bizSAFE Star Requirements: The ISO 45001 Condition

  • 08 Sep 2026
bizSAFE Star Requirements: The ISO 45001 Condition

bizSAFE Star requirements in Singapore come down to two documents, and one of them controls everything. The WSH Council’s supporting documents list, updated December 2025, asks for a Risk Management Implementation Audit Report and an accredited ISO 45001:2018 or SS 651:2019 certificate. This blog walks you through that condition, starting with the risk management implementation training the ladder is built on.

What does bizSAFE Star actually require?

Two documents, both issued in your company’s name. A Risk Management Implementation Audit Report from an accredited Auditing Organisation, and an ISO 45001:2018 or SS 651:2019 certificate awarded by a certification body accredited by the Singapore Accreditation Council or by an accreditation body recognised under a Mutual Recognition Arrangement.

That is the entire documentary requirement, set out in the Council’s supporting documents list. No course certificate, no Statement of Attainment, no separate application fee. Applying for bizSAFE at any level is free, and the Council processes applications in 10 working days.

The brevity is misleading. One of those two documents is a certified management system that takes most companies 9 to 18 months to build and certify, and the other is an audit against a checklist your ISO 45001 auditor never looked at. bizSAFE Star is the shortest requirement list in the programme and the longest project behind it.

Star sits at the top of a five-level structure covering roughly 43,000 bizSAFE-recognised companies in Singapore. The number holding Star is a small fraction of that, and the ISO 45001 condition is why.

What does bizSAFE Star actually require?

Does an ISO 45001 certificate alone get you bizSAFE Star?

No. You still need a current Risk Management Implementation Audit Report from an Auditing Organisation registered with MOM, submitted alongside the ISO 45001 certificate. Companies holding ISO 45001 routinely assume the bizSAFE application is a formality and discover the second requirement late.

The WSH Council addresses this directly in its bizSAFE guidance, because the question comes up constantly from certified companies. Its answer is that the Risk Management Implementation Audit focuses on the Code of Practice on WSH Risk Management, which “has additional coverage on addressing risks from terrorism, disease outbreaks and mental health.”

Those three areas are the gap. ISO 45001:2018 requires hazard identification and risk assessment, but it does not specifically require you to assess terrorism threats, infectious disease transmission, or mental well-being as hazard categories. The bizSAFE Level 3 Risk Management Audit Checklist does, at Question 3.4, and it tests employee awareness of SGSecure tenets at Question 4.8.

Budget for a separate audit on a separate timeline with a separate auditor. Understanding what safety auditors check under the RM checklist is the difference between a two-week application and a three-month one.

Does an ISO 45001 certificate alone get you bizSAFE Star?

Is bizSAFE Level 4 a prerequisite for Star?

No, and this is where published guidance gets it wrong. The WSH Council’s supporting documents list sets out what each level requires, and the Star row names only the audit report and the accredited certificate. No Level 4 document appears.

The Council also states that although bizSAFE is structured as a five-step programme, a company may apply for a level directly as long as it meets that level’s requirements. Read together, a company holding accredited ISO 45001 and a current RM audit report can apply for Star without ever having held Level 4.

Several widely-read guides state that Level 4 is required before Star. Check the Council’s own document list before you spend on a four-day WSHMS course you do not need for this purpose.

Worth noting: Level 4 remains valuable on its own terms. It requires a WSQ Statement of Attainment for Develop a WSHMS Implementation Plan under course code MF-COM-403E-1 or WPH-WSH-4086-1.1, and it trains the person who will run your management system. The risk management foundation underneath it comes from building the RM plan at Level 2, which every level above still rests on. The distinction is between useful and mandatory.

Does your ISO 45001 certificate actually qualify?

Only if the certification body that issued it is accredited by the Singapore Accreditation Council, or accredited by a body recognised under a Mutual Recognition Arrangement. An ISO 45001 certificate from an unaccredited certification body does not qualify, regardless of how the certificate looks.

The Council set this boundary explicitly in its requirements for bizSAFE Level 3, 4 and STAR, stating it will not accept OHSAS 18001 or non-accredited ISO 45001 certification approved after 31 March 2021. OHSAS 18001 was withdrawn internationally in March 2021 after a three-year migration window, so a company still holding it has a certificate that no longer exists as a live standard.

Check the accreditation mark on your certificate, not the certification body’s marketing. Unaccredited certificate mills operate in this market and their output is worthless for bizSAFE purposes, for most tender prequalification, and for the client audits that follow.

Where this breaks down in practice is companies that certified years ago through a body that has since lost accreditation. The certificate in your file says ISO 45001:2018. The accreditation behind it has lapsed. Verify current status before you build an application around it.

Can you use SS 651 instead of ISO 45001?

Only if you operate in the chemical industry. SS 651 is the Singapore Standard for safety and health management systems for the chemical industry, and the WSH Council lists it alongside SS ISO 45001 and SS 679 as an industry standard rather than a general alternative.

This gets misreported. Several guides present SS 651 as an interchangeable option for any company that prefers a local standard, which sends chemical-sector language to logistics operators and facilities managers who cannot use it. SS 679:2021 covers workplace safety and health management systems for construction worksites and does not appear on the Star document list at all.

A second correction is worth making. Pages published as recently as mid-2026 still name SS 506 as the Star standard. The Council’s December 2025 supporting documents list names ISO 45001:2018 and SS 651:2019. If your consultant is quoting SS 506, they are working from a superseded reference.

For a Jurong Island process operator or a Tuas chemical manufacturer, SS 651:2019 is a genuine route. For everyone else, ISO 45001:2018 is the only practical path to Star.

How long does bizSAFE Star last?

As long as your ISO 45001 certificate does, and no longer. The WSH Council sets Star validity as aligned to the ISO 45001 certificate expiry date, and its validity table applies three years or the expiry of the relevant external certification, whichever comes earlier.

Two clocks run against each other. The RM audit report carries its own life of three years from the date of audit. The ISO 45001 certificate runs on its own cycle, typically three years with annual surveillance audits. Star dies when the first of the two dies.

The arithmetic catches companies out. A company that certifies to ISO 45001 in January, then takes 14 months to complete its RM audit and apply, receives a Star status with roughly 22 months left on it. The bizSAFE certificate looks new and expires early.

Align the two deliberately. Schedule the RM audit close to your ISO 45001 recertification rather than in the middle of the cycle, and your Star status runs a full term instead of a partial one.

What is the difference between bizSAFE Star and Level 4?

Level 4 proves your people can build a management system. Star proves an accredited certification body found one already running. Level 4 is a capability level, Star is an outcome level, and the documents show it.

Level 4 requires a Risk Management Implementation Audit Report plus a WSQ Statement of Attainment for Develop a WSHMS Implementation Plan, issued in an attendee’s name. Star requires the same audit report plus a certified management system, issued in the company’s name.

Validity differs as sharply. Level 4 runs three years from the date of approval. Star runs to the ISO 45001 expiry date. A Level 4 certificate survives your WSHMS Champion resigning. A Star certificate does not survive your certification lapsing.

The practical read is that Level 4 is a staging post and Star is a commitment. Companies that reach Level 4 and stop have a trained programme lead and a plan. Companies that reach Star have committed to surveillance audits, management review cycles and an internal audit programme that continue every year, not every third year.

Who actually needs to be at Star rather than Level 3?

Companies whose clients or regulators already require a certified management system, and companies operating in the workplace categories where MOM mandates periodic SHMS audits. For most SMEs, Level 3 is the right ceiling.

MOM requires an SAC-accredited WSH Auditing Organisation or MOM-approved auditor to audit the safety and health management system in specific workplaces. Any worksite with a contract sum of $30 million or more must be audited at least once every 6 months. Any shipyard employing 200 or more people falls under a 12-month cycle. Factories processing petroleum or petrochemicals, premises storing 5,000 or more cubic metres of toxic or flammable liquids, and factories manufacturing pharmaceutical products or semiconductor wafers sit on a 24-month cycle.

A company already paying for mandatory SHMS audits at those intervals has most of the ISO 45001 infrastructure in place. For that company Star is a reasonable next step. A 25-person facilities contractor with no mandatory audit obligation is buying a certification cycle it will struggle to maintain.

The stance here is straightforward. Pursue Star when a named client, tender condition or regulation requires it. Pursuing it for positioning alone produces a lapsed certificate in three years and a worse market signal than holding Level 3 continuously. WSH consultancy and audit support is worth engaging at the decision stage rather than after the commitment.

What does the certified system have to demonstrate?

Operation, not documentation. ISO 45001:2018 auditors and RM auditors both test whether the system runs, and the two most common failure points are the management review and the internal audit programme.

The management review is where top management examines WSH performance, objectives, incident data, audit results and improvement opportunities on a defined cycle, and records decisions. A review that happened once, eighteen months ago, in a meeting with no minutes, fails. The internal audit programme has to cover the whole system across the cycle, with trained internal auditors and documented findings that were actually closed.

The RM audit layers its own operational tests on top. Question 4.3 asks whether risk controls were effective in reducing injury risk, evidenced by accident and injury records before and after implementation. Question 5.6 asks for communication and consultation records showing changes to risk assessments reached different functions and levels. Keeping HIRADC in daily operations rather than in an annual file is what makes those answers available.

Your WSHMS Champion carries this. Appoint someone with the authority to convene a management review, not someone who can only compile documents for one.

What breaks a bizSAFE Star application most often?

A mismatch between the scope of the ISO 45001 certificate and the scope of the company applying. The certificate covers one site or one business unit, the bizSAFE application covers the whole UEN, and the two do not reconcile.

Scope statements on ISO 45001 certificates are precise and often narrower than companies remember. A certificate scoped to “provision of mechanical and electrical installation services at the Tuas facility” does not cover a company that also runs a logistics arm. The RM audit, by contrast, samples the inventory of work activities across the operations the auditor can see.

Two other failures recur. Certificates issued to a related entity with a different UEN, since bizSAFE applications are tagged to the UEN and cannot be transferred. And RM audit reports with open findings, since the audit report template instructs applicants not to submit until all findings are closed.

Speaking at the WSH Awards on 24 September 2025, Minister of State for Manpower Dinesh Vasu Dash said MOM and the WSH Council were studying how bizSAFE could place more emphasis on the “adoption of progressive WSH practices.” Star already sits at that end of the programme, and applications are read accordingly. Choosing a WSH consultancy that has taken companies through both an ISO 45001 certification cycle and an RM audit removes most of these failures before submission.

Check the certificate before you plan the project

bizSAFE Star has the shortest requirement list in the programme and the least forgiving one. Your ISO 45001 certificate decides three separate things: whether you qualify at all, whether the issuing body’s accreditation makes it count, and when your Star status expires. The Risk Management audit sits beside it covering terrorism, disease outbreak and mental health ground that ISO 45001 does not specifically reach. Get the certificate verified first, then plan backwards from its expiry date.

Book a Star readiness assessment with Advanced Safe Consultants to have your ISO 45001 scope, accreditation status and Risk Management documentation checked against the current requirements before you apply.

FAQs About BizSAFE Star Requirements Singapore 

Does bizSAFE Star replace my mandatory SHMS audit?

No. The mandatory SHMS audit obligation comes from the WSH (Safety and Health Management System and Auditing) Regulations and applies by workplace type, such as every 6 months for worksites with a contract sum of $30 million or more. bizSAFE Star recognition is separate and does not exempt you from it.

What happens to bizSAFE Star if my ISO 45001 certificate is suspended?

Star status is tied to that certificate. The WSH Council aligns Star validity to the ISO 45001 expiry date, so a suspended or withdrawn certificate removes the basis for your recognition. Restore the certification first, then approach the Council with current documentation.

Can I go straight from bizSAFE Level 3 to Star?

Yes. The WSH Council states that a company may apply for a level directly as long as it meets that level’s requirements, and the Star requirements list only a Risk Management Implementation Audit Report and an accredited ISO 45001:2018 or SS 651:2019 certificate. Level 4 is not a documentary prerequisite.

Is OHSAS 18001 still accepted for bizSAFE Star?

No. The WSH Council stated it would not accept OHSAS 18001 or non-accredited ISO 45001 certification approved after 31 March 2021. OHSAS 18001 was withdrawn internationally in March 2021, so companies still holding it need to migrate to ISO 45001:2018 through an accredited certification body.

Does bizSAFE Star need renewing every three years?

Not on a fixed three-year cycle. Star validity follows your ISO 45001 certificate expiry date, capped at three years, whichever falls earlier. Submit the renewal application two months before that date with a current Risk Management Implementation Audit Report and your renewed certificate.

Related Blogs