Why a Signed HIRARC Doesn’t Protect Your Company From Liability in Malaysia

Ask most HSE Managers what protects their company from liability after an incident, and the answer usually involves a document: a signed HIRARC, a completed risk assessment, a form with the right boxes ticked. It’s an understandable assumption. It’s also incomplete in a way that matters the moment an investigation actually starts.

What a Signature Actually Proves

A HIRARC signed off by a competent Safety and Health Officer proves that a process happened — that hazards were identified, risks were rated, and controls were specified by someone qualified to do so. Under the Occupational Safety and Health Act 1994, as amended in 2022, this documentation is a genuine and necessary part of an employer’s risk management obligations.

What the signature does not prove is that the general duty underneath it was actually discharged. That duty — to protect the safety, health and welfare of employees so far as is reasonably practicable — sits with the employer, not with whoever filled in the form. A HIRARC is evidence that a risk assessment process took place. It is not, on its own, evidence that the risk was actually controlled on the floor.

Where the Gap Shows Up

This distinction rarely matters until something goes wrong. When it does, an investigation — whether internal, by DOSH, or as part of a legal claim — doesn’t stop at the document. It asks whether the control listed on the HIRARC was actually in place, actually resourced, actually maintained, and actually understood by the people expected to use it.

The gap that gets found most often isn’t a missing HIRARC. It’s a HIRARC that correctly identified a risk and specified a reasonable control, where the control existed on paper and nowhere else — never trained, never checked, never followed up after the person who wrote it moved on to the next audit item. The document was accurate about what should happen. Nobody verified it against what actually did.

Why This Distinction Matters for Directors and Managers

For company directors and senior management, this distinction has direct consequences. Liability under Malaysian OSH law doesn’t rest solely with the SHO who prepared the documentation or the supervisor who signed off the shift. It follows the actual conditions the employer allowed to exist — which means the paper trail alone is not a defence if the underlying conditions on site tell a different story.

This is a particularly important point for companies that treat their HIRARC as a compliance artefact — something produced for an audit or a client’s supplier pre-qualification checklist, then filed until the next annual review comes around. A document produced to satisfy a checklist and a document that actually reflects and controls current risk are not automatically the same thing, even when they look identical on the page.

What Actually Closes the Gap

Closing this gap isn’t about writing a more detailed HIRARC. It’s about building the verification loop the document assumes exists but rarely specifies: who checks that each listed control is actually in place, on what schedule, and what happens when a control turns out to exist only on paper. A risk assessment that survives scrutiny ties every control to a named owner and a way to confirm it was delivered — not just described.

It also means treating the HIRARC as a live document that gets reopened when the process changes — a new shift pattern, a different machine, a supplier substitution — rather than only when the calendar says a year has passed. A document that’s technically current by date and quietly wrong about what’s actually happening on the floor offers the same false confidence as one that was never written at all.

The Practical Question

For any HIRARC currently on file at your workplace, the question worth asking isn’t whether it’s signed and dated. It’s whether every control listed on it has a named owner, a verification method, and evidence it was actually delivered — not just documented as a plan.

That distinction — between a risk assessment that describes intent and one that reflects and controls actual conditions — is exactly what separates a HIRARC that protects a company from one that only protects a file.

Want your HIRARC and broader OSH obligations to hold up under real scrutiny, not just an audit checklist? Cikgu Barrier’s OSH Obligations for Management programme is built specifically for directors, HR, and management teams who need to understand where legal duty actually sits under Malaysian OSH law — and what genuinely discharges it. Available in-house and as a public workshop across Malaysia.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top