Resources · Compliance
ISO 45001 explained
ISO 45001 is the international standard for occupational health and safety management systems, and it replaced OHSAS 18001 entirely.
ISO 45001:2018 is the international standard for occupational health and safety management systems. It sets out requirements across ten clauses, built on the Plan, Do, Check, Act cycle, with a strong emphasis on leadership accountability and worker participation. It replaced OHSAS 18001, whose certificates ceased to be valid after the migration period ended in 2021.
What ISO 45001 is for
The standard describes what a management system for occupational health and safety has to contain. It does not tell you what your hazards are or what controls to use. It tells you that you must have a systematic way of finding them, deciding what to do, doing it, checking whether it worked, and improving.
That distinction matters, because it explains both the value and the common complaint. Organisations that treat it as a documentation exercise produce a folder of procedures and no change in outcomes. Organisations that treat it as a framework for the things they were going to have to do anyway find it gives structure to work that was previously ad hoc.
It applies to any organisation regardless of size or sector, and it covers workers in the broad sense: employees, contractors, agency staff and anyone else whose work is under the organisation’s control.
How the standard is structured
ISO 45001 follows the harmonised structure common to modern ISO management system standards, which is why it sits neatly alongside ISO 9001 and ISO 14001. Clauses 1 to 3 are scope, references and terms. The requirements are clauses 4 to 10.
- Clause 4, Context of the organisation. Understand the internal and external issues that affect your health and safety performance, identify interested parties and their expectations, and define the scope of the system.
- Clause 5, Leadership and worker participation. Top management must take accountability, not delegate it. Workers at all levels must be consulted and must participate.
- Clause 6, Planning. Identify hazards, assess risks and opportunities, determine legal requirements, and set objectives with plans to achieve them.
- Clause 7, Support. Resources, competence, awareness, communication and documented information.
- Clause 8, Operation. Operational planning and control, the hierarchy of control, management of change, procurement and contractors, and emergency preparedness.
- Clause 9, Performance evaluation. Monitoring and measurement, evaluation of compliance, internal audit and management review.
- Clause 10, Improvement. Incident and non-conformity handling, corrective action and continual improvement.
What changed from OHSAS 18001
OHSAS 18001 was a British standard that became the de facto international one. ISO 45001 superseded it, and the three-year migration period ended in 2021, so an OHSAS 18001 certificate no longer carries weight.
Four changes are substantive rather than cosmetic:
- Leadership cannot be delegated. OHSAS 18001 allowed a management representative to carry the system. ISO 45001 places accountability with top management directly.
- Worker participation became a requirement. Not consultation as a courtesy, but participation with the barriers to it identified and removed.
- Context and interested parties are new. The system has to be designed around the organisation’s actual circumstances rather than a generic model.
- Risk and opportunity, not just hazard. The standard asks about opportunities to improve, not only threats to control.
Incident reporting under clause 10
Clause 10.2 covers incidents and non-conformities together, and its requirements are specific about what happens after something goes wrong. You must react to the incident, evaluate the need for action to eliminate the root cause so it does not recur, review the effectiveness of any action taken, and make changes to the management system if needed.
Two words in that sequence do most of the work. Root cause means an investigation that stops at the immediate cause does not satisfy the clause. Effectiveness means closing an action is not the end of it; you have to come back and check the cause actually went away.
This is where a lot of certified organisations struggle at audit, not because they do not investigate, but because they cannot evidence the effectiveness review. See incident investigation basics and CAPA explained for the mechanics.
What certification involves
Certification is optional. Plenty of organisations use the standard as a framework without ever being audited against it, and that is a legitimate choice unless a client or a tender requires the certificate.
If you do pursue it, the process runs roughly like this. You implement the system and run it long enough to generate records, typically three to six months. A certification body then carries out a stage one audit, largely a documentation and readiness review, followed some weeks later by a stage two audit that tests whether the system is actually operating. Certification lasts three years, with surveillance audits usually annually, and a recertification audit at the end of the cycle.
The single most common finding is not a missing procedure. It is a procedure that exists and is not followed, or records that show an action was raised and never verified. Auditors look for evidence the system runs, and evidence means records with dates, owners and outcomes.
Important: this guide is a general explanation, not legal advice. the requirements of ISO 45001 are set by ISO and certification requirements vary by certification body. Always check the current source, and take professional advice where needed.
Frequently asked questions
Is ISO 45001 a legal requirement?
No. It is a voluntary standard. Complying with it does not discharge your legal duties, and meeting your legal duties does not certify you. In the UK your statutory obligations come from the Health and Safety at Work etc. Act 1974 and the regulations made under it.
Has ISO 45001 replaced OHSAS 18001?
Yes, completely. The migration period ended in 2021 and OHSAS 18001 certificates are no longer valid. Organisations still referring to OHSAS 18001 are working to a withdrawn standard.
How long does ISO 45001 certification take?
Typically six to twelve months from a standing start, depending on how much of a system already exists. You need enough operating history to produce records for the auditor, which is usually at least three months of the system actually running.
Does ISO 45001 apply to small organisations?
Yes. The standard is explicitly designed to be applicable regardless of size. What scales is the amount of documentation, not the requirements themselves.
What is the difference between ISO 45001 and ISO 9001?
ISO 45001 covers occupational health and safety. ISO 9001 covers quality management. They share the same ten-clause harmonised structure, which makes running them as one integrated management system considerably easier than running two.
What does clause 10.2 require after an incident?
React to it, evaluate whether action is needed to eliminate the root cause so it does not recur, review the effectiveness of the action taken, and change the management system if necessary. The effectiveness review is the part most often missing at audit.
Do we need a management representative under ISO 45001?
No, and that is a deliberate change. Accountability sits with top management and cannot be handed to a nominated representative, which was permitted under OHSAS 18001.
Sources
- International Organization for Standardization, ISO 45001:2018 Occupational health and safety management systems. https://www.iso.org/standard/63787.html
- Health and Safety Executive, managing for health and safety (HSG65). https://www.hse.gov.uk/pubns/books/hsg65.htm
- Health and Safety at Work etc. Act 1974. https://www.legislation.gov.uk/ukpga/1974/37/contents
- United Kingdom Accreditation Service, accredited certification bodies. https://www.ukas.com/
Evidence the system is actually running
Incidents, actions, owners and effectiveness reviews in one place, with the records an auditor asks for already there.
Book a demo