ISO 45001:2018 is the international standard published by ISO that establishes requirements for an occupational health and safety management system (OH&S MS), with the objective of preventing work-related injuries and ill health and providing safe and healthy workplaces. Applicable to any organization regardless of size, sector or geographical location, the standard follows the High Level Structure (HLS/Annex SL) and replaces OHSAS 18001:2007.
ISO 45001:2018 is the first international consensus standard for occupational health and safety management systems (OH&S MS), published by the International Organization for Standardization (ISO) in March 2018. The standard provides a systematic framework for organizations of any size, sector or geographical location to identify hazards, assess risks and implement controls that prevent work-related injuries, occupational diseases and fatalities.
ISO 45001 applies to any organization that wishes to establish, implement and maintain an OH&S MS. There is no minimum size, sector or activity type requirement: from a manufacturing SME with 50 workers to a multinational energy corporation with thousands of employees across multiple countries, the standard is applicable and scalable.
The standard was developed to fill a critical gap: until 2018, the primary international reference for OH&S management was OHSAS 18001:2007, a British specification (not an ISO standard) published by BSI. OHSAS 18001 did not follow the High Level Structure (HLS) common to other ISO management system standards, which made integration with ISO 9001 (quality) and ISO 14001 (environment) difficult. ISO 45001 resolved this by adopting the Annex SL, enabling native integration between standards. The transition period from OHSAS 18001 to ISO 45001 ended in March 2021.
ISO 45001 does not replace national occupational health and safety legislation in any jurisdiction. Instead, it complements and systematises compliance with legal obligations. Organizations must still comply with all applicable national and local OHS regulations. The standard provides a structured management system approach that helps organizations meet those legal requirements more effectively, while also addressing risks and opportunities beyond minimum legal compliance.
ISO 45001 transforms safety management from reactive to proactive. The system requires continuous hazard identification, risk assessment with a hierarchy of controls and monitoring through leading indicators. For the OHS professional, this means operating with documented evidence that demonstrates legal compliance, facilitates audits and supports data-driven decisions.
ISO 45001 certification reduces costs by systematizing accident prevention (absences, replacement, compensation, insurance premiums). The standard is increasingly required in supply chains, tendering processes and ESG frameworks, making it a market requirement beyond an operational choice.
The standard provides a documented due diligence framework. Clause 6.1.3 requires identification of legal requirements and clause 9.1.2 mandates periodic compliance evaluation. This creates an auditable record that demonstrates reasonable diligence, strengthening the defence in legal and regulatory proceedings.
ISO 45001:2018 follows the High Level Structure (HLS) of the ISO Annex SL, sharing the same 10-clause structure with other management system standards (ISO 9001, ISO 14001). This common architecture facilitates integration between systems. Clauses 1 to 3 are informative (scope, normative references and terms/definitions). Clauses 4 to 10 contain the auditable requirements of the management system.
The standard operates on the PDCA (Plan-Do-Check-Act) cycle, with leadership and worker participation as the central axis that permeates all phases:

This section details each auditable clause (4 to 10) with its sub-requirements, typical conformity evidence and implementation tips.
Clause 4 establishes the foundation of the OH&S MS by requiring the organization to understand its context, identify relevant interested parties and define the scope of the system.
Clause 5 is the central axis of the standard. It differentiates ISO 45001 from OHSAS 18001 by requiring active worker participation (not just consultation) and assigning direct accountability to top management. Leadership must demonstrate visible commitment, not merely delegate to the OHS department.
Clause 6 requires the organization to plan actions to address risks and opportunities, establish measurable OH&S objectives and define how to achieve them. It includes the systematic identification of hazards, assessment of OH&S risks and identification of applicable legal requirements.
Clause 7 addresses the resources needed for the OH&S MS to function. It covers competence, awareness, communication and documented information. It defines how the organization ensures the right people have the right skills, receive the right information and that everything is properly documented.
Clause 8 addresses the implementation of planned controls. It includes the hierarchy of controls, management of change, procurement management and emergency preparedness. This is where planning translates into daily operational action.
Clause 9 requires monitoring, measurement, analysis and evaluation of OH&S performance. It includes internal audits and management review. This is the check phase of PDCA, where the organization determines whether the system is functioning as planned.
Clause 10 addresses non-conformities, corrective actions, incident investigation and continual improvement. It requires the organization to react to deviations, investigate root causes and implement actions that prevent recurrence.
ISO 45001 does not prescribe a mandatory manual, but requires that certain information is documented, maintained and retained. The table below consolidates all documented information requirements of the standard, distinguishing between documents to be maintained (procedures, policies) and records to be retained (evidence).
Note: in addition to the mandatory documents above, the organization may maintain additional documentation as needed for the effectiveness of the OH&S MS.
Implementation of an OH&S MS conforming to ISO 45001 typically occurs in six phases. The total timeframe varies according to the prior maturity of the organization but generally ranges between 8 and 18 months for medium-sized organizations.

ISO 45001 certification is granted by accredited certification bodies (accredited by national accreditation bodies that are members of the IAF — International Accreditation Forum). The process follows a standardised model in two audit stages, preceded by the selection of the certification body.
1. Selection of the certification body — choose an accredited body, preferably with experience in the organization's sector. Request proposals from at least two bodies for comparison.
2. Stage 1 audit (documentary) — the auditor analyzes the OH&S MS documentation, verifies the scope, evaluates the organization's readiness and identifies areas of attention for Stage 2. May be conducted remotely.
3. Resolution of Stage 1 findings — the organization corrects any documentary gaps identified before proceeding.
4. Stage 2 audit (implementation) — full on-site audit that evaluates the effective implementation of the system. The auditor interviews workers, observes activities and verifies records.
5. Analysis of non-conformities — if major or minor non-conformities are identified, the organization submits corrective action plans within the defined timeframe (typically 90 days for major).
6. Certification decision — the certification body's technical committee analyzes the auditor's report and decides on certificate issuance.
7. Surveillance audits — conducted annually, covering part of the system each cycle, to verify maintenance of conformity.
8. Recertification audit — every 3 years, a full audit for certificate renewal.
The cost of certification varies significantly according to factors such as number of workers, number of sites, process complexity, risk level of activities, maturity of the pre-existing system and geographical location. The main cost components include:
Organizations should request detailed quotations from accredited bodies to obtain estimates appropriate to their circumstances. The IAF publishes document MD 5 with guidelines for calculating audit days based on the number of workers and risk level.
Based on reports from certification bodies and specialist audit literature for OH&S MS, the following non-conformities are recurrently identified in ISO 45001 certification and surveillance audits:
Source: compilation based on public reports from certification bodies (BSI, Bureau Veritas, DNV) and OH&S MS audit analyses published in safety management journals.
The table below highlights the most significant structural differences between OHSAS 18001:2007 (discontinued) and ISO 45001:2018. The transition ended in March 2021.
The main advantage of the High Level Structure is enabling an Integrated Management System (IMS) with shared processes. The most significant areas of overlap include:
Organizations that already hold ISO 9001 or ISO 14001 certification can leverage existing common processes (document control, internal audit, management review), significantly reducing the implementation effort for ISO 45001. The specific OH&S scope (hazard identification, hierarchy of controls, worker participation, emergency preparedness) remains exclusive to ISO 45001.
ISO 45001 is applicable to any sector, but implementation challenges vary according to the risk profile and operational complexity. The table below summarises the most relevant particularities by sector:
Digitalization of OH&S processes enables organizations to maintain ISO 45001 compliance more efficiently, reducing administrative burden and increasing the reliability of evidence. The main areas where technology adds value to the OH&S MS include:
Adoption of EHSQ software enables integration of multiple ISO 45001 requirements in a single platform, eliminating information silos and providing real-time visibility of the management system compliance status.
.webp)
ISO 45001:2018 is the international standard that establishes requirements for an occupational health and safety management system (OH&S MS). Published by ISO in March 2018, it applies to any organization regardless of size or sector, with the objective of preventing work-related injuries and ill health.
ISO 45001 is an international standard (ISO) whilst OHSAS 18001 was a British specification (BSI). The main differences include: HLS structure enabling integration with ISO 9001/14001; the organizational context requirement; leadership as non-transferable responsibility of top management; active participation (not just consultation) of workers; and management of change as an explicit requirement. OHSAS 18001 was discontinued in March 2021.
No. Certification is voluntary. However, it may be required contractually by clients, in public tendering processes, by supply chain requirements or by ESG frameworks. Implementation of the management system (without formal certification) is also a valid option.
The typical timeframe ranges between 8 and 18 months for medium-sized organizations. Influencing factors include: existence of a prior management system (ISO 9001 or 14001 significantly reduces the timeframe), maturity of the safety culture, number of sites and process complexity.
No. ISO 45001 is a voluntary management system standard; national occupational health and safety legislation comprises mandatory legal obligations. ISO 45001 complements and systematises compliance with national OHS laws and regulations. Organisations must continue to meet all applicable legal requirements in their jurisdiction. The standard provides a framework that helps structure and evidence legal compliance, but does not supersede any statutory obligation.
The High Level Structure (also called Annex SL or Harmonized Structure) is the standardized 10-clause model that ISO uses for all management system standards. It ensures that ISO 45001, ISO 9001, ISO 14001 and others share the same structure, common terms and definitions, facilitating integration into an Integrated Management System (IMS).
The main benefits include: structured framework for prevention of work-related injuries and ill health; demonstration of due diligence and reasonable care; systematised legal compliance; competitive advantage in tenders and supply chains; improvement of safety culture; and integration with other management systems (quality and environment).
The audit occurs in two stages: Stage 1 (documentary), where the auditor analyzes the documentation and system readiness; and Stage 2 (implementation), an on-site audit that evaluates the effective operation of the OH&S MS through interviews, observations and record verification. The certificate has a 3-year validity with annual surveillance audits.
The most frequent non-conformities include: insufficient worker participation (5.4); incomplete hazard identification, especially in occupational health and psychosocial risks (6.1.2); outdated legal compliance evaluation (9.1.2); absent or incomplete management of change (8.1.3); and incident investigation focused on individual blame without systemic analysis (10.2).
EHSQ software digitises key OH&S MS processes: digital checklists for hazard identification with real-time evidence; dynamic risk matrices; automated documented information control; training platforms with competence validation; inspection forms with automatic escalation; and integrated incident management systems with full corrective action cycle traceability.
Request your demo
Start your EHSQ Connected Worker journey with Glartek and become a leader in your industry.
Schedule Demo.webp)
Discover the power of the only AI-Native EHSQ solution built for the frontline