On top of the OSHA expansion, DOSH announced the Occupational Safety and Health Master Plan 2026–2030 (OSHMP30) in February 2026 — a national strategy targeting a 15% reduction in workplace accidents by 2030, with significantly stronger enforcement and new focus areas like psychosocial hazards and climate-related occupational risks.

For Malaysian employers, the question is no longer whether workplace safety applies to you. It does. The question is whether your current systems are adequate — and that's exactly where ISO 45001 certification becomes your most valuable compliance tool.

⚠️ Penalty Alert: RM500,000 Maximum Fine

The amended OSHA raised penalties tenfold. Maximum fines are now RM500,000 for general offences, and company directors can be held personally liable under Section 52. DOSH has signalled more frequent audits and stronger enforcement under OSHMP30.

What Changed: The OSHA Amendment Act in Plain English

Before the amendment, Malaysia's Occupational Safety and Health Act 1994 applied primarily to ten specific industries — manufacturing, mining, construction, and similar high-risk sectors. If you ran an office-based business, a retail store, or a professional services firm, you were largely outside DOSH's enforcement scope.

That era is over. The Occupational Safety and Health (Amendment) Act 2022, which came into force on 1 June 2024, removed the industry-specific limitations. The Act now applies to every place of work in Malaysia, with very limited exceptions.

Three Thresholds Every Employer Must Know

Threshold Requirement Details
5+ employees Appoint an OSH Coordinator Must be a competent person responsible for coordinating safety and health activities. Written OSH policy also required.
Gazetted industries Register a Safety and Health Officer (SHO) Applies to gazetted classes including construction projects above RM20 million. SHO must be registered with DOSH.
40+ employees Establish a Safety & Health Committee Must include employer and worker representatives. Regular meetings with documented minutes required.

Key Obligations Under the Amended Act

  • Written OSH Policy (Section 16): Every employer with five or more employees must prepare and display a written safety and health policy
  • Hazard Identification, Risk Assessment and Risk Control (HIRARC): Employers must conduct and document risk assessments for all workplace activities
  • Emergency Response Plan (ERP): A documented emergency preparedness procedure must be in place, tested, and communicated
  • Incident Reporting: Workplace accidents, dangerous occurrences, and occupational diseases must be reported to DOSH within prescribed timeframes
  • Worker Consultation: Employers must consult with workers on safety and health matters — now a statutory duty
  • Director Liability (Section 52): Directors and senior officers can be held personally liable unless they prove due diligence

💡 Why This Matters for Non-Industrial Businesses

A trading company in a shophouse, a digital agency on the 21st floor, a five-person accounting firm — all now have the same statutory safety duties that previously applied mainly to factories and construction sites. If you have five or more employees and haven't appointed an OSH Coordinator or written your OSH policy, you're already non-compliant.

OSHMP30: Malaysia's Safety Roadmap Through 2030

DOSH's own data shows occupational injury cases in Malaysia rose from 34,216 in 2022 to 38,950 in 2023 — a 13.8% increase. Fatal occupational injuries reached 324 cases in 2023. Falls from height remain the leading cause of fatal workplace accidents.

OSHMP30 responds to this reality with six strategic thrusts:

Strategic Thrust What It Covers ISO 45001 Alignment
1. Strengthening OSH Governance Tighter enforcement, updated legislation, improved compliance monitoring Clause 5: Leadership & Worker Participation
2. Worker Health & Wellbeing Mental health, psychosocial risks, occupational disease prevention Clause 6.1: Hazard identification including psychosocial hazards
3. Technology & Innovation Real-time monitoring, predictive risk data, digital inspection tools Clause 9: Performance evaluation, monitoring and measurement
4. SME & High-Risk Sector Empowerment Closing compliance gaps in construction, O&G, manufacturing, and SMEs Clause 8: Operational planning and control
5. Future of Work Readiness Gig economy, hybrid work, automation, climate-related occupational risks Clause 4.1: Understanding the organisation and its context
6. OSH Education & Competency Building safety competency from frontline workers to professionals Clause 7.2: Competence; Clause 7.3: Awareness

Notice the pattern: every OSHMP30 strategic thrust maps directly to ISO 45001 clause requirements. This isn't coincidental — OSHMP30 was developed with reference to international standards and ILO conventions. Malaysia ratified the ILO Occupational Safety and Health Convention (No. 155) in 2024, further aligning national policy with the international framework that ISO 45001 is built upon.

Why ISO 45001 Is Your Best Response to These Changes

The OSHA Amendment creates legal obligations. OSHMP30 sets enforcement direction. ISO 45001 gives you a structured system to meet both.

1. Leadership Accountability (Addressing Director Liability)

Section 52 of the amended OSHA makes directors personally liable. ISO 45001 Clause 5 requires top management to demonstrate leadership and commitment — taking overall responsibility, establishing policy and objectives, and integrating OH&S into business processes. This documented evidence of leadership involvement is your strongest defence against personal liability claims.

2. Systematic Risk Management (Beyond the Checklist)

The amended OSHA requires HIRARC. ISO 45001 goes further — Clause 6.1 requires you to identify hazards, assess risks and opportunities, and plan actions on an ongoing basis, not as a one-time exercise. OSHMP30's emphasis on psychosocial hazards and climate-related risks aligns perfectly with ISO 45001's requirement to consider the broader context (Clause 4.1).

3. Worker Consultation That Actually Works

Worker consultation is now a statutory duty. ISO 45001 Clause 5.4 goes beyond the legal minimum — requiring both consultation (seeking workers' views before decisions) and participation (involving workers in hazard identification and OH&S development). DOSH inspectors increasingly ask whether workers are genuinely involved, not just whether a committee exists.

4. Competency Development (Meeting OSHMP30's Education Thrust)

OSHMP30's sixth thrust focuses on OSH education. ISO 45001 Clause 7.2 requires organisations to determine competence, ensure workers are trained, and retain documented evidence. Your ISO 45001 training programmes directly satisfy both certification requirements and OSHMP30's competency agenda — and they're HRD Corp claimable.

5. Continual Improvement (The Competitive Advantage)

Compliance is the floor, not the ceiling. ISO 45001 Clause 10 drives continual improvement — proactively enhancing OH&S performance. This is where safety becomes a competitive advantage, particularly for Malaysian companies in supply chains serving international brands with strict ESG requirements.

Is Your Workplace Compliant with the Amended OSHA?

YHY Consultancy conducts compliance gap assessments for Malaysian organisations of all sizes. Find out where you stand before DOSH finds out for you.

Request Compliance Assessment →

The Environmental Quality Act Connection: Double Compliance Through IMS

Malaysia's environmental compliance landscape has shifted just as dramatically. The Environmental Quality (Amendment) Act 2024, effective 7 July 2024, raised maximum penalties for environmental violations to RM10 million — a 20-fold increase. New offences for unlicensed waste disposal and stricter EIA requirements are now in force.

Additionally, the Environmental Quality (Amendment) Bill 2026 was tabled in the Dewan Rakyat in February 2026, signalling continued legislative momentum.

For organisations holding or pursuing both ISO 45001 and ISO 14001, the answer is an Integrated Management System (IMS) that addresses safety and environmental obligations through unified processes.

With ISO 14001:2026 recently published and ISO 45001 revision underway (expected 2027), now is the ideal time to build or strengthen your IMS.

Practical Compliance Roadmap: What to Do Now

Step 1: Assess Your Current Status

A compliance gap assessment should evaluate:

  • Whether you have a written OSH policy (Section 16 requirement)
  • Whether an OSH Coordinator has been appointed (5+ employees)
  • Whether a safety and health committee exists (40+ employees)
  • Status of your HIRARC documentation
  • Emergency response plan adequacy
  • Incident reporting procedures
  • Worker consultation mechanisms
  • Training and competency records

Step 2: Address Immediate Legal Gaps

If you're missing any statutory requirements — OSH Coordinator, written policy, safety committee — fix these immediately. These are current legal obligations with significant penalties attached.

Step 3: Build a Systematic Framework with ISO 45001

Once immediate gaps are closed, implement ISO 45001 as your management system framework. For most Malaysian organisations, ISO 45001 implementation takes 4-8 months depending on size and complexity, with total investment typically ranging from RM15,000 to RM60,000 including consultancy and certification body fees.

Step 4: Train Your Team

OSHMP30 makes competency development a national priority. Your training plan should include:

  • Leadership briefing: Ensure top management understands their personal liability under Section 52
  • OSH Coordinator training: Equip your appointed coordinator with competency DOSH expects
  • Internal auditor training: Build in-house capability to audit your OH&S management system
  • Worker awareness: All employees must understand hazards, controls, and their right to consultation

All training programmes are available through YHY Consultancy and are HRD Corp claimable.

Step 5: Prepare for What's Coming

ISO 45001 itself is being revised, with publication expected in 2027. Early indications suggest the revision will incorporate mental health, inclusivity, resilience, and planning-of-changes requirements — all aligning with OSHMP30's strategic thrusts. Implementing ISO 45001 now builds a foundation that makes the future transition significantly easier.

✓ Industry-Specific Considerations

Construction (G7 contractors): OSHMP30 names construction as a high-priority sector. Falls from height are the primary enforcement focus. ISO 45001 combined with robust working-at-height procedures is essential.

Manufacturing: The expanded OSHA covers all manufacturing operations. Chemical management, machine guarding, ergonomics, and noise exposure require documented risk assessments.

Services & offices: Don't assume low risk means no obligation. Ergonomic hazards, psychosocial risks (stress, harassment), fire safety, and electrical safety all require assessment and management.

Frequently Asked Questions

Does the OSHA Amendment Act apply to offices and non-factory workplaces?

Yes. Since 1 June 2024, the Act extends to every place of work in Malaysia. If you have employees, you have statutory safety duties — regardless of industry.

What is OSHMP30 and how does it affect my business?

OSHMP30 is Malaysia's OSH Master Plan 2026–2030, announced by DOSH in February 2026. It targets a 15% reduction in workplace accidents by 2030 through six strategic thrusts. While it doesn't create new legal duties directly, it signals where enforcement attention and future legislative amendments are heading.

What are the penalties under the amended OSHA?

Penalties have increased tenfold. The maximum fine is now RM500,000. Directors face personal liability under Section 52. The DOE has similarly raised environmental penalties to RM10 million under the EQA Amendment 2024.

Is ISO 45001 certification legally required in Malaysia?

No — ISO 45001 certification is voluntary. However, it provides a structured framework that comprehensively addresses all OSHA requirements and aligns with OSHMP30. Many government contracts and international supply chains require it.

When do I need an OSH Coordinator versus a Safety and Health Officer?

An OSH Coordinator is required at five or more employees — all workplaces. A registered SHO is required for gazetted industries including construction above RM20 million. A safety committee is required at forty or more employees.

Can I pursue ISO 45001 and ISO 14001 certification together?

Absolutely — this is recommended. Both share the Annex SL structure, making integration straightforward. An IMS reduces duplication, saves costs, and creates a unified compliance framework. YHY Consultancy specialises in IMS implementation.

Is ISO 45001 training HRD Corp claimable?

Yes. ISO 45001 training programmes — awareness training, internal auditor courses, and implementation workshops — are eligible for HRD Corp claims.

Get Your Free Workplace Safety Compliance Assessment

YHY Consultancy helps Malaysian organisations of all sizes achieve ISO 45001 certification and full OSHA compliance. Practical, efficient, and HRD Corp claimable.

Contact YHY Consultancy Today →