ISO 45001

How to Address Risks and Opportunities in ISO 45001

ISO 45001 Clause 6.1 requires organizations to determine and assess two distinct types of risk — OH&S risks arising from identified hazards, and separate risks to the OH&S management system itself — alongside OH&S opportunities for improvement. Legal requirements must be identified, and actions to address all of these must be planned and integrated into the OHSMS proactively.

Clause 6.1 is one of the most misunderstood sections of ISO 45001 — not because the requirement is complex, but because most explanations conflate two genuinely different types of risk into one undifferentiated exercise. Organizations that treat "risks and opportunities" as a single combined activity miss half of what the clause actually requires. This article walks through what Clause 6.1 requires, how hazard identification, risk assessment, and opportunity identification relate to one another, and where this planning process connects to the rest of the OHSMS — drawing on the audit and implementation experience of Maria Falbo, a Lead Auditor with decades of ISO 45001 experience.

Maria Falbo|Lead Trainer, Logix ISO|July 2026|9 min read

What Clause 6.1 Actually Requires

Clause 6.1 — Actions to address risks and opportunities — is at the core of ISO 45001's planning requirements. It requires organizations, when planning their OHSMS, to take into account the internal and external issues identified under Clause 4.1, the needs and expectations of interested parties under Clause 4.2, and the scope of OHSMS under Clause 4.3, and to determine the risks and opportunities that need to be addressed as a result.

The clause is structured across four sub-clauses: 6.1.1 sets the general planning requirement, 6.1.2 covers hazard identification and the assessment of risks and opportunities, 6.1.3 covers legal and other requirements, and 6.1.4 covers planning the actions that will address everything identified in the preceding sub-clauses. Understanding how these four pieces connect — rather than treating them as a single undifferentiated planning task — is what separates a credible Clause 6.1 implementation from a superficial one. For a complete guide to the full ISO 45001 internal audit lifecycle, see our ISO 45001 Internal Audit: The Complete Guide.

Hazard Identification: The Starting Point

Everything under Clause 6.1 begins with hazard identification (Clause 6.1.2.1). A hazard is a source with the potential to cause injury or ill health, and identifying hazards means systematically examining the organization's activities, processes, and workplaces to find them — across routine operations, non-routine activities like maintenance and startup, past incidents, emergency situations, and how work is actually organized, including factors like workload, hours, and workplace culture that contribute to psychosocial hazards.

Hazard identification is not a one-time exercise conducted when the OHSMS is first implemented. It needs to be ongoing and proactive, triggered by planned changes, new equipment, new processes, and incidents or near-misses that reveal hazards the organization hadn't previously captured. For a full breakdown of how hazard identification works and what a credible process looks like in practice, see our guide to ISO 45001 hazard identification.

Once hazards are identified, the organization moves to the next stage: assessing the risks that arise from them. This is where Clause 6.1 introduces a distinction that most organizations do not fully capture.

Two Distinct Types of Risk

Clause 6.1.2.2 — Assessment of OH&S risks and other risks to the OH&S management system — is titled to make clear that it covers two genuinely different categories, even though most explanations of ISO 45001 treat "risk assessment" as a single activity.

The first type is OH&S risk — the risk arising directly from the hazards identified in 6.1.2.1. This is the familiar process: a hazard exists (a chemical, a piece of moving machinery, a work-at-height scenario), and the risk is the combination of the likelihood and severity of harm resulting from exposure to it. This assessment must take into account applicable legal requirements and the effectiveness of any existing controls.

The second type is risk to the OH&S management system itself — and this is the part organizations most consistently overlook. These are risks that could prevent the OHSMS from achieving its intended outcomes, arising not from physical hazards but from broader organizational issues — internal and external issues identified in Clause 4.1 and the needs of interested parties identified in Clause 4.2. Examples include the risk that budget constraints could undermine planned safety investments, the risk that high staff turnover could negatively affect safety knowledge, or the risk that a merger or restructuring could disrupt established reporting lines for hazard escalation.

The distinction matters because an organization that only assesses the first type — hazard-driven OH&S risk — is not meeting the full requirement of 6.1.2.2, even if its hazard register is thorough. Both types of risk assessment must be defined, proactive, systematic, and documented.

In Practice

When I ask organizations to show me their risk assessment for the management system itself — not their hazard-based risk register, but their assessment of what could undermine the OHSMS functioning as intended — the most common response is confusion about what I'm asking for. Most organizations have not performed the analysis of both. They have a comprehensive hazard and risk register and assume that satisfies the clause. It satisfies half of it. The risks to the management system — resourcing gaps, organizational change, loss of organizational knowledge — need their own deliberate assessment, and they're just as auditable as the hazard-based risks.

A useful test during audit interviews is to ask a safety manager to name one risk to the OHSMS itself, separate from a physical hazard. Organizations that have genuinely engaged with the full requirement of Clause 6.1.2.2 can usually answer without hesitation — pointing to a resourcing gap, an upcoming restructuring, or a known skills shortage on the safety team. Organizations that have only ever worked through hazard-based risk typically pause, because the question is asking about something their planning process has never actually considered.

Build the skills to audit ISO 45001 planning requirements with confidence

The ISO 45001 Internal Auditor course covers Clause 6.1 in depth, including how auditors distinguish and verify both types of risk assessment.

View Course

OH&S Opportunities: The Overlooked Half

Clause 6.1.2.3 requires organizations to identify OH&S opportunities — and opportunities are conceptually distinct from risks in a way that's easy to lose sight of in practice. Where hazards and risks are things to be controlled or minimized, opportunities are circumstances that could improve OH&S performance or strengthen the management system itself.

Opportunities can come from several sources: adapting work, work organization, or the work environment for the workforce (ergonomic improvements, better lighting, revised shift patterns); eliminating hazards entirely rather than just controlling them; incident investigations and internal audits that reveal not just what went wrong but what could be improved; and benchmarking against industry practice or learning from external incidents.

The standard expects opportunities to be treated with the same planning rigor as risks — assessed, prioritized, and translated into action plans under Clause 6.1.4, with resources and timelines assigned. An organization that identifies an ergonomic opportunity in its risk assessment process but never assigns a budget or a deadline to act on it has identified the opportunity without genuinely addressing it.

In practice, opportunities are the piece most likely to be skipped entirely, because risk assessment feels urgent in a way that opportunity identification does not. But an OHSMS that only ever reacts to risk, without deliberately seeking improvement, will plateau. The organizations getting the most value from ISO 45001 treat opportunity identification as a genuine planning discipline, not an afterthought bolted onto the risk register.

Clause 6.1.3 requires organizations to determine and have access to the legal requirements and other requirements applicable to their hazards, OH&S risks, and OHSMS — occupational health and safety legislation, industry-specific regulations, licensing conditions, and any voluntary commitments the organization has made. These requirements must be taken into account when the organization establishes, implements, and maintains its OHSMS, and must be kept up to date as legislation changes.

Clause 6.1.4 then brings everything together. Having identified hazards, assessed both types of risk, identified opportunities, and determined legal requirements, the organization must plan actions to address all of it — integrating those actions into the OHSMS processes, evaluating the effectiveness of the actions taken, and considering the hierarchy of controls when addressing OH&S risks specifically. This is the clause that converts identification and assessment into actual operational commitments — and it's the clause auditors use to check whether the earlier planning work led anywhere concrete.

A common gap at this stage is treating Clause 6.1.4 as a documentation task rather than an operational one. An organization might produce a well-organized action plan listing every risk, every opportunity, and every legal requirement with a corresponding action — but if those actions were never actually resourced, scheduled, or followed through, the plan exists as a document without existing as a functioning process. Auditors verify this by tracing specific entries in the action plan back to evidence that the action was actually completed, not just documented as planned.

Connecting Risks and Opportunities to Change Management

One of the most important — and most frequently missed — connections in ISO 45001 is between Clause 6.1 and Clause 8.1.3, management of change. The standard requires that when the organization plans permanent or temporary changes — new equipment, new processes, organizational restructuring, new personnel — the risk and opportunity assessment required by Clause 6.1 must be undertaken before the change is implemented, not after.

This is proactive risk management by design. An organization that installs new equipment and only then updates its hazard register and risk assessment has inverted the sequence the standard requires. The assessment is supposed to inform the decision and the implementation — identifying what controls are needed before the equipment goes live, not retrofitting the paperwork once it's already running. For a step-by-step walkthrough of how this planning connects to the full internal audit process, see our guide on how to conduct an ISO 45001 internal audit.

In Practice

The most revealing question I ask when auditing this connection is simple: "Show me the risk assessment for the last piece of new equipment you installed, and tell me when it was completed relative to the installation date." In many cases, the honest answer is that the equipment went live first, and the paperwork followed after the fact. That sequence — implement, then assess — is exactly what Clause 8.1.3 is designed to prevent, and it's one of the clearest signals of whether an organization's risk and opportunity planning is a genuine operational discipline or a compliance afterthought.

If your organization needs expert support building or strengthening its Clause 6.1 risk and opportunity planning process, our ISO 45001 consulting services cover gap analysis and full OHSMS implementation support.

FAQ

Frequently asked questions

What is the difference between a hazard and a risk in ISO 45001?

A hazard is a source with the potential to cause harm — a chemical, a piece of machinery, a work-at-height scenario. A risk is the combination of the likelihood and severity of harm that could result from exposure to that hazard. ISO 45001 requires organizations to first identify hazards (Clause 6.1.2.1), then assess the risks arising from them (Clause 6.1.2.2). Hazards are the source; risk is the measure of potential consequence.

Does ISO 45001 require a specific risk assessment methodology?

No — the standard does not mandate a specific method or matrix. It requires that the process for assessing risk be defined, systematic, proactive, and documented, taking into account applicable legal requirements and existing controls. Most organizations use a risk matrix scoring likelihood and severity, but the specific format is left to the organization to determine and implement.

What counts as a risk to the OH&S management system, as opposed to an OH&S risk?

An OH&S risk arises directly from a physical or operational hazard — the risk of injury from a piece of machinery, for example. A risk to the management system is broader — it's a risk that could prevent the OHSMS itself from functioning as intended, arising from organizational context, resourcing, interested party expectations, or structural change. Examples include the risk of losing safety expertise through staff turnover or the risk that budget cuts could delay planned safety improvements.

Are OH&S opportunities mandatory to identify, or optional?

Mandatory. Clause 6.1.2.3 requires organizations to identify OH&S opportunities as part of the planning process, not as an optional add-on. Opportunities must be assessed and, where pursued, translated into action plans with the same planning discipline as risks under Clause 6.1.4.

When does the risk and opportunity assessment for a planned change need to happen?

Before the change is implemented. Clause 8.1.3, management of change, requires that permanent or temporary changes to equipment, processes, or the organization be assessed for their risk and opportunity implications before they go live — not retroactively once the change has already been made.

About the Author
Maria Falbo — Lead Trainer, Logix ISO
Maria Falbo
Founder & Lead Trainer, Logix ISO · 25+ Years Global Experience

Maria Falbo has over 25 years of experience working as a Lead Auditor for certification bodies worldwide. She founded Logix ISO with the mission of making expert-level ISO training accessible to organizations of all sizes. Her work spans Quality, Environmental, Occupational Health and Safety, Food Safety, Automotive, and Energy management systems.

Learn more about Maria →
ISO 45001 Internal Auditor Training
Ready to become a qualified ISO 45001 internal auditor?

Self-paced · 365-day access · Training certificate included

View Course