Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Is ISO 45001 a legal requirement: voluntary standard versus mandatory law

Is ISO 45001 a Legal Requirement? The Clear Answer for 2026

No. ISO 45001 is not a legal requirement in any country. It is a voluntary international standard, and no government mandates certification to it.

That is the short answer, and it is also the answer that gets people into trouble, because the health and safety law sitting underneath ISO 45001 is absolutely mandatory. The standard is optional. The duties it helps you discharge are not.

Is ISO 45001 a legal requirement: what is voluntary, what is mandatory law, and what is contractual
Three different kinds of obligation, regularly confused for one another.

Every jurisdiction with an industrial economy places a general duty on employers to protect workers. That duty exists whether or not you have ever heard of ISO 45001.

Jurisdiction The mandatory duty
United States The OSH Act of 1970. Section 5(a)(1), the General Duty Clause, requires a workplace free from recognized hazards likely to cause death or serious physical harm, alongside the specific OSHA standards.
United Kingdom The Health and Safety at Work etc. Act 1974, plus the Management of Health and Safety at Work Regulations 1999, which require a suitable and sufficient risk assessment.
India The Occupational Safety, Health and Working Conditions Code 2020, consolidating earlier legislation including the Factories Act.
European Union Framework Directive 89/391/EEC, transposed into each member state’s national law.

None of these name ISO 45001. That is the whole answer to whether ISO 45001 is a legal requirement: the outcomes are compulsory, the certificate is not. All of them require the outcomes ISO 45001 is designed to produce: hazards identified, risks assessed, controls applied, workers consulted, incidents investigated.

Where it becomes effectively compulsory anyway

Plenty of organisations experience ISO 45001 as mandatory, and they are not wrong about their own situation. Is ISO 45001 a legal requirement for them? Still no. The obligation is contractual rather than legal.

Tenders and prequalification. Construction, energy, rail and public sector procurement routinely list certification as a condition of bidding. You are free not to hold it, and equally free not to win the work.

Supply chain requirements. Large manufacturers push their own management system requirements down to suppliers, and an ISO 45001 certificate is the cheapest way for a buyer to satisfy itself that a supplier has a system rather than a folder of policies.

Insurance. Some employers’ liability underwriters price against demonstrated safety management, and certification is accepted evidence.

The practical distinction: a legal requirement is enforced by a regulator with the power to prosecute. A contractual requirement is enforced by losing the contract. Both are real. Only one of them carries a criminal penalty.

How ISO 45001 helps with the law it is not

Two clauses do most of the legal work, and they are the reason the standard is worth holding even where nobody demands it.

Clause 6.1.3 requires you to determine your legal and other requirements and to keep that determination current. In practice this is a legal register: what applies to you, where it comes from, and who owns it. Most organisations find gaps the first time they build one honestly.

Clause 9.1.2 requires you to evaluate compliance with those requirements at planned intervals and to retain the results. This is the part that turns a register from a list into evidence, and it is the closest the standard comes to being a legal defence, because it produces a documented record that you checked.

Neither clause makes you compliant with anything. They make non-compliance visible early, which is a different and more useful thing.

A revision is close, so time this decision carefully

ISO 45001:2018 is the current edition. A revision is well advanced: the Draft International Standard went to ballot with the voting period closing on 8 September 2026, and publication is expected in 2027. The direction of travel is a wider frame that takes in worker wellbeing, psychosocial risk and safety culture alongside traditional hazard control.

That does not argue for waiting. Certification to the 2018 edition remains valid and a transition period will follow publication, as it did for previous revisions. It does argue for building your documentation somewhere it can be revised, rather than treating it as finished.

So should you certify

Is ISO 45001 a legal requirement you can simply ignore, then? Not quite, because the reasons to hold it are commercial rather than statutory. Certify if a customer or tender requires it, if you operate in a high-hazard sector where demonstrating system maturity has commercial value, or if your existing safety arrangements have grown organically and nobody can say with confidence what the whole picture looks like.

Do not certify because you think it is the law. ISO 45001 is not a legal requirement, anywhere. Certify because the discipline of clause 6.1.3 and clause 9.1.2 is worth having, or because somebody is paying you to hold the certificate.

More on ISO 45001

The standard itself is published by ISO as ISO 45001:2018. Legal register and compliance evaluation templates are included in the ISO 45001 Toolkit, or start with the free ISO templates.

Legislation cited as at 6 September 2026. Revision status taken from the ISO/TC 283 committee ballot record.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.