ISO 45001 certification: a practical guide for QEHS teams
Everything you need to know about ISO 45001 certification — the 10 clauses, the audit process, evidence collection, and how to avoid the 5 most common nonconformities.
QEHS Ethos Team
Founding team
The QEHS Ethos Team built the QEHS platform after a decade managing EHS programs in heavy industry. We write about safety culture, regulatory strategy, and how software can get out of the way.
12 min read
Reviewed by QEHS Ethos Team — Founding team
ISO 45001:2018 is the international standard for occupational health and safety management systems. It replaced OHSAS 18001 and follows the Annex SL structure shared by ISO 9001 and ISO 14001 — making integration across quality, environment, and safety straightforward.
Clause 4 (Context) is where most audits find their first nonconformity. Clause 5 (Leadership) requires demonstrable top management commitment. Clause 6 (Planning) requires documented risk assessments. Clause 8 (Operation) covers day-to-day controls. Clause 9 (Performance Evaluation) mandates monitoring and internal audit. Clause 10 (Improvement) closes the loop with CAPA. See the evidence collection guide.
For more, see the ISO 45001, internal audit, and management review glossary entries.
The ten clauses are the spine of the standard, and the audit reads them in order. Clause 4 asks the organization to determine its context — the external and internal issues that affect its OH&S, the interested parties, and the scope — and a context review that names no issues is the first finding. Clause 5 asks for leadership commitment, OH&S policy, and roles, and the commitment that is on the policy and not in the calendar is the finding. Clause 6 asks for hazard identification, risk assessment, legal requirements, and objectives, and the risk register that is a list of hazards without an evaluation is the finding. Clause 7 is support — resources, competence, awareness, communication, documented information. Clause 8 is operation — operational planning, management of change, procurement, contractors, emergency preparedness. Clause 9 is performance evaluation — monitoring, internal audit, management review. Clause 10 is improvement — incident, nonconformity, corrective action, continual improvement. The ten clauses are a loop, not a list, and the audit reads whether the loop closes.
The certification process runs in two stages and on a three-year cycle, and the cycle is the one a platform holds. Stage one is a document review — the auditor reads the management-system documentation, the scope, and the processes, and identifies gaps before the on-site audit. Stage two is the on-site audit — the auditor reads the implementation, interviews workers, observes work, and traces evidence from the policy through to the records. The initial certification is followed by annual surveillance audits (which sample a subset of clauses) and a recertification audit at the end of the three-year cycle (which samples the whole). A platform that holds the evidence against the clause map produces the stage-one document set and the stage-two traceable records from the same tenant, and the certification body that audits every year reads the same system of record.
Evidence collection is the activity the platform makes cheap, and it is the one that decides whether the audit is a confirmation or a discovery. The evidence the auditor needs is, for each clause, a policy that states the requirement, a procedure that operationalises it, a record that demonstrates it, and an audit trail that links them. The platform that holds the policy, the procedure, and the record on one tenant with the links between them produces the evidence in a query; the program that holds the policy in a document system, the procedure in a shared drive, and the record in a spreadsheet produces the evidence in a week of email, and the week is the gap during which the audit is a discovery. The evidence that is collected at the audit and not before is the evidence that does not hold up under a finding.
The five common nonconformities are the ones the auditor reaches for first, and they are the ones the platform closes before the audit. The first is a hazard identification that does not cover the full scope or the full lifecycle — the hazards that are missing are the hazards that produce the incident the audit did not prevent. The second is a risk assessment that is a matrix without an evaluation — the likelihood and severity are filled in, but the controls are not linked and the residual risk is not re-evaluated. The third is an internal audit that does not cover the whole system — the easy areas are audited every cycle and the difficult ones are never. The fourth is a management review that does not take the standard inputs — the meeting happens, but the audit results and the corrective-action status are not in the minutes. The fifth is a corrective-action system that closes actions without verification — the count of closed CAPAs rises and the verified-CAPA rate is not measured. The five are the five a platform turns into workflows and reports, and the five are the ones a paper program re-discovers at every audit.
- Map the management-system documentation to the ten clauses, so every policy and procedure is tagged with the clause it satisfies and the audit reads the documentation by clause.
- Hold the evidence — the policies, the procedures, the records, the audit trails — on one tenant with the links between them, so the auditor traces from the policy to the record in one query.
- Schedule the internal audit programme against the clause map on a cycle that covers the whole system, with auditors rotated across areas, so the surveillance audit finds the whole system audited.
- Structure the management review against the 9.3 inputs, so the review takes the audit results, the objective achievement, and the corrective-action status by default and not by request.
- Run the CAPA system with a verification step, so the verified-CAPA rate is the measure and the corrective-action count is not the only number.
The certification body is the other decision, and it is the one the market reads. A body accredited under the IAF Multilateral Recognition Arrangement (ANAB in the United States, UKAS in the United Kingdom, and the equivalents elsewhere) is a body whose certificate is recognised across borders; a body without that accreditation is a body whose certificate is a document. The scope on the certificate is the part to read — a scope that names the sites and activities the system covers is a scope a customer can rely on, and a scope that reads broadly is a scope that covers whatever the auditor did not exclude. For more, see the ISO 45001, internal audit, and management review glossary entries; for the audit-readiness gaps the auditor finds first, the ISO 45001 audit prep post, and for the integrated system, the what is a QEHS management system post.
The migration from OHSAS 18001 to ISO 45001 is the one many systems still have not finished, and it is the one the audit reads as a gap. ISO 45001:2018 replaced OHSAS 18001, and the transition closed; a system still certified to OHSAS 18001 is a system whose certificate is no longer valid, and the recertification to 45001 is the one that requires the context review, the worker participation, and the management of change that 18001 did not ask for. The migration is not a re-issue; it is a re-build of the management system against the Annex SL structure, and the platform that models the data against the ten clauses is the platform that makes the migration a configuration and not a project.
The audit programme is the schedule the surveillance audit reads, and it is the one a platform runs without a scramble. A three-year cycle has an annual surveillance audit that samples a subset of clauses and a recertification audit at year three that covers the whole system, and the platform that schedules the internal audit against the same clause map is the platform whose surveillance audit finds the year-sampled clauses already audited internally. The audit programme that is on the calendar is the audit programme that does not need a month of preparation, and the audit programme that is in a spreadsheet is the one that the auditor reads as reactive.
The gap analysis is the readiness assessment that precedes the stage-one audit, and it is the one that turns the certification from a pass-or-fail into a plan. A gap analysis reads the current system against the ten clauses and lists the clauses that are met, partially met, and not met, with the evidence for each, and the gaps that are found before the auditor are the gaps that are closed before the auditor. The platform that holds the gap analysis as a clause-by-clause register is the platform where the gaps close against the evidence, and the gap analysis that closes a gap without recording the evidence is the gap that reopens at the audit.