Security standard

ISO 45001

ISO 45001 is the international standard for occupational health and safety (OH&S) management. It defines the requirements for a system whose purpose is to prevent work-related injury and ill health and to provide safe and healthy workplaces — and it can be certified by independent bodies.

Start assessmentRead about the standard
36
controls in Guardiso
27
free-test questions
PL · EN
two languages

What is ISO 45001?

ISO 45001:2018 is the first ISO standard for occupational health and safety management systems, published in March 2018. It replaced the British OHSAS 18001 standard — the migration period for certified organisations ended in September 2021, and OHSAS 18001 has been withdrawn since. In Poland the standard has been adopted by the Polish Committee for Standardization as PN-ISO 45001.

The standard is built on the common ISO framework (the High Level Structure, also known as Annex SL) — the same one that underpins ISO 9001, ISO 14001 and ISO 27001. The requirements span clauses 4-10: organisational context, leadership and worker participation, planning, support, operation, performance evaluation and improvement. Thanks to the shared structure, an OH&S system integrates easily with other management systems into a single integrated system.

In February 2024 ISO published amendment ISO 45001:2018/Amd 1:2024 (the “climate amendment”): the organisation must determine whether climate change is a relevant issue for its OH&S system — for example heat stress, air quality or extreme weather events affecting workers. The amendment applies to all certified organisations.

Who is it for?

ISO 45001 certification is voluntary and open to any organisation regardless of size or industry — the standard covers “workers” in the broad sense: including temporary staff, contractors and anyone working under the organisation’s control. It is most often implemented by manufacturing, construction, logistics, energy, utilities and field-service companies, but increasingly also by office-based organisations that want to manage ergonomics and psychosocial hazards systematically.

In practice the certificate is often required in tenders (especially construction and industrial), in the supply chains of large corporations, and in contractor prequalification. Importantly, ISO 45001 does not replace labour law — statutory OH&S obligations and labour inspectorate oversight remain independent of the certificate. The standard helps you meet and evidence those obligations systematically.

What makes ISO 45001 distinctive?

Compared with other management system standards, ISO 45001 places exceptional emphasis on worker consultation and participation (clause 5.4): non-managerial workers must genuinely take part in hazard identification, risk assessment, incident investigation and system development — and the organisation must remove barriers to participation and protect those who report concerns from reprisals.

The second pillar is the hierarchy of controls (clause 8.1.2): when reducing risk, elimination of the hazard and substitution come first, then engineering and administrative controls, with personal protective equipment only as the last resort. The standard also requires management of change (8.1.3), control of contractors and procurement (8.1.4), and emergency preparedness and response (8.2) — including the obligation to test plans in drills.

What does certification look like?

The certificate is issued by an independent, accredited certification body (for example TÜV, BSI, DNV, Bureau Veritas). The certification audit has two stages: Stage 1 is a documentation and readiness review (scope, OH&S policy, hazard identification and risk assessment, the legal register), and Stage 2 is the implementation audit — the auditor visits workplaces, interviews workers and management, and verifies through sampling that the system genuinely works.

The certificate is valid for 3 years, with annual surveillance audits and full recertification before the end of the cycle. A distinctive feature of OH&S audits: the auditor spends significant time in the field — on the shop floor, construction site or in the warehouse — talking to frontline workers, not only the safety department. Evidence of worker participation, tested emergency plans and real application of the hierarchy of controls is checked in practice, not in a binder.

How long does it take and what does it cost?

Implementing an OH&S management system typically takes 4 to 9 months. Organisations already meeting their legal obligations (occupational risk assessments, training, health surveillance, workplace measurements) have a solid starting point — but the standard requires a management layer on top: context, objectives, worker consultation, internal audits and management review. Schedule the audit once the system has produced its first evidence: a practised evacuation, closed post-incident actions, consultation minutes.

Cost depends on headcount, the number of sites and the risk level of the industry — audit days increase with employment and hazard complexity. The budget includes the certification audit, annual surveillance audits, an optional consultant and your own team’s time — which for small and medium companies is usually the biggest item. Automating documentation, recurring tasks and evidence collection genuinely reduces that cost.

How does Guardiso help?

Guardiso guides you through the ISO 45001 implementation from the first self-assessment to the certification audit — and keeps the system alive after certification.

  • All 36 requirements of the standard (clauses 4.1-10.3) seeded automatically when you enable it — with descriptions, implementation statuses and assigned owners.
  • A risk register tailored to OH&S hazards — hazard identification, risk assessment, treatment plans and tracking of control implementation.
  • An incident register for reporting accidents and near misses, with root cause analysis and corrective actions.
  • Recurring tasks that guard deadlines: refresher training, evacuation drills, risk assessment reviews, workplace measurements, management reviews.
  • Policies and procedures generated from templates, with versioning and management approval.
  • Compliance evidence collected in one place — drill reports, training records, worker consultation minutes — ready to show the auditor.
  • Cross-mapping to other standards sharing the common structure (ISO 9001, ISO 14001, ISO 27001) — shared system elements are done once.
Official sources
01Select standard›02Complete the self assessment›03Close gaps in Guardiso
—
ISO 45001 readiness score
0/27 answered
The score updates live as you answer.

Other standards to assess

ISO 27001GlobalGDPREUNIS 2 (Polish KSC act)EU · PLSOC 2GlobalDORAEUTISAXAutomotiveISO 9001GlobalISO 42001 (AI)GlobalKRIPLPCI DSSGlobalNIST CSFUSANIST 800-53USAHIPAAUSACMMC 2.0USACyber EssentialsUKSOX ITGCUSABIO2NLEU AI ActEUISO 27701GlobalISO 22301GlobalISO 14001GlobalISO 13485MedicalIEC 62304MedicalMDREU · MedicalISO 14971MedicalDCB0129UKMiCAEUIEC 62443GlobalISO 21434Automotive
Browse all 30 standards