Safety and Health Management System Requirements: Checklist for Korean Entities

 

Key takeaways

  • Two separate statutes impose "management system" duties in Korea, and satisfying one does not satisfy the other. The Occupational Safety and Health Act (OSHA) requires appointments, a committee, and board-level reporting. The Serious Accidents Punishment Act (SAPA) requires nine distinct measures by the responsible management person, backed by criminal liability.

  • Most of the SAPA duties run on a half-year cadence. Five of the nine subparagraphs, plus the separate statutory-compliance check, require inspection "at least once every half year." An annual review does not discharge them.

  • The duty attaches to the person who represents and has overall control of the business in Korea normally the representative director of the Korean entity, not the global CEO. Assuming the obligation sits at headquarters is the structural error that most often surfaces after an incident, not before.

  • SAPA covers "workers and other persons engaged in work", a category broader than your payroll. Dispatched workers, contractor and subcontractor personnel, and outsourced service staff at your site are inside the scope.

  • SAPA has applied to businesses with 5 to 49 full-time workers since 27 January 2024. Businesses with fewer than 5 full-time workers remain outside it. A small Korean office of a large global group is judged on its own headcount, not the group's.


Why a global framework does not map cleanly onto this

Multinational groups arriving in Korea usually already have a safety and health management system. It is often certified to ISO 45001, documented in English, owned by a global EHS function, and audited on a cycle that has worked in a dozen other jurisdictions.

 

The difficulty is not that Korea rejects that system. It is that Korea asks a different question of it. ISO 45001 asks whether a management system exists and functions. Korean law asks whether nine specified things were done, by a specified person, at a specified frequency, with a record that survives inspection.

 

A certified system with no Korean-language record of a half-yearly review, signed off by the Korean representative director, does not answer the Korean question. A modest, unglamorous binder that does answer it will fare considerably better.


Layer one: what the Occupational Safety and Health Act requires

This layer is about structure who is appointed, what body meets, and what reaches the board.

 

The appointment thresholds turn on industry classification as well as headcount, and the classification matters especially for foreign-invested entities, because software development and supply, information services, finance and insurance, and leasing sit at much higher thresholds than manufacturing.

 

Requirement Who must do it Cadence / trigger
Safety and health manager in overall charge  Manufacturing and similar: 50+ full-time workers. Finance and insurance, software development and supply, information services, leasing, agriculture and fishery: 300+. Other businesses: 100+. Construction: works value KRW 2 billion or more On reaching the threshold
Supervisors Businesses with workers directing or supervising work at the production unit level Standing role; 16 hours of training per calendar year
Safety manager Manufacturing and similar: 50+ (2 required at 500+). Office-type industries at higher thresholds see note below On reaching the threshold
Health manager Manufacturing and similar: 50+ On reaching the threshold
Occupational Safety and Health Committee Manufacturing and similar hazardous industries: 50+. Wholesale, retail, lodging and food service: 100+. Software, IT, finance and insurance: 300+ Regular meeting at least once per quarter
Board reporting of the safety and health plan Stock companies with 500+ full-time workers, and construction companies ranked within the top 1,000 by construction capacity Annually; the representative director prepares the plan, reports it to the board, and obtains approval
Risk assessment All businesses within scope of the Act Initial, regular, and event-triggered; records retained

 

The exact industry lists and headcount bands in Enforcement Decree Tables 2, 3 and 9 should be checked against your Korean Standard Industrial Classification code before you conclude that a threshold does not apply to you. The bands above are drawn from secondary summaries that agree with each other but are not a substitute for the current table text for your specific classification.

 

Board reporting is the item global HR teams most often miss, because it looks like a governance matter rather than a safety one. If your Korean entity is a company with 500 or more full-time workers, the representative director must prepare an annual safety and health plan, report it to the board, and obtain board approval. The administrative fine is up to KRW 10 million. A global EHS plan approved by a parent-company board does not satisfy it the reporting must occur at the Korean company's own board.


Layer two: the nine measures under the Serious Accidents Punishment Act

This is the layer with criminal exposure, and it is the one that is genuinely difficult to satisfy from a distance.

The Enforcement Decree specifies nine measures. The English translation published by the Korea Legislation Research Institute is a useful reference point for global teams, though it is expressly non-official.

 

# Measure Half-year check?
1 Establish safety and health objectives and management policy for the business No fixed cadence stated
2 Establish a dedicated safety and health organisation of at least three persons required for businesses with 500 or more full-time employees, and for constructors ranked within the top 200 by construction capacity On reaching the threshold
3 Establish procedures to identify and improve hazardous and risk factors inspect at least once every half year and take necessary measures Yes
4 Allocate the budget necessary for accident prevention, improvement of hazards, and the safety and health measures determined by the Ministry Annual budgeting; execution monitored
5 Give the safety and health manager in overall charge the authority and budget to perform the role, and evaluate performance against criteria at least once every half year Yes
6 Place the safety and health personnel required by the OSH Act in the numbers the Act requires Continuous
7 Establish a procedure to hear the opinions of persons engaged in work on hazard improvement, and verify at least once every half year that opinions were heard and acted on Yes
8 Prepare a manual for responding to an imminent serious accident work stoppage, evacuation, rescue, and reporting and inspect at least once every half year that it is followed Yes
9 Where work is contracted out, established evaluation criteria and procedures covering the contractor's accident-prevention capability, safety and health management costs, and adequacy of the work period, and inspect at least once every half year Yes

 

Separately, the Decree requires a check, at least once every half year, that the duties imposed by safety and health statutes are actually being performed, with reporting and where they are not allocation of the budget and personnel needed to fix the gap.

 

The pattern is worth stating plainly to a headquarters audience. Korea has built a half-yearly rhythm into the compliance architecture: worker safety training runs on half-year cycles, and the great majority of the SAPA management-system duties run on half-year checks. An organisation that reviews Korea annually is out of step with the statute in both places at once.


Who is the responsible person in a foreign-invested structure?

SAPA attaches the duty to the business owner or the "responsible management person" the person who represents the business and has overall authority and responsibility for it, or a person with equivalent responsibility for safety and health matters.

 

For a locally incorporated subsidiary, this normally means the representative director of the Korean company. Not the regional president. Not the global CEO. Not the group EHS director. The person whose name is on the Korean corporate registry and who exercises actual authority over the Korean business is the starting point, and Korean practice looks at real decision-making authority rather than title alone.

 

Three structural situations recur in practice, and each deserves specific advice rather than a general answer:

The branch of a foreign company. A Korean branch is not a separate legal person, but it has a registered Korea representative and it employs workers in Korea. The duties of an employer under Korean labour and safety law generally follow the workplace, not the corporate form.

The liaison office. A liaison office is not permitted to conduct profit-generating business, but it may employ staff. Whether and how the management-system duties apply to an office in this position is not a question that can be answered generically.

Dual-hatted regional leadership. Where a regional executive based outside Korea holds decision authority over budget and headcount while a local country manager holds the title, the allocation of responsibility is a matter of substance. Structures designed for tax or reporting efficiency can produce an unintended answer here.

 

We recommend legal review before publication of any internal position on this point, and before relying on any conclusion above.


The scope problem: "persons engaged in work" is wider than your payroll

The single most consequential difference between a global framework and the Korean one is who counts.

SAPA speaks of persons engaged in work and the category reaches beyond direct employees. It covers workers under a labour contract, persons who provide labour for remuneration regardless of contract form, and the workers of contractors, subcontractors, and service providers in a contracting chain.

 

For a Korean entity of a global group, that typically means the following people are inside your scope even though none of them appear in your HRIS headcount: the security and reception staff supplied under a facilities contract, the cleaning crew, the cafeteria operator's employees, the dispatched workers filling temporary roles, the equipment vendor's engineers who come on site to service machines, and the construction crew doing your office fit-out.

 

A global procurement framework that scores vendors on price, quality, and delivery, with a generic EHS attestation checkbox, does not meet this. The criteria have to exist in a form you can show, and the half-yearly check has to have happened.


 

Mapping ISO 45001 onto the Korean checklist

For groups that already run a certified system, the efficient approach is mapping rather than rebuilding.

 

Much of ISO 45001 maps well: policy and objectives to subparagraph 1, hazard identification and risk assessment to subparagraph 3, resources to subparagraph 4, roles and responsibilities to subparagraphs 5 and 6, consultation and participation of workers to subparagraph 7, emergency preparedness and response to subparagraph 8, and procurement and contractor control to subparagraph 9.

 

What does not map is the specificity. ISO expects you to determine appropriate frequencies; Korea specifies half-yearly. ISO expects top management commitment; Korea names a person and attaches criminal liability. ISO expects competent persons; Korea specifies statutory appointments at defined headcount thresholds. And ISO 45001 says nothing about reporting an annual safety and health plan to the board of a Korean stock company.

 

The workable output is a two-column mapping document that lists each Korean requirement, the ISO clause and internal control that covers it, and the Korean-specific gap that has to be closed separately. That document is also the most useful thing to hand to Korean counsel, because it turns an open-ended review into a short list.


 

Common mistakes

  • Treating an ISO 45001 certificate as evidence of SAPA compliance. The certificate speaks to a system; the statute asks for nine specified measures with dated records.

  • Reviewing Korea annually. Five of the nine measures, plus the statutory-compliance check, are half-yearly.

  • Locating the responsible management person at headquarters. The duty follows actual authority over the Korean business.

  • Counting only payroll employees. Contractor, subcontractor, dispatched, and service-provider personnel are within scope.

  • Running contractor selection on a global procurement framework with no safety-specific evaluation criteria and no half-yearly check that they were applied.

  • Missing the board reporting duty because it sits with the corporate secretary rather than with EHS or HR.

  • Holding all evidence in English, in a headquarters system, with no Korean-language operative version and no local export capability.

  • Assuming a small Korean office is out of scope. The 5-worker floor is assessed at the business, and the 50-worker deferral ended on 27 January 2024.

  • Documenting that a half-yearly check occurred without documenting what it found and what changed as a result.


How EAP supports employees and HR

Subparagraph 7 asks for something that is easy to write down and hard to make real: a procedure through which the people doing the work can raise hazards, and evidence twice a year that their views were heard and acted on.

 

Procedures of this kind fail for reasons that are psychological rather than administrative. People do not raise a concern to a manager who assigns their work, in a second language, in a culture where they are uncertain how the report will be received. The form exists; the reporting does not happen; the half-yearly review records nothing to act on. That is a weak position on the day it matters.

 

WHO guidance on mental health at work identifies manager capability and worker-directed support as complementary interventions, and is explicit that organisational conditions not individual resilience alone determine outcomes. ISO 45003 places psychosocial risk inside the occupational health and safety management system, which means the framework carrying your nine Korean measures is the same framework expected to carry psychosocial risk. Under the EAPA Core Technology, consultation with managers and organisations on employee and organisational issues, and confidential problem identification and referral, are core employee assistance functions.

 

For a Korean entity of a global group, an EAP contributes at three specific points. It gives workers a confidential route, in Korean and English, that does not run through the line manager which is what makes a concern surfaceable when the reporting line is the problem. It gives the supervisor who receives a disclosure somewhere to take it before it becomes an incident. And where a pattern appears across a team rather than in one individual, it produces organisational-level input that belongs in the half-yearly review under subparagraph 7 the difference between a review with nothing to record and one with a genuine finding.

 

Serious accident prevention is not principally a mental health question. But the mechanism the statute relies on to surface hazards is a human one, and it works only if people are willing to speak.


Related guides


FAQ

Q1. We are ISO 45001 certified globally. How much of the Korean requirement does that cover?

Most of the substance, none of the specifics. Your certified system will almost certainly contain equivalents of the policy, risk assessment, resourcing, consultation, emergency response, and contractor control requirements. What it will not contain is the half-yearly cadence Korea specifies, the statutory appointments at Korean headcount thresholds, the identification of a Korean responsible management person, or the board reporting duty. Map the system to the nine measures and close the gaps individually.

 

Q2. Our Korean office has 30 employees and no factory. Are we in scope?

For SAPA, yes, the deferral for businesses with fewer than 50 full-time workers ended on 27 January 2024, and only businesses with fewer than 5 full-time workers sit outside the Act. For the OSH Act appointment thresholds, whether you must appoint a safety and health manager in overall charge, a safety manager, or a health manager depends on your industry classification as well as headcount, and office-type classifications sit at substantially higher thresholds. Risk assessment and worker safety training apply regardless.

 

Q3. Do the duties cover our outsourced facilities and security staff?

Yes. SAPA covers persons engaged in work, including the workers of contractors, subcontractors, and service providers. In practice this means your contractor evaluation criteria under subparagraph 9 have to cover them, and your emergency response manual and hazard reporting procedure have to reach them.

 

Q4. Does our documentation have to be in Korean?

The practical answer is that the operative version should be Korean, with an English version maintained alongside it. An inspector will read Korean; a substantial share of your workforce will read Korean; and a procedure for hearing worker opinions is difficult to defend if it exists only in a language many of those workers do not use. Bilingual maintenance is the approach we would recommend for any entity with a mixed-language workforce.


Next step

Build the mapping document before you build anything else. List the nine SAPA measures and the OSH Act appointment and reporting duties down one side; against each, record the internal control that covers it, the person accountable in the Korean entity, the last date it was performed, and where the record sits.

 

Two columns will tell you most of what you need. Any row where the last performed date is more than six months old is a gap on the statute's own cadence. Any row where the accountable person sits outside Korea is a gap on the question of who the responsible management person actually is.

 

Then take the completed mapping to Korean counsel rather than commissioning an open-ended review, and put the half-yearly checks into the Korean entity's calendar as fixed dates rather than as a task that follows the global audit cycle.

 

If your organization needs a coordinated approach to employee mental health, manager support, and workplace response alongside its statutory safety and health management system, contact Nudge EAP to discuss an implementation model suited to your workforce.

 


NOTE: This article is intended for general informational purposes only. Specific legal, medical, clinical, or employment-related matters may require review by an appropriately qualified professional. The Serious Accidents Punishment Act carries criminal liability, and the positions described here should not be relied on without qualified Korean legal advice.

 

👉 Go to Nudge EAP Implementation Consultation →

Sources

  1. Enforcement Decree of the Serious Accidents Punishment Act, Article 4 (Measures to establish and implement safety and health management systems) and Article 5, English translation, Korea Legislation Research Institute — https://elaw.klri.re.kr/eng_mobile/viewer.do?hseq=59953&type=sogan&key=6

  2. Serious Accidents Punishment Act, English translation, Korea Legislation Research Institute — https://elaw.klri.re.kr/eng_service/lawView.do?hseq=59952&lang=ENG

  3. 중대재해 처벌 등에 관한 법률 시행령 제4조 (안전보건관리체계의 구축 및 이행 조치), 국가법령정보센터 — https://www.law.go.kr/LSW/lsLinkCommonInfo.do?lspttninfSeq=173767&chrClsCd=010202

  4. 중대재해처벌법 적용 기준과 처벌 수위 — 5인 미만 적용 제외, 2024년 1월 27일 50인 미만 확대 적용, 중대산업재해의 정의, 사망 시 1년 이상 징역 또는 10억원 이하 벌금 및 법인 50억원 이하 벌금, 부상·질병 시 7년 이하 징역 또는 1억원 이하 벌금 및 법인 10억원 이하 벌금, 법무법인 대륜 — https://www.daeryunlaw-labor.com/lawInfo_new/2776

  5. 중대재해처벌법 경영책임자 의무 9가지 체크리스트 — 시행령 제4조 각 호의 실무 정리 및 기록 요건 — https://safeyou365.com/blog/ceo-safety-duties-checklist/

      1. 기준 산업안전보건법 주요내용 및 벌칙 — 제14조 이사회 보고 및 승인 대상(상시근로자 500명 이상 주식회사, 시공능력 상위 1,000위 이내 건설회사)과 1,000만원 이하 과태료, 관리자 선임 의무, 산업안전보건위원회, 안전보건교육 시간, 연세대학교 연구처 — https://rus.yonsei.ac.kr/research/foundation/safety.do?mode=download&articleNo=463948&attachNo=204984
  6. 산업안전보건법 시행령 [별표 2] 안전보건관리책임자를 두어야 하는 사업의 종류 및 사업장의 상시근로자 수 (제14조제1항 관련), 국가법령정보센터 — https://www.law.go.kr/LSW/flDownload.do?gubun=&flSeq=153272949&bylClsCd=110201

  7. 산업안전보건법 시행령 [별표 3] 안전관리자를 두어야 하는 사업의 종류, 사업장의 상시근로자 수, 안전관리자의 수 및 선임방법 (제16조제1항 관련), 국가법령정보센터 — https://law.go.kr/LSW/flDownload.do?flSeq=108497327&bylClsCd=110201

  8. 산업안전보건법 시행령 [별표 9] 산업안전보건위원회를 구성해야 할 사업의 종류 및 사업장의 상시근로자 수 (제34조 관련), 국가법령정보센터 — https://law.go.kr/LSW/flDownload.do?flSeq=108497393&bylClsCd=110201

  9. 안전보건관리책임자·안전관리자·보건관리자 선임기준 업종별 정리 — 제조업 50명 이상, 금융 및 보험업·소프트웨어 개발 및 공급업·정보서비스업·임대업 등 300명 이상, 그 밖의 사업 100명 이상, 건설업 공사금액 20억원 이상 — https://soonyguide.com/8-2/ ; 업종 수 기준 요약 — https://safetysupport.co.kr/safety-and-health-management-eligibility/

  10. 산업안전보건위원회 구성 대상 및 분기 1회 이상 정기회의, 500만원 이하 과태료, 다우오피스 HR — https://hr.daouoffice.com/blog/100-employee-legal-obligations

  11. 산업안전보건법에 따른 대표이사의 안전보건계획 수립 및 이사회 승인·보고 의무, 김·장 법률사무소 — https://www.kimchang.com/ko/insights/detail.kc?sch_section=4&idx=22967

  12. 안전보건관리체계 구축을 위한 가이드북, 고용노동부 — https://www.moel.go.kr/policy/policydata/view.do?bbs_seq=20210802108

  13. 사업장 위험성평가에 관한 지침 (고용노동부 고시), 국가법령정보센터 — https://www.law.go.kr/LSW//admRulInfoP.do?admRulSeq=2100000251014&chrClsCd=010201

  14. World Health Organization, Guidelines on Mental Health at Work (2022) — https://www.who.int/publications/i/item/9789240053052

  15. World Health Organization, Mental health at work fact sheet — https://www.who.int/news-room/fact-sheets/detail/mental-health-at-work

  16. ISO 45003:2021, Occupational health and safety management — Psychological health and safety at work — https://www.iso.org/standard/64283.html

  17. Employee Assistance Professionals Association, Definition and Core Technology of Employee Assistance Programs — https://eapassn.org/page/definitionandcoretechnology

댓글5
  • 익명4
    BEST
    How should a Korean subsidiary document the responsible management person when decision-making authority is split between a local representative director and a regional headquarters leader? This seems like an area where legal review is especially important.
  • 익명3
    The point about contractors and service-provider staff is important. A company may think only payroll employees are in scope, but outsourced facilities, cleaning, reception, or vendor staff can still matter for the Korean checklist.
  • 익명2
    The half-year cadence stood out to me. If five of the nine SAPA measures require checks at least every half year, an annual global audit cycle would clearly leave gaps.
  • 익명1
    This article was helpful because it separates the OSHA structure requirements from the Serious Accidents Punishment Act duties. Global teams often treat them as one safety management framework, but the Korean requirements seem much more specific.