Compliance 12 min read

ISO 45001 Clause 10.3: Continual Improvement Explained

J

Jared Clark

August 13, 2026

Clause 10.3 is the shortest clause in ISO 45001:2018, and in my consulting work it's one of the clauses I see cited most often in nonconformities — not because the organizations I work with aren't actually improving, but because clause 10.3 is where an auditor tests whether everything else in the management system adds up to something provable. If clauses 4 through 9 are about building and running a system, clause 10.3 asks a plainer question: is the system making work safer over time, and can you show it?

The nonconformities I see against this clause almost always trace back to the same root cause: an organization treats continual improvement as a mindset instead of a documented, evidenced process. ISO 45001 doesn't accept a mindset as objective evidence. It wants records.

What Clause 10.3 Actually Says

ISO 45001:2018 clause 10.3 requires the organization to continually improve the suitability, adequacy, and effectiveness of the OH&S management system to enhance OH&S performance. The clause breaks that requirement into five specific actions:

  1. Enhancing OH&S performance
  2. Promoting a culture that supports an OH&S management system
  3. Promoting worker participation in implementing continual improvement actions
  4. Communicating relevant continual improvement results to workers and, where they exist, workers' representatives
  5. Maintaining and retaining documented information as evidence of continual improvement

Notice what's missing from that list: there is no requirement for a specific rate of improvement, no mandated percentage reduction in incidents, and no prescribed methodology. Clause 10.3 is a performance-outcome clause wrapped around a process requirement — the standard cares that improvement is happening and evidenced, not that it hits an arbitrary number.

That distinction matters for how you build your system. I've seen organizations invent improvement targets — for example, committing to reduce their Total Recordable Incident Rate (TRIR, a standard lagging indicator calculated from OSHA recordable injuries per 200,000 hours worked) by a fixed percentage every year — because they assumed the standard required a metric threshold. It doesn't. What it requires is a demonstrable, documented cycle that connects your inputs — incidents, audits, management review, worker feedback — to actions that measurably change OH&S performance, suitability, or effectiveness.

Continual vs. Continuous: A Distinction That Shows Up in Audits

ISO 45001 deliberately uses "continual," not "continuous." Continuous implies an unbroken, real-time process. Continual means recurring, with pauses between cycles — annual management reviews, periodic internal audits, incident-driven corrective actions. Your OH&S management system doesn't need to be improving every single day to conform to clause 10.3. It needs a recurring, evidenced cadence of improvement activity that an auditor can trace across a full management system cycle, typically 12 months.

This is worth clarifying up front because it changes how you defend the clause in an audit. You are not proving perpetual motion. You are proving a pattern: inputs come in, they get evaluated, actions get taken, results get communicated, and records exist to show all four steps happened.

How Clause 10.3 Connects to the Rest of Clause 10 and Clause 9

Clause 10.3 doesn't operate alone. ISO 45001 structures clause 10 as a feedback loop, and clause 10.3 is the clause that closes it.

  • Clause 10.1 (General) requires the organization to determine opportunities for improvement and implement necessary actions.
  • Clause 10.2 (Incident, nonconformity and corrective action) requires reacting to incidents and nonconformities, evaluating causes, and taking corrective action — and, among its requirements, reviewing the effectiveness of any corrective action taken.
  • Clause 10.3 (Continual improvement) requires pulling the results of 10.1 and 10.2 — plus clause 9's monitoring, measurement, internal audit, and management review outputs — into a continuing improvement of the system as a whole.

In practice, auditors trace this chain backward. They'll pick a management review output, ask you to show the data that fed it (clause 9.1 monitoring and measurement, clause 9.2 internal audit findings, clause 9.3 management review inputs), then ask what action resulted and where clause 10.3's evidence trail — the documented information — lives. If any link in that chain is missing, the nonconformity often gets written against 10.3, even when the actual gap sits back in your clause 9 data collection.

This is also why I tell clients not to treat clause 10.3 as a standalone documentation exercise. It's the output clause for what ISO management-system standards call the Plan-Do-Check-Act (PDCA) cycle — plan the system, do the work, check performance, act on what you learn. If clause 6.1 planning and clause 9 monitoring are weak, clause 10.3 has nothing legitimate to draw on, and the "improvement" you document will read as manufactured rather than evidenced.

The Five Requirements of Clause 10.3, Broken Down

1. Enhancing OH&S Performance

This is the substantive requirement — actual improvement in outcomes, not just process activity. OH&S performance, as defined in ISO 45001:2018 clause 3.28, covers both leading indicators (training completion, near-miss reporting rates, audit closure times) and lagging indicators (recordable injury rates, lost workdays). Auditors look for evidence that your organization tracks both types and can show a trend, even a modest one, tied to specific actions.

2. Promoting a Supportive Culture

Clause 10.3(b) requires promoting a culture that supports the OH&S management system — not a separate "safety culture program," but evidence that leadership behavior, communication, and resource allocation reinforce the management system rather than working around it. Auditors typically test this through worker interviews, not documents. If workers describe safety concerns as something they report into a system that responds, that's culture evidence. If they describe workarounds or resignation, that's a gap regardless of what your policy states.

3. Promoting Worker Participation

This requirement links directly to clause 5.4 (worker consultation and participation). Clause 10.3(c) specifically wants worker participation in implementing improvement actions — not just being consulted about hazards, but actually contributing to how corrective and improvement actions get designed and rolled out. We've written in detail about what clause 5.4 requires in worker participation in ISO 45001: what clause 5.4 requires, and the overlap with 10.3 is one of the more commonly missed connections in a management system.

4. Communicating Results

Clause 10.3(d) requires communicating relevant continual improvement results to workers and, where they exist, worker representatives. This is a distinct requirement from clause 7.4's general communication process. Auditors will specifically ask: how do workers learn that the corrective action from last quarter's incident actually closed, and what changed as a result? A closed corrective action that nobody on the floor ever hears about does not satisfy 10.3(d).

5. Maintaining Documented Information

Clause 10.3(e) is where most nonconformities get written. The standard requires retained documented information as evidence of continual improvement — meaning you need records that show the loop closed, not just records that show an action was assigned. A corrective action tracker with an open date and no closure evidence, a management review with no follow-up action log, an internal audit finding with no verification of effectiveness — these are the exact gaps that generate a 10.3 finding.

What Auditors Actually Sample

Audit evidence type What the auditor is checking Common gap
Management review minutes (clause 9.3) Improvement opportunities identified and actioned Minutes list discussion but no decisions or owners
Corrective action records (clause 10.2) Root cause analysis and effectiveness verification Action closed without verifying it actually worked
Internal audit reports (clause 9.2) Findings tracked to resolution across cycles Same finding recurs audit after audit, unaddressed
OH&S performance data (clause 9.1) Trend analysis over multiple periods, not a single snapshot Only current-period data available; no trend
Worker interviews Awareness of changes made in response to their input Workers unaware any action was ever taken
Communication records Evidence results were shared, not just achieved Improvement happened but was never communicated

Common Nonconformities Against Clause 10.3

The nonconformities I see most often during gap assessments and certification audits fall into five recurring patterns:

  1. No traceable link between inputs and actions. The organization has incident data, audit findings, and management review minutes, but there's no record connecting any of them to a specific improvement action. Each exists in isolation.

  2. Improvement without communication. Real improvements happen — a machine guard gets redesigned, a permit-to-work process gets rewritten — but clause 10.3(d)'s requirement to communicate the result to workers gets skipped, usually because it wasn't built into the corrective action workflow.

  3. Closed actions with no effectiveness check. A corrective action gets marked closed the moment the physical fix is installed, with no follow-up to confirm the OH&S risk was actually reduced. Clause 10.2 requires reviewing the effectiveness of any corrective action taken, and that effectiveness data is exactly what clause 10.3 needs to demonstrate genuine improvement rather than completed activity.

  4. Culture claims without behavioral evidence. The OH&S policy states a commitment to continual improvement, but worker interviews reveal no awareness of any changes, no active participation mechanism, and no sense that reporting leads anywhere.

  5. Static metrics. The organization tracks the same leading and lagging indicators every year with no analysis of trend, no benchmarking against prior periods, and no narrative explaining what changed and why.

Building a Clause 10.3-Compliant Improvement Process

A conforming continual improvement process doesn't need to be elaborate. It needs four things working together on a recurring cycle:

  1. A defined set of inputs. Incident investigations, internal and external audit findings, nonconformities, worker feedback and near-miss reports, monitoring and measurement data, legal and regulatory changes, and management review outputs. Each input source should have an owner and a defined review frequency.

  2. A single point where inputs get evaluated. This is usually the management review meeting required under clause 9.3, but organizations with more mature systems often run a quarterly or monthly OH&S performance review as well. The point is not to invent a new committee — it's to make sure every input actually gets looked at by someone with authority to act.

  3. An action and effectiveness-verification workflow. Every improvement action needs an owner, a target date, an implementation record, and — critically — a follow-up check that confirms the action produced the intended effect. Without the effectiveness check, you have activity, not improvement.

  4. A communication step baked into the workflow, not bolted on after. The easiest way to satisfy clause 10.3(d) consistently is to make communication a required field in your corrective action or improvement tracker — the action isn't closed until the result has been communicated to affected workers.

If you're building this out from scratch as part of a broader implementation project, our ISO 45001 implementation guidance walks through how this fits into the overall system build, including the sequencing that keeps clause 10.3 from becoming an afterthought bolted on right before a certification audit.

Continual Improvement Isn't a Line Item — It's the Test of the Whole System

Here's the thing I keep coming back to with clients: clause 10.3 rarely fails because an organization lacks safety improvements. Most organizations I work with are making real safety improvements constantly — better guarding, better training, better reporting. Clause 10.3 fails because those improvements happen outside the management system's documented loop, so there's no way to demonstrate, on audit day, that the system itself is what's driving the improvement rather than individual initiative that would exist with or without ISO 45001.

That's the real function of this clause. It's not asking whether your workplace is getting safer. It's asking whether your management system is the mechanism producing that safety — because a system that can't demonstrate its own value is a system a certification body, and eventually your own leadership, will stop trusting.

FAQ

Does ISO 45001 clause 10.3 require a specific rate of improvement, like a percentage reduction in incidents? No. Clause 10.3 requires a documented, recurring process of improvement with retained evidence — it does not specify a numeric threshold or improvement rate. Auditors assess whether the process is functioning and evidenced, not whether a particular percentage was hit.

What's the difference between clause 10.2 corrective action and clause 10.3 continual improvement? Clause 10.2 addresses reacting to specific incidents and nonconformities with root cause analysis and corrective action. Clause 10.3 is broader: it requires the organization to pull results from clause 10.2, clause 9 monitoring, internal audits, and management review into an ongoing improvement of the OH&S management system's suitability, adequacy, and effectiveness as a whole.

What documented information satisfies clause 10.3(e)? There's no prescribed document type. Organizations typically use management review minutes with tracked action items, corrective action logs with effectiveness verification, OH&S performance trend reports, and communication records showing results were shared with workers. The key auditor test is traceability — can you show the full loop from input to action to verified result to communication?

Who needs to be told about continual improvement results under clause 10.3(d)? Workers, and where they exist, workers' representatives. This is broader than management-level reporting — the standard specifically requires that the people doing the work know what changed and why, not just that leadership reviewed the data.

Can a small organization satisfy clause 10.3 without a formal software system? Yes. Clause 10.3 doesn't require any particular tool. A well-maintained spreadsheet or log that tracks inputs, actions, effectiveness checks, and communication dates can satisfy the clause, provided it's actually used and retained as documented information. The requirement is about the process being real and evidenced, not about the sophistication of the platform running it.

Last updated: 2026-08-13

J

Jared Clark

Principal Consultant, Certify Consulting

Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.

Ready to Protect Your People?

Schedule a free consultation to discuss your ISO 45001 certification goals, OSHA compliance needs, and how we can build a safety management system that works for your organization.