A plant manager called me last month with what he thought was a simple question. His facility passes every OSHA inspection with a clean record, so why would he spend real money getting ISO 45001 certified on top of that? Isn't that just paying twice for the same outcome?
It's a fair question, and the honest answer is that OSHA and ISO 45001 aren't graded on the same curve. One is a law. The other is a management system standard. You can be fully compliant with one and still be exposed under the logic of the other, and understanding why is the difference between checking a box and running a safety program that actually holds up when something goes wrong.
The Short Answer
OSHA is a US federal regulatory floor, enforced through inspections and civil penalties under the Occupational Safety and Health Act of 1970. ISO 45001 is a voluntary, internationally recognized management system standard, certified by third-party auditors accredited under ISO/IEC 17021-1. Compliance with OSHA is mandatory for nearly every US employer with employees. Certification to ISO 45001 is optional everywhere, including in the US. Most organizations that pursue it do so because a customer, an insurer, or a foreign operation requires it, or because they want a structured way to manage risk that goes beyond meeting the legal minimum.
Neither one replaces the other, and that's the part people get wrong most often.
ISO 45001 and OSHA Are Not Competing Systems
I've sat across the table from executives who treat this as an either-or decision, as if adopting ISO 45001 somehow satisfies OSHA obligations or makes federal compliance optional. It doesn't work that way. OSHA has never recognized ISO 45001 certification as a substitute for regulatory compliance, and no clause in the standard claims otherwise. What ISO 45001 does is give you a management framework: a documented, auditable system for finding hazards, controlling them, and improving the process over time. OSHA gives you the specific, enforceable rules you have to follow regardless of whether you have that framework in place.
Think of it this way: OSHA tells you what the walls of the building have to be made of. ISO 45001 is the discipline of actually maintaining the building, inspecting it on a schedule, and fixing what you find before it becomes a citation.
What OSHA Actually Requires
The General Duty Clause
OSHA's authority traces back to Section 5(a)(1) of the OSH Act of 1970, codified at 29 U.S.C. ยง 654(a)(1) and known as the General Duty Clause. It requires every covered employer to furnish a workplace "free from recognized hazards that are causing or are likely to cause death or serious physical harm," whether or not a specific OSHA standard addresses that hazard. This is the clause OSHA uses to cite employers for things like heat stress, workplace violence, and other hazards that don't have a dedicated standard on the books. Section 5(a)(2) is the companion requirement: comply with the specific standards OSHA has actually written, found in 29 CFR 1910 (general industry), 1926 (construction), and the other part-specific volumes.
Recordkeeping and Specific Standards
Beyond the General Duty Clause, most employers with more than ten employees in a covered industry have to maintain injury and illness records under 29 CFR Part 1904: the OSHA 300 Log, the 300A annual summary, and the 301 incident report. These aren't optional paperwork. They're the backbone of how OSHA measures your facility's safety performance over time, and they're the first thing a compliance officer asks to see.
Enforcement: Inspections, Citations, and State Plans
OSHA enforcement runs through compliance safety and health officers who conduct inspections, either scheduled, complaint-driven, or triggered by a reportable incident. Citations carry civil penalties that Congress requires OSHA to adjust annually for inflation under the Federal Civil Penalties Inflation Adjustment Act of 2015.
OSHA's most recent adjustment took effect in January 2025, and it's still the current figure heading into 2026 โ a government-shutdown-delayed CPI report pushed back the usual annual update. Under that figure, the maximum penalty for a serious violation is $16,550, and for a willful or repeat violation, $165,514. Confirm both numbers against OSHA's current penalty table before budgeting for exposure, since they move every year.
Section 18 of the OSH Act also lets individual states run their own OSHA-approved enforcement programs, known as State Plans, as long as the state program is at least as effective as the federal one. If you operate in a State Plan state, your day-to-day inspector may work for the state, not federal OSHA, though the underlying obligation is the same.
What ISO 45001 Actually Requires
A Management System Built on Plan-Do-Check-Act
ISO 45001:2018 was published in March 2018 and replaced the older OHSAS 18001:2007. It's built on Annex SL, the high-level structure ISO uses across its management system standards, which is why its clause numbering mirrors ISO 9001:2015 and ISO 14001:2015. That shared structure is deliberate โ it's what lets an organization run integrated audits across quality, environmental, and safety systems instead of three separate programs bolted together.
The standard doesn't hand you a hazard list. It hands you a cycle: understand your context and the needs of workers and other interested parties (clause 4), commit leadership and define roles (clause 5), plan for risks and legal requirements (clause 6), support the system with competence and resources (clause 7), operate and control (clause 8), evaluate performance (clause 9), and improve (clause 10). The output looks different at every facility, because the standard is asking you to build a system suited to your own hazards, not comply with a universal checklist.
Hazard Identification Under Clause 6.1.2
Clause 6.1.2 requires a documented, ongoing process for identifying hazards, arising from routine and non-routine activities, from people other than direct employees, and from changes in the organization itself. This is broader than most single OSHA standards, which tend to be hazard-specific. ISO 45001 asks you to have a repeatable method for finding hazards you haven't thought of yet, not just the ones already named in a regulation. If you want the mechanics of building that process, our hazard identification page walks through the methodologies auditors expect to see.
Worker Participation Under Clause 5.4
Clause 5.4 is one of the standard's most distinctive requirements: consultation and participation of workers, including non-managerial workers, in hazard identification, incident investigation, policy development, and objective-setting. OSHA doesn't have a single unified clause that does this. Worker involvement shows up piecemeal across specific standards, like hazard communication training or emergency action plan requirements, but nothing in the OSH Act mandates the kind of structured, documented worker consultation that ISO 45001 clause 5.4 does. We cover exactly what auditors look for in worker participation in ISO 45001 if you want the detail.
Certification: Voluntary, Third-Party, and Renewable
Nobody is legally required to certify to ISO 45001, and certification isn't self-declared. It's issued by an independent certification body accredited under ISO/IEC 17021-1, following an initial audit, and it runs on a three-year cycle with annual surveillance audits in between. Let your system decay between surveillance visits and you can lose the certificate. That's a meaningfully different consequence than an OSHA citation, which attaches to a specific violation rather than to the health of your whole system.
ISO 45001 vs. OSHA at a Glance
| Dimension | OSHA | ISO 45001 |
|---|---|---|
| Legal status | Federal law, mandatory for covered employers | Voluntary international standard |
| Governing authority | US Department of Labor, under the OSH Act of 1970 | International Organization for Standardization |
| Geographic reach | United States, plus OSHA-approved State Plans (Section 18) | Adopted worldwide; not tied to any one country |
| Core mechanism | Specific standards (29 CFR 1910, 1926) plus the General Duty Clause | Plan-Do-Check-Act management system across clauses 4โ10 |
| Documentation | OSHA 300/300A/301 logs under 29 CFR 1904 | Documented information, risk register, objectives and targets |
| Worker involvement | Varies by standard; not a unified requirement | Explicit clause: 5.4, consultation and participation |
| Enforcement | Compliance officer inspections, civil penalties | Third-party audits under ISO/IEC 17021-1 |
| Consequence of gaps | Citations and fines, adjusted annually for inflation | Nonconformities, corrective action, or loss of certification |
| Renewal | Continuous; the law doesn't expire | Three-year certification cycle, annual surveillance |
Where the Two Systems Overlap
The overlap is real, and it's the reason the two get confused.
- Both care about hazard identification.
- Both expect documented procedures.
- Both want incidents investigated and corrective action tracked.
An organization that's already doing OSHA compliance well, meaning it has real hazard assessments, real training records, and a real incident investigation process, has already built most of the raw material ISO 45001 asks for. The gap is usually structural rather than substantive: OSHA doesn't require you to tie hazard controls back to a documented policy, leadership commitment statement, and set of measurable objectives the way ISO 45001's clauses 5 and 6 do.
Where They Genuinely Diverge
The biggest divergence is scope. OSHA standards are largely prescriptive and hazard-specific: fall protection has its own rule, lockout/tagout has its own rule, respiratory protection has its own rule. ISO 45001 is a system standard. It doesn't tell you the guard height for a machine; it tells you that you need a process to identify machine hazards, assess the risk, and decide on a control, whatever that control turns out to be. The second divergence is jurisdiction. OSHA stops at the US border, with the partial exception of federal contracts and maritime work covered by related statutes. ISO 45001 travels with you to any country your operations reach, which matters enormously if you have a facility overseas or a supply chain that runs through a customer who requires ISO 45001 certification as a condition of doing business.
Do You Need Both?
If You Operate Only in the US
You need OSHA compliance regardless. That's not a choice. Whether you also pursue ISO 45001 certification depends on what your customers, insurers, or corporate parent require, and on whether you want the discipline of a management system layered on top of regulatory compliance. Plenty of well-run US-only manufacturers never certify and are still safe places to work. What certification buys you is a documented, third-party-verified system that survives a change in safety manager, rather than one that lives in someone's head.
If You Operate Internationally or Sell to Multinational Customers
Here the case for ISO 45001 gets much stronger. A single management system that satisfies auditors in Ohio and Ontario and the EU is far more efficient than maintaining separate country-by-country programs. A growing number of multinational buyers now list ISO 45001 as a supplier qualification requirement, the same way ISO 9001 became a de facto entry ticket in manufacturing supply chains two decades ago.
If You're a Small Business
Small employers sometimes assume ISO 45001 is built for enterprises with dedicated EHS departments. It isn't. The standard scales to the size of the organization; clause 4.3 asks you to define the scope of your own system, not adopt someone else's. Our guide on whether ISO 45001 is worth it for a small business walks through that calculus in more detail.
Does ISO 45001 Certification Protect You From OSHA Citations?
No, and this is worth being direct about. Certification is a statement about your management system, not a legal shield. OSHA has never adopted ISO 45001 as a safe-harbor arrangement, and a compliance officer at your door doesn't care what's framed on your lobby wall if a specific standard is being violated. What certification tends to do, in my experience advising clients through both processes, is reduce the odds you end up in that position in the first place, because the clause 6.1.2 hazard identification process and the clause 9 performance evaluation requirements force a level of ongoing self-auditing that catches problems before an inspector does. That's a byproduct of good management, not a legal exemption.
How to Approach Both Without Duplicating Work
The mistake I see most often is treating ISO 45001 implementation as a project separate from the OSHA program that already exists. Don't rebuild from scratch. Map what you already have, your written OSHA programs, your 300 logs, your training records, against the ISO 45001 clause structure and find the gaps rather than starting over. Our implementation guide covers that gap-analysis approach in more depth, and it's the same approach that keeps certification projects from turning into a second, redundant compliance program running parallel to the one you already maintain.
FAQ
Is ISO 45001 required by OSHA?
No. ISO 45001 is a voluntary international standard with no legal force in the United States. OSHA compliance is mandatory under the Occupational Safety and Health Act of 1970 regardless of whether an organization pursues ISO 45001 certification.
Can ISO 45001 certification replace OSHA compliance?
No. Certification addresses the structure of your safety management system; it does not satisfy specific regulatory obligations under 29 CFR 1910, 1926, or any other OSHA standard. The two run in parallel, not in place of each other.
Does having ISO 45001 reduce the chance of an OSHA citation?
There's no guarantee, but a functioning ISO 45001 system, particularly the clause 6.1.2 hazard identification process and the clause 9 performance evaluation requirements, tends to surface problems before an inspector does. That's a management benefit, not a legal protection.
Who enforces OSHA rules if my state has its own plan?
States operating an OSHA-approved State Plan under Section 18 of the OSH Act enforce their own program, provided it is at least as effective as federal OSHA. Your day-to-day inspections may come from a state agency rather than federal OSHA, but the underlying obligations are equivalent.
How long does ISO 45001 certification last?
Certificates run on a three-year cycle, with annual surveillance audits in between to confirm the system is still functioning. A recertification audit is required at the end of the cycle to renew.
If you're weighing whether to pursue certification on top of your existing OSHA program, our OSHA compliance resources are a good place to see how the two fit together in practice, not just in theory.
Last updated: 2026-09-17
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.