Health and Safety at Work Amendment Bill 2026: What Changes for NZ Businesses

The Health and Safety at Work Amendment Bill has passed and introduces the first statutory definition of critical risk. Here’s what officers and H&S leads need to know before it takes effect.


Key takeaway: The Health and Safety at Work Amendment Bill has passed and is awaiting Royal Assent, expected before September 2026. It doesn’t create entirely new obligations – it removes the ambiguity that allowed boards to be comfortable with less. “Critical risk” is getting a legal definition, and officer verification duties are being made explicit. Most changes commence 1 April 2027, giving organisations a defined runway – but the standard the Bill describes already applies under the current Act. If your governance isn’t already built around it, now is the time to change that.

  • Bill introduced to Parliament: 12 February 2026
  • Passed third reading: 1 July 2026
  • Awaiting Royal Assent: expected before Parliament rises on 24 September 2026
  • Approved Code of Practice (ACOP) provisions take effect: the day after Royal Assent
  • Most other changes take effect: 1 April 2027
  • Action required now: conduct a formal critical risk assessment; review officer governance processes

It’s important to note that the Bill’s long-term shape isn’t fully settled. NZ First supported it under its coalition agreement but has signalled it will seek changes after the November 2026 election, and Labour has said it would repeal the Bill if it returns to government. None of that affects the obligations that already exist under the current Act – but it’s worth knowing the legislative picture may keep moving.

For the past decade, “critical risk” has been a phrase that everyone in health and safety uses and nobody has been required to define. WorkSafe has published guidance on it, industry bodies have built frameworks around it, and boards have asked about it in annual reports. But in the Health and Safety at Work Act 2015 itself, the term has never formally existed – which has meant that what counts as a critical risk, and what adequate governance of one looks like, has always been somewhat in the eye of the beholder.

That’s about to change.

The Health and Safety at Work Amendment Bill, which was introduced to Parliament in February 2026, passed its third reading on 1 July and is now awaiting Royal Assent – expected before the House rises on 24 September. Once assented, it will give “critical risk” a statutory definition for the first time. It’s the most significant reform to New Zealand’s health and safety framework since the 2015 Act came into force – and for organisations who need to manage critical risk, the implications go well beyond compliance.


The Bill defines a critical risk as a hazard that either appears in a new Schedule 1A list of specified hazards, or is likely to result in death, a notifiable injury or illness, a notifiable incident, or an occupational disease listed in Schedule 2 of the Accident Compensation Act 2001. In determining whether a risk meets that second threshold, a Person Conducting a Business or Undertaking (PCBU) must base its assessment on what it knows – or ought reasonably to know – about its business and the hazard in question.

That phrase “ought reasonably to know” matters. It means ignorance isn’t a defence. If the nature of your operations creates exposure to hazards that could kill or seriously harm someone, you’re expected to have identified them, whether you’ve formally done so or not.

Once a risk is identified as critical, the Bill requires PCBUs to prioritise it in a specific way: managing critical risks before other risks, monitoring and reviewing controls for them more frequently than for other risks, and directing a higher proportion of resources toward them. The word the Bill uses is “prioritise” – and it means something precise, not just “pay attention to.”

At select committee, the wording was sharpened further – the Act’s main purpose now explicitly extends the prioritisation to how PCBUs themselves manage those risks, not just the framework’s overall focus. It’s a precision fix, but it closes a gap in how directly the purpose clause applies to PCBU behaviour, not just legislative intent.


Area Current Act Amendment Bill
Definition of “critical risk” No formal definition Statutory definition introduced for the first time
Officer due diligence (s44) Open-ended list of examples Fixed, exhaustive set of obligations
Verification duty Implied but not named explicitly Named explicitly as an officer obligation
Prioritisation of critical risks Implicit in guidance; not in the Act Required by law; must be managed before other risks
Control monitoring frequency No distinction between risk types Critical risks must be reviewed more frequently
Small PCBU obligations Same duties apply to all PCBUs Small PCBUs (under 20 workers) limited to critical risk duties only

One nuance for construction and manufacturing readers in particular: the 20-worker threshold for small PCBU status isn’t limited to people on your payroll. The Bill relies on the HSWA’s existing definition of “worker” (section 19), which already extends to contractors and subcontractors. An organisation with 12 direct staff and a dozen regular contractors on site could sit well over the line – so small PCBU status shouldn’t be assumed from headcount alone.

The Bill also introduces a deeming provision: if an organisation acts in accordance with the relevant Approved Code of Practice (ACOP) for a specific risk, in the same situation or circumstances, it’s taken to have complied with the HSWA for that risk. Any person or organisation can develop a draft ACOP, though a non-regulator drafter must submit it to the regulator for recommendation to the Minister.

This won’t apply broadly from day one. Only two existing ACOPs are grandfathered into safe-harbour status at commencement – the Approved Code of Practice for Loading and Unloading Cargo at Ports and on Ships (2024), and the Approved Code of Practice: Safe Practice for Forestry and Harvesting Operations (2025). Every other existing ACOP keeps its current evidence-only status until it’s reviewed and reapproved under the new framework. The ACOP provisions themselves commence the day after Royal Assent – ahead of the rest of the Bill’s 1 April 2027 commencement date.

For boards and executives, the most significant change is in how officer due diligence is defined.


Under the current Act, the list of what due diligence requires is open-ended – a set of examples rather than a complete picture. The Bill makes it exhaustive. What’s expected of an officer is now a fixed, defined set of obligations rather than a floor that courts can interpret upward or downward depending on the circumstances.


Those obligations include three things that are especially relevant given the direction case law has been moving:

  • Understanding the nature of the organisation’s operations and the hazards they create
  • Ensuring the organisation has the right resources and processes in place to manage those hazards
  • Verifying that those resources and processes are being used

The Bill also narrows scope in one respect: it clarifies that an officer’s duty applies to their governance role specifically, not to other activities they might separately perform as a worker for the same PCBU. That’s a precision fix, not a loosening of the core verification duty – the standard the Port of Auckland conviction established stands.

The verification requirement above is the one that carries the most weight. It’s also the one that the Port of Auckland conviction turned on. Tony Gibson wasn’t found to have failed because Port of Auckland lacked systems. He was found to have failed because he hadn’t verified that those systems were functioning in practice. The Bill is now writing that standard into law – not as a principle that courts can invoke, but as a named, explicit officer obligation.


There’s a temptation to treat legislative reform as a long runway – something to prepare for eventually, once the Bill passes and guidance is issued and industry practice catches up. That’s probably the wrong frame here, for two reasons.

The first is what’s already true. Royal Assent is expected before September 2026, and while most of the Bill’s changes won’t formally commence until 1 April 2027, the officer verification duty at the heart of it isn’t new – it’s already the standard under the current Act, as the Port of Auckland conviction demonstrated. The commencement date gives you a defined runway to close any gaps. It doesn’t give you a reason to wait to start.

The second reason is that the Bill doesn’t create new obligations so much as it clarifies and sharpens existing ones. The expectation that officers would prioritise critical risks, verify controls, and maintain genuine visibility into operations – that expectation was already there. The Port of Auckland conviction demonstrated that courts were already applying it. What the Bill does is remove any remaining ambiguity about what’s required, and make it harder for organisations to argue they didn’t know the standard they were being held to.

In practice, that means the question isn’t “do we need to change what we do when the Bill passes?” It’s “are we already doing what the Bill describes – and can we demonstrate it?”


If you’re an H&S manager or risk lead, the Bill gives you a concrete framework for the conversations you need to be having internally right now. A few starting points:

Have you formally identified your critical risks? Not assumed them, not inherited them from a previous risk register – but assessed which hazards in your current operations are likely to result in death or serious harm, based on what you know about how work is done. The Bill requires this assessment to reflect reality, not aspiration.

Are your controls being monitored at the right frequency? The Bill requires critical controls to be reviewed more often than controls for other risks. If your current monitoring schedule doesn’t distinguish between the two, that’s a gap worth closing before the Bill passes – not after.

Can your officers verify, not just receive? There’s a difference between an executive who receives a monthly H&S report and an executive who has genuine visibility into whether critical controls are in place and working on the ground. The Bill names verification as an explicit officer duty. The question for your governance process is whether your current reporting gives officers what they’d need to meet that standard.

What does “work as done” look like in your organisation? The Port of Auckland judgment drew a sharp distinction between work as planned and work as carried out. If your critical risk data is built primarily on what workers are supposed to do rather than what they’re observed doing, there’s a gap between your documented critical controls and your real exposure.


The deeper significance of the Amendment Bill isn’t the specific changes it makes – it’s the shift in accountability it reflects. For years, the implicit standard for boards and executives was something like “did we have appropriate systems?” The question that courts, regulators, and now Parliament are converging on is different: “did we know our systems were working?”

That’s a harder question to answer. It requires more than a well-maintained management system or a clean audit report. It requires a continuous, verified picture of whether critical controls are in place and functioning – not a snapshot from last quarter, but an ongoing view.

The organisations that will navigate this period most confidently aren’t the ones scrambling to respond to the Bill. They’re the ones that have already built that kind of visibility into how they operate.


What is the new definition of critical risk under the Amendment Bill?
A critical risk is defined as a risk associated with a hazard that is likely to result in death, a notifiable injury or illness, a notifiable incident, or an occupational disease listed in Schedule 2 of the Accident Compensation Act 2001. PCBUs must assess this based on what they know – or ought reasonably to know – about their operations and the hazards they create.

When does the Health and Safety at Work Amendment Bill come into force?
The Bill passed its third reading on 1 July 2026 and is awaiting Royal Assent, expected before Parliament rises on 24 September 2026. The ACOP safe-harbour provisions take effect the day after Royal Assent. Most other changes – including the critical risk definition and officer duty provisions – commence on 1 April 2027. Organisations should begin preparing now rather than waiting for the commencement date.

What does the new verification obligation mean for officers?
Officers must verify – not just document or review – that the resources and processes they’re responsible for are being provided and used. This means having genuine evidence that critical controls are functioning, not just records that they were planned or agreed to.

Does the Bill apply to contractors and supply chains?
Yes. The duty to prioritise and verify critical controls extends to work carried out by contractors on a principal’s behalf. Having the right contracts in place is not sufficient – principals need reasonable confidence that their contractors’ critical controls are functioning.

Does the definition cover mental health risks?
Partially. The Bill’s definition of “risk” now includes harm to mental health associated with a hazard – but only where that mental health harm is likely to lead to one of the listed physical outcomes. An example: a traumatic work situation impairing someone’s judgement or reaction time in a way that’s likely to cause a vehicle crash or equipment misuse. It’s a narrower inclusion than full psychosocial risk coverage, and submitters pushed for broader scope during the select committee process without success.

What should organisations do before the Bill passes?
At a minimum: conduct a formal critical risk assessment against the new definition; review whether critical controls for critical risks are being monitored more frequently than other risks; and check that officer governance processes include genuine verification, not just receipt of reports.



Critter is built by IMPAC – New Zealand’s leading health and safety company, with 27 years of experience guiding organisations through complex critical risk challenges. Learn more about IMPAC.