
What Does DOSH Require From Malaysian Employers?
A workplace incident rarely begins at the moment someone is injured. It usually starts earlier: an unguarded machine, an unclear work instruction, a contractor working without supervision, or a hazard that was noticed but never recorded. For employers asking what does DOSH require, the practical answer is clear: a working safety and health system that identifies risk, controls it, involves employees and produces evidence that duties are being met.
DOSH, the Department of Occupational Safety and Health Malaysia, enforces workplace safety and health legislation. Its expectations apply far beyond heavy industry. Construction sites, warehouses, food operations, healthcare facilities, offices, logistics businesses and manufacturing plants all have duties, although the controls, competent persons and statutory requirements differ according to their activities and risk profile.
What DOSH Requires: A Duty to Manage Risk
At the centre of Malaysian occupational safety and health law is the employer's duty to provide, so far as practicable, a safe workplace. This is not limited to supplying personal protective equipment or putting up safety signs. Employers must consider the whole way work is planned, performed, supervised and reviewed.
In practice, this means providing safe plant and systems of work, maintaining the workplace in a safe condition, controlling exposure to hazards, and giving employees the information, instruction, training and supervision they need. The duty also extends to people who may be affected by the business, such as visitors, contractors, delivery drivers and members of the public.
The Occupational Safety and Health Act 1994, as amended, provides the core framework. Other regulations and industry-specific requirements may apply to machinery, construction work, chemicals, noise, confined spaces, lifting operations, pressure equipment and other higher-risk activities. A small professional-services office will not face the same control measures as a fabrication workshop, but neither can assume it has no safety obligations.
Risk Assessment Must Lead to Real Controls
A risk assessment is often the first document requested during an inspection, tender assessment or client audit. However, its value lies in the action it drives. A generic template copied from another business will not demonstrate that the employer understands its own workplace.
A suitable assessment should identify the hazards in each activity, consider who can be harmed and how, evaluate the level of risk, and establish controls based on the hierarchy of control. Eliminating a hazard or using an engineering control is normally more reliable than relying only on training or personal protective equipment.
For many Malaysian organisations, this process is documented through HIRARC - Hazard Identification, Risk Assessment and Risk Control. The assessment should cover routine work and non-routine tasks, including maintenance, cleaning, emergency work, contractor activity and work conducted off site.
It must also be reviewed when circumstances change. New machinery, a chemical substitution, an incident, revised production methods, workforce changes or a new work location can make an earlier assessment obsolete. DOSH inspectors are likely to look for the connection between identified hazards and the controls actually visible on the floor, site or work area.
Policies, Procedures and Safe Work Instructions
A written occupational safety and health policy is a key requirement for employers within the relevant legal scope, and it should set out management commitment, responsibilities and the arrangements used to control risk. A policy displayed on a noticeboard but unknown to supervisors will not be enough.
Supporting procedures should address the risks of the operation. Depending on the business, these may include permit-to-work arrangements, lockout procedures, emergency response plans, machine-guarding checks, contractor controls, chemical handling instructions and safe lifting methods. The right documentation is proportionate: it should be detailed enough to control work properly, but simple enough for employees to use.
Competent Persons and Safety Representation
Some workplaces must appoint specific competent persons or role holders because of their workforce size, industry classification or exposure to particular hazards. Requirements can involve a Safety and Health Officer, an Occupational Safety and Health Co-ordinator, a safety and health committee, or specialised competent persons for particular technical activities.
For example, organisations managing chemical exposure may need competent assessments and health surveillance arrangements. Work involving excessive noise, confined spaces, lifting equipment or construction activities can introduce further requirements for competent assessment, supervision, inspection or certification.
The precise appointment needed depends on the work carried out, not simply the number of employees. This is where organisations can lose time and incur unnecessary cost by appointing the wrong resource, or by assuming a general safety representative covers a specialist legal role. A proper compliance review should map the organisation's activities, locations, workforce and equipment against the applicable requirements.
Employee consultation matters as well. Workers and their representatives often identify practical issues that management cannot see from reports alone: a shortcut taken to meet production targets, an awkward manual-handling route, or a missing guard that is repeatedly removed. Where a safety and health committee is required, meetings, actions and follow-up should be recorded. Where it is not required, regular consultation remains good evidence of active management.
Training, Supervision and Contractor Control
DOSH expects employees to be capable of carrying out their work safely. Induction training is only the starting point. Training must be relevant to the job, delivered in a language and format workers understand, and refreshed when risks or procedures change.
Supervision is equally important. A trained employee can still be placed at risk if a supervisor permits unsafe methods, rushes a task or fails to enforce a control. Managers and supervisors need to understand their own safety responsibilities, not merely attend an annual awareness briefing.
Contractors require particular attention in Malaysian workplaces. Before allowing a contractor on site, the host employer should assess competence, define responsibilities, communicate site rules and coordinate risk controls. High-risk work should not begin until the method of work, permits, emergency arrangements and supervision are agreed. The principal employer cannot transfer all responsibility simply by issuing a purchase order.
Records That Stand Up to Inspection
Documentation is not compliance by itself, but missing records make it difficult to show that legal duties have been performed. A well-managed DOSH compliance file usually contains the policy, risk assessments, training records, inspection and maintenance logs, meeting minutes, incident investigations, emergency drills and evidence of corrective action.
The records required will vary. A factory may need machine inspection and testing records, while a laboratory may need chemical registers, safety data sheets, exposure assessments and health-monitoring evidence. Construction businesses may need records relating to site safety coordination, equipment checks and worker competency.
Records should be controlled, current and accessible. Backdating forms after an incident or inspection creates a far greater risk than acknowledging a gap and fixing it properly. Auditors and enforcement officers can usually identify when documents do not reflect day-to-day operations.
Incident Reporting and Investigation
Employers must report specified workplace accidents, dangerous occurrences, occupational poisonings and occupational diseases to DOSH under the applicable notification requirements. The reporting route and timing depend on the event, so businesses should have an escalation procedure that enables managers to act immediately rather than debate whether an event is serious enough.
Internal investigation should begin promptly. Its purpose is not to assign blame to the injured person. It is to establish what failed in the system: inadequate training, poor maintenance, unsuitable equipment, weak supervision, unclear instructions or an uncontrolled change in work. Corrective actions should have an owner, a completion date and evidence that they were effective.
Near misses deserve the same discipline. They are often the lowest-cost warning an organisation will receive.
DOSH Compliance Is Not an ISO Certificate
ISO 45001 can strengthen occupational safety and health management, but it does not replace legal compliance. Certification demonstrates that an organisation has an independently assessed management system; DOSH compliance requires the business to meet the applicable Malaysian legal duties in its actual operations.
The strongest approach is to align both. A well-built ISO 45001 system can provide the structure for legal registers, risk assessment, competency management, internal audits, consultation and continual improvement. However, it must be tailored to current DOSH requirements and the organisation's own hazards. A certificate cannot compensate for uninspected equipment, an untrained operator or an unreported incident.
A Practical Route to DOSH Readiness
For organisations with fragmented safety documents or growing operational risk, the fastest route is usually a structured implementation programme. Start with a gap analysis of sites, activities, existing controls and legal obligations. Then develop the required documentation, train the relevant people, carry out workplace inspections and test the system through an initial audit.
This process also identifies where specialist monitoring, testing or competent-person services are required. It avoids the common mistake of treating every workplace alike, while ensuring that critical actions are not delayed by uncertainty over technical regulations. Brook and Partners can support this work through practical DOSH compliance services, technical audits, monitoring and implementation support.
The goal is not to create a larger file of safety paperwork. It is to give managers clear control over risk, employees confidence in how work is done, and the organisation credible evidence that safety is managed before an inspection, tender requirement or incident puts that evidence to the test.



Comments