Skip to content
S.G. Technologies
All insights
Compliance · 8 min read

Safety and Security on One Risk Register: Closing Ghana's Compliance Gap

UK enforcement trends show what happens when occupational safety and physical security are managed apart. Here is how Ghanaian organisations can bring them together under one risk framework.

A tipper truck driver injured on a UK infrastructure project. A tank explosion prosecution against a defence contractor. A fatality on a residential site that leaves a family without a husband and father. None of these incidents happened in Ghana, but the pattern behind them is one we see in West African facilities every year: a safety failure that was, in truth, a risk management failure. The hazard existed. Someone likely knew about it. The systems meant to catch it — permits, inspections, reporting lines — either didn’t exist or weren’t followed.

For Ghanaian organisations, the lesson is not “improve safety.” It is narrower and more useful than that: stop managing safety and security as two separate conversations. They draw on the same risk methodology, the same site data, and, in most facilities, the same people. Treating them separately creates blind spots that regulators, insurers and courts are increasingly unwilling to accept.

Two Risk Registers, One Blind Spot

In many Ghanaian facilities — manufacturing plants, agribusiness processing sites, warehouses, even hospitals — physical security and occupational safety report through different lines. Security answers to operations or a facilities manager; safety answers to HR or a compliance officer. Each keeps its own risk register. Each runs its own audits. Each escalates to a different meeting.

The result is that hazards sitting at the intersection — a contractor with unsupervised site access, a fire exit blocked by stored stock, a tool crib with no control over checkout, unguarded machinery near a public-facing loading bay — fall into the gap between the two registers. Nobody owns them until an incident forces the question of who should have.

ISO 31000 does not distinguish between safety risk and security risk. It treats them both as sources of uncertainty to an organisation’s objectives, assessed through the same cycle: identify, analyse, evaluate, treat, monitor. Organisations that force their safety and security functions to use that same cycle, on the same register, close the gap before it becomes a headline.

What Ghana’s Regulatory Framework Already Demands

This is not a theoretical exercise — Ghanaian law already expects integration, even if practice hasn’t caught up.

  • The Factories, Offices and Shops Act (1970, Act 328) requires registered premises to maintain safe means of access and egress, guard dangerous machinery, and report notifiable accidents. Enforcement inspections increasingly look at whether physical security measures (access control, perimeter barriers, storage layouts) are undermining these safety obligations rather than supporting them.
  • GNFS fire certification is a recurring pain point precisely because security and safety decisions collide: security teams add grilles, barriers or turnstiles to control access, and these same measures can compromise a fire escape route or block an extinguisher point flagged in a fire audit. A fire certificate renewal that fails because of a security modification is an entirely avoidable, and increasingly common, finding.
  • The Labour Act (2003, Act 651) places general duties on employers to provide a safe working environment and requires reporting mechanisms for workers raising concerns — a domestic equivalent to the whistleblower protections regulators abroad are actively strengthening.
  • The Data Protection Act (2012, Act 843) governs how CCTV footage, access logs and biometric attendance data — all security tools — are captured, stored and used, which means security system design is now also a compliance obligation, not just an operational one.

None of these instruments separate “safety compliance” from “security compliance.” Neither should the organisations subject to them.

Building One Integrated Risk Register

An integrated register doesn’t require new software or a large project team. It requires a shared risk taxonomy and a single owner for the review cycle. In practice this means:

Contractor and third-party risk. Tool and equipment theft from site — a growing concern on construction and industrial sites regionally — is both a security failure (access control, custody chain) and a safety failure (unauthorised persons operating unfamiliar equipment). One register, one control set: sign-in/sign-out, supervised zones, verified inductions.

Occupational hazard monitoring. Noise exposure on production floors and chemical handling in processing or agribusiness settings are safety issues with a security dimension — access to hazard zones must be restricted and logged, and monitoring equipment itself needs protection from tampering or theft. Treating exposure monitoring purely as an HSE exercise, without security’s involvement in access control to those zones, weakens both.

Physical layout reviews. Every change to a site’s security architecture — a new barrier, an added checkpoint, a reconfigured storage area — should be reviewed against fire egress and safe access requirements before installation, not after a GNFS or Factories Inspectorate visit flags it.

Incident and near-miss reporting. A single reporting channel for safety near-misses, security breaches and suspicious activity produces better data than three fragmented systems, and it supports the kind of whistleblower confidence regulators globally are pushing organisations to strengthen.

Governance: Who Actually Owns This

Integration fails when it has no owner. The practical fix is a joint risk committee — security, safety/HSE, facilities and a senior operational sponsor — that meets on a fixed cycle to review the combined register, not two committees comparing notes afterwards. Findings from security audits should feed the safety review and vice versa. Where an organisation is ISO 9001 certified, this committee can sit naturally within the existing management review process rather than adding a parallel structure.

A Practical Starting Checklist

  • Confirm your Factories, Offices and Shops Act registration and GNFS fire certificate are current, and that any recent security modifications haven’t compromised egress routes
  • Map who currently owns safety risk versus security risk on your organisational chart — if they don’t meet, that’s your first gap
  • Review CCTV, access control and attendance data handling against the Data Protection Act’s requirements
  • Establish one incident/near-miss reporting channel covering both safety and security events
  • Check contractor and visitor access controls against equipment and tool custody procedures
  • Schedule a joint safety-security risk review at least quarterly, using one shared register

Enforcement actions abroad rarely stem from a single dramatic failure — they stem from small, siloed oversights that accumulated because no one function owned the full picture. A baseline security assessment that deliberately maps these intersections — where access control meets fire safety, where contractor management meets equipment custody, where data handling meets surveillance — gives Ghanaian organisations the evidence base to close that gap before a regulator, insurer or court does it for them.

Share this article

Start with a risk assessment

Every SGT engagement starts with a structured, evidence-led assessment. Tell us about your sites and we'll scope it within one business day.