Self-assessment · 9 questions · about two minutes

bizSAFE Level and Audit-Readiness Triage

Facts checked on 28 September 2026 · how this fits with an audit

Nine questions about your workplace, your records and your auditor. You get the level to aim at, what a Risk Management audit opens with, and the first thing to fix.

Who this is for: a Singapore company that has been asked for a bizSAFE level, or holds one and is not sure it will survive the next audit. It takes about two minutes, and it is scored on things an auditor can see: a trained person, a written plan, dated records, and an independent auditor.

Where a level is asked for

Tenders and contracts commonly ask for bizSAFE Level 3 or above. Level 1 and Level 2 last six months each and cannot be renewed, so they are steps on the way, not answers in themselves. Level 3 and Level 4 last three years. bizSAFE Star is the full safety management system, and it is built on an SS 651:2019 or ISO 45001:2018 certificate.

The questions

1. Which bizSAFE level does your company hold today?

This one is context, not a score. It decides which level to aim at.

2. Is a bizSAFE level actually being asked of you, in writing?

A tender document, a contract clause, a client questionnaire.

3. Has your CEO or a Board Director completed the 3-hour Top Executive WSH Programme?

Required for Level 1, and a legal requirement for the CEO or Board Director of companies in higher-risk sectors.

4. Do you have a trained Risk Management Champion, and are they still with the company?

Level 2 requires a trained RM Champion: the WSQ Develop Risk Management Implementation Plan course (MF-COM-402E-1), or an accepted equivalent.

5. Is there a written Risk Management plan that covers every work activity, not just the obvious risks?

Level 3 recognises risk assessments for every work activity and process your people carry out.

6. Have the risk assessments been reviewed in the last 3 years, or after a change in the work?

The WSH (Risk Management) Regulations require review as and when work activities change, or every 3 years.

7. Can you show the risk assessment records alongside the controls actually in use on site?

The audit checks implementation, not paperwork alone.

8. If you use lorries, are speed limiters fitted?

From 1 January 2026, Risk Management implementation audits include verification checks on speed limiters installed in lorries. A company without them in any of its lorries cannot complete a satisfactory RM audit.

9. Will your auditor be a MOM-registered Auditing Organisation that is entirely separate from your consultancy?

WSHC states that the consultancy organisation and the auditing organisation must be separate and independent, and that applications will be rejected if both come from the same company or are arranged as a package.

What the audit actually looks at

A bizSAFE Level 3 audit is a Risk Management Implementation Audit carried out by a MOM-registered Auditing Organisation, against the bizSAFE Level 3 Risk Management audit checklist. It ranges from half a day to two days, and what it produces is a Risk Management Audit Report: valid for 3 years from the audit date, and only accepted for a bizSAFE application while it has at least 6 months left to run.

The detail that catches firms out is independence. WSHC wording: your consultancy organisation and auditing organisation must be separate and independent, and applications are rejected if both are from the same company or arranged as a package. We will never offer you both, and a consultant who does is proposing something that will be refused.

The dates to know

What this is. A self-assessment of things you can point at: what is written down, who owns it, what is recorded. It is not an audit, not a compliance percentage and not a legal opinion. Ark Private prepares businesses for certification and never certifies, accredits or audits; the certification body or the MOM-registered Auditing Organisation decides. Nothing you select is sent anywhere: the score is worked out in your own browser.

Where these rules come from

Questions people ask about this

Which bizSAFE level do we need for a government tender?

Most government and large-corporate work asks for bizSAFE Level 3 or above, because Level 3 is where the company has implemented risk management across every work activity and had it independently audited. It is not itself a legal requirement, but contracts and tenders commonly make it one in practice. Check the exact wording of your own requirement before spending anything.

Is bizSAFE Star the same as ISO 45001?

Close, and worth getting exactly right. WSHC requires an SS 651:2019 certificate, or an ISO 45001:2018 certificate from a certification body accredited by the Singapore Accreditation Council (or one recognised under a mutual recognition arrangement), submitted with a Risk Management audit report. SS 506 was withdrawn in 2022, so an adviser still naming it is working from an out-of-date copy of the rules.

How long is bizSAFE Level 3 valid?

Three years from the approval date when it is applied for using a Risk Management Implementation Audit Report. Submit the renewal two months before it expires: a lapsed status can take you out of an active tender.

Can one company do our consultancy and our bizSAFE audit?

No. WSHC requires the consultancy organisation and the auditing organisation to be separate and independent, and rejects applications where both are the same company or arranged as a package. We prepare; a MOM-registered Auditing Organisation audits. Anyone offering both is offering you a rejected application.