
Those aren't abstract numbers. They're the reason ISO 45001 exists.
Published in March 2018, ISO 45001 became the world's first international standard for occupational health and safety management systems, replacing the older OHSAS 18001. This guide breaks down what it actually requires, its seven core clauses, and a realistic path to certification.
Key Takeaways
- ISO 45001 shares its High-Level Structure with ISO 9001 and ISO 14001, simplifying integrated management systems
- It formally replaced OHSAS 18001, and the migration deadline has already passed
- Seven clauses (4-10) organize the standard around the Plan-Do-Check-Act cycle
- Certification generally runs six to twelve months, depending on size and existing safety maturity
- Worker participation and leadership ownership are mandatory requirements, not optional extras
What Is ISO 45001?
ISO 45001:2018 is the international standard for occupational health and safety management systems (OHSMS), issued by the International Organization for Standardization. Its core purpose: prevent work-related injury, illness, and fatality through a structured, risk-based management framework.
It applies to organizations of any size, in any sector, anywhere. Certification is voluntary. Plenty of companies adopt the framework internally without ever pursuing formal registration.
Relationship to OHSAS 18001
ISO 45001 replaced OHSAS 18001:2007. Organizations holding OHSAS 18001 certificates had to migrate under a three-year transition plan, extended briefly for COVID-related delays to September 11, 2021, according to ISO/TC 283's migration notice.
That window is closed. OHSAS 18001 is no longer a valid certification target.
The shift wasn't cosmetic. Key differences:
- ISO 45001 is process-based; it weighs risks and opportunities and factors in workers, interested parties, and business context
- OHSAS 18001 was procedure-based, focused on internal hazards, and addressed risk only
Relationship to ISO 9001 and ISO 14001
ISO 45001 was built on Annex SL, the same High-Level Structure used by ISO 9001 (quality) and ISO 14001 (environmental management). Same core text. Same terminology. Same clause numbering.
That doesn't mean the subject matter overlaps — it means organizations already running ISO 9001 or ISO 14001 can slot ISO 45001 into an integrated management system without rebuilding their documentation architecture from scratch.
Who Needs ISO 45001
ISO's own guidance lists manufacturing, construction, transport, energy, healthcare, and public administration as common users. Higher-risk operations (oil and gas, mining, agriculture, heavy fabrication) usually see the fastest return because hazard exposure is part of daily work.
In practice, the standard matters most to:
- EHS managers and plant managers running day-to-day safety programs
- Quality directors integrating OH&S into an existing management system
- Procurement and supply chain teams facing certification requirements from customers
- Any organization bidding on contracts where OH&S credentials factor into vendor selection
The 7 Core Elements of ISO 45001
ISO 45001 organizes its requirements into seven clauses, numbered 4 through 10, built around the Plan-Do-Check-Act cycle. Each clause maps to a stage of that cycle:
| Clause | Title |
|---|---|
| 4 | Context of the organization |
| 5 | Leadership and worker participation |
| 6 | Planning |
| 7 | Support |
| 8 | Operation |
| 9 | Performance evaluation |
| 10 | Improvement |

Context of the Organization
Map the landscape first. Before building controls, businesses identify internal and external issues that affect OH&S: regulatory changes, workforce demographics, and site-specific hazards. They also capture worker needs and the expectations of interested parties such as regulators, insurers, and clients.
Leadership and Worker Participation
Ownership stays at the top. Leaders must visibly own the OH&S system, fund it with real resources, and consult workers on decisions that affect their safety. Worker input is a requirement under this clause, not a courtesy top management can skip.
Planning (Risk & Opportunity Management)
Identify hazards, then set objectives. Teams run hazard identification and risk assessment, determine applicable legal obligations, and set measurable OH&S objectives tied to those risks. Opportunities for safer processes get the same structured treatment as threats.
Support
Give the system what it needs to run. This clause covers resources, competence, awareness, communication, and documented information. In practice that means training records, controlled procedures, and internal channels that keep OH&S information current and accessible.
Operation
Control the work and the change. Operational planning covers process controls, hierarchy of controls, and emergency preparedness. It also governs how you manage change, contractors, and suppliers so new work does not introduce unmanaged hazards.
Performance Evaluation
Check whether the system works. Organizations monitor OH&S performance, run internal audits, and hold formal management review. The goal is evidence-based judgment on conformity, effectiveness, and where objectives are falling short.
Improvement
Act on what you find. Nonconformities and incidents must be investigated, corrected, and used to drive continual improvement. This is the "Act" stage of Plan-Do-Check-Act: close the loop so the next cycle starts stronger than the last.
Together, clauses 4–10 turn OH&S from a static policy binder into a managed cycle of context, leadership, planning, support, operation, evaluation, and improvement.
Why ISO 45001 Matters: Key Benefits
ISO 45001 gives organizations a structured way to identify and control OH&S risks, which helps prevent incidents and reduce the downtime and costs that follow them.
Business advantages show up in several places:
- Proactive risk management can help lower insurance premiums, though outcomes vary by insurer and industry
- Reduced legal liability from documented hazard controls and compliance tracking
- Stronger standing in supplier and tender qualification (BSI's Beard Construction case study links certification to more competitive bids)
Workforce impact shows up in engagement and retention. Employees who see leadership invest in safety tend to engage more and stay longer.
One QMS Learning customer, COMAV, put it plainly: after role-specific EHS training, their team became confident "identifying hazards, conducting risk assessments, and maintaining compliance." That is the standard's worker-participation requirement working in practice.
How to Get ISO 45001 Certified
Certification follows a phased path that builds on whatever safety practices already exist. No organization starts from zero.

Step 1: Secure Leadership Commitment and Conduct a Gap Analysis
Nothing moves without leadership buy-in. Run a gap analysis comparing current OH&S practices against every ISO 45001 clause to identify what's missing before you build anything new.
Step 2: Conduct Risk Assessments and Build Documentation
Identify hazards, build a risk register, and draft the OH&S policy along with supporting procedures. This documentation becomes the backbone auditors will review later.
Step 3: Implement Training and Embed Worker Participation
This is where most organizations stall. Teams finish a training module, then freeze the first time an auditor asks them to produce evidence under pressure.
Practitioner-built training closes that gap. QMS Learning's Environmental & Safety Compliance pathway pairs role-specific coursework with hands-on practice so teams build evidence, not just course completions:
- 12-module, 50-lesson EHS Fundamentals covering ISO 14001, ISO 45001, OSHA, and EPA reporting
- AI Workbench trained on ISO 45001, ISO 14001:2026, and OSHA 29 CFR 1910
- Practice diagnosing live problems and generating audit-ready documentation as you go
Step 4: Run Internal Audits and Management Review
Before you call a registrar, prove the system works. Complete internal audits against ISO 45001, close nonconformities, and hold a management review that confirms the OH&S system is ready for external assessment.
Step 5: Complete the Two-Stage Certification Audit
An accredited certification body conducts:
- Stage 1: a documentation review confirming your system's scope and readiness for Stage 2
- Stage 2: an implementation audit checking whether the system actually works in practice, through interviews, observation, and record review
The system needs to be operating with real evidence behind it before Stage 2. Auditors need something to observe, not just paperwork.
How Long Does ISO 45001 Certification Take?
Most organizations report a certification journey of roughly six to twelve months. Several variables affect that timeline:
- Organization size and number of sites
- Complexity of operations and hazard profile
- Maturity of existing safety practices
- How quickly documentation and training can be completed
Once certified, the certificate carries a three-year validity period, with surveillance audits typically conducted once or twice a year to confirm the system is still functioning.
Self-paced, role-specific training can shorten the documentation and training phases. Coordinating classroom sessions across shifts and locations often eats weeks on its own. QMS Learning's self-paced modules let teams finish training in days and build toward audit-readiness within about 30 days, removing that scheduling bottleneck entirely.
Frequently Asked Questions
What is the ISO 45001 standard for occupational health and safety management systems?
Published in 2018, ISO 45001 is the international standard for occupational health and safety management systems. It gives organizations a framework to prevent work-related injury and illness and replaced OHSAS 18001.
What are the 7 elements of ISO 45001?
The seven core elements map to clauses 4–10: Context of the Organization, Leadership and Worker Participation, Planning, Support, Operation, Performance Evaluation, and Improvement. Together they follow the Plan-Do-Check-Act cycle.
How do I get ISO 45001 certified?
Complete a gap analysis, build risk assessments and required documentation, train your team and run the system, then pass a two-stage audit by an accredited certification body.
How long does it take to get ISO 45001 certification?
Most organizations need six to twelve months, depending on company size, complexity, and how mature their existing safety practices already are.
Do you have to be certified to benefit from ISO 45001?
No. Many organizations use ISO 45001 purely as a reference framework to structure their safety programs, without pursuing formal third-party certification.
What is the difference between ISO 45001 and OHSAS 18001?
ISO 45001 takes a broader, risk-based approach, shares its High-Level Structure with ISO 9001 and ISO 14001, and requires stronger worker participation than OHSAS 18001.


