Why Every ISO 45001 Consulting Website Says the Same Thing
Search "ISO 45001 consultant" and you'll get a wall of nearly identical pages: "expert guidance," "tailored solutions," "proven methodology," "fast-track certification." I've read a lot of these sites preparing proposals against competitors, and the language is so interchangeable you could swap the logos and nobody would notice.
That's not an accident. ISO 45001:2018 is a documented, clause-numbered standard, so anyone can copy its table of contents into a service page and call it a methodology. The differentiation isn't in what a firm says it does. It's in what happens when your auditor opens Annex SL clause 6.1.2 and asks you to demonstrate that your hazard identification process actually produced a risk register someone uses, not one that exists to be filed.
"Generic" here describes a real pattern I've seen repeatedly: a template-driven engagement that produces a documented management system without producing an operational one. Here's where that pattern breaks, clause by clause, and what a different approach looks like.
The Template Problem: Documentation That Passes Stage 1, Fails Stage 2
Generic ISO 45001 consulting almost always follows the same arc. You get a shared drive full of policy templates, a gap assessment scored against a checklist, and a documentation package built to satisfy Stage 1 (documentation review). The consultant's job, as they define it, ends when the manual exists.
The problem shows up at Stage 2 (the on-site certification audit), when the auditor stops reading documents and starts interviewing workers. ISO 45001:2018 clause 5.4 requires "consultation and participation of workers" in hazard identification, risk assessment, and incident investigation — not just a documented process, but evidence that non-managerial workers were actually involved. A template consultant hands you a worker participation procedure. It doesn't hand you workers who can describe, in the audit interview, what they participated in.
The same gap shows up under clause 6.1.2.1 (hazard identification) and 6.1.2.2 (assessment of OH&S risks and other risks to the management system). A generic risk register lists hazards by job title, copied from an industry template, with likelihood and severity scores that were never validated against your actual site conditions.
An auditor doing a floor walk against clause 8.1.2 (elimination of hazards and reduction of OH&S risks, via the hierarchy of controls) will ask why the register says "guarding present" when the guard is missing a bolt. That's a nonconformity, and it's the direct, traceable result of documentation that was written instead of built.
I say this not to score a point against every other firm in this space, but because it's the single most common failure mode I've seen in ISO 45001 engagements that stall at Stage 2: a system that reads well and doesn't hold up when a person walks the floor with it.
What the Standard Actually Requires vs. What Gets Delivered
| Clause | What ISO 45001:2018 Requires | Generic Template Delivery | What Certification-Ready Delivery Looks Like |
|---|---|---|---|
| 4.3 – Scope | Documented scope reflecting actual boundaries, activities, and interested parties | Boilerplate scope statement copied across clients | Scope tested against actual site operations and contractor relationships before it's written down |
| 5.1 – Leadership | Top management demonstrates accountability, not just signs a policy | A pre-written policy for the CEO to sign | Leadership commitments tied to specific, checkable actions (budget lines, management review agendas) |
| 5.4 – Worker Participation | Documented mechanism AND evidence workers used it | Participation procedure with no interview-ready evidence | Workers who can describe, unprompted, how they raised a hazard and what happened next |
| 6.1.2 – Hazard ID & Risk Assessment | Risk register reflecting actual site hazards, methodology defined and applied | Industry-generic hazard list, static scores | Site-walked register, validated methodology, updated on a defined trigger (not just annually) |
| 8.1.2 – Hierarchy of Controls | Controls selected by hierarchy (elimination first, PPE last), not by convenience | PPE-heavy control lists regardless of feasibility | Documented rationale for why higher-order controls were or weren't feasible |
| 9.3 – Management Review | Review inputs per clause 9.3(a)-(i), including OH&S performance and worker feedback | A meeting-minutes template with boxes checked | Review that produces documented decisions and resource commitments, traceable to clause 10.3 continual improvement |
None of this is exotic. It's the standard as written. The difference is whether the consultant treats each clause as a document to produce or a condition to verify.
Certification Bodies Aren't Grading Your Paperwork, They're Grading Your Operation
It helps to remember who's actually auditing you. Certification bodies that issue ISO 45001 certificates operate under ISO/IEC 17021-1 (requirements for bodies providing audit and certification of management systems), which requires the audit process to sample actual operational evidence on-site, not just review documents, before a body can recommend certification. For OH&S specifically, certification bodies must also meet IAF MD 22:2018, the International Accreditation Forum's mandatory document governing the transition of OH&S certification body accreditation from OHSAS 18001:2007 to ISO 45001:2018. If your consultant built you a system designed to survive a document review, they built it for the wrong audit stage.
This is also why the transition history matters more than most sites mention. ISO 45001:2018 replaced OHSAS 18001, and organizations certified under OHSAS 18001 had until September 2021 to transition — the IAF extended its original March 2021 deadline because of COVID-19 disruptions to audit scheduling (per the IAF's published transition requirements). Firms that only did OHSAS transitions and rebranded as ISO 45001 consultants sometimes carry over an audit mindset built for a British-standard predecessor rather than an ISO management-systems structure aligned to Annex SL, the high-level structure shared across ISO 9001, ISO 14001, and ISO 45001. If your organization already runs ISO 9001 or ISO 14001, that Annex SL alignment is a real point of leverage a generic OH&S-only shop may not exploit, since clauses like 4.3, 5.1, 9.3, and 10.2 are numbered and structured identically across all three standards.
Sector Specificity Is Where Generic Consulting Runs Out
A hazard identification methodology that works for a general manufacturing floor doesn't transfer cleanly to a construction site with rotating subcontractors, an oil and gas facility with process safety overlaps, or a hospital where clinical and non-clinical hazards coexist under one management system. Generic consulting groups often run one methodology across every client because it's cheaper to scale a single template than to build sector logic into the engagement.
This matters most at clause 6.1.3 (legal and other requirements), where OSHA standards intersect with ISO 45001's risk-based framework. A manufacturing client's machine guarding and lockout/tagout exposure under 29 CFR 1910.147 needs to show up in the risk register with the same rigor as a construction client's fall protection exposure under 29 CFR 1926 Subpart M. A consultant who treats OSHA compliance and ISO 45001 risk assessment as two separate deliverables is doing double the work and producing a system with gaps between them. For more on how the two frameworks are meant to function together rather than as parallel tracks, see ISO 45001 vs. OSHA: How They Work Together.
What I Actually Do Differently
I'll own the bias here: I run Certify Consulting, so take this section as a disclosed position, not a neutral comparison. But the specifics are checkable against the clauses above, which is the point.
The engagements I build start with the hazard identification methodology, not the policy manual, because clause 6.1.2 is where audits are won or lost and it's the section that requires the most site-specific work. I want a risk register that a worker helped build and can defend in an interview, not one a consultant built alone and handed to a safety manager to sign off on. That means time on the floor before time in the document template, which is a different sequencing than most engagements use, and it costs more hours up front. It also means the documentation that comes out the other end reflects a system I've watched operate, not a system I've described in the abstract.
I also treat clause 9.3 management review as an operational habit to install, not a form to fill out quarterly. A management review that doesn't produce a resourcing decision or a documented improvement action under clause 10.3 isn't doing what the clause requires. It's theater with an agenda.
When you're evaluating a consultant, ask them to walk you through how they'll handle clause 6.1.2 and clause 5.4 specifically, in your facility, with your workers. If the answer is a template name instead of a methodology, you have your answer.
How to Evaluate Any ISO 45001 Consultant, Including Us
Ask these questions regardless of who's pitching you:
- Will workers be interviewed and involved during the engagement, or only during the audit? Clause 5.4 participation built in audit week is not participation, it's rehearsal.
- Who validates the risk register against your actual site conditions? If the answer is "our template library," push back.
- What's the plan for clause 9.3 management review after certification? A system that isn't maintained past the certificate ceremony will show nonconformities at surveillance audit.
- Does the consultant distinguish your sector's legal requirements (OSHA standards, state plans, industry-specific regulations) inside the risk register, or bolt them on as a separate compliance checklist?
- Has the consultant explained the difference between Stage 1 and Stage 2 audits and what each one is actually testing? If they haven't, they may be building for the wrong one.
A consultant who answers these with specifics, clause numbers, and a description of process rather than a list of deliverables is worth a longer conversation. That's true whether that consultant works for Certify Consulting or somebody else. For a broader walkthrough of what a full engagement looks like end to end, see ISO 45001 Implementation: The Complete Guide.
The Real Differentiator Isn't the Firm, It's the Sequencing
If there's one thing I'd want a reader to take from this, it's that the difference between consulting groups is rarely about expertise on paper. Most consultants in this space know the standard. The difference is sequencing. Do you build the hazard identification and worker participation evidence first and let the documentation follow what's real? Or do you build the documentation first and hope the operation catches up before the auditor shows up? I've watched the second approach fail at Stage 2 enough times that I no longer think of it as a shortcut. It's a different, more expensive way to get to the same result, if it gets there at all.
Frequently Asked Questions
Is ISO 45001 certification the same regardless of which consultant I use?
The certificate itself is issued by an accredited certification body, not the consultant, so the credential is identical on paper. What differs is whether your management system holds up at surveillance audits after certification, which depends on whether the consultant built an operational system or a documentation package.
How do I know if a consulting proposal is template-based?
Ask what methodology they'll use for clause 6.1.2 hazard identification specific to your site. A template-based proposal will describe a document deliverable (a risk register format) rather than a process (how hazards get identified, validated, and updated with worker input).
Does ISO 45001 replace OSHA compliance?
No. ISO 45001 is a voluntary, internationally recognized management system standard; OSHA regulations under 29 CFR are mandatory U.S. federal requirements. A properly built ISO 45001 system incorporates applicable OSHA standards under clause 6.1.3 (legal and other requirements), but certification does not substitute for regulatory compliance. See our full comparison at ISO 45001 vs. OSHA: How They Work Together.
What happens if my documentation passes Stage 1 but the operation doesn't match at Stage 2?
The certification body will issue nonconformities, and depending on severity, certification is delayed until you close them with corrective action evidence. This is the most common failure point for organizations that used a template-only consulting approach.
Should I check whether a consulting firm has sector-specific experience?
Yes. Ask specifically how they'd handle your industry's legal requirements under clause 6.1.3 and whether their hazard identification methodology has been adapted for your operations rather than applied generically.
Last updated: 2026-08-27
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.