Our accident reporting FAQs answer your questions about what to do in the event of a workplace accident or incident.
ISO 45001 stands for the international standard for Occupational Health and Safety Management Systems, with ISO referring to the International Organization for Standardization and 45001 being the specific standard number.
ISO 45001 is an international standard for occupational health and safety (OH&S) management systems, developed by the International Organization for Standardization.
It provides a structured framework that helps organisations identify hazards, assess and control risks, and improve workplace health and safety performance.
The purpose of ISO 45001 is to provide organisations with a systematic framework for managing occupational health and safety, with the aim of preventing work-related injury and ill health and creating safer workplaces.
ISO 45001 helps organisations to:
Rather than focusing only on compliance or reactive measures, an ISO 45001 safety management system integrates health and safety into everyday business operations, promoting a proactive and continuous approach to risk management across the organisation.
ISO 45001 covers all elements needed to establish, implement, maintain, and continually improve an occupational health and safety (OH&S) management system within an organisation.
It covers:
ISO 45001 applies to all activities, products, and services that can impact workers’ health and safety, whether those risks arise from routine operations, non-routine activities, contractors, or visitors.
ISO 45001 requirements set out what an organisation must do to establish, implement, maintain, and continually improve an occupational health and safety (OH&S) management system.
Key requirements include:
ISO 45001 contains 10 clauses in total.
The first three clauses are introductory, while Clauses 4 to 10 set out the mandatory requirements for an occupational health and safety management system. These clauses follow the common High-Level Structure used across ISO management system standards, making ISO 45001 easier to integrate with standards such as ISO 9001 and ISO 14001.
ISO 45001 is structured into 10 clauses, following the common High-Level Structure used by ISO management system standards.
Clause 1 – Scope
Defines the purpose of the standard and the outcomes an organisation is expected to achieve through its occupational health and safety management system.
Clause 2 – Normative references
Identifies any referenced documents that are essential for the application of ISO 45001 (there are no normative references in this standard).
Clause 3 – Terms and definitions
Provides definitions of key terms used throughout the standard to ensure consistent understanding.
Clause 4 – Context of the organisation
Requires organisations to understand internal and external issues, worker needs, and the scope of the OH&S management system.
Clause 5 – Leadership and worker participation
Sets expectations for top management accountability, leadership, consultation, and active worker involvement in health and safety.
Clause 6 – Planning
Focuses on identifying hazards, assessing OH&S risks and opportunities, and planning actions to achieve health and safety objectives.
Clause 7 – Support
Covers the resources, competence, awareness, communication, and documented information needed to operate the OH&S system effectively.
Clause 8 – Operation
Addresses operational planning and control, including risk controls, change management, outsourcing, and emergency preparedness.
Clause 9 – Performance evaluation
Requires organisations to monitor, measure, analyse, audit, and review their OH&S performance.
Clause 10 – Improvement
Focuses on incident investigation, corrective actions, and continual improvement of the OH&S management system.
In ISO 45001, risk and opportunity refer to factors that can affect the effectiveness of an organisation’s occupational health and safety (OH&S) management system.
OH&S risks are the combination of the likelihood and severity of injury or ill health resulting from exposure to hazards. These include physical, psychological, and organisational hazards that could harm workers or others affected by the organisation’s activities.
OH&S opportunities are circumstances that can improve health and safety performance, such as eliminating hazards, introducing safer work methods, improving competence, or strengthening worker participation.
ISO 45001 requires organisations to identify, assess, and address both risks and opportunities as part of planning, ensuring that health and safety risks are reduced while opportunities for improvement are actively pursued.
ISO 45001 does not prescribe a fixed list of mandatory documents. Instead, it requires organisations to maintain documented information where necessary to demonstrate that the occupational health and safety (OH&S) management system is operating effectively and meets the standard’s requirements.
In practice, organisations usually maintain documented information such as:
This reflects ISO 45001’s risk-based, flexible approach, where documentation is proportionate to the organisation’s size, complexity, and risk profile.
Under ISO 45001, worker participation means actively involving workers (especially non-managerial workers) in how health and safety is managed, not just informing them of decisions.
In practice, this includes:
Auditors look for evidence that workers’ views influence decisions and improvements to the OH&S management system.
No. ISO 45001 does not explicitly require you to have a health and safety committee.
However, Clause 5.4 (Consultation and participation of workers) requires organisations to have effective arrangements for involving workers in health and safety matters. A health and safety committee is one of the most common and effective ways to demonstrate this, particularly in larger or higher-risk organisations.
You can meet ISO 45001’s requirements without a formal committee if you can show meaningful consultation and participation in other ways, such as regular worker consultations, toolbox talks, safety representatives, or involvement in risk assessments and incident reviews.
During an audit, you must be able to evidence how workers are consulted and how their input influences decisions.
ISO 45001 covers mental health and workplace stress through its definitions and risk requirements.
Under Clause 3.20, a hazard is anything with the potential to cause injury or ill health, and “ill health” includes psychological as well as physical conditions.
Clause 6.1.2.1 requires organisations to identify hazards arising from how work is organised, social factors at work, and human factors (which is where psychosocial risks such as stress, burnout, bullying, and harassment fall).
Clause 5.4 requires worker consultation and participation, which is essential for identifying stress-related risks.
ISO 45003 is a guidance standard that explains how to manage psychological health and psychosocial risks at work.
ISO 45003 supports ISO 45001 by showing organisations how to identify, assess, and control risks such as work-related stress, burnout, bullying, harassment, excessive workload, poor job design, and lack of support.
While ISO 45001 sets the requirements for an occupational health and safety management system, ISO 45003 provides practical advice on applying those requirements specifically to mental health and wellbeing.
Yes, any company can pursue ISO 45001, regardless of size, industry, or sector.
ISO 45001 is suitable for low-risk office environments as well as higher-risk industries such as construction, manufacturing, logistics, and shipping.
The standard focuses on managing occupational health and safety risks relevant to the organisation’s activities, rather than prescribing specific controls. This enables organisations to tailor their management system to their hazards, legal obligations, and operating context.
No, ISO 45001 is not a legal requirement in the UK.
ISO 45001 is a voluntary international standard for managing occupational health and safety, developed by the International Organization for Standardization. Organisations are not legally obliged to be certified to ISO 45001.
However, UK employers are legally required to protect the health, safety, and welfare of their workers under legislation such as the Health and Safety at Work etc. Act 1974. ISO 45001 can help organisations demonstrate a structured approach to meeting these legal duties.
In practice, ISO 45001 may be:
So, while ISO 45001 itself is not law, it is often adopted to support legal compliance and meet commercial or contractual expectations.
ISO 45001 was introduced in March 2018.
It was published by the International Organization for Standardization as the international replacement for OHSAS 18001, providing a modern, globally consistent framework for managing occupational health and safety.
The current official version of ISO 45001 is ISO 45001:2018, the international standard for occupational health and safety management systems. An amendment — ISO 45001:2018/Amd 1:2024 — has also been published to update the standard (for example, to include climate-related considerations).
A fully revised version — ISO 45001:2027 — is in development and expected to be published in 2027, with a transition period likely lasting a few years after publication.
Yes, ISO 45001 does replace OHSAS 18001.
ISO 45001 was published in 2018 by the International Organization for Standardization as the formal successor to OHSAS 18001. OHSAS 18001 is no longer a recognised or certifiable standard.
Organisations certified to OHSAS 18001 were required to transition to ISO 45001 by March 2021. After this date, OHSAS 18001 certifications ceased to be valid.
ISO 45001 certification is independent, third-party verification that an organisation’s occupational health and safety (OH&S) management system meets the requirements of the ISO 45001 standard, published by the International Organization for Standardization.
Certification is achieved following a formal audit by an accredited certification body, confirming that the organisation has effective systems in place to manage health and safety risks and continually improve performance.
It is important because ISO 45001 certification:
The main benefit of ISO 45001 certification is that it provides independent assurance that an organisation is effectively managing occupational health and safety risks to protect its workers.
By achieving certification, an organisation demonstrates that health and safety is managed through a structured, proactive system, rather than relying on ad hoc or reactive measures. This leads to fewer work-related injuries and ill health, stronger legal compliance, and greater confidence among employees, clients, and regulators.
In practice, ISO 45001 certification shows that health and safety is embedded into everyday business operations and subject to continual improvement, helping to create safer, more resilient organisations.
The benefits of ISO 45001 include:
For many organisations, ISO 45001 also provides a recognised framework that supports tendering, supply chain requirements, and alignment with other management system standards such as quality and environmental management.
For more information, please read our article, What are the benefits of ISO 45001?
ISO 45001 certification is valid for three years.
Once certified, an organisation must undergo annual surveillance audits by an accredited certification body to confirm the occupational health and safety management system continues to meet ISO 45001 requirements.
At the end of the three-year cycle, a recertification audit is required to renew certification for a further three years.
If surveillance or recertification audits are not completed successfully, certification can be suspended or withdrawn, so ongoing compliance and continual improvement are essential to maintaining ISO 45001 certification.
1st, 2nd, and 3rd party audits refer to different types of audits used to assess management systems, such as those required for ISO 45001, based on who carries out the audit and its purpose.
1st party audits (internal audits)
These are audits carried out by the organisation itself, or on its behalf, to assess whether its management system is being implemented effectively and meets ISO 45001 requirements. They identify gaps, verify compliance, and drive continual improvement before external audits.
2nd party audits (supplier or customer audits)
These audits are conducted by an interested party, such as a client or customer, on an organisation or its suppliers. They are often used to verify that health and safety arrangements meet contractual or supply chain requirements.
3rd party audits (certification audits)
These are independent audits carried out by an accredited certification body to determine whether an organisation meets the requirements of ISO 45001. Successful completion of a 3rd party audit results in ISO 45001 certification, which is valid for three years, subject to annual surveillance audits.
An ISO 45001 checklist is a practical audit tool used to assess how well an organisation’s occupational health and safety management system aligns with the requirements of ISO 45001. It helps identify gaps, risks, and areas for improvement before implementation or certification.
To achieve ISO 45001 accreditation for your organisation, you need to understand your current state of risk management and what changes are required to meet the standard. Conducting a health and safety audit against ISO 45001 is the first step in that process.
At Praxis42, we provide a practical audit-ready checklist to help you:
ISO 45001 is not inherently hard to achieve, but the level of effort involved depends on an organisation’s size, risk profile, and current health and safety maturity.
Organisations that already have established health and safety arrangements, or existing management systems such as ISO 9001 or ISO 14001, often find ISO 45001 straightforward to implement due to the shared structure and requirements. For others, particularly those moving from a more informal or reactive approach, additional time may be needed to put effective systems, documentation, and processes in place.
If you want expert support, Praxis42’s friendly team of ISO 45001 consultants can help. We offer a pre-audit health check and work in partnership with your organisation to make targeted, cost-effective improvements to your occupational health and safety management system (OHSMS).
In an ISO 45001 audit, a non-conformity means that part of your management system does not fully meet a requirement of the standard.
A non-conformity does not automatically mean you have failed. Most audits identify minor non-conformities, which indicate a gap or weakness that needs to be corrected. You are normally given time to implement corrective actions and provide evidence that the issue has been addressed.
A major non-conformity is more serious and indicates a significant failure of the system or a risk to health and safety. This may delay certification or require additional audit activity, but it still does not necessarily mean permanent failure.
ISO 45001 audits aim to drive continual improvement, not to catch organisations out. Non-conformities are treated as opportunities to strengthen your health and safety management system.
Yes, ISO 45001 certification can be suspended or withdrawn, but this usually happens only where serious issues are not addressed.
Certification may be at risk if an organisation fails to correct major non-conformities, does not implement agreed corrective actions, repeatedly fails surveillance audits, or allows the management system to lapse rather than being actively maintained. Serious health and safety breaches can also put certification at risk if they show the system is ineffective.
ISO 45001 is intended to be a living management system. If issues are identified, corrective actions are taken, and the system is maintained and reviewed, certification is unlikely to be withdrawn.
ISO 45001 requires organisations to manage the health and safety risks of contractors in the same structured way as their own workers.
Under Clause 8.1.4 (Procurement) and Clause 8.1.2 (Eliminating hazards and reducing OH&S risks), organisations must ensure that contractors’ activities are controlled, coordinated, and do not create unacceptable risks. You are expected to assess contractor risks before work starts, define safety requirements, and monitor performance during the work.
The cost of implementing ISO 45001 varies widely depending on your organisation’s size, complexity, existing systems, and whether you use external support.
Cost elements include:
There’s no fixed price for ISO 45001 implementation. Small, low-risk organisations with mature safety practices may spend relatively little, while larger or more complex organisations will invest more in establishing compliant systems.
If you want expert help to manage costs and focus effort on what matters most, Praxis42 offers ISO 45001 consultancy to support you from gap analysis through to certification.
Yes, ISO 9001, ISO 14001, and ISO 45001 can be implemented at the same time, and many organisations choose to do so.
All three standards follow ISO’s High-Level Structure (Annex SL), which means they share common requirements such as leadership, risk-based thinking, documented information, internal audits, and management review. This makes it practical to develop an integrated management system covering quality, environmental management, and occupational health and safety.
Implementing the standards together can:
The key is to tailor the integrated system to your organisation’s size, activities, and risks, ensuring each standard’s specific requirements are clearly addressed while benefiting from a unified approach.
The difference between ISO 45001 and ISO 9001 lies in their focus and objectives, although they share a common structure.
ISO 45001 focuses on occupational health and safety. It provides a framework for identifying workplace hazards, managing health and safety risks, preventing injury and ill health, and involving workers in safety management.
ISO 9001 focuses on quality management. It aims to ensure organisations consistently deliver products and services that meet customer and regulatory requirements, while improving customer satisfaction and process efficiency.
Key differences include:
Both standards are published by the International Organization for Standardization and follow the same High-Level Structure, which makes them easy to implement together as part of an integrated management system.
No, shipping companies are not required to use ISO 45001.
ISO 45001 is a voluntary international standard for occupational health and safety management, developed by the International Organization for Standardization. There is no legal requirement for shipping companies to be certified to ISO 45001.
However, shipping companies must comply with maritime and health and safety legislation, such as requirements under the International Maritime Organization (IMO) and the International Safety Management (ISM) Code, as well as relevant national regulations.
In practice, some shipping companies choose to implement ISO 45001 because it:
While ISO 45001 is not mandatory for shipping companies, it is often adopted as a best-practice framework to support and enhance existing safety management arrangements.