Key timelines to ensure compliance

Issue 6 2023 Security Services & Risk Management


Kate Collier.

Amended regulations regulating Major Hazard Installations (MHI) under the Occupational Health and Safety Act (OHSA) were promulgated in January 2023. They apply to MHI establishments with the prescribed quantities of listed substances and major pipeline establishments. They require the duty holder (the employer, self-employed person, a user or pipeline operator who is in control of an establishment) to take steps to manage health and safety risks, some of which are in addition to the measures required under the 2001 regulations. In respect of existing establishment, timelines for compliance with some of these new obligations have been set out.

To comply fully with the MHI regulations, duty holders should have assessed and determined whether the MHI or major pipeline establishment is a low, medium, or high-hazard establishment.

Although the MHI regulations came into effect in January 2023, certain extended time periods were provided for duty holders to achieve specific regulatory compliance.

The following timelines should be borne in mind when existing MHI establishments are under the control of employers:

• All duty holders must update the notification of an existing establishment and send it to the Chief Inspector, the relevant Chief Director: Provincial Operations and local government, using the prescribed form, by 31 January 2025. Extensive information has to be submitted, and duty holders should ensure they have sufficient time to complete the necessary risk assessments and collate the required information.

• Duty holders of medium and high-hazard establishments must draw up and record a major incident prevention policy based on the criteria contained in MHI regulation 11 and Annexure C to the MHI regulations by 31 January 2026.

• Duty holders of high-hazard establishments must prepare a comprehensive, site-specific safety report in terms of MHI regulation 12. The report must be sent to the Chief Inspector by 31 January 2026.

• Duty holders who operate a high-hazard establishment must apply for a licence to operate it by no later than 31 January 2026.

• Emergency plans must be updated and aligned with SANS 1514 criteria by 31 January 2024.

Current obligations for which there are no transitional time periods include:

• Notifications under MHI regulation 4 must be made 90 days before a new establishment is erected or when a change to an existing establishment is anticipated.

• Competent person(s) must be appointed in a full-time capacity for every premises on which an establishment is operated. They will be responsible for ensuring that the OHSA and the MHI regulations are complied with.

• Holding regular consultations with neighbouring establishments and counterparties within the potential impact zone.

• Providing details of any alteration to the particulars of a registered establishment no later than 14 days from the date of the alteration.

• Conducting risk assessments in accordance with MHI regulation 10.

• Appointing an emergency co-ordinating team and establishing emergency plans.

• Reporting major incidents or incidents that brought the emergency plan into operation, including submitting a preliminary incident report within seven days and a final report within six months of the date of the incident.

• Providing information and training as set out in MHI regulation 17.

• Suppliers of a dangerous substance to an establishment must inform other clients to whom they have supplied that substance about emerging potential dangers in the event of an incident involving that substance. In the event of a major incident, suppliers must be readily available on a 24-hour basis to all duty holders, relevant local government and any other body concerned.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Global security in 2026
Editor's Choice News & Events Security Services & Risk Management Industrial (Industry) Mining (Industry)
The World Security Report 2026 states: “In a world of increasing volatility, physical security has evolved. It is no longer just a defensive measure; it is a critical driver of corporate value.”

Read more...
Who is to blame for autonomous mistakes?
Editor's Choice Security Services & Risk Management Industrial (Industry) Mining (Industry)
Most supply agreements for AI-integrated equipment still closely resemble plant hire contracts from ten years ago: bilateral, human-focused, and silent on who bears the risk when a machine makes a decision on its own.

Read more...
Cyber resilience is the real defence
Security Services & Risk Management Information Security Infrastructure
Cyber resilience has evolved into a form of strategic agility, ensuring that when an interruption occurs, the business does not just survive; it snaps back into place before the market even notices a pause.

Read more...
Employees are SA’s biggest cyber threat
Security Services & Risk Management Information Security
South Africa experienced a 46% increase in insider cyber risk in 2026, surpassing the global average of 44%. What is more, 63% of South African companies surveyed expect insider-driven data losses to increase.

Read more...
The post-Q1 security checklist
Asset Management Security Services & Risk Management
By this time of year, employees have changed jobs or roles, suppliers may have changed, and devices have moved between offices, homes, and sites. This is the right time for businesses to run a practical post-Q1 security check.

Read more...
PoPIA turns its attention to gated access
News & Events Security Services & Risk Management
The Information Regulator has gazetted its proposed Code of Conduct for the processing of personal information at gated access points. At 65 pages long, the code signals a significant shift in how personal information is collected and managed at entry points.

Read more...
Your company is already breached, you just do not know it yet
Information Security Security Services & Risk Management
Attackers are no longer relying on sophisticated exploits to break-in. Instead, they are systematically targeting weak credentials, misconfigured systems, and exposed devices stemming from preventable gaps such as identity weaknesses and poor visibility across digital environments.

Read more...
Excellerate Services sets a new standard
News & Events Security Services & Risk Management
Excellerate Services relies on specialist expertise and the sophistication of its operations deployment and management. Central to this is an investment in smarter, data-driven operations through the Velocity and Performance Centre platforms.

Read more...
957 women killed in three months
News & Events Security Services & Risk Management
Despite years of summits, task teams and public commitments, South Africa’s femicide rate remains around five times higher than the global average, and too few are using the legal lifelines available.

Read more...
The security debt hidden in residential estates
Security Services & Risk Management Integrated Solutions Residential Estate (Industry)
Many residential estates undermine their own security not through a lack of technology, but through hidden weaknesses in gate design, fragmented systems, recurring software dependence, weak operational ownership, and insufficient estate management input.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.