Professional Service
ISO 45001:2018
All 10 Clauses

We prepare your ISO 45001
gap assessment

Our EHS specialists conduct a full ISO 45001:2018 gap assessment for your organization — covering all 10 clauses, identifying compliance gaps, and delivering a prioritized action plan to achieve certification.

✓ All 10 clauses assessed   ✓ Prioritized action plan   ✓ Fixed fee, fast turnaround

What is ISO 45001?

ISO 45001:2018 is the international standard for occupational health and safety management systems (OHSMS). It replaced OHSAS 18001 as the global benchmark for OH&S management and is used by more than 300,000 organizations worldwide.

Certification to ISO 45001 signals to customers, insurers, and regulators that your organization systematically manages workplace safety risks — not just reacts to incidents.

For US businesses, ISO 45001 certification complements OSHA compliance — the standard's systematic approach to hazard identification and risk control aligns directly with OSHA's expectations for proactive safety management.

PublishedMarch 2018 (replacing OHSAS 18001)
Standard bodyISO (International Organization for Standardization)
Certification body optionsBSI, Bureau Veritas, DNV, SGS, TÜV, UL
Typical certification timeline3–12 months from gap assessment to Stage 2 audit
Certification cycle3 years with annual surveillance audits
Compatible standardsISO 9001, ISO 14001 (Annex SL structure)

The ISO 45001 certification journey

Stage 1

Documentation Review

1–2 days on-site or remote

Auditor reviews your documented information — policies, procedures, risk register, legal register, objectives. Verifies scope and readiness for Stage 2.

Preparation tips

  • Ensure all required documented information is complete and current
  • Have your scope statement clearly defined
  • Demonstrate your legal and other requirements register is comprehensive
  • Show evidence of management commitment beyond a signed policy

Stage 2

Certification Audit

2–5 days on-site (varies by organization size)

Auditor verifies the OHSMS is effectively implemented throughout the organization. Worker interviews, site observations, and record sampling.

Preparation tips

  • Train workers on the ISO 45001 policy and their responsibilities
  • Have operational records (training records, inspection logs, incident investigations) organized and accessible
  • Demonstrate worker participation — not just management talking
  • Show that risk assessments drive actual operational controls

Surveillance

Surveillance Audits

Annual (Years 1 and 2 of 3-year cycle)

Confirms the system continues to function effectively. Focuses on areas identified in Stage 2 and any significant changes.

Preparation tips

  • Maintain momentum after certification — don't let the system slide
  • Track and close corrective actions from the previous audit
  • Document continual improvement activities throughout the year
  • Keep your legal register updated as OSHA regulations change

Clause-by-clause audit checklist

For each clause, the key requirement and the typical audit question your certification auditor will be asking.

4
Clause 4: Context of the Organization
4.1

Understanding the organization and its context

Can you demonstrate a structured analysis of internal and external issues affecting your OH&S objectives?

4.2

Understanding the needs of workers and interested parties

Is there a documented register of interested parties and their relevant requirements?

4.3

Determining the scope of the OH&S MS

Is the scope clearly defined, documented, and available to interested parties?

4.4

OH&S management system

Is there evidence that the OHSMS is established, implemented, maintained, and continually improved?

5
Clause 5: Leadership & Worker Participation
5.1

Leadership and commitment

Can top management demonstrate active commitment — not just a signed policy, but measurable involvement?

5.2

OH&S policy

Is the policy documented, communicated, available to workers, current, and signed by top management?

5.3

Organizational roles, responsibilities, and authorities

Are EHS roles and responsibilities assigned, documented, and communicated at all levels?

5.4

Consultation and participation of workers

Are there mechanisms for workers at all levels to participate in hazard identification, incident investigation, and system improvement?

6
Clause 6: Planning
6.1.1

General planning for risks and opportunities

Is there a process to determine risks and opportunities that need to be addressed?

6.1.2

Hazard identification

Is hazard identification systematic, ongoing, and covering routine/non-routine activities and emergencies?

6.1.3

Assessment of OH&S risks and opportunities

Is there a documented risk assessment methodology with risk scoring and residual risk evaluation?

6.1.4

Determination of legal and other requirements

Is there a legal register covering all applicable OSHA standards, EPA requirements, and state regulations?

6.2

OH&S objectives and planning to achieve them

Are objectives measurable, monitored, communicated, and supported by action plans with owners and due dates?

7
Clause 7: Support
7.1

Resources

Are adequate resources (financial, human, infrastructure) provided for the OH&S management system?

7.2

Competence

Is there a competency matrix? Are training records maintained and verified for all safety-critical roles?

7.3

Awareness

Do workers demonstrate awareness of the OH&S policy, their contribution, the consequences of non-conformance?

7.4

Communication

Are there documented processes for internal and external OH&S communication? Is communication two-way?

7.5

Documented information

Is documented information controlled, protected from unintended alterations, and retrievable? Version control in place?

8
Clause 8: Operation
8.1.1

Operational planning and control

Are operational controls established for all significant hazards, including documented procedures where absence could lead to deviation?

8.1.2

Eliminating hazards and reducing risks

Is the hierarchy of controls applied systematically, with documented rationale for control selection?

8.1.3

Management of change

Is there a formal MOC process evaluating OH&S implications before changes are implemented?

8.1.4

Procurement and contractors

Are contractor pre-qualification, site induction, and ongoing oversight procedures documented and followed?

8.2

Emergency preparedness and response

Are emergency scenarios identified, procedures documented, personnel trained, and drills conducted and recorded?

9
Clause 9: Performance Evaluation
9.1.1

Monitoring, measurement, analysis and evaluation

Are leading and lagging indicators defined, measured, and analyzed? Who reviews what, and when?

9.1.2

Evaluation of compliance

Is there a documented process to evaluate compliance with legal and other requirements at planned intervals?

9.2

Internal audit

Is an internal audit program established? Are audits conducted, findings documented, and corrective actions tracked?

9.3

Management review

Does management review occur at planned intervals? Are all required inputs covered? Are outputs documented and acted upon?

10
Clause 10: Improvement
10.1

General improvement

Is there a systematic approach to identifying improvement opportunities and implementing them?

10.2

Incident, nonconformity and corrective action

Is there a documented process for investigating incidents, determining root cause, and implementing/verifying corrective actions?

10.3

Continual improvement

Is there evidence of ongoing, proactive improvements to OH&S performance — not just reactions to incidents?

HMS Nova is built for ISO 45001

Every feature in HMS Nova maps to a specific ISO 45001 clause — so as you use the platform, you're automatically generating the evidence an auditor needs.

Clause 6.1.2

Risk assessment module with hazard register and risk scoring

Clause 6.1.4

Legal and other requirements register with compliance tracking

Clause 7.2

Competency matrix and training records with renewal tracking

Clause 7.5

Document control with version history and approval workflows

Clause 9.2

Internal audit program with scheduling, findings, and CAPAs

Clause 9.3

Management review module with input/output documentation

Clause 10.2

Incident investigation with 5-Whys and corrective action tracking

Clause 9.1.1

KPI dashboards with TRIR, DART, and leading indicators