Case Study

HIRARC Compliance in Malaysia: Meeting OSHA 1994 and ISO 45001 Risk Assessment Requirements​

Switchgear

A Switchgear Manufacturer Case Study — Shah Alam, Selangor

Every employer in Malaysia is legally required to identify workplace hazards and assess the risk they pose. Under Section 18B of the Occupational Safety and Health Act 1994 (OSHA 1994) — inserted by the Occupational Safety and Health (Amendment) Act 2022 and in force since 1 June 2024 — every employer, self-employed person and principal must conduct a risk assessment of the safety and health risks arising from their undertaking, and implement risk control measures where the assessment shows they are needed.

Internationally, ISO 45001 sets the same expectation for certified occupational health and safety management systems. Clause 6.1.2 requires organizations to establish, implement and maintain an ongoing, proactive process for hazard identification and risk assessment. Once risks are identified and rated, Clause 8.1.2 sets out the hierarchy of controls — elimination, substitution, engineering controls, administrative controls, and PPE last.

A Hazard Identification, Risk Assessment and Risk Control (HIRARC) study is the standard method used to satisfy both OSHA 1994 and ISO 45001, breaking every work process into discrete activities, identifying hazards, and mapping each risk to a control on the hierarchy.

The Challenge

The client is an electrical switchgear manufacturer operating a world-class facility in Shah Alam, Selangor. Its production model is Engineered to Order (ETO): rather than running a fixed, repeatable line, the manufacturer designs and builds switchgear to each customer’s specification, which means a high degree of variation across work processes and sub-processes from one order to the next.

That variation is precisely what made the challenge significant. The manufacturer needed a comprehensive, process-level view of workplace hazards across its operations, in line with its obligations under OSHA 1994 Section 18B and its ISO 45001 risk assessment requirements. In an ETO environment, sampling risks missing hazards specific to less common configurations and sub-processes. Without granular, verified data across the full range of variation, risk control decisions would rely on assumption rather than actual on-the-ground conditions.

The Solution

The benefits of conducting HIRARC assessments are immense. They extend beyond compliance with legal requirements to encompass enhanced employee well-being, improved operational efficiency, and the establishment of a proactive safety culture. By identifying and controlling risks before they manifest as incidents, businesses can save lives, reduce costs associated with accidents and downtime, and bolster their reputation as responsible employers.

Assembly of Switchgear

Results

The completed HIRARC gave the manufacturer a process-by-process risk register built from verified on-site data, satisfying both its OSHA 1994 Section 18B risk assessment obligation and its ISO 45001 Clause 6.1.2 requirement, and forming the basis for risk controls applied in line with the ISO 45001 hierarchy.

  • Risk assessments completed: ~1,200
  • Scope: Every work process and sub-process, organization-wide
  • On-site engagement: 80 man-days

Takeaway

HIRARC is not a paperwork exercise — under OSHA 1994 Section 18B it is a legal duty, and under ISO 45001 it is a certification requirement. Exhaustive, activity-level HIRARC assessments require substantial on-site time investment, but they produce a level of granularity that sampled or desk-based assessments cannot match, and they map directly onto the hierarchy of controls that both the law and the standard require organizations to follow.

For organizations running complex, multi-process operations, this kind of comprehensive risk mapping creates a more defensible and actionable safety baseline than a high-level review — and, where possible, a starting point for shifting future projects toward Prevention through Design.

Related Reading

  • Section 18B of OSHA 1994: what “employer,” “self-employed person” and “principal” duties mean in practice
  • ISO 45001 Clause 8.1.2: applying the hierarchy of controls after a HIRARC