ADOSH-SF v4.0 explained: what it is and what you must do
The Abu Dhabi occupational safety and health framework catches out more organisations than any ISO standard, usually because they assumed certification covered it, or that it only applied to construction.

Two misconceptions cause most of the trouble. The first is that the Abu Dhabi framework applies only to construction. The second is that holding ISO 45001 means you are compliant with it. Both are wrong, and both are expensive to discover during an inspection.
What the framework actually is
The Abu Dhabi Occupational Safety and Health System Framework is the Emirate-wide regulatory system governing workplace health and safety. It is not a certification scheme and there is no certificate to display. It is a set of legal obligations, administered through Sector Regulatory Authorities, each responsible for entities operating in its sector.
That structure matters practically. Your obligations are enforced by the regulator for your sector rather than by a single central body, and the specific requirements applied to you are proportionate to your size and risk profile. Two organisations of similar size in different sectors may face meaningfully different expectations.
OSHAD, ADOSH, and which version applies
You will encounter several names for what is substantially the same framework, plus references to superseded versions such as OSHAD-SF v3.1. The naming has evolved through successive administrative arrangements; the framework itself has continued and been revised.
A surprising number of the management systems we review still reference framework documents that have been superseded, typically because a consultant built the system years ago and nobody has revisited it since. An inspector reading a policy that cites a withdrawn document version draws an immediate and unfavourable conclusion about how current the rest of your system is. Confirm the applicable version with your Sector Regulatory Authority rather than relying on a copy downloaded from a search result.
Who it applies to
If you employ people in the Emirate of Abu Dhabi, you fall within the framework's reach. The entities most often surprised by this are not contractors: contractors generally know. They are:
- Retail, hospitality and food service businesses, which frequently assume the framework is a construction matter.
- Healthcare and education providers, whose sector regulators apply the framework alongside their own clinical or academic requirements.
- Professional services firms and offices, which have lower obligations but not zero obligations.
- Facilities management providers, operating across many client sites they do not control.
- Logistics, warehousing and transport operators, where vehicle and materials handling risk is often under-managed.
- SMEs generally: proportionality reduces what is expected, but it does not remove the duty.
How the framework is structured
Understanding the layers helps you work out what actually applies to you, rather than attempting to implement everything:
| Layer | What it covers | Does it apply to you? |
|---|---|---|
| System Framework Elements | What an OSH management system must contain: policy, risk management, competence, emergency management, incident reporting, audit and review | Yes, to every entity, proportionately |
| Codes of Practice | Specific requirements for particular hazards and activities | Only those relevant to your activities |
| Mechanisms | How the system is administered: registration, reporting, enforcement | Yes, in the parts that concern your entity type |
| Technical Guidelines & Standards | Detailed technical requirements and guideline values | Where your activities engage them |
| Sector Regulatory Authority requirements | Additional sector-specific obligations | Yes, identify your SRA first |
The most common wasted effort we see is an entity implementing Codes of Practice that have nothing to do with its activities, while missing the two or three that genuinely do. Identifying applicability precisely is the first task, not an afterthought.
How it differs from ISO 45001
| ADOSH-SF v4.0 | ISO 45001 | |
|---|---|---|
| Nature | Regulatory obligation | Voluntary certification |
| Assessed by | Your Sector Regulatory Authority | An accredited certification body |
| Output | No certificate: compliance status | A three-year certificate |
| Style | Prescriptive: states what controls must look like | Outcome-based. You determine the controls |
| Geographic reach | Emirate of Abu Dhabi | International recognition |
| Consequence of failure | Regulatory enforcement | Loss of certificate and tender eligibility |
| Optional? | No | Yes, unless a client requires it |
The practical conclusion is that most Abu Dhabi organisations need both, and should build them as one system. An ISO 45001 framework with every applicable ADOSH requirement mapped in as a compliance obligation discharges both duties from a single document set, one risk process and one audit programme. Building them separately produces two manuals that gradually contradict each other, and a contradiction is a finding in both.
Six ways entities get caught out
- Assuming ISO 45001 is enough. Certification demonstrates a functioning management system. It does not demonstrate compliance with a specific local regulatory framework, and an inspector will ask for framework-specific evidence a generic system does not produce.
- Generic risk assessments. Templates that name no real task, location, plant or control fail on sight. Risk assessments must describe your work.
- No appointed competent person. Entities are expected to have OSH competence proportionate to their risk, formally appointed, with evidence of that competence on file.
- Heat stress treated as a poster. The summer midday break and heat stress management are among the most actively inspected areas in the Emirate. A documented programme covering acclimatisation, hydration, shaded rest, monitoring and response to heat illness is expected, not a laminated notice.
- Subcontractors outside the system. You remain accountable for the OSH performance of parties working under your control, including their competence, their risk assessments and their incidents.
- Late incident notification. Reportable incidents carry defined notification timescales. Missing the deadline is a compliance failure in its own right, entirely separate from the incident that caused it.
What to do about it
- Identify your Sector Regulatory Authority and confirm which framework version and requirements currently apply to your entity.
- Determine applicability: which Codes of Practice genuinely engage your activities, and which do not.
- Gap analyse honestly against those requirements. Optimistic self-assessment is the most expensive kind.
- Build one system, structured to ISO 45001 if you also need certification, with framework requirements mapped in as compliance obligations.
- Appoint and evidence competence proportionate to your risk.
- Rehearse your people. The gap that sinks inspections is rarely documentation. It is supervisors who cannot describe the controls their own procedures require.
- Audit yourself the way a regulator would, at least annually, and close what you find.
Questions
No. It is a compliance framework, not a certification scheme, so there is no certificate and no accredited body issuing one. Any organisation offering to sell you an ADOSH certificate is selling something that does not exist. If you need a certificate for tender purposes, that is ISO 45001.
Yes, proportionately. You are not expected to hold a contractor-scale management system, but you are expected to have an OSH policy, risk assessments relevant to your actual activities, competent oversight, training records, emergency arrangements and incident procedures. The volume of work is small. The obligation is not zero.
Typically a review of your documented system, verification on site or at your premises, and interviews with staff at various levels. Documentation gets you through the first part. What determines the outcome is whether your supervisors and workers can describe the controls that your own procedures specify.
Six to ten weeks for a small, lower-risk entity to reach a defensible position. Twelve to twenty weeks for a contractor with active sites and several applicable Codes of Practice. If you have an inspection or client audit scheduled sooner, tell us the date and we will prioritise the areas carrying the most exposure.
Take the two-minute readiness check for an indicative picture, or book a free thirty-minute call and we will tell you which framework requirements actually apply to your entity before you spend anything. Book a consultation.

Let’s make your next audit a non-event.
Book a free 30-minute consultation. We will tell you honestly whether you need a consultant, and if you do, exactly what it will take.