ISO 45001:2018
ISO 45001 Occupational Health & Safety Management
Protect people with a safety system that works on site, not just on paper.
Site hazards
Hazard ID (Cl 6)
Process hazards
Risk assessed (Cl 6)
Engineering controls
Eliminate first (Cl 8)
Residual risk
Safe systems of work
Permits + method stmts
Competent supervision
Training records (Cl 7)
Emergency response
If barriers fail (Cl 8)
Speak up
Worker consultation
Clause 5 participation
Improve returns to Engineering controls
People go home safe
Every shift, every site
SYS/03 · Barrier layers
Site hazards are arrested by successive control barriers while worker consultation keeps every layer honest.
What ISO 45001 is
ISO 45001 is the international standard for occupational health and safety management. It requires hazard identification, risk control, legal compliance, worker consultation and a leadership role that cannot be delegated to a safety officer.
CORE audits ISO 45001 where safety is decided: at the work face, in planning and in supervision. Your auditor observes activity on site, speaks to workers and contractors without a manager present where participation is being tested, and compares the risk assessment with what is actually happening. Permits, method statements, inductions, plant records, incident investigations and the legal register are examined as evidence. The findings raised most often concern risk assessments that do not match the task, worker consultation that exists only as a notice board, and incident investigations that stop at human error.
Who it is for
- Construction, manufacturing, logistics and FM operations whose clients require certification to ISO 45001
- Principal contractors and prequalification applicants who must show an audited safety system to win work
- Organizations whose regulator, insurer or scheme expects independent assessment of safety management
- Certified organizations transferring an active ISO 45001 certificate from another certification body
- Groups seeking one combined audit covering safety alongside quality and environment
Business outcomes
What leadership should expect the system to change, in operational terms.
Fewer incidents
Systematic hazard identification and risk control reduce both frequency and severity over time.
Legal defensibility
A live legal register, competence records and audit trails demonstrate due diligence.
Worker participation
Consultation and participation requirements turn the workforce into sensors, not bystanders.
Prequalification success
A certificate of registration satisfies the OH&S management-system requirements in client and scheme prequalification.
Benefits beyond the certificate
Leadership visibility
Defined OH&S roles and review cadence give directors the oversight regulators expect of them.
Contractor control
Procurement and contractor-management controls extend safety beyond your direct employees.
Insurance position
Documented systematic risk management supports premium and claims discussions.
Morale and retention
People stay where they feel protected, and consultation makes protection visible.
Integration
Annex SL structure aligns with ISO 9001 and ISO 14001 for one integrated system.

The main requirements
The themes your auditor will examine, in plain language. The full clause detail is worked through at Stage 2.
01
Context and workers (Clause 4)
Scope the system around sites, activities and everyone performing work under your control.
02
Leadership and participation (Clause 5)
Top-management accountability, an OH&S policy and formal worker consultation and participation.
03
Hazards and legal requirements (Clause 6)
Hazard identification, risk and opportunity assessment, legal register and OH&S objectives.
04
Support (Clause 7)
Competence, awareness, communication and control of OH&S documented information.
05
Operation (Clause 8)
Hierarchy of controls, management of change, procurement, contractors and emergency preparedness.
06
Evaluation and improvement (Clauses 9 and 10)
Monitoring, compliance evaluation, incident investigation, internal audit and management review.
What each requirement buys you
Select a requirement theme to see the business outcomes it chiefly drives. The mapping reflects where audit sampling concentrates, not a normative ISO table.
Requirement themes
Context and workers (Clause 4) chiefly drives 2 of 4 ISO 45001 outcomes.
Outcomes it drives
Fewer incidents
Systematic hazard identification and risk control reduce both frequency and severity over time.
Legal defensibility
A live legal register, competence records and audit trails demonstrate due diligence.
Worker participation
Consultation and participation requirements turn the workforce into sensors, not bystanders.
Prequalification success
A certificate of registration satisfies the OH&S management-system requirements in client and scheme prequalification.
How CORE audits ISO 45001
Step 1
Stage 1 reviews scope, hazards and legal position
Your auditor confirms the scope covers every site and everyone performing work under your control, reads the hazard identification and risk assessment method, the legal register and the consultation arrangements, and checks that internal audit, compliance evaluation and management review have taken place.
Step 2
Stage 2 examines control at the work face
The audit samples live activity: high-risk tasks against their risk assessments and permits, the hierarchy of controls as actually applied, management of change, contractor and procurement controls, plant and equipment records, emergency arrangements, and interviews with workers about consultation and participation.
Step 3
Surveillance samples incidents and change
Year 1 and Year 2 audits sample incidents and investigations since the last visit, new activities, sites or contractors, changes in legislation and the resulting compliance evaluation, participation records, progress against OH&S objectives, and the closure of previous findings.
Step 4
Recertification revisits the whole cycle
In Year 3 the audit reviews three years of safety performance: whether incident trends improved, whether investigations produced systemic change, whether consultation has been sustained, whether leadership accountability is visible, and whether the scope and site list are still accurate.
What your auditor expects to see
Before Stage 2 can proceed, the system needs to have run long enough to have produced its own evidence.
01Internal audit completed
A full internal audit against ISO 45001:2018 that sampled real work at real sites, run by auditors independent of the operations they audited.
02Legal compliance evaluation completed
A documented, dated evaluation against the OH&S legal register, with the evidence relied on for each duty and any shortfall recorded and actioned.
03Management review held
Minuted review covering incidents, participation and consultation, compliance status, objectives and audit results, with decisions and owners recorded.
04Records covering a meaningful period
Inductions, toolbox talks, permits, inspections, plant checks, incident and near-miss reports spanning enough time to show the system operating across normal fluctuations in workload.
05Corrective actions closed
Incident and audit actions showing root-cause analysis beyond individual error, the control change made, and verification that the change held.
06Competence demonstrable
Training, ticket and authorization records connecting named workers, supervisors and contractors to the tasks they are permitted to perform, with a defined scope and site list to audit against.
Certification decision
With that evidence in place, Stage 1 and Stage 2 can run. The decision that follows is taken by a reviewer who was not on your audit team.
CORE is the certification body. We assess and certify management systems. We do not build them — that separation is what makes the certificate worth holding. We do not design, document or implement the systems we audit, and we do not run your internal audits. If you need that work done, our directory of independent consultants is a starting point, and engaging one has no bearing on the decision. More on how we keep the audit and the decision separate.
The optional pre-assessment
Before Stage 1 you can ask for an optional pre-assessment: an audit-style review of hazard identification, legal compliance, operational controls, consultation and incident management against ISO 45001:2018, conducted on site rather than in a meeting room. It returns a written report of findings, graded the way a certification audit would grade them.
The report says where the evidence falls short. It does not write your risk assessments, choose your controls or design your consultation arrangements: doing so would make CORE the author of the system it must later audit, which ISO/IEC 17021-1 prohibits. If you want support acting on the report, the directory of independent consultants at /resources/find-a-consultant is a starting point.
What you receive
- Findings against each clause of the standard
- Where the evidence is missing or incomplete
- Whether Stage 2 could proceed on today's records
- The same sampling method a certification audit uses
Training for ISO 45001
Courses that teach how the standard is written and how it is audited.
ISO 45001 questions, answered straight
Related standards
Ready to certify to ISO 45001?
Tell us your standards, scope, effective headcount and sites. You will get a scope statement and a fixed quotation, with audit duration calculated from the accreditation body's mandatory formula.
