Good occupational safety and health (OSH) compliance is good for business — and never more visibly so than when a company goes through an IPO. It protects the people the business depends on, it’s part of what gives the board and shareholders confidence in management, and it’s part of the reputation a company carries into public life. Legal due diligence for an IPO treats OSH as a critical item for exactly these reasons — not because it’s named as a Bursa Malaysia listing criterion (it isn’t). Directors carry personal exposure too: Section 52 of the Occupational Safety and Health Act 1994 (Act 514) makes them personally liable for the company’s OSH offences unless they can prove they exercised due diligence. For a company preparing for an IPO, OSH compliance is worth getting right well before the due diligence team asks the first question — not as a box to tick, but as part of the case for why the company deserves the market’s confidence.
An IPO is the moment a company asks the public, institutional investors, and its own future shareholders to trust its management. A demonstrable, well-run OSH programme is part of how that trust is earned — it signals that the board and management team run a disciplined, well-governed operation, not just that the company has avoided trouble so far. Poor OSH compliance signals the opposite: gaps in oversight, weak internal controls, and an operation that hasn’t been tested against its own risks.
This is also where legal due diligence comes in. The Securities Commission’s Guidelines on Due Diligence Conduct for Corporate Proposals require the due diligence working group — sponsor, reporting accountants, solicitors — to review the issuer’s material contracts, contingent liabilities, ongoing material litigation, and material legal and business risks. A significant DOSH enforcement action, a fatality-related prosecution, or an unresolved improvement/prohibition notice under Act 514 sits squarely inside that review, the same way any other material regulatory exposure would.
In MESH’s experience advising clients preparing for an IPO, this question is usually raised early and bluntly — by the investment bank or corporate/listing adviser running the deal, or by the external legal team conducting due diligence. It’s treated as core regulatory due diligence and a genuine governance signal, not an ESG afterthought.
It’s worth being direct about why this matters, beyond satisfying a due diligence checklist:
This is the reasoning MESH uses with clients preparing for an IPO: OSH compliance isn’t something to tidy up because a regulator eventually requires disclosure — it’s good business, because it protects people first, and builds the board, shareholder, and public confidence a newly listed company needs second.
In practice, a due diligence exercise on OSH compliance typically covers:
A disclosed, well-managed issue reads very differently to a due diligence team than an undisclosed one found later. Companies with a documented history of addressing incidents properly are in a materially stronger position than ones that have simply avoided major enforcement so far.
Act 514 adds a sharper edge to all of this. Section 52 (“Liability of director, etc., of company, etc.”) provides that where a company, LLP, firm, society or other body of persons commits an offence under the Act, any person who at the time was a director, compliance officer, partner, manager, secretary, or other officer responsible for or assisting in the company’s management is deemed guilty of the same offence and liable to the same punishment — unless that person proves the offence was committed without their knowledge or consent, and that they had taken all reasonable precautions and exercised due diligence to prevent it.
For a company preparing for an IPO, this turns OSH compliance into a governance question the board has to be able to answer directly, not delegate away. Due diligence teams — and the board itself — will want to know whether directors could actually make out that due-diligence defence if an incident happened: whether there’s real OSH oversight at board level, clear reporting lines, and documented management involvement, rather than a policy sitting unread in a drawer. Being able to answer that confidently is itself a mark of good governance — the kind that gives a board, and its future shareholders, genuine confidence in management.
A company’s OSH record keeps mattering as a matter of good governance and public reputation well after the IPO itself — Bursa Malaysia’s admission criteria (profit or market-capitalisation thresholds, public shareholding spread, management continuity) don’t name OSH specifically, but every Main Market and ACE Market listed issuer must publish an annual Sustainability Statement, and Bursa is in the middle of moving that disclosure from a fixed “Health and Safety” indicator set (number of work-related fatalities, lost time incident rate, employees trained) towards a materiality-based approach aligned with Malaysia’s National Sustainability Reporting Framework (NSRF) and IFRS S1/S2, phased in from financial years ending 31 December 2025 (larger Main Market issuers) through 2027 (ACE Market). The mechanics matter less than the underlying point: once public, a company’s safety record becomes something shareholders, analysts, and the public can see and judge on an ongoing basis — one more reason it pays to have the substance in place well before the IPO, not just the disclosure.
The point of getting ahead of this is building genuine board and shareholder confidence on your own timeline, rather than scrambling to fix gaps once an IPO due diligence exercise is already underway. Before your IPO:
Both. It protects the people working for the company, which matters on its own terms. But it’s also a genuine positive: a demonstrable, well-run OSH programme signals disciplined governance to the board, to investors, and to the market — the same maturity institutional investors and analysts look for when assessing a company going public. Treated well, it’s part of the trust story a company tells at IPO, not just a risk to manage.
Because an unresolved OSH issue is first a real risk to the people working for the company, and second a reputational and financial risk to the company itself at the moment it has the most public visibility. Legal due diligence treats it as a critical compliance item for exactly that reason.
Not as a standalone admission criterion — Bursa’s listing tests are financial and governance-based. OSH becomes directly relevant through legal due diligence (material litigation and regulatory risk) before the IPO, and through annual sustainability reporting after listing.
Yes. Material litigation and regulatory risk are reviewed as part of IPO due diligence, and an unresolved or undisclosed OSH issue is the kind of matter that can affect timing, pricing, investor confidence, or disclosure in the prospectus.
Yes. Section 52 of Act 514 makes directors, compliance officers, partners, managers and other officers responsible for a company’s management personally liable for the company’s OSH offences, unless they can prove the offence happened without their knowledge or consent and that they exercised due diligence to prevent it. This is one of the first governance points a listing adviser or legal due diligence team will probe.
It becomes part of the annual Sustainability Statement every Main Market and ACE Market issuer must publish, with Bursa Malaysia moving from a fixed indicator set towards a materiality-based approach under the new National Sustainability Reporting Framework, phased in from FYE 31 December 2025 through 2027 depending on market and size.
Yes. MESH works with companies preparing for an IPO to get OSH compliance in order well before due diligence begins, including: