What is ISO 45001 and what results does it aim to achieve?
ISO 45001 establishes a framework for managing occupational health and safety as part of an organization’s day-to-day management. Its intended outcomes are continual improvement of OHS performance, compliance with applicable legal requirements and other commitments, and the achievement of OHS objectives . To achieve these outcomes, it requires identifying hazards, assessing risks and opportunities, establishing controls, and verifying their effectiveness.
The standard is not simply a set of procedures. It requires that policy, responsibilities, resources, operational decisions, and management review form a coherent system. The organization must be able to demonstrate that the system is applied in actual work and that it produces useful information for preventing injuries and ill health.
Scope and limits of the standard
It can be used by any organization, regardless of its size, activity, legal structure, or location. The system adapts to its context, the relevant needs and expectations of employees and other stakeholders, and the risks over which the organization has control or influence. It also covers those who work under its control and other individuals who may be affected by its activities.
ISO 45001 does not establish a universal accident rate or prescribe a single design. Nor does it, on its own, regulate product safety, property damage, or environmental impacts, except when related to occupational health and safety. Conformity requires incorporating and meeting all applicable requirements of the standard within the declared scope.
How the improvement cycle works
The system follows the Plan-Do-Check-Act (PDCA) cycle:
- Planning: understanding the context, identifying hazards and obligations, assessing risks and opportunities, and setting objectives and actions.
- Do: contribute resources and skills, communicate, consult and involve, and control operations, purchases, contractors, changes and emergencies.
- Verify: measure performance, assess compliance, conduct internal audits, and review the system from management.
- Act: respond to incidents and nonconformities, implement corrective actions, and continuously improve.
This approach avoids treating each problem in isolation. The results of the verification process are fed back into the planning stage and can modify controls, objectives, resources, or processes. The harmonized structure facilitates integration of the system with other ISO management standards.
Leadership, consultation, and participation
Senior management retains responsibility for the effectiveness of the system: they must establish policy, integrate requirements into processes, provide resources, and support those who contribute to occupational health and safety. Delegating tasks to a prevention service or a designated individual does not eliminate this accountability.
The consultation and participation of employees, especially those in non-managerial roles, is essential. The organization must provide time, training, information, and mechanisms for them to participate in hazard identification , risk assessment, incident investigation, control definition, and performance evaluation. It must also eliminate or reduce barriers such as fear of retaliation, inaccessible language, or lack of response to communications.
Risk planning and control
Planning combines occupational health and safety (OHS) risks with the risks and opportunities that may affect the system itself. It must consider routine and non-routine activities, human factors, work organization, changes, emergencies, contractors, and past or foreseeable conditions. Legal requirements and other requirements accepted by the organization must be identified, kept up to date, and translated into verifiable controls.
When determining controls, a hierarchy is applied: eliminate the hazard; replace processes, materials, or equipment with less hazardous alternatives; use technical controls and reorganize work; implement administrative controls and provide training; and use PPE for residual risk. Purchases, outsourcing, and changes require proportionate controls so that a business or technical decision does not introduce unassessed risks.
How to implement it in a practical way
A successful implementation begins with a diagnosis of the context, applicable obligations, and existing preventative system. Next, the scope is defined, responsibilities and resources are assigned, and actual practices are compared with the requirements. This gap analysis then informs the development of a prioritized plan, not an indiscriminate collection of documents.
It is advisable to integrate controls into existing processes: design, production, maintenance, purchasing, contracting, training, and change management. Each objective requires an indicator, a responsible party, resources, and a timeframe. Documented information must be sufficient for operational purposes and to provide evidence, but its extent depends on the complexity and risk involved. Before declaring conformity, the organization must test the controls, evaluate compliance, complete an internal audit, and conduct a management review.
Evaluation, incidents and continuous improvement
The organization determines what it needs to measure and by what criteria. It can combine outcome indicators, such as damages or incidents, with preventive indicators, such as completed inspections, controlled exposure, effective closure of actions, or participation. In addition, it periodically assesses legal compliance, audits the system, and reviews trends and changes during management review.
In the event of an incident or nonconformity, you must react, control and correct the situation, address its consequences, and investigate the causes. Corrective actions must prevent recurrence, respect the hierarchy of controls, and be subject to effectiveness verification. A certificate or an audit without findings does not, in itself, demonstrate the absence of risks; the decisive evidence is a maintained system that learns and improves its performance.
Certification, legal relationship and current version
Certification by an independent body is voluntary and distinct from implementation: an organization can use ISO 45001 without being certified. If you are seeking external recognition, an accredited certification body provides additional proof of competence and impartiality. ISO publishes the standard but does not certify organizations.
In Spain, ISO 45001 does not replace Law 31/1995, the Regulation of Prevention Services, or specific regulations. It can help to organize compliance, but legal responsibility is determined by the applicable regulations, not by the possession of a certificate.
As of August 29, 2026, ISO 45001:2018 was still the current version: it had been revised and confirmed in 2024 and was to be applied with Amendment 1:2024, which incorporates the consideration of climate change within the context of the system. The second edition, ISO/DIS 45001, was in the draft stage and did not yet replace the 2018 edition.
