ISO 45001 is the international standard for Occupational Health and Safety Management Systems. It provides a structured framework that helps organizations of any size or sector identify workplace hazards, manage risks to worker health and safety, meet legal and regulatory obligations, and demonstrate a credible commitment to protecting workers — whether or not they pursue formal certification.
ISO 45001 is the fastest-growing major management system standard in the world — and one of the most consequential, given what's at stake when it isn't implemented well. Organizations pursue it for different reasons: regulatory pressure, customer requirements, ESG reporting obligations, or a genuine commitment to protecting the people who work for them. This guide explains what ISO 45001 is, what an Occupational Health and Safety Management System actually involves, who needs it, and what the certification process looks like — drawing on the experience of Maria Falbo, a Lead Auditor with decades of ISO 45001 experience.
ISO 45001 is the international standard that defines the requirements for an Occupational Health and Safety Management System. Published by the International Organization for Standardization on March 12, 2018, it provides a framework that organizations use to identify workplace hazards, assess and manage the associated risks, involve workers in decisions that affect their safety, and demonstrate continual improvement in occupational health and safety performance over time.
The standard does not prescribe specific safety targets or dictate exactly what an organization's safety performance must look like. Instead, it defines the system — the processes, documentation, consultation mechanisms, and governance structures — through which an organization manages worker health and safety. What that looks like in practice depends on the organization's operations, sector, workforce, and the legal and regulatory environment it operates within.
ISO 45001 replaced OHSAS 18001, the previous industry benchmark for occupational health and safety management, which was never itself a genuine ISO standard. With 542,527 organizations certified worldwide as of the most recent ISO Survey — a figure that has nearly tripled since 2020 — ISO 45001 is now the fastest-growing major ISO management system standard globally, reflecting both regulatory pressure and a broader shift in how organizations think about worker safety.
An Occupational Health and Safety Management System is the set of processes, policies, procedures, and practices through which an organization manages worker health and safety in a systematic and documented way. ISO 45001 defines what that system must include — not exactly how it must look, but what it must address.
The OHSMS required by ISO 45001 covers several interconnected elements. The organization must understand its context — the internal and external issues that affect its ability to manage worker safety, the legal and regulatory requirements it must meet, and the needs of its interested parties. It must identify the hazards arising from its activities and processes — across normal operations, non-routine activities, and potential emergency situations — and assess the risks associated with them.
The system must establish operational controls for significant hazards, set measurable OHS objectives, monitor and measure performance, evaluate compliance with legal obligations, conduct internal audits, and review the system's effectiveness through formal management review. Incidents and nonconformities must be addressed through root cause analysis and corrective action, with documented evidence at every stage.
What genuinely sets ISO 45001 apart from a general safety program is Clause 5.4 — the requirement for consultation and participation of workers, including non-managerial workers, in the development, implementation, and evaluation of the OHSMS. This is a structural requirement, not a suggestion, and it's the single element with no direct equivalent in ISO 9001 or ISO 14001.
ISO 45001 is relevant to any organization that has workers whose health and safety could be affected by its operations — which effectively means any organization at all. The standard explicitly states that it is applicable to organizations of all sizes, in both the public and private sectors, across any industry.
In practice, the organizations that most commonly pursue ISO 45001 certification include manufacturing, construction, transportation and logistics, energy, healthcare, and public administration — sectors where physical hazards are significant, regulatory scrutiny is demanding, and the consequences of poor safety management are severe. But the standard's reach extends well beyond traditionally high-risk industries; office-based and service sector organizations pursue it too, particularly given the growing recognition of psychosocial hazards as a legitimate safety concern regardless of physical risk level.
Certification is not legally mandatory — ISO 45001 is a voluntary standard. However, the decision to pursue it is increasingly driven by factors that make it effectively mandatory in practice. Large customers and public sector contracts increasingly require suppliers to hold ISO 45001 certification. Insurance providers in some markets offer more favorable terms to certified organizations. ESG reporting frameworks reference worker safety management as a governance indicator, and ISO 45001 certification provides investors and stakeholders with a recognized, auditable signal of genuine commitment rather than a self-reported claim.
Our ISO 45001 Internal Auditor course covers OHSMS requirements, audit planning, hazard identification, operational controls, and corrective action, built on ISO 45001 and ISO 19011.
The reasons organizations pursue ISO 45001 fall into two broad categories: external drivers and internal value.
External drivers are the market, regulatory, and stakeholder pressures that make certification necessary or strategically important. Customer and supply chain requirements — particularly in construction, manufacturing, and energy — frequently mandate ISO 45001 certification as a condition of contract. Regulatory environments in many jurisdictions are tightening around workplace safety obligations. ESG reporting has become a mainstream expectation, and worker safety and wellbeing are explicit components of the "S" in ESG — ISO 45001 certification gives organizations a credible, third-party-verified way to demonstrate that commitment rather than relying on self-reported safety statistics.
Internal value comes from what a well-implemented OHSMS actually delivers. Organizations that take ISO 45001 seriously typically see measurable reductions in incident rates, lower insurance costs, reduced absenteeism, and improved workforce morale and retention — safety performance and organizational performance are more closely linked than many leadership teams initially recognize. The discipline of systematic hazard identification and worker consultation also tends to surface operational inefficiencies that have nothing directly to do with safety but improve productivity when addressed.
The difference between certification pursued as a compliance exercise and certification pursued as genuine commitment is visible the moment you talk to frontline workers. In organizations where ISO 45001 is taken seriously, workers can describe specific instances where their input changed a procedure or a layout of equipment. In organizations that pursued certification purely to satisfy a customer requirement, workers often can't name a single safety decision they've influenced — even if the organization has a certificate hanging on the wall and a safety committee that meets on schedule. The certificate looks identical in both cases. What happens on the floor does not.
ISO 45001 certification is conducted by an independent, accredited certification body — not by ISO itself. ISO publishes the standard; it does not certify organizations. Certification bodies assess whether an organization's OHSMS meets the requirements of the standard and issue a certificate when they confirm that it does.
The certification process follows a defined sequence. Before engaging a certification body, the organization must implement the OHSMS — building the system, establishing required documentation, running the internal audit program, conducting management review, and addressing any nonconformities found through internal auditing.
The certification audit itself proceeds in two stages. The Stage 1 audit is primarily a documentation review — the certification body assesses whether the OHSMS documentation is in place and whether the organization is ready to proceed to Stage 2. The Stage 2 audit is the on-site implementation audit — auditors verify that the documented OHSMS is being implemented in practice, which for ISO 45001 specifically includes interviewing workers directly to verify that consultation and participation are genuine, not just documented. Major nonconformities found at Stage 2 must be resolved before certification can be granted.
Once certified, organizations undergo annual surveillance audits to confirm the OHSMS continues to function effectively, with a full recertification audit every three years. For organizations preparing for their first certification audit, understanding what internal audits need to cover — and how to conduct them effectively — is one of the most important steps in the preparation process. For a complete guide to ISO 45001 internal auditing, see our ISO 45001 Internal Audit: The Complete Guide.
ISO 45001 shares the same Harmonized Structure as ISO 9001 (Quality Management Systems) and ISO 14001 (Environmental Management Systems). This common framework means the clause numbering, core terminology, and overall logic of all three standards align closely.
The practical implication is that organizations holding multiple certifications can integrate their management systems rather than maintaining them as separate, parallel structures. An Integrated Management System combining ISO 45001 and ISO 9001 — or ISO 45001 and ISO 14001 — consolidates documentation, internal audits, and management review into a single unified system, significantly reducing the administrative burden of maintaining multiple certifications while still meeting each standard's specific requirements in full.
It's also worth understanding how ISO 45001 came to exist in its current form. The standard replaced OHSAS 18001 in 2018, introducing genuinely new requirements — expanded worker participation and organizational context chief among them — that organizations transitioning from the older standard had to build from scratch. For the full history of that transition, see our article on ISO 45001 vs OHSAS 18001.
For organizations considering ISO 45001 alongside an existing or planned ISO 9001 certification, understanding how the two standards relate — and whether integration makes sense — is an important early decision. For a full comparison of what separates ISO 45001 from ISO 9001 and how the two can work together, see our article on ISO 45001 vs ISO 9001.
ISO 45001 certification is voluntary. However, it is increasingly required in practice by customers, supply chains, and public procurement processes. Many organizations find that ISO 45001 certification becomes effectively mandatory when their major customers or key contracts require it as a qualification condition.
ISO 45001 certificates are valid for three years, subject to annual surveillance audits. The certification body conducts a surveillance audit in years one and two to confirm the OHSMS continues to function effectively, and a full recertification audit in year three to renew the certificate.
Workplace safety regulations are legal requirements set by government authorities that organizations must comply with regardless of certification status. ISO 45001 is a management system standard that requires organizations to identify their applicable legal obligations — including safety regulations — and demonstrate that they are systematically meeting them. ISO 45001 certification does not replace legal compliance obligations; it requires organizations to manage their compliance with them systematically and to go beyond the legal minimum where the standard's requirements demand it.
Yes — ISO 45001 is designed to be applicable to organizations of any size. The standard is scalable; its requirements apply regardless of organizational size, and the depth and formality of the OHSMS documentation should reflect the scale and complexity of the organization's hazards and workforce. A small operation with a limited number of significant hazards can implement ISO 45001 with a proportionate system.
Certification has nearly tripled since 2020, driven by a combination of regulatory pressure, growing ESG reporting requirements that reference worker safety governance, increasing customer and supply chain requirements, and a broader shift in how organizations understand the connection between worker safety and overall organizational performance. ISO 45001 is currently the fastest-growing major ISO management system standard globally.

Maria Falbo has over 25 years of experience working as a Lead Auditor for certification bodies worldwide. She founded Logix ISO with the mission of making expert-level ISO training accessible to organizations of all sizes. Her work spans Quality, Environmental, Occupational Health and Safety, Food Safety, Automotive, and Energy management systems.
Learn more about Maria →Self-paced · 365-day access · Training certificate included