ISO 45006

ISO 45006:2023 is an international standard providing guidelines for organizations on preventing, controlling, and managing infectious diseases in the workplace. Its official title is Occupational health and safety management – ​​Guidelines for organizations on preventing, controlling, and managing infectious diseases . It was published in December 2023 by ISO/TC 283 as its first edition. It does not contain requirements, is not certifiable, and does not replace mandatory regulations on biological agents.

In short

Guidelines on infectious diseases at work. Published in 2023, first edition, by ISO/TC 283 committee. It provides criteria for anticipating, assessing, and controlling the risk of transmission in the workplace, with organizational, technical, and communication measures. It succeeds ISO/PAS 45005, which focused on the COVID-19 pandemic, and is applied voluntarily alongside each country’s regulatory framework.

Content
  1. What is ISO 45006?
  2. What it covers
  3. Who does it help?
  4. Relationship with Spanish regulations
  5. How it is applied in practice
  6. Non-certifiable character
  7. Limits and common mistakes
  8. Practical example
  9. Differences with other publications in the family
  10. Regulatory and reference framework
  11. Related concepts
  12. References

A–Z dictionary →

What is ISO 45006?

The experience of the pandemic left many organizations with written protocols for a specific disease but without a general framework for future outbreaks. ISO 45006 addresses this gap: it tackles infectious diseases as a category, not just a specific outbreak, with guidelines on how to prevent, control, and manage them in the workplace.

Its exact code and name are ISO 45006:2023, Occupational health and safety management. Guidelines for organizations on preventing, controlling and managing infectious diseases . It is the first edition, published in December 2023 and prepared by the ISO/TC 283 technical committee, and is listed in the official ISO catalog as a published international standard.

What it covers

  • Anticipation. How to identify the risk of transmission associated with the activity, workplaces and travel.
  • Prevention. Organizational and technical measures before resorting to individual measures, consistent with the hierarchy of controls.
  • Control. Action when cases appear, including criteria for isolation and continuity of activity.
  • People. Attention to those who are most vulnerable and to the effects on their psychological health.
  • Communication. Information that is understandable, timely, and consistent with the available evidence.

Who does it help?

It is intended for any organization that wants to establish a stable framework, rather than an improvised protocol, for dealing with communicable diseases. It is especially relevant in healthcare, social services, education, passenger transport, hospitality, the food industry, and activities involving frequent contact with the public.

It is also useful for those who already manage the risk from biological agents and want to review the organizational aspects: communication, coordination with prevention services, business continuity and support for affected individuals.

Relationship with Spanish regulations

In Spain, the protection of workers from biological agents is regulated by Royal Decree 664/1997, which mandates risk assessment, the application of containment measures according to the agent’s classification, and the establishment of health surveillance where appropriate. This obligation is prior to and independent of any voluntary regulations.

ISO 45006 goes beyond that minimum: it doesn’t replace it, but rather provides organizational and management criteria that the regulatory standard doesn’t detail. When specific health obligations exist, these also take precedence.

How it is applied in practice

The starting point is usually an inventory of exposure situations: contact with users or patients, working in crowded, enclosed spaces, shared use of equipment, travel, and activity in areas with seasonal disease transmission. Based on this inventory, decisions are made about what measures are appropriate before resorting to individual ones: ventilation, separation of traffic flows, shift scheduling, teleworking when possible, and adjustments to space occupancy.

The second area is decision-making: what triggers each level of action, who declares it, and with what information. Without these criteria defined in writing, the organization is once again improvising in each situation.

The third is about people: how information is provided, how those who are most vulnerable are cared for, how coordination with health surveillance is carried out, and how the confidentiality of data is protected, since these are health data and are subject to a specific regime.

Finally, the review: each episode leaves information about what worked and what didn’t, and that information should be fed back into the procedure.

Non-certifiable character

  1. It is a set of guidelines: it does not establish auditable requirements nor does it allow for certification.
  2. The certification of health and safety management systems is carried out according to ISO 45001.
  3. ISO publishes standards; it does not certify organizations or issue certificates.
  4. Presenting a certification seal under ISO 45006 would be incorrect.
  5. It can be stated that the procedures have been developed following their guidelines.

Limits and common mistakes

  1. Treat it as a standard of requirements or as a certification.
  2. Replace with it the biological risk assessment required by Royal Decree 664/1997.
  3. Reducing it to a cleaning and ventilation protocol, ignoring the organizational and communication aspects.
  4. Copying the pandemic protocol without reviewing activation and de-escalation criteria.
  5. Take individual measures before exhausting collective and organizational ones.
  6. Processing people’s health data without the required confidentiality guarantees.

Practical example

A nursing home reviews its management of communicable diseases after several outbreaks of seasonal flu impacted staff and residents.

  • Starting point. There are health protocols, but no organizational framework: it is not clear who decides, with what criteria, or how it is communicated.
  • Review. Taking the standard as a guide, activation levels, responsible parties, graduated measures, and return criteria are defined.
  • Integration. It is linked to the biological risk assessment and health surveillance, and is agreed upon with the safety and health committee.
  • Outcome. The next outbreak is managed with documented decisions and predictable communication, without improvisation.

Differences with other publications in the family

  • ISO 45001. Standard of requirements, the only one that can be certified.
  • ISO 45002 and ISO 45004. Guidelines on implementation and on performance evaluation.
  • ISO 45003. Guidelines on psychosocial risks.
  • ISO/PAS 45005. Specification focused on safe work during the COVID-19 pandemic, with a narrower scope and earlier.
  • ISO/PAS 45007. Specification on risks arising from climate change and climate action.

Regulatory and reference framework

Related concepts

References

  1. International Organization for Standardization. ISO 45006:2023, Occupational health and safety management. Guidelines for organizations on preventing, controlling and managing infectious diseases . First edition, December 2023. ISO/TC 283 Committee. Official source
  2. International Organization for Standardization. ISO/PAS 45005:2020, General guidelines for safe working during the COVID-19 pandemic . Official source
  3. International Organization for Standardization. Technical Committee ISO/TC 283, catalogue of published and developing standards. Official source
  4. Official State Gazette. Royal Decree 664/1997, of May 12, on the protection of workers against risks related to exposure to biological agents at work. Current consolidated text. Official source
  5. Official State Gazette. Law 31/1995, of November 8, on Occupational Risk Prevention. Current consolidated text. Official source

Editorial information

Last revision: September 5, 2026 .

Editorial Manager: Sabentis Editorial Team .

First editorial review by Pablo Rodríguez LinkedIn

Executive Vice President of the ORP International Foundation and Chief Financial Officer of Sabentis.

Request a Demo

Discover all that Sabentis can do for your organization.

Try Sabentis

request a demo
stars 5
GetApp Software Advice Capterra