One system for every compliance obligation. Zero gaps between them.
ZERO by AOAL is a QHSE operating system built for how South African businesses are actually regulated — safety files, legal registers, incidents, vendors, training and medical surveillance, running off one shared employee profile instead of six disconnected systems.
Built by the AOAL team on the same legislative interpretation we use in our audits and legal registers — not a generic template.
Most compliance systems don’t fail on knowledge. They fail on custody.
Legal appointments lapse quietly. Safety files live in someone’s inbox. An incident gets a WhatsApp thread instead of an investigation. Individually each gap is small. Under sections 8 and 9 of the OHS Act, they’re the director’s problem.
The record and the reality drift apart
A legal register built once at audit time is out of date the day legislation changes — and recent years have produced more regulatory amendments than most compliance calendars can track.
Vendor risk lives outside your system
Competency, insurance and safety-file status usually sit in someone else’s paperwork, so the one place you need visibility — before a contractor sets foot on site or a supplier’s PO gets renewed — is the one place you don’t have it.
Sensitive data gets treated like ordinary data
Medical surveillance and exposure records are special personal information under POPIA. Spreadsheets and shared drives were never built to carry that classification.
Six modules. One shared employee profile.
Every person in your organisation gets a Compliance Profile automatically — it’s not something you buy. Each module below plugs into that same profile when you add it, instead of starting a new record from scratch.
Safety File Automation
Compiles and maintains site and contractor safety files from the documents you already collect — no more assembling a folder the night before an inspection.
- ✓ Auto-builds site and contractor files against the document set your scope requires
- ✓ Flags expiring legal appointments, permits and certificates before they lapse
- ✓ Configurable approval chain — Safety Officer drafts, Manager reviews, Client signs off — everyone notified the moment it’s their turn
- ✓ Built-in e-signatures for legal appointments and approvals
- ✓ Print-ready exports for clients who still want a hard copy on file
3 hard copies of the Groen Energy Site Safety File printed and couriered for the client’s on-site audit.
Legal Registers
A living legal register mapped to South African HSE, environmental and labour legislation — maintained by the same regulatory monitoring behind AOAL’s compliance work, not a static document nobody updates.
- ✓ Applicability screening per site, sector and activity
- ✓ Compliance status per obligation, with evidence attached at clause level
- ✓ Amendment alerts the moment a Government Gazette changes a requirement
— AOAL’s monitoring team scans the Gazette every morning
Scanned the Government Gazette overnight — no changes to your applicable legislation.
The Draft Construction Regulations, 2025 moved to public comment. We’ve flagged this for your review.
Incident Management
Structured capture through to root-cause investigation, so a near-miss produces a corrective action, not just a form.
- ✓ Mobile-first reporting from site, with photo and witness capture
- ✓ Built-in 5-Whys and root-cause workflow, reviewer sign-off included
- ✓ COIDA-aligned reporting fields and trend analytics across sites
— keep it going
Closed out the chemical spill investigation at Bay 3. Root cause: valve seal wear.
New near-miss reported: forklift, Warehouse B. Root-cause workflow started automatically.
Vendor Management
Onboarding, risk scoring and compliance tracking for everyone outside your organisation who touches your operation — site contractors and supply-chain vendors alike — tied to who’s actually cleared for site access or an approved supplier list today.
- ✓ Contractor and supplier onboarding in one workflow, from site access to procurement approval
- ✓ Vendor risk scoring across compliance, insurance and financial-standing documentation
- ✓ Site access and purchase-order status both driven by the same live compliance record
Approved Sithole Electrical’s induction — they’re cleared for site access today.
Flagged PPE Supplier (Pty) Ltd — insurance certificate expires in 9 days, before their PO renewal.
Training Matrices
A live competency matrix mapping every person and role to the training they need, what they’ve completed, and what’s expiring — written straight into their Compliance Profile the moment it changes.
- ✓ Role-based training matrix built automatically from job profiles and site risk exposure
- ✓ Expiry tracking on certifications — first aid, working at heights, confined space and more — with automatic reminders
- ✓ Gap analysis showing exactly who needs what before they can be signed off for a task
Aid
at Height
Space
Fighting
Nomvula D.’s Working at Heights certificate expired 3 days ago. Flagged to her line manager.
Medical Monitoring
Occupational health surveillance scheduling tied to actual exposure data — noise, hazardous chemical agents, physical agents — built on an architecture designed for special personal information, not repurposed HR software.
- ✓ Surveillance scheduling driven by exposure profile per role and site
- ✓ Field-level encryption and role-segregated access for health data
- ✓ Fitness-for-duty status visible to management without exposing clinical detail
Completed audiometry for 14 employees at the Rosebank site. All results filed.
Fitness-for-duty summary ready for management. Clinical detail stays with the provider.
Built to carry the data South African and international law treats as sensitive
Medical monitoring, incident records and contractor data all qualify as personal — some of it special personal information — under POPIA. ZERO’s security architecture is designed against that classification from the start, not bolted on afterward.
ISO/IEC 27001
Information security controls aligned to ISO/IEC 27001:2022 — access control, cryptography, operations security and incident management, covering the full control set relevant to a compliance-data platform.
ENCRYPTION
Data encrypted in transit (TLS 1.2+) and at rest, with field-level encryption on medical and biometric data specifically.
ACCESS CONTROL
Role-based access with segregation of duties — HSE, occupational health and management see what their role requires, nothing more.
AUDIT TRAIL
Immutable logging of who viewed or changed a record, and when — the evidence trail an inspector or auditor actually asks for.
DATA RESIDENCY
Hosting and processing arrangements documented against POPIA’s cross-border transfer conditions (section 72).
Why medical monitoring gets its own security tier
POPIA classifies health information as special personal information under section 26 — processing it requires a specific justification and a higher duty of care than ordinary employee data.
ZERO isolates the medical monitoring module on its own access tier: clinical detail is visible only to the occupational health provider, while HSE and management see fitness-for-duty status and scheduling — enough to manage risk, without exposure to information they have no legal basis to hold.
How an implementation actually runs
Same sequence whether you’re rolling out one module or all five.
Gap assessment
We audit your current legal register, safety files and contractor records against what the platform expects, and migrate what’s usable.
Configuration
Sites, roles, applicable legislation and exposure profiles are configured to your operation — not a generic template.
Rollout & training
Phased rollout by module or by site, with role-specific training for HSE staff, contractors and management.
Go-live & support
AOAL’s HSE consulting team stays attached to the account — this is a system with a consultant behind it, not a support ticket queue.
Join our subscribers
Stay in the loop with everything you need to know regarding Quality, Health, Safety, and Environmental (QHSE) and legal compliance consulting services in South Africa — including updates on ZERO.
See ZERO against your own legal register.
30 minutes, run on your sites and your obligations — not a generic demo script.
