Integrating Mental Well Being Terrorism Preparedness Into Your bizSAFE Star Audit: The 2026 Complete Implementation Guide

Introduction

Achieving bizSAFE Star status now requires far more than physical hazard control. Under the Code of Practice on WSH Risk Management (Third Revision, 2021), every company pursuing star certification must systematically address mental well-being, terrorism preparedness, and workplace violence as formal risk categories within their safety and health WSH management system. For HR Leaders and WSH Steering Committees in engineering, architecture, and construction consultancies, this represents a fundamental shift in how risk management audits are scoped, documented, and defended.

This guide covers the three pillars of integration-psychosocial hazard assessments, SGSecure terrorism risk protocols, and workplace violence prevention-that now define compliant bizSAFE Level Star performance while helping build a safe workplace. It is designed for organizations already holding or pursuing ISO 45001 certification and a valid bizSAFE certificate, and focuses specifically on practical implementation rather than theoretical overview. Topics outside the Singapore regulatory context (such as GCC-specific OSH frameworks) fall beyond scope, though ISO alignment principles apply globally.

Direct answer: Integration requires systematic risk assessment documentation covering mental health stressors, terror threat scenarios, and violence prevention measures embedded into your ISO 45001-aligned WSHMS programme. Businesses integrate mental well-being and terrorism preparedness into bizSAFE audits by updating their Risk Register, training staff in SGSecure protocols, and demonstrating board-level commitment through management reviews that evaluate both mental health metrics and security preparedness.

By the end of this guide, you will understand:

  • The expanded audit requirements under the 2026 risk management regulations and how they apply to your RM audit

  • How to implement compliant risk assessments that cover psychosocial hazards, terror threats, and violence prevention

  • What documentation and evidence a MOM-approved WSH auditor or SAC accredited auditing organisation will specifically examine

  • How incorporating non-physical risks elevates your safety culture from compliance exercise to genuine bizSAFE Star performance

The image depicts an open office workspace where a team is engaged in a discussion around a conference table, surrounded by safety planning documents. This setting emphasizes the importance of risk management and workplace safety in the context of conducting risk assessments and implementing health management systems.

Understanding the 2026 Expanded Risk Management Framework

The Code of Practice on WSH Risk Management (RMCP), third revision marked a paradigm shift in how Singapore defines workplace safety and health, with the health council helping shape this broader framework. Where previous editions focused almost exclusively on physical, chemical, biological, and ergonomic hazards, the updated framework explicitly requires duty holders to assess and control risks related to mental well-being, disease outbreaks, and terrorism threats. This expansion reflects lessons from COVID-19, rising awareness of psychosocial risks in high risk industries, and Singapore’s national security posture.

For companies on the bizSAFE journey, this isn’t optional guidance, because the framework sits within employer duties under the WSH Act. BizSafe was launched in Singapore in 2007, and the BizSafe framework includes five progressive certification levels-from Level 1 (requiring CEO involvement in safety commitment) through Levels 2, 3, 4, and finally Star. BizSafe STAR requires ISO 45001 certification and a Risk Management Audit Report assessed by a SAC accredited auditing organisation. The Level 3 Risk Management Audit Checklist now includes explicit questions on whether conducted risk assessments address mental well-being, disease outbreaks, and terrorism threats. Companies need to demonstrate managing mental health and terrorism risks through their safety management systems-this is what auditors seek as evidence that policies for mental well-being and emergency protocols are practiced.

The Mental Well-being Component

Psychosocial hazards are aspects of work design, organization, and social environment that can cause psychological or physical harm. In engineering and construction contexts, these include excessive workload during project crunches, role ambiguity across multi-stakeholder coordination, workplace harassment, fatigue from extended site hours, and the psychological stress of complex technical decision-making. These are distinct from clinical mental illness but can lead to burnout, anxiety, depression, and reduced safety performance.

BizSafe now includes mental well-being in risk assessments, and BizSafe mandates formal assessment of psychosocial hazards. Singapore’s adoption of SS ISO 45003:2022 provides guidelines for managing psychological health within an ISO 45001-aligned health management system. The Tripartite Advisory on Mental Health and Well-being at Workplaces (November 2023) further specifies that employers should periodically review employee mental well-being through surveys and focus groups, equip managers to spot distress, and foster psychologically safe cultures. Total WSH integrates mental health into workplace safety protocols, connecting the dots between psychosocial risk control and overall company safety outcomes.

Organizations must include psychosocial hazards like excessive workloads and bullying in risk assessments-and the data underscores why. Singapore’s National Population Health Survey (2022) found that 17.0% of residents aged 18–74 report poor mental health, with work stressors among key contributors. Over 60% of workers fear disclosing mental health issues, making anonymous reporting mechanisms and cultural destigmatization essential components of any credible risk management implementation plan.

SGSecure Terrorism Preparedness Requirements

Terrorism risk assessment under the updated framework requires organizations to plan for threat scenarios, establish evacuation and lockdown procedures, maintain business continuity protocols, and train employees in emergency response. The SGSecure@Workplaces programme encourages every company to register a representative, conduct training in “Run · Hide · Tell” and “Press · Tie · Tell” protocols, and integrate terror preparedness into existing emergency management.

SGSecure integration is not standalone-the SGSecure Guide for Workplaces is officially incorporated into bizSAFE Levels 1–3 and extends through Star. Terrorism threats should incorporate security risk scenarios like terror attacks, suspicious packages, and unauthorized access. For construction sites with high foot traffic, multiple contractors, and delivery vehicles, this means mapping complex escape routes, establishing access control measures, and designating first responder teams trained in both physical first aid and psychological first aid.

The SGSecure framework involves preparing the workforce through training and awareness of emergency protocols-and this contributes directly to Singapore’s overall resilience framework as defined by the Singapore government.

Workplace Violence Prevention Integration

Workplace violence prevention sits at the intersection of mental health and security risk management. It covers internal conflict management (harassment, bullying, interpersonal disputes), external threat assessment (intrusion, unauthorized visitors, disgruntled clients), and preventive intervention protocols (de-escalation training, grievance procedures, victim support).

These three components-psychosocial hazards, terrorism preparedness, and violence prevention-are not separate audit streams. They interconnect within your existing WSHMS structure: psychosocial stressors can escalate into internal violence; external terror threats require both physical security and psychological resilience; violence prevention policies support both mental well-being and security objectives. The risk management plan must treat them as an integrated system for comprehensive risk coverage.

The image depicts a construction site where workers, dressed in protective equipment, are engaged in a safety briefing near safety barriers and access control gates. This scene emphasizes the importance of workplace safety and health, showcasing a proactive approach to risk management and compliance with safety and health standards.

Implementation Framework for Integrated Risk Assessments

Moving from understanding to action requires translating these expanded requirements into your engineering or construction consultancy’s daily operations. The following framework provides a systematic approach to hazard identification, risk evaluation, and risk control across all three pillars.

Mental Health Risk Assessment Integration

Start with systematic identification of psychosocial stressors specific to your work environment. For engineering consultancies, these typically include:

  • Deadline pressure: Project milestones, submission deadlines, tender response windows creating sustained high-intensity periods

  • Multi-stakeholder complexity: Conflicting client requirements, contractor coordination, regulatory submissions generating role ambiguity and decision fatigue

  • Work arrangement stress: Hybrid office/site split, after-hours client calls, travel to remote project locations disrupting work-life balance

  • Technical burden: Design liability, professional indemnity concerns, complex calculations requiring sustained concentration

Documentation requirements include workload analysis records, stress monitoring protocols (such as Singapore’s iWorkHealth tool), and evidence that support systems are available and communicated. Employee Assistance Programs (EAPs) should be part of the psychosocial support frameworks, and their availability must be documented in the risk register. Mental well-being practices include training supervisors to recognize signs of stress and burnout-this is a specific competency that auditors will verify.

Integration with existing safety officer responsibilities means the WSHMS programme lead or risk management champion should coordinate with HR to ensure psychosocial risk data feeds into the same risk register and review cycle as physical hazards. NUS won the WSH CARE Award for mental well-being practices, demonstrating that academic and industry leaders are already setting benchmarks in this space.

Terrorism Risk Scenario Development

Site-specific threat assessment is essential. Construction sites present unique vulnerabilities: open perimeters, heavy machinery that could be weaponized, stored materials (chemicals, fuel), multiple entry points for unauthorized access. Office environments have different profiles: building-level access control, shared tenancy, public-facing reception areas.

Your SGSecure protocol implementation plan should include:

  1. Registering an SGSecure representative who coordinates with authorities and maintains awareness of current threat advisories

  2. Training all staff in “Run · Hide · Tell” (for terror attack response) and “Press · Tie · Tell” (for treating blast/penetrating injuries), with documented attendance records

  3. Mapping escape and lockdown routes for every work location-office, construction sites, and client premises visited regularly

  4. Conducting integrated drills that combine existing fire/evacuation exercises with terror scenarios (e.g., suspicious package, active threat), at least annually

  5. Developing business continuity protocols for maintaining critical operations during and after an incident, tested through tabletop exercises

Emergency response integration means your existing evacuation procedures should include lockdown options, communication cascades should cover both safety and security incidents, and first aid teams should be trained in psychological first aid for trauma response-not only physical injury management.

Workplace Violence Prevention Protocols

Early warning system development requires both structural and cultural elements. Structurally, implement grievance procedures with clear escalation paths, anonymous reporting channels (digital or physical), and defined response timelines. Culturally, the CEO or board director must visibly endorse zero-tolerance policies.

De-escalation training should be integrated with existing bizsafe training programs rather than treated as separate modules. Visitor and contractor management protocols-access logs, identification verification, escort requirements-address external threats while supporting overall site safety.

All violence prevention measures feed into the comprehensive risk register and incident reporting system. Near-misses (verbal threats, confrontations, unauthorized entry attempts) must be captured with the same rigor as physical safety near-misses. Monitoring indicators like absenteeism and near misses is essential for continuous improvement in safety management.

The image depicts a modern office environment featuring emergency evacuation route signs and a first aid station, with employees engaged in reviewing safety procedures displayed on digital screens. This scene emphasizes workplace safety and health, highlighting the importance of risk management and preparedness in the office setting.

Audit Compliance and Documentation Requirements

Understanding what a MOM-approved WSH auditor from a SAC accredited auditing organisation (AO) will specifically examine transforms abstract requirements into concrete preparation tasks. The RM audit for bizSAFE Star is rigorous, and the expanded scope means auditors now evaluate non-physical risks with the same scrutiny as traditional hazards.

Documentation Framework and Evidence Requirements

For audit success, your documentation must demonstrate systematic coverage across all three integrated components. BizSafe Level 3 requires an external audit by a MOM-approved auditor, and Star certification demands even more comprehensive evidence:

  • Risk assessment records for all core work activities (design office work, site visits, temporary works design, client meetings) that explicitly list mental well-being hazards, disease outbreak scenarios, and potential terror threats. These should follow quarterly review cycles at minimum, with additional reviews whenever work activities change.

  • Staff training records for mental health awareness (supervisor recognition of stress/burnout signs, EAP referral procedures), SGSecure protocols (“Run · Hide · Tell,” “Press · Tie · Tell”), and conflict resolution/de-escalation. Records must include dates, attendees, content covered, and competency verification.

  • Incident reporting systems capturing near-misses and preventive interventions across all three pillars-not just physical safety events. This includes reported psychosocial concerns, security incidents, and interpersonal conflicts.

  • Management review documentation showing that the CEO or board director has signed off on policies and that senior management periodically reviews non-physical risk performance metrics. Management reviews should evaluate both mental health metrics and security preparedness-absenteeism trends, survey results, drill performance, and BCP test outcomes.

  • WSH policy documents explicitly covering mental well-being, terrorism preparedness, and violence prevention, communicated to all employees with acknowledgment records.

Internal audits verify implementation effectiveness of mental health guidelines and emergency protocols. This internal audit cycle must produce documented findings and corrective actions, demonstrating the PDCA cycle (Plan-Do-Check-Act) is actively operating.

Risk assessments must explicitly cover psychosocial hazards and security threats under bizSAFE requirements-this is not a suggestion but a compliance obligation.

Auditor Interview Preparation

Beyond documentation, auditors will conduct interviews at multiple organizational levels. Preparation should ensure:

  • General staff can explain what to do during a terror threat (escape routes, lockdown procedures, who to call), where to find mental well-being support resources, and how to report harassment or security concerns

  • Supervisors and managers can demonstrate ability to recognize signs of employee distress, describe escalation procedures, and explain their role in crisis response teams

  • HR and WSH personnel can articulate the full risk management framework, describe how risk assessments are reviewed and updated, and present data on well-being metrics and security drill outcomes

  • Senior management can explain organizational commitment to holistic risk management, describe how board-level reviews incorporate non-physical risk findings, and demonstrate how the company allocates resources for these expanded requirements

Auditors seek evidence that policies for mental well-being and emergency protocols are practiced-not merely documented. Staff competency verification across mental health awareness, terrorism response procedures, and violence prevention protocols is a standard audit component.

Integration with ISO 45001 Requirements

Understanding the alignment between your expanded risk management components and ISO 45001 clauses helps organizations maintain dual compliance with local bizSAFE requirements and international safety and health standards.

ISO 45001 Clause

Mental Well-being Integration

Terrorism Preparedness Integration

Violence Prevention Integration

4. Context of the Organization

Identify psychosocial factors in work environment analysis

Assess terror threat landscape for all operating locations

Evaluate internal/external violence risk factors

5. Leadership & Worker Participation

CEO/board commitment to mental health policy; worker consultation

Senior management endorsement of SGSecure participation

Zero-tolerance policy signed by top executive; WSH programme lead accountability

6. Planning (Risks & Opportunities)

Psychosocial hazard identification in risk register

Terror scenario risk evaluation and BCP development

Violence risk assessment and preventive controls

7. Support (Competence, Communication)

Supervisor training; EAP communication; stigma reduction

SGSecure training records; emergency communication systems

De-escalation training; grievance procedure awareness

8. Operations

Workload management procedures; flexible scheduling controls

Evacuation/lockdown procedures; access control protocols

Incident response procedures; visitor management

9. Performance Evaluation

Mental well-being surveys; absenteeism tracking; health system management metrics

Drill performance; BCP test results; after-action reviews

Incident reports; near-miss analysis; complaint tracking

10. Improvement

Policy updates based on survey findings; risk control adjustments

Protocol refinement from drill lessons; threat landscape updates

Corrective actions from incidents; enhanced prevention measures

This alignment demonstrates that enhanced risk management (RM) strengthens overall certification value. BizSafe STAR requires ISO 45001 certification issued by a Singapore Accreditation Council (SAC) accredited body under a mutual recognition arrangement-the integrated approach ensures your health system management meets both legal compliance obligations simultaneously.

BizSafe helps companies comply with the WSH (Risk Management) Regulations, and companies with BizSafe certification have lower accident rates, demonstrating the tangible value of comprehensive risk management.

Common Implementation Challenges and Solutions

Engineering consultancies implementing integrated risk management typically encounter three significant obstacles. Each has proven solutions that leverage existing organizational capabilities.

Resistance to Mental Health Risk Assessment

The challenge: Cultural stigma around mental health remains substantial-over 60% of workers fear disclosing mental health issues. Management in traditional engineering firms may view psychosocial hazard assessment as outside the remit of workplace safety, treating it as an HR concern rather than a WSH obligation.

The solution: Begin with leadership modeling. When senior management and the CEO or board director openly discuss well-being as a safety issue and participate in mental health awareness sessions, it signals organizational commitment. Implement anonymous reporting systems (digital platforms or physical drop-boxes) to reduce disclosure barriers. Integrate EAPs into existing benefits communication rather than introducing them as standalone “mental health programs.” Use data-absenteeism rates, turnover costs, error frequencies-to demonstrate the business case. Gradual cultural change anchored in measurable outcomes overcomes resistance more effectively than policy mandates alone.

BizSafe Level 4 integrates a comprehensive safety management system, and at this stage organizations should already have the infrastructure to absorb psychosocial risk management processes without creating entirely new systems.

SGSecure Training and Protocol Confusion

The challenge: Staff often confuse SGSecure protocols with standard fire evacuation procedures, or view terror preparedness training as irrelevant to their daily work. Construction sites with high contractor turnover face particular difficulty maintaining consistent training coverage. Coordination with building management and local authorities can be administratively complex.

The solution: Utilize systematic staff orientation that integrates SGSecure components into existing safety induction processes rather than treating them as separate training modules. Combine terror scenario drills with regular evacuation exercises to reinforce protocols without creating drill fatigue. Establish clear escalation procedures with named contacts (SGSecure representative, building security, emergency services) posted at all work locations. For construction sites with main contractors and subcontractors, include SGSecure briefing requirements in subcontractor agreements and site safety plans. Regular drill exercises-at least semi-annually-with structured debriefs capture lessons learned and maintain readiness.

Resource Allocation for Comprehensive Risk Management

The challenge: Training, audits, policy development, mental health support infrastructure, physical security upgrades, and regular drills demand significant investment. Smaller engineering consultancies may lack dedicated WSH staff and budgets for expanded compliance.

The solution: Phased implementation reduces upfront burden. Begin with a gap analysis of your current WSHMS against the updated audit checklist, prioritize the highest-risk gaps, and develop a multi-quarter implementation plan. Leverage existing safety resources-your risk management champion, safety committee meetings, existing training schedules-to embed new components rather than creating parallel structures.

Demonstrate ROI through concrete metrics: companies with BizSafe certification enjoy lower insurance premiums, reduced risk of project delays due to safety incidents, and enhanced tender competitiveness. BizSafe certification is a prerequisite for many government tenders-indeed, BizSafe Level 3 is the minimum for most government tenders-making the investment directly revenue-relevant. BizSafe certification enhances corporate branding and market access, and the bizSAFE logo on marketing collaterals signals maturity to potential clients through the bizSAFE marketplace. BizSafe certification is a de facto license to operate in Singapore’s engineering and construction sectors.

A team of professionals is gathered in a modern meeting room, actively reviewing safety documentation and risk assessment charts as part of their risk management implementation plan. This collaborative effort highlights their commitment to workplace safety and health standards, ensuring legal compliance and effective risk control within their organization.

Conclusion and Next Steps

Integrating mental well-being and terrorism preparedness into your bizSAFE Star audit is not merely an expanded compliance checklist-it transforms your safety culture from reactive physical hazard management to proactive organizational resilience. Companies that embed psychosocial risk assessment, SGSecure protocols, and violence prevention into a unified WSH risk management framework gain genuine competitive advantage: stronger bizsafe recognition, improved safety performance metrics beyond traditional LTIFR, higher employee retention, and demonstrable ESG readiness for clients and investors. The bizSAFE programme, since its launch in Singapore in 2007, has continuously evolved, and the current expanded scope reflects where regulatory requirements and market expectations have converged.

Immediate action steps:

  1. Conduct a gap analysis of your current WSHMS against the RMCP third revision criteria and the updated RM audit checklist-identify which work activities lack risk assessments covering mental well-being, disease outbreaks, or terror threats

  2. Assign clear roles: Designate your risk management champion, SGSecure representative, and mental well-being coordinator; ensure the CEO or board director formally endorses expanded policies

  3. Schedule integrated training for all staff covering mental health awareness, SGSecure protocols, and de-escalation procedures within the next quarter

  4. Update your risk register to include psychosocial hazards, terror threat scenarios, and violence prevention measures for every core work activity

  5. Engage a MOM-approved WSH auditor from a qualified auditing organisation (AO) for a pre-assessment review to identify compliance gaps before your formal bizSAFE application

Related areas worth exploring: Advanced crisis communication systems for multi-site operations, international project risk integration for firms operating across jurisdictions, emerging psychosocial risk factors in remote and hybrid work environments, and the growing convergence of OH&S performance data with ESG reporting requirements under subsidiary legislation and international standards.

Additional Resources

What do you think?

Leave a Reply

Your email address will not be published. Required fields are marked *