A construction-phase risk register is a statutory requirement under the Workplace Safety and Health (Risk Management) Regulations and must remain accessible on site throughout the works. Project managers should start one immediately, populated with risk ID, hazard, likelihood, consequence, score, controls, owner and review date for each entry. Retain every risk assessment record for a minimum of three years from its approval date, as the regulations specify.
TL;DR:
- Record retention requires keeping risk assessment records for at least three years from approval, accessible for MPOL inspection at any time.
- A compliant risk register should include fields like risk ID, hazard, controls, owner, review date, and linkages to permits or method statements, maintained on-site and in the cloud.
- Use a 5×5 matrix to score risks, prioritize high scores for immediate management action, and document the control hierarchy, emphasizing elimination over PPE for severe hazards.
- Continual updating and review are essential, with high-rated risks reviewed weekly and full revisions at scope changes or every three years, linking each risk to specific control actions.
- Smaller projects can rely on spreadsheets, but larger builds benefit from field apps and ePTW systems, with external reviews recommended before audits or tenders to ensure compliance.
Table of Contents
- What Singapore law requires of your risk register
- Essential fields and a practical template schema
- Scoring, prioritizing, and applying ALARP
- The operational workflow from identification to closeout
- Common risks to pre-populate on a Singapore site
- Keeping records audit and tender ready
- Choosing between spreadsheets, apps, and ePTW integration
- How MOSAIC supports the register lifecycle
- What actually separates a compliant register from a useful one
- Get your register reviewed before your next audit
- FAQ
- Sources
What Singapore law requires of your risk register
The statutory foundation for every construction-phase risk register sits in the Workplace Safety and Health (Risk Management) Regulations, which obligate employers, self-employed persons and principals, including main contractors and sub-contractors, to carry out risk assessments for both routine and non-routine work. The regulation is unambiguous about recordkeeping: assessments must be documented and retained for a minimum of three years from the date of approval. Reviews are triggered by any change in scope, a near miss, an incident, or simply the passage of time since the last formal assessment.
This construction-phase register is distinct from the Design for Safety Register, a lifecycle document that captures residual design risks and must be handed over to the building owner at completion rather than closed out when construction ends.
- Risk assessments cover routine tasks and one-off or unusual activities alike.
- Records of each assessment must be kept for at least three years from approval.
- The register must stay available for inspection by Ministry of Manpower officers at any time.
- Non-compliance exposes the principal and contractors to enforcement action, not only the employer.
**Statistic Callout: ** Records must be kept for at least three years from the risk assessment’s approval date, giving inspectors and auditors a clear retention window to check against.
Essential fields and a practical template schema
A compliant register does not need elaborate software, but it does need a consistent schema. The WSH Council’s Code of Practice on Risk Management provides a risk register template with a cover sheet, and building your columns around that structure keeps you aligned with what auditors expect to see.
| Column | Purpose |
|---|---|
| Risk ID | Unique reference for tracking and audit trail |
| Area / activity | Location and task the risk relates to |
| Hazard and cause | What could go wrong and why |
| Consequence | Likely harm if the hazard materializes |
| Likelihood and consequence rating | Numeric scores feeding the overall risk score |
| Existing controls | Measures already in place |
| Additional controls | Actions needed to reach ALARP |
| Owner and due date | Named person and deadline for closing the gap |
| Review date | Next scheduled reassessment |
- Reference method statements and permits-to-work directly in the register so inspectors can trace the paperwork trail.
- Use a consistent file-naming convention (project, date, revision) so version history is traceable.
- Keep a live copy on site and a synchronized backup in the cloud.
Pro Tip: Lock the scoring columns with dropdown lists in Excel or your field app to stop inconsistent manual entries from skewing your risk scores.
Scoring, prioritizing, and applying ALARP
Most Singapore contractors use a 5×5 matrix, scoring likelihood from rare to almost certain and consequence from negligible to catastrophic, then multiplying the two for an overall score. Scores typically bucket into Low, Medium and High bands, with High triggering immediate escalation to site management before work proceeds.
MOM’s guidance on risk management stresses that duty holders apply the hierarchy of control in strict order: elimination, substitution, engineering controls, administrative controls, and personal protective equipment as the last resort. Documenting why a particular control level was chosen, rather than a more rigorous one further up the hierarchy, is how you evidence As Low As Reasonably Practicable to an inspector or tender evaluator.
- Reserve quantitative risk analysis for complex activities such as deep excavation or tower crane erection where a simple matrix undersells the exposure.
- Record the specific reason a control was accepted as sufficient, not just the control itself.
- Revisit scores whenever site conditions, plant, or personnel change materially.
**Statistic Callout: ** MOM guidance places elimination, substitution, engineering controls, administrative controls and PPE in that strict order, meaning PPE should never be the first or only control recorded against a high-severity hazard.
The operational workflow from identification to closeout
Building and maintaining the register is a continuous cycle, not a one-time exercise completed before the first permit is issued.
- Before mobilization, inventory the handover notes from the Design for Safety Professional and convene a risk identification workshop with site supervisors and subcontractor representatives.
- Assign an owner and due date to every identified risk the moment it enters the register, never leaving an entry unassigned.
- Fold toolbox talks and daily briefings into the register’s update cycle, linking each new risk assessment to its corresponding permit-to-work or method statement.
- Review high-rated risks weekly and open action items monthly, with a full formal revision whenever scope changes or at the three-year mark at the latest.
- At project closeout, reconcile the construction-phase register against the Design for Safety Register to confirm residual risks have been correctly transferred for handover.
A step-by-step guide to conducting site risk assessments walks through the identification and owner-assignment steps in more detail for managers building this out for the first time.
Common risks to pre-populate on a Singapore site
Seeding your register with the hazards every Singapore project encounters saves time and reduces the chance of a glaring omission during an inspection.
- Work at height: falls from scaffolding or edges; mandate harnesses, edge protection and permit-to-work before access.
- Excavation and geotechnical risk: collapse or instability, a particular concern on reclaimed land; require shoring plans and daily inspections.
- Lifting operations: dropped loads or crane instability; enforce lifting plans, certified riggers and exclusion zones.
- Moving plant: collisions with pedestrians or structures; separate vehicle and pedestrian routes with signage and banksmen.
- Electrical hazards: shock or arc flash from temporary installations; require licensed electricians and contactors and regular testing.
- Weather exposure: flash flooding and lightning during the monsoon season; suspend outdoor work and monitor forecasts.
- Public interface: pedestrian or traffic conflict near MRT lines or arterial roads; install hoarding and traffic management plans.
- Subcontractor scope conflicts: overlapping work fronts causing uncontrolled interaction; clarify boundaries in the method statement before work starts.
Escalate anything involving deep excavation, heavy lifting near live utilities, or confined spaces to a specialist assessment rather than relying on the standard matrix alone.
Keeping records audit and tender ready
Inspectors and tender evaluators look for more than a populated spreadsheet: they want to see signed risk assessment forms, an action log showing closure dates, linked method statements and permits, and training records that match the people on site.
- Maintain a version history so reviewers can see the register evolving alongside site conditions.
- Keep meeting minutes from toolbox talks and safety committee reviews as evidence of continuous improvement.
- Cross-reference completed actions against their original due dates to show the loop actually closes.
Public-sector tenders now carry heavier weighting for demonstrated WSH technology adoption, including electronic permit-to-work and vehicle safety technology on larger projects, so tender documentation should reflect your technology plan alongside the register itself.
Pro Tip: Before submitting a tender, have someone outside the project team review your register as a mock auditor would, since gaps are far easier to spot from outside the daily workflow.
Choosing between spreadsheets, apps, and ePTW integration
A well-structured spreadsheet remains perfectly adequate for smaller projects, provided someone owns it and updates it consistently. The limiting factor is rarely the software; it is whether anyone is accountable for keeping it current.
- Spreadsheet template: low cost, fast to deploy, works well where one or two people manage updates directly.
- Field apps: better for multi-site operations, allowing toolbox talks and inspections to feed the register in real time.
- ePTW-integrated systems: necessary on larger public-sector projects where permit-to-work and vehicle safety technology adoption is now an explicit tender criterion.
Match the tool to project scale rather than defaulting to the most sophisticated option available; a $2 million renovation rarely needs the same stack as a $300 million infrastructure build.
How MOSAIC supports the register lifecycle
MOSAIC Ecoconstruction Solutions works across the full register lifecycle rather than a single stage of it. The firm’s Design for Safety Professional service bridges the gap between the DfS Register maintained pre-construction and the construction-phase register your site team runs daily, while WSH Audit and Inspection support checks that both are tender and inspection ready.
- Template creation and column structuring aligned to the WSH Council’s Code of Practice.
- Ongoing register maintenance support for teams without a dedicated EHS resource.
- Training for site supervisors on scoring, ALARP documentation and review cadence.
- Handover assistance reconciling the construction-phase register against the DfS Register at project close.
More context on how the two registers interact and where the obligations overlap is available in MOSAIC’s resource on risk register and risk management practices for Singapore businesses.
What actually separates a compliant register from a useful one
Most guidance on this topic treats the risk register as a compliance artifact, something to produce once and defend if an inspector asks. That framing misses the point. A register that only exists to survive an audit tends to be backdated, generic, and disconnected from what is actually happening on site, which defeats its purpose entirely.
The registers that hold up under scrutiny are the ones treated as working documents: updated the same week a risk changes, reviewed by the people actually doing the work, and specific enough that a stranger could read an entry and understand exactly what happened and why a control was chosen. ALARP documentation is where this shows most clearly. Writing “PPE provided” next to a high-severity hazard signals a box-ticking exercise, not genuine hierarchy-of-control reasoning.
If you take one thing from this guide, let it be this: prioritize ownership and review discipline over software sophistication. A plain spreadsheet maintained weekly beats an expensive platform nobody updates.
— Aman
Get your register reviewed before your next audit
If your register needs restructuring, your Design for Safety handover documentation needs tightening, or you simply want a second set of eyes before an inspection or tender submission, MOSAIC’s consultants work directly with Singapore construction teams on exactly these gaps.
Our Design for Safety Professional service handles the DfS side of the register lifecycle, WSH Audit and Inspection prepares your documentation for MOM or tender scrutiny, and EHS Advisory and Documentation support covers template drafting and ongoing register maintenance for teams without a dedicated resource.
- Request a register review ahead of your next scheduled audit.
- Ask about DfS Register handover support for projects nearing completion.
- Get a consultancy quote tailored to your project size and risk profile.
Reach out through MOSAIC’s services to scope the support your project needs.
FAQ
Is a risk register a legal requirement in Singapore?
Yes. The Workplace Safety and Health (Risk Management) Regulations require employers, principals and contractors to conduct risk assessments and keep records, and the WSH Council’s Code of Practice specifies preparing a risk register as the practical means of documenting those assessments.
Is risk assessment required by law on construction sites?
Yes, risk assessment is a statutory obligation for both routine and non-routine work under the Workplace Safety and Health (Risk Management) Regulations. Records of each assessment must be retained for at least three years from approval.
How do you build a risk register from scratch?
Start with columns for risk ID, hazard, cause, consequence, likelihood, score, existing controls, additional controls, owner and review date, following the structure in the WSH Council’s risk management code. Populate it with common site hazards first, then refine entries as site-specific activities and conditions become clear.
How do you conduct a risk assessment on a construction site?
Identify hazards for each task, rate likelihood and consequence using a matrix, and apply controls in hierarchy order, elimination first and PPE last, as outlined in MOM’s risk management guidance. Document the rationale for every control chosen so the reasoning is auditable later.
What is the difference between a Risk Register and a DfS Register?
The construction-phase Risk Register tracks active site hazards and closes out at project completion, while the DfS Register captures residual design risks and remains with the structure for its entire lifecycle, handed over to the building owner at completion.
Sources
- Workplace Safety and Health (Risk Management) Regulations — SSO (AGC)
- Code of Practice on WSH Risk Management — WSH Council
- Risk management — Ministry of Manpower (MOM)



