top of page
Search

Occupational Health Safety Gap Analysis Explained

Writer: Mohamed Mabrook Abdul Hameed
Mohamed Mabrook Abdul Hameed
Jul 31
6 min read

A missed permit, an outdated risk assessment or an untrained contractor can turn a routine site visit into a serious incident, a DOSH issue or a lost tender opportunity. An occupational health safety gap analysis gives Malaysian organisations a clear view of where their current practices fall short, what requires immediate control and what is needed to achieve ISO 45001 readiness without wasting effort on paperwork that does not improve safety.

For managing directors and operational leaders, the value is not simply a list of non-conformities. A properly conducted analysis converts safety obligations into a practical implementation plan: assigned owners, realistic deadlines, suitable evidence and controls that work on the shop floor, site, warehouse, clinic, kitchen or office.

What an occupational health safety gap analysis does

A gap analysis compares what your organisation currently does against defined requirements. In an occupational health and safety context, these requirements normally include ISO 45001, applicable Malaysian legislation and DOSH expectations, client or principal-contractor conditions, and your own operational risk profile.

The result should answer three direct questions. What is already effective? What is missing or inconsistent? What must be done first to reduce risk and demonstrate compliance?

This is different from a certification audit. A certification audit determines whether a management system conforms to a standard and whether it is ready for certification. A gap analysis is a preparatory diagnostic. It is designed to find weaknesses early, explain their operational impact and give the business time to correct them before an external auditor, regulator or client identifies them.

The distinction matters. Treating a gap analysis as a box-ticking exercise often produces a large action register but little improvement at site level. Treating it as a management tool helps leaders make proportionate decisions about resources, training, maintenance, supervision and documentation.

Where gaps commonly appear

Most businesses have some safety controls already in place. Toolbox talks may be held, PPE may be issued and incident forms may exist. The problem is usually that these activities are not consistently planned, recorded, evaluated or connected to the organisation's most significant risks.

In construction and logistics, the gaps may involve contractor control, traffic management, work at height, lifting operations, machinery guarding or emergency arrangements. In manufacturing, recurring issues include chemical management, lock-out procedures, preventive maintenance and competent-person records. Healthcare, hospitality and food operations may need closer control of manual handling, sharps, cleaning chemicals, slips, stress and fatigue.

Across sectors, an assessor will often find four connected weaknesses: risk assessments that no longer reflect actual work, legal obligations that have not been systematically reviewed, training records that do not prove competence, and corrective actions that are raised but never verified as effective.

None of these findings automatically means an organisation has an unsafe workplace. It does mean leadership lacks reliable assurance that controls are adequate and consistently applied. That assurance is central to ISO 45001 and to sound operational governance.

The right scope before assessment begins

A useful occupational health safety gap analysis starts by defining its scope. This means identifying the sites, activities, employees, contractors and services to be included. A single-office business will need a very different assessment from a company operating multiple construction sites, workshops and warehouses.

Scope should also reflect the reason for the exercise. If a business is pursuing ISO 45001 certification, the analysis should cover the full management system, including leadership, worker consultation, planning, support, operations, performance evaluation and improvement. If the immediate concern is DOSH compliance at a specific facility, the review may place greater weight on legal registers, statutory inspections, exposure monitoring, safety committees and site controls.

A narrow scope can provide a fast answer to an urgent issue, but it may miss system-level causes. A full review gives stronger assurance but requires more interviews, documents and site observation. The appropriate approach depends on risk, company size, certification timing and client requirements.

How the assessment should be carried out

Effective assessments combine document review with evidence from actual work. Policies alone do not prove that employees understand emergency procedures; a training matrix alone does not prove that a forklift operator is competent; a risk assessment alone does not confirm that a machine guard is in place.

The assessor should review relevant records, speak with management and workers, observe activities and test whether processes are followed in practice. Worker consultation is particularly valuable. Employees often know which controls are impractical, which procedures are bypassed under time pressure and where near misses are not being reported.

Evidence may include:

  • risk assessments, safe work procedures and permit-to-work records;

  • incident, near-miss, inspection and corrective-action records;

  • competency, induction, refresher-training and contractor records;

  • equipment maintenance, statutory inspection and calibration records;

  • emergency drills, health surveillance and workplace monitoring results.

The objective is not to collect every document available. It is to verify that the system is suitable for the organisation's risks and that the evidence supports what management says is happening.

Turning findings into a prioritised action plan

A long list of observations can create unnecessary delay. Findings should instead be graded according to risk, legal exposure and their effect on ISO 45001 conformity. An unguarded machine, uncontrolled work at height or absent emergency arrangements demands urgent action. A poorly formatted document may need correction, but it should not displace a high-risk control.

Each action should state the requirement, the current gap, the required correction, the responsible person, target date and evidence needed to close it. This makes progress visible to senior management and reduces the common problem of safety actions becoming everyone's responsibility and therefore no one's priority.

For example, if contractor induction is inconsistent, the solution is not merely to create a new induction form. The business may need to define contractor categories, assess competence before appointment, establish site-entry rules, brief supervisors, retain signed records and monitor contractor performance. The document is only one component of the control.

Management should also consider what is sustainable. Buying new equipment may reduce risk quickly but involve capital expenditure and lead times. Revising a procedure may be faster, but only if supervisors can enforce it and workers understand it. The best corrective action is the one that addresses the root cause and can be maintained through normal operations.

Building ISO 45001 readiness from the findings

ISO 45001 requires more than a safety manual. It expects an organisation to understand its context, identify interested parties, establish leadership accountability, consult workers, manage risks and opportunities, evaluate performance and continually improve.

A gap analysis provides the baseline for this work. From there, implementation can follow a focused sequence: close priority safety and legal gaps, establish or refine the documented management system, train relevant personnel, conduct internal audits and management review, then prepare for certification audit.

Documentation should be proportionate. A complex manufacturer with multiple shifts, contractors and hazardous processes requires more detailed operational control than a low-risk professional-services office. Both, however, need clear responsibilities, risk-based controls, evidence of competence and a method for learning from incidents and changes.

This is where external support can reduce friction. Brook and Partners can translate assessment findings into a managed ISO 45001 implementation programme, covering documentation, staff training, internal audit preparation and certification support. The aim is a system that satisfies recognised requirements while remaining practical for the people expected to use it.

Measuring whether the gaps are truly closed

Closing an action in a register is not the same as proving its effectiveness. Once changes are introduced, the organisation should check whether the control is being applied, whether workers understand it and whether the intended risk reduction has occurred.

Useful measures may include completion of statutory inspections, corrective-action closure times, near-miss reporting trends, training competency results, audit findings and repeat incidents. Numbers need context. A rise in near-miss reports can indicate increased risk, but it can also show that employees now trust the reporting process. Leaders should investigate the story behind the data rather than rewarding low reporting figures.

Periodic internal audits and management reviews keep the assessment current as new machinery, processes, contractors, locations or legal obligations emerge. Safety management is not static, particularly in sectors with changing work sites, seasonal labour or rapid growth.

A well-run gap analysis gives leaders a defensible starting point: clear risks, clear ownership and a credible route to compliance. The most valuable next step is to act on the highest-risk findings while the evidence is fresh and before a preventable gap becomes an incident.

 
 
 

Comments


LETS WORK TOGETHER

Brook and Partners Sdn Bhd

SSM No: 202601018420 (1680517-U)

No.2, Jalan Kemuning Damai 32/147M, Kemuning Utama 40460, Shah Alam, Selangor, Malaysia

info@brookandpartners.com.my

www.brookandpartners.com.my

0167074092

  • Instagram
  • Facebook
  • LinkedIn

© 2035 by BizBud. Powered and secured by Wix

Contact us

Whatsapp
bottom of page