ISO 45001:2018: complete guide to implementation, certification and compliance

ISO 45001:2018 is the international standard published by ISO that establishes requirements for an occupational health and safety management system (OH&S MS), with the objective of preventing work-related injuries and ill health and providing safe and healthy workplaces. Applicable to any organization regardless of size, sector or geographical location, the standard follows the High Level Structure (HLS/Annex SL) and replaces OHSAS 18001:2007.

Knowledge Base

What is ISO 45001:2018?

ISO 45001:2018 is the first international consensus standard for occupational health and safety management systems (OH&S MS), published by the International Organization for Standardization (ISO) in March 2018. The standard provides a systematic framework for organizations of any size, sector or geographical location to identify hazards, assess risks and implement controls that prevent work-related injuries, occupational diseases and fatalities.

ISO 45001 applies to any organization that wishes to establish, implement and maintain an OH&S MS. There is no minimum size, sector or activity type requirement: from a manufacturing SME with 50 workers to a multinational energy corporation with thousands of employees across multiple countries, the standard is applicable and scalable.

The standard was developed to fill a critical gap: until 2018, the primary international reference for OH&S management was OHSAS 18001:2007, a British specification (not an ISO standard) published by BSI. OHSAS 18001 did not follow the High Level Structure (HLS) common to other ISO management system standards, which made integration with ISO 9001 (quality) and ISO 14001 (environment) difficult. ISO 45001 resolved this by adopting the Annex SL, enabling native integration between standards. The transition period from OHSAS 18001 to ISO 45001 ended in March 2021.

ISO 45001 does not replace national occupational health and safety legislation in any jurisdiction. Instead, it complements and systematises compliance with legal obligations. Organizations must still comply with all applicable national and local OHS regulations. The standard provides a structured management system approach that helps organizations meet those legal requirements more effectively, while also addressing risks and opportunities beyond minimum legal compliance.

Why is ISO 45001 important?

For the OHS / EHS manager

ISO 45001 transforms safety management from reactive to proactive. The system requires continuous hazard identification, risk assessment with a hierarchy of controls and monitoring through leading indicators. For the OHS professional, this means operating with documented evidence that demonstrates legal compliance, facilitates audits and supports data-driven decisions.

For the C-level and CFO

ISO 45001 certification reduces costs by systematizing accident prevention (absences, replacement, compensation, insurance premiums). The standard is increasingly required in supply chains, tendering processes and ESG frameworks, making it a market requirement beyond an operational choice.

For compliance and legal

The standard provides a documented due diligence framework. Clause 6.1.3 requires identification of legal requirements and clause 9.1.2 mandates periodic compliance evaluation. This creates an auditable record that demonstrates reasonable diligence, strengthening the defence in legal and regulatory proceedings.

Structure of the standard: clause map

ISO 45001:2018 follows the High Level Structure (HLS) of the ISO Annex SL, sharing the same 10-clause structure with other management system standards (ISO 9001, ISO 14001). This common architecture facilitates integration between systems. Clauses 1 to 3 are informative (scope, normative references and terms/definitions). Clauses 4 to 10 contain the auditable requirements of the management system.

The standard operates on the PDCA (Plan-Do-Check-Act) cycle, with leadership and worker participation as the central axis that permeates all phases:

Clause Title PDCA phase Main purpose
4 Context of the organisation Plan Determine internal/external issues, interested parties and OH&S MS scope
5 Leadership and worker participation Central axis Ensure top management commitment and active worker consultation
6 Planning Plan Identify hazards, assess risks/opportunities and define OH&S objectives
7 Support Plan/Do Provide resources, competence, communication and documented information
8 Operation Do Implement operational controls, management of change and emergency preparedness
9 Performance evaluation Check Monitor, measure, conduct internal audits and management review
10 Improvement Act Address non-conformities, incidents and promote continual improvement

Practical guide: clause by clause

This section details each auditable clause (4 to 10) with its sub-requirements, typical conformity evidence and implementation tips.

Clause 4: context of the organization

Clause 4 establishes the foundation of the OH&S MS by requiring the organization to understand its context, identify relevant interested parties and define the scope of the system.

Sub-clause Requirement Typical evidence
4.1 Understanding the organisation and its context Documented OH&S SWOT/PESTEL analysis; context analysis meeting minutes
4.2 Understanding the needs and expectations of workers and other interested parties Interested parties matrix with mapped needs and influences
4.3 Determining the scope of the OH&S MS Documented scope statement with boundaries and applicability
4.4 OH&S management system OH&S MS manual or equivalent describing processes and interactions

Clause 5: leadership and worker participation

Clause 5 is the central axis of the standard. It differentiates ISO 45001 from OHSAS 18001 by requiring active worker participation (not just consultation) and assigning direct accountability to top management. Leadership must demonstrate visible commitment, not merely delegate to the OHS department.

Sub-clause Requirement Typical evidence
5.1 Leadership and commitment Management review minutes; documented resource allocation; management participation in inspections
5.2 OH&S policy Documented policy, communicated and available to interested parties
5.3 Organisational roles, responsibilities and authorities OH&S organisational chart; role descriptions with OH&S responsibilities
5.4 Consultation and participation of workers Safety committee records; reporting mechanisms; evidence of participation in risk assessments

Clause 6: planning

Clause 6 requires the organization to plan actions to address risks and opportunities, establish measurable OH&S objectives and define how to achieve them. It includes the systematic identification of hazards, assessment of OH&S risks and identification of applicable legal requirements.

Sub-clause Requirement Typical evidence
6.1.1 General Documented OH&S risk and opportunity management procedure
6.1.2 Hazard identification and assessment of risks Hazard inventory; risk matrices; assessment records by activity/process
6.1.3 Determination of legal requirements and other requirements Register of applicable legislation; compliance evaluations
6.1.4 Planning action Action plans with responsible persons, deadlines and resources to address risks and opportunities
6.2 OH&S objectives and planning to achieve them Documented SMART objectives; management programmes with indicators and targets

Clause 7: support

Clause 7 addresses the resources needed for the OH&S MS to function. It covers competence, awareness, communication and documented information. It defines how the organization ensures the right people have the right skills, receive the right information and that everything is properly documented.

Sub-clause Requirement Typical evidence
7.1 Resources OH&S budget; personnel allocation; safety infrastructure
7.2 Competence Competence matrix; training records; technical certifications
7.3 Awareness Induction records; safety campaigns; documented toolbox talks
7.4 Communication Communication plan; defined channels; internal and external communication records
7.5 Documented information Document control procedure; master list; revision history

Clause 8: operation

Clause 8 addresses the implementation of planned controls. It includes the hierarchy of controls, management of change, procurement management and emergency preparedness. This is where planning translates into daily operational action.

Sub-clause Requirement Typical evidence
8.1.1 General Standard operating procedures (SOPs) incorporating OH&S controls
8.1.2 Eliminating hazards and reducing OH&S risks Documented application of the hierarchy of controls (elimination > substitution > engineering > administrative > PPE)
8.1.3 Management of change MOC procedure; records of OH&S impact analysis for changes
8.1.4 Procurement (including contractors) OH&S criteria in contracts; supplier evaluation; contractor management
8.2 Emergency preparedness and response Emergency plans; documented drills; post-drill analysis

Clause 9: performance evaluation

Clause 9 requires monitoring, measurement, analysis and evaluation of OH&S performance. It includes internal audits and management review. This is the check phase of PDCA, where the organization determines whether the system is functioning as planned.

Sub-clause Requirement Typical evidence
9.1.1 Monitoring, measurement, analysis and performance evaluation Defined leading/lagging indicators; dashboards; periodic reports
9.1.2 Evaluation of compliance Periodic evaluation records; action plans for identified gaps
9.2 Internal audit Audit programme; audit reports; internal auditor qualifications
9.3 Management review Minutes with inputs defined by the standard; outputs with decisions and actions

Clause 10: improvement

Clause 10 addresses non-conformities, corrective actions, incident investigation and continual improvement. It requires the organization to react to deviations, investigate root causes and implement actions that prevent recurrence.

Sub-clause Requirement Typical evidence
10.1 General Evidence of continual improvement (positive trends, benchmarking)
10.2 Incident, non-conformity and corrective action Investigation records; root cause analysis; corrective action plans with effectiveness verification
10.3 Continual improvement Improvement projects; benchmarking results; control innovations

Documentation requirements

ISO 45001 does not prescribe a mandatory manual, but requires that certain information is documented, maintained and retained. The table below consolidates all documented information requirements of the standard, distinguishing between documents to be maintained (procedures, policies) and records to be retained (evidence).

Clause Document/Record Type Mandatory?
4.3 Scope of the OH&S MS Maintained Yes
5.2 OH&S policy Maintained Yes
5.3 Roles and responsibilities Maintained Yes
6.1.1 Risks and opportunities + planned actions Maintained Yes
6.1.2 Methodology and criteria for risk assessment Maintained Yes
6.1.2 Results of hazard identification and risk assessment Retained Yes
6.1.3 Legal requirements and other requirements Maintained Yes
6.2 OH&S objectives and plans to achieve them Maintained Yes
7.2 Evidence of competence Retained Yes
7.4 Evidence of communication Retained Yes
8.1 Operational control processes and plans Maintained Yes
8.2 Emergency response plans Maintained Yes
9.1.1 Monitoring and measurement results Retained Yes
9.1.2 Compliance evaluation results Retained Yes
9.2 Internal audit programme and results Retained Yes
9.3 Management review results Retained Yes
10.2 Nature of incidents/NCs and actions taken Retained Yes
10.2 Corrective action results and their effectiveness Retained Yes

Note: in addition to the mandatory documents above, the organization may maintain additional documentation as needed for the effectiveness of the OH&S MS.

Implementation roadmap

Implementation of an OH&S MS conforming to ISO 45001 typically occurs in six phases. The total timeframe varies according to the prior maturity of the organization but generally ranges between 8 and 18 months for medium-sized organizations.

Phase Description Typical duration Key deliverables
1. Initial diagnosis Gap analysis against all standard requirements 4-6 weeks Gap report; project plan
2. Planning Definition of scope, policy, objectives and document structure 4-8 weeks OH&S policy; scope; implementation schedule
3. Process implementation Creation/revision of procedures, training and operational controls 3-6 months SOPs; risk matrices; emergency plans; training records
4. Operation and records System operation with generation of evidence and records 3-6 months Inspection records; incident reports; indicator monitoring
5. Internal verification Complete internal audit and management review 4-6 weeks Audit report; management review minutes; corrective actions
6. Certification Stage 1 audit (documentary) and Stage 2 (implementation) 4-8 weeks ISO 45001 certificate (3-year validity with annual surveillance audits)

Factors that accelerate implementation

  • Pre-existing management system (ISO 9001 or ISO 14001) with HLS already implemented
  • Visible top management commitment with dedicated resource allocation
  • Mature safety culture with active worker participation
  • Use of OH&S management software that automates workflows and evidence
  • Specialist consultancy to accelerate interpretation of requirements
  • Internal team with prior experience in management system audits

Factors that delay implementation

  • Lack of leadership commitment, treating the project as the sole responsibility of OHS
  • Cultural resistance to documentation and formalisation of processes
  • Multiple sites with heterogeneous processes requiring harmonisation
  • High staff turnover, compromising competence retention
  • Complex or rapidly changing legal requirements that complicate clause 6.1.3
  • Attempting to implement without an initial gap analysis, generating rework

Certification process

ISO 45001 certification is granted by accredited certification bodies (accredited by national accreditation bodies that are members of the IAF — International Accreditation Forum). The process follows a standardised model in two audit stages, preceded by the selection of the certification body.

Process stages

1. Selection of the certification body — choose an accredited body, preferably with experience in the organization's sector. Request proposals from at least two bodies for comparison.

2. Stage 1 audit (documentary) — the auditor analyzes the OH&S MS documentation, verifies the scope, evaluates the organization's readiness and identifies areas of attention for Stage 2. May be conducted remotely.

3. Resolution of Stage 1 findings — the organization corrects any documentary gaps identified before proceeding.

4. Stage 2 audit (implementation) — full on-site audit that evaluates the effective implementation of the system. The auditor interviews workers, observes activities and verifies records.

5. Analysis of non-conformities — if major or minor non-conformities are identified, the organization submits corrective action plans within the defined timeframe (typically 90 days for major).

6. Certification decision — the certification body's technical committee analyzes the auditor's report and decides on certificate issuance.

7. Surveillance audits — conducted annually, covering part of the system each cycle, to verify maintenance of conformity.

8. Recertification audit — every 3 years, a full audit for certificate renewal.

Factors that influence the investment

The cost of certification varies significantly according to factors such as number of workers, number of sites, process complexity, risk level of activities, maturity of the pre-existing system and geographical location. The main cost components include:

  • Implementation consultancy (optional, but recommended for organizations without prior experience)
  • Training and internal capacity building (internal auditors, OH&S managers)
  • Infrastructure and engineering control adaptations
  • Certification body fees (calculated based on audit days)
  • Annual maintenance (surveillance audits + continual improvements)

Organizations should request detailed quotations from accredited bodies to obtain estimates appropriate to their circumstances. The IAF publishes document MD 5 with guidelines for calculating audit days based on the number of workers and risk level.

Most common non-conformities in audits

Based on reports from certification bodies and specialist audit literature for OH&S MS, the following non-conformities are recurrently identified in ISO 45001 certification and surveillance audits:

# Non-conformity Clause Impact
1 Worker participation limited to formal consultation without effective contribution mechanisms 5.4 Major
2 Incomplete hazard identification (focus only on safety risks, neglecting occupational health and psychosocial factors) 6.1.2 Major
3 Legal compliance evaluation not updated or without defined periodicity 6.1.3 / 9.1.2 Major
4 OH&S objectives not measurable or without action plans with responsible persons and deadlines 6.2 Minor
5 OH&S competencies not defined for critical roles or without evidence of assessment 7.2 Minor
6 Management of change absent or applied only to physical changes (without including organisational changes) 8.1.3 Major
7 Controls for contractors and suppliers insufficient or limited to contractual requirements without verification 8.1.4 Minor
8 Emergency drills without post-drill critical analysis and without incorporation of lessons learnt 8.2 Minor
9 Performance indicators exclusively reactive (lagging), without proactive indicators (leading) 9.1.1 Minor
10 Incident investigation focused on individual blame without systemic cause analysis 10.2 Major
11 Management review without all inputs required by the standard or without documented outputs 9.3 Minor
12 Corrective actions without effectiveness verification or with only documentary verification 10.2 Minor

Source: compilation based on public reports from certification bodies (BSI, Bureau Veritas, DNV) and OH&S MS audit analyses published in safety management journals.

Comparison with related standards

OHSAS 18001 vs. ISO 45001

The table below highlights the most significant structural differences between OHSAS 18001:2007 (discontinued) and ISO 45001:2018. The transition ended in March 2021.

Aspect OHSAS 18001:2007 ISO 45001:2018
Nature British specification (BSI) International standard (ISO)
Structure Proprietary (4 main clauses) High Level Structure / Annex SL (10 clauses)
Organisational context Not required Clause 4 — mandatory context and interested parties analysis
Leadership Responsibility delegable to management representative Non-transferable responsibility of top management (5.1)
Worker participation Consultation Consultation AND active participation (5.4)
Risk approach Focus on OH&S hazards and risks Risks and opportunities of the management system (6.1.1) + OH&S risks (6.1.2)
Management of change Implicit Explicit requirement (8.1.3)
Contractors and suppliers Basic requirements Expanded control of outsourcing, procurement and contractors (8.1.4)
Integration with other standards Difficult (incompatible structure) Native (same HLS as ISO 9001 and ISO 14001)
Continual improvement Generic Structured with specific requirements (10.3)

Integration with ISO 9001 and ISO 14001

The main advantage of the High Level Structure is enabling an Integrated Management System (IMS) with shared processes. The most significant areas of overlap include:

Process ISO 45001 ISO 9001 ISO 14001
Context and interested parties Clause 4 Clause 4 Clause 4
System policy 5.2 5.2 5.2
Risk assessment 6.1 6.1 6.1
Competence and awareness 7.2 / 7.3 7.2 / 7.3 7.2 / 7.3
Documented information control 7.5 7.5 7.5
Internal audit 9.2 9.2 9.2
Management review 9.3 9.3 9.3
Non-conformity and corrective action 10.2 10.2 10.2

Organizations that already hold ISO 9001 or ISO 14001 certification can leverage existing common processes (document control, internal audit, management review), significantly reducing the implementation effort for ISO 45001. The specific OH&S scope (hazard identification, hierarchy of controls, worker participation, emergency preparedness) remains exclusive to ISO 45001.

Examples by industry sector

ISO 45001 is applicable to any sector, but implementation challenges vary according to the risk profile and operational complexity. The table below summarises the most relevant particularities by sector:

Sector Priority hazards Implementation challenges Differentiated controls
Construction Falls, collapse, electricity, heavy machinery Multiple simultaneous sites; high turnover; extensive subcontracting Permits to work; task-level preliminary risk analysis; contractor management (8.1.4)
Mining Structural collapse, dust, vibration, explosives Remote operations; variable geological conditions; additional sector regulation Continuous environmental monitoring; specific emergency plans for underground/open pit
Chemical / Oil & Gas Hazardous substances, explosions, leaks, confined spaces Process safety vs. occupational safety; major accident scenarios Robust management of change (8.1.3); integration with process safety standards (IEC 61511)
Manufacturing Rotating machinery, ergonomics, noise, chemicals Multiple production lines with distinct risks; shift work Hierarchy of controls applied per workstation; machine guarding; ergonomics programmes
Healthcare Biological agents, ergonomics, violence, stress 24-hour operation; patients as a source of risk; waste disposal Biosafety protocols; sharps management; violence prevention programmes
Logistics and transport Collisions, ergonomics, fatigue, yard pedestrian strikes Drivers in motion; limited control over external environment Fatigue management; telematics; loading/unloading procedures; yard safety

The role of technology in ISO 45001 compliance

Digitalization of OH&S processes enables organizations to maintain ISO 45001 compliance more efficiently, reducing administrative burden and increasing the reliability of evidence. The main areas where technology adds value to the OH&S MS include:

OH&S MS area ISO 45001 requirement Technology solution Benefit
Hazard identification 6.1.2 Digital checklists with geolocation and photographic evidence Real-time recording at the point of work; automatic traceability
Risk management 6.1.2 / 8.1.2 Dynamic risk matrices with automated reassessment Continuous updating as new data emerges; deviation alerts
Documented information 7.5 Document management systems with version control and digital approval Elimination of obsolete documents in circulation; simplified auditing
Training and competence 7.2 / 7.3 Digital work instruction platforms and augmented reality Training at the point of use; real-time competence validation
Inspections and audits 9.1.1 / 9.2 Digital forms with automatic escalation workflows Structured data for analysis; elimination of data re-entry
Incident management 10.2 Reporting and investigation platforms with cause trees and corrective actions Complete cycle from incident to corrective action with traceability

Adoption of EHSQ software enables integration of multiple ISO 45001 requirements in a single platform, eliminating information silos and providing real-time visibility of the management system compliance status.

Request a demonstration to learn how the platform supports ISO 45001 implementation and maintenance in your organization.

Request a Demo
Laptop and two smartphones displaying Glartek software dashboards and workflows for work orders and incident reports.

Frequently Asked Questions

What is ISO 45001:2018?

ISO 45001:2018 is the international standard that establishes requirements for an occupational health and safety management system (OH&S MS). Published by ISO in March 2018, it applies to any organization regardless of size or sector, with the objective of preventing work-related injuries and ill health.

What is the difference between ISO 45001 and OHSAS 18001?

ISO 45001 is an international standard (ISO) whilst OHSAS 18001 was a British specification (BSI). The main differences include: HLS structure enabling integration with ISO 9001/14001; the organizational context requirement; leadership as non-transferable responsibility of top management; active participation (not just consultation) of workers; and management of change as an explicit requirement. OHSAS 18001 was discontinued in March 2021.

Is ISO 45001 certification mandatory?

No. Certification is voluntary. However, it may be required contractually by clients, in public tendering processes, by supply chain requirements or by ESG frameworks. Implementation of the management system (without formal certification) is also a valid option.

How long does it take to implement ISO 45001?

The typical timeframe ranges between 8 and 18 months for medium-sized organizations. Influencing factors include: existence of a prior management system (ISO 9001 or 14001 significantly reduces the timeframe), maturity of the safety culture, number of sites and process complexity.

Does ISO 45001 replace national OHS legislation?

No. ISO 45001 is a voluntary management system standard; national occupational health and safety legislation comprises mandatory legal obligations. ISO 45001 complements and systematises compliance with national OHS laws and regulations. Organisations must continue to meet all applicable legal requirements in their jurisdiction. The standard provides a framework that helps structure and evidence legal compliance, but does not supersede any statutory obligation.

What is the High Level Structure (HLS)?

The High Level Structure (also called Annex SL or Harmonized Structure) is the standardized 10-clause model that ISO uses for all management system standards. It ensures that ISO 45001, ISO 9001, ISO 14001 and others share the same structure, common terms and definitions, facilitating integration into an Integrated Management System (IMS).

What are the benefits of ISO 45001 certification?

The main benefits include: structured framework for prevention of work-related injuries and ill health; demonstration of due diligence and reasonable care; systematised legal compliance; competitive advantage in tenders and supply chains; improvement of safety culture; and integration with other management systems (quality and environment).

How does the certification audit work?

The audit occurs in two stages: Stage 1 (documentary), where the auditor analyzes the documentation and system readiness; and Stage 2 (implementation), an on-site audit that evaluates the effective operation of the OH&S MS through interviews, observations and record verification. The certificate has a 3-year validity with annual surveillance audits.

What are the most common non-conformities?

The most frequent non-conformities include: insufficient worker participation (5.4); incomplete hazard identification, especially in occupational health and psychosocial risks (6.1.2); outdated legal compliance evaluation (9.1.2); absent or incomplete management of change (8.1.3); and incident investigation focused on individual blame without systemic analysis (10.2).

How can technology help with ISO 45001 compliance?

EHSQ software digitises key OH&S MS processes: digital checklists for hazard identification with real-time evidence; dynamic risk matrices; automated documented information control; training platforms with competence validation; inspection forms with automatic escalation; and integrated incident management systems with full corrective action cycle traceability.

Request your demo

It's time to elevate Safety, Quality, and Performance in your operations

Start your EHSQ Connected Worker journey with Glartek and become a leader in your industry.

Schedule Demo
mockup glartek

Subscribe now to get our latest insights and updates 🚀

Discover the power of the only AI-Native EHSQ solution built for the frontline

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.