ISO 9001 is the international standard for Quality Management Systems, focused on customer satisfaction and process performance. ISO 45001 is the international standard for Occupational Health and Safety Management Systems, focused on worker safety and hazard management. Both share the same Harmonized Structure — which means they are designed to work together and can be maintained as a single Integrated Management System.
Many organizations hold both ISO 9001 and ISO 45001 certification — and many more are considering adding one to the other. Understanding how the two standards relate to each other, what they share, and where they differ is essential for organizations deciding whether to pursue both and how to do it efficiently. This article explains the key differences between ISO 9001 and ISO 45001, how the Harmonized Structure makes integration practical, and what an Integrated Management System combining both standards actually looks like — drawing on the audit experience of Maria Falbo, a Lead Auditor with decades of experience across both quality and occupational health and safety management systems.
ISO 9001 is the international standard for Quality Management Systems. Its central focus is on meeting customer requirements and enhancing customer satisfaction — ensuring that an organization's products and services consistently meet specified requirements and that processes are in place to improve when they don't. ISO 9001 is the most widely implemented management system standard in the world, with over 1 million certified organizations globally.
ISO 45001 is the international standard for Occupational Health and Safety Management Systems. Its central focus is on identifying workplace hazards and managing the associated risks to worker health and safety, with worker consultation and participation built into the standard as a structural requirement. ISO 45001 is currently the fastest-growing major ISO management system standard, with 542,527 certified organizations as of the most recent ISO Survey.
Both standards require organizations to build a management system — a documented, systematic framework for managing a specific area of organizational performance. Both require internal audits, management review, corrective action processes, and continual improvement. But the subject matter they manage, and who they aim to protect, are fundamentally different.
The core difference between ISO 9001 and ISO 45001 is what they are managing and who they are managing it for.
ISO 9001 manages quality — conformity of products and services to customer requirements, process performance, and customer satisfaction. The primary stakeholder is the customer. The primary risk being managed is the risk of delivering products or services that fail to meet requirements.
ISO 45001 manages worker safety — the hazards arising from an organization's operations, and whether the risks to workers from those hazards are being identified, controlled, and reduced. The primary stakeholders are the workers themselves, along with regulators, unions, and safety authorities. The primary risk being managed is the risk of injury, illness, or death arising from the workplace.
In practical terms, an ISO 9001 audit focuses on whether processes produce the right outputs consistently, whether customer complaints are being addressed, and whether quality objectives are being met. An ISO 45001 audit focuses on whether hazards have been genuinely identified across all operating conditions, whether operational controls are functioning in practice, and whether workers have actually been consulted — not just informed. The auditing methods are similar — document review, process observation, interviews — but the questions being asked and the evidence being sought are different.
The other significant difference is worker participation. ISO 9001 has no direct equivalent to ISO 45001's Clause 5.4 requirement for consultation and participation of workers, including non-managerial workers, in the development and evaluation of the management system itself. Genuine worker involvement is structural to ISO 45001 in a way that has no parallel in quality management.
For a complete guide to ISO 45001 internal auditing specifically, see our ISO 45001 Internal Audit: The Complete Guide. For a full explanation of what ISO 9001 is and what QMS certification involves, see our complete guide to ISO 9001.
ISO 9001 and ISO 45001 share the Harmonized Structure — the common framework that ISO introduced to make its management system standards compatible with each other. The Harmonized Structure gives both standards the same clause numbering at the top level, the same core terminology, and the same overall logic.
Both standards follow the Plan-Do-Check-Act cycle. Both require a context analysis, a policy, defined roles and responsibilities, competence and awareness requirements, documented information, operational controls, monitoring and measurement, internal audit, management review, and corrective action.
Worth being precise about: while the top-level clause structure aligns exactly — Clauses 4 through 10 in both standards — the specific sub-clause content underneath does not align one-to-one, because each standard addresses genuinely different subject matter. Clause 6.1.2 in ISO 45001 covers hazard identification; there's no direct equivalent sub-clause in ISO 9001, which instead structures its planning clause around quality system risks and opportunities. The shared architecture makes integration structurally straightforward, but it doesn't mean the two systems become identical underneath.
This shared architecture is not accidental. ISO designed it specifically to make it practical for organizations to implement multiple standards simultaneously and maintain them as a single integrated system rather than parallel, siloed structures.
Our ISO 45001 Internal Auditor course prepares your team to audit the worker safety requirements that ISO 9001 doesn't cover — built on ISO 45001 and ISO 19011.
Yes — and for organizations holding both certifications, integration is strongly advisable. The Harmonized Structure means that ISO 9001 and ISO 45001 are designed to coexist in a single management system rather than operate as separate, parallel systems.
An Integrated Management System combining ISO 9001 and ISO 45001 eliminates duplicated documentation — one document control procedure, one internal audit program, one management review — covering both standards simultaneously. It reduces audit time and cost, because combined internal audits and surveillance audits from the certification body can cover both standards in a single exercise. And it removes the organizational silos that develop when quality and safety are treated as separate disciplines managed by separate teams with separate reporting structures.
The integration does not eliminate the standard-specific requirements — an IMS still needs to address hazard identification and worker consultation as ISO 45001 requires, and customer requirements and quality objectives as ISO 9001 requires. What it eliminates is the duplication in the management system infrastructure that supports both.
The most consistent friction point I see when integrating these two standards isn't structural — it's cultural. Quality teams are typically metrics-driven, focused on defect rates and process capability. Safety teams are typically driven by a very different urgency, where the cost of a missed control isn't a returned product but an injured worker. When these two functions are asked to share a single management system, the tension isn't usually about which clause goes where. It's about whose priorities get heard first when resources are limited. Integration works best when leadership treats both disciplines as equally non-negotiable, rather than letting one quietly subordinate the other.
An Integrated Management System combining ISO 9001 and ISO 45001 maintains one unified framework rather than two parallel systems. In practice, this means:
One document control system covering all quality and OHS documented information — procedures, work instructions, registers, records — under a single version control and retention framework.
One internal audit program that covers both ISO 9001 and ISO 45001 requirements across the audit cycle. Auditors are trained to audit both standards, and audit plans are structured to cover quality and safety elements within the same audit rather than running separate exercises.
One management review that addresses both quality and safety performance simultaneously — reviewing customer feedback, quality objectives, incident rates, hazard trends, audit findings, and corrective actions in a single management forum.
One corrective action process that handles nonconformities and improvement opportunities from both the quality and safety dimensions of the system.
The standard-specific elements — the hazard identification and risk assessment register, the worker consultation mechanisms, the compliance obligations register — remain distinct because they address subject matter that has no quality equivalent. But the system that manages them is shared.
Logix ISO offers dedicated training for organizations managing combined systems — our IMS courses cover ISO 9001 with ISO 14001, and ISO 14001 with ISO 45001, for auditors working across multiple standards.
For a deeper look at what an Integrated Management System involves and how organizations structure it in practice, see our guide to Integrated Management Systems. For a full explanation of what ISO 45001 is and what certification involves, see our complete guide to ISO 45001.
No — the two certifications are independent. Organizations can hold ISO 9001 certification without ISO 45001, and vice versa. Many organizations hold both because they operate in industries where both quality and worker safety are market or customer requirements — construction, manufacturing, and energy are typical examples.
Neither is inherently harder — they address different subject matter. ISO 45001 has requirements that have no equivalent in ISO 9001, particularly the hazard identification and risk assessment process, and the structural requirement for worker consultation and participation. Organizations that already have ISO 9001 in place typically find ISO 45001 implementation somewhat faster because the management system infrastructure is already established, though the safety-specific content still needs to be built from scratch.
Yes — internal auditors can audit both standards provided they are competent in both and do not audit their own work. In an Integrated Management System, it is common for a small number of trained internal auditors to cover both quality and safety requirements within the same audit program, though competence in occupational health and safety auditing specifically — including how to conduct meaningful worker interviews — is essential and not automatically transferable from quality auditing experience.
No — they address different subject matter and serve different purposes. ISO 9001 manages quality and customer satisfaction. ISO 45001 manages worker health and safety. ISO 9001 is not a substitute for ISO 45001 and does not address the hazard identification, risk assessment, or worker participation requirements that ISO 45001 covers.
An IMS internal audit covers the requirements of multiple standards — ISO 9001 and ISO 45001, and potentially ISO 14001 — within the same audit exercise. Auditors must be competent in all standards being audited, and the audit plan must ensure coverage of both quality and safety requirements across the audit cycle. The methodology is the same as a single-standard audit, but the scope is broader and the auditor competence requirements are higher.

Maria Falbo has over 25 years of experience working as a Lead Auditor for certification bodies worldwide. She founded Logix ISO with the mission of making expert-level ISO training accessible to organizations of all sizes. Her work spans Quality, Environmental, Occupational Health and Safety, Food Safety, Automotive, and Energy management systems.
Learn more about Maria →Self-paced · 365-day access · Training certificate included