Canada CCOHS and the Internal Responsibility System: A Compliance Primer
If you manage health and safety for an operation with Canadian sites, you have probably noticed that the rulebook reads differently than OSHA. Canadian occupational health and safety law expects you to figure out the appropriate controls for your own workplace rather than handing you a checklist of prescriptive steps. That shift in burden — from following rules to demonstrating a working system — is the Internal Responsibility System, and misunderstanding it is how organizations end up exposed in an audit or, worse, a criminal investigation.
This primer explains what the Internal Responsibility System (IRS) is, how the Canadian Centre for Occupational Health and Safety (CCOHS) frames it, what the Westray Bill added in terms of criminal liability, and what you need to have in place to show due diligence. It is written for EHS and compliance managers who need to operationalize the concept, not just define it.
Build the evidence trail Canadian OHS expects. WhyTrace Plus turns every incident, near-miss, and corrective action into a documented, time-stamped record of the steps your organization took — the exact proof an IRS-based system requires. See how WhyTrace Plus supports OHS compliance →
What the Internal Responsibility System (IRS) Actually Means
The Internal Responsibility System is the foundational philosophy of occupational health and safety legislation across every Canadian jurisdiction. It holds that everyone in the workplace — employers, supervisors, and workers alike — shares responsibility for health and safety, and that each party is accountable both for their own safety and for the safety of those around them.
This is a different starting point from prescriptive regimes. According to CCOHS, Canadian OHS acts and regulations frequently do not impose or prescribe the specific steps an employer must take. Instead, the law holds employers responsible for determining the steps necessary to ensure the health and safety of all workers in their specific operation. The expectation is an employer-worker partnership that solves hazards collaboratively rather than waiting for an inspector to dictate a fix.
Three practical consequences follow from the IRS model:
- The duty is internal first. Government enforcement is the backstop, not the front line. The system assumes the workplace identifies and resolves its own hazards before a regulator becomes involved.
- Responsibility is layered, not delegated away. A worker's responsibility to follow safe practices does not relieve a supervisor's responsibility to provide a safe system of work, and neither relieves the employer's overarching duty.
- You must be able to show your reasoning. Because the law often does not prescribe the "how," you carry the burden of demonstrating that the controls you chose were reasonable for the hazards you faced.
That last point is where documentation stops being administrative overhead and becomes your primary legal protection.
| IRS party | Core responsibility | Typical evidence expected |
|---|---|---|
| Employer | Establish policies, procedures, and resources for a safe workplace | OHS program, risk assessments, management review records |
| Supervisor | Ensure workers follow safe practices and use required protection | Inspection logs, toolbox talks, training sign-offs |
| Worker | Follow safe work practices and report hazards | Hazard reports, near-miss submissions, training completion |
How CCOHS Frames Your Compliance Obligations
CCOHS is the federal Crown agency that publishes the authoritative plain-language guidance Canadian employers rely on to interpret OHS law. It does not write the legislation — that authority sits with each province, territory, and the federal jurisdiction — but its OSH Answers materials are the reference point most EHS managers and joint health and safety committees use to understand what compliance looks like in practice.
For compliance purposes, CCOHS guidance organizes worker protection around three rights that the IRS depends on to function:
- The right to know about hazards in the workplace, including the materials, equipment, and processes a worker is exposed to.
- The right to participate in identifying and resolving health and safety concerns, typically through a joint health and safety committee or worker representative.
- The right to refuse work the worker reasonably believes is dangerous, without reprisal.
These rights are not decorative. They are the mechanism that makes internal responsibility enforceable from the bottom up. A worker who cannot access hazard information, cannot raise a concern through a functioning committee, or fears retaliation for refusing dangerous work breaks the feedback loop the entire system relies on.
The compliance implication for you is concrete: an IRS program that exists only on paper — a policy binder with no active committee, no hazard reporting traffic, and no record of issues being raised and resolved — is the pattern auditors and investigators treat as a system that is not actually operating. CCOHS guidance repeatedly emphasizes that the IRS is something a workplace must keep functioning, not a status it achieves once.
Make the three rights demonstrable. WhyTrace Plus gives workers a low-friction channel to report hazards and near-misses, routes them to the right owner, and keeps the resolution trail intact — so your "right to participate" produces records, not just intentions. Explore WhyTrace Plus for field reporting →
The Westray Bill and Criminal Liability for Workplace Safety
The Westray Bill — Bill C-45 — amended Canada's Criminal Code to establish criminal liability for organizations and individuals who fail to protect worker safety. It became law on March 31, 2004, in response to the 1992 Westray coal mine explosion in Nova Scotia, where a methane ignition killed 26 miners after warnings about unsafe conditions went unaddressed.
The core provision is Section 217.1 of the Criminal Code:
"Every one who undertakes, or has the authority, to direct how another person does work or performs a task is under a legal duty to take reasonable steps to prevent bodily harm to that person, or any other person, arising from that work or task."
Two points about Section 217.1 matter for your risk picture. First, it did not create a brand-new offence; instead it clarified a legal duty, which makes it far easier for prosecutors to pursue the existing offence of criminal negligence when a workplace death or serious injury occurs. Second, the duty attaches to anyone with the authority to direct how work is done — that reaches supervisors, managers, and directors, not just the corporate entity.
This is the dimension that distinguishes Canadian OHS exposure from a purely regulatory fine. A serious OHS failure in Canada can produce two parallel tracks: provincial OHS prosecution carrying substantial penalties, and Criminal Code prosecution that can result in imprisonment for individuals. The IRS philosophy and Section 217.1 reinforce each other — the law expects you to run an internal system, and failing to take "reasonable steps" can become a criminal question, not only an administrative one.
Demonstrating Due Diligence Under Canadian OHS Law
Due diligence is the legal defence available when an organization has taken every reasonable precaution to prevent a workplace incident, even if an incident still occurs. In a system built on internal responsibility, due diligence is not a slogan — it is the standard against which your decisions are judged after something goes wrong.
Legal guidance on establishing due diligence consistently points to a "proper system to prevent the commission of an offence." The factors courts and regulators weigh include:
- Whether the employer appointed appropriate and sufficient supervisory personnel.
- Whether the employer reviewed the workplace for foreseeable health and safety risks.
- Whether the employer developed policies and procedures to protect workers against those risks.
- Whether the employer implemented and maintained disciplinary guidelines for non-compliance.
- Whether management received regular reports on the operation of the health and safety program.
Read that list again with one question in mind: how would you prove each item after an incident? Every factor turns on records that existed before the event — a risk assessment dated last quarter, training sign-offs, inspection logs, committee minutes showing a hazard was raised and acted on, and corrective actions tracked to verified closure. Reconstructing this evidence after an incident is both unconvincing and, in many cases, impossible.
The table below maps the due diligence factors to the documentation that demonstrates them.
| Due diligence factor | Evidence that demonstrates it |
|---|---|
| Foreseeable risk reviewed | Dated, version-controlled risk assessments and job hazard analyses |
| Policies and procedures developed | Approved SOPs with revision history and worker acknowledgment |
| Supervision and competence | Training records, supervisor assignments, competency verification |
| Program monitored by management | Inspection logs, committee minutes, management review records |
| Corrective actions effective | CAPA records showing assignment, completion, and verified closure |
Closed-loop corrective action — the connection from a finding through root cause to a verified, effective fix — is the single most scrutinized link in this chain. A corrective action that was assigned but never verified, or a repeat incident that shows a prior action did not hold, undercuts a due diligence defence directly. The same standard applies under ISO 45001 incident investigation requirements, which makes a single investigation discipline workable across Canadian sites and ISO-certified operations.
Operationalizing IRS Compliance Across Sites
Operationalizing the IRS means turning a shared-responsibility philosophy into repeatable workflows that generate evidence automatically. The gap most organizations face is not intent — it is that responsibility distributed across employers, supervisors, and workers tends to produce fragmented records that are hard to assemble into a defensible whole.
A practical operating model rests on four moving parts:
- A functioning joint health and safety committee. Meeting minutes that show hazards raised, discussed, and resolved are direct evidence that the "right to participate" is live, not theoretical.
- Frictionless hazard and near-miss reporting. If reporting is hard, it does not happen, and an empty hazard log reads as a dormant system rather than a safe one. Mobile-first submission removes that friction.
- Tiered, owned corrective actions. Every action needs a named owner, a due date proportionate to the risk, and a verification step before it can close — the difference between a documented fix and a documented intention.
- Management review on a defined cadence. Periodic review of program data is itself one of the due diligence factors, and it is the step that converts individual records into management oversight.
Across multiple Canadian jurisdictions, the underlying IRS philosophy is consistent even though specific provincial requirements differ. That consistency lets you standardize one investigation-and-corrective-action workflow and apply it everywhere, while still capturing jurisdiction-specific obligations as fields within the same record. Standardization is what makes multi-site evidence comparable and audit-ready instead of a patchwork of local spreadsheets.
One system, every site, an unbroken record. WhyTrace Plus standardizes incident investigation, root cause analysis, and corrective action tracking across locations — so your IRS program produces the same defensible evidence trail at each site without manual assembly. Request a WhyTrace Plus demo →
For teams formalizing the corrective-action half of this model, our guide to corrective action management and CAPA tracking covers the closure and verification discipline that due diligence depends on.
Frequently Asked Questions
Q. Is the Internal Responsibility System a law or a philosophy?
It is both. The IRS is the underlying philosophy of occupational health and safety legislation in every Canadian jurisdiction, and it is given legal force through the duties that each OHS act assigns to employers, supervisors, and workers. You comply with the IRS by meeting those statutory duties and by being able to demonstrate that your workplace actively identifies and resolves its own hazards.
Q. Does CCOHS enforce OHS compliance?
No. CCOHS is a federal Crown agency that provides authoritative information, training, and guidance on occupational health and safety. Enforcement is carried out by the OHS regulator in each province, territory, or the federal jurisdiction, depending on where the workplace falls. CCOHS guidance is widely used to interpret what compliance requires, but inspections, orders, and penalties come from the relevant jurisdictional regulator.
Q. Who can be held criminally liable under the Westray Bill?
Section 217.1 of the Criminal Code places a legal duty on anyone who undertakes, or has the authority, to direct how another person does work — which can include supervisors, managers, directors, and the organization itself. The provision makes it easier to pursue criminal negligence charges when a failure to take reasonable steps results in death or serious bodily harm.
Q. What does due diligence require under Canadian OHS law?
Due diligence requires demonstrating that you took every reasonable precaution to prevent the incident. In practice, that means dated risk assessments, documented policies and procedures, adequate supervision and training, disciplinary processes for non-compliance, and regular management reporting on the safety program. The defence depends on records that existed before the incident, not explanations constructed afterward.
Q. How is Canadian OHS different from OSHA compliance?
The biggest difference is prescriptiveness. OSHA standards often specify required controls in detail, while Canadian OHS legislation under the IRS frequently leaves it to the employer to determine appropriate steps for their specific workplace. That places more emphasis on documented hazard assessment and due diligence, and it adds a criminal-liability dimension through the Westray Bill that has no direct OSHA equivalent.
Key Takeaways
- The Internal Responsibility System is the philosophy underpinning OHS law in every Canadian jurisdiction: employers, supervisors, and workers all share responsibility, and the law often expects you to determine appropriate controls rather than follow a prescriptive checklist.
- CCOHS provides the authoritative guidance Canadian employers use to interpret OHS obligations, including the worker rights — to know, to participate, and to refuse unsafe work — that keep the IRS functioning.
- The Westray Bill (Bill C-45) added Criminal Code Section 217.1, creating criminal liability for failing to take reasonable steps to prevent workplace harm, reaching individuals with authority over how work is done.
- Due diligence is your primary protection, and it depends on evidence created before an incident: dated risk assessments, training records, inspection logs, and verified closed-loop corrective actions.
- Operationalizing IRS compliance means standardizing hazard reporting, investigation, and corrective action across sites so the system produces a defensible, audit-ready record automatically.
Related Resources
| Resource | Description | Best For |
|---|---|---|
| ISO 45001 Incident Investigation: Requirements and Best Practices | How Clause 10.2 investigation obligations align with due diligence evidence | EHS managers running both Canadian sites and ISO-certified operations |
| Corrective Action Management: Stop Losing Track of Your CAPA Items | Closure and verification discipline that due diligence depends on | Teams formalizing corrective action across multiple locations |
| Safety Management Trends 2026: AI, IoT, and Regulatory Changes | The regulatory and technology shifts shaping EHS programs this year | Safety leaders planning compliance investments for the year ahead |