What should exist in writing — and how to test it
Written by Nicolai Bjerknes Slinning, Founder, Sydera.io Technologies AS · Working Group Expert, ISO/TC 283/WG 6 and WG 10 · member of SN/K 551. Last reviewed .
A checklist only helps if it tests whether a document governs something, not merely whether it exists. Here are the items usually asked for in an occupational health and safety management system, what is good enough, and the four questions that decide whether the text holds.
The items usually asked for
Objectives for the working environment. An overview of organisation, responsibility, tasks and authority. Hazard identification and risk assessment, psychosocial conditions included. Plans and measures that follow from the assessment. A process for raising, correcting and preventing non-conformities. Systematic monitoring and review of the system itself. Documented worker participation. Where an organisation is certified, the certification standard's own documentation requirements apply in addition.
The four questions that decide
For each document: who owns this, by named role? What triggers the action — does something happen on its own, or only once a person takes the initiative and explains themselves? Where is the evidence left when something happens? And when was the text last reviewed, with a note of what changed? A document that answers all four governs something. A document that answers none describes intentions.
The data protection check in the same pass
Read each document with this question too: does the text require someone to record something about a person's health for the arrangement to work? Where the answer is yes, it is worth seeing whether the measure can move to system level, where nobody has to disclose anything. At the same time, check whether forms have open free-text fields with no limit, and whether the text says who has access and how long anything is kept.
What is good enough for a small organisation
Four to six pages plus a handful of routines can cover what is required in writing. Objectives can be three sentences. Responsibility can be a table with names. The assessment can be twelve points taken from your own working week. The non-conformity routine can be one paragraph covering reporting, follow-up and closure. Short and true governs more than long and generic.
The most common gaps
The non-conformity routine has no closure. The review has no date. Responsibility is written to “management”. Psychosocial conditions appear as an intention with no arrangement behind them. And the document was taken from another industry, so the hazards it describes do not exist here.
Test one document free of charge
Send one governance document. We read it against relevant legal requirements and give up to three areas for improvement with one suggested rewrite. For the management system as a whole there is the Sydera HSE review, which tests the documents as a single whole against control points with clause and date, without personal data.
One governance document reviewed free of charge. We read the document, never employees. The document must not contain personal data.
Sources
Frequently asked questions
- How much documentation is enough?
- Enough for an outsider to read what has been decided, who owns it, how it is triggered and what changed last time. The volume follows risk and size, not ambition.
- Do we need a separate document for psychosocial conditions?
- No. It belongs in the same system as the rest of the working environment work. A parallel document creates two versions of the same truth.
- Is it enough to keep routines in a digital system?
- Yes, the format is open as long as the content can be retrieved and read. What counts is that responsibility, triggering, non-conformities and review exist and leave evidence.
- How often should the system be reviewed?
- On significant changes, and otherwise at least once a year. What matters most is that the review leaves a note of what changed.
- Can we use a template from the internet?
- As a starting point for structure, yes. But a template describes another organisation's risk. The points have to be rewritten to your own working week, or the document governs nothing.