ISO 45001

ISO 45001 certification,
explained plainly

ISO 45001 is the international standard for an occupational health and safety management system, the successor to OHSAS 18001 and the first OH&S standard you can certify against worldwide. Here is what certification actually involves: the clauses, worker consultation and participation, hazard identification and the hierarchy of controls, the certification stages and the surveillance audits that keep the certificate valid, plus how teams that also run ISO 9001 or ISO 14001 keep every system in one Swiss-hosted workspace.

Book a conversation
Every framework
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
  • ISO/IEC 27001
  • SOC 2
  • GDPR
  • HIPAA
  • Swiss nFADP
  • NIST CSF 2.0
  • OWASP
  • EU AI Act
The standard

What ISO 45001 actually requires

ISO 45001 certifies an occupational health and safety management system (OH&S management system), not an accident rate. The 2018 edition sets out its requirements in seven clauses and asks you to identify hazards, control risks in a mandated order, involve your workers in all of it, and prove it keeps working over time.

The clauses (4 to 10)

Context, leadership and worker participation, planning, support, operation, performance evaluation and improvement. The same harmonized structure ISO 9001, ISO 14001 and ISO 27001 use, which is why the four combine into one integrated system.

Workers at the centre

A clause no other management system standard has: workers at all levels must be consulted on the system and must participate in hazard identification, risk assessment, incident investigation and improvement, without fear of reprisal.

The hierarchy of controls

There is no control catalogue. Instead the standard mandates the order in which risks are treated: eliminate, substitute, engineer, administer, and only then protective equipment, with the reasoning recorded.

The certification cycle

A Stage 1 and Stage 2 audit to certify, then a surveillance audit in years one and two and a full recertification in year three, with worker interviews and a site walk at every visit.

The full picture

ISO 45001, from first audit to recertification

A plain-language walkthrough of what the standard asks for, and what actually keeps a certificate valid between audits.

01

What is ISO 45001?

ISO 45001 is the international standard for occupational health and safety management. It does not certify that your workplace is accident-free. It certifies that your organization runs a working OH&S management system: a defined way of identifying the hazards in your work, assessing the risks, controlling them in a mandated order, involving the people who do the work, investigating what goes wrong and improving, over and over.

Published in March 2018, it replaced OHSAS 18001, the British specification most of the world had used until then, and it was the first OH&S standard issued by ISO itself. Amendment 1:2024 added the same sentence ISO added to all its management system standards: the organization must determine whether climate change is a relevant issue, which for worker safety means heat, extreme weather and changed working conditions. A revision of the 2018 edition is under way, with a draft circulating in 2026; until the new edition is published and its transition begins, ISO 45001:2018 remains the edition you certify against.

ISO 45001 vs ISO 14001 and ISO 9001

All three share the harmonized clause structure and the same certification rhythm, and most organizations that hold ISO 45001 also hold at least one of the others. What ISO 45001 adds is people: a dedicated clause on worker consultation and participation, a right to remove oneself from imminent danger, incident investigation with worker involvement, and management review outputs that must be communicated to workers. Where ISO 14001 manages environmental aspects and ISO 9001 manages product conformity, ISO 45001 manages hazards to the people doing the work.

02

The clauses, 4 to 10

Clause 4 is context: the issues that affect worker safety, the workers and other interested parties and their needs, and the scope, which must include every activity under your control or influence that can affect OH&S performance. Clause 5 is leadership and worker participation: top management takes overall accountability for preventing injury and ill health, sets the OH&S policy with its five commitments, assigns roles at every level, and establishes consultation and participation of workers. Clause 6 is planning: hazard identification, assessment of risks and opportunities, legal and other requirements, planned actions along the hierarchy of controls, and OH&S objectives.

Clause 7 is support: resources, competence including the ability to identify hazards, awareness including the right to refuse dangerous work, communication that accounts for language, literacy and disability, and documented information. Clause 8 is operation: operational controls, the hierarchy of controls, management of change, procurement, contractors and outsourcing, and emergency preparedness and response including first aid. Clause 9 is performance evaluation: monitoring with leading and lagging indicators, evaluation of compliance, internal audit and management review. Clause 10 is improvement: incident investigation, nonconformity and corrective action, and continual improvement.

03

Worker consultation and participation

Clause 5.4 is what makes ISO 45001 different from every other ISO management system standard. Workers at all levels, and their representatives where they exist, must be consulted on the policy, the roles, the legal requirements, the objectives, the controls, outsourcing and monitoring, and must participate in hazard identification, risk assessment, control selection, competence needs, communication, incident investigation and improvement. The standard singles out non-managerial workers, because they are the ones who know where the real hazards are.

The organization must provide the mechanisms, time, training and information for this, and must identify and remove the barriers: language, literacy, fear of reprisal, lack of time. Auditors test it directly. They ask workers whether they were consulted on the last risk assessment, whether they know how to report a hazard, and what happened the last time someone did.

04

Hazards, risks and the hierarchy of controls

Hazard identification under ISO 45001 is ongoing and proactive, not an annual form. It covers how work is organized, workload and psychosocial factors, routine and non-routine work, past incidents, emergencies, contractors and visitors, workplace design and every planned change. Risks are assessed with documented criteria and with existing controls taken into account, and opportunities to design hazards out are assessed as well.

When it comes to treating the risks, the standard mandates an order. Eliminate the hazard first. If that is impossible, substitute a less hazardous process, material or equipment. Then engineering controls and reorganization of work. Then administrative controls such as procedures and training. Personal protective equipment comes last. Every control decision has to show that the higher rungs were considered, and a risk assessment that jumps straight to a helmet and gloves is the finding auditors raise most often.

05

How ISO 45001 certification works, step by step

Certification is carried out by an accredited certification body in two stages. Stage 1 is a readiness review: the auditor checks that the system exists as documented information, that the scope, policy, hazard register, risk assessments and legal requirements are in place, and that internal audit, compliance evaluation and management review have been planned or done. Stage 2 is the certification audit proper: the auditor walks the workplaces, follows hazards into the controls that manage them, interviews workers about consultation, hazards and their right to refuse dangerous work, checks contractor management and tests emergency preparedness.

From a serious start, most small and mid-size organizations reach Stage 2 in six to twelve months, driven mostly by how mature hazard identification and worker participation already are. The certificate is then valid for three years, with a surveillance audit in each of years one and two and a full recertification in year three.

Incident investigation: the record the auditor reads first

Clause 10 requires incidents, including near misses, to be reported, investigated with worker participation, corrected at the root cause along the hierarchy of controls, and fed back into the risk assessments, with results communicated to workers. Auditors read the incident register first because it shows whether the system learns. A register with no near misses is not a safe workplace; it is a reporting channel nobody trusts.

06

What drives the cost of ISO 45001

The certification body charges for the Stage 1 and Stage 2 audits and for each surveillance audit, scaled to the number of sites, workers and risk level in scope. That fee is usually the smaller part. The larger cost is building and running the system: hazard identification with worker participation, risk assessments, legal requirements, safe work procedures, contractor management, emergency drills, competence and training, monitoring, compliance evaluation, audits and reviews, and keeping all of it current through every audit.

Two levers move that cost more than the certification fee. Scope, because certifying the sites and activities your customers and regulators actually ask about is cheaper than certifying everything at once. And integration, because if you also run ISO 9001, ISO 14001 or ISO 27001, one context analysis, one audit programme, one management review and one corrective-action process can serve every certificate, and certification bodies commonly audit them together.

The real problem

Audit-ready is a state you keep, not a sprint you survive.

Most tools optimize for getting the first certificate. The expensive part is the years after: the risk assessment nobody updated when the new machine arrived, the contractor who was never inducted, the near miss that was reported and never investigated. That is the part a surveillance auditor finds in a worker interview, and the part no first-cert tool was built for.

Spreadsheet sprawl across drives, tabs and inboxes
The week-before scramble, reassembled from memory
The control you haven't looked at since last cycle
Audit-readiness over time
3-year cycle
audit-readyCertSurveillance 1Surveillance 2
Point-in-time tools — scramble & drift
devguard — a state you keep
Run it in devguard

Your ISO 45001 management system, in one workspace

The management-system side of the standard, from clause coverage and legal requirements to incidents, audits, findings and reviews, kept current between surveillance audits. Pick one to see it.

Every clause, in one view

See clauses 4 to 10 as a control set, what applies to your scope and where you stand, each requirement mapped to the documented information, processes and evidence that satisfy it, so the picture stays live instead of being rebuilt before each audit.

Learn more
Control coverage64%
Asset managementCovered
CryptographyPartial
Supplier securityGap
Document once. Reuse across every standard you add.

ISO 45001 shares its clause structure with ISO 9001, ISO 14001 and ISO 27001. Map the management-system clauses once in devguard and the same context analysis, audit results and management review satisfy them everywhere they appear, so the next certificate is a fraction of the work of the first.

See the full feature comparison

Already certified and dreading the next cycle? See how we help certified companies stay audit-ready.

Already certified? Move your ISO 45001 system across

If you already hold ISO 45001, you do not want to rebuild your OH&S management system from a blank page. In a scoped conversation we agree exactly what moves (your hazard register and risk assessments, legal requirements, policy and objectives, incident records, audit history and management review records) and run that migration with you, for a fixed scope and a date set before we start. Your existing setup stays untouched and exportable until you are satisfied the new one holds up side by side.

Book a conversation
ISO 45001 FAQ

ISO 45001, answered plainly.

How long does ISO 45001 certification take?

For most small and mid-size organizations, roughly six to twelve months from a serious start to the Stage 2 audit, depending on how mature hazard identification, worker participation and incident reporting already are. Maintaining it afterwards is the longer game: a surveillance audit each year and a full recertification every three years.

What happened to OHSAS 18001?

OHSAS 18001 was withdrawn when ISO 45001 was published in 2018, and the migration period for existing certificates ended in 2021. ISO 45001 keeps the substance but adds the harmonized clause structure, a much stronger role for top management and for worker consultation and participation, and explicit treatment of contractors, outsourcing and management of change.

Does ISO 45001 have controls like Annex A in ISO 27001?

No. ISO 45001 has no control catalogue. Its requirements are the clauses themselves, and the substance comes from your own hazard identification and risk assessments: you determine the hazards, and the standard mandates the order in which you control them, from elimination down to personal protective equipment. Annex A of the standard is guidance, not a list of controls.

Is a new edition of ISO 45001 coming?

A revision is under way; the draft international standard was balloted in mid-2026, and publication is expected afterwards with the usual three-year transition period. Until then ISO 45001:2018 with Amendment 1:2024 is the edition you certify against, and a system built on it will carry over, because the harmonized structure and the core requirements are being clarified rather than replaced.

Can I combine ISO 45001 with ISO 9001 and ISO 14001?

Yes, and this is the most common way to run it. All three follow the same harmonized clause structure, so one context analysis, one internal audit programme, one management review and one corrective-action process can serve all of them. Certification bodies commonly audit the three together as an integrated management system, which cuts audit days as well as maintenance effort. ISO 45001 keeps its own consultation and participation processes, which the other two do not require.

Is devguard an occupational safety tool?

devguard is a compliance workspace, and it carries the management-system side of ISO 45001: clause coverage, versioned documented information, the hazard register, risk assessments, legal requirements and incident investigations as evidence, internal audits, nonconformities and corrective actions, management reviews and the roadmap from adoption to certification. It does not replace exposure monitoring, permit-to-work or occupational health systems. Where you already run ISO 9001 or ISO 14001 in devguard, ISO 45001 slots into the same system.

See how your ISO 45001 system would look in devguard.

The fastest way to know if this fits is a short conversation about how you run ISO 45001 today: where the hazard register and the risk assessments live, how incidents and consultation are recorded, and whether it should share a workspace with your other management systems. No deck unless you want one.

Book a conversation
Sign in
Start for free
Book a conversationStart for free