Streamline ISO Consultants

  • Home
  • Security & AI
    • ISO 27001 Information Security
    • ISO 42001 AI Management
    • Cyber & Information Security Advisory
    • Essential Eight
    • SOC 2
    • TISAX
  • ISO Consulting Services
    • ISO Consultants Australia
    • ISO 9001 for US Companies
    • ISO Mentoring
    • Independent ISO Internal Audit Services Australia (Clause 9.2)
    • ISO Gap Analysis Audits: Know Where You Stand Before Stage 1
    • ISO Certification Auditors
    • ISO System Development
    • ISO Management System Maintenance & Ongoing Support
  • ISO Standards
    • ISO 9001 Quality Management
    • ISO 45001 Occupational Health and Safety
    • ISO 14001 Environmental Management
    • ISO 17025 Testing and Calibration
    • HACCP Food Safety
    • ISO 19443 Nuclear Supply Chain
  • Resources
    • All Articles
    • ISO Clause Guides
    • Quality Quotes
  • About
    • ISO FAQs
    • Quality Policy
    • Client Testimonials
    • ISO 9001 Certificate
  • Contact
    • Business Info
    • Privacy Policy

By Streamline ISO Consultants

Your Plant Risk Assessment Is a Document. Is It a Control?

There is a question I ask early in a safety audit that tells me more than an hour of reading policies: when was this machine’s risk assessment last reviewed, and what changed as a result?

The first half gets an answer. The plant risk assessment exists and it is signed. The second half goes quiet, because nothing has been looked at since it was written, and it was written when the machine arrived. That was four years, two operators and a new attachment ago.

A control that exists on paper is not a control until you can evidence it was applied. Plant is where that bites hardest, because the paperwork is done once and then left alone while the machine keeps changing.

Miniature industrial yard with a mobile crane on outriggers and timber packing inside a taped exclusion zone, and a worker in hi-vis at a table with a lift plan
The model Code of Practice for managing the risks of plant was updated in November 2024 to add guidance on vehicle roll-aways and safe immobilisation. A separate model Code for elevating work platforms followed in December 2025.

What counts as plant

Most people picture a forklift. Under the model Work Health and Safety Act, plant includes any machinery, equipment, appliance, container, implement and tool, along with any component, fitting or accessory. That takes in the pedestal drill, the pallet racking, the compressor, the scissor lift, the chain block on the beam and the sling somebody made up on site.

So a register built from the asset list will be short, because asset registers exist for depreciation and stop at a dollar threshold. Build yours by walking the site, and treat the accessory as plant in its own right: a crane with a current inspection and a sling with no legible tag is not a compliant lift.

Who holds the duty

Duties on plant overlap rather than hand off. The business that manages or controls the plant holds the primary duty, so far as is reasonably practicable, to ensure it is without risks to health and safety. That sits alongside the duties of those who design, manufacture, import, supply, install or commission it, who must design risk out where they can and supply the information needed to use it safely. You have to use it the way that information describes. Officers hold a due diligence duty of their own, which in a plant-heavy business becomes a question about whether the maintenance budget was approved.

The codes that apply, and what they are worth

A plant risk assessment stops being a private document once there is a public benchmark to measure it against. The primary one is the model Code of Practice Managing the risks of plant in the workplace, current edition November 2024, updated to add guidance on vehicle roll-aways and safe immobilisation. Alongside it, depending on what you run:

  • How to manage work health and safety risks, November 2024. The parent method.
  • Construction work, November 2024. Whenever plant operates on a construction site.
  • Elevating work platforms, December 2025. New, and it replaces the two older EWP guides.
  • Tower cranes, June 2023.
  • Confined spaces, November 2024. Plant creates them: hoppers, silos, tanks, mixers.
  • Managing the risk of falls at workplaces.
  • Managing noise and preventing hearing loss at work, November 2024.

An approved code is admissible in proceedings under the WHS Act, and a court may rely on it as evidence of reasonably practicable ways of managing a hazard. New South Wales went further: from 1 July 2026, section 26A requires a duty holder to comply with an approved code that applies to a risk in their business, or to manage that risk to an equivalent or higher standard. You cannot be charged under a code, because a code is not an offence provision, but complying with it has become the duty, and we set out the mechanics in NSW Codes of Practice are now enforceable. Either way, departing from the code needs a written case that your approach is at least as safe.

Free download: Codes of Practice compliance register

A sheet per jurisdiction, with each code named, the requirement summarised, and columns for how you address it, who owns it and when it is next due. Built against ISO 45001 clause 9.1.2.

Download the free Codes of Practice compliance register, with official code links for every Australian jurisdiction.

The steps the code sets out

Identify the hazards at every stage, not just normal operation: commissioning, cleaning, maintenance and repair, adjustment while running, transport, storage and disposal. Cleaning and maintenance are when guards come off and people get inside machines, and they are the phases most assessments skip. Assess the risk with exposure read broadly, taking in the contractor nearby and the cleaner on night shift. Control it using the hierarchy below.

Then review. The code names the triggers: a control that is not effective, a change that may introduce new risk, a new hazard, or a health and safety representative asking. Most registers have a review date field. Very few have a review record naming the trigger and what changed.

The hierarchy applied to plant

Eliminate the machine, or substitute a lower powered, quieter or remotely operated one. Isolate people from plant with fencing, exclusion zones and separated pedestrian and mobile plant routes. Engineer the risk down with guards, interlocks, emergency stops, presence sensing, overload and roll-over protection, and immobilisation. Then administrative controls: procedures, permits, safe work method statements, isolation and tagging, and lift plans. Personal protective equipment comes last.

A case finalised on 28 August 2026 shows what that separation is worth. ANJ Container Services and Bond Stores Pty Ltd was convicted and fined $800,000 in the District Court of NSW after a pedestrian was fatally struck by a reversing reach stacker on 21 April 2022. Two details are worth sitting with. The duty breached was section 19(2), the duty owed to persons other than workers, so the plant duty reached a person who was not on the payroll. And the company contested it: the conviction followed a defended hearing, and the penalty was still $800,000. More than four years passed between the incident and the sentence, which is the part no budget and no insurance policy plans for.

Plant is where that ranking is most often inverted, because the top costs money once and the bottom costs nothing on the day. Engineering controls also have a failure mode the others do not: they can be removed, and a guard defeated in service is worse than no guard, because everyone downstream assumes it works. That is the principle behind our piece on critical control verification. If a control can be defeated, it needs a scheduled check proving it was in place.

Inspection and maintenance records

Plant is maintained in almost every business I audit. Plant maintenance is evidenced in far fewer, and the duty is continuing rather than satisfied at purchase.

What that takes is the manufacturer’s schedule as the baseline, with a written reason wherever a harder duty cycle shortens an interval; pre-start checks that leave a trace, and a defect route that closes, because a defect written in a book nobody reads is a documented failure to act; third party inspection where required, with certificates retained and expiry tracked; and a modification record, because a modified machine is not the machine the assessment described.

Rated gear, and the gear somebody made up

Lifting equipment inspection is the clearest example of the difference between a control and the appearance of one, because the item either carries its identification or it does not. Rated and certified gear arrives with a working load limit marked on it, a compliance certificate and instructions for use, inspection and discard. Managed properly, each item is uniquely identified, on a register, inspected by a competent person at a defined interval, checked by the user before every use, and destroyed when it fails either check.

Improvised gear arrives from the workshop: a bar with two holes burned in it, a chain of unknown grade, a lifting lug welded on by someone competent to weld who was not the designer. It has no working load limit and no criterion to inspect it against. The same applies to rated gear that has lost its markings. It may well be sound, but it cannot be proven sound, so the right action is to destroy it rather than return it to the rack.

Lift planning

A lift plan is where a plant risk assessment stops being about a machine and becomes about a specific job on a specific day. Routine lifts inside rated capacity can sit under a standard procedure. Everything else needs a crane lift plan, settled before the crane arrives.

  • The load. Mass, dimensions, centre of gravity and lifting points. Estimates run optimistic, and an estimated mass is the most common root cause of a lift going wrong.
  • The configuration and rigging. Boom length, counterweight, and rated capacity at the worst radius in the lift rather than the best. Which slings and shackles, with sling angle factored into each leg, because a two-leg sling at a wide angle carries far more per leg than half the load.
  • The ground and surrounds. Bearing capacity, outrigger loads, packing, excavations and services, powerlines, and wind limits. Ground failure under an outrigger is a plant failure with no mechanical fault in it.
  • The people and the stop conditions. Who runs the lift, who holds the exclusion zone, and what ends it. Naming the stop conditions in advance is what lets a junior person use them.

A lift plan filed and not briefed to the crew is a document, not a control. The signed briefing record is the evidence.

Competence, and verifying it

Every control in the plant code assumes a competent operator, so competence is a control and it has to be evidenced. The legal floor is the licence: some plant may only be operated by the holder of a high risk work licence in the right class. That is a check of a card, necessary rather than sufficient.

Above the floor sits verification of competency, and it is worth being clear that this is not a term in the WHS Act. It is an industry practice that grew up to answer the question a licence does not: this person is licensed for this class of plant, but are they competent on this machine, on this site?

Done properly it is a practical assessment by a competent assessor, against defined criteria, on the specific machine, with a recorded outcome and a review period. Done badly it is a form signed because a client asked for one, which is worse than having none, because you have created a record you cannot support. The operators most confident they need no assessment are often the ones who most need it, which is the ground we covered in Dunning-Kruger and ISO clause 7.2.

How ISO 45001 keeps it true

All of this is achievable without a management system. What a system does is stop it decaying, and two clauses do most of that work.

Clause 8.1, operational planning and control, turns the plant risk assessment into a process with criteria, controlled in accordance with them, with documented information retained to show it was carried out as planned. It also extends control to procurement, contractors and outsourced processes, which is the part plant-heavy businesses skip. A hired scissor lift arriving with no inspection record is your control failure, not the hire company’s.

Clause 9.1, monitoring and measurement, is what makes the assessment stay true. It asks what needs monitoring, by what method, against what criteria, and when results are evaluated. Applied to plant, the inspection interval becomes a monitored parameter with an owner and a due date rather than a hopeful note in a register. Clause 9.1.2 then asks you to evaluate compliance with your legal requirements, which is where the codes register earns its keep.

Around them, clause 9.2 tests whether controls operate as described, clause 9.3 puts plant in front of the people who approve maintenance budgets, and clause 10.2 governs nonconformity. Finding a defeated guard is not the failure. Finding it and doing nothing traceable is, and that is what a regulator looks for too, as we set out in the SafeWork NSW 2026-27 regulatory priorities.

What an auditor asks for

If I were auditing your plant tomorrow, this is the thread I would pull. It is a useful self-test even if nobody is coming.

  1. The register. Built from a walk of the site, and does it include accessories?
  2. The assessment. Does one exist for a machine I pick at random, and does it cover maintenance and cleaning as well as operation?
  3. The review trigger. What prompted the last review, and what changed?
  4. The controls as found. Guard working, emergency stop reachable, exclusion zone observed, isolation point identified?
  5. The records. Last service against what schedule, and the pre-start book, including a page where the answer was no and what happened to it.
  6. The gear and the operator. Is that sling identified, on the register and in date, and can the person handing it to me state its working load limit? What licence and verification of competency does the operator hold?
  7. The loop back. Did any of this reach management review, and did anything change?

Points 3, 5 and 7 are where most systems break, and all three are the same failure wearing different hats.

Where this comes unstuck

The assessment written by the supplier. A useful starting point, not a substitute. It describes the machine in general, not your machine in your layout, and it will not mention the pedestrian route past it.

The register that is a folder. A folder of PDFs has no due dates and no owners. Nor does an invoice prove maintenance: it proves a payment, so ask for the report. And hired or contractor plant is inside your control boundary the moment it is on your site.

Plant that belongs to someone else. Hired plant, and a contractor’s own machine brought onto your site, sit inside your duty when you manage or control the work. The duties overlap rather than hand off, which is easy to say and expensive to learn. We looked at a business fined $230,000 over someone else’s worker on someone else’s plant, which is the clearest illustration available of how far that overlap reaches.

No project plan. This one quietly costs the most on a certification build. Businesses decide to implement ISO 45001, start on documents, and never produce a plan with dates, owners and dependencies. It matters because the plan is shared with the certification body so they can schedule Stage 1 and Stage 2. Without it, audit dates suit the certifier’s diary rather than your readiness, and a business that would have been ready in five months finds Stage 2 booked for a date it cannot meet.

Where Streamline fits

Most businesses that get into difficulty with plant are not careless. What they lack is the loop that proves it, and that loop is what a regulator, a certification auditor and a principal contractor all ask to see.

Streamline is run by a practising ISO Lead Auditor, so you get the view from the other side of the audit table. We run independent gap analysis audits that tell you where your plant risk assessments, registers and evidence stand against the codes that apply to you and against ISO 45001. We provide the independent internal audit your system needs under clause 9.2, we build ISO 45001 systems end to end, and ISO mentoring guides your own people if you would rather build in-house.

For most small and medium Australian organisations, ISO 45001 certification takes three to six months and a first-year investment of roughly $7,000 to $25,000. Built as part of an integrated management system alongside quality or environmental, the cost per standard runs at about 50 to 75 per cent of standalone.

Pick one machine, find its risk assessment, and see how far down the auditor’s list you get. If the answers stop at question three, get in touch and we will work through the rest with you.

Sources

  • Safe Work Australia, model Code of Practice: Managing the risks of plant in the workplace, current edition November 2024, and the Safe Work Australia news item on the vehicle roll-away and safe immobilisation update.
  • Safe Work Australia, model Codes of Practice: How to manage work health and safety risks (November 2024), Construction work (November 2024), Confined spaces (November 2024), Managing noise and preventing hearing loss at work (November 2024), Tower cranes (June 2023), Elevating work platforms (December 2025), Managing the risk of falls at workplaces.
  • Model Work Health and Safety Act: definition of plant, primary duty of care, upstream duties, officer due diligence, and the admissibility of approved codes of practice.
  • Work Health and Safety Act 2011 (NSW) section 26A, in force 1 July 2026, inserted by the Industrial Relations and Other Legislation Amendment (Workplace Protections) Act 2025.
  • ISO 45001, clauses 7.2, 8.1, 9.1, 9.1.2, 9.2, 9.3 and 10.2.

This article is general information from an auditing and management system perspective. It is not legal advice, and it does not comment on any current incident, investigation or proceeding. Codes of practice are approved jurisdiction by jurisdiction, so check with your regulator which apply to you.

General guidance only. This article is general information, not legal, financial, safety or compliance advice, and it does not take account of your specific circumstances. Streamline ISO Consultants are ISO management-system consultants, not lawyers or licensed advisers. Standards, laws and regulator guidance change, and details were correct only at the time of writing. Always seek professional advice before acting. See our full Disclaimer.

Stay in the Loop

Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.

We handle your details in line with our privacy policy.

More ISO Certification Information

  • ISO Frequently Asked Questions
    Frequently Asked Questions: ISO FAQs
  • ISO 14001 environmental management
    ISO 14001 Consulting, Environmental Audits and Mentoring
  • Consultant guiding a business owner through their ISO management system at a laptop
    ISO Mentoring: Expert Guidance for DIY ISO Systems
  • ISO 45001 workplace safety inspection
    ISO 45001 Consulting, Safety Audits and Mentoring
  • ISO 27001 information security risk analysis
    ISO 27001 Consulting, Internal Audits & Mentoring
  • Tilt-shift miniature of a collapsed bridge with engineers at a drawing board tracing the failure back to the design
    ISO 9001 Clause 8.3: Design Inputs, Outputs, Review,…
  • Tilt-shift miniature of a submarine periscope casting a narrow cone of light onto one small island of activity in a vast dark ocean
    ISO Clause 4.3: Determining Your Scope (Inside Your…
  • ISO certification bodies in Australia
    How to Choose an ISO Certification Body in Australia
  • Tilt-shift miniature of an office where an oversized industrial valve marked OPEN pours paperwork over the desks, burying workers, while a figure carries papers into an empty meeting room nobody is using
    Psychosocial Hazards at Work: What Australian Law…

Filed Under: Articles Tagged With: #iso45001

Quick Information Request

Brisbane ISO Consultants

Level 14, 167 Eagle St
Brisbane Queensland 4000
Phone: 07 3667 8280
Email: hello@streamline.business

Sydney ISO Consultants

Level 5, 20 Bond Street,
Sydney NSW 2000
Phone: 02 8315 7780
Email: hello@streamline.business

Melbourne ISO Consultants

Level 8, 350 Collins Street
Melbourne, Victoria 3000
Phone: 03 9034 3990
Email: hello@streamline.business

Client and partner logos

KEY ISO ARTICLES

Articles, Deep Dives & More
Frequently Asked Questions
Quality Quotes
Funding Grants for ISO Certification
ISO Consultants
Strategic Planning - Mystical Art?
ISO Certification Auditors
How to get ISO 9001 Certification
ISO Certification Cost
How to tell if your ISO Cert is fake
4-year-olds and Root Cause Analysis
Fast ISO 9001 Certification
The Ultimate Guide to ISO 9001 Audit
ISO 45001 Certification Cost
Who's Interested in a Party?
How to use Smartsheet for ISO
Smarter Quality Objectives
Local Government QMS
Quality Assurance, Quality Control or QMS
ISO Certification in Sydney
ISO Certification in Melbourne
ISO Certification in Brisbane
SAI Global Consultant Affiliate Program

QUICKLINKS TO ISO INFO

ISO Consultants Australia
ISO Mentoring
ISO 27001 Certification Cost
ISO 9001 Quality Management
ISO 45001 Health & Safety
ISO 14001 Environment
ISO 17025 Testing & Calibration
ISO 27001 Information Security
ISO 42001 AI Management
ISO 22000 HACCP Food Safety

Search

FOLLOW OR GET IN TOUCH

linkedinmail
Smartsheet Platinum Partner

Copyright © 2026 Streamline · Log in

Privacy Policy · Terms of Use · Disclaimer

Call us Enquire