Guide 16 min read

ISO 45001 Hazard Identification: JSA, HAZOP, Checklists

J

October 01, 2026

What Is Workplace Hazard Identification?

Workplace hazard identification is the structured process of finding anything at work that could cause injury or ill health, including physical conditions, substances, tasks, work organization, and the behavior of people around the work. In ISO 45001:2018 it is a requirement, not a good habit. Clause 6.1.2.1 says the organization must establish, implement and maintain a process for ongoing and proactive hazard identification.

Two words in that clause do most of the work: "ongoing" and "proactive." A one-time walkthrough before certification does not satisfy either. Neither does a risk register that gets updated only after someone gets hurt.

The standard does not name a single method. It tells you what the process must take into account and leaves the technique up to you. That is where Job Safety Analysis (JSA), HAZOP, and checklists come in, and where many organizations get stuck. They pick one method for everything, usually the one the last consultant or safety manager liked, and then wonder why it misses things.

In my view, the right question is not "which method is best?" It is "which method fits what I am looking at?" A forklift loading task, a chemical reactor, and a quarterly site inspection are three different problems, and each one has a technique that was built for it.


What Does ISO 45001 Clause 6.1.2 Actually Require?

Clause 6.1.2 has three parts, and people searching for it usually want the first:

  • 6.1.2.1 Hazard identification: the process itself, with a list of things it must consider.
  • 6.1.2.2 Assessment of OH&S risks and other risks: evaluating the risks from the hazards you found, while accounting for the effectiveness of existing controls.
  • 6.1.2.3 Assessment of OH&S opportunities and other opportunities: looking for ways to improve OH&S performance, including adapting work to workers and eliminating hazards.

Clause 6.1.2.1 requires the process to take into account, among other things:

  1. How work is organized, including social factors such as workload, working hours, harassment, and bullying, as well as leadership and culture.
  2. Routine and non-routine activities, including the hazards from infrastructure, equipment, materials, and substances, and human factors.
  3. How the work is actually done, as opposed to how the procedure says it is done.
  4. Past relevant incidents, internal or external, and their causes.
  5. Potential emergency situations.
  6. The people involved: workers, contractors, visitors, and others, including people in the vicinity.
  7. Changes or proposed changes to the organization, processes, and the OH&S management system.
  8. Changes in knowledge and information about hazards.

Look at how much of that list no single method covers. A checklist handles known physical hazards well but is poor at workload and bullying. HAZOP is superb on process deviations and says nothing about psychosocial risk. That gap is the reason most mature programs use a combination. For the psychosocial side, our piece on psychological health and safety under ISO 45001 goes deeper.

The phrase "how the work is actually done" deserves a pause. Auditors will ask a worker to show them the task and then compare it to your hazard register. If the register describes the procedure and the worker describes a shortcut, the register is wrong, and the audit finding is deserved.


Which Hazard Identification Method Should You Use?

Here is a side-by-side comparison of the three techniques this guide covers.

Factor JSA / JHA HAZOP Checklist
Best for Specific tasks and job steps Complex processes with flows, pressures, temperatures, or sequences Known hazards in known settings, such as inspections and audits
Level of detail Step by step Node by node, deviation by deviation Item by item
Team size Supervisor plus workers who do the task Multidisciplinary team with a facilitator and scribe One person or a small team
Effort and cost Low to moderate High Low
Finds novel hazards Moderately Strongly Poorly
Typical output Task-hazard-control worksheet Deviation table with causes, consequences, safeguards, actions Pass/fail or yes/no record with findings
Common weakness Written by a supervisor alone at a desk Treated as a one-off design exercise Becomes a tick-box exercise
Relevant references OSHA publication 3071, Job Hazard Analysis IEC 61882:2016; 29 CFR 1910.119(e) lists HAZOP among accepted PHA methods Internal checklists tied to legal requirements and standards

ISO 31010:2019 (risk assessment techniques) catalogs these and many other methods, including what-if analysis, FMEA, and fault tree analysis. It is worth having on the shelf if you want to see where your chosen technique sits among the alternatives.


How Does a Job Safety Analysis (JSA) Work?

A JSA, also called a Job Hazard Analysis (JHA), breaks a task into steps, identifies the hazards in each step, and decides on controls. OSHA's guide, publication 3071, Job Hazard Analysis, describes this approach, and it works in nearly every industry. I have also written a longer treatment of why the job hazard analysis is your most important ISO 45001 tool.

JSA step by step

  1. Pick the job. Start with tasks that have a history of injuries or near misses, tasks with severe potential consequences, new tasks, and tasks that changed recently. You do not need to analyze every job in week one.
  2. Assemble the right people. Include the workers who actually do the task, their supervisor, and anyone who knows the equipment. This is where clause 5.4 on consultation and participation of workers stops being abstract. The people at the bench know the shortcuts.
  3. Watch the work being done. Observe, or walk through it on site. Do not reconstruct it from the written procedure.
  4. Break the job into steps. Aim for roughly 5 to 15 steps. Too few steps hide hazards. Too many turn the document into something nobody reads.
  5. Identify hazards at each step. Ask what could go wrong: struck by, caught in, falls, strains, exposure to substances, energy sources, noise, heat, and the social and organizational factors from clause 6.1.2.1.
  6. Assess the risk. Rate severity and likelihood using the same scale you use elsewhere in the system. A consistent scale matters, and our guide to building an ISO 45001 risk assessment matrix from scratch walks through it.
  7. Define controls using the hierarchy. Clause 8.1.2 requires you to eliminate hazards and reduce risks using the hierarchy: eliminate, substitute, engineering controls and reorganization of work, administrative controls including training, and PPE last.
  8. Review and communicate. Walk the finished JSA back to the people who do the job, train on it, and set a review trigger.

A short worked example

Take the task "change a pallet of product on a conveyor feed line."

Job step Hazard Risk before Control Level of hierarchy
Stop the conveyor Unexpected restart High Lockout/tagout at the isolator Engineering/administrative
Remove empty pallet by hand Back strain, pinch points Medium Pallet jack or lift assist Engineering
Place new pallet Struck by moving forklift High Segregated walkway and marked forklift route Engineering/administrative
Restart and test Person still in the guarded zone High Interlocked guard and two-person visual check Engineering/administrative

Notice that the controls column does not say "be careful." If a control reads like advice, it is not a control yet.

When JSA fails

The most common failure I see is a JSA written by a supervisor alone, at a desk, from memory. It looks tidy and describes a job that does not exist. The second most common is a JSA that sits in a binder while the work changes around it. Tie JSA review to your management of change process under clause 8.1.3, so a new machine, material, or crew triggers a refresh. Our article on management of change in ISO 45001 explains how.


How Does HAZOP Work?

HAZOP (Hazard and Operability study) is a structured team examination of a process design or operation. The team takes each part of the process, called a node, and applies guide words to process parameters to find deviations from the design intent. IEC 61882:2016 is the international application guide for it.

HAZOP began in the chemical and process industries, and it is still most at home there: reactors, pipework, tank farms, pressure systems, batch processes. In the United States, 29 CFR 1910.119(e)(3) requires a process hazard analysis for covered processes to address hazards of the process, previous incidents, engineering and administrative controls, and human factors, among other things. Paragraph (e)(2) names HAZOP as one of the acceptable methods, along with what-if, checklist, what-if/checklist, FMEA, and fault tree analysis. Paragraph (e)(6) requires the analysis to be updated and revalidated at least every five years.

The standard guide words

Guide word Meaning Example on a feed line
No / Not Complete negation of intent No flow
More Quantitative increase More pressure, more temperature
Less Quantitative decrease Less flow, less level
As well as Something extra happens Contamination in the stream
Part of Only part of the intent is achieved Wrong composition
Reverse Opposite of the intent Reverse flow
Other than Something completely different happens Wrong material, wrong operating mode

HAZOP step by step

  1. Define scope and objectives. Which process, which operating modes, and which consequences count (safety, health, environment)?
  2. Assemble the team. A trained facilitator, a scribe, a process engineer, an operations person who runs the plant, maintenance, and someone with instrumentation or control knowledge.
  3. Divide the process into nodes. Use piping and instrumentation diagrams. A node is a section with a clear design intent.
  4. State the design intent for each node: what it should do, at what flow, pressure, and temperature.
  5. Apply guide words to parameters and list credible deviations.
  6. For each deviation, record the causes, consequences, existing safeguards, and recommended actions.
  7. Assign actions with owners and dates. A HAZOP report with unowned actions is a very expensive document.
  8. Track closure and revisit. Feed the results back into your risk register, operational controls, and emergency preparedness planning under clause 8.2.

Where HAZOP fits in ISO 45001

HAZOP is not required by ISO 45001, but it is a legitimate and strong way to meet clause 6.1.2.1 for process hazards and for the "changes" consideration when you modify a process. I think it is the technique most often under-used outside the chemical sector. Oil and gas, food manufacturing with ammonia refrigeration, and even some renewable energy installations have process-type risks where a node-by-node review pays off. For sector context, see our pages on ISO 45001 in oil and gas operations.

HAZOP is also overkill for many tasks. Running a full HAZOP on a hand-assembly workstation wastes everyone's time and teaches people to hate hazard identification.


How Do Checklists Fit In?

A checklist is a list of known hazards, conditions, or requirements against which a place, piece of equipment, or activity is checked. It is the lightest tool of the three, and also the one most easily abused.

Checklists are good for:

  • Routine workplace inspections (housekeeping, walkways, guarding, extinguishers, emergency exits)
  • Pre-use equipment checks
  • Contractor and visitor induction checks
  • Legal compliance verification against a specific regulation
  • Audit preparation

They are weak at finding what nobody thought to put on the list. A checklist reflects the knowledge of the person who wrote it, which is useful and limiting in equal measure.

Making a checklist useful

  1. Build it from real hazards. Start from your JSA results, incident history, and legal requirements, not from a generic template.
  2. Be specific. "Machine guarding adequate?" invites a lazy yes. "Fixed guard in place on drive belt of Line 3 and secured with tool-only fasteners?" does not.
  3. Leave room for the unlisted. Add an "other hazards observed" field and mean it.
  4. Record findings and close them. A checklist that identifies a hazard and never leads to an action is documentation of negligence.
  5. Review the checklist itself whenever you see an incident the checklist did not catch. That is the process learning.

Checklists also produce documented information that auditors like. If you are unsure what you must retain, our ISO 45001 required documents complete list covers it.


How Do You Combine the Methods?

Most organizations land on layers. A practical combination looks like this:

Layer Purpose Method Frequency or trigger
Site-wide baseline Identify hazards across all activities, areas, and people types Workshop with walkthrough, using clause 6.1.2.1 as the prompt list Annually and when scope changes
Task level Analyze specific jobs JSA/JHA New task, incident, change, or scheduled review
Process level Analyze complex process deviations HAZOP or similar PHA Design stage, major change, and the legal revalidation cycle where applicable
Routine verification Catch conditions in daily and weekly work Checklists Daily, weekly, monthly, depending on risk
Worker reports Capture hazards seen in the moment Hazard and near-miss reporting Continuous

The last row is easy to forget. Clause 6.1.2.1 requires the process to be ongoing, and worker reporting is the one source that runs every hour of every shift. Clause 5.4 requires processes for worker consultation and participation, including involving non-managerial workers in hazard identification. Our article on what clause 5.4 requires for worker participation shows what auditors look for.


What Does Continual Improvement Signify in ISO 45001?

This question comes up often in connection with hazard identification, so I will answer it directly. In ISO 45001, continual improvement (clause 10.3) means the organization keeps improving the suitability, adequacy, and effectiveness of the OH&S management system, promotes a culture that supports it, and involves workers in the improvement actions. It is a recurring activity that feeds from audits, management review, incident investigation, and monitoring results, not a single project that finishes.

For hazard identification the connection is practical. Each method above should generate learning:

  • A JSA review after a near miss reveals a step nobody saw.
  • A HAZOP action list closes out, and the next revalidation finds fewer open items.
  • A checklist gets revised because an incident exposed a gap.
  • Hazard reports per worker go up as trust improves, which is often a good sign rather than a bad one.

If hazard identification looks identical year after year, either nothing changed, which is rare, or nobody is looking hard.


What Do Auditors Look for in Hazard Identification?

An auditor verifying clause 6.1.2 will usually do the following:

  1. Ask to see the hazard identification process and check it covers each consideration in 6.1.2.1.
  2. Pick a task at random, watch it, and compare what they see to your documented hazards and controls.
  3. Interview workers to see whether they took part and whether they know the hazards of their own job.
  4. Check how contractors, visitors, and non-routine activities are handled.
  5. Look for evidence the process was updated after an incident, a change, or new information.
  6. Confirm the risk assessment results feed into objectives (clause 6.2), operational controls (clause 8.1), and competence needs (clause 7.2).

Documentation is where small organizations tend to trip. You are not required to produce a particular format. You do need to retain evidence that the process operates. For a full documentation view, see our ISO 45001 documentation requirements checklist.


Hazard Identification Rollout Checklist

Use this to check where you stand:

  • [ ] A documented process describes how hazards are identified, who is involved, and when it is repeated
  • [ ] The process explicitly covers every consideration in clause 6.1.2.1, including work organization and psychosocial factors
  • [ ] Routine and non-routine activities, and all types of people, are in scope
  • [ ] JSAs exist for high-risk and recently changed tasks, built with the people who do them
  • [ ] HAZOP or another recognized process hazard analysis covers complex processes, with actions tracked to closure
  • [ ] Checklists derive from real hazards, legal requirements, and incident history
  • [ ] Workers have a simple, safe way to report hazards, and they get feedback
  • [ ] Management of change triggers a review of hazard identification
  • [ ] Results feed into risk assessment, objectives, controls, and training
  • [ ] Management review looks at hazard identification effectiveness, and improvements are recorded

For a broader view of how this fits the rollout of the whole system, the ISO 45001 implementation complete guide is the place to go next.


Frequently Asked Questions

What is the difference between JSA and HAZOP?

JSA analyzes a task by breaking it into steps and finding the hazards workers face at each step. HAZOP analyzes a process by applying guide words such as "more" or "reverse" to parameters like flow and pressure to find design or operating deviations. JSA fits tasks and people. HAZOP fits process systems and equipment.

Does ISO 45001 require a specific hazard identification method?

No. Clause 6.1.2.1 requires an ongoing and proactive process and lists what it must take into account, but it does not name a technique. You can choose JSA, HAZOP, checklists, what-if analysis, or others, as long as the process covers the required considerations and you can show it works.

How often should hazard identification be repeated?

ISO 45001 sets no fixed interval because the process must be ongoing. In practice, review whenever something changes (new equipment, materials, processes, or incidents) and on a scheduled cycle. In the United States, 29 CFR 1910.119(e)(6) requires covered process hazard analyses to be revalidated at least every five years.

Are checklists enough for ISO 45001 compliance?

Usually not by themselves. Checklists verify known hazards and conditions, but clause 6.1.2.1 also expects you to consider things like work organization, non-routine activities, and change. Checklists work best as one layer alongside JSA and, where relevant, process hazard analysis.

Who should take part in hazard identification?

The people who do the work, their supervisors, and people with technical knowledge of the equipment or process. Clause 5.4 requires the participation of non-managerial workers in hazard identification, and auditors commonly interview workers to confirm it happened.


Last updated: 2026-10-01

Jared Clark, JD, MBA, PMP, CMQ-OE, CQA, CPGP, RAC, is Principal Consultant at Certify Consulting. For help building or auditing a hazard identification process, visit certify.consulting.

J

Jared Clark

Principal Consultant, Certify Consulting

Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.

Ready to Protect Your People?

Schedule a free consultation to discuss your ISO 45001 certification goals, OSHA compliance needs, and how we can build a safety management system that works for your organization.