Beta

The Scope is in beta, and we're publishing new articles every day for the coming month. Read about us. Send us feedback at .

TheScope

The QHSE, CSR & Supply Chain magazine

Industries Construction, Transport & Logistics

ISO 45001 from a standing start: what the first six months look like

ISO 45001 asks you to run health and safety as a system. What the first six months actually contain, what you can skip, and the failure mode auditors spot fastest.

Summarize with AILe ChatChatGPTClaude
A worker in a high-visibility vest walking a marked aisle on a factory floor
On this page
  1. What the standard actually requires
  2. What the first six months contain
  3. What you can skip
  4. The failure mode worth naming

The auditor will not start with your binders. They will walk to a workstation and ask an operator how a near miss gets reported.

That is the whole standard in one question. ISO 45001 replaced OHSAS 18001 as the international standard for occupational health and safety management systems, and if your customers or your insurer have started asking for it, the question on the table is not whether your workplace is safe. It is whether you can show a system that identifies hazards, controls them, and improves, and whether the people doing the work are inside that system.

What the standard actually requires

The structure follows the same high-level format as ISO 9001 and ISO 14001, which matters if you already hold either: the context, leadership, planning, support, operation, performance evaluation and improvement clauses will look familiar, and some documentation can be shared.

Four requirements do most of the work.

Context and interested parties. Who is affected by your OHS performance, and what they require of you. For a construction firm that includes subcontractors on your sites; for a logistics operator it includes drivers who are not your employees.

Hazard identification and risk assessment. A documented, repeatable process covering routine and non-routine activities, including how work is actually organized. This is where auditors spend most of their time.

Worker consultation and participation. ISO 45001 is unusually specific here. Non-managerial workers must be consulted on hazard identification, on incident investigation and on the OHS policy itself, and barriers to their participation must be removed. What gets audited is the evidence of the consultation, not the assertion that it happens.

Operational planning and control, including emergency preparedness and the control of procurement and contractors.

What the first six months contain

Weeks 1 to 4: scope and gap. Decide the scope precisely, by site and activity, then compare what exists against the clauses. The gap analysis usually lands on the same finding: the operational work already happens, and the documented process around it does not.

Weeks 4 to 10: the risk assessment process. Not the assessments themselves yet, the process: who identifies hazards, when, how they are rated, how controls are chosen, how the result is recorded and reviewed. Apply the hierarchy of controls (elimination, substitution, engineering, administrative, personal protective equipment) explicitly, in that order, because the standard expects it.

Weeks 8 to 16: participation and competence. Set up the consultation mechanism and record it. Map required competences to roles and record the training behind them, with dates and a completion rate.

Weeks 12 to 20: legal register and operational controls. A maintained list of applicable OHS requirements and how you meet each one. Emergency procedures tested, not merely written.

Weeks 18 to 26: internal audit and management review. You need at least one full internal audit cycle and one management review before a certification body finds enough to assess. This is the part most often compressed, and the part auditors read most closely.

What you can skip

A new document management system. Use what you have. The standard requires documented information under control, not a particular tool.

Rewriting procedures that work. A method statement in daily use that reflects real practice is better evidence than a rewritten one nobody follows.

Certifying everything at once. Scope one site, get the system running, then extend. A narrow scope certified honestly is worth more than a broad one that fails.

The failure mode worth naming

The most common way a first attempt goes wrong: the system gets built as a documentation project on the side, by one person, and never touches how work is planned on Monday morning. Auditors detect this quickly, because they interview workers. If the people doing the job have not heard of the risk assessment process, the certificate is not the problem you have.

So start from what your supervisors already do to keep people safe, write that down accurately, and fix the parts that turn out to be missing. That takes about six months on one site, and it produces a system that survives the audit for the only durable reason: it is the one you actually use.

More in QHSE