ISO 45001 implementation fails for predictable reasons: it is run as a
documentation project, the workforce finds out about it at the audit, and the legal register is
written the week before stage 1. This is a ten-step plan that avoids those, with honest timings.
Before step one of ISO 45001 implementation: decide who owns it
ISO 45001 implementation starts higher up than it used to. The standard removed the concept of a “management representative” that OHSAS 18001 relied on, and
put accountability on top management directly under clause 5.1. You still need someone to run the
project day to day, but if the only person who can describe the system is the health and safety
adviser, stage 2 will go badly. Auditors interview senior managers.
The ten steps of ISO 45001 implementation
- Gap analysis (2–4 weeks). The first move in any ISO 45001
implementation. Assess current practice against every clause and
produce a costed action list. This is the step that makes the remaining nine estimable. - Scope and context (1–2 weeks). Define what the system covers: sites,
activities, workers, contractors. Record internal and external issues, including climate change as
required by the 2024 amendment, and the needs of workers and other interested parties. - Policy and leadership commitment (1 week). A short policy signed and meant,
plus documented roles and responsibilities. - Set up worker consultation (2–4 weeks, then ongoing). Clause 5.4 is the
clause most often left until last and it is the one that cannot be retrofitted — you need a
record of participation over time. Start it early. - Hazard identification and risk assessment (4–10 weeks). Write the
methodology first, then work through activities. See our guide to
ISO 45001 risk assessment. - Legal register and compliance evaluation (3–6 weeks). Identify the
obligations that actually apply and record how you evaluate compliance with each. - Objectives and operational controls (3–6 weeks). Measurable objectives
with owners; operational controls applying the hierarchy in 8.1.2; management of change; contractor
and procurement controls; emergency preparedness with drills scheduled. - Competence, awareness and communication (3–6 weeks, overlapping). Define
competence requirements, close the gaps, keep the records. - Run the system (3–6 months). This is the step nobody puts in the plan.
The system must generate real records — incidents, monitoring, consultation, drills —
before an audit has anything to sample. - Internal audit, management review, then certification. Both are prerequisites.
See the ISO 45001 internal audit checklist and
our guide to ISO 45001 certification.
Skip the blank page.
The ISO 45001 Toolkit supplies every document in this plan in editable Word and Excel — policy, risk methodology, legal register, objectives, operational controls, emergency plans, audit set — so implementation becomes editing rather than authoring.
The three steps ISO 45001 implementation plans always underestimate
Step 9, running the system. This is the single biggest scheduling error in ISO 45001 implementation. Plans routinely go from “documents complete” to
“certification audit” in a fortnight. It cannot work: clause 9.2 needs audit results, 9.3 needs
management review inputs, 10.2 needs incidents processed through the system. Budget three to six
months of genuine operation, and start the clock when the process goes live, not when the document is
signed.
Step 6, the legal register. A list of statute titles takes a day and is worthless.
A register that names the specific duties that bind your activities, in each jurisdiction you operate
in, with an evaluation of compliance against each, takes weeks and is what 6.1.3 and 9.1.2 actually
require.
Step 4, worker consultation. Retrofitting it late in an ISO 45001 implementation is impossible. The evidence is a trail
over months: committee minutes, hazard reports and what happened to them, workers involved in writing
the risk assessments for their own tasks.
ISO 45001 implementation alongside ISO 9001 or ISO 14001
If you already run either, roughly half of ISO 45001 implementation is done. Clauses 4, 5, 7, 9 and 10 follow the same
harmonized structure, so context, competence, document control, internal audit, management review and
improvement can be shared processes with OH&S content added rather than rebuilt. Budget the saving
against clauses 6.1.2, 8.1.2 and 5.4, which have no equivalent in the other two and will absorb it.
Our overview of ISO 45001 and workplace safety covers where the standard sits in a
wider management system.
A second edition is on its way
ISO 45001:2018 is now marked on iso.org as an International Standard to be revised, and the draft second edition, ISO/DIS 45001, has reached the DIS ballot stage (40.20) — a twelve-week vote by national member bodies. The draft runs to 48 pages against the current 41.
Two things follow from that, and they pull in opposite directions. A draft is not a standard: DIS text can and does change before publication, so nothing in it should be built into a management system yet. But a revision does mean a transition period will follow publication, as it did when OHSAS 18001 gave way to ISO 45001. A system that is documented cleanly, with a maintained clause cross-reference, transitions in weeks. One held together by tribal knowledge does not. That is an argument for getting the documentation right now rather than after the second edition lands.
The separate climate action amendment is already in force. ISO 45001:2018/Amd 1:2024, published in February 2024 and issued free of charge, adds climate change to clause 4.1 and to the interested-party expectations in clause 4.2. It is short, but it is a live requirement and auditors do ask about it.
A realistic total for ISO 45001 implementation
For a single-site organisation of fifty to two hundred people with no existing certification,
nine to twelve months from gap analysis to certificate is a plan you can defend.
Six months is possible where an ISO 9001 system already exists and health and safety practice is
mature. Anything under four months means either the scope is very small or step 9 has been skipped,
and step 9 is the one the auditor samples.
References
- ISO 45001:2018 — the standard itself on iso.org.
- ISO 45001:2018/Amd 1:2024 — the climate action amendment, published free of charge by ISO.
- ISO/DIS 45001 — the draft second edition, currently at DIS ballot.
More on ISO 45001
- ISO 45001 certification
- ISO 45001 implementation guide — you are here
- ISO 45001 mandatory documents
- ISO 45001 risk assessment
- ISO 45001 internal audit checklist
- ISO 45001 gap analysis
All of these are covered by the ISO 45001 Toolkit. To score where you stand first, use the ISO 45001 Assessment Tool, or browse the free ISO templates.
Implementation guides for the other standards
- ISO 27001 implementation
- ISO 9001 implementation
- ISO 13485 implementation
- ISO 14001 implementation
- ISO 45001 implementation — you are here
- ISO 22301 implementation
- GDPR implementation
- ISO 42001 implementation
- ISO 20000 implementation
- HIPAA implementation