Why Most ISO 45001 Rollouts Stall in the Same Place
I have sat across the table from a lot of operations managers who started their ISO 45001 implementation with a binder full of templates and a deadline from a customer contract. Six months later, the binder is fuller, the deadline has moved twice, and nobody can tell me who actually owns the hazard register. That is not a documentation problem. It is a sequencing problem.
ISO 45001:2018 is built on the Annex SL high-level structure — the same ten-clause skeleton used by ISO 9001:2015 and ISO 14001:2015. That shared architecture is a gift if you already run one of those systems, and a trap if you treat ISO 45001 as a paperwork exercise rather than a management system that has to change how decisions get made on the floor. The standard itself is explicit about this in clause 5.1: top management has to demonstrate leadership and commitment, not just sign a policy. Everything else in this guide follows from that one requirement.
Below is the sequence I actually use with clients, mapped to the clauses an auditor will check it against.
Step 1: Get Leadership Commitment on the Record (Clause 5.1)
Clause 5.1 lists specific things top management must do: take accountability for the effectiveness of the OH&S management system, ensure the policy and objectives are compatible with the organization's strategic direction, and integrate the system requirements into business processes. An auditor will ask for evidence of each of these — not a statement of intent, but records: meeting minutes where resources were approved, a signed policy, objectives tied to a budget line.
If you skip this step, everything downstream gets built on sand. I have seen implementation teams spend four months on a risk assessment methodology that leadership never resourced to fix the hazards it found. The system passed a documentation review and failed the moment a worker asked why nothing changed.
Step 2: Define the Scope of Your Management System (Clause 4.3)
Clause 4.3 requires you to determine the boundaries and applicability of the OH&S management system, considering the external and internal issues from clause 4.1, the needs of interested parties from clause 4.2, and the activities, products, and services under your control or influence. Write this down as a scope statement — which sites, which operations, which legal entities. A scope that is vague ("our manufacturing operations") invites an auditor to ask you to prove where the line actually sits.
For guidance on how this clause interacts with the rest of your planning, see our breakdown of determining the scope of an OH&S management system.
Step 3: Run a Gap Analysis Against Your Current State
Before you build anything new, find out what you already have. Most organizations pursuing ISO 45001 already have some safety infrastructure — OSHA-mandated programs under 29 CFR 1910, a safety committee, incident logs. A gap analysis maps what exists against each of the ten Annex SL clauses and tells you where the real work is.
If your organization is transitioning from OHSAS 18001, note that the International Accreditation Forum set March 2021 as the deadline for OHSAS 18001 certificates to be migrated to ISO 45001 — a three-year transition window from the standard's March 2018 publication. That transition is closed now, but the gap-analysis logic is identical for anyone starting fresh: inventory what you have, clause by clause, before you write a single new procedure.
Step 4: Identify Hazards and Assess Risk (Clause 6.1.2)
This is the clause that does the most work in the entire standard. Clause 6.1.2.1 requires a hazard identification process that is proactive, considers routine and non-routine activities, and accounts for how work is actually organized — not just how it is documented. Clause 6.1.2.2 then requires you to assess OH&S risks from those hazards, and clause 6.1.2.3 requires you to assess OH&S opportunities — a piece organizations frequently skip because it does not feel like "safety."
I have written a full methodology walkthrough because this step is where most gap analyses reveal the biggest hole: ISO 45001 clause 6.1.2 hazard identification methodologies. If you need a working risk matrix rather than a theoretical one, our guide on building an ISO 45001 risk assessment matrix from scratch walks through the scoring logic auditors expect to see.
Worker participation is not optional here. Clause 5.4 requires consultation and participation of workers at non-managerial levels in hazard identification and risk assessment — an auditor who interviews shop-floor workers and finds they were never consulted has a finding, regardless of how good your hazard register looks on paper.
Step 5: Determine Legal and Other Requirements (Clause 6.1.3)
Clause 6.1.3 requires you to determine and have access to the legal requirements and other requirements applicable to your hazards and OH&S management system, and to determine how those requirements apply. In the U.S., this means building a register that ties specific OSHA standards — lockout/tagout under 29 CFR 1910.147, respiratory protection under 29 CFR 1910.134, whatever applies to your operations — to the hazards you identified in Step 4. This register is not a static document; clause 6.1.3 also requires you to keep it current.
Step 6: Set Objectives and Plan Actions to Achieve Them (Clause 6.2)
Clause 6.2.1 requires OH&S objectives that are consistent with the policy, measurable (where practicable), monitored, and communicated. Clause 6.2.2 then requires you to plan how to achieve them: what will be done, what resources are required, who is responsible, when it will be completed, and how results will be evaluated. This is where I tell clients to resist the urge to write objectives like "reduce incidents." An objective without a measurable target and an owner is not an objective under this clause — it is a wish.
Step 7: Build Competence, Awareness, and Communication (Clause 7)
Clause 7.2 requires you to determine the necessary competence of workers whose work affects OH&S performance, and clause 7.3 requires you to ensure workers are aware of the policy, their contribution to the system's effectiveness, and the consequences of not conforming. Clause 7.4 covers internal and external communication — what gets communicated, when, to whom, and how.
Training records are one of the first things an auditor pulls. If you cannot connect a specific role to a specific competence requirement to a specific training record, that gap surfaces immediately. We cover what auditors actually look for in ISO 45001 competence requirements — training records auditors want.
Step 8: Establish Operational Controls (Clause 8)
Clause 8.1 requires you to plan, implement, and control the processes needed to meet the OH&S management system requirements — including the hierarchy of controls: eliminate the hazard, substitute, use engineering controls, use administrative controls, and use adequate PPE, in that order of preference. Clause 8.2 addresses emergency preparedness and response. This is also where management of change lives: any change that affects OH&S performance — new equipment, new processes, organizational changes — has to go through a controlled review before it happens, not after an incident reveals it should have.
Step 9: Check Performance (Clause 9)
Clause 9.1 requires monitoring, measurement, analysis, and performance evaluation. Clause 9.2 requires internal audits at planned intervals. Clause 9.3 requires management review at planned intervals to ensure the system's continuing suitability, adequacy, and effectiveness. None of these are one-time events — they are the mechanism that keeps the system alive after the certification audit is over. An organization that treats the internal audit as a pre-certification formality, rather than a genuine check, tends to find out the hard way at the next surveillance audit.
Step 10: Correct, Improve, and Certify (Clause 10)
Clause 10.2 requires you to react to nonconformities, evaluate the need for action to eliminate root causes, and review the effectiveness of corrective action taken. Clause 10.3 requires continual improvement of the system's suitability, adequacy, and effectiveness. Once this loop is running, you are ready for certification: a Stage 1 audit (documentation review and readiness check), a Stage 2 audit (evidence of implementation and effectiveness), and — once certified — a three-year cycle of annual surveillance audits with recertification at year three, per the accreditation rules in ISO/IEC 17021-1 that certification bodies operate under.
Implementation Steps Mapped to Clause Numbers
| Step | Clause | What the Auditor Checks |
|---|---|---|
| Leadership commitment | 5.1 | Records of resourcing, policy sign-off, integration into business processes |
| Scope definition | 4.3 | Documented scope statement with clear boundaries |
| Hazard identification & risk assessment | 6.1.2 | Process covering routine/non-routine activities; worker consultation evidence |
| Legal and other requirements | 6.1.3 | Register linking OSHA/regulatory citations to identified hazards |
| Objectives and planning | 6.2 | Measurable targets with owners, resources, and timelines |
| Competence and awareness | 7.2, 7.3 | Training records tied to specific roles and hazards |
| Operational controls | 8.1, 8.2 | Hierarchy of controls applied; emergency response plans tested |
| Performance evaluation | 9.1–9.3 | Internal audit records, management review minutes |
| Corrective action | 10.2 | Root cause analysis and effectiveness review, not just closure |
How Long Does ISO 45001 Implementation Actually Take?
There is no fixed number the standard gives you, and I am wary of anyone who quotes one without knowing your site count, your existing safety program maturity, or your industry's hazard profile. What I can tell you is the sequence does not compress well: you cannot meaningfully write objectives (Step 6) before you have completed hazard identification (Step 4), and you cannot run a credible internal audit (Step 9) against controls that were only implemented last week. Organizations that already have a mature OSHA compliance program and a functioning safety committee move through Steps 1–5 faster because much of that infrastructure already exists — it just needs to be mapped to the clause structure. For a full walkthrough of the required documentation set at each stage, see our complete list of ISO 45001 required documents.
The One Thing I'd Tell You to Fix First
If I had to pick a single point of failure across the implementations I have reviewed, it is clause 5.4 — worker participation. Organizations build a technically compliant hazard register in a conference room and never take it to the floor. ISO 45001 is structured differently from ISO 9001 in exactly this respect: it assumes the people doing the work know things about the hazards that the people writing the procedure do not. A system built without that input can pass a paper audit and still fail the people it exists to protect. That gap is worth closing before you spend another dollar on documentation software.
Frequently Asked Questions
What is the first step in implementing ISO 45001?
The first step is securing documented leadership commitment under clause 5.1 — top management has to formally take accountability for the system's effectiveness and allocate resources before any hazard identification, risk assessment, or documentation work begins.
How many clauses does ISO 45001 have?
ISO 45001:2018 has ten clauses, following the Annex SL high-level structure shared with ISO 9001:2015 and ISO 14001:2015. Clauses 1–3 cover scope, normative references, and terms; clauses 4–10 contain the actual management system requirements, from context of the organization through continual improvement.
Do I need a consultant to implement ISO 45001?
No — the standard does not require a consultant, and small organizations with a straightforward hazard profile can implement it internally. A consultant adds the most value in accelerating the hazard identification and risk assessment methodology (clause 6.1.2) and in preparing for the certification audit, since those are the areas where inexperienced teams tend to build systems that look complete but do not hold up under auditor questioning.
What is the difference between Stage 1 and Stage 2 certification audits?
A Stage 1 audit reviews your documentation and assesses whether your management system is ready for a full audit — it checks that the scope, policy, objectives, and legal register exist and are coherent. A Stage 2 audit examines whether the system is actually implemented and effective, through site observation, worker interviews, and record review.
How does ISO 45001 relate to OSHA compliance?
ISO 45001 is a management system standard; OSHA regulations are legal requirements. Clause 6.1.3 requires you to identify and track applicable legal requirements — including specific OSHA standards under 29 CFR 1910 and 1926 — as part of the system, but certification to ISO 45001 does not itself satisfy OSHA compliance obligations. For a deeper comparison of how the two frameworks work together, see ISO 45001 vs. OSHA: how they work together.
If you are staring down an implementation timeline and want a second set of eyes on your sequencing before you commit resources to it, our implementation services page outlines how we typically structure that engagement.
Last updated: 2026-09-10
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.