
This guide is written for EHS managers, plant managers, quality directors, and OH&S committee members who implement or audit ISO 45001 systems. Clause 6.1.2 is one of the most-cited clauses in the standard and one of the most poorly implemented. Many organizations treat it as a paperwork exercise completed once and filed away, rather than the ongoing, proactive process the standard actually requires.
Here's what this article covers: what the process is, why ISO 45001 mandates it, how it works step-by-step, where it applies, and the mistakes that generate audit findings.
TL;DR
- Clause 6.1.2 requires ongoing, proactive hazard ID and risk assessment—not a one-time exercise.
- Scope routine and non-routine work, human factors, past incidents, and organizational change—not only visible hazards.
- Use JSA, workplace inspections, HAZOP studies, and worker consultation as core methods.
- Apply the hierarchy of controls (elimination through PPE), then reassess after implementation.
- Most audit failures stem from static, generic hazard registers disconnected from real conditions.
What Is ISO 45001 Hazard Identification & Risk Assessment?
ISO 45001 defines a hazard as "a source with a potential to cause injury and ill health." That definition is broader than it sounds: it covers physical sources, hazardous situations, and circumstances that create harmful exposure, not just obvious things like exposed machinery or chemical spills.
Risk assessment, meanwhile, is the process of evaluating the likelihood and severity of harm resulting from that hazard. ISO does not prescribe a single formula for this calculation. The ISO/TC 283 committee's guidance makes clear that organizations must define their own methodology and criteria, applied systematically and proactively rather than reactively.
Hazard ID Finds It, Risk Assessment Prioritizes It
These two activities are inseparable in practice:
- Hazard identification is the "finding" step: surfacing sources of harm before anyone gets hurt.
- Risk assessment is the "evaluating and prioritizing" step, determining how likely and how severe the harm could be.
One always feeds the other. A hazard register without risk ranking is just a list. Without solid hazard identification up front, any risk ranking is guesswork on an incomplete picture.
This is different from incident investigation, which is reactive and happens after harm has already occurred. It is also distinct from ISO 14001's environmental aspect and impact assessment, which addresses harm to the environment rather than to workers.
Clause 6.1.2.1 is explicit on one point that trips up a lot of organizations: the process must be "ongoing and proactive." Not a project with a completion date, but a standing operational discipline.
Why Hazard ID & Risk Assessment Is Central to ISO 45001
This isn't a best practice you can skip if resources are tight. Clause 6.1.2 is a mandatory certification requirement. An organization cannot achieve or maintain ISO 45001 certification without a documented, functioning hazard identification and risk assessment process.
The stakes behind that requirement are real. Private-industry employers reported 2.5 million nonfatal workplace injuries and illnesses in 2024, according to Bureau of Labor Statistics data, with a total-recordable-case rate of 2.3 cases per 100 full-time workers. That's an improvement from 2023, but it still represents millions of preventable injuries, most of them tied to hazards someone could have caught earlier.

What Happens Without a Functioning Process
Skip proactive hazard management, and a predictable pattern emerges:
- Hazards go undetected until an incident forces the issue.
- The same root cause produces repeat injuries, sometimes years apart.
- Auditors flag nonconformities tied to outdated or generic hazard registers.
Stopping that pattern takes more than a static register. ISO 45001 requires worker participation and consultation under clause 5.4, so the people doing the work help identify hazards and shape controls. Workers on the task daily catch risks a quarterly walkthrough misses, and their buy-in is what makes those controls hold.
How the Process Works: From Hazard ID to Risk Control
The flow is straightforward: identify hazards across all activities and interfaces, assess likelihood and severity, determine the risk level, select controls using the hierarchy of controls, implement them, then reassess.
Inputs feeding this process include workplace inspections, incident and near-miss records, worker interviews, safety data sheets, and industry alerts. The output is a documented hazard register and risk assessment record, communicated to workers before they start the task, not after something goes wrong.
Step 1: Identify Hazards Across Routine and Non-Routine Activities
Clause 6.1.2.1 requires organizations to consider how work is organized, social factors, past incidents, and non-routine situations (breakdowns, maintenance, emergencies), not just the standard daily task. This is where many programs fail: they document the routine job perfectly and ignore the messy, infrequent work where injuries actually cluster.
Core identification methods include:
- Job Safety Analysis (JSA): break a task into steps and identify hazards at each stage
- Workplace inspections: scheduled and unannounced walkthroughs
- HAZOP studies: structured, multidisciplinary reviews for process deviations, especially in complex operations
- Safety data sheet reviews: chemical and material hazards
- Worker-reported near misses: often the earliest warning signal available
OSHA's hazard identification guidance specifically flags maintenance, startup, and shutdown activities as areas requiring the same rigor as routine work — precisely because they're irregular enough that workers and supervisors alike can underestimate the risk.
Step 2: Assess and Rank the Risk
Once a hazard is identified, combine likelihood and severity (often through a risk matrix) to classify the risk as acceptable, tolerable, or intolerable. This step should involve competent personnel and the workers actually affected by the task. A risk assessment written entirely from an office desk misses context that only shows up on the floor.
Not every hazard needs the same rigor. A simple JSA might be enough for a routine task; a HAZOP or FMEA is warranted for complex or high-consequence processes. Choosing the wrong methodology for the situation — either overkill or under-analysis — is a common source of weak risk assessments.
This diagnostic step trips up teams without a strong internal process.
QMS Learning's AI-guided Method Router helps EHS teams choose the risk assessment approach that fits a given hazard scenario from the team's own description of the situation. It then generates the corresponding audit-ready documentation instead of leaving that judgment call to whoever is free that week.
Step 3: Control, Communicate, and Review
Once risk is ranked, select controls using the hierarchy of controls, in strict order of preference, not convenience:
- Elimination: remove the hazard entirely
- Substitution: replace it with something safer
- Engineering controls: redesign the process or equipment to reduce contact
- Administrative controls: change work practices, schedules, or procedures
- PPE: protect the worker as a last line of defense

According to NIOSH's hierarchy of controls guidance, elimination, substitution, and engineering controls are generally more effective because they don't depend on consistent worker behavior. That matters when fatigue, time pressure, or turnover make procedure-only controls fail.
After controls go in, reassess the risk, communicate results to affected workers, and review the register periodically or whenever conditions change.
Where the Process Is Applied & Key Factors That Affect It
Where It's Applied
Hazard identification and risk assessment isn't a once-a-year certification activity. It repeats at defined trigger points:
- Pre-task planning, before work begins
- Introduction of new equipment or processes
- After an incident or near-miss
- Management of change (new materials, workflows, or organizational structure)
- Scheduled periodic reviews
It's recurring and condition-based. It fires again whenever the work, the people, or the conditions shift.
Key Factors That Affect Effectiveness
A few variables determine whether the process actually works or just looks good on paper:
- Depth of worker consultation — hazard registers built without frontline input miss task-level realities
- Coverage of non-routine activities — maintenance, breakdowns, and emergencies often get skipped
- Quality of historical data — incident, near-miss, and industry hazard records feed better assessments
- Operational complexity — determines whether a checklist suffices or a formal method like HAZOP is needed
- Jurisdiction-specific legal obligations — some industries and regions mandate specific assessment depths
Tracking these factors at a team level is difficult without visibility into who's actually competent versus who's just completed a course. QMS Learning's Manager Dashboard surfaces those capability gaps before an auditor finds them.
Common Mistakes and Misconceptions
Even organizations that have run ISO 45001 for years fall into predictable traps.
The generic hazard list. Copying templated JSAs across job roles without reflecting the actual equipment, environment, and procedures is the most common failure. It looks compliant. It leaves real risks completely unaddressed.
Treating it as a one-time project. Hazard identification isn't a deliverable you check off during implementation. It needs updating every time a process, piece of equipment, or team member changes.
Skipping frontline workers. Supervisors often think they understand task-level risk better than they do. Workers usually know more. ISO 45001 auditors often interview workers during audits to confirm the register matches what happens on the floor, not only what's written down.
Over-relying on PPE. PPE sits at the bottom of the hierarchy of controls for a reason: it depends entirely on consistent human behavior to work. Treating it as the primary control instead of engineering or administrative measures is a red flag auditors catch quickly.

Closing these gaps takes more than one safety manager's memory. QMS Learning's Environmental & Safety Compliance pathway builds verified hazard identification and risk assessment competence across the team, so the capability stays put when people leave.
Frequently Asked Questions
What hazards does ISO 45001 require organizations to consider?
Clause 6.1.2.1 requires you to consider how work is organized, routine and non-routine activities, past incidents, and potential emergencies. It also covers everyone on site (workers, contractors, visitors) and changes in operations or hazard knowledge.
What are the types of hazard identification in ISO 45001?
ISO 45001 does not prescribe one method. Common approaches include Job Safety Analysis, workplace inspections, HAZOP studies, worker consultation, incident and near-miss reviews, and checks of safety data sheets and industry alerts.
What are the 7 elements of ISO 45001?
The seven core system elements are clauses 4–10, run on Plan-Do-Check-Act: context; leadership and worker participation; planning (including hazard ID and risk assessment); support; operation; performance evaluation; and improvement.
What is the difference between ISO 9001 and ISO 45001?
ISO 9001 focuses on quality management and customer satisfaction; ISO 45001 focuses on occupational health and safety and worker protection. Both share the same Annex SL structure, but one doesn't substitute for the other.
Who is responsible for hazard identification in ISO 45001?
Responsibility is shared. Top management sets the process and allocates resources, supervisors and safety personnel lead execution, but workers must actively participate since they understand task-level hazards best.
How often should hazard identification and risk assessment be reviewed?
It should be ongoing, not just an annual exercise. Trigger a review after process changes, new equipment, incidents, near misses, or new workers, in addition to any scheduled periodic reviews.


