Part 1: History · Chapter 2
The Rise of Digital EHS: From Paper Logs to Safety Software
How EHS moved from paper logs to software: OSHA recordkeeping, ISO 45001, leading vs lagging indicators, the vendors that built EHS software and the SaaS and mobile era.
By LIPAI WANG · Updated · 19 min read · 24 sources
EHS (environment, health and safety) software began as a way to keep legally required records, such as injury logs and chemical safety data sheets, and grew into platforms that run incident management, inspections, audits, risk assessments and corrective actions across whole companies. Management system standards such as ISO 45001, the move from lagging to leading indicators, and the arrival of cloud and mobile software shaped that growth between the 1990s and the 2020s. This chapter explains how that happened and what it means for anyone buying or connecting safety technology today.
What did safety records look like before software?
For most of the twentieth century, safety data lived on paper. A typical industrial site kept a handful of record types:
- an injury and illness log required by law;
- accident report forms, often filled in by the supervisor of the injured person;
- inspection checklists on clipboards;
- permits to work for hot work, confined spaces and isolations;
- training records in personnel files;
- binders of material safety data sheets for every chemical on site.
Paper had real strengths. It was cheap, needed no training and worked anywhere. Its weaknesses were just as clear. Records were hard to search and harder to combine across sites. Trends showed up months late, if at all. Corrective actions written on a form were easy to lose. A corporate safety director with fifty sites might wait until the end of a quarter to learn how many injuries had occurred.
The OSHA log as the first standard dataset
In the United States, the most important paper record was the OSHA injury and illness log. Employers covered by the 1970 Act had to record work-related injuries and illnesses that met set criteria. For decades this was the OSHA 200 log. In January 2001 OSHA published a revised recordkeeping rule, effective January 1, 2002, which introduced the current Form 300 log, Form 301 incident report and Form 300A annual summary [1].
These forms gave American companies a standard data model: what counts as recordable, how to classify days away from work and restricted duty, and how to calculate rates. The total recordable incident rate (TRIR) and the days away, restricted or transferred (DART) rate both come from this system. When software vendors began to build incident management tools, the OSHA forms were usually the first thing they automated.
Other countries have their own equivalents. In Great Britain, the Reporting of Injuries, Diseases and Dangerous Occurrences Regulations (RIDDOR) require employers, the self-employed and people in control of work premises to report work-related deaths, specified injuries, injuries that keep a worker off normal duties for more than seven consecutive days, certain occupational diseases and dangerous occurrences [24]. In the EU, the 1989 Framework Directive requires employers to assess risks and keep records of occupational accidents, with national laws setting the detail [6].
How did management systems change safety work?
The second big influence on EHS software was the idea that safety should be managed like quality: as a system with policies, plans, controls, checks and reviews.
From quality to safety
The quality movement produced ISO 9001 and the environmental movement produced ISO 14001 in the 1990s. Safety followed. In Great Britain, HSE first published its guidance Successful health and safety management, known as HSG65, in 1991, with a second edition in 1997. The third edition, published in 2013 as Managing for health and safety, framed the approach around Plan, Do, Check, Act and treated safety as part of good management generally [5].
In Europe, the 1989 Framework Directive, Directive 89/391/EEC, set general principles that employers must follow, including evaluating all risks to workers and integrating protective measures into all activities of the organization at every level [6].
In the United States, an ANSI committee started work in 1999 on a national standard for occupational health and safety management systems. It published ANSI/AIHA Z10 in 2005, the first American national consensus standard of its kind [7].
OHSAS 18001 and ISO 45001
Internationally, many organizations used OHSAS 18001, a specification first published in 1999 by a project group of national standards bodies, certification bodies and other organizations, outside ISO [9]. In March 2018, ISO published ISO 45001, the first international standard for occupational health and safety management systems [8]. Organizations certified to OHSAS 18001 had until March 2021 to migrate [9]. Because of COVID-19, the International Accreditation Forum (IAF) extended the deadline by six months, to 30 September 2021 [23].
ISO 45001 follows the common high-level structure of other ISO management system standards. Its main requirements include:
- understanding the organization's context and the needs of workers and other interested parties;
- leadership commitment and worker consultation and participation;
- hazard identification and assessment of risks and opportunities;
- legal and other requirements;
- operational controls following the hierarchy of controls;
- emergency preparedness;
- monitoring, measurement, analysis and performance evaluation;
- internal audit and management review;
- incident investigation, nonconformity and corrective action;
- continual improvement.
Uptake has been large. The ISO Survey recorded 185,166 ISO 45001 certificates worldwide in 2023, although the survey that year lacked data from China's accreditation body, so the true figure was likely higher [10].
Why management systems suit software
Every element of a management system creates records: risk registers, legal registers, audit findings, action plans, training matrices, management review minutes. Each element also needs workflows: someone raises an issue, someone else investigates, an action is assigned, tracked and verified. Paper and spreadsheets can handle this for a small site. For a company with many sites and certification audits each year, software becomes the practical option.
Management systems also brought a culture of evidence. An auditor wants to see that a hazard was identified, assessed, controlled and checked. Software that timestamps each step and links them together makes that evidence trail easier to produce. This is one reason EHS software vendors marketed themselves heavily around ISO certification.
How did process safety change what companies measure?
Major chemical accidents in the 1980s, including the 1984 Bhopal disaster, led to process safety regulation. In 1992 OSHA issued its Process Safety Management (PSM) standard, 29 CFR 1910.119, which covers facilities handling highly hazardous chemicals above threshold quantities [11]. PSM requires elements such as process hazard analysis, written operating procedures, training, mechanical integrity, management of change, incident investigation, emergency planning and compliance audits [11].
Each of those elements produced documents and workflows. Management of change, in particular, became a common software module: any change to equipment, chemicals or procedures must be reviewed for safety impact before it is made.
The lesson from Texas City
On 23 March 2005, an explosion and fire at BP's Texas City refinery killed 15 people and injured more than 170 [12]. The independent panel led by James Baker found that BP had emphasized personal safety and improved its personal injury rates, but had not given the same attention to process safety [12]. The panel concluded that personal injury rates were not predictive of process safety performance at BP's five US refineries, and that an effective personal safety system did not ensure an effective process safety system [12]. It recommended that BP develop an integrated set of leading and lagging process safety indicators for use by line managers, executives and the board [12].
Texas City changed how many companies measure safety performance. A company could have excellent TRIR numbers while the conditions for a catastrophe grew unchecked. Industry groups later developed process safety indicator frameworks, and the broader safety profession began to talk seriously about leading indicators and about serious injury and fatality (SIF) potential.
What are leading and lagging indicators?
Lagging indicators measure outcomes that have already happened. Leading indicators measure activities and conditions that come before outcomes and that, if managed well, should reduce harm. OSHA's 2019 guide, Using Leading Indicators to Improve Safety and Health Outcomes, describes leading indicators as proactive, preventive and predictive measures that reveal potential problems in a safety program before injuries occur [13].
| Type | Examples | Strengths | Weaknesses |
|---|---|---|---|
| Lagging | TRIR, DART rate, lost-time injury frequency, fatalities, workers' compensation costs | Standard definitions, comparable over time and between companies, required by law in some cases | Report harm after it happens; rare events produce noisy rates; can be suppressed by underreporting |
| Leading (activity) | Inspections completed, training delivered, safety meetings held, audits on schedule | Easy to count and control | Measure effort, not effectiveness; easy to game |
| Leading (condition) | Hazards identified, near misses reported, corrective actions closed on time, high-risk exposures observed | Closer to actual risk; can reveal trends early | Depend on reporting culture and detection quality; definitions vary |
OSHA's guide sets out three approaches to building leading indicators: use data the organization already collects to work toward a safety goal; build indicators around controlling an identified hazard; and build indicators around improving a program element such as training or worker participation [13].
Common problems with indicators
Both kinds of indicator have well-known failure modes.
Lagging rates reward silence. If bonuses depend on low TRIR, people may stop reporting minor injuries or manage cases to avoid recordability. The rate looks better while actual risk stays the same.
Leading indicators reward activity. If the target is "500 safety observations a month," people may submit 500 low-value observations. Counting inspections says nothing about whether the inspections found anything important.
Near-miss counts are ambiguous. A rise could mean more hazards or a better reporting culture. A fall could mean fewer hazards or that people have given up reporting.
These problems matter for technology because automated systems change the volume and character of data. A camera system may detect thousands of events that people never reported. That can make a site look worse on paper in the short term, even if nothing about its actual risk has changed. Chapter 15 covers how to measure outcomes honestly when the measurement tool itself is new.
Safety-I and Safety-II
In a 2013 white paper for EUROCONTROL, the safety scientist Erik Hollnagel and colleagues set out the distinction between Safety-I and Safety-II, which Hollnagel developed in a 2014 book [14]. Safety-I defines safety as a state where as few things as possible go wrong. Safety-II defines it as the ability to succeed under varying conditions, so that as many things as possible go right [14]. In practice this encourages organizations to study normal work and how people adapt to it, not only failures.
Hollnagel's ideas, along with related movements such as "safety differently," pushed some EHS teams to collect data on how work is actually done, through learning teams, operational learning reviews and observations of normal operations. That has implications for monitoring technology, which can capture a great deal about everyday work. Whether it is used to learn or to police depends on the organization.
How did EHS software develop as an industry?
EHS software grew from several specialist niches that gradually merged into platforms.
The early niches
In the 1980s and 1990s, the first products tended to solve one problem well:
- occupational health records for company medical departments;
- chemical inventory and safety data sheet management, driven by hazard communication rules;
- environmental compliance for air permits, emissions and waste;
- incident and injury recording to produce the OSHA log and similar reports;
- document control and training records for management systems.
Several of today's established vendors trace their roots to those niches. Medgate, a Toronto company with more than 30 years in occupational health software, rebranded as Cority in June 2017 after venture investment in 2016 and acquisitions that added environmental and quality management [17]. MSDSonline specialized in managing safety data sheets. After joining with Knowledge Management Innovations (KMI) in 2014, the combined business began trading as VelocityEHS in September 2015 to reflect a broader EHS platform [18]. Intelex built a broad environment, health, safety and quality platform; it was acquired in 2019 by Industrial Scientific, part of Fortive, for about $570 million [15]. Enablon, founded in France in 2000, focused on large enterprises and sustainability reporting as well as EHS. Wolters Kluwer agreed to buy it for €250 million in 2016, when Enablon reported more than 1,000 corporate customers and around €45 million in 2015 revenue [16].
From on-premise to SaaS
Early EHS systems were usually installed on a company's own servers, customized heavily, and upgraded rarely. Implementation projects could run for many months. Large enterprises bought them; small and mid-sized companies mostly stayed with spreadsheets.
From the late 2000s, vendors moved to software as a service (SaaS), where the provider hosts the software and customers pay a subscription. SaaS lowered upfront costs, shortened deployments and made continuous updates normal. It also made it easier for vendors to offer configurable modules rather than custom builds, so a company could start with incident management and add audits, risk assessment or permits later.
The mobile turn
Smartphones and tablets changed who could enter data. A supervisor could complete an inspection on a phone at the point of work, attach photos, and assign a corrective action before walking away. Frontline workers could report a hazard or near miss in under a minute.
SafetyCulture, founded in Townsville, Australia, in 2004 by Luke Anear, became one of the best known examples with its iAuditor inspection app, which made digital checklists available to very small businesses as well as large ones. In September 2024 it was reported to be valued at A$2.5 billion after an A$165 million capital raise [19]. Its growth showed that a large market existed for simple, mobile-first tools below the level of enterprise EHS suites.
Consolidation and platforms
By the 2010s, the market was consolidating. Large software and information companies bought EHS specialists, and EHS vendors bought each other to fill gaps. The acquisitions of Enablon and Intelex described above are two examples. The industrial technology company Fortive's interest in Intelex, through its gas detection business Industrial Scientific, also signaled a link between EHS software and connected sensors that later chapters explore.
| Era | Typical technology | Who used it | Main purpose |
|---|---|---|---|
| Before 1990 | Paper forms, binders, filing cabinets | Everyone | Legal records |
| 1990s | Desktop databases, spreadsheets, specialist programs | Large companies, specialists | Compliance reporting, chemical and health records |
| 2000s | On-premise enterprise EHS suites, early web systems | Large multinationals | Corporate reporting, management systems |
| 2010s | SaaS platforms, mobile apps | Large and mid-sized companies, some small businesses | Workflow, inspections, action tracking, analytics |
| 2020s | Cloud platforms with integrations, AI features, sensor and video data | Broadening to all sizes | Predictive analytics, automated data capture, ESG reporting |
What does a typical EHS platform include today?
Product names and packaging vary, but most established EHS platforms are built from a similar set of modules. Buyers rarely license all of them at once. A common path is to start with incident management and inspections, then add modules as the program matures.
| Module | What it does | Typical data it holds |
|---|---|---|
| Incident management | Records injuries, illnesses, near misses and property damage; runs investigations | Event details, people involved, root causes, regulatory classification |
| Inspections and audits | Digital checklists, scheduled audits, findings | Checklist answers, photos, scores, nonconformities |
| Corrective and preventive actions | Assigns, tracks and verifies actions | Owners, due dates, evidence of closure |
| Risk assessment | Job hazard analyses, risk registers, task-based assessments | Hazards, controls, risk ratings |
| Permits to work | Hot work, confined space, isolation and other permits | Approvals, conditions, time limits |
| Management of change | Reviews changes to equipment, chemicals or procedures | Change requests, reviews, sign-offs |
| Chemical management | Safety data sheets, inventories, labeling | Substances, locations, quantities, hazard classes |
| Training and competence | Training matrices, certifications, expiry tracking | Courses, completion dates, qualifications |
| Occupational health | Medical surveillance, exposure monitoring, case management | Health records, exposure results (often with stricter access controls) |
| Environmental and ESG | Permits, emissions, waste, sustainability reporting | Monitoring data, calculations, disclosures |
| Analytics and reporting | Dashboards, regulatory reports, indicator tracking | Aggregated data from all modules |
Two features of this structure matter when adding new data sources such as sensors or video. First, the incident and action modules are usually the system of record for what happened and what was done about it, so automated detections need a route into them. Second, occupational health data and any data that identifies individual workers often carry stricter legal and contractual controls than general safety data. Any integration has to respect those boundaries.
How big is the EHS software market?
Market estimates vary by definition, so they should be read with care. The independent research firm Verdantix estimated global spending on EHS software at $1.8 billion in 2023 and forecast growth at a compound annual rate of 11.5% to $3.1 billion in 2028 [20]. Verdantix found that safety management, including incidents, risk assessment and audits, makes up about 60% of spending, while ESG and emissions reporting is under 6% of spend but growing fastest [20]. It named computer vision, predictive analytics and AI among the developments expected to drive upgrades of safety management systems [20]. These are forecasts from one analyst firm and should be treated as outlook, not settled fact.
How did regulators push data online?
Regulators have also moved toward digital data. In May 2016 OSHA issued a rule requiring certain employers to submit injury and illness data electronically [2]. OSHA launched its Injury Tracking Application (ITA) web portal on 1 August 2017, later than first planned [3]. The requirements have changed several times since.
Under OSHA's current rule, published in July 2023 and effective January 1, 2024, establishments with 100 or more employees in designated high-hazard industries must submit information from their Form 300 log and Form 301 incident reports each year, in addition to the Form 300A summary [4]. Establishments with 250 or more employees in industries that must keep records continue to submit Form 300A data [4]. OSHA says it does not collect worker names or addresses or health care provider details from these submissions, to protect privacy [4].
Electronic submission matters for software in two ways. First, it makes structured, accurate injury data a compliance task, so incident systems must classify cases correctly and export data in the required format. Second, OSHA publishes much of the data it collects, which lets researchers, journalists, investors and the public compare establishments.
What problems did digital EHS not solve?
Digital EHS made records searchable, workflows trackable and reporting faster. Most of the data still depends on a person noticing something and deciding to report it.
Several gaps remain common:
- Underreporting. Near misses and minor injuries often go unreported because workers are busy, fear blame or see no point. Bird's 1969 study suggested near misses outnumber serious injuries by hundreds to one [21], but few organizations capture anything close to that ratio.
- Sampling. Inspections and observations are snapshots. A walk-through once a shift sees a tiny fraction of the hours of work in a busy warehouse or yard.
- Delay. Even a mobile report arrives after the event. The data is useful for learning, but not for stopping the event in progress.
- Bias. Reports reflect what people notice and choose to write down. Routine risks that everyone has accepted rarely appear.
- Data quality. Free-text fields, inconsistent categories and missing root cause information limit analysis.
There is also a scale problem. OSHA has about 1,850 inspectors for roughly 130 million workers [22]. Internal safety teams are similarly thin compared with the number of tasks happening at any moment. Paper and software both rely on a small number of people to observe a very large amount of work.
These gaps explain the interest in sensors, wearables and computer vision, which promise to collect data continuously without depending on someone to report it. They also explain the risks of those technologies. Continuous monitoring can produce far more events than a team can review, raise privacy concerns, and shift attention from serious hazards to easy-to-detect ones. Chapter 3 traces how computer vision reached the workplace. Chapter 7 returns to how EHS software and new data sources can be integrated.
What should buyers carry forward from this history?
The history of digital EHS offers several practical lessons for anyone evaluating safety technology today.
Start from the workflow, not the data. EHS software succeeded where it made an existing job easier: completing a legal log, running an audit, tracking an action to closure. New data sources need a clear place in those workflows, with someone responsible for responding.
Choose indicators with care. Texas City showed the danger of managing to the wrong number. Any new technology should be judged on whether it improves visibility of serious risks, not only on how many events it records.
Expect integration work. Most organizations already have an EHS system of record. A new tool that cannot send events, actions and evidence into that system creates a second, disconnected source of truth.
Treat market forecasts and vendor claims as claims. Analyst forecasts are useful context, and vendor case studies can be instructive, but neither replaces a well-designed pilot with a baseline.
Summary
EHS software grew from legal recordkeeping. In the US, OSHA's injury log, revised into the Form 300 system effective January 1, 2002, gave companies a standard data model and metrics such as TRIR and DART. Chemical data sheets, occupational health records, environmental permits and incident reports were the first workloads to be digitized.
Management system thinking, through HSE's HSG65, the 1989 EU Framework Directive, ANSI Z10 in 2005 and ISO 45001 in March 2018, turned safety into a Plan-Do-Check-Act cycle with records and workflows that software handles well. The 2005 BP Texas City explosion showed that good injury rates can hide catastrophic risk and pushed the profession toward leading indicators, which OSHA described in its 2019 guide.
Vendors such as Medgate (now Cority), MSDSonline (now VelocityEHS), Intelex and Enablon grew from specialist niches into platforms and were part of a wave of consolidation. Cloud delivery and mobile apps such as SafetyCulture's iAuditor brought digital inspection and reporting to the front line. Verdantix estimated the market at $1.8 billion in 2023, forecast to reach $3.1 billion in 2028.
OSHA's electronic reporting rules, most recently expanded from January 1, 2024, have made structured injury data a compliance requirement. Digital EHS still depends largely on people noticing and reporting events after they happen, with known problems of underreporting, sampling and delay. Those gaps are the starting point for the sensor and computer vision technologies covered in the rest of this guide.
Frequently asked questions
+What is EHS software?
EHS (environment, health and safety) software is a system for recording and managing safety and environmental work: incidents, near misses, inspections, audits, risk assessments, corrective actions, permits, chemicals, training and regulatory reports. Most products are now sold as cloud subscriptions with mobile apps for frontline staff.
+What is the difference between leading and lagging indicators?
Lagging indicators measure harm that has already happened, such as injury rates, lost workdays and fatalities. Leading indicators measure the activities and conditions that come before harm, such as hazards reported, inspections completed, corrective actions closed on time and training delivered. OSHA published a guide to leading indicators in 2019.
+Do I need ISO 45001 certification to use EHS software?
No. ISO 45001 is a voluntary management system standard, and EHS software can be used without it. Many organizations use software to support ISO 45001 because the standard requires documented processes, records, audits and management review that are easier to manage digitally.
+Does OSHA require electronic injury reporting?
Some employers, yes. Establishments with 250 or more employees in industries that keep OSHA records must submit Form 300A data electronically each year. Since January 1, 2024, establishments with 100 or more employees in designated high-hazard industries must also submit Form 300 and 301 data through OSHA's Injury Tracking Application.
Related reading
Sources
- [1]Occupational Injury and Illness Recording and Reporting Requirements, final rule (OSHA, January 19, 2001)
- [2]Improve Tracking of Workplace Injuries and Illnesses (Federal Register, May 12, 2016)
- [3]OSHA Launches Injury Tracking Application (National Law Review)
- [4]Recordkeeping: Final Rule Issued to Improve Tracking of Workplace Injuries and Illnesses (OSHA, 2023)
- [5]Managing for health and safety, HSG65, 3rd edition 2013 (HSE)
- [6]Directive 89/391/EEC, OSH Framework Directive (EU-OSHA)
- [7]Occupational Health and Safety Management Systems: Standards Development (US Department of Labor / ERG)
- [8]ISO 45001:2018 Occupational health and safety management systems (ISO)
- [9]OHSAS 18001 (Wikipedia)
- [10]ISO Survey 2023 Results (Certiget)
- [11]Process Safety Management of Highly Hazardous Chemicals, 29 CFR 1910.119 (OSHA)
- [12]The BP U.S. Refineries Independent Safety Review Panel report (Baker Panel, 2007)
- [13]Using Leading Indicators to Improve Safety and Health Outcomes (OSHA, 2019)
- [14]From Safety-I to Safety-II: A White Paper (Hollnagel, Leonhardt, Licu and Shorrock, EUROCONTROL, 2013)
- [15]Kirkland Represents Fortive on Industrial Scientific's Acquisition of Intelex for $570 Million (Kirkland & Ellis, 2019)
- [16]Wolters Kluwer Makes Binding Offer to Purchase Enablon (GlobeNewswire, 2016)
- [17]Medgate Rebrands as Cority (GlobeNewswire, 2017)
- [18]MSDSonline and KMI Are Now VelocityEHS (GlobeNewswire, 2015)
- [19]SafetyCulture valued at $2.5b after $165m capital raise (Business News Australia, 2024)
- [20]EHS Software Market Size: The Road To $3 Billion (Verdantix)
- [21]The Heinrich/Bird safety pyramid (Risk Engineering)
- [22]Commonly Used Statistics (OSHA)
- [23]Q15: What will happen to the migration period for ISO 45001; will it be extended? (IAF, 2020)
- [24]Types of reportable incidents, RIDDOR (HSE)
New chapters and updates, once a month
One email when we publish or update guidance. No vendor promotions. Unsubscribe any time.