Documentation Policy and Procedures: WHS Guide 2026

Expert workplace safety insights and guidance

Safety Space TeamWorkplace Safety

A crew arrives for a crane lift and finds a printed SWMS in the site folder. It looks familiar, so nobody checks the revision register. Later, the supervisor discovers that the crew has been working from a copy that no longer reflects the current lift method. The near miss gets reported, but the failure happened earlier, when the document control system allowed an obsolete procedure to remain usable.

That's the test of documentation policy and procedures. The policy must control work, not just prove that paperwork exists. It needs clear ownership, reliable version control, practical access arrangements, and retention rules that preserve evidence long after the job has finished. Australian guidance consistently treats WHS records as controlled, traceable evidence, not short-term administration. ANU's WHS documentation procedure describes retention of records arising from WHS processes and completion evidence for 10 years after completion, while National Archives guidance includes records that may be transferred as Retain as National Archives.

Table of Contents

Why Most WHS Documentation Sets Fail in the Field

The near miss above isn't unusual. The document may have been approved correctly, but the system failed at distribution. A printed copy sat on a noticeboard, another lived in a supervisor's ute, a subcontractor held a PDF in an inbox, and nobody could identify which version controlled the lift.

The root causes are predictable:

  • Uncontrolled paper distribution: Teams print procedures without recording where copies go or when they must be removed.
  • No named document owner: Everyone assumes someone else will review, update, or withdraw the document.
  • Missing revision details: Field copies don't show a clear document number, revision, issue date, or approval status.
  • Review cycles that never trigger: The procedure has a review date, but no event-based trigger after an incident, design change, plant change, or regulatory update.

An infographic detailing four main reasons why WHS documentation sets fail in a construction site environment.

The policy needs to control the work

A binder on a shelf can't stop an outdated SWMS circulating. A working control set can. It defines which documents exist, who owns them, who approves them, where the master copy sits, how workers access the current version, and what happens to superseded copies.

The failure patterns usually appear together. Procedures become outdated, duty-holder accountability becomes unclear, subcontractors can't access the right documents, and records are retained only until the next audit. That last habit is particularly weak in Australian workplaces, where WHS documentation is built around controlled retention and auditable evidence over multi-year periods. WorkSafe ACT's record-keeping guidance identifies consultation records, orientation records, inspections, incident investigations, first aid records, and corrective-action information as useful safety records.

Field rule: If a supervisor can't identify the current procedure without calling the office, document control has failed.

The fix starts with scope. Then assign ownership, control revisions, set retention rules, and build storage that works across sites, labour-hire teams, and subcontractors.

Setting the Scope and Purpose of Your Documentation Policy

Start with a purpose statement that connects documentation to the PCBU's duty to provide and maintain a work environment without risks to health and safety under section 19 of the WHS Act. It should also recognise the consultation duties in sections 46 to 49, because consultation records are part of the evidence that workers and health and safety representatives had a meaningful opportunity to contribute.

Use one sentence. Name the organisation, the people covered, and the operational outcome. For example: “This policy controls WHS documents and records used by the PCBU, workers, labour-hire personnel, contractors, and visitors so that safe systems of work are current, accessible, understood, and supported by retrievable evidence.”

That sentence gives you a boundary. The policy should cover documents that direct work or demonstrate that WHS processes occurred.

Document TypeIn ScopeOut of Scope
Work instructionsSWMS, SOPs, JSAs, JHAs, task controlsGeneral office administration
Risk informationRisk registers, hazard assessments, change assessmentsCommercial pricing models
Assurance recordsInspection checklists, audit reports, corrective-action recordsFinancial audit files
Event recordsIncident reports, investigation records, first aid recordsHR performance reviews
Competence recordsInductions, training records, licences, verification evidencePayroll and leave records
ConsultationHSR consultation, toolbox records, meeting recordsClient marketing material

Set the boundary across sites and contractors

For a multi-site PCBU, state whether the corporate master applies everywhere or whether each site can issue local supplements. Local documents should add site-specific controls, not override corporate requirements.

Contractor-issued documents need a clear decision rule. Reissue a contractor document under your controlled system when your PCBU relies on it to direct work, when it affects your workers or site controls, or when the document needs local consultation and approval. Keep the contractor's original as supporting evidence, but don't let an unreviewed external PDF become the operative procedure.

Australian businesses sometimes encounter overseas terminology and foreign regulatory references. A useful comparison is what small businesses should know about OSHA, but Australian organisations must still apply the WHS Act, local jurisdictional requirements, SafeWork expectations, and their own duty-holder arrangements.

Roles, Responsibilities and Document Ownership

Assign every document-control action to a person, not an unnamed department. The PCBU remains the policy owner and carries the organisational duty. The senior WHS manager should act as custodian of the master system, while supervisors control field use and workers provide feedback when a procedure doesn't match the task.

The policy should identify the person currently holding each role and a backup. “WHS Manager” isn't enough if nobody knows who acts during leave, project mobilisation, or a sudden incident investigation.

Use a practical RACI structure

For each document, record who drafts, reviews, approves, distributes, withdraws, and audits it. Don't allow one person to draft and approve the same high-risk document. Approval rights must sit with someone who can challenge the control, understands the work, and holds suitable authority.

A SWMS provides a useful example:

  • Engineer: Drafts the work method and identifies technical constraints.
  • Senior WHS manager: Reviews the hazards, controls, consultation evidence, and implementation method.
  • Site manager: Approves the document for the project and confirms resources are available.
  • Supervisor: Controls the field copy, briefs the crew, checks implementation, and reports changes.
  • HSR: Provides the consultation checkpoint and raises worker concerns before work starts.

The PCBU doesn't transfer its legal accountability by delegating an administrative task. Delegation should clarify who performs the task and who checks it, not create a gap between the person doing the work and the person accountable for the system.

A diagram outlining roles and responsibilities for document ownership including PCBU, Senior WHS Manager, and Supervisors.

Put ownership on the document

Every controlled document should show its owner, custodian, approver, issue date, revision, and next review condition. The review condition should include events, not only calendar dates. A plant modification, changed sequence, new subcontractor, incident, non-conformance, or legislative change should force a review.

A document owner isn't the person who wrote the file. It's the person who must make sure the file remains fit for the work.

This approach also supports consultation. Workers and HSRs need a defined route to challenge unclear controls, report field changes, and request a review. Feedback that goes nowhere turns consultation into a signature exercise.

Document Control That Stops Outdated Procedures Spreading

Document control starts with a numbering convention that makes mistakes visible. Use a structure such as project code, document type, sequence, and revision. The exact format matters less than consistency. A supervisor should be able to distinguish a project SWMS from a corporate procedure at a glance.

Record revision history in the document itself. Include the change description, author, reviewer, approver, issue date, and reason for the change. Don't rely on file names like “final”, “final updated”, or “new final”. Those labels create ambiguity and make audit reconstruction difficult.

A four-step infographic illustrating a document control process to prevent the spread of outdated business procedures.

Control the master and the workflow

Maintain one controlled master copy. The custodian should manage permissions so ordinary users can view and download the current document but can't overwrite it. The approval workflow should identify the author, reviewer, approver, and distribution group before release.

A workable sequence is:

  1. Draft the change against the current approved version.
  2. Record why the change is needed.
  3. Consult affected workers, HSRs, supervisors, and contractors.
  4. Complete technical and WHS review.
  5. Obtain approval from the named authority.
  6. Issue the new revision through the controlled source.
  7. Withdraw or mark every superseded copy.
  8. Record implementation and briefing evidence.

If a procedure changes mid-project, treat the release as a field-control event. Mark superseded printed copies OBSOLETE in red, remove them from site boards, vehicles, cabins, and contractor packs, and confirm that the current copy has reached the people doing the work.

Test the failure points auditors notice

Auditors commonly find documents that exist but can't be traced. Uncontrolled USB copies, duplicate PDFs in subcontractor inboxes, and overseas-issued procedures with no local sign-off all create uncertainty about which control applied at the time.

For high-risk construction work, the SWMS must identify the activities, hazards and risks, control measures, and how those controls will be implemented, monitored, and reviewed. Safe Work Australia says it must be prepared before work starts, kept readily available for the duration of the work, and retained for at least two years after a notifiable incident occurs. Safe Work Australia's construction code sets out those requirements.

Retention, Records and Audit-Ready Evidence

Retention rules should answer four questions. What must be kept, where is it stored, who controls access, and what event starts the retention period? Don't put current procedures and completed records in the same category. A current SWMS is an operational control. A signed briefing, inspection, or review record is evidence that the control was implemented.

For SWMS, retain the approved and superseded versions that governed the work, along with consultation, briefing, review, and closeout evidence. Safe Work Australia requires a SWMS for high risk construction work and requires the PCBU to prepare, keep, comply with, and review it, as well as provide a copy to the principal contractor. The SWMS must remain available and followed throughout the project, not merely filed after approval. The Safe Work Australia duty guidance explains these PCBU duties.

Document TypeMinimum RetentionTrigger
High-risk construction SWMSAt least two years after a notifiable incidentThe notifiable incident
WHS process actions and completion evidence10 years after completionCompletion of the action
WHS investigations and inspectionsApply the authorised retention ruleCreation or closure of the record
Audit documentationOrdinarily no shorter than five years from the report dateReport date
Training recordsSet an organisation-specific period linked to engagement and riskCompletion or end of engagement

The table separates verified minimums from internal rules. Don't invent a single universal period for every WHS record. Check the applicable jurisdiction, record class, exposure risk, contractual duties, insurance requirements, and approved authority. Worker injury and exposure records also need access controls because retention doesn't remove privacy obligations.

Make retrieval part of retention

A record that can't be found is weak evidence. Use a consistent index with site, project, task, worker or contractor group, document type, revision, date, and status. Preserve the original evidence where authenticity matters, and restrict editing after closeout.

Australian auditing standards provide a useful benchmark. Documentation should allow an experienced auditor with no prior connection to understand the nature, timing, and extent of the work performed, the evidence obtained, and significant judgements. The standard also addresses confidentiality, safe custody, integrity, accessibility, retrievability, and a retention period ordinarily no shorter than five years from the report date. ASA 230 is not a WHS procedure, but its traceability discipline is exactly what high-risk operations need.

For broader storage planning, this data retention guide for SMBs is useful background. For a WHS-specific rule set, use the document retention policy as a starting point, then tailor it to your record classes and legal duties.

Storage, Access and Multi-Site Distribution

Choose storage based on how work happens, not on what looks tidy in the office. A shared drive may suit a small operation with stable users and disciplined permissions. It becomes fragile when several sites, subcontractors, mobile crews, and offline work are involved.

Storage OptionVersion ControlSubcontractor AccessOffline UseAudit Trail
Shared driveDepends on permissions and naming disciplineUsually manualPossible, but copies can become staleOften limited
Paper registerWeak unless copies are numbered and checkedEasy to hand overStrongSignatures may exist, distribution history often doesn't
Dedicated H&S platformDesigned for controlled masters and revisionsTiered access can be configuredDepends on the platformUsually stronger, if configured correctly

Paper still has a place. Keep controlled printed copies where workers need immediate access, particularly in areas with unreliable connectivity or strict site-board routines. The printed copy needs a document number, revision, issue date, and a check method. Paper without withdrawal discipline becomes a second uncontrolled system.

Shared drives often break at the edges. A subcontractor downloads a PDF, forwards it, and keeps using it after the master changes. Permission groups may be too broad, read receipts may not exist, and the audit trail may show that a file was uploaded without showing who received or understood it.

A practical construction arrangement is hybrid. Use a controlled platform as the source of truth, issue a limited set of printed site copies, and give subcontractors access only to the documents relevant to their work. Record the issue, briefing, acknowledgement, and withdrawal. Don't give every external user access to the entire WHS library.

The same design applies in manufacturing and industrial services, with permissions aligned to plant, shift, role, and contractor scope. Safety Space's document management program is one example of a system designed around policy control, access, and document oversight. Compare it with your existing shared drive and test the result in a live site environment before committing.

Building the Policy Step by Step and Keeping It Alive

Build the policy in an order that exposes gaps early. Each step needs a deliverable and a named owner.

  1. Draft the purpose statement. The PCBU owner signs off the duty boundary and affected worker groups.
  2. Map hazards and work activities. The senior WHS manager links documentation to actual construction, manufacturing, and industrial tasks.
  3. Map SWMS requirements. The construction lead identifies high-risk construction work, including falls over two metres, demolition, asbestos disturbance, confined spaces, deep trenches, explosives, and work near specified pressurised services. Safe Work Australia's high-risk construction guidance lists these trigger categories.
  4. Set the document structure. The custodian defines codes, document classes, revision fields, status labels, and the master register.
  5. Set approval rules. Assign separate drafting, review, consultation, and approval responsibilities.
  6. Define distribution. List sites, roles, contractors, devices, noticeboards, and printed-copy controls.
  7. Roll out training. Supervisors brief workers on finding the current procedure and reporting a mismatch.
  8. Monitor field use. Inspect the footer, revision, access route, briefing record, and actual task behaviour.
  9. Create the improvement loop. Feed incidents, near misses, audits, worker feedback, and corrective actions into controlled revisions.

Use a simple evidence check at every stage. The document footer should show its revision. The approval record should attach to the released version. The distribution log should identify recipients. The field inspection should test whether a worker can locate and explain the current procedure without office assistance.

Keep the control set active

Review the policy on its scheduled cycle, after a serious incident or near miss, after a regulatory change, after a major audit finding, and whenever the organisation changes its sites, plant, process, contractor model, or workforce structure. A calendar reminder alone won't protect the system.

Ask supervisors direct questions:

  • Can the crew find the current SWMS at the work location?
  • Can they identify a superseded copy?
  • Does the procedure match the plant and sequence being used?
  • Can the supervisor show the consultation and briefing evidence?
  • Can a subcontractor access only the documents relevant to its work?
  • Can the custodian retrieve the approved version that applied when an event occurred?

AI can assist with drafting, comparison, and document review, but it can't replace local consultation, technical approval, or PCBU accountability. General background on AI tools for legal document creation may help with tool selection, but don't let an automated draft become a WHS control without competent review. For a controlled starting structure, use the policies and procedures template, then adapt it to your sites, hazards, contractors, and approval chain.

The ANAO's audit lessons show why this discipline matters. Seven of eight procurement audits in 2023–24 included records-management recommendations, or 88%, according to its records-management audit insights. That result reinforces the practical point: policy wording isn't the control. Ownership, evidence linkage, version discipline, access, and retrieval are the control.


Safety Space helps Australian teams manage controlled policies, procedures, forms, records, and multi-site contractor access in one H&S platform. Visit Safety Space to arrange a demonstration and review how your current document system handles revisions, field access, approvals, and audit evidence.

Ready to Transform Your Safety Management?

Discover how Safety Space can help you implement the strategies discussed in this article.

Explore Safety Space Features

Related Topics

Safety Space Features

Explore all the AI-powered features that make Safety Space the complete workplace safety solution.

Articles & Resources

Explore our complete collection of workplace safety articles, tools, and resources.