ISO 45001 — Occupational Health & Safety Management

The only one here that changes how you work, not what you show

Get your free website review Talk to us

  • No contract
  • From £29 a month
  • First month free

What ISO 45001 is

ISO 45001 is the international standard for occupational health and safety management systems. Certification runs around £4,500 and works on a three-year cycle rather than an annual one — which by itself tells you it is a different kind of thing from everything else on this page.

Major clients value it, and it can replace or supplement SSIP assessments in some procurement processes. But that is a by-product. The other schemes here ask you to demonstrate that you manage safety. This one specifies a system for managing it and then audits whether the system is actually running.

That distinction is the whole page. CHAS, SafeContractor and Constructionline can, in principle, be satisfied by a well-assembled folder. ISO 45001 cannot, because the audit looks for evidence that the system operated over time — audits conducted, incidents investigated, actions closed out, the legal register reviewed when the law changed.

What certification requires

  • An occupational health and safety policy

    , signed at the highest level, committing to worker health, safety and wellbeing.

  • Hazard identification and risk assessment

    As a systematic process across all activities and locations — not a set of documents but a repeatable method.

  • A legal and regulatory register

    Listing the health and safety legislation that applies to you, reviewed and updated when it changes. This one has no equivalent in the SSIP schemes and is where most of the initial work goes.

  • An incident investigation process

    Documented, covering accidents and near misses, identifying root causes and driving preventive action.

  • An internal audit programme

    , conducted at planned intervals. You audit yourself, on a schedule, and keep the evidence.

  • Stage 1 and Stage 2 certification audits

    Through a UKAS-accredited certification body — Stage 1 reviews the documents, Stage 2 checks that what they describe is what happens.

What you have to keep doing

Annual surveillance audits in years one and two, then re-certification in year three.

Review and act on incidents — accidents, near misses and RIDDOR reports — inside the management system rather than alongside it.

When it is genuinely worth it, and when it is not

This is the one scheme on this site where the honest answer for a lot of readers is “not yet”, so it is worth being straight about where the line falls.

It is worth it when a client requires it, which is the simplest case and increasingly common on large frameworks and in sectors like rail, energy and major public works. If a contract you want names ISO 45001, the calculation is already made.

It is worth it when you have enough people that safety cannot be held in one head. Somewhere above a handful of employees, informal management stops working — not because anyone gets careless, but because the person who knows everything is no longer on every site. A system exists to survive that, and firms that grow through it without one tend to discover the gap through an incident.

It is worth it when your incident record needs a structural answer. A firm with a poor few years and a serious client relationship to repair has a much stronger case with a certified management system than with any number of assurances.

It is not worth it as a badge. At £4,500 and a three-year commitment of real internal effort — internal audits, a maintained legal register, closed-out actions — buying it to look impressive is an expensive way to look impressive, and an SSIP member scheme at a tenth of the price satisfies most buyers who are merely checking.

The three-year cycle changes how you should plan it

Every other scheme here is an annual scramble that resets. This one is a programme, and treating it like an annual submission is why implementations stall.

Year one is the heavy one: writing the system, building the legal register, running the first internal audits so there is something for Stage 2 to look at, then the two certification audits themselves. Trying to compress that into the weeks before a tender does not work, because Stage 2 is specifically looking for a system that has been operating rather than one that has been written.

Years two and three are lighter but not empty — surveillance audits still expect to see the internal audit programme running and incidents being closed out. The failure mode is a firm that certifies, relaxes, and arrives at the year-two surveillance audit with an internal audit programme that has not run since certification.

The practical version: put the internal audits in the calendar for the whole three years on the day you certify, and treat the legal register review as a fixed quarterly task rather than something triggered by hearing about a change. Both are small when scheduled and large when reconstructed.

The mistakes we see most

  • Buying it as a badge.

    An SSIP member scheme satisfies most buyers who are only checking, at a tenth of the cost.

  • Compressing year one into a tender deadline.

    Stage 2 audits a system that has been running, not one that has been written.

  • Letting the internal audit programme lapse after certification.

    It is the first thing the year-two surveillance audit asks for.

  • Treating the legal register as a one-off.

    It is a maintained document, and “reviewed when we heard something changed” is not a review process.

The second standard is much cheaper than the first

Worth knowing before you commit, because it changes the arithmetic.

ISO management system standards share a common high-level structure — the same clauses for context, leadership, planning, support, operation, evaluation and improvement. So a firm that has built the management system for one standard has already built most of the scaffolding for another. Document control, internal audit, management review, corrective action: written once, they serve both.

The practical version is that ISO 9001, the quality standard, becomes substantially cheaper and faster once 45001 is running, and the reverse is equally true. Firms that certify to both in sequence generally find the second cycle a fraction of the first, and certification bodies will usually audit them together, which reduces the audit days too.

That matters commercially because of something on the Constructionline page: Gold membership requires evidence of quality management, and ISO 9001 satisfies that outright. So a firm holding both standards clears the health and safety strand, the quality strand, and a good part of what large clients ask for beyond SSIP, from one management system.

None of which makes it worth starting for a firm that does not need the first one. But if a client has pushed you into 45001 and you were also contemplating 9001, doing them close together is markedly cheaper than treating them as separate projects years apart.

Where this lands in Gaffer

Incidents and near misses are recorded against the job and the person as they happen, with the investigation and the actions attached — which is precisely the evidence chain a surveillance audit follows, and the thing that is impossible to reconstruct afterwards.

Scheduled internal audits and register reviews sit as recurring tasks with owners, because the three-year cycle’s real failure is not a bad audit but a programme that quietly stopped running in month four.

Questions contractors ask

Does it replace CHAS or SafeContractor? For some clients yes, for others no — plenty of procurement systems still want an SSIP dossier specifically. Check before you drop anything.

How long does certification take? Months, and it should. The system has to be operating before Stage 2 can audit it.

Do I need a consultant? Many firms use one for the first cycle. The risk is a system written by somebody else that nobody internally runs, which passes Stage 2 and fails surveillance.

Is ISO 9001 the same thing? No — 9001 is quality, 45001 is health and safety. They share a structure, which is why firms holding one find the second considerably easier.

Get your free website review · Deciding whether it is worth it? Talk to us

Find out what your website is costing you

Put your website in and we'll tell you what's losing you work — speed, mobile, your Google profile, reviews and the pages you're missing. Two minutes, no call unless you want one.

Get your free website reviewSee pricing