- 08 Sep 2026
Companies chasing bizSAFE Level 3 certification in Singapore usually prepare against the wrong document. The WSH Council publishes the exact checklist auditors use, and revision V3.3 took effect on 1 July 2026. This blog walks you through what the auditor checks, how the sampling works, and what to close first, starting from the Level 2 risk management course that qualifies your team leaders.
What is bizSAFE Level 3, and what does the certification actually prove?
bizSAFE Level 3 is the stage of Singapore’s bizSAFE programme where an independent MOM-approved WSH auditor verifies that a company has conducted risk assessments for every work activity and implemented risk controls in line with the WSH (Risk Management) Regulations. Certification follows the auditor’s recommendation, and the audit report stays valid for three years from the audit date.
The reference standards are named on the report cover page. Audits run against the WSH (Risk Management) Regulations and the Code of Practice on Workplace Safety and Health Risk Management. Nothing else. Auditors are not assessing your ISO alignment or your safety culture in the abstract.
Level 3 functions commercially as a gate. Government agencies and most large private buyers set it as a floor for tender eligibility, and regulators use it inside licensing regimes. The National Environment Agency, for instance, builds bizSAFE Level 3 into cleaning business licensing requirements through a dedicated guidebook for cleaning businesses.
Worth being direct about what it does not prove. Level 3 confirms your risk management system existed and functioned on the day it was audited. It says nothing about your incident record. Companies that treat the certificate as a safety outcome rather than a system check tend to be the ones surprised at renewal.
What must be in place before you can book the audit?
Two training prerequisites and one document set. Your CEO or top management must have attended the bizSAFE Level 1 workshop, and your appointed risk assessment team leaders must hold the qualification the checklist specifies.
Question 2.1 is precise about team leader competence. Leaders must have minimally completed the bizSAFE Level 2 risk management course taken after November 2007, or the WSQ Workplace Safety and Health Control Measures course under code WPH-WSH-4075-1.1. Older certificates from before that November 2007 cutoff do not satisfy the requirement, which catches out long-established companies with veteran safety staff.
The document set starts earlier than most companies expect. Question 2.2 requires an inventory of work activities covering routine, non-routine and new activities, and the checklist is explicit that this list should have been developed prior to the risk assessments. The auditor walks the worksite to validate that inventory against what actually happens there.
Sequence matters more than speed. An inventory built after the risk assessments tends to describe the assessments rather than the operation, and the walkthrough exposes that quickly. Teams comfortable with how hazard identification works usually build the inventory first and derive assessments from it. Companies still working through the earlier stages can find Level 2 certification support covers the groundwork this audit assumes is done.
Who is allowed to conduct the audit, and can your consultant do it?
A MOM-approved WSH Auditor from a Singapore Accreditation Council accredited Auditing Organisation. Your consultant cannot audit work they helped you build, and the requirement runs deeper than professional courtesy.
Revision V3.1 in February 2022 added a reviewer field to the report cover page for exactly this reason. The Auditing Organisation must ensure that before issuance, the audit report is approved by a person or committee different from those who carried out the audit, with appropriate competence, based on ISO/IEC 17021-1 Annex A. Independence is enforced twice: once between preparer and auditor, once between auditor and reviewer.
The practical split is worth understanding because it shapes who you hire. A consultancy builds your inventory, risk register, safe work procedures and implementation plan, then runs a pre-audit gap check. An accredited Auditing Organisation then audits it cold. Buying both from one supplier is not available, and any provider suggesting otherwise has misread the accreditation rules.
Scope reduction is negotiable but not guaranteed. Where a company wants part of its operation excluded, that must be communicated to the auditor before the audit commences, and NEA’s guidance notes that the auditor has the discretion to reject the request based on his/her assessment of the whole business function. Ask early, and expect the answer to depend on whether the excluded work is genuinely separable.
What documents does the auditor ask for?
Eight core items, and they map directly to checklist questions rather than to a generic filing structure. The WSH policy, top management’s Level 1 certificate, team leader Level 2 certificates, the inventory of work activities, the risk register, accident and near-miss records, safe work procedures for high-risk activities, and evidence of risk assessment review.
The risk register carries the most weight. Question 3.1 defines it simply as a compilation of risk assessments, and requires it to be readily available and maintained at the workplace. The auditor attaches a photograph of it as evidence. A register that lives only on a consultant’s laptop fails this on availability, regardless of quality.
Accident records do more work here than companies expect. Question 3.2 requires the top three hazards for each work activity to be identified in the risk assessment, including at least one health hazard, and the auditor cross-checks that against your accident, injury, reportable incident and near-miss records. Risk assessments that name only safety hazards fail the health hazard requirement outright.
Safe work procedures are sampled from the top of your risk ratings. Question 4.6 has the auditor pick three high or highest risk work activities from the inventory and ask for the matching SWPs. Companies that write procedures for easy activities and skip the dangerous ones get found in one question. This is the point where building the implementation plan properly pays back.
What does the auditor check, section by section?
Five sections, 23 questions for a new application. Renewals answer 28, because questions 5.2 through 5.6 are flagged as additional questions for renewal applications only.
Section 1 covers policy and holds a single question. The WSH policy must be current, signed by the CEO or top management within the top three tiers, and communicated internally. The auditor interviews three employees to confirm they know where to find it.
Section 2 covers preparation and holds two questions: team leader competence and the inventory of work activities.
Section 3 is the heart of the audit with eleven questions on hazard identification, risk evaluation and risk control. It covers the risk register, top three hazards including a health hazard, the six hazard categories spanning physical, mechanical, electrical, chemical, biological and psychosocial, and risks from terrorism threats, disease outbreaks and mental wellbeing. Question 3.9 checks that controls focus on upstream measures, meaning elimination, substitution and engineering control, and the auditor walks the site to verify those controls physically exist.
Section 4 covers implementation across eight questions, aimed at whether controls left the paperwork. Section 5 covers review, opening with a single question that applies to all applications and adding five renewal-only questions on review triggers.
The renewal split changes how you prepare. A first-time applicant proves the system exists. A renewing company proves it has been maintained across three years, with evidence of reviews after incidents, after significant changes to work practices, and when new information on emerging risks appears. Renewal is the harder audit, and companies that pass comfortably at first application often struggle three years later because nothing was reviewed in between.
How does the auditor sample your records?
In threes, almost without exception. The checklist repeatedly instructs the auditor to check three risk assessments and interview three employees, which makes the sampling method entirely predictable.
The pattern holds across Section 3. Three risk assessments for hazard categories under 3.3. Three for terrorism, disease outbreak and mental wellbeing under 3.4. Three for work organisation factors such as excessive workload, prolonged working hours and inadequate acclimatisation to hot environments under 3.5. Three for personal health risk factors including chronic disease, pregnancy and physical fitness under 3.6. Three for manager approval under 3.11.
Two questions narrow to one record. Question 3.10 checks a single risk assessment for implementation dates and interviews the named implementation person about their deadline. Question 5.4 checks at least one significant change against its corresponding revised assessment.
The preparation implication is straightforward and most companies miss it. Auditors do not read your entire register. They pull a small sample, and a company with forty excellent risk assessments and three weak ones has a real chance of failing on the sample. The cleaner approach is to bring your weakest assessments up to standard rather than polishing your best ones further, which is the same discipline that separates companies genuinely turning assessments into controls from those maintaining a document set.
Who gets interviewed, and what are they asked?
Managers, supervisors, implementation persons, the RM Champion, and ordinary employees. Roughly half the checklist carries an interview component, marked IP in the method column, and employees are interviewed in groups of three.
Employees face verification questions rather than technical ones. Where is the WSH policy. Show me how you access the correct risk assessment on site. What hazards exist at your workstation and what controls are in place. Question 4.7 sends the auditor to a workstation to interview one manager, one supervisor and one worker on how the worker obtains the safe work procedure and uses it during the job.
Managers face accountability questions. Question 4.1 asks the manager directly whether the risk control implementation plan is followed through, and requires a documented process for checking implementation status. Question 4.2 asks implementation persons whether their control measures are actually in place, verified by walking to one completed and one ongoing control.
SGSecure sits inside the interview scope. Question 4.8 requires three employees to explain key SGSecure tenets, and the checklist names the specific responses expected: “Run, Hide, Tell” for an attack and “Press, Tie, Tell” for treating casualties, alongside knowledge of escape routes.
Briefing staff to recite answers backfires. Auditors interview at the workstation and ask people to demonstrate rather than describe, and a worker who can recite the policy location but cannot open the right risk assessment on site produces a finding against question 4.4.
What are the Audit Highlights, and do they affect the result?
Five additional questions covering national WSH priorities, scored separately from the main checklist. They track vehicular safety, machinery safety, slips trips and falls, work at height, and health promotion, and the WSH Council ties them to the National WSH Campaign and the WSH 2028 strategy.
The scoring difference tells you their status. Main checklist questions accept Yes or No. Audit Highlights accept Yes, No or NA, which means an area genuinely outside your operations can be marked not applicable without penalty. A company with no vehicles is not failed for lacking a fatigue management programme.
Content follows current enforcement attention. Vehicular safety asks about driver fatigue management, workplace traffic management, and vehicular safety technology, with the December 2025 revision specifically adding checks for the installation of speed limiters. Machinery safety looks for machine safeguards, presence sensors and a lockout-tagout procedure. Work at height requires a Fall Prevention Plan customised to your actual site rather than a template, plus visible secure anchorage points.
Health promotion is the one companies overlook. The auditor checks for at least one programme managing health risks identified in your risk register, and at least one programme supporting worker health and mental wellbeing. Two programmes, both evidenced, and health screening or health talks satisfy it.
How long does the process take, and what happens after the audit?
Close every finding before you apply. The audit report cover page instructs companies plainly: Do NOT submit the bizSAFE application until all findings are closed.
That sequencing catches people out. The audit is not the final step; the auditor produces a report, records observations, and states whether they recommend the company for bizSAFE Level 3 recognition. Findings must be corrected and closed, then the application goes to the WSH Council. Companies that submit early on the assumption that the Council will process alongside their corrections create avoidable delay.
Realistic preparation runs longer than the audit. The audit itself occupies a day for most SMEs, covering document review, site walkthrough and interviews. Building the inventory, register, procedures and implementation evidence from a standing start takes considerably longer, and the binding constraint is usually implementation evidence, since question 4.3 asks for records showing controls were assessed after implementation. That evidence cannot be created retrospectively in a week.
Validity runs three years from the audit date, autofilled on the cover page. Renewal then faces the five additional review questions, which is why maintaining review records through the three years matters more than the initial push.
Two other cover page fields deserve attention. The auditor records whether previous non-conformities were effectively corrected, and whether any significant change has affected the management system since the last audit. Both are renewal traps for companies that changed operations without revisiting their assessments. The broader documentation discipline behind general audit preparation applies here, and companies wanting the gap check before booking an accredited auditor can arrange bizSAFE consultancy support separately from the audit itself.
The checklist is public, so prepare against it
Singapore runs bizSAFE Level 3 as an open-book assessment. The WSH Council publishes the exact instrument, complete with the guidance auditors follow, the evidence they attach, and the sample sizes they pull. Companies still fail because they prepare against a general idea of safety rather than against 23 numbered questions, and because they polish strong records while weak ones sit in the same sample pool.
Run a gap check against the V3.3 checklist before you book an accredited auditor: team leader certificate dates against the November 2007 cutoff, health hazards in every work activity, safe work procedures for your three highest-risk activities, and post-implementation evidence for controls already in place. Advanced Safe Consultants can tell you which questions your current documentation would fail.
FAQs About BizSAFE Level 3 Certification Singapore
How long is bizSAFE Level 3 certification valid in Singapore?
Three years from the audit date. The WSH Council audit report cover page autofills the expiry as three years from the date of audit. Renewal requires a fresh Risk Management audit by a MOM-approved WSH Auditor, answering 28 questions rather than the 23 that apply to new applications.
What changed in the bizSAFE Level 3 audit checklist for 2026?
Revision V3.3 took effect 1 July 2026, adding auditor guidance on speed limiter verification under Vehicular Safety. The preceding V3.2 revision in December 2025 removed the Safe Management Measures question entirely and introduced the original speed limiter checks. Download the current version from the WSH Council before preparing.
Can you apply for bizSAFE Level 3 without completing Levels 1 and 2?
No, because the Level 3 checklist audits them directly. Question 1.1 requires evidence that the CEO or top management attended the bizSAFE Level 1 workshop, and question 2.1 requires risk assessment team leaders to hold the bizSAFE Level 2 course certificate dated after November 2007, or the WSQ course WPH-WSH-4075-1.1.
How many risk assessments will the auditor actually look at?
Three for most document review questions. The checklist repeatedly instructs the auditor to check three risk assessments for hazard categories, work organisation factors, personal health risk factors and manager approval. Questions 3.10 and 5.4 narrow to a single assessment, and question 4.6 samples safe work procedures for three high-risk activities.
Does a company need vehicles or machinery to pass the Audit Highlights?
No. Audit Highlights are scored Yes, No or NA, unlike the main checklist which accepts only Yes or No. A company with no vehicles marks vehicular safety as not applicable. Health promotion applies to every organisation, requiring at least one health risk programme and one wellbeing programme.


