OHS Management System: What ISO 45001 Actually Requires and Why Most Companies Get It Wrong

Many companies have an OHS management system “in place.” They have the documentation, the policy, the appointed responsible person. But when an external audit arrives or an accident happens, the real problem surfaces: the system exists on paper, not in daily operations.
ISO 45001 does not ask for documents. It asks for a management system that works. And that difference — which sounds small — is what separates companies that pass audits from those that face corrective actions, fines, or worse.
This article explains what ISO 45001 actually requires, what typically fails in practice, and how to build an OHS management system that does not depend on one person or live inside a shared folder nobody updates.
What Is an OHS Management System and Why Does ISO 45001 Matter?
An Occupational Health and Safety (OHS) management system is the set of processes, policies, and controls that an organization uses to identify, assess, and manage risks that could affect the health and safety of its workers.
ISO 45001:2018 is the international standard that defines how an OHS management system should be structured and operated. It replaced OHSAS 18001 and is currently the global reference for occupational health and safety management, applicable to any organization regardless of size, sector, or location. We cover this further in our guide to ISO 45001:2018.
What makes ISO 45001 different from previous approaches is its emphasis on integration. It is not a checklist. It is a Plan-Do-Check-Act (PDCA) cycle embedded into the organization’s overall management structure, with leadership commitment, worker participation, and continual improvement as non-negotiable elements.
Who Does It Apply To?
Every organization that wants to demonstrate a systematic approach to OHS management. Certification to ISO 45001 is voluntary in most jurisdictions, but it is increasingly required by clients, public tenders, and supply chain agreements — particularly in industries such as construction, manufacturing, energy, logistics, and healthcare.
Beyond certification, the standard provides a solid framework for any organization that wants to move from reactive safety management — responding to accidents after they happen — to proactive risk control.
What Does ISO 45001 Actually Require?
The standard is organized around ten clauses. These are the most critical in practice:
Organizational Context and Leadership
The organization must understand the internal and external factors that affect its OHS performance, identify the needs and expectations of workers and other interested parties, and define the scope of the management system.
Leadership is not optional. Top management must demonstrate active commitment: establishing the OHS policy, ensuring resources, promoting a safety culture, and participating in the review process. A policy signed by someone who has never engaged with the system does not meet the standard’s intent.
Hazard Identification and Risk Assessment
This is the core of the system. The organization must identify all hazards to which workers are exposed, assess the associated risks, and define control measures following the hierarchy of controls: elimination, substitution, engineering controls, administrative controls, and personal protective equipment — in that order. This begins with understanding what a workplace risk is and applying structured methods like the NTP-330 methodology.
Hazard identification is not a one-time exercise. It must be updated when processes change, when incidents occur, when new equipment is introduced, or when work arrangements are modified.
OHS Objectives and Planning
The organization must set measurable OHS objectives consistent with the policy, and develop plans to achieve them. Objectives without resources, timelines, and assigned responsibilities are not objectives — they are wishes.
Competence, Training, and Awareness
Every worker must have the knowledge and skills needed to perform their tasks safely. The organization must determine what competence is required, verify that workers have it, and provide training where gaps exist. Evidence of training — records, assessments, certificates — must be maintained.
Operational Planning and Control
Processes that affect OHS must be planned and controlled. This includes managing contractors and outsourced processes: the organization remains responsible for ensuring safe conditions for all workers on site, regardless of their employment relationship.
Change management is a specific requirement. Before introducing a new process, chemical substance, piece of equipment, or work arrangement, the organization must assess the new risks it creates.
Incident Investigation and Corrective Action
All incidents — accidents, near misses, and situations with potential for harm — must be investigated to identify root causes and prevent recurrence. Investigation must be systematic, not a search for someone to blame. Treating near misses as warning signals is essential here.
Corrective actions must be tracked to completion. An organization that identifies problems but does not close them is not managing safety — it is documenting it.
Internal Audit and Management Review
The system must be audited at least annually. Audit findings must reach top management through a formal review process, and the review must result in decisions and actions. Without this cycle, the system does not improve — it stagnates.
What Typically Fails in Practice?
The same patterns appear across organizations of different sizes and sectors:
The system lives in a folder, not in operations.
Documents exist, but nobody updates them. The risk assessment was done three years ago and has not been reviewed since. Last year’s action plan was never closed. Training happened but there is no evidence.
It depends on one person.
When the OHS manager leaves or is on leave, the system stops. There are no defined processes, no shared tools, no continuity.
Contractors are not integrated.
Many organizations manage OHS for their direct employees but ignore contractors and subcontractors. ISO 45001 is clear: the organization is responsible for safe conditions for all workers under its control.
Corrective actions are not closed.
Problems are identified, measures are proposed, but nobody follows up. The same root causes generate the same incidents.
There is no traceability.
When an audit arrives, the OHS manager has to search through emails, folders, and spreadsheets to reconstruct what happened. That is not a system — it is a historical archive.
What Are the Consequences of Poor OHS Management?
The consequences of inadequate OHS management go beyond regulatory penalties, though those can be significant depending on jurisdiction.
The real costs are:
- Accidents that could have been prevented
- Occupational diseases that develop without early detection
- Legal liability for contractor incidents
- Reputational damage with clients and partners
- Loss of contracts in tenders that require ISO 45001 certification
- Direct and indirect costs of workplace injuries: medical expenses, lost productivity, replacement, investigation time
How Should It Be Managed Correctly?
An OHS management system that works has three characteristics that distinguish it from one that only exists on paper:
It is continuous, not periodic.
It does not activate before an audit. It operates every day because there are clear processes, shared tools, and defined responsibilities.
It generates evidence automatically.
Every activity leaves a record: a training session is logged, an inspection generates a report, a corrective action has a follow-up trail. Evidence is not reconstructed after the fact — it is produced in real time.
It connects all actors.
The OHS manager, line managers, workers, contractors, and top management each have access to the information relevant to their role and can act on it.
The PDCA cycle that ISO 45001 requires is not a formality. It is the structure that allows the system to improve rather than stagnate.
How an OHS Platform Supports ISO 45001 Compliance
Managing an OHS system with spreadsheets and email can work in very small organizations. In medium or large organizations — with multiple sites, contractors, and more than one person responsible for safety — that model creates inconsistencies, information gaps, and lack of traceability.
An OHS platform centralizes management in a single environment: updated risk assessments, action plans with real-time tracking, training records with evidence, incident investigations with root cause analysis, contractor document verification, and internal audits with mandatory corrective action closure.
The result is not just regulatory compliance. It is a system that generates useful information for decision-making: where the most critical risks are, which actions are pending, which workers need training, which contractors have expired documentation.
If you want to understand how this approach works in practice, you can read this article about OHS management platforms.
How Sabentis Fits Into This Context
Sabentis is an OHS management platform with over 20 years in the market, operating across Spain and Latin America. It is designed to help organizations implement and maintain an OHS management system aligned with ISO 45001, covering the full PDCA cycle.
It manages hazard identification and risk assessment, annual work plans, training with evidence, incident investigations, contractor coordination, and internal audits — all in a single environment with complete traceability.
For organizations operating across multiple countries, Sabentis also provides multinational regulatory coverage: the same platform manages OHS requirements in Spain, Colombia, Chile, Argentina, and Peru, each with its local regulatory framework.
ISO 45001 is not difficult to understand. What is difficult is maintaining a system that works in practice, generates real evidence, and improves over time.
Organizations that struggle with OHS management rarely have a knowledge problem. They have a management problem: unclear processes, dispersed tools, single-person dependency, and lack of traceability.
A well-structured system, with the right tools, makes ISO 45001 compliance manageable. More importantly, it builds something that actually protects workers — which is the point.
Ready to see how Sabentis can help you structure your OHS management system in line with ISO 45001? Request a demo and we will show you the platform configured for your regulatory context.



