- 08 Sep 2026
bizSAFE Level 3 audit preparation in Singapore means assembling the evidence a MOM-approved WSH Auditor reviews against the WSH (Risk Management) Regulations, in the order the WSH Council’s audit checklist sets out. That checklist moved to Revision V3.3 on 1 July 2026. This blog walks you through the document order, starting with the Level 2 risk management course that certifies your team leader.
What is the bizSAFE Level 3 audit actually checking?
The audit checks whether your company has assessed the risk of every work activity and implemented the controls it wrote down. Nothing wider. It is a Risk Management audit, assessed against two reference documents named on the report cover page: the WSH (Risk Management) Regulations and the Code of Practice on WSH Risk Management.
This is narrower than the general safety inspection most managers picture. A MOM inspector arriving unannounced will work through wider MOM audit expectations covering permits, machinery, emergency response and housekeeping. A bizSAFE Level 3 auditor follows a fixed checklist and samples evidence against each question on it. The checklist codes three methods against every question: document review, interview personnel, physical inspection. Nineteen of the twenty-eight main questions use at least two.
The auditor must hold MOM approval as a WSH Auditor and work through an Auditing Organisation accredited by the Singapore Accreditation Council. Advanced Safe Consultants prepares companies for that audit and does not conduct it. Any provider offering to both prepare you and award your Level 3 status is describing an arrangement the accreditation framework does not permit.
Which version of the RM audit checklist applies to your audit in 2026?
Revision V3.3, with effect from 1 July 2026. The WSH Council published it on 30 June 2026, and the file itself is dated 20260701. If your consultant handed you a checklist labelled V3.2, January 2026 or Revision 2020, the document set they built for you is out of date at the edges.
V3.3 contains 28 main audit questions across five sections, 5 Audit Highlights, and an interview sheet with 22 reference points tied back to specific questions. Section 3, covering hazard identification, risk evaluation and risk control, carries 11 of the 28 questions on its own. That single section decides roughly 39% of the audit.
Two changes matter for preparation. The December 2025 revision (V3.2) removed the Audit Highlight question on Safe Management Measures entirely, so the SMM folder many companies still maintain for audit purposes now has no question attached to it. The May 2026 revision (V3.3) added auditor guidance on verifying speed limiter installation under the vehicular safety highlight. Companies running lorries should expect that check.
Which documents does a bizSAFE auditor ask for first?
The WSH policy, then the competency certificates, then the inventory of work activities. The checklist runs in a fixed sequence and auditors work it in order, so your file structure should mirror it rather than fight it.
Section 1 is a single question about policy. Section 2 has two: RM team leader competency, and the inventory of work activities. Section 3 opens with the risk register. By the time an auditor reaches Section 4, they have already formed a view of whether your paperwork was built as a system or assembled the week before.
In practice, the companies that clear the audit on the first pass organise their evidence into five folders named after the five checklist sections, with the question number on every document. The companies that struggle hand over one binder labelled “bizSAFE” and let the auditor hunt. A structured evidence trail changes the audit from a search into a verification, and verification is faster.
Who signs the WSH policy, and what else does that one question check?
The current CEO or a member of top management within the top three tiers of the organisation. Question 1.1 checks the signature is current, that the policy is communicated, and that the CEO or top management attended the bizSAFE Level 1 workshop.
The signature trips up more companies than any other single item. A policy signed by a managing director who left in 2023 fails the question outright, regardless of how good the rest of the system is. Check the name against your current ACRA record before the auditor arrives.
Question 1.1 also carries an interview component. The auditor speaks to three employees and asks where they retrieve the policy and what it means to them. A framed policy in reception satisfies nobody if the three people sampled cannot say where to find it or what it commits the company to. Brief the floor, not just the office.
What proof of RM team leader competency does the auditor accept?
A bizSAFE Level 2 certificate issued after November 2007, a WSQ Develop Risk Management Implementation Plan certificate, or a WSQ Workplace Safety and Health Control Measures certificate. Question 2.1 asks whether the appointed team leaders are competent, and competency here is documentary.
This is where the appointment letter matters. A certificate proves training. An appointment letter proves the trained person actually holds the RM role. Companies routinely send a supervisor for training and never formalise the appointment, which leaves the auditor with half an answer. Guidance on choosing the RM Champion removes the problem before it starts.
The bizSAFE Level 2 course at Advanced Safe Consultants runs 2 days, 16 hours of classroom time under course code TGS-2024052143, at $320 before GST and from $124.80 after subsidies for eligible SMEs. Participants must reach 100% competency in both the written and case study components to receive the Statement of Attainment.
What is the difference between the inventory of work activities and the risk register?
The inventory is the list of every work activity in the company. The risk register is the compilation of risk assessments covering those activities. Question 2.2 asks for the first, Question 3.1 asks for the second, and they are separate submissions.
The inventory must cover routine, non-routine and new work activities. The checklist tells the auditor to walk the worksite and validate the inventory against what is actually happening, so an inventory that lists eleven activities on a site running seventeen fails on physical inspection rather than document review. Building the RM plan properly starts with getting this list exhaustive.
Question 3.1 asks whether the register is readily available and maintained at the workplace, and requires the auditor to attach a photograph of it. A register living only on a consultant’s laptop does not meet that test. Keep a controlled copy on site, with a version number and a review date on the front sheet.
How many risk assessments does the auditor actually sample?
Three, for most questions. The checklist repeats the number relentlessly: check 3 RAs for hazard categories, 3 RAs for terrorism and mental well-being considerations, 3 RAs for work organisation factors, 3 RAs for personal health-risk factors, 3 RAs for upstream control, 3 SWPs for the highest-risk activities, 3 employees for awareness.
That three-sample pattern changes what preparation means. You are not preparing 200 risk assessments to the same standard. You are making sure that any three the auditor pulls will hold, which in practice means your worst risk assessment sets your result. Audit your own file for the weakest three before someone else does.
Question 3.2 adds a specific trap: the top three hazards for each work activity must include at least one health hazard. Physical hazards get listed. Noise, heat strain, chemical exposure and manual handling strain get forgotten. Understanding how HIRADC runs daily is what stops health hazards from dropping out of the register between reviews.
Question 3.11 catches another. Completed risk assessments must be approved by the Manager of the work activity, defined in the checklist as the person managing the physical area, the function or the activity. A warehouse manager signs off warehouse activities. The RM Champion signing everything is a finding.
What evidence shows risk controls were implemented, not just written?
Post-implementation records, an implementation plan with named persons and due dates, and physical evidence the auditor can photograph on the walkthrough. Section 4 carries eight questions and every one of them combines document review with either interview or physical inspection.
Question 3.10 requires each risk control measure to name an implementation person and a due date. Question 4.2 then interviews three of those named persons about their plan. A control measure column reading “supervisor to monitor” with no name and no date fails both.
Question 4.3 goes further and asks whether the controls were effective in reducing injury risk. The evidence the checklist wants is accident and injury records from before and after implementation. Companies with zero incidents in both periods need a different proof, usually a post-implementation review record or a monitoring log. Prepare that document deliberately rather than hoping the question is skipped.
Question 3.9 sets the standard for the controls themselves: elimination, substitution and engineering control. Risk assessments that lean on PPE issuance records and toolbox meeting records as primary controls read as weak, because administrative and PPE controls sit at the bottom of the hierarchy. Keep the PPE records, but do not let them carry the argument. Speaking at the National WSH Campaign launch on 15 May 2026, WSH Council Chairman Abu Bakar Mohd Nor said companies must go “go beyond systems and processes”, which is the same point an auditor makes when they walk your floor.
Which documents does a renewal audit need that a new application does not?
Five of the six Section 5 questions. Only Question 5.1, on whether a review procedure exists, applies to every application. Questions 5.2 through 5.6 are labelled additional questions for renewal, and this split is missing from almost every published bizSAFE document list.
For renewals, the auditor wants: meeting minutes showing risk assessments were reviewed and approved within the last three years, evidence that risk assessments were revised after any bodily injury caused by workplace hazard exposure, a record of at least one significant change in work practice with the corresponding revision, evidence of new WSH information sources and their impact on at least one risk assessment, and communication records showing changes were consulted on across functions and levels.
First-time applicants preparing all six waste weeks building records they cannot have. Renewing companies preparing only Question 5.1 walk into five open findings. Corrective action tracking, meeting minutes and briefing records are the three sets renewals underestimate most, and the ones that take longest to reconstruct after the fact. This is the point where risk management consultancy support usually pays for itself.
What do the five Audit Highlights require you to have on site?
Vehicular safety, machinery safety, slips trips and falls, work at height, and health promotion. Each highlight asks whether the company manages that risk area, and each is verified through document review, physical inspection and interview together.
The evidence each one expects is specific. Vehicular safety looks for a driver fatigue management programme, traffic management inside the workplace, vehicular safety technology, and since the December 2025 revision, speed limiter installation records. Machinery safety looks for machine safeguards and a Lock-out Tag-out procedure, with workers able to explain what LOTO is for. Slips, trips and falls looks for housekeeping control and a regular inspection and replacement regime for company-issued safety footwear. Work at height looks for a Fall Prevention Plan customised to the actual site, plus secure anchorage points the auditor can see. Health promotion requires at least two programmes: one addressing a health risk named in your risk register, and one supporting well-being.
The weighting is not arbitrary. MOM’s Workplace Safety and Health Report 2025, released 25 March 2026, recorded 36 workplace fatalities at a rate of 0.96 per 100,000 workers, with vehicular incidents, falls from height and collapse or failure of structures accounting for 78% of them, 28 deaths in total. Three of the five Audit Highlights map directly onto those three causes.
That last highlight links back to Question 3.2. If no health hazard appears in your risk register, you cannot show a programme managing it, and two questions fail from one root cause.
Who gets interviewed, and what are they asked?
Employees, managers, supervisors, workers, the RM team and top management. The interview sheet in V3.3 carries 22 reference points, and seventeen of them tie to main checklist questions while five tie to the Audit Highlights.
The questions are plain. Where do you retrieve the policy. Tell me about the accident that happened on this work activity. How do you determine severity and likelihood. Are you aware of your appointment and the deadline for implementation. Can you show me the risk assessment for your work activity. Where do you hook your safety harness.
Two catch companies out. Question 4.8 asks employees to explain the SGSecure tenets, Run Hide Tell and Press Tie Tell, and to describe the terror threat scenario the company has planned for. Audit Highlight 1 asks drivers about rewards and performance incentives, which is a question about whether your incentive structure quietly encourages speeding.
Interview preparation is not coaching answers. It is making sure the three people sampled have genuinely been briefed, because an auditor who hears a rehearsed script and then sees no matching briefing record has found a documentation gap rather than a competent workforce. At the WSH Awards 2025 on 24 September 2025, Minister of State for Manpower Dinesh Vasu Dash said MOM and the WSH Council were reviewing how bizSAFE could become “even more effective and reflective of good WSH performance.” Interviews are where that shift shows up first.
Getting the document set in the right order
The bizSAFE Level 3 audit rewards companies whose evidence is organised the way the auditor reads it, and penalises companies whose weakest three risk assessments are the three that get pulled. Revision V3.3 tightened the vehicular safety checks, dropped Safe Management Measures, and left the new-versus-renewal split that most published document lists still blur. The certificate that follows is valid for three years from the audit date, which makes the file you build now the file you defend until 2029.
Book a pre-audit gap analysis with Advanced Safe Consultants to have your risk register, inventory and Section 5 records checked against Revision V3.3 before you engage an Auditing Organisation.
FAQs About BizSAFE Level 3 Audit Preparation Singapore
How long is bizSAFE Level 3 certification valid?
Three years from the date of the audit, stated on the cover page of the Risk Management audit report. The WSH Council also expects risk assessments to be reviewed at least once every three years under the WSH (Risk Management) Regulations, which lines the two cycles up. Start renewal preparation at month 30.
Can my usual safety consultant carry out the bizSAFE Level 3 audit?
Only if they are a MOM-approved WSH Auditor working through an Auditing Organisation accredited by the Singapore Accreditation Council. Consultancies like Advanced Safe Consultants prepare the documentation, run gap analysis and conduct pre-audit checks, then hand over to an independent Auditing Organisation for the audit itself.
Do I still need Safe Management Measures documents for a bizSAFE audit?
No. The December 2025 revision of the Risk Management Audit Checklist removed the Audit Highlight question on Safe Management Measures. Revision V3.3, effective 1 July 2026, carries five Audit Highlights covering vehicular safety, machinery safety, slips trips and falls, work at height, and health promotion.
How long does bizSAFE Level 3 take from a standing start?
Between one and three months for most companies, assuming risk assessments and control implementation are already in place. The time goes into the inventory of work activities, the risk register and the implementation evidence. Companies with no existing risk assessments should plan for longer.
How many risk assessments will the auditor check?
Three per question, in most cases. Revision V3.3 repeatedly instructs the auditor to sample three risk assessments, three safe work procedures and three employees. Your weakest three risk assessments effectively set the audit result, so review the file for the poorest examples before submission.


