ISO 45001

ISO 45001 Gap Analysis: How to Assess Your OHS Management System

An ISO 45001 gap analysis is a structured assessment of an organization's current occupational health and safety practices against the requirements of ISO 45001 — clause by clause — to identify what is in place, what is missing, and what needs to be developed or strengthened before pursuing certification. The output is a prioritized action plan that sequences OHSMS development based on risk and effort.

Most organizations already have some occupational health and safety activity in place — inspections, training records, incident reporting. What they typically lack is the documented management system that ISO 45001 requires. A gap analysis is the tool that maps where an organization currently stands against where the standard requires it to be, and tells you what needs to happen before a certification auditor walks through the door. This article explains what an ISO 45001 gap analysis covers, what the most common gaps look like, and what a well-structured gap analysis output should contain — drawing on the audit and implementation experience of Maria Falbo, a Lead Auditor with decades of ISO 45001 experience.

Maria Falbo|Lead Trainer, Logix ISO|July 2026|8 min read

What an ISO 45001 Gap Analysis Is

An ISO 45001 gap analysis is a diagnostic assessment that compares an organization's current occupational health and safety practices against the requirements of ISO 45001 — clause by clause — to determine what is in place, what is partially in place, and what is missing entirely.

The purpose is not to find fault. It is to give management an accurate, evidence-based picture of how much work needs to be done before the organization is ready for certification — and in what priority order that work should happen. A gap analysis conducted at the right stage prevents organizations from discovering significant deficiencies at the certification audit, where finding them is costly and damaging to the certification timeline.

A gap analysis is distinct from an internal audit. An internal audit assesses whether an implemented OHSMS conforms to requirements and is functioning effectively. A gap analysis assesses the current state of the organization before — or during — implementation, to determine what remains to be built. The two exercises use similar methods — document review, process observation, interviews — but serve different purposes and are conducted at different points in the OHSMS lifecycle. For a detailed explanation of how ISO 45001 internal audits work once the OHSMS is implemented, see our ISO 45001 Internal Audit: The Complete Guide.

What a Gap Analysis Covers

A well-structured ISO 45001 gap analysis covers every clause from Clause 4 through Clause 10. For each clause, the assessment examines what the standard requires, what the organization currently has in place, and what the gap is between the two.

Clause 4 — Context examines whether the organization has documented its internal and external issues, identified its interested parties and their requirements, and defined an appropriate OHSMS scope.

Clause 5 — Leadership examines whether top management has formally committed to the OHSMS through a documented OHS policy, assigned roles and responsibilities, and — distinctively for ISO 45001 — established genuine mechanisms for worker consultation and participation under Clause 5.4.

Clause 6 — Planning is where most organizations have their largest gaps. The hazard identification and risk assessment register is frequently incomplete — missing psychosocial hazards, abnormal and emergency condition scenarios, or failing to reflect recent operational changes. The legal and other requirements register is often underdeveloped, covering major regulations but missing lesser-known obligations. For a full breakdown of how ISO 45001 requires organizations to address risks and opportunities under Clause 6.1, see our guide to how to address risks and opportunities in ISO 45001.

Clause 7 — Support examines competence records, awareness training, communication processes, and document control. Organizations frequently have informal training in place but lack the documented records needed to demonstrate competence.

Clause 8 — Operation examines operational controls for significant hazards and emergency preparedness. The gap analysis looks for controls that exist on paper but are not implemented in practice, and for significant hazards that have no controls at all.

Clause 9 — Performance evaluation examines monitoring and measurement, compliance evaluation records, the internal audit program, and management review. Organizations that have never conducted a formal ISO 45001 internal audit or management review have automatic gaps in this section.

Clause 10 — Improvement examines incident investigation, corrective action processes, and continual improvement — whether there is a documented procedure, whether root cause analysis is being conducted, and whether effectiveness is being verified.

Need expert support conducting an ISO 45001 gap analysis?

Our consulting service covers gap analysis, OHSMS development, internal audit support, and full certification preparation.

Explore Consulting

The Most Common Gaps Organizations Find

Regardless of sector or size, certain gaps appear consistently in ISO 45001 gap analyses.

An incomplete or shallow hazard register is the single most common gap. Organizations often have a register that covers obvious physical hazards but is thin or absent on psychosocial hazards, non-routine activities, and emergency scenarios. For a full breakdown of what a credible hazard identification process requires, see our guide to ISO 45001 hazard identification.

No formal compliance evaluation process is the second most consistent gap. Organizations can identify applicable occupational health and safety legislation but have no documented process for checking whether they are actually meeting it.

Worker consultation that exists on paper but not in practice is a gap specific to ISO 45001. A safety committee that meets and produces minutes looks compliant on a document review — but a gap analysis that includes worker interviews frequently reveals that consultation isn't genuinely shaping decisions.

No functioning internal audit program is an automatic gap for organizations pursuing first-time certification. The certification body's Stage 2 audit requires evidence of at least one completed internal audit cycle.

In Practice

One of the most misleading signals I encounter during a gap analysis is a strong safety record — low incident numbers, few reported near-misses. Management often takes this as evidence the OHSMS is working well, when in reality it can just as easily mean incidents aren't being reported, or that the organization has been lucky rather than systematic. A gap analysis has to look past the outcome metrics and examine the underlying process: is hazard identification genuinely ongoing, is worker consultation genuinely happening, is corrective action genuinely closing root causes. A good safety record with weak underlying processes is not a strength — it's a gap that hasn't been tested yet.

What a Gap Analysis Output Should Include

A gap analysis that produces a list of yes/no answers against each clause is not very useful. The output should give management the information they need to plan and allocate resources to an OHSMS implementation project effectively.

A well-structured gap analysis output includes a clause-by-clause assessment of current conformity — what is in place, what is partially in place, what is missing — with specific evidence for each finding. It includes a risk-based prioritization of gaps, distinguishing between those that represent significant risk to worker safety and those that are primarily administrative. It includes a realistic implementation plan with sequenced workstreams, resource requirements, and timeline estimates. And it includes an honest assessment of whether the organization is likely to be ready for certification within the desired timeframe.

In Practice

A gap analysis conducted entirely by internal staff has a specific limitation worth being honest about: it tends to miss the gaps that have become normalized within the organization. If a facility has operated a certain way for years, the people conducting the assessment have often stopped noticing the things an outside auditor would flag immediately — a hazard that's been "always like that," a control that everyone knows doesn't quite work but nobody has escalated. This isn't a competence issue. It's simply harder to see gaps in a system you're embedded in every day. This is exactly why external gap analysis support adds genuine value beyond just having more time available — it brings a perspective that isn't shaped by organizational familiarity.

If your organization needs support conducting an ISO 45001 gap analysis, our ISO 45001 consulting services cover the full process from initial assessment through certification preparation.

When to Conduct a Gap Analysis

The right time to conduct an ISO 45001 gap analysis is before the OHSMS implementation project begins — not partway through it. A gap analysis conducted at the outset gives the implementation team a clear picture of the full scope of work and produces a realistic timeline for certification.

For organizations that have been certified for several years and are preparing for a recertification audit, a pre-audit gap analysis — typically conducted three to six months before the audit — can surface emerging nonconformities before the certification body does. For a step-by-step guide to conducting the internal audit that follows OHSMS implementation, see our guide on how to conduct an ISO 45001 internal audit. Once the gap analysis is complete and implementation is underway, our ISO 45001 Internal Auditor course prepares your team to run the internal audit program the certification body will expect to see in place.

FAQ

Frequently asked questions

How long does an ISO 45001 gap analysis take?

The duration depends on the size and complexity of the organization and the number of sites within scope. For a single-site organization, a thorough gap analysis typically takes one to two days on site plus time to document findings and produce the output report. Larger multi-site organizations may require several days per site.

Can we conduct an ISO 45001 gap analysis ourselves?

Yes — and many organizations do, particularly those with in-house health and safety expertise. However, an internally conducted gap analysis has limitations: it may miss gaps that have become normalized within the organization, and it may not reflect current certification auditor expectations. An externally conducted gap analysis by someone with recent certification audit experience adds objectivity and practical relevance to the assessment.

What is the difference between a gap analysis and a Stage 1 certification audit?

A gap analysis is conducted before or during OHSMS implementation to assess how much work remains. A Stage 1 audit — sometimes called a readiness review — is conducted after the OHSMS is implemented to verify that it is functioning as required and ready for the certification body's assessment.

Does a gap analysis need to be conducted by an accredited auditor?

No — there is no requirement under ISO 45001 for a gap analysis to be conducted by an accredited auditor or certification body. It is an internal assessment tool, not a formal audit. However, the person conducting it should have sufficient knowledge of ISO 45001 requirements and practical OHS experience to identify gaps that aren't immediately obvious from documentation review alone.

Is a gap analysis required for ISO 45001 certification?

ISO 45001 does not formally require a gap analysis as part of the certification process. However, it is standard practice before certification and strongly advisable — particularly for first-time certification projects — because it prevents organizations from arriving at the certification audit with significant gaps that could result in major nonconformities and delay certification.

About the Author
Maria Falbo — Lead Trainer, Logix ISO
Maria Falbo
Founder & Lead Trainer, Logix ISO · 25+ Years Global Experience

Maria Falbo has over 25 years of experience working as a Lead Auditor for certification bodies worldwide. She founded Logix ISO with the mission of making expert-level ISO training accessible to organizations of all sizes. Her work spans Quality, Environmental, Occupational Health and Safety, Food Safety, Automotive, and Energy management systems.

Learn more about Maria →
ISO 45001 Consulting
Need help closing the gaps in your OHSMS?

From gap analysis through full certification preparation, our ISO 45001 consulting service gives you a clear, expert-led picture of what's left to do.

Explore ISO 45001 Consulting