An ISO 45001 assessment can mean four different exercises, and the word gets used interchangeably for all of them. They have different purposes, different people running them, and different outputs — and asking for the wrong one is how organizations end up paying for a certification audit they were not ready for.
This guide sets out the four, what each proves, when to run it, and how to score one so the result is usable rather than a colour-coded opinion.

The four types of ISO 45001 assessment
| Type | Question it answers | Who runs it |
|---|---|---|
| Self-assessment | Roughly where are we, clause by clause? | The OH&S lead, on a scoring sheet |
| Gap analysis | What specifically is missing before we certify, and what will it cost? | An experienced practitioner, internal or external |
| Internal audit | Does the system conform and is it effectively implemented and maintained? | Trained internal auditors, independent of the area audited |
| Certification audit | Can a certificate be issued? | An accredited certification body, in two stages |
The internal audit is the only one ISO 45001 actually requires — clause 9.2 obliges you to run an internal audit programme at planned intervals. The other three are choices, and each earns its place at a different point.
1. Self-assessment
A scoring pass across the clauses, done by the person who runs the system, usually in a workbook. Its value is speed and repeatability: run it quarterly and the trend tells you whether the system is maturing or drifting. Its weakness is that the person scoring is the person responsible, which pushes scores up.
Counter it with evidence rules. Score against what you could put in front of an auditor this afternoon, not what exists in draft. A useful convention: 0 nothing, 1 documented but not implemented, 2 implemented in part of the organization, 3 implemented everywhere, 4 implemented and evidenced as effective. Anything above 1 needs a named artifact next to it.
2. Gap analysis
Narrower and more decisive than a self-assessment: what is missing, what does closing it involve, and in what order. A gap analysis is worth buying externally because the value is in the estimate — someone who has seen a dozen certifications can tell you which gaps are two days of writing and which are six months of behaviour change. Our guide to running an ISO 45001 gap analysis covers the scoring and weighting in detail.
3. Internal audit
Clause 9.2 requires internal audits at planned intervals to determine whether the OH&S management system conforms to the organization’s own requirements and to the standard, and whether it is effectively implemented and maintained. Two features distinguish it from the first two: the auditors must be objective and impartial with respect to what they audit, and the results must be reported to relevant management — which is what turns findings into action.
Alongside it sits the evaluation of compliance under clause 9.1: a separate, documented determination of whether you meet your legal and other requirements. Organizations routinely fold this into the internal audit and then cannot produce it as a record. Keep it as its own output.
4. Certification audit
Run by an accredited certification body in two stages: a stage 1 that checks readiness, scope, documented information and the internal audit and management review records, then a stage 2 that tests implementation and effectiveness across the scope. Certification then runs on a three-year cycle with surveillance in between.
The size of the audit is not negotiable in the way people expect — accredited bodies work from IAF mandatory documents that set audit duration against the number of effective personnel and the risk category of the work, with defined limits on how far that can be adjusted. If a quote looks unusually cheap, the question to ask is how many audit days it contains.
Which ISO 45001 assessment to run, and when
- Twelve months out: self-assessment to establish the baseline, then a gap analysis to convert it into a costed plan.
- Six months out: close the structural gaps — hazard identification and risk assessment methodology, legal register, worker consultation and participation arrangements, incident procedure, objectives and plans.
- Three months out: a full internal audit cycle covering every clause and every site in scope, plus the evaluation of compliance and a management review. These are the records stage 1 will ask for, and their absence is the most common reason a stage 1 ends with a delay.
- Then: stage 1, remediate, stage 2.
Running them in the other order — booking certification first and discovering the gaps during stage 1 — is what turns a nine-month project into an eighteen-month one.
Scoring an ISO 45001 assessment so the result is usable
Three rules make the difference between a scoring sheet that drives work and one that decorates a slide:
- Weight the clauses. Hazard identification and risk assessment, worker consultation and participation, legal compliance and incident management carry more consequence than, say, the format of your documented information. A flat average across clauses hides the gaps that matter.
- Record the evidence reference, not the opinion. “Procedure OHS-07 rev 3, last reviewed March, three trained assessors” is a score you can defend. “Mostly compliant” is not.
- Separate design from operation. A control that exists and a control that works are two different scores, and mixing them is how a system that looks complete on paper fails a stage 2.
Frequently asked questions
Is an ISO 45001 assessment the same as an audit?
No. An audit is a formal, evidence-based examination against defined criteria by an objective auditor. Self-assessments and gap analyses are management tools with no independence requirement.
Does ISO 45001 require a gap analysis?
No. It requires internal audits, an evaluation of compliance, and management review. Gap analyses and self-assessments are optional but usually cheaper than discovering the same information during a certification audit.
Who can run our internal audit?
Anyone competent and objective with respect to the area audited. Small organizations often cross-audit between departments or bring in an external auditor for independence.
How long does the certification audit take?
It depends on effective personnel numbers and risk category, using the IAF duration tables the certification body must apply. Ask any prospective body to state the audit days in the quote.
How often should we self-assess?
Quarterly is enough to show a trend without becoming an administrative burden. The value is in comparing the same questions over time.
Where this leaves you
Pick the ISO 45001 assessment that matches the decision you are trying to make. Self-assess to see the trend, gap-analyze to build a costed plan, audit internally because the standard requires it and because it is your rehearsal, and only then book the certification body. Score against evidence you could show today, weight the clauses that carry real consequence, and keep the evaluation of compliance as its own record — it is the one auditors ask for and organizations most often cannot find.
References
- ISO 45001:2018 — Occupational health and safety management systems, including clause 9 performance evaluation.
- IAF mandatory documents — the audit-duration and certification requirements accredited bodies must apply.
More on ISO 45001
- The ISO 45001 assessment — you are here
- Running an ISO 45001 gap analysis
- The ISO 45001 internal audit checklist
- ISO 45001 certification, stage by stage
The scoring workbook behind a clause-by-clause review is the ISO 45001 Assessment Tool, or start with the free ISO templates.