ISO 45001: What an OH&S Management System Really Requires
September 4, 2026
What ISO 45001 is, and what it is not
ISO 45001 is the international standard for an occupational health and safety management system. It is not a safety score, not a technical specification for your installations, and not a statement that your site is low risk. It describes a way of organising decisions about health and safety so that the decisions are repeatable, traceable, and improved on a cycle.
The whole thing compresses into one line that safety professionals recognise immediately: we have to write what we do, and we have to do what we write.
The question in a certification audit is not whether your workplace is safe on the day the auditor visits, but whether you can show how you decided it was safe, who decided it, on what basis, and what happened when reality turned out different.
The clause structure, in plain terms
ISO 45001 uses the same high level structure as other management system standards, which is why it sits next to ISO 9001 and ISO 14001 without friction. Anyone who has been through an ISO 27001 certification will recognise the shape of it: context, leadership, worker participation, planning, support, operation, evaluation.
The clauses that carry most of the weight in practice:
- Clause 4, context. Who your interested parties are, what they expect, and what the scope of your system covers. Scope is a decision, and a badly drawn scope creates audit findings for years.
- Clause 5, leadership and worker participation. This is the clause that distinguishes 45001 from its predecessor. Consultation of workers is not a courtesy in this standard, it is a requirement with evidence attached.
- Clause 6, planning. Hazard identification, assessment of risks and opportunities, legal and other requirements, and objectives. This is where most of the real work lives.
- Clause 7, support. Competence, awareness, communication, and documented information. Competence means you can show why this person is allowed to do this task.
- Clause 8, operation. Operational planning and control, management of change, procurement and contractors, emergency preparedness and response.
- Clause 9, performance evaluation. Monitoring, internal audit, management review.
- Clause 10, improvement. Incidents, nonconformity, corrective action, continual improvement.
What auditors actually look at
An auditor works by sampling. They take a documented claim and follow it into your daily reality, then take a piece of your daily reality and follow it back to the documented claim. The gap between those two directions is where findings come from.
In practice they tend to pull on:
- Traceability of a single hazard. Pick one hazard from your risk assessment, then ask for the control, the instruction, the training record of the person doing it, and the last time it was verified.
- Corrective actions with a closing date and evidence. An action that has been open for eleven months is a statement about your system, not about that action.
- Management of change. Something in your plant or organisation changed. Did the risk assessment follow, and can you show the trail?
- Consultation. Not the existence of a committee, but records of what workers raised and what was done with it.
- The gap between the written procedure and how the work is done. Ask the operator, then read the procedure.
If you are also under Dutch supervisory pressure from the Nederlandse Arbeidsinspectie or your regional authority such as DCMR, note that this is a different track from certification. A certificate is not a defence, and an inspector is not auditing against ISO 45001. What the two have in common is that both come down to demonstrability.
Where implementations go wrong
Three failure patterns show up again and again.
Writing too much. Teams fill paragraphs by referring to every internal instruction and procedure they have, and the system becomes a document set nobody reads. More text is not more control. It is more surface that has to stay current.
Checklists that cannot be completed honestly. A four page checklist handed to someone with two hours for a walkdown across a large installation will get ticked, not performed. If the points are mixed together without following the physical route of the inspection, the errors are built in before anyone starts. Designing the inspection around how the work is actually done is a large part of what makes safety inspection software worth anything at all.
Knowledge that lives in people who leave. An experienced technician explained the reasoning behind a control three years ago, verbally, to someone who accepted it. That technician has since left, and now there is a finding on the table and nobody can reconstruct the argument. A management system is partly a defence against this, and only if the reasoning got written down, not just the outcome.
A workable order of work
If you are starting, or restarting, this sequence tends to hold up:
- Fix the scope and the list of legal and other requirements first. Everything downstream inherits from it.
- Run a gap analysis against the clauses before you write anything new. You almost certainly already comply with more than you think, in documents that are not labelled as ISO 45001.
- Rebuild hazard identification and risk assessment as living records, not annual documents.
- Make corrective actions the beating heart of the system. Owner, date, evidence, verification.
- Get inspections and observations onto a form that the person on the floor can complete in the time they actually have.
- Only then write procedures, and write them short.
For high hazard sites, be honest that a generic management system will carry you only so far, which is the argument in our piece on why generic safety management software falls short for Seveso III companies.
What software can and cannot do here
Software does not make you compliant, and no tool decides your acceptable risk for you. It is your management system, not your vendor's. What a tool can do is remove the mechanical reasons systems decay: forms that match the walkdown, findings that become actions with an owner, evidence attached at the moment of observation instead of reconstructed later, and a record that survives the departure of the person who made the call.
The certificate is the receipt. The system is whether anyone can still explain, two years from now, why you did what you did.
If you are in the middle of a gap analysis and want to compare notes on how the inspection and corrective action side is usually set up, we are happy to have that conversation without a demo attached. What is the part of your system you would least like an auditor to sample first?