Consequential Amendments to Seven Queensland Codes of Practice

Queensland businesses should be aware of important updates to seven Work Health and Safety (WHS) Codes of Practice taking effect from 1 September 2026.

The amendments affect the following Codes of Practice:

  • Managing the risk of psychosocial hazards at work Code of Practice 2022
  • Managing noise and preventing hearing loss at work Code of Practice 2021
  • Safe design of structures Code of Practice 2021
  • How to manage work health and safety risks Code of Practice 2021
  • Confined spaces Code of Practice 2021
  • Managing the work environment and facilities Code of Practice 2021
  • Managing risks of plant in the workplace Code of Practice 2021

WorkSafe Queensland describes these as consequential amendments. They are intended to ensure the Codes remain consistent with changes to Queensland’s WHS legislative framework. The amended Codes commence on 1 September 2026.

What Are Consequential Amendments?

Consequential amendments are changes made to supporting documents, such as Codes of Practice, because the underlying legislation has changed.

Importantly, this does not necessarily mean that every amendment creates a new WHS obligation. Rather, the purpose is generally to ensure that the guidance provided to businesses reflects the current legislation, terminology, processes and requirements.

This distinction is important for businesses reviewing their WHS systems. A Code of Practice is not legislation itself, but an approved Code can be highly relevant to compliance. Codes may be admissible in court proceedings and may be relied upon when determining what is known about a hazard, risk or control and what is reasonably practicable in the circumstances.

1. Managing The Risk Of Psychosocial Hazards At Work

The most significant targeted change is to the Managing the risk of psychosocial hazards at work Code of Practice 2022.

WorkSafe Queensland confirms that the Code has been amended to reflect updated processes and timeframes for dispute and issue resolution, together with amendments relating to sexual harassment provisions. These changes take effect from 1 September 2026.

This is particularly relevant because psychosocial hazards can arise from the way work is designed, organised and managed, as well as workplace interactions and behaviours.

The Code already provides guidance on hazards including:

  • high or low job demands
  • low job control
  • poor support
  • poor organisational change management
  • poor workplace relationships
  • bullying
  • harassment, including sexual harassment
  • violence and aggression
  • remote or isolated work
  • traumatic events.

The updated provisions reinforce the need for businesses to have appropriate mechanisms for responding to concerns, complaints and disputes involving psychosocial hazards.

For employers, this means that it is timely to review not only the psychosocial risk assessment process but also the complaints, issue-resolution and workplace behaviour procedures that support it.

2. Managing Noise And Preventing Hearing Loss At Work

The Managing noise and preventing hearing loss at work Code of Practice 2021 has also been consequentially amended.

The Code provides practical guidance on identifying hazardous noise, assessing exposure and implementing controls to prevent hearing loss. It also addresses audiometric testing, personal protective equipment and the responsibilities of designers, manufacturers, importers, suppliers and installers of plant.

For businesses, the amendment is an important reminder that noise management should not be treated simply as a matter of providing hearing protection.

The Code continues to emphasise the hierarchy of controls and the importance of considering noise at its source. Where workers are required to use hearing protection because their work exceeds the noise exposure standard, specific requirements apply to audiometric testing.

Businesses should therefore take the opportunity to review:

  • noise risk assessments
  • noise monitoring arrangements
  • engineering and other higher-order controls
  • hearing protection programs
  • audiometric testing arrangements
  • worker consultation and training
  • information provided with noisy plant and equipment.

3. Safe Design Of Structures

The Safe design of structures Code of Practice 2021 is another Code affected by the consequential amendments.

Safe design is particularly important because decisions made during the design stage can eliminate or reduce risks long before workers encounter them.

The Code applies to people involved in designing structures and is also relevant to clients, developers, builders and others whose decisions influence design outcomes.

The current Code takes a lifecycle approach to safety. Designers are expected to consider risks associated with construction, use, maintenance, modification and eventual demolition or dismantling.

The Code also recognises that safe design should consider both physical and psychosocial hazards. For example, design decisions may influence workplace violence, worker accommodation, access, environmental conditions and the way work is performed.

For designers and organisations commissioning design work, the amendments provide an opportunity to ensure that WHS considerations are being incorporated into design briefs, design reviews and information transferred between designers, clients and construction teams.

4. How To Manage Work Health And Safety Risks

The How to manage work health and safety risks Code of Practice 2021 is the foundation for the WHS risk-management process.

The Code applies across workplaces and provides guidance on identifying hazards, assessing risks where necessary, controlling risks and reviewing control measures. It also recognises that risks can be physical, psychological or both.

One of the important practical messages is that the risk-management process is not limited to traditional physical hazards.

For example, workplace hazards may arise from:

  • equipment and machinery
  • noise
  • hazardous chemicals
  • manual tasks
  • work design
  • high job demands
  • bullying and harassment
  • violence and aggression
  • workplace interactions and behaviours.

The Code also reinforces the importance of worker consultation and the need to consider psychosocial risks as part of the broader risk-management framework.

Businesses should therefore avoid treating risk assessments as static documents. Risk-management processes should be reviewed when work changes, new equipment is introduced, incidents occur, controls are found to be ineffective or workers identify new hazards.

5. Confined Spaces

The Confined spaces Code of Practice 2021 has also been updated as part of the consequential amendments.

Confined-space work remains a high-risk activity because conditions can change quickly and hazards may not always be obvious. Risks can include oxygen deficiency, airborne contaminants, fire or explosion, engulfment, falls and difficulties associated with rescue.

The Code requires a systematic approach to managing these risks, including identifying hazards, assessing risks where required, eliminating risks where reasonably practicable and implementing effective controls.

The Code also highlights the importance of design. Designers, manufacturers, importers, suppliers, installers and constructors have duties relating to structures or plant that contain, or may become, confined spaces. Where reasonably practicable, the need for entry should be eliminated and the risk of inadvertent entry should be addressed.

Businesses undertaking confined-space work should use the amended Code as an opportunity to review:

  • confined-space registers
  • risk assessments
  • entry permits
  • isolation procedures
  • atmospheric monitoring
  • communication systems
  • emergency and rescue arrangements
  • training and competency
  • consultation with workers and other duty holders.

6. Managing The Work Environment And Facilities

The Managing the work environment and facilities Code of Practice 2021 has also received consequential amendments.

The Code covers the physical work environment and facilities provided to workers, including work areas, lighting, ventilation, toilets, drinking water, dining areas, change rooms, personal storage, remote or isolated work and emergency arrangements.

A key feature of the current Code is its recognition that the work environment can contribute to both physical and psychosocial risks.

For example, workplace design, lighting and visibility can influence the risk of violence, aggression and harassment. Similarly, remote and isolated work can increase exposure to both physical and psychosocial risks.

The Code also contains guidance concerning ventilation and airborne contaminants, reinforcing the need for businesses to consider air quality as part of maintaining a safe work environment.

This makes the updated Code particularly relevant to employers undertaking workplace refurbishments, relocations, facility upgrades or changes to working arrangements.

7. Managing Risks Of Plant In The Workplace

The Managing risks of plant in the workplace Code of Practice 2021 is the final Code included in the consequential amendments.

Plant is a major source of workplace injury, and the Code applies to businesses that manage or control plant as well as those involved in installing, constructing or commissioning plant.

The Code adopts a lifecycle approach, covering matters including:

  • purchasing and hiring plant
  • second-hand plant
  • installation and commissioning
  • operation
  • modifications
  • inspection
  • maintenance and repair
  • storage
  • powered mobile plant
  • decommissioning and disposal
  • guarding
  • operational controls
  • emergency stops
  • warning devices
  • isolation of energy sources.

For businesses, the key message is that plant safety starts well before a machine is switched on. Procurement, design, installation and commissioning decisions can determine the level of risk workers will face throughout the plant’s lifecycle.

The updated Code should therefore be considered when reviewing plant procurement processes, machinery risk assessments, safe operating procedures and maintenance programs.

What Should Queensland Businesses Do Now?

Although these are described as consequential amendments, businesses should not assume that the changes can simply be filed away as administrative updates.

The seven Codes collectively cover many of the systems that underpin a modern WHS management framework.

Businesses should consider undertaking a targeted review before or from 1 September 2026, including:

  1. Review the amended Codes relevant to your business and identify changes to terminology, references and guidance.
  2. Review WHS policies and procedures, particularly psychosocial risk, complaints, issue resolution, consultation and workplace behaviour procedures.
  3. Check risk assessments to ensure they address both physical and psychosocial hazards where relevant.
  4. Review control measures rather than relying solely on administrative controls or PPE.
  5. Check training and competency requirements, particularly for high-risk work such as confined-space entry and plant operation.
  6. Review design and procurement processes so WHS considerations are incorporated before structures, plant or work systems are introduced.
  7. Confirm consultation arrangements with workers and health and safety representatives.
  8. Update internal references to legislation and Codes of Practice so supervisors, managers and workers are working from current information.
  9. Check contractor and supplier arrangements, particularly where multiple duty holders share responsibility for plant, structures, confined spaces or workplaces.
  10. Keep evidence of the review. Documenting what was reviewed, who was consulted and what actions were taken can help demonstrate that the business is actively managing its WHS obligations.

The Bigger Picture

The amendments demonstrate an important feature of Australia’s WHS framework: safety obligations do not operate in isolation.

Psychosocial health, workplace design, plant safety, confined-space work, noise, workplace facilities and general risk management can overlap considerably. A single activity may involve several of these Codes at the same time.

For example, a new manufacturing facility could involve safe design of structures, plant risk management, hazardous noise, workplace facilities and psychosocial hazards arising from work design. Similarly, confined-space work may involve plant isolation, atmospheric hazards, emergency response and psychosocial risks.

The most effective approach is therefore not to treat each Code as a standalone compliance exercise. Instead, businesses should integrate the updated Codes into their broader WHS management system.

Conclusion

From 1 September 2026, Queensland businesses will need to work with consequentially amended versions of seven important Codes of Practice covering psychosocial hazards, noise, safe design, risk management, confined spaces, workplace environments and facilities, and plant.

The changes are designed to keep the Codes aligned with Queensland’s current WHS legislative framework. In particular, businesses should take note of the updated processes and timeframes for dispute and issue resolution and the amended sexual-harassment provisions within the psychosocial hazards Code.

For duty holders, the practical response should be more than simply downloading the new documents. The commencement date provides a useful trigger to review WHS systems, risk assessments, consultation arrangements, procedures, training and controls and ensure that workplace practices continue to reflect current Queensland requirements.

Important: This article provides general information only and is not legal advice. Approved Codes of Practice and WHS legislation can have different application depending on the circumstances. Businesses should refer to the current Queensland legislation and WorkSafe Queensland guidance when determining their specific obligations.

Sherm Software equips organisations with powerful tools to maintain comprehensive, accurate and up to date records. With Sherm Software’s Registers module, you can maintain records of all relevant legislation affecting business operations, linking to the regulators’ site and monitoring through Workplace Inspections Management.

By centralising data, automating workflows and ensuring compliance, Sherm Software enhances safety management, boosts regulatory compliance and fosters continuous improvement in workplace safety practices.

Get in touch with us today and learn more.

Electrical Safety Regulation 2026 QLD: What Has Changed?

Queensland’s new Electrical Safety Regulation 2026 is set to replace the Electrical Safety Regulation 2013 from 1 September 2026.

For electricians, electrical contractors, businesses and other people working with electrical installations and equipment, the change is important, but it is not a major overhaul of Queensland’s electrical safety requirements.

The Queensland Government has confirmed that the 2026 Regulation does not introduce new policy or regulatory obligations. Instead, the regulation has been substantially reorganised and rewritten to make it easier to navigate, understand and apply alongside the Electrical Safety Act 2002.

Why Has The Electrical Safety Regulation Been Replaced?

The Electrical Safety Regulation 2013 was subject to Queensland’s statutory sunset review process. Queensland subordinate legislation generally expires after 10 years unless it is reviewed and remade.

The 2013 Regulation was due to expire on 31 August 2026. The review found that the regulation remained necessary and that its underlying policy and regulatory intent continued to be appropriate.

Rather than allowing the regulation to expire, the Queensland Government remade it as the Electrical Safety Regulation 2026. The new regulation was notified on 14 August 2026 and commences on 1 September 2026.

The official position is that the remake is primarily about structure, clarity and usability, rather than introducing a new set of electrical safety rules.

What Are The Main Changes?

Although the practical electrical safety requirements are largely unchanged, there are several important structural changes that electrical businesses should be aware of.

  1. The Regulation Has Been Completely Reorganised

One of the biggest changes is the structure of the regulation.

Sections have been reordered and grouped into new parts to better align the regulation with the Electrical Safety Act 2002. As a result, virtually all section numbers have changed.

This means a procedure, safety document, contract, training resource or other business document that currently refers to a particular section of the 2013 Regulation may contain an outdated reference after 1 September 2026.

For example, rather than assuming that a section number from the 2013 Regulation remains valid, businesses should check the Queensland Government’s comparison information to identify the corresponding provision in the 2026 Regulation.

This is likely to be one of the most noticeable changes for contractors and compliance teams.

  1. Greater Connection Between The Regulation and The Electrical Safety Act

The 2026 Regulation contains additional legislative references throughout the document.

These references are intended to make it clearer how individual requirements relate to the corresponding provisions of the Electrical Safety Act 2002.

The aim is to make the legislation easier to interpret and navigate, particularly where a duty originates in the Act and the Regulation provides more detailed requirements about how that duty is to be met.

  1. Some Provisions Have Been Streamlined

A small number of provisions have been removed or combined where they were considered unnecessary or duplicated requirements elsewhere.

The purpose is to reduce duplication and make the regulation easier to read and use.

Importantly, this should not be interpreted as a broad removal of electrical safety responsibilities. The Queensland Government states that the remake does not change the underlying policy or intent of the regulation.

  1. Work Near Electrical Lines Has Been Restructured

Requirements dealing with work near overhead and underground electric lines have been reorganised.

The provisions have been separated according to the different risk profiles associated with overhead and underground electrical lines.

Definitions relating to exclusion zones and unsafe distances have also been moved to the beginning of the regulation so they are easier to locate and apply throughout the legislation.

For businesses carrying out construction, excavation, civil works, tree work or other activities near electrical infrastructure, this restructuring should make the relevant requirements easier to find.

It is still important, however, to review the new provisions rather than relying on old section references.

  1. Licensing Provisions Have Been Consolidated

The 2026 Regulation reorganises provisions relating to licensing and qualified persons.

Definitions for qualified technical person (QTP) and qualified business person (QBP) have been included in the licensing part of the Regulation, along with definitions for other terms used in the licensing provisions.

The intention is to make the licensing requirements more logically organised and consistent.

Do electricians need to apply for a new licence?

No.

The commencement of the Electrical Safety Regulation 2026 does not invalidate existing electrical licences. Licences issued under the 2013 Regulation continue to have effect under the 2026 Regulation.

Queensland Government guidance confirms that licence holders do not need to apply for a new licence or take action simply because the new regulation commences.

  1. High-Voltage Live-Line Work Has Been Separated Into Two Sections

Requirements for high-voltage live-line work have been reorganised into two separate provisions.

The purpose is to make the requirements easier to understand and apply rather than to introduce a new policy approach to high-voltage live-line work.

Businesses involved in high-voltage work should nevertheless update internal references to the relevant sections of the new Regulation.

  1. Safety Management System Requirements Have Been Restructured

The requirements for safety management systems (SMS) have been reorganised into discrete sections.

The Queensland Government has also included a transitional arrangement so that the new SMS provisions do not commence immediately.

The restructured SMS requirements commence on 1 September 2027, giving prescribed electricity entities an additional 12 months to become familiar with the new structure.

During the transitional period, the former section 234 of the 2013 Regulation continues to apply.

Importantly, the Government says there are no changes to the underlying SMS requirements, the changes are primarily structural and clarifying.

  1. Changes To SMS Auditing Requirements

The 2026 Regulation provides additional clarity around safety management system auditing.

For example, it clarifies that an audit report must be provided to the regulator following an audit and removes the broader requirement to provide “any further information” required by the regulator.

The annual audit provisions have also been clarified, including what is subject to an annual audit while retaining flexibility for a prescribed electricity entity to determine the scope of an audit.

The timeframe for providing an annual audit plan has also been expressly stated: generally, the later of 30 days before the audit begins or an agreed date.

  1. Transitional Arrangements Protect Existing Licences and Processes

The new Regulation contains transitional provisions in Part 16.

These provisions are designed to ensure continuity when the 2013 Regulation is replaced.

For example, existing licences, notices and authorisations continue to operate under the transitional arrangements. Certain applications, investigations and proceedings that began under the 2013 Regulation can also continue under the appropriate legislative framework.

This means businesses should not assume that the changeover date requires them to start existing processes again.

What Does This Mean For Electricians and Electrical Contractors?

For most electricians and electrical contractors, the practical impact should be relatively small.

If your business was already complying with the Electrical Safety Regulation 2013, the Queensland Government says you are unlikely to need to change your work practices simply because the 2026 Regulation commences.

However, there are several things worth doing.

Review Your Procedures

Check your electrical safety procedures, safe work procedures, compliance manuals and other documents for references to the Electrical Safety Regulation 2013.

Where your documents refer to specific section or part numbers, those references should be checked and updated.

Update Templates and Compliance Documents

Businesses may have references to the 2013 Regulation in:

  • electrical safety procedures
  • SWMS and risk-management documentation
  • compliance manuals
  • internal audit documents
  • training materials
  • contractor documentation
  • inspection and testing procedures
  • electrical installation checklists
  • safety management system documents
  • website compliance information.

Not every document will need to be rewritten. If a document describes a practical safety requirement without referring to an old section number, the Queensland Government says substantial changes are unlikely to be necessary. However, documents should still be reviewed for accuracy.

Make Your Team Aware Of The New Section Numbers

There is no general requirement to retrain workers simply because the 2026 Regulation has commenced.

Workers should, however, be made aware of the new structure and any changes to legislative references that affect their work.

This is particularly relevant for supervisors, electrical contractors, compliance managers and anyone responsible for preparing or reviewing safety documentation.

Has Anything Actually Changed In Day-To-Day Electrical Safety?

For most electrical work, the answer is not in a substantive policy sense.

The Queensland Government has been very clear that the 2026 Regulation is not intended to introduce new policy or regulatory obligations. The purpose of the remake was to improve the regulation’s structure, clarity and usability.

This distinction is important.

The regulation looks substantially different, section numbers have changed and provisions have been moved around, but that does not mean electricians suddenly have an entirely new set of electrical safety obligations.

In practical terms, the biggest immediate challenge may be finding the equivalent provision in the new Regulation.

What About Enforcement?

The Queensland Government has stated that the Electrical Safety Regulation 2026 will not result in a different enforcement approach.

The remake does not change the policy intent or how the obligations are intended to operate. The changes are primarily structural and drafting improvements.

Businesses should therefore treat the commencement of the new Regulation as an important compliance-document update rather than assuming that the change creates a new enforcement regime.

Don’t Confuse The 2026 Regulation With Other Electrical Legislation Changes

There have also been separate changes to Queensland electrical safety legislation during 2026.

For example, the Electrical Safety and Other Legislation Amendment Act 2026 was assented to on 27 March 2026. Those legislative amendments are separate from the sunset remake of the Electrical Safety Regulation 2026.

The 2026 Regulation itself is the replacement for the 2013 Regulation and is primarily a restructure and clarification exercise.

This distinction matters when researching “electrical safety changes in Queensland in 2026”, because not every 2026 legislative change is a consequence of the new Regulation.

When Does The Electrical Safety Regulation 2026 Start?

The Electrical Safety Regulation 2026 commences on 1 September 2026.

The existing Electrical Safety Regulation 2013 expires at the same time. The new Regulation has been made as Queensland subordinate legislation and is scheduled to remain in force until its next statutory expiry in 2036, subject to any future legislative changes.

The exception is the restructured safety management system provisions discussed above, which commence on 1 September 2027 under the transitional arrangements.

A Practical Checklist For Queensland Electrical Businesses

Before the new Regulation takes effect, electrical businesses should consider:

  • Review your references to the Electrical Safety Regulation 2013.
  • Check the new section numbers for requirements relevant to your business.
  • Update policies and procedures that cite the old Regulation.
  • Update compliance and audit documentation.
  • Brief supervisors and workers about the new structure.
  • Review documentation relating to work near overhead and underground electrical lines.
  • Check licensing documentation and references to QTPs and QBPs.
  • Review safety management system documentation if your business is a prescribed electricity entity.
  • Keep copies of the new Regulation and the official comparison material available to relevant staff.

The Bottom Line

The Electrical Safety Regulation 2026 is a major rewrite in structure, but not a major change in electrical safety policy.

From 1 September 2026, Queensland will move from the Electrical Safety Regulation 2013 to the new 2026 Regulation. The biggest changes are the rearrangement of provisions, new section numbers, clearer legislative references, consolidated licensing provisions, restructured requirements for work near electrical lines and clearer safety management system and audit provisions.

For most electricians and contractors who already comply with the existing requirements, there should be no need to change established work practices simply because the new Regulation commences.

The key task is to make sure your business documentation, procedures and legislative references keep pace with the new structure.

For the definitive requirements, businesses should refer to the official Electrical Safety Regulation 2026 and the Queensland Government’s Electrical Safety Regulation 2026 guidance rather than relying solely on summaries or third-party interpretations.

Why Australian Businesses Need to Review Their Standards Regularly

Australian businesses operate in an environment shaped by legislation, regulations, industry codes, Australian Standards, workplace requirements and customer expectations. While not every standard is legally mandatory, standards can play an important role in helping businesses operate safely, consistently and professionally.

The challenge is that standards do not remain static. They can be revised, replaced or referenced by legislation and regulations. A standard that was appropriate when a business procedure was written several years ago may no longer reflect current requirements.

For this reason, businesses should regularly review the standards referenced in their policies, procedures, work instructions and other controlled documents.

What Are Australian Standards?

Australian Standards are documents that provide specifications, procedures, guidelines or other information intended to promote safety, consistency, reliability and quality.

Standards Australia explains that standards can cover a wide range of areas, including construction, consumer products and services, energy, water, environment and other sectors. Standards may be Australian Standards (AS), Australian/New Zealand Standards (AS/NZS), or adopted international standards.

An important point for businesses is that an Australian Standard is not automatically law.

Standards are generally voluntary. However, Australian, state and territory governments can reference standards in legislation and regulations. When a standard is incorporated into legislation, regulatory requirements or other legally enforceable arrangements, compliance may become mandatory.

Businesses may also encounter mandatory industry codes, codes of practice, product safety requirements and other regulatory obligations that operate alongside standards.

Common Types Of Standards Businesses May Encounter

The standards relevant to a business depend heavily on its industry and activities.

For example, a business may need to consider standards relating to:

  • Workplace health and safety
  • Electrical work and equipment
  • Building and construction
  • Fire protection and emergency systems
  • Machinery and equipment
  • Personal protective equipment
  • Quality management
  • Environmental management
  • Information security
  • Food safety
  • Accessibility
  • Product design and safety
  • Testing and inspection
  • Installation and maintenance
  • Risk management
  • Competency and training
  • Documentation and record keeping

A business may also have contractual obligations to follow particular standards. A customer, principal contractor, insurer, certification body or tender specification may require work to be performed in accordance with a particular standard.

This means a business should look beyond legislation alone when identifying the requirements that apply to its operations.

Why Should Businesses Review Their Documented Standards?

One of the most common problems in business documentation is the “set and forget” standard.

A procedure may state:

“All inspections must be completed in accordance with AS XXXX:2018.”

But what happens if that standard has since been revised or superseded?

The procedure may continue to circulate internally, staff may continue following it, and the business may believe it is working to the appropriate requirement, when in fact its documented process is based on an outdated publication.

Regular review helps prevent this situation.

  1. Standards can change

Standards Australia regularly reviews standards to ensure they remain relevant as technology, industry practices and community expectations change.

A revised standard may introduce:

  • New safety requirements
  • Different testing methods
  • Updated terminology
  • New equipment requirements
  • Changed inspection intervals
  • Additional documentation requirements
  • Revised technical specifications
  • New responsibilities for workers or businesses

If an internal procedure continues to reference an old edition, there is a risk that the business’s documented process no longer reflects current industry requirements.

  1. Regulations can change

A standard may also become more significant because legislation or regulation changes.

Government agencies can reference standards in legislation. In those circumstances, a standard that was previously voluntary may become relevant to a legal compliance obligation.

Businesses should therefore consider standards as part of their broader compliance monitoring process rather than treating them as static technical documents.

  1. Your business may have changed

Even when a standard has not changed, the business may have.

Consider whether your organisation has:

  • Introduced new equipment
  • Changed suppliers
  • Expanded into another state or territory
  • Started offering new services
  • Changed its workplace or premises
  • Introduced new technology
  • Taken on new types of customers
  • Changed its processes
  • Outsourced activities
  • Started working on larger projects

These changes can introduce new standards and compliance requirements.

A standards review should therefore ask two questions:

“Has the standard changed?”

and

“Has our business changed?”

Both are important.

Standards Should Be Controlled Within Your Business

If your organisation maintains policies, procedures, work instructions, forms or manuals, standards referenced by those documents should be treated as controlled information.

A simple standards register can be extremely useful.

The register does not need to be complicated. Its purpose is to give the business visibility over the standards and requirements that underpin its operations.

What Should A Standards Review Include?

A practical review can include the following steps.

Step 1: Identify every standard you currently reference

Search your policies, procedures, manuals, forms, contracts, specifications and work instructions.

Look for references such as:

  • AS XXXX
  • AS/NZS XXXX
  • ISO XXXX
  • IEC XXXX
  • “current Australian Standard”
  • “relevant standard”
  • “applicable code”
  • “industry standard”

Create a central register of everything you find.

Step 2: Confirm the standard is still current

Check the official source to determine whether the publication is:

  • Current
  • Superseded
  • Withdrawn
  • Amended
  • Under revision
  • Replaced by another standard

Do not assume that the year shown in an internal procedure is still the current edition.

Step 3: Check whether the standard is legally relevant

Determine whether the standard is referenced by:

  • Commonwealth legislation
  • State or territory legislation
  • Regulations
  • Mandatory industry codes
  • Product safety requirements
  • Licencing conditions
  • Contracts
  • Project specifications
  • Certification requirements

This distinction is important because the legal status of a standard depends on how it is referenced and applied.

Step 4: Compare the new requirements with your procedures

If a standard has changed, ask:

Does our current process still meet the requirements?

This may require reviewing equipment, training, forms, inspection methods, records, responsibilities and work practices.

Step 5: Update your documentation

Where necessary, update the relevant:

  • Policies
  • Procedures
  • Work instructions
  • Forms
  • Checklists
  • Training material
  • Risk assessments
  • Registers
  • Contracts
  • Technical specifications

Make sure obsolete versions are removed or clearly identified so employees do not accidentally use them.

Step 6: Communicate the changes

Updating a document is only part of the process.

Employees who rely on the procedure need to understand what has changed and what they are now expected to do.

Business.gov.au recommends documenting policies, processes and procedures, making them accessible to staff, providing relevant training and regularly reviewing processes and procedures.

Make Standards Review Part Of Your Management System

Standards review should not be an activity that happens only when an auditor arrives.

A better approach is to incorporate it into the business’s normal management system.

For example, a business could establish an annual review process that asks:

  1. What standards do we rely on?
  2. Are they still current?
  3. Have any amendments or replacements been published?
  4. Are any of these standards referenced by legislation or regulations?
  5. Have our products, services or processes changed?
  6. Do our procedures still reflect the requirements?
  7. Do employees need additional training?
  8. Do our forms and records need updating?
  9. Are contracts or customer requirements affected?
  10. Has responsibility for monitoring each requirement been assigned?

This approach turns standards management from a reactive task into a proactive business process.

The Benefits Go Beyond Compliance

Keeping standards and internal documentation current can provide benefits beyond simply meeting regulatory requirements.

It can help businesses:

  • Reduce operational risk
  • Improve workplace safety
  • Improve consistency
  • Reduce errors and rework
  • Strengthen employee training
  • Demonstrate due diligence
  • Improve quality
  • Support tender and contract requirements
  • Prepare for audits
  • Improve customer confidence
  • Identify outdated business practices
  • Maintain better organisational knowledge

Standards can provide businesses with a recognised framework for achieving consistent and reliable outcomes.

A Final Reminder For Australian Businesses

Your business’s procedures are only as useful as the information on which they are based.

If a procedure references an Australian Standard from five or ten years ago, don’t assume it is still current. Check it.

If your business has introduced new equipment, technology or services, don’t assume your existing standards register still covers everything. Review it.

And if you discover that a standard has changed, don’t simply update the reference number. Determine whether the change affects the way your business actually operates.

Standards management is ultimately about keeping the connection between external requirements and internal business practices alive.

Regularly reviewing standards, legislation, industry codes and the documents that reference them can help Australian businesses stay informed, reduce risk and maintain processes that are fit for purpose.

Important: This article provides general information and is not legal or compliance advice. Businesses should confirm the specific requirements applicable to their industry, state or territory, products, services and contractual obligations with the relevant regulator or suitably qualified adviser.

HVNL Changes from 1 August 2026: What Heavy Vehicle Operators Need to Do

The biggest changes to Australia’s Heavy Vehicle National Law (HVNL) in more than a decade will take effect on 1 August 2026, bringing a stronger focus on proactive safety management, documented systems, and demonstrable compliance.

For heavy vehicle operators, the reforms represent a shift away from simply complying with prescriptive rules towards proving that your business actively manages transport safety risks.

Whether you operate a single truck or a national fleet, now is the time to review your systems and ensure your business is ready.

Why the HVNL is Changing

The reforms have been developed by the National Transport Commission (NTC) in partnership with the National Heavy Vehicle Regulator (NHVR) and participating state and territory governments. The aim is to modernise heavy vehicle regulation, improve safety outcomes and reduce unnecessary regulatory complexity while maintaining productivity.

The updated legislation applies in all Heavy Vehicle National Law participating jurisdictions:

  • Queensland
  • New South Wales
  • Victoria
  • South Australia
  • Tasmania
  • Australian Capital Territory

Western Australia and the Northern Territory continue to operate under their own heavy vehicle legislation.

The Biggest Change: Safety Management Systems Become Central

The most significant reform is the introduction of a formal Safety Management System (SMS) as the foundation of heavy vehicle accreditation.

Rather than focusing solely on meeting individual compliance requirements, operators will need to demonstrate they have systems in place that:

  • identify transport risks
  • assess those risks
  • implement effective controls
  • monitor performance
  • continually improve safety outcomes.

The regulator’s focus will increasingly be on whether your business can prove its systems are working, not simply whether paperwork exists.

What Operators Will Be Required to Have

Under the updated HVNL, operators should expect to have documented processes covering areas such as:

Leadership and Safety Commitment

Management must actively support transport safety rather than treating compliance as an administrative exercise.

This includes:

  • clearly defined responsibilities
  • documented safety objectives
  • evidence that management reviews safety performance.

Risk Management

Operators must identify hazards before incidents occur.

Examples include:

  • fatigue risks
  • vehicle maintenance
  • loading practices
  • scheduling pressures
  • driver competency
  • subcontractor management.

Importantly, businesses should be able to demonstrate how these risks are assessed and controlled.

Driver Competency

Businesses will need documented processes for:

  • induction
  • licence verification
  • ongoing training
  • competency assessments
  • refresher programs.

The expectation is that operators can demonstrate drivers remain competent throughout their employment.

Vehicle Maintenance

Maintenance systems must ensure vehicles remain roadworthy.

Operators should maintain documented procedures for:

  • inspections
  • preventative maintenance
  • defect reporting
  • repairs
  • maintenance records.

Incident Reporting and Investigation

Simply recording incidents will no longer be enough.

Businesses should investigate:

  • crashes
  • near misses
  • equipment failures
  • recurring defects

and use findings to improve safety systems.

Internal Auditing

Operators should regularly review their own compliance before the regulator does.

Internal audits help identify weaknesses and provide evidence that safety systems are functioning effectively.

Expanded “Fit to Drive” Requirements

The updated HVNL introduces a broader obligation regarding driver fitness.

Previously, compliance focused largely on work and rest hours.

The reforms extend this concept to ensure drivers are genuinely fit to operate a heavy vehicle.

This includes considering whether a driver may be impaired by:

  • fatigue
  • illness
  • injury
  • medication
  • alcohol or drugs
  • any other condition affecting safe driving.

Operators should have documented procedures for assessing and managing fitness for duty rather than relying solely on legal driving hours.

Changes to Accreditation

The National Heavy Vehicle Accreditation Scheme (NHVAS) will transition to a new accreditation framework built around documented Safety Management Systems.

The new framework includes:

  • General Safety Accreditation (GSA) as the baseline accreditation for operators seeking formal recognition.
  • Alternative Compliance Accreditation (ACA) for businesses seeking operational concessions, such as alternative fatigue management arrangements.

Existing accredited operators will have a transition period to move to the new framework.

Chain of Responsibility Remains Critical

The reforms do not remove existing Chain of Responsibility (CoR) obligations.

Instead, they strengthen expectations that every party in the transport supply chain actively manages safety risks.

This includes:

  • operators
  • employers
  • schedulers
  • consignors
  • loaders
  • loading managers
  • consignees
  • contractors.

Businesses must continue taking all reasonably practicable steps to eliminate or minimise transport risks.

Productivity Improvements

Not all reforms involve additional compliance.

Several changes are designed to improve productivity, including:

  • increases to General Mass Limits in some circumstances
  • simplified mass management arrangements
  • an increase in the general vehicle length limit from 19 metres to 20 metres for eligible vehicles.

These changes aim to simplify regulation while maintaining safety standards.

How Operators Should Prepare

Businesses should begin preparing well before the commencement date by:

  • reviewing current compliance systems
  • conducting a gap analysis against the new SMS requirements
  • documenting policies and procedures
  • reviewing fatigue and fitness-for-duty processes
  • training managers and supervisors
  • ensuring records can demonstrate compliance
  • preparing for future audits under the new National Audit Standard.

Operators who already have strong systems in place may only require refinements, while smaller businesses relying on informal processes are likely to have more work to do.

The Bottom Line

The updated HVNL marks a significant shift in how heavy vehicle safety is regulated in Australia.

The emphasis is no longer simply on following rules, it is on demonstrating that your business has effective systems to identify, manage and continuously improve transport safety.

For operators, success under the new legislation will depend on evidence. Policies, procedures, training records, maintenance documentation, risk assessments and internal audits will all play an increasingly important role in proving compliance.

Sherm Software has all of the necessary functions to cover your requirements, with all evidence available at the touch of a button for your next audit.

Businesses that begin preparing now will be in a stronger position when the reforms commence on 1 August 2026, reducing compliance risk while improving operational safety and efficiency.

Get in touch with us today and let us help you prepare.

Mid-Year Audit Planning: Aligning Strategy With WHS Trends

As the financial year gets underway, many Australian businesses are focused on budgets, growth plans, and operational priorities. However, the middle of the year is also an ideal time to assess another critical area of business performance, Work Health and Safety (WHS).

A mid-year WHS audit is more than a compliance exercise. It provides an opportunity to evaluate how effectively your current safety systems are working, identify emerging risks, and ensure your business is keeping pace with changing workplace expectations.

With evolving legislation, increased regulatory scrutiny, and new workplace risks continuing to emerge, businesses that review their WHS strategy mid-year are better positioned to protect their workers, maintain compliance, and support long-term business success.

Why Conduct a Mid-Year WHS Audit?

Annual reviews are important, but waiting until the end of the year to evaluate your safety systems can allow issues to persist for months.

A mid-year audit enables business owners to:

  • Identify gaps before they become compliance issues.
  • Review incident and near-miss trends from the first half of the year.
  • Assess whether existing controls remain effective.
  • Confirm that policies reflect current workplace activities.
  • Ensure workers have completed required training and competency refreshers.
  • Prepare for regulator inspections or external audits.

Rather than reacting to incidents, businesses can proactively strengthen their safety management systems.

WHS Trends Australian Businesses Should Consider

Workplaces continue to evolve, and so do the risks they face. During your mid-year review, consider whether your safety approach reflects current WHS trends.

  1. Greater Focus on Psychosocial Hazards

Mental health has become a key component of workplace safety.

Psychosocial hazards, including excessive workloads, workplace bullying, poor communication, fatigue, and role ambiguity, are now recognised as WHS risks that require the same level of attention as physical hazards.

Business owners should review:

  • Workload management
  • Employee wellbeing initiatives
  • Reporting processes
  • Leadership capability
  • Workplace culture

Addressing psychosocial risks early can improve both employee wellbeing and organisational performance.

  1. Increased Regulator Expectations

Australian WHS regulators continue to increase inspections and enforcement activities across many industries.

Businesses are expected to demonstrate not only that policies exist but that they are actively implemented, monitored, and reviewed.

Documentation should clearly show:

  • Risk assessments
  • Consultation with workers
  • Incident investigations
  • Corrective actions
  • Training records
  • Maintenance schedules

Strong records provide evidence that safety responsibilities are being effectively managed.

  1. Better Use of Safety Data

Many organisations now use safety data to identify trends before incidents occur.

Rather than focusing solely on injury statistics, businesses are monitoring:

  • Near misses
  • Hazard reports
  • Safety observations
  • Corrective action completion rates
  • Training compliance
  • Equipment inspections

Reviewing this information during a mid-year audit helps identify recurring issues that may otherwise go unnoticed.

  1. Contractor and Supply Chain Safety

Many businesses rely on contractors, subcontractors, and suppliers to deliver services.

A mid-year audit should confirm that contractor management processes remain effective, including:

  • Prequalification requirements
  • Inductions
  • Safe work procedures
  • Insurance documentation
  • Competency verification
  • Ongoing supervision

Managing contractor safety reduces risk across the entire operation.

Key Areas to Review During Your Mid-Year Audit

A structured audit provides a clear picture of your current WHS performance.

Consider reviewing:

Safety Management System

  • Policies and procedures
  • Risk management processes
  • Emergency plans
  • Safe work instructions

Workplace Inspections

  • Housekeeping standards
  • Plant and equipment condition
  • Hazard identification
  • Maintenance records

Training and Competency

  • New employee inductions
  • Refresher training
  • High-risk work licences
  • First aid qualifications

Incident Management

  • Incident reporting procedures
  • Investigation quality
  • Corrective action follow-up
  • Lessons learned

Worker Consultation

Consulting workers is a fundamental part of effective WHS management.

Review whether employees are:

  • Reporting hazards
  • Participating in safety meetings
  • Contributing to risk assessments
  • Providing feedback on controls

Workers often identify practical improvements that management may overlook.

Turning Audit Findings Into Action

The value of an audit lies in what happens after it is completed.

Prioritise findings according to risk, assign responsibilities, establish realistic timeframes, and monitor progress until actions are complete.

Business owners should also communicate improvements to employees. Demonstrating that concerns lead to meaningful action helps strengthen trust and encourages ongoing participation in workplace safety.

The Business Benefits of Mid-Year WHS Reviews

An effective WHS audit delivers more than regulatory compliance.

Businesses often experience:

  • Reduced workplace incidents
  • Improved operational efficiency
  • Lower workers’ compensation costs
  • Better employee engagement
  • Stronger reputation with clients and stakeholders
  • Greater confidence during regulator inspections

When safety becomes part of strategic planning rather than simply an administrative requirement, it contributes directly to business resilience and long-term performance.

Final Thoughts

Mid-year provides an ideal opportunity to step back and assess whether your WHS systems are supporting both your people and your business objectives.

By reviewing current performance, responding to emerging WHS trends, and addressing gaps before they escalate, Australian business owners can create safer workplaces while strengthening compliance and operational performance.

Rather than viewing a WHS audit as a once-a-year obligation, consider it an ongoing strategy that helps your business adapt, improve, and thrive in an evolving regulatory and workplace environment.

Learn more about audit readiness and use our free checklist to help with your mid-year audit plan.

Contractor Inductions: Why Compliance Slips Through the Cracks

Across Australian worksites, from construction and mining to logistics and facilities management, contractor inductions are a routine part of onboarding. They’re meant to ensure every worker understands site rules, hazards, and responsibilities before starting work. On paper, the process looks solid. In practice, however, contractor inductions are one of the most common points where compliance quietly breaks down.

This isn’t usually due to negligence or bad intent. More often, it’s the result of rushed processes, fragmented systems, and assumptions that don’t hold up under scrutiny. Understanding where things go wrong is the first step to tightening compliance and reducing risk.

The “Tick-and-Flick” Mentality

One of the biggest pitfalls is treating inductions as a box-ticking exercise. When deadlines loom and contractors are needed on-site quickly, the focus shifts from comprehension to completion. Workers may click through online modules or skim documents just to gain site access.

The problem? Completion doesn’t equal understanding. If a contractor hasn’t genuinely absorbed key safety procedures, the business is exposed, not just to regulatory penalties, but to real-world incidents.

Inconsistent Induction Standards Across Sites

Many organisations operate across multiple locations, each with slightly different induction requirements. While some variation is necessary due to site-specific risks, inconsistency can create confusion, especially for contractors moving between sites.

Without a standardised baseline, important information can fall through the cracks. Contractors may assume they’ve “already done this before,” while site managers assume prior knowledge that may not exist.

Poor Record-Keeping and Verification

In an audit or incident investigation, documentation is everything. Yet many businesses still rely on scattered systems like emails, spreadsheets and paper forms to track inductions.

This fragmentation leads to common issues:

  • Missing or incomplete records
  • Difficulty verifying who completed what training
  • Expired inductions going unnoticed

When regulators come knocking, these gaps quickly become liabilities.

Language and Literacy Barriers

Australia’s workforce is diverse, and not all contractors will have the same level of English proficiency or literacy. Standard induction materials often fail to account for this.

If critical safety information isn’t clearly understood, the induction has effectively failed, even if it’s been “completed.” Visual aids, translated materials, and interactive formats can make a significant difference here, but they’re not always implemented.

Lack of Engagement and Relevance

Generic inductions that cover broad policies without tailoring to specific roles or risks tend to lose attention quickly. Contractors may struggle to see how the information applies to their actual tasks.

Effective inductions need to answer a simple question: What does this mean for me, today, on this site? Without that connection, retention drops and compliance weakens.

No Ongoing Reinforcement

Induction shouldn’t be a one-off event. Over time, people forget procedures, become complacent, or develop shortcuts. Yet many organisations fail to reinforce key messages after the initial onboarding.

Toolbox talks, refresher training, and periodic assessments are critical to maintaining compliance, not just establishing it.

Overreliance on Contractors to Self-Manage

It’s common for businesses to assume that contractors, especially experienced ones, will manage their own compliance. While contractors do carry responsibilities under Australian work health and safety laws, the host organisation still has a duty of care.

Assumptions like “they’ve done this before” or “they know the risks” can lead to dangerous gaps in oversight.

Closing the Gaps

Improving contractor induction compliance doesn’t necessarily mean adding more content, it means improving how it’s delivered, tracked, and reinforced.

Some practical steps include:

  • Standardising core induction requirements across sites
  • Using digital systems for real-time tracking and verification
  • Designing content for clarity, engagement, and accessibility
  • Incorporating site-specific, role-relevant information
  • Scheduling regular refreshers and compliance checks

Ultimately, contractor inductions are more than a procedural step, they’re a frontline defence against incidents and non-compliance. When done well, they set clear expectations, build safety culture, and protect both workers and businesses.

When done poorly, they create a false sense of security.

That’s where the real risk lies.

For a broader explanation of how inductions fit into defensible contractor management, see our Contractor and Supplier Compliance Management Guide.

Sherm Software can help close the gaps using the Contractor and Supplier Register by maintaining records and sending automatic notifications when scheduled refreshers and compliance checks are due.

Use our Checklist to assess whether your contractor compliance approach would stand up to audit, investigation, or client scrutiny.

Contractor Prequalification in Australia, More Than a Paper Chase

Across Australia, contractor prequalification is often treated as a compliance exercise—collect the required documents, tick the boxes, and move on. With strict regulatory frameworks and a strong focus on workplace safety, it’s understandable why documentation plays such a central role.

But here’s the reality, collecting documents alone doesn’t ensure a contractor is safe, capable, or reliable. In fact, over-reliance on paperwork can create blind spots that expose businesses to serious operational and legal risks.

Compliance Doesn’t Equal Capability

In the Australian context, contractors are typically required to provide:

  • Public liability and workers’ compensation insurance
  • Relevant licences and tickets (e.g. White Cards, high-risk work licences)
  • Safe Work Method Statements (SWMS)
  • Safety management plans and policies

These are all essential. However, they only confirm that a contractor meets minimum requirements at a specific point in time. They don’t guarantee that work will be carried out safely on-site or that systems are actively followed.

A contractor might submit a compliant SWMS, but is it actually used in day-to-day operations? Are workers properly trained, supervised, and accountable?

Documentation alone can’t answer these questions.

The Risks of a “Set and Forget” Approach

Many businesses adopt a “set and forget” model—documents are collected during onboarding and rarely revisited. In a fast-moving environment like construction, mining, or infrastructure, this approach can quickly become outdated.

Common issues include:

  • Expired insurances or licences going unnoticed
  • Generic SWMS that don’t reflect actual site conditions
  • Changes in subcontractors or workforce capability
  • Deterioration in safety performance over time

Under Australian Work Health and Safety (WHS) laws, businesses (PCBUs) have a duty to ensure, so far as reasonably practicable, the health and safety of workers—including contractors. Simply collecting documents is unlikely to meet this obligation if something goes wrong.

Bridging the Gap Between Paper and Practice

The key challenge is ensuring that what’s documented is actually implemented.

To bridge this gap, organisations need to go beyond collection and focus on validation. This might include:

  • Reviewing SWMS for task-specific relevance, not just completeness
  • Verifying licences with issuing authorities where applicable
  • Confirming insurance coverage directly with providers
  • Conducting site observations or audits
  • Speaking with referees about past performance

These steps help ensure that contractors are not just compliant on paper, but competent in practice.

Prequalification Should Be Ongoing

In Australia’s high-risk industries, conditions can change rapidly. That’s why contractor prequalification should be treated as a continuous process, not a one-off task.

A more effective approach includes:

  • Regular reviews of contractor documentation
  • Automated alerts for expiring licences and insurances
  • Monitoring incident reports and near misses
  • Periodic reassessment based on project risk

This dynamic model aligns more closely with WHS expectations and helps organisations stay ahead of potential issues.

Using Technology the Right Way

Digital prequalification platforms are becoming increasingly common across Australia, particularly in sectors like construction and energy. While these systems can streamline administration, they shouldn’t be used as a shortcut.

The real value of technology lies in:

  • Providing visibility over contractor compliance status
  • Enforcing document currency through automated reminders
  • Highlighting gaps or inconsistencies in submissions
  • Supporting ongoing monitoring and reporting

Technology should enhance decision-making—not replace critical thinking.

A Shift Towards Risk-Based Thinking

To strengthen contractor prequalification, Australian businesses need to shift their mindset from compliance to risk management.

Instead of asking, “Have we collected everything?”, the better question is, “Is this contractor genuinely capable of doing the job safely and effectively?”

This means considering factors such as:

  • The complexity and risk level of the work
  • The contractor’s track record and experience
  • Their safety culture and leadership
  • Their ability to adapt to changing site conditions

A risk-based approach ensures that higher-risk work receives greater scrutiny, rather than treating all contractors the same.

Building a More Robust System

A stronger contractor prequalification framework in Australia should include:

  1. Baseline document collection to meet regulatory requirements
  2. Verification processes to confirm accuracy and authenticity
  3. Ongoing monitoring aligned with WHS obligations
  4. Risk-based assessments tailored to specific work activities
  5. Continuous improvement driven by performance data

This approach not only supports compliance but actively reduces the likelihood of incidents and disruptions.

Final Thoughts

In Australia’s regulatory environment, paperwork is essential—but it’s only the starting point.

True contractor prequalification goes beyond documents to assess real-world capability, behaviour, and risk over time. Businesses that move past the “paper chase” mindset are better equipped to protect their workers, meet their WHS duties, and deliver successful projects.

Because when it comes to contractor management, what happens on-site matters far more than what’s sitting in a folder.

This is explored further in our Contractor and Supplier Compliance Management Guide.

Sherm Software manages all of your Contractor and Supplier requirements, from monitoring incidents reported to notifications sent when expiry dates are approaching for documentation supplied.  Get in touch and let us help you make periodic reassessment much easier.

ISO 45001 vs WHS Act: What Businesses Get Wrong

Many Australian businesses assume that if they’re certified to ISO 45001, they’ve “covered” their legal WHS obligations.

Others assume that if they comply with the WHS Act, there’s no need to worry about ISO certification.

Both assumptions are wrong.

Understanding the difference between ISO 45001 and Australia’s WHS legislation — and how they intersect — is critical to avoiding compliance gaps, wasted effort, and audit findings.

The Legal Foundation: The WHS Act

Australia’s work health and safety laws are built around the model Work Health and Safety Act 2011, adopted (with variations) across most states and territories.

The WHS Act:

  • Is law
  • Imposes mandatory duties
  • Creates enforceable obligations
  • Carries penalties for non-compliance

It establishes the primary duty of care for a PCBU (Person Conducting a Business or Undertaking) and requires risks to be eliminated or minimised so far as is reasonably practicable.

Regulators such as SafeWork NSW and WorkSafe Victoria enforce compliance.

Failure to comply can result in improvement notices, prohibition notices, fines, or prosecution.

The International Standard: ISO 45001

ISO 45001 is an international management system standard published by International Organisation for Standardisation.

It is:

  • Voluntary (unless contractually required)
  • A framework for managing OH&S risks
  • Audited by certification bodies
  • Focused on systems and continual improvement

It does not replace or override legal obligations.

The Core Difference

WHS Act = What you must do (legal duties)

ISO 45001 = How you can structure your system to manage those duties

One is law.

The other is a management framework.

Confusing the two is where businesses go wrong.

What Businesses Commonly Get Wrong

  1. “We’re ISO Certified, So We’re Legally Compliant”

ISO 45001 requires organisations to identify and comply with applicable legal requirements — but certification does not guarantee legal compliance.

Auditors assess whether you have a system to manage compliance. Regulators assess whether you are actually compliant.

An organisation can pass an ISO audit yet still breach the WHS Act.

Certification bodies do not enforce legislation — regulators do.

  1. Treating ISO as a Paper Exercise

Some businesses implement ISO 45001 purely for:

  • Tender eligibility
  • Prequalification
  • Client expectations

They build extensive documentation but fail to ensure controls are embedded operationally.

ISO 45001 emphasises:

  • Leadership commitment
  • Worker consultation
  • Risk-based thinking
  • Continual improvement

If documentation exists without real implementation, both ISO auditors and regulators will identify the gap.

  1. Ignoring Officer Due Diligence

The WHS Act imposes personal duties on officers (e.g. directors and senior executives).

ISO 45001 requires leadership involvement — but it does not create personal criminal liability.

Some businesses mistakenly believe board-level review for ISO purposes automatically satisfies WHS due diligence.

Due diligence under the Act requires officers to:

  • Acquire knowledge of WHS matters
  • Understand operations and risks
  • Ensure resources are provided
  • Verify controls are implemented

That verification element is where many organisations fall short.

  1. Confusing Risk-Based Thinking with “Reasonably Practicable”

ISO 45001 uses risk-based thinking to manage OH&S risks.

The WHS Act uses the legal test of “so far as is reasonably practicable.”

These concepts overlap — but they are not identical.

The legal test considers:

  • Likelihood of hazard or risk occurring
  • Degree of harm
  • What the person knows (or should reasonably know)
  • Availability and suitability of controls
  • Cost relative to risk

If risk assessments don’t reflect this reasoning, legal defensibility may be weak — even if ISO processes exist.

  1. Over-Documenting to Satisfy ISO

ISO 45001 does not require excessive paperwork.

Yet many organisations create:

  • 100+ page manuals
  • Multiple redundant forms
  • Complex approval pathways

The WHS Act does not require elaborate documentation either — it requires effective risk management and control.

Over-complication often creates implementation gaps.

  1. Failing to Integrate Psychosocial Risk Management

Australian regulators are increasingly focused on psychosocial hazards (e.g. bullying, workload, fatigue).

While ISO 45001 covers psychological health risks in scope, many organisations:

  • Focus heavily on physical safety
  • Fail to systematically assess psychosocial risks
  • Lack documented controls

Regulators are far more likely to issue notices for these failures than ISO auditors are to withdraw certification.

Where ISO 45001 Adds Value

When implemented properly, ISO 45001 strengthens WHS compliance by:

  • Creating structured governance
  • Formalising consultation mechanisms
  • Improving documentation control
  • Embedding continual improvement
  • Driving leadership accountability

In mature organisations, ISO becomes a tool to demonstrate WHS compliance — not a substitute for it.

A Practical Comparison

WHS Act ISO 45001
 Mandatory law  Voluntary standard
 Enforced by regulators  Audited by certification bodies
 Breaches can lead to prosecution  Nonconformities affect certification
 Focus on duties and risk control  Focus on systems and improvement
 Personal liability for officers  Organisational certification only

The Smart Approach

Australian businesses should:

  1. Treat the WHS Act as the baseline requirement
  2. Use ISO 45001 as a structured framework
  3. Ensure risk management aligns with the “reasonably practicable” test
  4. Embed leadership accountability beyond symbolic review
  5. Focus on implementation, not paperwork

Final Thoughts

ISO 45001 and the WHS Act are not competitors.

They operate at different levels:

  • The WHS Act defines your legal duty.
  • ISO 45001 provides a management system to help meet that duty.

Businesses get into trouble when they mistake certification for compliance — or treat compliance as a tick-box exercise.

In Australia, the safest position is this:

Build a WHS system that genuinely manages risk and meets legislative duties.

Then use ISO 45001 to strengthen, structure, and continuously improve it.

Get in touch with us today and see how Sherm Software and Safety for Life can help.

Our Audit Readiness Guide explains how businesses can design systems that withstand multiple audit regimes simultaneously.

Why Spreadsheets and Shared Drives Stop Working for Audit Readiness

For many Australian businesses, spreadsheets and shared drives start as practical solutions for managing compliance evidence, policies, and audit documentation. They are familiar, inexpensive, and flexible.

But as organisations grow and regulatory expectations increase, these tools often become the very thing that slows down — or jeopardises — audit readiness.

From ISO certifications to industry-specific regulations and internal governance reviews, businesses across Australia are finding that spreadsheets and shared folders simply cannot keep up with modern audit requirements.

Let’s explore why.

  1. Version Control Becomes a Nightmare

In a spreadsheet-based compliance system, multiple people often update documents simultaneously.

This creates problems like:

  • Multiple file versions (e.g. RiskRegister_v5_FINAL_FINAL.xlsx)
  • Uncertainty about which document is the latest
  • Edits being overwritten
  • Important changes going untracked

During an audit, this leads to confusion and delays when auditors ask a simple question:

“Which version of this control was in effect during the review period?”

Without clear version history, proving this can become difficult.

  1. Evidence Is Scattered Across Systems

Audits rely heavily on evidence.

However, when organisations rely on shared drives, audit evidence is often spread across:

  • Email attachments
  • Different folders on network drives
  • Personal desktop files
  • Team collaboration tools
  • Individual spreadsheets

This fragmentation creates a huge administrative burden during audits. Teams spend hours — sometimes days — searching for documentation instead of demonstrating compliance.

Worse still, critical evidence can be accidentally missed.

  1. No Clear Ownership or Accountability

Compliance tasks typically involve many people across different teams:

  • IT
  • Finance
  • HR
  • Operations
  • Risk and compliance teams

In spreadsheets and shared drives, responsibilities are rarely structured. Tasks might be written in a sheet, but there’s usually no system enforcing:

  • Ownership of controls
  • Deadlines for reviews
  • Automated reminders
  • Escalation when tasks are overdue

Without clear accountability, controls that look complete on paper may actually be outdated or untested.

  1. Limited Audit Trail

Auditors want to see a clear trail of activity.

They need to know:

  • Who updated a policy
  • When a risk assessment was last reviewed
  • When a control was tested
  • What changes were made

Spreadsheets rarely provide a reliable audit trail, especially when files are downloaded, copied, or edited offline.

This lack of traceability raises questions about the integrity of compliance records.

  1. Scaling Becomes Impossible

A spreadsheet-based compliance approach may work when a business has:

  • One certification
  • A small team
  • Limited regulatory exposure

But as organisations expand, compliance requirements multiply. Businesses may need to manage:

  • Multiple standards
  • Several audits each year
  • Hundreds of controls
  • Dozens of evidence requests

At this point, spreadsheets become unmanageable. Teams end up maintaining multiple disconnected trackers that quickly fall out of sync.

  1. Audit Preparation Becomes a Fire Drill

Perhaps the biggest problem with spreadsheet-driven compliance is what happens before an audit.

Instead of being continuously audit-ready, teams scramble to prepare documentation:

  • Evidence is chased across departments
  • Controls are quickly re-reviewed
  • Policies are updated at the last minute
  • Teams rush to assemble audit folders

This reactive approach increases stress, wastes time, and increases the risk of non-conformities.

  1. Lack of Real-Time Visibility

Executives and compliance leaders need a clear view of risk and compliance status.

However, spreadsheets rarely provide real-time insight into:

  • Which controls are overdue
  • Which risks are increasing
  • Which departments are behind on reviews
  • What evidence is missing

Without this visibility, compliance management becomes reactive instead of proactive.

What Modern Audit-Ready Organisations Do Differently

Organisations that consistently pass audits with minimal disruption typically move beyond spreadsheets and shared drives.

Instead, they implement structured compliance systems that provide:

  • Centralised evidence management
  • Automated control tracking
  • Built-in audit trails
  • Clear ownership and accountability
  • Real-time compliance dashboards

This allows teams to maintain continuous audit readiness, rather than preparing only when an audit is scheduled.

The Bottom Line

Spreadsheets and shared drives are useful tools — but they were never designed to manage complex compliance frameworks or support audit readiness.

As Australian businesses face increasing regulatory expectations, relying on manual systems becomes risky and inefficient.

Moving toward a more structured approach to compliance management helps organisations:

  • Reduce audit stress
  • Improve accountability
  • Save time during reviews
  • Strengthen governance and risk management

And most importantly, it ensures that when auditors arrive, the business is already prepared.

Get in touch with us today and see how Sherm Software can help with that preparation.

Our Audit Readiness Guide explains what scalable, audit-ready systems look like in practice.

Audit Evidence: What to Keep, What to Drop, What to Digitise

If you’ve ever prepared for a WHS audit, you know the temptation: keep everything.

Folders expand. Shared drives overflow. Email chains get archived “just in case.”

But experienced auditors don’t reward volume — they look for relevance, reliability, and traceability.

Whether you’re preparing for a regulator interaction, client audit, or certification against ISO 45001, here’s how to decide what audit evidence to keep, what to drop, and what to digitise.

First: What Counts as “Audit Evidence”?

Audit evidence is any information that demonstrates your WHS management system:

  • Meets legal requirements (e.g. Work Health and Safety Act 2011 and state equivalents)
  • Is implemented in practice
  • Is effective and reviewed

Evidence must be:

  • Accurate
  • Current
  • Accessible
  • Traceable

If it doesn’t support those criteria, it’s probably clutter.

What to Keep

These are documents and records that auditors consistently request and rely on.

  1. Core Governance Documents

Keep:

  • WHS policy signed by senior leadership
  • Roles and responsibilities
  • Organisational chart
  • Legal compliance register
  • Risk management procedure

These demonstrate structure and accountability.

  1. Risk Management Records

Keep:

  • Current risk assessments
  • SWMS (where applicable)
  • Hazard registers
  • Control implementation records
  • Review evidence

Important: Outdated risk assessments that no longer reflect operations should be archived — not active.

  1. Training and Competency Records

Keep:

  • Induction records
  • High-risk work licences
  • Verification of competency (VOC)
  • Refresher training logs
  • Supervisor competency evidence

Auditors look for proof that workers are competent at the time of work, not just when they were first hired.

  1. Incident and Corrective Action Records

Keep:

  • Incident reports
  • Investigation findings
  • Root cause analysis
  • Corrective action tracking
  • Evidence of close-out

What matters most is showing that actions were implemented and verified.

  1. Consultation Evidence

Keep:

  • Safety committee minutes
  • HSR records
  • Toolbox talk records
  • Worker consultation feedback

WHS legislation places strong emphasis on consultation — auditors expect to see evidence of it.

What to Drop (or Archive Properly)

Not all documents need to stay in your active audit folder.

  1. Superseded Policies and Procedures

If a document has been replaced:

  • Archive it with version control
  • Remove it from operational folders
  • Ensure only current versions are accessible

Auditors often identify “document control failures” when outdated procedures remain in circulation.

  1. Redundant Forms

Many organisations collect forms no one reviews:

  • Pre-start checklists never analysed
  • Hazard reports with no follow-up
  • Meeting minutes no one reads

If a record doesn’t inform decisions or improvements, question why it exists.

  1. Excessive Email Evidence

Email chains are weak audit evidence unless:

  • They demonstrate formal approval
  • They verify a decision
  • They confirm action completion

Where possible, convert critical decisions into controlled records.

  1. Duplicated Records

If information exists in multiple systems:

  • Choose one “source of truth”
  • Eliminate manual duplication
  • Reduce reconciliation errors

Duplication creates audit risk.

What to Digitise

Digitisation isn’t just about convenience — it improves traceability and audit readiness.

  1. Training Registers

Move from spreadsheets to:

  • Centralised training management systems
  • Automated refresher alerts
  • Licence expiry tracking

This reduces non-compliance risk.

  1. Risk Registers

Digital risk systems allow:

  • Version control
  • Review tracking
  • Control verification
  • Dashboard reporting

Auditors appreciate systems that clearly show when risks were last reviewed.

  1. Corrective Action Tracking

Manual spreadsheets often fail because:

  • Actions aren’t assigned clearly
  • Deadlines aren’t monitored
  • Close-outs aren’t verified

Digital systems provide accountability and audit trails.

  1. Contractor Management

Digitise:

  • Prequalification documents
  • Insurance currency
  • SWMS approvals
  • Induction records

This is especially valuable for construction, logistics, and multi-site businesses.

How Long Should You Keep WHS Records?

Retention requirements vary depending on the type of record and state legislation, but common examples include:

  • Incident records involving serious injury: often 5+ years
  • Health monitoring records (e.g. asbestos exposure): decades
  • Training records: duration of employment + additional period

Always align with applicable WHS regulations and industry-specific requirements.

The “Audit-Ready” Test

Ask these five questions about any document:

  1. Does this demonstrate compliance or effectiveness?
  2. Is it current?
  3. Is it controlled (versioned and authorised)?
  4. Can we retrieve it within minutes?
  5. Does it show follow-through, not just intent?

If the answer is “no” to most of these, reconsider its place in your system.

The Biggest Mistake Businesses Make

They build systems for the audit — not for the business.

Auditors (including those assessing against ISO 45001) are trained to detect:

  • Over-documented systems
  • Forms created purely for compliance
  • Records that exist but aren’t used

Strong evidence is:

  • Simple
  • Relevant
  • Consistent
  • Embedded in daily operations

Final Thoughts

Good audit evidence isn’t about volume — it’s about clarity and control.

Keep what proves your system works. Drop what adds noise. Digitise what improves visibility and accountability.

An audit-ready organisation isn’t the one with the most folders. It’s the one where evidence is accurate, current, and easy to find — every day, not just before the auditor arrives.

Sherm Software will help you to become an audit-ready organisation, book a demo today to see how.

Our Audit Readiness guide explains how businesses can design systems that withstand multiple audit regimes simultaneously.