Guide
Risk Assessment in Singapore: The Practical WSH Guide
What the WSH Risk Management Regulations require, the three steps of a proper risk assessment, and how to fill the form so it holds up in an audit.
7 min readEvery workplace in Singapore must do a risk assessment by law. It is the process of finding the hazards in your work, judging how serious each risk is, and putting controls in place before someone gets hurt. A good risk assessment is built around how your team actually works, not copied from a template. This guide walks through what the law asks for and how to do it properly.
Key takeaways
- Risk assessment is a legal duty under the WSH (Risk Management) Regulations, for every workplace.
- It has three core steps: identify hazards, evaluate the risk, then control the risk.
- Controls follow the hierarchy of control. PPE is the last resort, not the first.
- The assessment must be reviewed at least once every three years, or when work changes.
- A risk assessment copied from a template is the top reason audits raise findings.
What the law requires
The WSH (Risk Management) Regulations place a legal duty on every employer, self-employed person, and principal to manage the safety and health risks at their workplace. You cannot opt out of it. In plain terms, the regulations ask you to do four things.
- Conduct a risk assessment for every work activity at the workplace.
- Put in control measures to remove or reduce each risk.
- Keep records of the assessment and show them when asked.
- Review the assessment at least once every three years, or sooner if the work changes or after an incident.
The same risk assessment sits at the heart of bizSAFE certification and the ISO 45001 safety management standard. Get the risk assessment right and you have the foundation for both.
The three steps of a risk assessment
A proper risk assessment moves through three steps in order. Do them as a team, with the people who actually do the work in the room.
Hazard identification. Break the job into its main activities. For each one, list everything that could cause harm: machinery, chemicals, working at height, manual handling, electrical, slips and trips, noise, and more. Walk the floor and ask the workers.
Risk evaluation. For each hazard, rate how likely harm is and how severe it would be. Multiply likelihood by severity to get a risk level. This tells you which risks to deal with first.
Risk control. For every risk above an acceptable level, decide the controls using the hierarchy of control. Assign an owner and a date. Then put the controls in place and check they work.
The hierarchy of control
When you choose controls, work from the top of this list down. The controls near the top remove the hazard. The ones near the bottom only protect the worker if everything else holds. Most weak risk assessments jump straight to PPE, which is exactly what an auditor flags.
| Level | Control | Example |
|---|---|---|
| 1 | Elimination | Remove the hazard. Do the work a different way that has no risk. |
| 2 | Substitution | Swap a hazardous material or process for a safer one. |
| 3 | Engineering | Guarding, ventilation, barriers, or safer equipment design. |
| 4 | Administrative | Safe work procedures, training, signage, permits, job rotation. |
| 5 | PPE | Helmets, gloves, harnesses. The last line, not the first. |
How to fill the risk assessment form
The standard risk assessment form is a table. Each row is one hazard for one activity, carried across the columns from hazard to control. Here is what each column means.
- Work activity: the task being assessed, for example "loading goods onto a lorry".
- Hazard: what could cause harm in that task.
- Possible harm: the injury or illness that could result.
- Existing controls: what you already have in place.
- Likelihood, severity, risk level: your scoring before and after controls.
- Additional controls: what more you will do to bring the risk down.
- Action owner and due date: who fixes it, and by when.
We made a clean, ready to use version you can download and adapt. See the free risk assessment template for Singapore, with the columns already set up and a worked example.
Common mistakes that fail an audit
Across hundreds of audits, the same handful of problems come up again and again.
- A generic template that does not match how the work is really done.
- Going straight to "wear PPE" instead of working down the hierarchy of control.
- No worker involvement, so real hazards on the ground get missed.
- Scoring every risk as low to make the form look tidy.
- No record that the controls are actually used, only the paperwork.
- An assessment that was never reviewed after the work or equipment changed.
If you are doing this for certification, our Risk Management plan guide shows how the assessment fits the full bizSAFE audit.
How ZES helps
You work directly with one experienced consultant the whole way, no sales handovers and no juniors. We build the risk assessment with your team, so it reflects your real operations and stands up in an audit. The same assessment then feeds your bizSAFE or ISO 45001 certification. Our bizSAFE Level 3 consultancy starts from $888, with a custom quote based on your size and industry.
Frequently asked questions
Is a risk assessment a legal requirement in Singapore?
Yes. The WSH (Risk Management) Regulations require every employer, self-employed person, and principal to conduct a risk assessment for the work carried out at their workplace, put in control measures, keep records, and review the assessment at least once every three years.
What are the three steps of risk assessment?
Hazard identification, risk evaluation, and risk control. You find the hazards in each work activity, rate how likely and how severe the harm is, then put in controls using the hierarchy of control.
How often must a risk assessment be reviewed?
At least once every three years. You should also review it sooner whenever the work process, equipment, or materials change, or after any incident or near miss.
What is the hierarchy of control?
It is the order in which you choose controls: elimination, substitution, engineering controls, administrative controls, then PPE last. Controls near the top remove the hazard. PPE only protects the worker and should be the final layer, not the first choice.
Who should be involved in a risk assessment?
The people who actually do the work, led by a trained risk assessment team. Workers know the real hazards on the ground, so involving them gives a more accurate assessment and builds the evidence trail auditors look for.
Can ZES do the risk assessment for my company?
Yes. We build the risk assessment with your team so it matches your real operations, and it feeds straight into bizSAFE or ISO 45001 certification. WhatsApp us at 8901 2255 or use our contact page to start.
Get your risk assessment done right
Tell us your industry and headcount, and get a quote and a realistic timeline, free, same day.
bizSAFE Level 3 from $888 + custom quote
One experienced consultant, the whole way. Official audit arranged. Quote based on your size and industry.
WhatsApp us: 8901 2255Prefer email? Leave your details and Nachi replies within one working day:
ZES Consulting · 20+ years · 268+ projects · contact page