For many organisations, OSH Code compliance evidence still begins with a familiar question:
Where is the document?
The policy may be in one folder. Training records may sit in another system. Inspection sheets may be stored site-wise. Contractor information may live in spreadsheets. Permit records may be somewhere else entirely. Corrective actions may be tracked through email.
Individually, all of those records can exist.
The harder question during a compliance review or audit is whether they can be connected.
Can the organisation show which requirement applied, where it applied, who owned the control, which version was current, what activity was completed, who approved it, whether exceptions were raised and whether related actions were actually closed?
That is why OSH Code compliance evidence should be managed as an evidence system rather than as a collection of stored documents.
India’s four Labour Codes, including the Occupational Safety, Health and Working Conditions Code, 2020, were made effective from 21 November 2025. The Occupational Safety, Health and Working Conditions (Central) Rules, 2026 were subsequently notified in May 2026. Organisations should assess the exact provisions, rules, notifications and appropriate-government requirements applicable to their own establishments and operations.
This article is not legal advice. Its focus is narrower: how EHS and compliance leaders can make operational evidence easier to own, validate and retrieve.
Why OSH Code Compliance Evidence Needs More Than a Document Repository
Document repositories are useful.
They solve an important problem: storage.
But storage is only one part of compliance evidence management.
Imagine an auditor asks for evidence relating to a particular safety requirement at Plant B.
The EHS team finds a PDF.
That may answer the first question.
It may immediately create six more:
- Does this document apply to Plant B?
- Is it the current approved version?
- Who owns implementation?
- Which workers or activities are affected?
- What operational records demonstrate that the requirement was implemented?
- Were any findings or exceptions raised?
- If actions were assigned, were they completed and verified?
A file can contain information without answering those questions.
This is why an evidence system should be designed around relationships, not only folders.
The relationship might look like:
Requirement → Applicability → Control → Owner → Activity → Record → Approval → Exception → Action → Verification
That chain is far more useful during an audit than a collection of disconnected PDFs.
OSH Code Compliance Evidence Should Start With Applicability
Before asking what evidence to retain, organisations need to understand what actually applies.
This is where compliance management frequently becomes difficult in multi-site operations.
A manufacturing organisation may operate factories across several states. A construction or EPC business may have temporary project sites. A company may use contractors whose activities and workforce profiles differ substantially from its direct employees.
The evidence requirement therefore cannot always be managed using a single generic checklist.
For each applicable obligation, a compliance team should be able to identify at minimum:
Requirement
What provision, rule, notification, internal standard or other obligation is being addressed?
Applicability
Which establishment, activity, employee category, contractor, process or location does it affect?
Control owner
Who is responsible for ensuring the requirement is implemented?
Operational mechanism
How does the requirement enter everyday work?
This could involve training, an inspection, a permit, medical surveillance, a licence, a committee, a register, an approval workflow or another control.
Evidence
Which record demonstrates that the required activity occurred?
Once those relationships are defined, evidence becomes easier to manage systematically.
1. Map the Obligation to the Record
A common weakness is collecting records first and trying to understand their regulatory relevance later.
Reverse that logic.
Strong OSH Code compliance evidence starts by connecting each applicable obligation to the operational record that demonstrates how it was addressed.
Start with the obligation.
Then ask:
What evidence would demonstrate that this requirement has been addressed for this establishment?
Depending on the requirement and applicable rules, evidence might include records relating to:
- workforce information;
- training or competency;
- inspections;
- occupational-health activities;
- contractor management;
- incidents and dangerous occurrences;
- licences and registrations;
- statutory roles;
- permits and work controls;
- committees and meetings;
- corrective actions;
- returns or prescribed registers.
The 2026 Central Rules themselves include prescribed forms and registers across several areas, illustrating why organisations need to understand the specific record context rather than treating “compliance documentation” as one generic category.
The important management question is therefore not simply:
“Do we have records?”
It is:
“Can we show which obligation each material record supports?”
2. Give Every Evidence Requirement an Owner
Shared responsibility frequently becomes unclear responsibility.
For example, one requirement could involve several functions:
HR maintains worker information.
EHS manages safety training.
Operations ensures the worker is deployed correctly.
Contractor management verifies contractor documentation.
A supervisor confirms field implementation.
Compliance prepares evidence for review.
If nobody is identified as the record owner, evidence quality becomes dependent on individual memory.
For OSH Code compliance evidence to remain reliable, ownership should be defined before an audit or inspection creates urgency.
A practical evidence register should therefore distinguish between:
- obligation owner;
- operational control owner;
- record owner;
- reviewer or approver.
They are not necessarily the same person.
This becomes particularly important in multi-site organisations where a central compliance team may set governance requirements but individual sites generate the actual evidence.
3. Control Version, Approval and Validity
Finding the document is not enough.
You also need to know whether it is the right document.
Consider three files:
Safety_Procedure.pdf
Safety_Procedure_Final.pdf
Safety_Procedure_Final_Updated.pdf
Which one was approved?
Which version was in force when a particular activity took place?
Who authorised the update?
Did affected sites receive it?
Were related training or work procedures changed?
Version control therefore needs more than a file name.
Version control is also a fundamental part of maintaining trustworthy OSH Code compliance evidence.
Useful metadata can include:
- document or record ID;
- version;
- effective date;
- approval status;
- approving role;
- applicable site;
- next review date;
- superseded version;
- source workflow.
This makes retrieval significantly more meaningful.

4. Connect Evidence to the Site, Activity and Workforce
Evidence becomes stronger when its operational context is visible.
OSH Code compliance evidence becomes more useful when its operational context is visible.
Take contractor safety as an example.
An induction certificate tells you that someone attended induction.
But if you are reviewing a specific high-risk activity, you may also need to understand:
- which contractor employed the worker;
- which project or plant they were assigned to;
- whether required competency evidence remained valid;
- what activity they were authorised for;
- which permit covered the work;
- who supervised the job;
- whether associated inspections or observations raised issues.
The same principle applies in manufacturing.
An inspection report becomes more useful when it can be associated with the:
plant → department → line → machine → finding → action → closure
That relationship turns an isolated document into operational evidence.
5. Do Not Separate Actions From Compliance Evidence
Evidence systems often become fragmented at the point where something goes wrong.
An audit or inspection identifies a gap.
An action is created.
A photograph is later uploaded.
The action is marked complete.
But the original evidence repository may never show what happened afterwards.
Good traceability connects:
Finding → Owner → Due Date → Corrective Action → Evidence → Verification → Closure
This is important because an exception is itself part of the compliance story.
An organisation does not demonstrate mature control by pretending that no gaps exist.
It demonstrates control by showing that gaps are identified, assigned, escalated and appropriately closed.
The 2026 Central Rules include an improvement-notice mechanism under which identified contraventions may require rectification and submission of a compliance report. That provides a useful reminder of why corrective-action evidence should remain connected to the original issue rather than disappear into a separate task tracker.
6. Build Retrieval Into the Normal Workflow
Audit preparation becomes painful when evidence is assembled only after someone asks for it.
Effective OSH Code compliance evidence should therefore be generated during normal operations rather than reconstructed immediately before an audit.
A stronger model is to create evidence during normal operations.
For example:
When a training activity is completed, the attendance and applicable competency information should already be associated with the worker.
When an inspection identifies a finding, the action and subsequent closure evidence should remain connected to that inspection.
When a permit is issued, approval, validity, role information and supporting evidence should remain associated with that permit.
When a document is updated, its approval and version history should remain visible.
When a corrective action is closed, the verification should remain connected to the original finding.
The goal is simple:
An ordinary operational workflow should create tomorrow’s audit evidence automatically as part of doing the work correctly.
Audit readiness then becomes a property of normal operations rather than an emergency exercise before an inspection.
This aligns with established management-system thinking. HSE’s HSG65 guidance treats health and safety through a Plan–Do–Check–Act management approach, while ISO 45001 provides an OH&S management-system framework rather than treating safety as a collection of independent documents.
7. Central Visibility Should Not Remove Site Accountability
Multi-site businesses face a recurring tension.
Corporate leaders want one compliance view.
Sites need responsibility for their own controls and evidence.
Centralising every task with the corporate EHS team can create bottlenecks.
Leaving everything entirely site-managed can create inconsistent records.
The better governance question is:
What should be standardised centrally, and what must remain owned locally?
A useful division might be:
Centrally governed
- compliance obligation register;
- evidence taxonomy;
- document standards;
- review frequencies;
- escalation rules;
- reporting dashboards.
Site owned
- operational evidence;
- inspection completion;
- worker records;
- permit execution;
- corrective actions;
- local approvals;
- closure evidence.
Leadership can then see the overall status without removing accountability from the people closest to the work.
What Should a Compliance Evidence Register Contain?
A useful OSH Code compliance evidence register does not need to begin as a complicated system.
Start with one meaningful obligation.
Track:
| Field | Question it answers |
|---|---|
| Obligation ID | Which requirement are we managing? |
| Source / reference | Where does the requirement originate? |
| Applicability | Which establishment/activity/workforce does it affect? |
| Control owner | Who ensures implementation? |
| Evidence required | What should demonstrate implementation? |
| Record owner | Who generates or maintains the evidence? |
| Approver | Who confirms it where approval is required? |
| Frequency / validity | When does the record need review or renewal? |
| Site / activity | Where does it apply operationally? |
| Current version/status | Is the evidence current? |
| Related finding/action | Is there an unresolved exception? |
| Closure evidence | Was the issue completed and verified? |
| Retention requirement | How long should it remain available? |
| Retrieval location | Can authorised users find it quickly? |
| Last verified | When was the evidence trail last checked? |
Then perform a simple test:
Choose one obligation and attempt to retrieve its complete evidence chain without relying on the memory of a specific employee.
The gaps you find will tell you far more than the number of documents stored in the repository.
Where Connected EHS Workflows Help
This is where digitalisation can provide value—but only when it connects the operating process.
Simply scanning existing documents into another repository does not solve the underlying problem.
A connected EHS environment can make it easier to link records from activities such as:
- audits;
- inspections;
- corrective actions;
- training;
- Permit to Work;
- document control;
- workforce records;
- approvals;
- dashboards and management review.
With OQSHA, the useful objective is not merely to “digitise compliance”.
It is to help teams maintain traceability between the activity, responsible role, record, evidence and resulting action.
For example, an audit finding can remain connected to its owner and CAPA. An inspection record can retain its action history. Training evidence can remain associated with the relevant worker. Permit records can maintain their approval trail.
That can make evidence easier to review and retrieve.
It does not, by itself, establish that every applicable legal obligation has been met. Legal applicability and compliance decisions remain the organisation’s responsibility and should be validated by appropriate legal, compliance and EHS professionals.
The Practical Test for EHS Leaders
Before your next compliance review, choose one requirement and ask:
- What exactly applies?
- Which site, process or workforce does it apply to?
- Who owns the control?
- What evidence should exist?
- Is that evidence current and approved?
- Can we connect it to the actual activity?
- Were exceptions or findings raised?
- Can we demonstrate closure?
- Can another authorised person retrieve the same evidence without asking the original record owner where it is?
If the answer to the last question is no, the problem may not be a lack of documentation.
It may be a lack of evidence architecture.
Because during an audit, having evidence and being able to prove the complete context of that evidence are not the same thing.
Test One Obligation End to End
Do not begin by reorganising every compliance folder.
Choose one important obligation and map it through:
Requirement → Applicability → Owner → Control → Record → Approval → Action → Closure

Use OQSHA’s Compliance Evidence Register & Audit Retrieval Checklist to identify where the chain breaks.
FAQ
Is the Occupational Safety, Health and Working Conditions Code, 2020 currently effective?
Yes. The Government of India announced that the four Labour Codes, including the OSH&WC Code, would be effective from 21 November 2025. The OSH&WC (Central) Rules, 2026 were published in May 2026. Organisations should still determine the exact central/state rules, notifications, sector provisions and appropriate-government requirements applicable to each establishment.
Government announcement on implementation of the four Labour Codes
Is storing OSH documents in one repository enough for compliance?
A repository can improve storage and retrieval, but it does not by itself establish compliance. Organisations still need to determine applicability and maintain appropriate evidence of implementation, ownership, approvals, actions and other requirements relevant to their operations.
What makes compliance evidence traceable?
At minimum, teams should be able to connect the record to the applicable requirement, establishment or activity, responsible role, current version or validity status, approvals, related findings and closure evidence.
Does ISO 45001 certification prove compliance with India’s OSH Code?
No. ISO 45001 is an international OH&S management-system standard. It can support systematic safety management, but it should not be represented as a substitute for meeting applicable legal requirements.
What management approach can help organisations maintain evidence continuously?
A structured management-system approach is useful because it integrates planning, implementation, checking and improvement into normal operations. HSE’s HSG65 guidance, for example, uses the Plan–Do–Check–Act model for managing health and safety.
0 Comments