SHEQ24 FAQ: OHS Act, POPIA & ISO Compliance.
What SHEQ means and where the obligations behind it actually come from, followed by straight answers on data sovereignty, POPIA, deployment timelines, and offline field capabilities.
SHEQ Fundamentals
SHEQ stands for Safety, Health, Environment and Quality — the four management disciplines most South African industrial operations govern together. You will also see HSE (Health, Safety, Environment), HSEQ, and SHERQ, which adds Risk as a separate letter. The abbreviation varies by organisation and sector; the underlying disciplines do not. SHEQ is a management convention rather than a legal term: no South African statute defines the word, but each letter maps to obligations that are separately enforceable.
A SHEQ management system is a single system of record for safety, health, environmental and quality obligations, rather than four sets of registers maintained separately by different departments. The practical argument for combining them is evidentiary rather than philosophical: the same training record, contractor file or corrective action is usually needed by more than one audit. Maintained separately, those records are captured more than once and drift apart, and the version an auditor is shown may not be the version that was current on the date in question. Maintained together, one record serves an inspection, a certification audit and a customer audit alike.
See the SHEQ24 platform architectureNot under that name. "SHEQ" appears in no South African Act, and nothing obliges you to operate a system called a SHEQ system. The obligations behind the letters are statutory and are enforced separately. Safety and health fall under the Occupational Health and Safety Act 85 of 1993 — or the Mine Health and Safety Act 29 of 1996 where the operation is a mine — with injury reporting under the Compensation for Occupational Injuries and Diseases Act 130 of 1993. Environmental duties fall under the National Environmental Management Act 107 of 1998 and the specific environmental management Acts beneath it. Quality is the outlier: it is generally not statutory, and quality obligations usually arise from contract, from sector-specific regulation, or from certification a customer requires as a condition of supply. Certification to ISO 45001, ISO 14001 or ISO 9001 is voluntary in law, which is a separate question from whether your largest customer will keep buying without it.
How the Legal Register module tracks these obligationsThree different exercises get called a SHEQ audit. An internal audit is your own scheduled check that the system is being followed, and is itself a requirement of the ISO management-system standards. A certification audit is conducted by an accredited certification body against a standard such as ISO 45001, ISO 9001 or ISO 14001, with surveillance audits between certification cycles. A second-party or customer audit is a customer auditing you, which is routine in food manufacturing, retail supply and mining contracting. A statutory inspection by the Department of Employment and Labour is not an audit in this sense — it is an enforcement visit, and it does not follow an audit programme you control. In all three audit types the auditor tests evidence rather than intent: whether the risk assessment was current on the date the work happened, whether the person doing it was trained and medically fit at that time, and whether corrective actions were actually closed rather than merely raised.
Audit Management moduleSHEQ procedures are the documented ways of working that a management system requires, and they sit in a hierarchy worth keeping distinct. A policy states intent and is signed at executive level. A procedure describes how a process runs, who is accountable for it, and what evidence it produces. A work instruction is the step-by-step for a specific task at a specific place. A record is proof that the above actually happened, and it is the tier an auditor asks for. Most audit findings concern that fourth tier rather than the first: the procedure exists and reads well, but the records it calls for were never produced, were not signed, or cannot be retrieved for the date requested.
Document Control moduleFrom the statutes that apply to your operation, not from the abbreviation. In practice most industrial employers are working against a common set: hazard identification and risk assessment; legal appointments made in writing and acknowledged; incident reporting, including injuries on duty reportable to the Compensation Fund; demonstrable training and competency for the work being done; control over contractors on site, which Section 37(2) of the OHS Act addresses through the mandatary agreement; health surveillance where a hazard warrants it; and environmental incident reporting under Section 30 of NEMA where an emergency incident occurs. Which of these bind you, and to what degree, depends on your sector and your risk profile — a foundry, a food plant and a civil contractor answer to materially different regulations. This page is general orientation and is not legal advice; the applicable requirements for a specific operation should be confirmed with a qualified South African practitioner.
Compliance requirements by industryData Security & POPIA
Yes. Unlike generic international SaaS platforms, all SHEQ24 infrastructure is hosted securely within South African data centres. This ensures absolute adherence to the Protection of Personal Information Act (POPIA) regarding data sovereignty and localisation requirements.
Medical surveillance data undergoes Field-Level Encryption (FLE). Access is strictly governed by Role-Based Access Control (RBAC), meaning only appointed Occupational Medical Practitioners (OMPs) and authorised HR personnel can view sensitive clinic histories. Site supervisors and security personnel see only a compliance status indicator — never the underlying medical data.
Read: POPIA Compliance for Contractor DataYou retain 100% ownership of your data at all times. We provide open APIs and bulk export functionality allowing you to retrieve your complete database, documents, and audit trails in standard formats. There are no data lock-in clauses.
The platform includes built-in data subject request workflows. When an employee or contractor submits a POPIA access or deletion request, the system routes it to your designated Information Officer with a tracked response deadline. Automated data destruction schedules ensure that personal information is not retained beyond its lawful purpose.
Read: POPIA & Contractor Data ManagementImplementation & Migration
Our onboarding team handles the heavy lifting. We map your existing HIRA registers, Asset Registers, Employee lists, and Training matrices via structured CSV sanitisation processes. Our data architects validate the imported data against your operational structure before go-live, ensuring zero historic data is lost during the transition.
Depending on the complexity of your legacy data and the number of modules deployed, complete system handover typically occurs between 4 to 8 weeks. We phase the rollout to prioritise your highest-liability modules first — typically Risk, Incident, and Documents — before expanding to the full platform. We do not disrupt your active production environment during this phase.
Yes. Our architecture supports secure API handshakes with major South African-used ERP systems to synchronise employee payroll data, cost centre structures, and live asset directories. This eliminates duplicate data entry and ensures your compliance records always reflect your current organisational structure.
Absolutely. You do not need to deploy all 24+ modules on day one. Our enterprise architects will conduct a liability assessment of your current compliance posture and recommend a phased implementation plan that addresses your highest-risk areas first. Most clients begin with Risk, Incident, and Documents, then expand to People and Assets modules as adoption matures.
Explore the full module listField Operations
Yes. The SHEQ24 mobile application is built on an Offline-First architecture. Supervisors can complete audits, log hazards, capture incident reports, and trigger NCRs entirely offline. The app caches all data with full encryption and automatically synchronises with the main server the moment Wi-Fi or LTE connectivity is restored. GPS coordinates are captured at the time of the action, not at sync time.
Yes. The platform includes a dedicated Contractor Portal aligned to Section 37.2 of the OHS Act. Contractors can upload their safety files, competency certificates, medical fitness records, and Letters of Good Standing directly to the portal before arriving on site. Your safety team reviews compliance status digitally, and site access can be automatically blocked for contractors with expired documentation.
Contractor Management moduleSHEQ24 is architected for multi-site enterprise operations. Each site can have its own risk registers, inspection schedules, and compliance calendars, while executive management retains a consolidated view across all facilities. Role-Based Access Control ensures that site-level users only see their own data, while group-level managers have cross-site visibility.
Legal & Compliance
Yes. When an injury on duty (IOD) is logged in the Incident module, the system automatically populates the DoL Annexure 1 form using the injured employee's profile data, the incident details, and the employer's registered information. The completed form is available for immediate submission to the Compensation Fund, with a deadline tracker ensuring the seven-day reporting window is not missed.
Incident Management moduleSHEQ24 creates an immutable, timestamped audit trail of every compliance action taken across the organisation. In the event of a DoL investigation following a serious incident, your legal team can immediately produce evidence showing that risk assessments were current, employees were trained and medically fit, equipment was maintained, and supervisors were conducting regular inspections. This is the 'reasonably practicable' evidence chain that Section 16(1) defence requires.
Read: Engineering ISO 45001 to Defend Section 16(1)Yes. The platform includes specific workflows for construction-sector requirements, including Health and Safety Plans, baseline risk assessments for construction activities, and contractor management aligned to the Construction Regulations. The Appoint module manages the mandatory appointment of Construction Health and Safety Officers and Agents.
Have a specific technical question?
Speak directly to our technical architects regarding custom security protocols, Service Level Agreements (SLAs), and enterprise deployment requirements.