ISO 45001 is an international standard for occupational health and safety (OH&S) management systems. It provides organizations with a structured framework to identify workplace hazards, manage risks, meet applicable requirements, involve workers, and continually improve occupational health and safety performance.
The current published standard is ISO 45001:2018, which was reviewed and confirmed in 2024 and remains the current published edition. ISO 45001 is applicable to organizations of different sizes, industries, and locations.
For businesses, implementing ISO 45001 is not simply about preparing documents for certification. It involves creating practical processes that help an organization understand workplace risks, establish appropriate controls, monitor performance, investigate incidents, and improve safety practices over time.
ISO 45001:2018 specifies requirements for an occupational health and safety management system. Its purpose is to help organizations provide safer and healthier workplaces by preventing work-related injury and ill health and improving OH&S performance.
The standard follows a management-system approach based on the Plan-Do-Check-Act (PDCA) methodology. This enables businesses to plan their safety objectives, implement controls, evaluate results, and take corrective action where improvements are required.
ISO 45001 focuses on several important areas, including:
Rather than prescribing one specific safety program for every organization, ISO 45001 allows businesses to develop an OH&S management system that reflects their own activities, risks, workforce, and operating environment.
Workplace health and safety can affect employees, contractors, visitors, business operations, and other relevant interested parties. A structured management system helps organizations address safety risks systematically rather than relying only on individual precautions.
ISO states that the standard can help organizations systematically assess hazards, implement risk controls, demonstrate commitment to worker health and safety, address legal requirements, prepare for emergencies, investigate incidents, and continually improve OH&S performance.
A strong OH&S management system can also provide practical business benefits.
Organizations can identify hazards before they result in incidents and establish controls appropriate to the level of risk.
Clearly defined procedures can help employees understand responsibilities, safe working methods, reporting processes, and emergency arrangements.
ISO 45001 places emphasis on consultation and participation of workers. Employees can provide valuable information about hazards and operational conditions because they experience workplace processes directly.
Organizations need to determine applicable legal and other requirements and consider them within their OH&S management system.
Safety performance should not remain static. Organizations can monitor results, investigate incidents, identify weaknesses, and make improvements.
ISO 45001 follows the common high-level structure used by many modern ISO management system standards. This makes it possible for organizations to integrate their OH&S system with standards such as ISO 9001 and ISO 14001.
The organization needs to understand internal and external issues that can affect its ability to achieve the intended outcomes of its OH&S management system.
It should also identify relevant interested parties and determine the scope of the management system.
For example, a manufacturing company may need to consider production processes, machinery, contractors, workplace conditions, regulatory requirements, and the expectations of workers.
Leadership has an important role in establishing and maintaining the OH&S management system.
Management should demonstrate commitment to occupational health and safety and ensure that responsibilities and authorities are clearly defined.
Worker consultation and participation are also important elements. Employees should have appropriate opportunities to contribute to safety-related decisions and improvements.
Planning involves identifying hazards, assessing OH&S risks, identifying opportunities, considering applicable requirements, and establishing OH&S objectives.
Hazard identification may involve reviewing:
The organization can then determine appropriate controls and priorities.
A management system requires appropriate resources and competent people.
Organizations should consider areas such as:
Employees should understand relevant safety procedures and the potential consequences of failing to follow established controls.
Operational planning and control translate safety policies into everyday activities.
Organizations should establish processes for controlling identified risks and managing changes that could affect occupational health and safety.
Where contractors or outsourced activities can influence OH&S performance, appropriate controls should also be considered.
Businesses should identify potential emergency situations and establish processes for responding to them.
Depending on the organization, emergencies may include:
Emergency procedures should be communicated, tested where appropriate, and reviewed after incidents or exercises.
An effective OH&S management system needs measurable performance information.
Organizations can monitor indicators such as:
Internal audits and management reviews provide additional opportunities to determine whether the system is working as intended.
Continual improvement is a central principle of ISO 45001.
When an incident or nonconformity occurs, the organization should determine what happened, investigate relevant causes, take appropriate corrective action, and evaluate whether similar problems could occur elsewhere.
This creates a cycle in which safety performance can improve through experience and systematic review.
Organizations that want certification generally need to implement the OH&S management system before an independent certification body conducts an external audit.
A typical implementation process may include the following stages.
The organization first reviews its current health and safety arrangements against the requirements of ISO 45001.
This helps identify areas that require improvement.
The organization establishes or updates its OH&S policy, procedures, processes, objectives, risk assessments, operational controls, and other necessary documented information.
The developed system is put into practice. Employees receive relevant information and training, while responsibilities are assigned throughout the organization.
An internal audit helps determine whether the OH&S management system has been implemented and is functioning effectively.
Senior management reviews system performance, objectives, audit results, risks, opportunities, and improvement requirements.
An independent certification body evaluates the organization’s management system against ISO 45001 requirements.
Certification is not automatic. The organization must demonstrate conformity with the applicable requirements.
ISO explains that organizations can implement ISO 45001 without certification, while those seeking independent certification can use a third-party certification body.
ISO 45001 can be used by organizations regardless of their size, type, or industry.
It can therefore be relevant to:
The specific hazards and controls will vary significantly between industries.
For example, a construction company may focus heavily on work at height, machinery, site traffic, and contractor management, while an office-based organization may focus more on ergonomics, emergency preparedness, electrical safety, and psychosocial risks.
One of the important characteristics of ISO 45001 is its emphasis on worker participation.
Employees can contribute practical knowledge about workplace conditions and operational risks. Their involvement can support better hazard identification and more practical safety controls.
Worker participation can include:
Creating clear channels for workers to raise safety concerns can strengthen the overall management system.
ISO 45001 can be integrated with other management system standards because it uses a compatible structure.
For example, an organization may combine:
ISO 9001 for quality management
ISO 14001 for environmental management
ISO 45001 for occupational health and safety
An integrated management system can reduce duplication by using common processes for areas such as document control, internal audits, management review, corrective actions, and continual improvement.
However, each standard has its own specific requirements, so integration should not result in important OH&S controls being overlooked.
Organizations should also be aware that ISO 45001 is currently being revised.
As of 2026, ISO 45001:2018 remains the current published standard, while ISO/DIS 45001 is under development and is intended to replace the 2018 edition. The draft is currently in the enquiry stage.
The 2018 standard also has Amendment 1:2024, titled “Climate action changes.”
Organizations certified to ISO 45001 should monitor official updates and obtain transition guidance from their certification body when the revised standard is formally published.
It is important not to treat a draft standard as a final set of certification requirements. The final published revision may differ from the current draft.
Organizations may encounter several challenges when implementing an OH&S management system.
If senior management treats safety as only a compliance department responsibility, implementation can become disconnected from everyday operations.
Some organizations focus on obvious hazards while overlooking less visible risks associated with contractors, maintenance, organizational changes, or workplace behavior.
A system designed without meaningful worker input may not reflect actual workplace conditions.
Incomplete records can make it difficult to demonstrate that processes are implemented and monitored.
Identifying a safety issue is only the beginning. Organizations need to ensure corrective actions are implemented and reviewed for effectiveness.
Addressing these challenges early can make the management system more practical and sustainable.
ISO 45001 is not intended to be a one-time certification exercise. The management system should evolve as the organization changes.
New machinery, employees, suppliers, locations, processes, technologies, and regulatory requirements can introduce new risks.
Regular risk assessments, inspections, audits, worker consultation, incident reviews, and management meetings can help organizations identify opportunities for improvement.
This continuous approach allows safety management to become part of normal business operations rather than a separate administrative activity.
ISO 45001 provides organizations with a structured framework for managing occupational health and safety risks and improving workplace safety performance. Its requirements cover leadership, worker participation, hazard identification, risk assessment, operational controls, emergency preparedness, performance evaluation, and continual improvement.
For businesses seeking certification, successful implementation depends on more than documentation. Employees, managers, contractors, and leadership should understand their responsibilities and contribute to the effectiveness of the OH&S management system.
The current published edition remains ISO 45001:2018, including its 2024 climate-action amendment, while a revised edition is under development. Organizations should therefore keep track of official ISO updates and plan appropriately for future transition requirements.
A well-managed ISO 45001 system can help organizations establish consistent safety processes, understand workplace risks, strengthen compliance management, and create a foundation for continual improvement.
What is ISO 45001?
ISO 45001 is an international standard specifying requirements for an occupational health and safety management system.
Is ISO 45001:2018 still valid?
Yes. ISO currently identifies ISO 45001:2018 as the current published standard, while a revised edition is under development.
Who can implement ISO 45001?
Organizations of any size, type, or industry can implement ISO 45001.
Is ISO 45001 certification mandatory?
ISO 45001 itself does not automatically make certification mandatory. Organizations can implement the management system without third-party certification; certification is an additional independent assessment by a certification body.
What is the main purpose of ISO 45001?
Its purpose is to help organizations provide safe and healthy workplaces, prevent work-related injury and ill health, manage OH&S risks, and continually improve OH&S performance.