1) • Change management is now more explicitly addressed (4.3.1 & 4.4.6)

  14. Summary of Key Changes • Clauses 4.3.3 Objectives and 4.3.4 Programmes were merged • New requirements have been introduced for participation and consultation ( • A new clause on the “Evaluation of compliance” has been introduced, aligned with ISO 14001 (4.5.2) • New requirement have been introduced for the investigation of incidents (

  15. Benefits of OHSAS 18001 • Demonstrating your commitment to Occupational Health & Safety can positively improve the efficiency of internal operations and consequently reduce accidents, ganger and downtime. • Employee safety and the quality of the working environment are actively improved because objectives and responsibilities are made clearer and all employees are prepared to effectively deal with any future hazards. • OHSAS 18001 ensures compliance with current legal requirements, reducing the risk of penalties or possible litigation.


  17. Methodology of OHSAS Std. Follow a Plan-Do-Check-Act approach. • Plan - Establish the objectives and processes needed to deliver the results (in line with the OHSMS). • Do - Implement the needed processes of the OHSMS. • Check - Check the processes against the policy, objectives, targets, regulations, and report the results. (Auditing) • Act - Take actions that will continually improve the OHSMS. ACT CHECK PLAN DO

  18. Characteristics of OHSAS 18001:2007 • Contains requirements that can be objectively audited • Does not establish absolute requirements for OH&S performance beyond the commitments • Requires policy commitment to comply with applicable legal requirements and with other requirements to which the organization subscribes, to the prevention of injury and ill health and to continual improvement • Application of various elements of the management system might differ depending on the intended purpose and the interested parties involved.

  19. Level of Detail and Complexity of OH&S Management System • The extent of documentation and the resources devoted to OH&S Management System depend on: • Scope of the system • Size of an organization • Nature of activities, products and services • Organizational culture

  20. Terms and Definitions • Acceptable risk (3.1) • Hazard (3.6) • Hazard identification (3.7) • Ill health (3.8) • Incident (3.9) • Occupational Health and Safety (OH&S) (3.12) • Occupational Health and Safety Management System (3.13) • Risk (3.21) • Risk Assessment (3.22) • Workplace (3.23)

  21. OHSAS 18001:2007 Main Clause Titles • 1. Scope • 2. Reference Publications • 3. Terms and Definitions • 4. OH&S Management System Requirements • 4.1 General Requirements • 4.2 OH&S Policy • 4.3 Planning • 4.4 Implementation and Operation • 4.5 Checking • 4.6 Management Review

  22. 1. Scope • Sets out requirements for OH&S management system • Describes good management practices • Does not state specific OH&S performance criteria • Applicable to small or large organizations • Applicable to any industry, organization or activity • Intended to address occupational health and safety • Not intended to address the following: • Other health and safety areas such as employee well being/wellness programmes • Product safety, property damage, environmental impacts

  23. 4.1 General Requirements • Organization shall: • Establish, document, implement, maintain and continually improve an OH&S management system in accordance with the requirements of this OH&S standard • Determine how it will fulfill these requirements • Shall define and document the scope of its OH&S management system

  24. 4.2 OH&S Policy • Top management shall define and authorize the OHS Policy and ensure that within the defined scope of the OHSMS • It is appropriate to the organization’s OH&S Risks • Commit to prevention of injury and ill health and continual improvement • Commit to comply with legislation and other requirements that relate to its OHS hazards • Provides the framework for setting and review OH&S objectives • Documented, implemented and maintained • Communicated to all persons working under the control of the organization with the intent that they are made aware of their individual OH&S obligations • Available to interested parties • Reviewed periodically

  25. 4.3.1 Hazard Identification, Risk • Procedure for ongoing hazards identification, risk assessment and determination of necessary controls • Procedure shall take into account the following: • Routine and non-routine activities; • Activities of all personnel (including subcontractors and visitors) • Human behavior, capabilities and other human factor • Hazards originating outside the workplace capable of adversely affecting the H&S of personnel within the workplace 4.3 Planning

  26. 4.3.1 Hazard Identification, Risk • Procedure shall take into account the following: • Infrastructure, equipment and materials at the workplace whether owned or provided by others • Changes or proposed changes in the organization, its activities, or materials, including temporary changes; • Modifications to the OH&S management system, including temporary changes, and their impacts on operations, processes, and activities • Any applicable legal obligations; • Design of work areas, processes, installations, machinery / equipment, operating procedures and work organization including their adaptation to human capabilities 4.3 Planning

  27. 4.3.1 Hazard Identification, Risk • Methodology shall: • Be defined with respect to its scope, nature and timing to ensure it is proactive; • Provide for the identification, prioritization and documentation of risks and application of controls • Management of change – OHS hazards and risks associated with changes shall be identified prior to the introduction of such changes. • Results of risk assessments are considered when determining controls 4.3 Planning

  28. 4.3.1 Hazard Identification, Risk • When determining controls or changes to existing controls, consideration shall be given to reducing risks following this hierarchy: • Elimination • Substitution • Engineering controls • Signage/warnings/administrative controls • Personal Protective Equipment (PPE) • OH&S risks and determined controls are taken intro account when establishing, implementing and maintaining its OH&S management system 4.3 Planning

  29. 4.3.2 Legal & Other Requirements • Procedure for identifying and accessing the legal and other applicable requirements • Taken into account in establishing, implementing, and maintaining OH&S management system • Keep the information up to date • Communicate up-to-date information to relevant persons working under the control of the organization and other relevant interested parties 4.3 Planning

  30. 4.3.3 Objectives and Programmes • Documented OH&S objectives at relevant functions and levels • Measurable, where practicable • Consistent with OH&S policy • Legal requirements and other requirements, OH&S risks, technological options, financial, operational and business requirements and views of interested parties taken into account • Establish programmes for achieving its objectives which include as a minimum responsibilities, means and time frame. Such programmes shall be reviewed at regular, planned intervals. 4.3 Planning

  31. 4.4.1 Resources, Roles, Responsibility, Accountability and Authority • Top management – ultimate responsibility • Ensuring availability of resources; • Defining roles, responsibilities and accountabilities; • Appointing a management representative • All personnel with management responsibility shall demonstrate their commitment to the continual improvement of OHS performance. • Persons in the workplace take responsibility for OH&S aspects over which they have control 4.4 Implementation & Operation

  32. 4.4.2 Competence, Training and Awareness • Ensure competence of personnel to carry out designated functions • Identify training needs associated with its OHS risks and its OHS management system • Provide training or other actions, evaluate effectiveness of the training or action taken, and retain associated records. 4.4 Implementation & Operation

  33. 4.4.2 Competence, Training and Awareness • Procedure to make personnel aware of • OH&S consequences, actual or potential, of their work activities, their behavior, OH&S benefits of improved performance • Their specific roles/responsibilities • OH&S policies and procedures / requirements • Emergency preparedness and response requirements • Potential consequences of departure from specified procedures • Training procedure to consider differing levels of responsibility, ability, language skills and literacy and risk 4.4 Implementation & Operation

  34. 4.4.3 Communication, Participation and Consultation Communication • With regard to its OH&S hazards and management system, establish procedure for: • Internal communication among various levels and function • Communication with contractors and visitors • Receiving, documenting and responding to relevant communications from external parties 4.4 Implementation & Operation

  35. 4.4.3 Communication, Participation and Consultation Participation and Consultation • Procedure for: • Participation of workers by their appropriate involvement in HIRADC, incident investigation, development and review of OH&S policies and objectives; consultation where there are changes that affect their OH&S; representation on OH&S matters • Consultation with contractors where there are changes that affect their OH&S • Workers informed about their participation arrangements and who their representative(s) on OH&S matters • Relevant external parties are consulted about pertinent OH&S matters, when appropriate 4.4 Implementation & Operation

  36. 4.4.4 Documentation The OH&S management system documentation shall include: • OH&S policy and objectives • Description of the scope of the OH&S management system • Description of the main elements of the OH&S management system and their interacting, and reference to related documents; • Documents, including records, required by OH&S standard; • Documents, including records determined by the organization to be necessary to ensure effective planning, operation and control of processes that relate to the management of its OH&S risks. 4.4 Implementation & Operation

  37. 4.4.5 Control of Documents Procedure established for controlling all documents and data required by OH&S management system to ensure that: • They are approved for adequacy prior to issue; • They are reviewed and updated as necessary and re-approved; • Changes and current revision status are identified; • Current revisions of relevant documents and data are available at point of use; • Documents remain legible and readily identifiable; • Documents of external origin are identified and distribution controlled • Obsolete documents are assured against unintended use • Obsolete documents retained for legal or knowledge preservation purposes or both, are suitable identified 4.4 Implementation & Operation

  38. 4.4.6 Operational Control • Operations and activities that are associated with the identified hazards where the implementation of controls is necessary • Includes management of change • For those operations and activities, the following shall be implemented and maintained; • Operational controls and integrate it into the OH&S MS • Controls related to purchased goods, equipment and services; • Controls related to contractors and other visitors in the workplace 4.4 Implementation & Operation

  39. 4.4.6 Operational Control • For those operations and activities, the following shall be implemented and maintained: • Documented procedures to cover situations where their absence could lead to deviations from the OH&S policy and objectives; • Stipulated operating criteria where their absence can lead to deviations from the OH&S policy and objectives. 4.4 Implementation & Operation

  40. 4.4.7 Emergency Preparedness and Response • Procedure to identify the potential for emergency situations • Procedure to respond to such emergency situations, taking into account the needs of relevant interested parties (ex. Emergency Services and Neighbors) • Respond to actual emergency situations and mitigate associated adverse OH&S consequences • Identify and provide appropriate emergency equipment (e.g. alarm systems, fire-fighting equipment, critical isolation valves) • Review of emergency response procedure periodically and after periodical testing and occurrence of accident/emergency situations • Carry out periodic emergency response drills and practices 4.4 Implementation & Operation

  41. 4.5.1 Performance Measurement and Monitoring • Procedure to monitor and measure OH&S performance regularly. • The procedure shall provide for: • Qualitative and quantitative measures; • Monitoring of the OH&S objectives are met • Monitoring effectiveness of control • Proactive measures of performance that monitor conformance with OH&S programmes, controls and operational criteria; • Reactive measure of performance that monitor ill health, incidents, other historical evidence of deficient OH&S performance 4.5 Checking

  42. 4.5.1 Performance Measurement and Monitoring • The procedure shall provide for: • Recording the data and results sufficient to facilitate corrective action analysis and preventive action analysis • Procedure for the calibration and maintenance of monitoring equipment 4.5 Checking

  43. 4.5.2 Evaluation of Compliance Procedure for periodically evaluating compliance with applicable legal requirements Procedure for periodically evaluating compliance to other requirements to which it subscribes • Frequency of periodic evaluation may very for different legal requirements. • Maintain records of periodic evaluation. 4.5 Checking

  44. 4.5.3 Incident Investigation, Non-conformity, Corrective Action and Preventive Action Incident Investigation • Procedure to record, investigate and analyze incidents in order to: • Determine OH&S deficiencies that caused or contributed to the occurrence of incidents; • Identify the need for corrective action; • Identify opportunities for preventive actions; • Identify opportunities for continual improvement; • Communicate results of such investigations. 4.5 Checking

  45. 4.5.3 Incident Investigation, Non-conformity, Corrective Action and Preventive Action Incident Investigation • Investigation performed timely • Any identified need for corrective and opportunities for preventive actions shall be dealt with according to requirements of • Results of incident investigations documented and maintained 4.5 Checking

  46. 4.5.3 Incident Investigation, Non-conformity, Corrective Action and Preventive Action Nonconformity, Corrective Action and Preventive Action • Procedure for dealing with actual and potential nonconformities that defines the following: • Identifying and correcting non-conformities and taking actions to mitigate impact. • Determining their causes and taking action to prevent recurrence • Evaluating the need for actions to prevent occurrence of potential nonconformities • Recording and communicating results of corrective and preventive actions taken; • Reviewing effectiveness. 4.5 Checking

  47. 4.5.3 Incident Investigation, Non-conformity, Corrective Action and Preventive Action Nonconformity, Corrective Action and Preventive Action • Where corrective and preventive actions identifies new or changed or the need for new or changed controls, these shall be reviewed, through the risk assessment process prior to implementation. • Changes arising from corrective and preventive actions are made to the relevant documented procedures and appropriate OH&S MS documentation. 4.5 Checking

  48. 4.5.4 Control of Records • Records kept as demonstration of OH&S system’s implementation and use to measure OHSMS performance • Procedure includes identification, storage, protection, retrieval, retention and disposition of records • Records are legible, identifiable and traceable • Records may include: • Hazard Identification and Risk Assessment (living document) • Emergency Drills • Inspection / Audit Records • Incident / Accident / Investigation Report 4.5 Checking

  49. 4.5.4 Control of Records • Records may include: • Health Surveillance • Safety Meeting Minutes • PPE issue / maintenance records • Calibration Records 4.5 Checking

  50. 4.5.5 Internal Audit • Internal audits of the OH&S Management System conducted at planned intervals to: • Determine conformance to planned arrangements for OH&S MS and requirements of OHSAS 18001; • Determine proper implementation and maintenance; • Determine effectiveness in meeting policy and objectives; • Provide information on the results of audits to top management • Audit program/schedule based on result of risk assessments and results of previous audits. 4.5 Checking