Most organizations don't fail Clause 10.2 because they skip the investigation. They fail it because they stop at the symptom. An employee slips on a wet floor, someone mops it up, a "wet floor" sign goes in the supply closet, and the file gets closed. Six months later, someone else slips on the same floor, in the same spot, for the same reason nobody ever asked why the floor was wet in the first place. That gap between "we fixed the puddle" and "we fixed the leaking chiller line that keeps making the puddle" is exactly what Clause 10.2 exists to close.
ISO 45001:2018 Clause 10.2, "Incident, nonconformity and corrective action," is where the standard stops being about paperwork and starts being about whether your organization actually learns from what goes wrong. It sits inside Clause 10, Improvement, and it's one of the clauses auditors spend the most time on, because it's where the gap between a documented system and a functioning one becomes visible fastest.
What Clause 10.2 Actually Requires
The clause text is compact, but it packs in a specific sequence. When an incident or nonconformity occurs, the organization must react in a timely manner to control and correct it and deal with the consequences, then evaluate the need for corrective action to eliminate the root cause so it doesn't happen again or happen somewhere else. That last phrase, "or happen somewhere else," is the part people miss most often. Clause 10.2 doesn't just want the specific hazard fixed. It wants you to check whether similar nonconformities exist elsewhere in the organization, or could occur, before you consider the corrective action complete.
The clause then requires you to review the effectiveness of any corrective action taken, and, if needed, update the risk assessment and other outputs of the OH&S management system before the corrective action is finalized, and make changes to the management system itself if necessary. Corrective actions have to be appropriate to the effects or potential effects of the incidents or nonconformities encountered, which is the standard's built-in proportionality test: a near miss with catastrophic potential deserves more rigor than a paper-cut incident, even if the actual harm in both cases was minor.
Annex A.10.2 adds a clarification worth sitting with: the standard requires investigation of incidents and nonconformities, including near misses, because a near miss is often the same failure mode as a serious injury, just without the unlucky timing. Treating near misses as low priority is one of the most common ways organizations quietly defeat the purpose of the clause while technically complying with its letter.
Incident, Nonconformity, and Near Miss Are Not the Same Thing
ISO 45001's definitions matter here because auditors will test whether your procedure actually distinguishes them. An incident is an occurrence arising from or in the course of work that could or does result in injury or ill health. A nonconformity is non-fulfillment of a requirement, which could be a missed inspection, an expired certification, or a control that exists on paper but wasn't followed on the floor. A near miss is a specific kind of incident, one where no injury or ill health occurred, but could have. Some organizations fold near misses into a separate "safety observation" program that never touches the Clause 10.2 process, and that's a mistake auditors are trained to look for. If your near-miss reports never generate a root cause analysis or a corrective action record, you don't have a Clause 10.2 process; you have a suggestion box.
The Investigation Sequence, Step by Step
A defensible incident investigation under Clause 10.2 generally moves through the same five stages, whether the incident is a recordable injury or a process nonconformity caught during an internal audit.
1. Immediate response and containment. Stop the hazard from causing further harm, secure the scene, provide first aid or medical attention, and preserve evidence before it gets cleaned up or altered. This is the "react in a timely manner" language from the clause text, and it's judged on speed as much as substance.
2. Fact-finding. Interview witnesses separately and promptly, before accounts blend together. Photograph the scene. Pull equipment logs, maintenance records, and training records. Document conditions exactly as they were, not as they're remembered a week later.
3. Root cause analysis. This is where most investigations either earn their keep or collapse into theater. A "5 Whys" exercise or a fishbone diagram that stops at "employee error" hasn't found a root cause; it's found a scapegoat. The real question is always what allowed the unsafe condition or unsafe act to exist and go unaddressed. In my experience reviewing investigation files during ISO 45001 gap assessments, the single most common finding is a root cause statement that restates the incident instead of explaining it, something like "root cause: employee did not wear PPE," with no exploration of why PPE wasn't available, wasn't enforced, or wasn't practical for the task.
4. Corrective action determination. Once you know the actual failure mode, you choose an action sized to it. A hierarchy of controls applies here just as it does in risk assessment: eliminating the hazard beats engineering controls, which beat administrative controls, which beat relying on PPE or "retraining" as the fix. An investigation that concludes every time with "retrain the employee" is a warning sign that root cause analysis isn't actually happening.
5. Verification of effectiveness. Clause 10.2 explicitly requires reviewing whether the corrective action worked. This means going back after the action is implemented, not just closing the record the day the fix is installed. If the same failure mode shows up again in three months, the corrective action wasn't effective, and the clause requires you to say so and act again.
Regulatory Reporting Windows Versus ISO 45001 Timing
Clause 10.2 says organizations must react "in a timely manner," which is intentionally not a fixed number, because ISO 45001 is written to apply across jurisdictions with wildly different reporting rules. That flexibility is useful, but it means your internal procedure needs to state real deadlines, not just repeat the standard's language back to an auditor. Here's how the major regulatory clocks compare to what a well-run Clause 10.2 process should be doing internally.
| Trigger | Regulatory Reporting Deadline | Recommended Internal Investigation Start |
|---|---|---|
| Fatality (US, OSHA 29 CFR 1904.39) | Report to OSHA within 8 hours | Immediately, same shift |
| In-patient hospitalization, amputation, or loss of an eye (OSHA) | Report to OSHA within 24 hours | Immediately, same shift |
| Reportable major injury (UK, RIDDOR) | Report "without delay" | Immediately, same shift |
| Recordable injury, no hospitalization | No fixed federal reporting clock; log on OSHA 300 within 7 calendar days | Within 24-48 hours |
| Near miss / nonconformity, no injury | Not externally reportable | Within 5 business days per most ISO 45001 procedures |
Note that OSHA's recordkeeping deadline (the 7-day window to enter a case on the OSHA 300 log) is a documentation requirement, not an investigation deadline. Clause 10.2 auditors want to see that the investigation itself started well before any regulatory paperwork was due, because starting the investigation the same day the log entry is due is a sign the process is reactive rather than genuinely improvement-driven.
From Root Cause to Corrective Action: Closing the Loop
The corrective action step is where Clause 10.2 connects back to the rest of the management system, and this is the linkage auditors are specifically trained to trace. A properly closed corrective action should touch at least three other parts of your OH&S management system:
- The risk assessment (Clause 6.1.2). If the incident revealed a hazard that wasn't previously identified or was underrated, the risk register has to be updated. An investigation that finds a new hazard but never feeds it back into the risk assessment has broken the loop halfway through.
- Operational controls (Clause 8.1). If a procedure, work instruction, or engineering control needs to change, that change has to be made and communicated, not just recommended in the investigation report.
- Competence and awareness (Clause 7.2, 7.3). If the root cause involves a training gap, a real training record has to exist showing the gap was closed, not a note that "training was discussed."
I've come to think of a corrective action record as incomplete until it names the specific document, control, or record that changed as a result. "We reminded staff to be careful" is not a corrective action. "We relocated the chiller drain line and updated the daily inspection checklist to include drain line inspection" is.
Where Organizations Get Cited: The Common Nonconformities
Across the ISO 45001 audits and gap assessments I've reviewed, the Clause 10.2 findings cluster into a small, predictable set of patterns.
Root cause analysis that stops at human error. Auditors will ask "why" until the answer points at a system, not a person. If your investigation form has a single line for "root cause" instead of a structured analysis method, that's usually the first thing flagged.
No evidence of effectiveness review. Plenty of organizations implement the fix and close the file the same week. Clause 10.2 requires a documented check-back, and if your corrective action log has an "implemented" date but no "verified effective" date, that's a gap.
Corrective actions that never touch the risk assessment. This is the single most cited disconnect I see. The investigation is thorough, the fix is reasonable, but the risk register from Clause 6.1.2 is untouched, meaning the organization's official record of hazards doesn't reflect what it just learned.
Near misses excluded from the formal process. If your near-miss reporting system feeds a spreadsheet that nobody analyzes for trends, you have data collection, not incident investigation.
No check for similar nonconformities elsewhere. The clause specifically requires evaluating whether the same nonconformity exists, or could occur, in other locations, processes, or shifts. Auditors will ask directly: "did you check the other three lines that use the same equipment?" If the answer is no, that's a finding.
Documented Information: What You Need to Retain
Clause 10.2 comes with an explicit requirement to retain documented information as evidence of the nature of incidents or nonconformities, any subsequent action taken, and the results of any corrective action, including its effectiveness. In practice, a defensible file includes the initial incident report, witness statements, photos or scene documentation, the root cause analysis with whatever method was used, the corrective action plan with owners and target dates, evidence the action was actually implemented, and the effectiveness review conducted after enough time has passed to know whether it worked. Missing any one of these is usually enough to generate a minor nonconformity at audit, and missing several at once starts to look like a systemic gap rather than a paperwork oversight.
Why This Clause Carries More Weight Than Its Word Count Suggests
The scale of the underlying problem is part of why Clause 10.2 gets this much attention in the standard. The International Labour Organization estimates that around 2.3 million people die every year from work-related accidents or diseases, which works out to roughly one worker dying every 15 seconds somewhere in the world. In the United States, the Bureau of Labor Statistics has reported private industry recordable case rates hovering near 2.7 cases per 100 full-time workers in recent years, a number that has been essentially flat for several reporting cycles, which is itself a signal that incident investigation and corrective action processes, industry-wide, aren't closing the loop as effectively as they could. Certification activity has grown alongside that pressure: the ISO Survey has shown ISO 45001 certificates climbing into the hundreds of thousands globally since the standard replaced OHSAS 18001 in 2018, reflecting how many organizations are now being formally audited against exactly this clause.
None of that data changes what Clause 10.2 asks of any single organization, which is simpler than the statistics make it sound: when something goes wrong, find out why it actually went wrong, fix the thing that let it happen, check whether the fix worked, and check whether the same failure is hiding somewhere else. For a deeper look at how the risk assessment obligations under Clause 6.1.2 hazard identification connect back into this corrective action loop, or for a structured walkthrough of building an internal audit program that will surface these nonconformities before a certification body does, see our related guide on ISO 45001 internal audit planning.
FAQ
What is the difference between Clause 10.1 and Clause 10.2 in ISO 45001?
Clause 10.1, General, sets the overall requirement to determine and select opportunities for improvement and implement necessary actions to achieve the intended outcomes of the OH&S management system. Clause 10.2 is more specific: it's the mechanism for reacting to incidents and nonconformities after they occur, investigating root causes, and taking corrective action so they don't recur.
Does every near miss require a formal investigation under Clause 45001?
Yes, in principle. Annex A.10.2 makes clear that near misses should be investigated with the same rigor as incidents that caused harm, because the underlying hazard and failure mode are often identical, and the only difference is timing or luck. A near-miss program that never triggers root cause analysis is not meeting the intent of the clause even if it technically logs the events.
How long do we have to complete a corrective action under ISO 45001?
The standard doesn't set a fixed number of days; it requires action "appropriate to the effects or potential effects" of the incident, completed in a "timely manner." Most organizations build tiered internal deadlines into their procedure, for example 24 to 48 hours to begin investigating a serious incident and 30 to 90 days to close the corrective action, scaled to severity, and auditors will check whether those internal deadlines were actually met.
What counts as documented evidence for Clause 10.2 compliance?
At minimum: the initial incident or nonconformity report, evidence of the root cause analysis method used, the corrective action plan with responsible parties and dates, proof the action was implemented, and a documented review of whether the action was actually effective. Missing the effectiveness review is the single most common gap auditors cite.
Can the same corrective action process satisfy both ISO 45001 and ISO 9001?
Largely yes. ISO 45001 was deliberately structured on the same high-level structure as ISO 9001:2015, and Clause 10.2 in both standards follows a nearly parallel logic of react, correct, evaluate root cause, and verify effectiveness. Organizations with an integrated management system typically run one corrective action procedure that captures both quality and safety nonconformities, distinguishing them by category rather than running two separate systems.
Last updated: 2026-08-06
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.