Skip to main content

Certification you can stand behind.

ISO 45001:2018

ISO 45001 Occupational Health & Safety Management

Protect people with a safety system that works on site, not just on paper.

Health & safety
  1. Site hazards

    Hazard ID (Cl 6)

  2. Process hazards

    Risk assessed (Cl 6)

  3. Engineering controls

    Eliminate first (Cl 8)

    Residual risk

  4. Safe systems of work

    Permits + method stmts

  5. Competent supervision

    Training records (Cl 7)

  6. Emergency response

    If barriers fail (Cl 8)

    Speak up

  7. Worker consultation

    Clause 5 participation

    Improve returns to Engineering controls

  8. People go home safe

    Every shift, every site

SYS/03 · Barrier layers

Site hazards are arrested by successive control barriers while worker consultation keeps every layer honest.

What ISO 45001 is

ISO 45001 is the international standard for occupational health and safety management. It requires hazard identification, risk control, legal compliance, worker consultation and a leadership role that cannot be delegated to a safety officer.

CORE audits ISO 45001 where safety is decided: at the work face, in planning and in supervision. Your auditor observes activity on site, speaks to workers and contractors without a manager present where participation is being tested, and compares the risk assessment with what is actually happening. Permits, method statements, inductions, plant records, incident investigations and the legal register are examined as evidence. The findings raised most often concern risk assessments that do not match the task, worker consultation that exists only as a notice board, and incident investigations that stop at human error.

Who it is for

  • Construction, manufacturing, logistics and FM operations whose clients require certification to ISO 45001
  • Principal contractors and prequalification applicants who must show an audited safety system to win work
  • Organizations whose regulator, insurer or scheme expects independent assessment of safety management
  • Certified organizations transferring an active ISO 45001 certificate from another certification body
  • Groups seeking one combined audit covering safety alongside quality and environment

Business outcomes

What leadership should expect the system to change, in operational terms.

Fewer incidents

Systematic hazard identification and risk control reduce both frequency and severity over time.

Legal defensibility

A live legal register, competence records and audit trails demonstrate due diligence.

Worker participation

Consultation and participation requirements turn the workforce into sensors, not bystanders.

Prequalification success

A certificate of registration satisfies the OH&S management-system requirements in client and scheme prequalification.

Benefits beyond the certificate

  • Leadership visibility

    Defined OH&S roles and review cadence give directors the oversight regulators expect of them.

  • Contractor control

    Procurement and contractor-management controls extend safety beyond your direct employees.

  • Insurance position

    Documented systematic risk management supports premium and claims discussions.

  • Morale and retention

    People stay where they feel protected, and consultation makes protection visible.

  • Integration

    Annex SL structure aligns with ISO 9001 and ISO 14001 for one integrated system.

Safety helmet and high-visibility vest on a steel bench
ISO 45001 in the field

The main requirements

The themes your auditor will examine, in plain language. The full clause detail is worked through at Stage 2.

01

Context and workers (Clause 4)

Scope the system around sites, activities and everyone performing work under your control.

02

Leadership and participation (Clause 5)

Top-management accountability, an OH&S policy and formal worker consultation and participation.

03

Hazards and legal requirements (Clause 6)

Hazard identification, risk and opportunity assessment, legal register and OH&S objectives.

04

Support (Clause 7)

Competence, awareness, communication and control of OH&S documented information.

05

Operation (Clause 8)

Hierarchy of controls, management of change, procurement, contractors and emergency preparedness.

06

Evaluation and improvement (Clauses 9 and 10)

Monitoring, compliance evaluation, incident investigation, internal audit and management review.

What each requirement buys you

Select a requirement theme to see the business outcomes it chiefly drives. The mapping reflects where audit sampling concentrates, not a normative ISO table.

Requirement themes

Context and workers (Clause 4) chiefly drives 2 of 4 ISO 45001 outcomes.

Outcomes it drives

Fewer incidents

Systematic hazard identification and risk control reduce both frequency and severity over time.

Legal defensibility

A live legal register, competence records and audit trails demonstrate due diligence.

Worker participation

Consultation and participation requirements turn the workforce into sensors, not bystanders.

Prequalification success

A certificate of registration satisfies the OH&S management-system requirements in client and scheme prequalification.

How CORE audits ISO 45001

Step 1

Stage 1 reviews scope, hazards and legal position

Your auditor confirms the scope covers every site and everyone performing work under your control, reads the hazard identification and risk assessment method, the legal register and the consultation arrangements, and checks that internal audit, compliance evaluation and management review have taken place.

Step 2

Stage 2 examines control at the work face

The audit samples live activity: high-risk tasks against their risk assessments and permits, the hierarchy of controls as actually applied, management of change, contractor and procurement controls, plant and equipment records, emergency arrangements, and interviews with workers about consultation and participation.

Step 3

Surveillance samples incidents and change

Year 1 and Year 2 audits sample incidents and investigations since the last visit, new activities, sites or contractors, changes in legislation and the resulting compliance evaluation, participation records, progress against OH&S objectives, and the closure of previous findings.

Step 4

Recertification revisits the whole cycle

In Year 3 the audit reviews three years of safety performance: whether incident trends improved, whether investigations produced systemic change, whether consultation has been sustained, whether leadership accountability is visible, and whether the scope and site list are still accurate.

What your auditor expects to see

Before Stage 2 can proceed, the system needs to have run long enough to have produced its own evidence.

  1. 01Internal audit completed

    A full internal audit against ISO 45001:2018 that sampled real work at real sites, run by auditors independent of the operations they audited.

  2. 02Legal compliance evaluation completed

    A documented, dated evaluation against the OH&S legal register, with the evidence relied on for each duty and any shortfall recorded and actioned.

  3. 03Management review held

    Minuted review covering incidents, participation and consultation, compliance status, objectives and audit results, with decisions and owners recorded.

  4. 04Records covering a meaningful period

    Inductions, toolbox talks, permits, inspections, plant checks, incident and near-miss reports spanning enough time to show the system operating across normal fluctuations in workload.

  5. 05Corrective actions closed

    Incident and audit actions showing root-cause analysis beyond individual error, the control change made, and verification that the change held.

  6. 06Competence demonstrable

    Training, ticket and authorization records connecting named workers, supervisors and contractors to the tasks they are permitted to perform, with a defined scope and site list to audit against.

  7. Certification decision

    With that evidence in place, Stage 1 and Stage 2 can run. The decision that follows is taken by a reviewer who was not on your audit team.

CORE is the certification body. We assess and certify management systems. We do not build them — that separation is what makes the certificate worth holding. We do not design, document or implement the systems we audit, and we do not run your internal audits. If you need that work done, our directory of independent consultants is a starting point, and engaging one has no bearing on the decision. More on how we keep the audit and the decision separate.

The optional pre-assessment

Before Stage 1 you can ask for an optional pre-assessment: an audit-style review of hazard identification, legal compliance, operational controls, consultation and incident management against ISO 45001:2018, conducted on site rather than in a meeting room. It returns a written report of findings, graded the way a certification audit would grade them.

The report says where the evidence falls short. It does not write your risk assessments, choose your controls or design your consultation arrangements: doing so would make CORE the author of the system it must later audit, which ISO/IEC 17021-1 prohibits. If you want support acting on the report, the directory of independent consultants at /resources/find-a-consultant is a starting point.

What you receive

  • Findings against each clause of the standard
  • Where the evidence is missing or incomplete
  • Whether Stage 2 could proceed on today's records
  • The same sampling method a certification audit uses
How the pre-assessment works

Training for ISO 45001

Courses that teach how the standard is written and how it is audited.

All courses

ISO 45001 questions, answered straight

Ready to certify to ISO 45001?

Tell us your standards, scope, effective headcount and sites. You will get a scope statement and a fixed quotation, with audit duration calculated from the accreditation body's mandatory formula.