ISO 45001:2018 is the international standard for occupational health and safety (OH&S) management systems. It replaced OHSAS 18001 and follows the same high-level structure as ISO 9001 and ISO 14001, which makes it straightforward to integrate with an existing system. What makes it different is its insistence that health and safety is managed with workers, not for them. This guide sets out the implementation steps in the order that works in practice, and the points auditors focus on at each stage.
Step 1 — Secure leadership commitment
Clause 5 of ISO 45001 places responsibility for preventing work-related injury and ill health on top management, and it cannot be delegated to a safety officer. In practice this means top management sets the OH&S policy, provides resources, takes part in management review and is visibly involved in the system. Auditors interview senior leaders directly, and a leadership team that cannot describe its own OH&S objectives is a finding in itself.
Step 2 — Define the context and scope
Identify the internal and external issues that affect your ability to achieve the intended outcomes of the system, and the needs and expectations of workers and other interested parties — contractors, visitors, regulators, neighbours. Then define the scope: which sites, activities and workers are covered. The scope must include every activity under your control that can affect OH&S performance; you cannot leave out a hazardous process simply because it is difficult.
Step 3 — Build consultation and participation
Clause 5.4 is the requirement most organisations underestimate. Non-managerial workers must be consulted on matters such as determining needs, setting the policy and objectives and deciding on legal compliance arrangements, and must participate in hazard identification, risk assessment, determining controls and investigating incidents. The standard also expects you to remove barriers to participation — fear of reprisal, language, literacy, or simply not being given the time.
Step 4 — Identify hazards and assess risks
Clause 6.1.2 requires an ongoing, proactive process for hazard identification. It must consider routine and non-routine activities, human factors, how work is organised, past incidents, emergencies, people beyond the workforce, changes in knowledge and information about hazards, and work-related hazards outside the workplace, such as travel or work at client sites. Psychosocial hazards — workload, working hours, harassment — are within scope too.
Assess the resulting risks with a method you can apply consistently, and also identify OH&S opportunities: chances to adapt work to workers, eliminate hazards or improve the working environment.
Step 5 — Determine legal and other requirements
Build a register of the legal requirements that apply to your hazards and operations, and of any other requirements you have committed to, such as customer codes or industry standards. In India this typically means the Occupational Safety, Health and Working Conditions Code, 2020 and the rules made under it, along with sector-specific and state requirements — and for some sites, earlier laws such as the Factories Act, 1948 that the Code consolidates. Check which provisions apply to each of your sites; a register copied from another organisation is a common source of findings. Clause 9.1.2 then requires you to evaluate compliance periodically and keep evidence of the results.
Step 6 — Apply the hierarchy of controls
Clause 8.1.2 requires controls to be chosen in a defined order of preference. Lower levels are only acceptable when higher ones are not reasonably practicable:
- Eliminate the hazard
- Substitute with less hazardous processes, operations, materials or equipment
- Use engineering controls and reorganise work
- Use administrative controls, including training
- Use adequate personal protective equipment
Auditors frequently find risk assessments where every control is training or PPE. That is a sign the hierarchy has not been applied, and it is one of the most common ISO 45001 nonconformities.
Step 7 — Set objectives and plan operational controls
Set measurable OH&S objectives at relevant functions and levels, with owners, resources and dates. Then put operational controls in place: safe systems of work, permits to work for high-risk tasks, management of change (clause 8.1.3), procurement and contractor controls (clause 8.1.4), and emergency preparedness and response (clause 8.2), including periodic drills and a review of how they went.
Step 8 — Train, communicate and document
Determine the competence each role needs, including the ability to identify hazards, and close the gaps. Make sure workers know the policy, the hazards relevant to them, the outcome of incident investigations and their right to remove themselves from situations they reasonably believe present an imminent and serious danger. Keep documented information in proportion — enough to show that processes are carried out as planned, not a manual nobody reads.
Step 9 — Report, investigate and improve
Establish a process to report and investigate incidents, near misses and nonconformities, determine root causes, take corrective action and review its effectiveness (clause 10.2). Monitor performance against objectives, run internal audits across the whole scope, and hold a management review. These records are what an auditor needs to see before certification.
Step 10 — Prepare for certification
- Operate the system long enough to generate records across the scope
- Complete a full internal audit cycle and a management review
- Close or progress the actions arising from both
- Confirm your legal register and compliance evaluation are current
- Apply to an accredited certification body for the Stage 1 and Stage 2 audits
If you already hold ISO 9001 or ISO 14001, much of the system structure — document control, internal audit, management review, corrective action — can be shared, and an integrated audit may reduce the total audit time. Request a quote from GMSCPL with your sites and headcount and we will explain the audit duration and timeline for ISO 45001 certification.