Treadstone Associates
Guide

Writing a health and safety management system

A safety manual copied from another firm reads well and protects nobody. Here is how to write one section by section from the actual mechanics regulators require, so the document matches the work it governs.

Treadstone Associates · Updated 2026

Key takeaways

  • • Alberta's OHS Code Part 2 gives a usable four-part skeleton — assess, control in a mandated order, involve workers, and reassess on a trigger — even for an SMS built outside Alberta.
  • • The control hierarchy has a mandated order: engineering controls, then administrative controls, then PPE, then a combination — each available only once the previous one isn't reasonably practicable.
  • • Ontario and BC set materially different notice-of-project thresholds: $50,000 with no lead time in Ontario, versus $100,000 with 24 hours' notice in BC.
  • • COR certification runs on a national 65%-per-element, 80%-overall audit standard, with IHSA as Ontario's authority having jurisdiction — structure your document to map onto that standard from the start if certification is a goal.

STEP 01 OF 10

Start from a hazard-assessment skeleton, not a policy-statement skeleton

A policy statement that opens with a mission-style commitment to safety reads well and establishes nothing operational. Alberta's OHS Code Part 2 gives a genuinely usable structure instead — assess, control, involve workers, reassess — that works as a document skeleton regardless of which province the SMS actually governs.

Borrowing a statutory structure as a skeleton is different from claiming Alberta's Code applies outside Alberta. State plainly in the document's front matter which jurisdiction's rules actually govern the work, and that the structure is used for its clarity, not its jurisdiction.

STEP 02 OF 10

Write the hazard-identification section first

Alberta's OHS Code s.7(1) requires an employer to "assess a work site and identify existing and potential hazards before work begins at the work site or prior to the construction of a new work site" (search-ohs-laws.alberta.ca, current to March 2023). Under ss.7(2)-(3), the employer must prepare a report of the results and control methods, and record the date it was prepared or revised.

Write this section as a method, not a static list — how a hazard assessment gets done at your firm, who does it, and where the dated report is filed. A list of hazards without a documented method for producing it is not what s.7 actually asks for.

STEP 03 OF 10

Write the control-hierarchy section in the mandated order

Alberta OHS Code s.9(2)-(5) sets the hierarchy in order: engineering controls, then administrative controls ("as low as reasonably achievable"), then personal protective equipment, then a combination — each step available only if the previous one is not reasonably practicable. Write the document's control section in that exact order, not with PPE listed first because it's the most visible control on a job site.

A document that jumps straight to a PPE list, without addressing engineering and administrative controls first, inverts the hierarchy the regulator actually expects — and reads as a checklist rather than a genuine control programme.

STEP 04 OF 10

Build worker involvement into the document itself

Alberta OHS Code s.8(1) requires an employer to "involve affected workers in the hazard assessment and in the control or elimination of the hazards identified." Name the mechanism in the document — a toolbox-talk process, a JHSC review step, a sign-off field — rather than leaving worker involvement as an unwritten assumption.

A documented mechanism is also the difference between a genuine practice and a claim that can't be evidenced. If a regulator or an auditor asks how workers were involved, the document should point to a specific, repeatable step.

STEP 05 OF 10

Write the review-trigger section explicitly

s.7(4) requires reassessment "at reasonably practicable intervals," when a new work process is introduced, when a process or operation changes, or before construction of significant additions or alterations. List these triggers explicitly in the document rather than relying on an implied "review periodically" statement — a trigger-based review clause is auditable in a way a vague interval isn't.

Cross-reference this section against the compliance calendar's own review cadence where the two overlap — a hazard reassessment triggered by a new process shouldn't be tracked in a separate system from everything else on the calendar.

STEP 06 OF 10

Add the jurisdiction-specific committee section

Pull the JHSC threshold for wherever the SMS actually operates from CCOHS's jurisdictional table — 20 or more workers in nearly every Canadian jurisdiction, with Saskatchewan at 10 as the exception (ccohs.ca). Write the committee section around the actual jurisdiction the SMS governs, not the jurisdiction whose hazard-assessment structure you borrowed in step one.

If the firm operates across more than one province, this section needs its own sub-sections by jurisdiction — a single national threshold statement will be wrong somewhere.

STEP 07 OF 10

Add the notice-of-project section with both provinces' thresholds named

Ontario requires a Notice of Project where the expected cost exceeds $50,000 (or $250,000 for a project confined to an automobile-manufacturing factory), with no stated lead time (O.Reg 213/91 s.6, via ontario.ca/page/file-work-notice). BC's OHSR 20.2 sets the cost threshold at $100,000, plus structural triggers (buildings over 2 storeys or 6m, retaining structures over 3m, and others), with written notice required at least 24 hours before work begins.

Name both thresholds explicitly in the document if the firm works in both provinces, rather than writing one generic "notice of project" clause and assuming it covers both regimes. The cost trigger and the lead-time requirement both differ.

STEP 08 OF 10

Add the emergency-response and incident-reporting section, cross-referenced not duplicated

Point this section to an incident response runbook for a site rather than rewriting the same reporting clocks in two places. A duplicated section is a section that drifts out of sync the first time one copy gets updated and the other doesn't.

Keep in this section only what's specific to this SMS document's own governance — who owns the incident file, how it links back to the hazard-assessment record from step two — and let the runbook itself carry the procedural detail.

Cross-referencing rather than duplicating also means a jurisdiction-specific update to the reporting clocks — a regulation amendment, a moved page — only has to be made in one place, not chased down across every document that mentions it.

STEP 09 OF 10

Structure toward COR from the start, if certification is a goal

COR's national standard is explicit: "Minimum 65% in each element and an overall audit score of 80%," with IHSA as "the 'Authority having Jurisdiction' to grant COR in the province of Ontario," and the programme dating back "more than 20 years" from Alberta, enhanced to "COR 2020" (ihsa.ca/COR). No fee figure is published on that page — IHSA directs cost questions to cor@ihsa.ca, so don't state a price in the SMS document itself.

Structuring each SMS section to map cleanly onto a COR audit element from the outset saves a full rewrite later if the firm decides to pursue certification. Retrofitting a document written with no audit structure in mind is far more work than building toward one from the first draft.

STEP 10 OF 10

Set the document's own review cycle before filing it away

Apply s.7(4)'s reassessment logic to the SMS document itself, not just to individual hazard assessments — a fixed interval, plus the same triggers (new process, process change, significant addition). A safety management system that's never revisited after it's written is exactly the failure mode s.7(4) exists to prevent, applied one level up.

Record the review date on the document's own cover page, the same way a credential's expiry date belongs on its own line in the training register.

Name who has the authority to trigger an off-cycle review when something changes — the same accountable-owner discipline the training register needs. A review clause with no named owner tends to become a review clause nobody actually acts on.

Common mistakes

Writing the control-hierarchy section with PPE listed first. The mandated order is engineering, then administrative, then PPE, then a combination — each available only when the previous option isn't reasonably practicable. A PPE-first document inverts the hierarchy regulators expect.

Writing the SMS once and never revisiting the review-trigger section. s.7(4)'s reassessment triggers apply to the document itself as much as to any single hazard assessment. A static SMS is the exact gap this section exists to close.

Assuming a template SMS built for one province satisfies another province's thresholds. Ontario's $50,000 notice-of-project trigger and BC's $100,000-plus-structural-triggers version are genuinely different rules. A firm working in both needs both named explicitly, not one borrowed clause.

The notice-of-project threshold, worked

Scenario. A $95,000 building renovation crosses Ontario's $50,000 Notice of Project threshold and requires notice, with no stated lead time. The identical $95,000 project in BC falls under the $100,000 OHSR 20.2 cost trigger and needs no notice at all, absent one of the separate structural triggers (height, retaining-structure size, and so on). Raise the same project to $120,000, and it now crosses both thresholds — requiring notice in Ontario with no lead time, and requiring at least 24 hours' written notice in BC before work begins. The SMS document's notice-of-project section needs to carry both rules, not a single blended threshold.

Where COR certification fits, and what it isn't

COR is a voluntary, nationally trademarked programme endorsed by the Canadian Federation of Construction Safety Associations — it is not itself an OHSA or OHS Code requirement. A firm can operate fully compliant with statutory hazard-assessment and reporting obligations without ever pursuing COR. The 65%-per-element, 80%-overall audit standard matters as a document-structure target only for a firm that has decided certification is worth pursuing — write the SMS around the statutory obligations first, and treat COR alignment as a bonus structural choice, not a legal necessity.

Frequently asked

Does a written SMS need to be COR-certified to be legally valid?

No. COR is a voluntary national programme, not a statutory requirement. A firm's SMS needs to satisfy the actual regulatory obligations — hazard assessment, worker involvement, the control hierarchy, reassessment triggers — whether or not it ever pursues certification.

How often should the hazard assessment itself be reviewed?

At reasonably practicable intervals, and immediately on any of three named triggers: a new work process, a change to an existing process, or before constructing a significant addition or alteration. Don't rely on a fixed annual date alone if one of those triggers happens sooner.

Does a crew under 20 workers need a formal SMS at all?

The JHSC committee requirement doesn't apply below the threshold, but the underlying hazard-assessment and control obligations under OHS legislation generally do not depend on headcount. A small crew still needs the assessment and control-hierarchy discipline; it just won't need a formal committee section yet.

What's the difference between a hazard assessment and a full SMS?

A hazard assessment is one input — the s.7 report for a specific work site. The SMS is the whole governing document: hazard assessment, control hierarchy, worker involvement, review triggers, committee structure and incident-reporting links, all in one place.

Get a health and safety management system built around your actual work.

A 30-minute call is enough to map the sections your firm's SMS is missing.