ISO 45001

ISO 45001 vs OHSAS 18001: Why the Standard Changed and What's Different

OHSAS 18001 changed to ISO 45001 because OHSAS 18001 was never an ISO standard — it lacked the Annex SL structure shared by ISO 9001 and ISO 14001. ISO 45001, published March 2018, replaced it with a genuine ISO standard built on worker participation, organizational context, and proactive risk prevention. OHSAS 18001 was formally withdrawn in March 2021.

Organizations that have been operating occupational health and safety management systems for a long time sometimes still ask why OHSAS 18001 was replaced at all — and the answer goes deeper than a simple standard update. ISO 45001 wasn't a revision of OHSAS 18001. It was a genuinely new standard, built by a different organization, using a different structure, with several requirements that had no equivalent in the standard it replaced. This article explains why the change happened, what structurally and substantively is different between the two, and what organizations that transitioned needed to do — drawing on the audit and implementation experience of Maria Falbo, a Lead Auditor with decades of ISO 45001 experience.

Maria Falbo|Lead Trainer, Logix ISO|July 2026|9 min read

Why OHSAS 18001 Was Replaced

OHSAS 18001 was never an ISO standard. It was developed by the British Standards Institution (BSI) and a consortium of national standards bodies and certification organizations, outside the formal ISO development process. This meant it lacked the rigorous, multi-stakeholder consensus process that genuine ISO standards go through, and different countries and certification bodies interpreted and applied it in inconsistent ways — a real problem for multinational organizations trying to run a single, coherent safety management system across multiple jurisdictions.

By the time ISO 45001 was developed, ISO had introduced the Harmonized Structure (also known as Annex SL) — the common framework that all new ISO management system standards are built on, including ISO 9001 and ISO 14001. OHSAS 18001 predated this framework entirely, which made it genuinely difficult to integrate an OHSAS-based safety system with a quality or environmental management system. Organizations running all three had to manage systems built on three different architectures with three different sets of terminology.

ISO 45001 was published on March 12, 2018, developed through ISO's normal international consensus process involving safety experts, national delegations, and industry stakeholders from around the world. Does ISO 45001 replace OHSAS 18001? Yes — completely. OHSAS 18001 was formally withdrawn in March 2021, and organizations previously certified to it were required to transition to ISO 45001 by that date.

Organizations sometimes assume ISO 45001 was simply a renamed or lightly revised version of OHSAS 18001, given how closely the subject matter overlaps. This assumption causes real problems during transition. The two standards address the same domain — occupational health and safety — but they are built on different foundations, developed by different organizations, using different structures. Treating the change as cosmetic is the single most common reason organizations struggled during their transition audits. For a full explanation of what ISO 45001 is and what certification involves today, see our complete guide to ISO 45001. For a comprehensive overview of the full ISO 45001 internal audit lifecycle, see our ISO 45001 Internal Audit: The Complete Guide.

Key Differences: Structure and Approach

The most immediately visible difference is structural. ISO 45001 follows the Harmonized Structure, giving it the same clause numbering and overall logic as ISO 9001 and ISO 14001 — Clauses 4 through 10, covering context, leadership, planning, support, operation, performance evaluation, and improvement. OHSAS 18001 had its own distinct structure and its own terminology, including a formal distinction between "documents" and "records" that ISO 45001 replaced with the more flexible concept of "documented information."

The deeper difference is philosophical. OHSAS 18001 was built around identifying and controlling known hazards — a reactive model focused on hazards that had already been recognized. ISO 45001 introduced a proactive, prevention-oriented model, requiring organizations to evaluate and remedy hazard risks before they result in incidents, and to explicitly seek out opportunities to improve safety performance rather than simply controlling what's already known to be dangerous. The concept of "OH&S opportunities" — positive possibilities to improve safety performance — did not exist as an explicit requirement under OHSAS 18001 at all. For a full breakdown of how ISO 45001 requires organizations to address both risks and opportunities under Clause 6.1, see our guide to how to address risks and opportunities in ISO 45001.

This shift from reactive to proactive thinking extended beyond terminology into how audits are actually conducted. An OHSAS 18001 audit was largely a verification exercise — checking whether known hazards had documented controls. An ISO 45001 audit expects to see evidence of a system that is actively looking for hazards that haven't yet caused harm, and actively seeking opportunities to improve performance rather than waiting for an incident to reveal a gap.

Key Differences: Worker Participation

This is the single most consequential change between the two standards. OHSAS 18001 mentioned worker consultation, but it framed workers largely as passive recipients of safety policies decided elsewhere. In practice, many organizations treated OHSAS-era consultation as a formality — a box to tick rather than a genuine mechanism for worker input.

ISO 45001 changed this fundamentally through Clause 5.4, which requires organizations to establish processes for consulting and involving workers — including non-managerial workers — in the development, planning, implementation, performance evaluation, and improvement of the OHSMS. This reflects the position, consistent with the International Labour Organization's Occupational Safety and Health Convention, that workers themselves are the most reliable source of information about the hazards present in their own work.

In Practice

Organizations transitioning from OHSAS 18001 consistently underestimate how much work Clause 5.4 actually requires. Under OHSAS, having a safety committee that met periodically was generally sufficient evidence of consultation. Under ISO 45001, a certification auditor will interview frontline workers directly and ask them to describe specific instances where their input shaped a safety decision. A safety committee's meeting minutes are not, on their own, sufficient evidence of participation — the auditor is verifying whether workers were genuinely involved, not just informed after the fact.

Learn the practical skills to audit every ISO 45001 Requirement

The ISO 45001 Internal Auditor course covers Clause 5.4 in depth, along with every other requirement introduced since OHSAS 18001.

View Course

Key Differences: Context and Leadership

ISO 45001 introduced an entirely new requirement that had no equivalent under OHSAS 18001: understanding the context of the organization (Clause 4.1). This requires organizations to determine the internal and external issues relevant to their purpose that affect their ability to achieve the intended outcomes of the OHSMS — a broader strategic analysis that OHSAS 18001 never required.

Leadership accountability was also substantially strengthened. Under OHSAS 18001, safety management was, in practice, often treated as the safety manager's responsibility, with limited direct involvement from senior executives. ISO 45001 requires top management — not just the safety function — to demonstrate leadership and commitment, take direct accountability for the effectiveness of the OHSMS, integrate OHS considerations into core business processes, and ensure resources are allocated. Safety is no longer permitted to sit in a silo; it has to be visibly owned at the top of the organization.

In Practice

One of the clearest signals I look for when auditing an organization that transitioned from OHSAS 18001 is whether the context analysis reads like a genuine strategic exercise or like a box that was filled in to satisfy a new clause. A context analysis that lists generic factors — "the economy," "competition," "regulations" — without connecting them to how they specifically affect the organization's ability to manage worker safety is a sign the transition addressed the letter of Clause 4.1 without engaging with its purpose. A credible context analysis identifies specific, organization-relevant issues: an aging workforce with different injury patterns, a recent expansion into a new jurisdiction with different OHS legislation, a planned automation project that will change the hazard profile of several roles.

What Organizations Needed to Do to Transition

For organizations with a well-implemented OHSAS 18001 system, the transition to ISO 45001 typically took between three and nine months. The core management system elements — document control, internal audit, management review, corrective action — carried over conceptually, since both standards require them. What genuinely needed to be built from a different starting point were the elements ISO 45001 introduced that had no OHSAS equivalent.

The primary transition work involved conducting a formal context analysis under Clause 4, establishing and documenting genuine worker participation mechanisms under Clause 5.4, updating the hazard identification and risk assessment process to explicitly address opportunities alongside risks, and producing documented evidence of top management leadership and accountability that went beyond what OHSAS 18001 had ever required.

Certification bodies conducting transition audits during the 2018–2021 window consistently reported the same pattern: organizations that engaged seriously with worker participation and context analysis transitioned smoothly, often within the shorter end of the three-to-nine-month range. Organizations that treated the exercise as a documentation update — changing terminology, updating templates, and leaving the underlying practices unchanged — took longer, and were more likely to receive nonconformities related to these two specific areas during their transition audit. For a full comparison of how ISO 45001 compares to ISO 9001 and how the two standards can work together in an integrated system, see our article on ISO 45001 vs ISO 9001.

FAQ

Frequently asked questions

Did ISO 45001 replace OHSAS 18001 completely?

Yes. ISO 45001 fully replaced OHSAS 18001 as the international standard for occupational health and safety management systems. OHSAS 18001 was formally withdrawn in March 2021, and organizations previously certified to it were required to transition to ISO 45001 to maintain a valid certification.

Is OHSAS 18001 still a valid certification?

No. OHSAS 18001 is no longer valid or recognized. Any organization still referencing OHSAS 18001 certification is referring to a withdrawn standard. Current certification requires conformity to ISO 45001.

How long did organizations typically take to transition from OHSAS 18001 to ISO 45001?

For organizations with a well-implemented OHSAS 18001 system, the transition typically took three to nine months. The timeline depended primarily on how much work was needed to build out worker participation mechanisms, conduct a formal context analysis, and document senior leadership involvement — the areas with no direct OHSAS equivalent.

Was OHSAS 18001 an ISO standard?

No — this is one of the most misunderstood facts about the transition. OHSAS 18001 was developed by the British Standards Institution and a consortium of certification bodies, entirely outside the formal ISO development process. ISO 45001 was the first genuine ISO standard for occupational health and safety management.

What was the biggest practical challenge organizations faced transitioning to ISO 45001?

Most organizations found that building genuine worker participation mechanisms under Clause 5.4 was the most substantial new work required. OHSAS 18001's consultation requirements were often satisfied by a periodically-meeting safety committee. ISO 45001 requires organizations to demonstrate that workers were meaningfully consulted and involved, which certification auditors verify directly through worker interviews rather than relying on documentation alone.

About the Author
Maria Falbo — Lead Trainer, Logix ISO
Maria Falbo
Founder & Lead Trainer, Logix ISO · 25+ Years Global Experience

Maria Falbo has over 25 years of experience working as a Lead Auditor for certification bodies worldwide. She founded Logix ISO with the mission of making expert-level ISO training accessible to organizations of all sizes. Her work spans Quality, Environmental, Occupational Health and Safety, Food Safety, Automotive, and Energy management systems.

Learn more about Maria →
ISO 45001 Internal Auditor Training
Ready to become a qualified ISO 45001 internal auditor?

Self-paced · 365-day access · Training certificate included

View Course