Guide 11 min read

ISO 45001: The Complete OH&S Certification Guide

J

Jared Clark

July 23, 2026

ISO 45001 is the international standard for occupational health and safety (OH&S) management systems. Published by the International Organization for Standardization on March 12, 2018, it replaced OHSAS 18001 — which was officially withdrawn in September 2021 — and established a single, globally recognized framework for protecting workers from injury, illness, and death.

The scale of the problem this standard addresses is hard to sit with. The International Labour Organization estimates 2.3 million workers die from work-related causes each year, and another 374 million suffer non-fatal workplace injuries and illnesses annually. Those aren't statistics to cite in a board presentation and move on from — they're the reason this standard exists.

In my eight years and 200+ client engagements across manufacturing, construction, healthcare, and professional services, the organizations that treat ISO 45001 as a genuine management system — rather than a compliance box to check — see measurable reductions in incidents, lower workers' compensation costs, and a workforce that actually trusts leadership cares about their safety. The ones who treat it as a paperwork exercise get a certificate, a binder, and not much else.

This guide covers what ISO 45001 actually requires, how it differs from what came before, how to implement it, and what the certification process looks like end to end.


What ISO 45001 Requires

ISO 45001 follows the High Level Structure (HLS) used across all modern ISO management system standards — the same architecture you'll find in ISO 9001 (quality) and ISO 14001 (environment). If your organization already holds one of those certifications, the integration path for ISO 45001 is considerably shorter than starting from scratch.

The standard spans ten clauses. Clauses 1 through 3 cover context and definitions. The substantive requirements live in clauses 4 through 10.

Clause 4 — Context of the Organization

You need to understand the internal and external factors that affect your OH&S performance, identify the workers and other interested parties who have a stake in your system, and define the scope of your OH&S management system. This isn't bureaucratic throat-clearing — it's the foundation everything else sits on. An organization that can't articulate who its workers are and what hazards they face can't manage those hazards systematically.

Clause 5 — Leadership and Worker Participation

ISO 45001 clause 5.1 places explicit accountability on top management — not on the safety manager, not on a committee, but on the people who actually run the organization. The standard also requires genuine worker participation (clause 5.4), which is where I see the most shortcuts taken. Consulting workers is not the same as involving them. The standard requires the latter, and auditors know the difference.

Clause 6 — Planning

This clause contains two of the most consequential requirements in the standard. Clause 6.1.2 requires organizations to identify hazards and assess OH&S risks — proactively, not just after something goes wrong. Clause 6.1.3 requires identification of legal and other requirements. Together, these clauses force organizations to actually look at what could hurt someone and figure out what they're legally obligated to do about it.

Clause 7 — Support

Resources, competence, awareness, communication, and documented information. The documentation requirements in ISO 45001 are often misunderstood — the standard doesn't require mountains of paperwork, it requires documented information as evidence that the system is working. That distinction matters enormously when you're designing your system.

Clause 8 — Operation

This is where the rubber meets the road. Clause 8.1.2 introduces the hierarchy of controls, requiring organizations to eliminate hazards where possible and work down the hierarchy — elimination, substitution, engineering controls, administrative controls, PPE — to manage what can't be eliminated. Clause 8.4 addresses contractors and outsourcing, which is where many organizations have genuine exposure they haven't looked at closely.

Clause 9 — Performance Evaluation

Monitoring, measurement, internal audits (clause 9.2), and management review (clause 9.3). The internal audit requirement exists to catch problems before your certification body does. I've seen organizations treat internal audits as a formality and pay for it in their Stage 2 audit. A rigorous internal audit program is your best quality control on the entire system.

Clause 10 — Improvement

Incident investigation, nonconformity, corrective action, and continual improvement. Clause 10.2 requires that nonconformities are investigated to root cause — a requirement that sounds obvious but is routinely handled superficially. Corrective actions that don't address root cause don't prevent recurrence, and auditors know the difference.


ISO 45001 vs. OHSAS 18001: What Changed

OHSAS 18001 was a British Standard, not an ISO standard, which created a globally fragmented landscape — different countries, different interpretations, different audit expectations. ISO 45001 resolved that. Beyond the structural shift, the substantive changes are significant.

Feature OHSAS 18001 ISO 45001
Standard type British Standard (BSI) ISO International Standard
Published 1999, revised 2007 2018
Status Withdrawn September 2021 Current
Worker participation Referenced Explicitly required (Clause 5.4)
Leadership accountability General Specific top management obligations
Hazard identification Reactive focus acceptable Proactive identification required
Contractor management Limited scope Explicit requirements (Clause 8.4)
Hierarchy of controls Present Explicitly mandated (Clause 8.1.2)
Context of organization Not required Required (Clause 4)
Opportunities Not addressed OH&S opportunities addressed
Integration with other ISO standards Difficult Designed for integration via HLS

The OHSAS 18001 withdrawal in September 2021 ended a three-year migration window. If your organization still operated under an OHSAS 18001 certificate that lapsed, you're starting the ISO 45001 process fresh — not upgrading.


How to Implement ISO 45001: A Practical Roadmap

Most organizations follow a six-phase implementation path. The timeline varies considerably based on size, operational complexity, and how mature the existing safety program is.

Phase 1: Gap Assessment. Before you can plan the work, you need to know where you stand. A gap assessment benchmarks your current practices against ISO 45001 requirements clause by clause and produces a prioritized list of what needs to be built, fixed, or documented. In my view, this is the highest-ROI step in the entire process — it prevents organizations from over-engineering areas that are already compliant and from underestimating areas with real gaps. See our ISO 45001 gap assessment guide for a detailed walkthrough of what this involves.

Phase 2: System Design. Once you know the gaps, you design the OH&S management system. This means defining your OH&S policy (clause 5.2), establishing your hazard identification methodology (clause 6.1.2), documenting your legal register (clause 6.1.3), and creating the documented information the standard requires. System design is where you make the fundamental choice between building something your organization will actually use versus building something that will satisfy an auditor once a year.

Phase 3: Implementation. This is the longest phase and the one where most projects stall. You're training workers, standing up new processes, conducting hazard identifications across your operation, and building the corrective action and incident investigation workflows required by clauses 10.1 and 10.2. Worker participation requirements (clause 5.4) mean implementation can't be a top-down rollout — workers need to be involved in identifying hazards and developing controls, not just informed of the results.

Phase 4: Internal Audit. Before you invite a certification body in, you need to audit your own system. Clause 9.2 requires a planned internal audit program covering the full scope of the system against all applicable clause requirements. Organizations that run superficial internal audits typically find their certification body doing a more thorough job in Stage 2 than they did internally — which is exactly the wrong sequence.

Phase 5: Management Review. Clause 9.3 requires top management to review the OH&S management system at planned intervals. This isn't delegatable — the standard requires top management involvement, documented inputs per clause 9.3.2, and documented outputs per clause 9.3.3. Before you certify, you need at least one completed management review on record.

Phase 6: Certification Audit. The certification process involves two stages — the Stage 1 documentation review and readiness assessment, followed by the Stage 2 on-site audit. We cover this in detail below.


The Certification Process, Start to Finish

Certification is performed by an accredited third-party certification body (CB). Common CBs operating in North America include BSI, Bureau Veritas, DNV, SGS, and UL. The CB must be accredited by an IAF-recognized accreditation body — in the US, that's ANAB or A2LA.

Stage 1 Audit. The Stage 1 is a documentation review and readiness assessment. The auditor reviews your OH&S policy, documented procedures, and key system documentation, then assesses whether your system is sufficiently developed and implemented to proceed to Stage 2. Stage 1 typically surfaces gaps that need to be addressed before Stage 2 — think of it as your final check before the real exam.

Stage 2 Audit. The Stage 2 is the on-site audit where the auditor verifies that your system is implemented, effective, and conforming to ISO 45001 requirements. Auditors will interview workers, review records, observe operations, and trace processes end to end. Nonconformities found at Stage 2 must be resolved before certification is granted. Minor nonconformities typically require a corrective action plan; major nonconformities may require a full re-audit of the affected area.

Surveillance Audits. ISO 45001 certification is valid for three years, with annual surveillance audits verifying the system remains effective. Year 3 brings a recertification audit, which functions similarly to the original Stage 2.

Certify Consulting has maintained a 100% first-time audit pass rate across all client certifications. That's not because we paper over weaknesses — it's because we don't present clients to Stage 2 until the system is genuinely ready.


What It Costs and How Long It Takes

These ranges reflect real-world outcomes across organization types and sizes. Your actual numbers will vary based on starting maturity, operational complexity, and the CBs available in your market.

Organization Size Implementation Timeline Consultant Support Cost CB Audit Cost (approx.)
Small (<50 employees) 4–6 months $8,000–$18,000 $3,000–$6,000
Medium (50–250 employees) 6–10 months $18,000–$40,000 $5,000–$12,000
Large (250–1,000 employees) 10–18 months $35,000–$80,000 $10,000–$25,000
Enterprise (1,000+) 15–24 months $75,000+ $20,000–$60,000+

These costs assume organizations are starting with a meaningful safety program already in place. Organizations with no documented safety management system at baseline should add 20–30% to implementation timelines and costs.


Common Mistakes That Sink First-Time Audits

In my experience, the same patterns surface across failed or near-failed audits. They're worth naming directly.

Treating worker participation as consultation. Clause 5.4 requires workers to participate in hazard identification, risk assessment, and the determination of controls. "We surveyed our workforce" doesn't meet that requirement. Workers need to be in the room — or the equivalent — when hazards are being identified and controls are being designed.

Legal registers that haven't been maintained. I've seen legal registers built at implementation and never touched again — out-of-date regulations, requirements that apply to operations the register doesn't account for, documents linked but never reviewed. A legal register is only useful if someone owns it and updates it on a defined schedule.

Internal audits that read as checklists, not audits. An internal audit that produces no findings is almost always a sign of an ineffective internal audit program, not an effective OH&S system. If your internal audit produces a clean report, spend another day auditing before you invite the certification body in.

Incident investigations that stop at immediate cause. Clause 10.2 requires root cause analysis. An investigation that concludes "the worker slipped on a wet floor" and recommends "post wet floor signs" has not addressed root cause. Root cause analysis is the mechanism by which incidents prevent future incidents — superficial analysis breaks that chain entirely.

Scoping out real risk. Organizations sometimes define their OH&S scope narrowly to exclude high-risk operations, contractors, or worksites. This typically comes back in the audit when the auditor asks about operations the scope doesn't cover that clearly generate OH&S risk. Scope decisions should be defensible, not evasive.


ISO 45001 and the Current Regulatory Environment

ISO 45001 is increasingly referenced in regulatory frameworks and procurement requirements. In the US, while OSHA doesn't mandate ISO 45001 certification, alignment with the standard supports compliance with OSHA's General Duty Clause and specific regulatory standards across construction, manufacturing, and general industry. Federal contractors are seeing ISO 45001 or equivalent requirements appear in solicitations with growing frequency.

Globally, the picture is clearer. The ISO Survey 2023 reports more than 400,000 ISO 45001 certificates issued worldwide, reflecting adoption across 130+ countries. Many EU-based supply chains now require supplier ISO 45001 certification as a condition of contract.

The business case has evolved. A decade ago, organizations pursued ISO 45001 because a customer required it. Increasingly, they pursue it because insurance carriers recognize the certification, because their legal exposure profile changes when they can demonstrate systematic hazard management, and because workers want to work somewhere that takes safety seriously.

ISO 45001 is the single most widely adopted OH&S management system standard in history, and its adoption rate has accelerated in every year since its 2018 publication. That's not a trend worth waiting out.

Explore our ISO 45001 implementation services to learn how Certify Consulting approaches this work, from initial gap assessment through certification day.


Last updated: 2026-07-23

J

Jared Clark

Principal Consultant, Certify Consulting

Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.

Ready to Protect Your People?

Schedule a free consultation to discuss your ISO 45001 certification goals, OSHA compliance needs, and how we can build a safety management system that works for your organization.