ISO 45001 Certification
Occupational Health and Safety Management System
Quick Answer
ISO 45001:2018 is the international standard for occupational health and safety management systems (OH&S), certifying that an organization prevents work-related injury and ill health through a structured, auditable management system, hazard identification, risk assessment, worker consultation, incident investigation, rather than reactive, paperwork-driven safety compliance. It follows the same Harmonised Structure as ISO 9001 and ISO 14001, making it straightforward to integrate for organizations already certified to those standards. Certification is issued by an accredited certification body after an audit, and most organizations complete implementation and certification in three to five months.
What ISO 45001 Certification Actually Certifies?
ISO 45001 certification confirms an organization’s occupational health and safety (OH&S) management system has been independently audited against ISO 45001:2018 and found to conform. It replaced OHSAS 18001 as the internationally recognized OH&S management standard, and the shift was more than a rename: ISO 45001 is built on the same Harmonised Structure as ISO 9001 and ISO 14001, explicitly requires top management leadership and accountability for OH&S outcomes (Clause 5.1) in a way OHSAS 18001 left more optional, and places far greater formal weight on worker participation and consultation, Clause 5.4 requires documented mechanisms for workers, including non-managerial staff, to participate in hazard identification, incident investigation, and OH&S policy development, not just receive safety instructions from above.
Certification does not mean an organization has eliminated workplace risk, no standard can promise that. It means the organization has a documented, functioning system for identifying hazards, assessing and controlling risk through the hierarchy of controls, investigating incidents to find root causes, and demonstrably improving over time. Certification bodies accredited under UKAS, ANAB, SAAC, DAkkS, JAS-ANZ, and equivalent national accreditation bodies within the IAF framework issue the certificate after independently verifying this system is operating, not just documented.
What are the steps to get ISO 45001 Certification?
our services
- ISO 9001 Certification
- ISO 14001 Certification
- ISO 27001 Certification
- ISO 22000 Certification
- ISO 45001 Certification
- ISO 13485 Certification
- ISO 20000 Certification
- ISO 17025 Certification
- CE Mark Certification
- GMP Certification
- Halal Certification
- SOC Certification
ShineCert's 5-Step ISO 45001 Certification Process
Gap Analysis and Scope Definition
ShineCert reviews current safety practices and defines OH&S scope, which sites, activities, and worker categories are included, against ISO 45001 requirements.
Gap assessment report and defined OH&S scope.
Hazard Identification and Risk Assessment
The Occupational Health and Safety Policy, hazard identification and risk assessments covering site-specific and activity-specific risks, and required procedures across Clauses 4 through 10 are developed.
Complete OH&S documentation set and hazard risk register.
Implementation and Worker Training
Operational controls, permit-to-work systems, emergency preparedness procedures, are rolled out, and workers are trained on their specific safety responsibilities, including genuine worker consultation and participation.
Training records and operational implementation evidence.
Internal Audit and Management Review
An internal audit against ISO 45001 requirements is conducted, followed by a formal Management Review evaluating safety performance and risk register accuracy.
Internal audit report and management review minutes.
Certification Audit Support
ShineCert supports Stage 1 and Stage 2 audits with your chosen accredited certification body, including site visits to locations and activities in scope.
ISO 45001:2018 certificate and surveillance audit schedule.
Gap Analysis and Scope Definition
ShineCert reviews current safety practices and defines OH&S scope, which sites, activities, and worker categories are included, against ISO 45001 requirements.
Gap assessment report and defined OH&S scope.
Hazard Identification and Risk Assessment
The Occupational Health and Safety Policy, hazard identification and risk assessments covering site-specific and activity-specific risks, and required procedures across Clauses 4 through 10 are developed.
Complete OH&S documentation set and hazard risk register.
Implementation and Worker Training
Operational controls, permit-to-work systems, emergency preparedness procedures, are rolled out, and workers are trained on their specific safety responsibilities, including genuine worker consultation and participation.
Training records and operational implementation evidence.
Internal Audit and Management Review
An internal audit against ISO 45001 requirements is conducted, followed by a formal Management Review evaluating safety performance and risk register accuracy.
Internal audit report and management review minutes.
Certification Audit Support
ShineCert supports Stage 1 and Stage 2 audits with your chosen accredited certification body, including site visits to locations and activities in scope.
ISO 45001:2018 certificate and surveillance audit schedule.
What Is ISO 45001?
ISO 45001:2018 specifies requirements for establishing, implementing, maintaining, and continually improving an occupational health and safety management system, covering hazard identification, risk assessment and control, worker consultation and participation, and incident investigation across the full range of an organization’s activities and worksites. It applies equally to office-based organizations and high-hazard industrial operations, and its Harmonised Structure makes integration with ISO 9001, ISO 14001, or ISO 41001 relatively straightforward for organizations pursuing multiple certifications.
ISO 45001 Certification Cost
Cost is driven heavily by hazard complexity and site count, a single low-risk office certifies faster and cheaper than a multi-site industrial operation with elevated hazard classifications, since both consulting effort and certification body audit time scale with genuine risk complexity, not just headcount. Combining ISO 45001 with ISO 9001 and ISO 14001 as an integrated QHSE system typically reduces total cost meaningfully versus three separate certification projects, since context analysis, leadership commitment, and management review can be run once rather than three times.
ISO 45001 and Client Prequalification Requirements
A certified OH&S system gives an organization a structured internal system, but the client-facing prequalification questionnaire or site safety induction requirement remains a separate commercial artifact, the two need to align, since a prequalification response promising safety performance the internal OH&S system can’t actually evidence creates a credibility gap the moment a site audit or incident investigation happens. ShineCert reviews common client prequalification and site-access requirements alongside OH&S design specifically to confirm the internal system can genuinely back up what’s being commercially represented, since a beautifully documented OH&S system that doesn’t match real site conditions satisfies an auditor but not a principal contractor’s safety team.
Mandatory Documented Information for ISO 45001
At minimum: OH&S policy and objectives; legal and regulatory requirements register; hazard identification and risk assessment records; documented worker participation and consultation mechanism; emergency preparedness and response plans with testing evidence; incident investigation records with root-cause analysis; internal audit program and reports; and management review records.
The Structure of ISO 45001: Clauses Explained
- Clause 4 — Context of the Organization : Requires defining OH&S scope, which sites, activities, and worker categories, including contractors and visitors, are covered, and identifying worker and other interested party needs.
- Clause 5 — Leadership and Worker Participation : Requires top management commitment to safety and genuine mechanisms for worker consultation and participation, not token representation.
- Clause 6 — Planning : Requires systematic hazard identification, risk and opportunity assessment, and setting OH&S objectives tied to actual site conditions.
- Clause 7 — Support : Covers resources, competence of safety-critical staff, communication, and documented information requirements.
- Clause 8 — Operation : The technical core, covering operational planning and control, management of change, procurement and contractor management, and emergency preparedness and response.
- Clause 9 — Performance Evaluation : Requires monitoring and measurement of safety performance, internal audit, and management review.
- Clause 10 — Improvement : Requires incident investigation, corrective action, and continual improvement of the OH&S system.
ISO 45001 and Integrated Management Systems — How They Connect
ISO 45001 shares the Harmonised Structure with ISO 9001, ISO 14001, and ISO 41001, meaning organizations already certified to those standards can integrate occupational health and safety requirements into an existing management system framework rather than building a parallel one. This matters practically for construction and industrial contractors who often need to demonstrate quality, environmental, and safety competence simultaneously to win large tenders, a single integrated audit cycle covering all applicable standards is both more efficient and more coherent for auditors evaluating the whole operation than separate, disconnected certification projects.
Benefits of ISO 45001 Certification
Certification opens access to prequalification lists and tenders that require a certified OH&S management system as an entry condition, a common gatekeeping requirement in construction, manufacturing, and government contracting.
Fewer disruptive stoppages result from proactively managed hazards, supported by clearer accountability for site safety across roles and levels.
A structured hazard identification and risk assessment process helps catch unsafe conditions before they lead to an incident, rather than triggering a response only after one occurs.
Genuine worker consultation that improves reporting of near-misses and unsafe conditions, rather than encouraging staff to suppress or underreport them.
Measuring OH&S Performance: Leading and Lagging Indicators
- A genuinely functioning ISO 45001 system tracks both lagging indicators, lost-time injury rate, total recordable incident rate, days away from work, and leading indicators that predict problems before an injury occurs: near-miss reporting rates, the percentage of scheduled safety inspections actually completed, hazard closure time (how long it takes from a hazard being reported to being controlled), and worker participation rates in safety committees or toolbox talks. Organizations that track only lagging indicators are, by definition, only finding out about safety failures after someone has already been hurt; the near-miss reporting rate in particular is one of the more reliable single indicators of whether a safety culture is genuinely open or whether workers are quietly not reporting hazards for fear of blame. A mature ISO 45001 implementation sets targets for leading indicators specifically, not just a target of “zero incidents” for the lagging ones, since a zero-incident target with no supporting leading-indicator data can mask under-reporting rather than genuine safety performance.
- Clause 9.1 requires this monitoring and measurement to be planned, what will be measured, by what method, when, and by whom, rather than assembled retrospectively for the management review meeting. Data quality matters here: an incident classification system that inconsistently distinguishes a recordable incident from a first-aid case will produce lagging-indicator trends that don’t reflect reality, undermining the very risk-based decisions Clause 6.1 is meant to support.
ISO 45001 vs. OHSAS 18001: Why the Change Matters
- Organizations still holding an OHSAS 18001 certificate, a legacy standard formally withdrawn in March 2021, are not currently certifiable to it at all; any OHSAS 18001 certificate still in circulation is no longer valid under IAF recognition. The substantive differences that made ISO 45001 a genuine advance rather than a rebrand are worth understanding on their own terms. First, ISO 45001 requires top management to take direct, demonstrable accountability for OH&S outcomes under Clause 5.1, rather than allowing safety to be delegated entirely to a safety manager while leadership stays a step removed. Second, worker participation under Clause 5.4 is a formal, auditable requirement, not a best-practice suggestion, auditors now expect to see and interview genuine worker representatives, not just review a safety policy signed by management. Third, ISO 45001 embeds risk-based thinking consistent with the Harmonised Structure shared with ISO 9001 and ISO 14001, meaning organizations pursuing multiple certifications can run one integrated risk methodology rather than maintaining separate, incompatible risk frameworks for quality, environment, and safety. Fourth, the standard explicitly addresses psychosocial risk and worker wellbeing as within its scope, a dimension OHSAS 18001 didn’t meaningfully cover, reflecting a broader shift in how occupational safety is understood internationally
- For an organization that previously held OHSAS 18001 and is now re-certifying, this means a genuine gap assessment against the new clauses is necessary — treating the transition as a formality and simply re-issuing the same documentation under a new cover page is one of the more common mistakes ShineCert sees in organizations attempting a self-managed migration.
Who Actually Needs ISO 45001 Certification?
Situation | Why ISO 45001 Applies |
Construction, manufacturing, or industrial operations | Elevated injury risk profile makes a formal OH&S management system both a safety and a commercial necessity |
Bidding for tenders in construction, oil & gas, or infrastructure | Public and major-project tenders increasingly score ISO 45001 into technical qualification alongside ISO 9001 and ISO 14001 |
Operating across multiple sites with varied hazard profiles | A documented, auditable OH&S system ensures the same safety standard holds across every location, not just the ones under closest management attention |
Responding to a serious incident or regulatory scrutiny | Formal hazard identification and incident investigation discipline reduces recurrence risk and demonstrates due diligence |
Insurance and liability considerations | Some insurers offer more favorable terms to ISO 45001-certified organizations, reflecting the lower incident risk a functioning OH&S system represents |
Region- and Sector-Specific Considerations
- Enforcement of underlying occupational safety law varies meaningfully by jurisdiction even though ISO 45001 itself is internationally uniform, a certified OH&S management system still needs to be built around the specific legal and regulatory OH&S requirements of the country and sector it operates in, which is why Clause 6.1.3 (compliance obligations) is not a boilerplate section but one requiring genuine jurisdiction-specific legal research.
- Organizations operating across multiple countries under one ISMS scope need a single system flexible enough to satisfy the strictest applicable jurisdiction’s legal requirements while remaining genuinely one coherent management system, not a patchwork of jurisdiction-specific side documents that auditors struggle to assess coherently.
Technology and Safety Management Systems
- Modern occupational safety relies on digital permit-to-work systems, wearable sensors monitoring fatigue or gas exposure, and incident-reporting apps. ISO 45001 certification must account for how these technologies fit within the broader OH&S system, rather than treating them as a separate IT concern. A digital permit system is only as valuable as the discipline behind verifying conditions before work starts. Auditors increasingly want to see genuine system data, near-miss reporting rates, permit closure times, and recurring hazard patterns, rather than a policy document describing how the system is supposed to work.
- Organizations that invest in safety technology without the process discipline to use it consistently often find the investment doesn’t translate into the incident reduction it promised. Closing that gap is exactly what a well-designed OH&S system does, by tying technology adoption to genuine operational accountability.
Ready to scope your 45001 certification project? Book your free consultation or contact ShineCert directly.
Book Free ConsultationReady to scope your 45001 certification project? Book your free consultation or contact ShineCert directly.
Book Free ConsultationWhy Choose ShineCert for ISO 45001 Certification?
ShineCert has guided more than 10,000 organizations through ISO certification from genuine operating offices in Riyadh, Lebanon, and India, with meaningful experience implementing ISO 45001 in construction, industrial, and logistics environments where hazard complexity is real, not theoretical. We build worker participation mechanisms that function in practice, not just on paper, because that’s specifically what separates a certificate that survives surveillance audits from one that doesn’t.
Choosing an Accredited Certification Body
Confirm current ISO 45001 accreditation and, specifically, sector experience relevant to your hazard profile, an auditor experienced in office-based low-risk environments will assess a construction site or manufacturing floor less effectively than one with genuine industrial safety audit background.
Factor | Why It Matters |
Current IAF-recognized ISO 45001 accreditation | Ensures the certificate is internationally recognized |
Sector-specific hazard experience | Determines audit quality for higher-risk industrial or construction environments |
Multi-site audit capability | Relevant for organizations with varied hazard profiles across locations |
Willingness to conduct genuine site visits, not desk-based review alone | OH&S conformity can’t be meaningfully assessed without observing actual site conditions |
Common Implementation Challenges
- Worker participation that exists on paper but not in practice : Auditors interview workers directly, and a safety committee that never actually meets or a hazard-reporting process nobody uses is a near-certain finding.
- PPE-first thinking instead of the hierarchy of controls : Defaulting to personal protective equipment without first genuinely considering elimination, substitution, or engineering controls is a common and significant nonconformity.
- Contractor and visitor safety gaps : Organizations often manage employee safety well but under-document how contractors and visitors are inducted, monitored, and included in emergency procedures.
- Incident investigation that stops at the immediate cause : Fixing the specific trip hazard without asking why the walkway wasn’t inspected on schedule misses the systemic root cause Clause 10.2 expects investigation to reach.
- Emergency plans that have never been tested : A documented emergency response plan that’s never been drilled is a paper exercise, not a functioning control, auditors increasingly ask for drill records, not just the plan document.
Frequently Asked Questions
ISO 45001 certifies your occupational health and safety management system against an internationally recognized standard. It’s typically essential for higher-hazard industries and increasingly required in tender technical scoring; lower-risk businesses can benefit but face less external pressure to certify immediately.
It depends heavily on hazard complexity and site count. ShineCert provides a fixed quote after scoping your specific operation.
Most organizations move from kickoff to certificate in three to six months, depending on hazard complexity and existing safety program maturity.
Yes, this integrated QHSE approach is common and typically more cost-efficient than three separate certification projects.
No certification eliminates all risk. It certifies a functioning system for identifying hazards, controlling risk, and investigating incidents, organizations that treat it as a genuine operating system, not a paperwork exercise, see real safety improvement.
ISO 45001 itself is a voluntary international standard, not a legal requirement in most jurisdictions. It becomes effectively mandatory when a tender, major client, or insurer specifically requires it as a condition of doing business, which is increasingly common in construction, oil and gas, and industrial sectors.
