What is the OSH policy
A policy is a stable set of guidelines approved by the organization’s leadership. In prevention, it identifies the commitments made to protect people and how these commitments should be reflected in the company’s activities. Its usefulness depends on its ability to recognize decisions that are consistent with these commitments and to identify those that contradict them. A well-written policy can be ineffective if deadlines, purchasing practices, or staff allocation lead to unsafe work practices.
The policy is part of the occupational health and safety (OSH) management system, but it does not replace it. The system includes procedures, responsibilities, and the means to implement it. It is also not equivalent to a disciplinary code or a set of equipment operating instructions. These documents have other functions and must be consistent with the overall commitment declared by the organization.
Difference between policy, objectives and planning
Policy explains the direction; OSH objectives express the desired outcomes; planning identifies actions, resources, responsible parties, and deadlines. Confusing these levels results in lengthy and impractical documents. For example, committing to integrate prevention into purchasing falls under policy. Ensuring that new equipment purchases are reviewed before contracting is an operational objective. Designing the form, assigning the reviewer, and training the purchasing department are actions within the plan.
It’s important to keep this relationship visible. Each priority objective should be linked to a commitment and a real problem. If activities appear that are unrelated to relevant risks, the organization may be measuring administrative activity rather than preventive improvement. A “zero accidents” declaration also doesn’t, on its own, describe what conditions will be changed or how problems will be addressed.
What it should include and how to adapt it
The content needs to consider the activity, the people involved, the facilities, the work arrangements, and the most significant risks. A home care company and an industrial facility may share principles, but they must apply commitments to different realities. The policy must be understandable to anyone who organizes shifts, contracts a service, performs maintenance, or coordinates an activity with another company.
Among the commitments that are typically made are protecting safety and health, complying with applicable requirements, involving workers, and improving prevention. Their formulation should be accompanied by a practical question: what decision will change within the company if this commitment is taken seriously? It is not helpful to promise capabilities, controls, or resources that the organization has not planned to provide.
Approval, participation and communication
Approval rests with management, which has the authority to make commitments and mobilize resources. Preparation should incorporate the technical knowledge and experience of those exposed, utilizing appropriate consultation and participation mechanisms. Consultation is not simply about circulating a closed document; it allows for the uncovering of discrepancies between what is declared and what actually happens on the ground.
Communicating effectively means facilitating access and understanding, including for new hires, managers, and partner companies when it affects them. It can be integrated into onboarding, coordination meetings, and change management. Language, literacy, digital access, and the geographical dispersion of work centers must all be considered. A signature acknowledging receipt confirms delivery, but it does not, in itself, demonstrate understanding of how to respond to production pressure or unsafe conditions.
How to check that it applies
Policy is verified by observing the system’s decisions and results. Useful evidence includes changes to purchases due to identified risks, budget allocations for priority controls, and traceable responses to staff communications. Equally useful are the decisions made when a measure is ineffective and needs to be reviewed.
The review can be supported by audits, incidents, changes in activity, and the evolution of occupational health and safety (OSH) indicators. It doesn’t need to become a mere annual ceremonial re-edition without any changes. If activity expands, new technologies are incorporated, or a significant risk emerges, it’s essential to verify that commitments and resources remain adequate. The PDCA cycle helps connect this review with new decisions.
Practical example
In a workshop, the policy states that risks will be considered before purchasing equipment. However, the maintenance department receives a machine chosen solely based on price and delivery time. Before it is put into service, difficulties are discovered in safely accessing certain areas. The problem is not solved by adding another signature to the policy document.
The company reviews the purchasing process, incorporates a preliminary assessment with production and safety, defines who accepts the installation conditions, and retains the decisions. In a subsequent purchase, the supplier adapts the solution before delivery. This example illustrates how a general commitment becomes part of a routine decision and generates evidence of its implementation.
Common mistakes
Copying policies from other organizations can overlook real risks or activities. Delegating the entire policy to the prevention service can undermine the accountability of those who decide on resources and operations. Another mistake is communicating it only as a poster, while incentives reward concealing incidents or breaking procedures to finish quickly.
Policy should also not be used to shift responsibilities onto the staff that belong to the company. Individual collaboration is necessary, but it depends on having adequate conditions, resources, and organization. A credible policy acknowledges that failures require learning, investigation, and system correction.
Framework and documentation
In Spain, Article 2 of the Regulations for Prevention Services places the policy, objectives, and goals within the prevention plan, along with the organization and resources. The Occupational Risk Prevention Law provides the general framework for protection, integration, consultation, and participation. The documentation must be tailored to the company’s actual circumstances.
OSHA’s leadership guidelines are used here as a management reference, not as Spanish legislation. In organizations with locations in multiple countries, corporate commitments must be implemented through local requirements and responsibilities. Document control allows for the identification of the current version and maintains traceability of its approval and revision.
