ISO 45001 Clause 6.1.2 requires organizations to systematically identify hazards arising from their activities, processes, and work environment — across routine operations, non-routine activities, and potential emergency situations. Identification must cover physical, chemical, biological, ergonomic, and psychosocial hazards, and the outputs feed directly into risk assessment, operational controls, and audit priorities.
Hazard identification is the foundation everything else in an OHSMS is built on — get it wrong, and every downstream element, from risk assessment to operational controls to the internal audit program, inherits that gap. Yet it's also one of the most frequently underdeveloped requirements in ISO 45001, not because organizations skip it entirely, but because they do it once, thoroughly, and then don't keep it up to date. This article explains what Clause 6.1.2 requires, how organizations identify hazards systematically, and what auditors actually look for when they examine a hazard register — drawing on the audit experience of Maria Falbo, a Lead Auditor with decades of ISO 45001 experience.
Clause 6.1.2 — Hazard identification and assessment of risks and opportunities — requires organizations to establish, implement, and maintain a process for hazard identification that is ongoing and proactive. The word "ongoing" matters as much as "identification" itself: this is not a one-time exercise conducted when the OHSMS is first implemented, but a continuous process that keeps pace with how the organization actually operates.
A hazard, under ISO 45001, is a source with the potential to cause injury or ill health. Identifying hazards means systematically examining every activity, process, product, and service within the scope of the OHSMS to determine where those sources exist. This is distinct from risk assessment — hazard identification answers "what could cause harm," while risk assessment (covered under Clause 6.1.2.2) answers "how likely is that harm, and how severe." For a full explanation of how these two stages connect and how ISO 45001 structures the broader planning process, see our guide to how to address risks and opportunities in ISO 45001. For a comprehensive overview of the full ISO 45001 internal audit lifecycle and how hazard identification fits into it, see our ISO 45001 Internal Audit: The Complete Guide.
The clause explicitly requires organizations to take into account how work is organized — not just physical conditions. This includes social factors such as workload, work hours, victimization, harassment, and bullying, all of which contribute to psychosocial hazards. It also requires consideration of past incidents, whether internal or reported externally, and requires the process to account for people — including contractors, visitors, and anyone else who could be affected by the organization's activities, not just direct employees.
Hazard identification also has to account for organizational knowledge that is outside of the current hazard register. Equipment manufacturers' safety documentation, industry incident databases, regulatory guidance, and lessons learned from similar organizations can all surface hazards that internal experience alone hasn't yet revealed. An organization relying purely on its own historical incidents to identify hazards is mostly building a register that only ever catches up to harm after it's already occurred.
Hazards fall into several recognized categories, and a credible identification process needs to cover all of them — not just the ones that are visually obvious.
Physical or safety hazards are the most commonly identified category: moving machinery, unguarded equipment, working at height, exposed electrical components, hot surfaces, slippery floors. These are the hazards that show up on a walkthrough without much effort, because they're visible.
Chemical hazards — exposure to toxic, flammable, or corrosive substances through inhalation, contact, or ingestion — require a more deliberate process, typically anchored to a chemical inventory and safety data sheets.
Biological hazards — exposure to bacteria, viruses, or other biological agents — are relevant in healthcare, laboratory, agricultural, and food processing environments, and are frequently underrepresented in general manufacturing hazard registers even where some exposure risk exists.
Ergonomic hazards — repetitive motion, awkward postures, manual handling, poorly designed workstations — cause cumulative harm rather than acute injury, which makes them easy to overlook in an identification process built around observing a single moment in time.
Psychosocial hazards are the category most consistently missing from hazard registers, even though ISO 45001 explicitly requires their consideration. Workload, unreasonable time pressure, poor management practices, harassment can all contribute to psychological harm, and Clause 6.1.2 treats them as legitimate hazards requiring the same systematic identification as a chemical spill risk for example.
When I review a hazard register during an audit, the psychosocial category is almost always not included. An organization can have a meticulously detailed register covering every machine guard and every chemical in the facility, and then nothing at all addressing workload, shift patterns, or management behavior. That gap isn't usually deliberate. It reflects the fact that physical hazards are easier to see and easier to write down. Psychosocial hazards require actually talking to people about how the work affects them — which is a fundamentally different identification method, not just a different category on a form.
Our ISO 45001 Internal Auditor course covers Clause 6.1.2 in depth, including how auditors verify identification methods are genuinely comprehensive.
Effective hazard identification uses multiple methods in combination, because no single method surfaces every category of hazard.
Workplace inspections are the starting point — systematic walkthroughs that examine each area, process step, and piece of equipment for physical, chemical, and environmental hazards. Inspections work best when they follow the actual workflow rather than a generic checklist, moving through incoming materials, production, maintenance, and dispatch in sequence.
Job safety analysis breaks a specific task down into its individual steps and identifies the hazards associated with each step — useful for high-risk tasks where a general walkthrough wouldn't capture the specific sequence of actions involved. This method is particularly valuable for tasks that are infrequent but high-consequence, such as confined space entry or work involving hazardous energy isolation, where the specific sequence of steps matters more than the general area.
Incident and near-miss investigation is one of the most valuable and most underused identification methods. Every incident and near-miss reveals a hazard that may have been missed. An organization that investigates incidents thoroughly and feeds the findings back into the hazard register is running a genuinely proactive system. An organization that investigates incidents and stops at the immediate cause is missing the identification value entirely.
Worker consultation is required under Clause 5.4 and is specifically valuable for hazard identification because workers performing the task have direct knowledge of conditions that a periodic inspection will never capture — a guard that gets removed for convenience during a specific task, a shortcut that's become normal practice, a psychosocial pressure that management doesn't see. Structured mechanisms — safety committees, direct interviews, hazard reporting systems — all serve this purpose, but the mechanism matters less than whether workers are genuinely being heard. For a complete guide to how the full internal audit process examines these methods in practice, see our guide on how to conduct an ISO 45001 internal audit.
Clause 6.1.2 requires hazard identification to extend beyond routine, day-to-day operations. This is one of the most consistently underdone parts of the requirement, because it's genuinely harder to identify hazards for conditions that aren't happening in front of you at the time of the review.
Non-routine activities — maintenance shutdowns, equipment startup and commissioning, process changes, unusual production runs — often introduce hazards that don't exist during normal operation. A machine that's perfectly safe during standard operation may present an entirely different hazard profile during a maintenance procedure that requires bypassing a guard or working inside the equipment.
Emergency situations — fires, chemical spills, structural failures, severe weather events — require their own identification process, distinct from routine hazard identification. The organization needs to determine what potential emergencies could arise from its hazards and prepare accordingly, which connects directly to the emergency preparedness and response requirements elsewhere in the standard.
A pattern I see consistently: a facility's hazard register is comprehensive for the day shift, standard operating conditions, under normal staffing. The same facility running a reduced weekend crew, or operating during a planned maintenance shutdown with contractors on site, has a materially different hazard profile that the register never anticipated. The identification process that only ever observes the facility under its most typical conditions will systematically miss the conditions that are statistically most likely to produce a serious incident — because those are exactly the conditions where controls, supervision, and familiarity are all reduced at once.
Hazard identification isn't an isolated compliance exercise — it's the input that everything downstream depends on. Once hazards are identified, they feed directly into risk assessment under Clause 6.1.2.2, which determines the likelihood and severity of harm associated with each one. Significant risks then drive the operational controls required under Clause 8.1 — the actual physical, procedural, and administrative measures that manage the hazard in practice, following the hierarchy of controls rather than defaulting straight to PPE.
Hazard identification also directly shapes the internal audit program. Areas with significant, high-severity hazards should be audited more frequently and more rigorously than lower-risk administrative functions — which means an incomplete or outdated hazard register doesn't just create a gap in planning, it distorts the entire risk-based logic the audit program is supposed to be built on.
This is why auditors treat the hazard register as one of the first documents worth examining in any internal or certification audit. An auditor who reviews an outdated or incomplete register before walking the floor already knows where the biggest gaps are likely to be found. That single document, more than almost any other in the OHSMS, tells an auditor whether the organization's safety management is genuinely proactive or fundamentally reactive.
Organizations preparing for certification or looking to strengthen their hazard identification process before an audit can benefit from expert support — our ISO 45001 consulting services cover gap analysis and hazard identification review as part of full OHSMS implementation support.
No — the standard does not mandate a specific hazard identification methodology. It requires the process to be defined, systematic, ongoing, and proactive, and to cover the full range of hazard categories and operational conditions the standard describes. Most organizations use a combination of workplace inspections, job safety analysis, incident investigation, and worker consultation rather than relying on a single method.
ISO 45001 does not require a dedicated safety function to own hazard identification exclusively. In practice, the most effective programs combine responsibility across levels — supervisors and safety personnel leading structured inspections and job safety analysis, while workers contribute frontline knowledge through consultation. Relying on a single safety officer to identify every hazard across an organization typically produces a thinner, more physical-hazard-skewed register than a genuinely distributed process.
Yes. ISO 45001 explicitly requires organizations to consider how work is organized, including social factors such as workload, work hours, and workplace culture, as part of hazard identification. Psychosocial hazards are treated with the same requirement for systematic identification as physical or chemical hazards, even though they're commonly underrepresented in practice.
ISO 45001 does not specify a fixed review interval, but the process must be ongoing and triggered by relevant changes — new equipment, new processes, incidents or near-misses, organizational changes, or changes to legal requirements. Most organizations combine a scheduled periodic review with an unplanned review triggered by specific operational changes.
Yes. Clause 6.1.2 requires organizations to consider people who could be affected by their activities, which explicitly includes contractors, visitors, and anyone else present within the scope of the OHSMS — not just direct employees.

Maria Falbo has over 25 years of experience working as a Lead Auditor for certification bodies worldwide. She founded Logix ISO with the mission of making expert-level ISO training accessible to organizations of all sizes. Her work spans Quality, Environmental, Occupational Health and Safety, Food Safety, Automotive, and Energy management systems.
Learn more about Maria →Self-paced · 365-day access · Training certificate included