Your bizSAFE Level 2 Risk Management Plan Is Incomplete — Here’s What Most Singapore Companies Miss
Most Singapore companies walk out of the bizSAFE Level 2 training with a Statement of Attainment in hand and assume the hard part is done.
It is not.
The hard part — the part that actually gets your company through the Level 3 audit without findings — is what you build after the course ends: a bizSAFE Level 2 Risk Management Plan that is specific, top-management-approved, and covers a dimension most newly certified RM Champions do not expect.
Terror threats. Mandatory. In your RM plan. Since 26 September 2017.
If your bizSAFE Level 2 Risk Management Plan does not include documented risk assessments for potential workplace terror scenarios — armed attackers, suspicious parcels, vehicle ramming — with corresponding control measures and response protocols, your Level 3 audit will not go well. The WSH Council’s auditors will check for it explicitly.
This guide covers exactly what the bizSAFE Level 2 Risk Management Plan in Singapore requires, how SGSecure integrates into your RM obligations, and what your company needs to have ready before the Level 2 certificate runs out.

Key Takeaways
- The bizSAFE Level 2 Risk Management Plan requires your trained RM Champion to develop a company-specific RM Implementation Plan and conduct risk assessments for all work activities — not just complete the qualifying course.
- Since September 2017, managing terror threats is a mandatory component of the RM Implementation Plan — not optional, not a separate exercise.
- Your RM Champion must identify at least one plausible terror threat scenario relevant to your workplace and document control measures using the 4Ds framework: Deter, Detect, Delay, Deny.
- At Level 3, auditors will verify four SGSecure deliverables: your WSH Policy, your terror threat risk assessment, your RM Implementation Plan, and employee awareness of “Run, Hide, Tell” and “Press, Tie, Tell.”
What the bizSAFE Level 2 Risk Management Plan Actually Requires You to Produce
The bizSAFE Level 2 Risk Management Plan starts with having a trained RM Champion who can facilitate and mobilise employees to develop an RM Implementation Plan and conduct risk assessments across all work activities.
To qualify, your RM Champion must hold a WSQ Statement of Attainment from one of two courses:
- “Develop Risk Management Implementation Plan” (Course Code MF-COM-402E-1), or
- “Workplace Safety and Health Control Measures” (Course Code WPH-WSH-4075-1.1)
Both programmes are open to supervisors and above. If your RM Champion completed either course at a previous employer, that Statement of Attainment remains valid — provided they are the appointed RM Champion at your current company. You can explore accredited training options and get guidance on next steps through our bizSAFE Level 2 certification consultation page.
But here is what course completion does not do for you: it does not produce the plan itself.
Your bizSAFE Level 2 Risk Management Plan must be a real, company-specific document — approved by top management, identifying hazards, specifying control measures, assigning responsible persons, and setting clear action items. It needs to reflect your actual workplace and your actual work activities, not a recycled template from a different industry. Auditors are experienced enough to spot the difference immediately.
What many RM Champions also overlook is that the plan is a living document. It must be reviewed and updated whenever work activities change or new hazards emerge — and it must include one hazard category that is non-negotiable since September 2017: terror threats. Leaving this out is not a minor administrative gap. It is a gap that will generate findings at your Level 3 audit and, depending on the severity, may require a re-audit before your certification can proceed. The RM Champion owns this. Getting it right is not the auditor’s job — it is yours.
How SGSecure Integrates Into Your bizSAFE Level 2 Risk Management Plan in Singapore
This is where most RM Champions are caught off guard, and where the gap between “attended the course” and “audit-ready” becomes plainly visible.
The WSH Council formally incorporated SGSecure into the bizSAFE framework in September 2017. When building your bizSAFE Level 2 Risk Management Plan, the RM Champion is responsible for conducting a risk assessment to identify potential workplace terror threats and including the management of those threats inside the RM Implementation Plan — the same document that covers your occupational safety hazards. This is not a separate SGSecure workbook. It lives inside your RM plan.
Step 1: Decide What to Protect
Start with human lives — know where employees and premise users congregate throughout the workday. Then identify assets critical to your operations: server rooms, power supply equipment, areas containing sensitive materials. Prioritise protection based on how critical each asset is to maintaining business continuity during and after an incident.
Step 2: Identify the Threats
The SGSecure framework outlines the forms terror attacks can take:
- Armed attackers
- Vehicles used as weapons
- Explosive devices, including improvised explosive devices concealed in suspicious parcels
- Chemical or biological agents
Assess which of these are plausible in your specific context. A night club in Clarke Quay faces different exposure than a warehouse in Tuas or a manufacturing facility in Jurong. Consider what features of your premises increase vulnerability: open public access, proximity to main roads, and areas where people congregate in large numbers.
Step 3: Apply the 4Ds to Your Mitigation Measures
Control measures in your bizSAFE Level 2 Risk Management Plan should follow the 4Ds framework:
- Deter — make your premises a harder target through visible security personnel, controlled access points, and adequate lighting.
- Detect — build systems and staff capability to identify a threat early: CCTV monitoring, training employees to recognise suspicious behaviour or unattended items, and clear reporting procedures.
- Delay — slow an attacker’s ability to penetrate or move through your premises: locked internal doors, physical barriers, and controlled entry protocols.
- Deny — prevent attackers from reaching critical areas or completing their objectives.
Review your existing security measures honestly. Identify gaps between what exists on paper and what is genuinely operational on the ground.
Step 4: Build Your Contingency Response Plan
Beyond risk assessment, your Singapore bizSAFE Level 2 Risk Management Plan requires a documented contingency response plan structured across three phases:
Design it. Your plan must cover how your organisation will detect a threat, lock down premises where feasible, alert all occupants, evacuate via multiple pre-planned routes, and designate safe hiding locations when evacuation is not possible. It must also address how your people will coordinate and link up with the Police.
Familiarise your people with it. Run security inductions for new staff. Brief your team on the “Run, Hide, Tell” protocol for active threat situations. Ensure key staff understand “Press, Tie, Tell” improvised first aid for bleeding injuries. Encourage all employees to download the SGSecure mobile app — it enables geo-tagged emergency calls to the Police, reporting of suspicious persons or articles, real-time emergency alerts, and access to SGSecure e-learning resources.
Exercise it regularly. Drills expose gaps that desktop planning cannot. Ensure all staff — not just the RM Champion — know evacuation routes and designated hiding locations. Review and revise the plan whenever your premises layout, operations, or workforce composition changes.
Appoint an SGSecure Representative
Your company should appoint an SGSecure Representative to champion preparedness measures internally and serve as the designated point of contact with MOM during a crisis. There are no formal training prerequisites for the role, but the appointee must be capable of keeping the workplace safe, healthy, and secure. The representative is expected to work with management to implement SGSecure initiatives proactively — not just respond reactively when an incident occurs. Register at www.mom.gov.sg/sgsecure to receive direct SGSecure updates and connect with the wider SGSecure business community in Singapore.
What the Level 3 Audit Will Scrutinise in Your RM Plan
Once your bizSAFE Level 2 Risk Management Plan is developed, progression to Level 3 requires a Risk Management Implementation Audit conducted by a registered Auditing Organisation (AO). This AO must be independent from any consultancy engaged to develop the plan. The WSH Council is unambiguous on this point: consultancy and auditing cannot be arranged as a package from the same company, and any application structured that way will be rejected outright. This separation protects the integrity of the audit process and ensures the review is genuinely objective. When selecting an AO, verify their registration with MOM and confirm there is no organisational overlap with whoever helped you build the plan.
As of 1 January 2026, RM implementation audits include a new verification check: speed limiters installed in company lorries. Businesses that operate lorries without speed limiters will not achieve a satisfactory audit result. Resolve this before engaging your auditor.
For the SGSecure components of your bizSAFE Level 2 Risk Management Plan, auditors will assess four specific deliverables:
- WSH Policy — Does it explicitly state the company’s commitment to manage and respond to terror threats? A policy that only references conventional occupational hazards will fail this checkpoint.
- Risk Assessment — Does it identify at least one plausible terror threat scenario applicable to your business? Armed attack, suspicious parcel, vehicle ramming — at least one must be documented and contextually relevant to your industry and premises.
- RM Implementation Plan — Is it approved by top management? Does it include identified terror threats alongside corresponding control and mitigation measures, clear action items, and responsible persons named against each item?
- Employee Awareness — Has an SGSecure Representative been appointed? Can employees explain “Run, Hide, Tell” and “Press, Tie, Tell”? Do they know evacuation routes, hiding locations, and what to do during a lockdown procedure?
All four checkpoints must be satisfied. Partial compliance does not pass the audit.
The Bottom Line
A bizSAFE Level 2 Risk Management Plan that covers only conventional workplace hazards is, under the WSH Council’s current requirements, an incomplete plan. The SGSecure terror threat requirements are not a soft add-on — they are a mandatory component with four distinct audit checkpoints at Level 3. Every Singapore company progressing through the bizSAFE framework needs to understand this before sitting down to build the plan, not after receiving audit findings.
Building this correctly from the start means no audit findings, no rework, and no disruption to your certification progression.
At Ensure Safe Consultancy, we specialise in helping Singapore businesses develop bizSAFE Level 2 Risk Management Plans that are built to pass — covering workplace hazards, SGSecure integration, contingency response planning, and the full documentation your Level 3 auditor expects to see.
Ready to get your bizSAFE Level 2 Risk Management Plan right from day one? Book a consultation with Ensure Safe Consultancy →
