[email protected]
ISO Standards

How to Implement ISO 45001: Where to Start

September 26, 20267 min read

ISO 45001 is the international standard for occupational health and safety management systems. Published in 2018, it replaced OHSAS 18001. For companies starting from scratch, the hardest part is knowing where to begin. Here is a practical order of work.

1. Start With a Gap Assessment

Most manufacturers already have safety programs driven by OSHA requirements. A gap assessment compares what you already do against each ISO 45001 clause, so you build on existing programs instead of starting over.

2. Understand Your Context (Clause 4)

Identify internal and external issues that affect safety performance, the needs of workers and other interested parties, and the scope of the system. The 2024 amendment added a requirement to consider whether climate change is a relevant issue.

3. Secure Leadership and Worker Participation (Clause 5)

ISO 45001 goes further than many standards on people. Top management must take overall responsibility and accountability (5.1), and the organization must consult and involve non-managerial workers (5.4) in decisions such as hazard identification, incident investigation, and determining training needs. This is not optional and auditors test it by talking to workers.

4. Identify Hazards and Assess Risk (Clause 6)

Build a process for ongoing hazard identification, including routine and non-routine activities, human factors, and changes. Determine legal requirements and set measurable objectives.

5. Build Support and Operational Controls (Clauses 7 and 8)

Define competence and training, communication, and documented information. Apply the hierarchy of controls (8.1.2), manage change (8.1.3), control contractors and procurement, and prepare for emergencies.

6. Measure, Audit, and Improve (Clauses 9 and 10)

Monitor performance, evaluate compliance, run internal audits, hold management review, and investigate incidents and nonconformities for root cause.

7. Certification

Certification is performed by an accredited certification body in two stages: a Stage 1 review of readiness and documentation, followed by a Stage 2 audit of implementation. Before Stage 1, you should have completed at least one internal audit cycle and a management review.

Common Mistakes

  • Buying a template manual that does not match how the site actually works
  • Treating worker participation as a signature on a form
  • Rushing to certification before the system has run long enough to produce records

Related reading: ISO 45001 vs OSHA: What's the Difference?

How Compliance Fortress Solves This: The Exceleor Path

  1. Discovery: understand the problem, measure where things stand today, and agree on what success looks like.
  2. Define the engagement path: most organizations don't know the path. We do. A proven method, tailored to your situation.
  3. Training: bring your people to a clear understanding of the requirements.
  4. Implement and engage: carry out the work jointly, with your people involved from day one.
  5. Verify: confirm the work was done and meets the requirement.
  6. Validate: confirm the original problem is actually solved, measured against the success measures from Discovery.
  7. Transfer ownership: we collaborate throughout, so your team can run it without us.
  8. Sustain and grow: we stay close, check in, and catch the next need early. We're here to make sure you succeed.

Is this your situation? See how we approach it on the AI for Safety and ISO 45001 page, or request a Situation Review. You can also email [email protected].

Need an EHS Audit?

Veteran-led, certified lead auditors covering ISO 14001, ISO 45001, RC14001, CFATS and more. Get a tailored proposal within 24 hours.

Request Your Assessment

Free EHS Compliance Checklist

Download our 50-point EHS Audit Readiness Checklist — the same framework our auditors use.

Download Free Checklist

Fortify Your Compliance Today

Don't wait for an audit finding to reveal your gaps. Partner with the Southeast's most comprehensive EHS and security audit team.