An ISO 45001 maturity assessment measures something certification does not: not whether the occupational health and safety management system meets the standard, but how deeply it has taken root. Two organizations can hold the same certificate with one running a compliance exercise owned by the HSE manager and the other running a system in which supervisors identify hazards, workers report near misses without being asked and directors read incident trends before financial ones. The certificate cannot tell them apart; a maturity assessment can. This guide sets out a five-level maturity scale for ISO 45001, the seven dimensions it is scored on, the evidence that distinguishes each level, and how the assessment is used to set a target that the standard itself never sets.

ISO 45001 maturity assessment vs conformity audit
ISO 45001:2018 is a conformity standard. Clause 4.1 to 10.3 either are or are not met, and the certification audit reports nonconformities. It does not grade how well a requirement is met, and it deliberately allows a system that is documented, operated and evidenced at the minimum to be certified. A maturity assessment adds the grading: it asks, for each dimension of the system, whether the requirement is met because a procedure says so, because managers enforce it, because the organization measures and improves it, or because it is how people behave when nobody is checking. The distinction matters because incident rates track maturity, not certification. Our guide to the four types of ISO 45001 assessment places the maturity assessment among the others.
The five maturity levels
| Level | Name | How the system behaves | Typical evidence |
|---|---|---|---|
| 1 | Reactive | Safety is what happens after an incident; the system exists to satisfy a customer or the certificate | Procedures written by a consultant; hazard register not updated since certification; incidents recorded, not investigated |
| 2 | Managed | Requirements are met because the HSE function makes them happen | Current registers and records maintained by HSE; audits and reviews held on schedule; line managers comply when asked |
| 3 | Defined | Line management owns OH&S in its area; the system is embedded in operations | Supervisors run risk assessments and toolbox talks; managers chair safety meetings; KPIs cascade to departments |
| 4 | Measured | Performance is measured with leading indicators and drives decisions | Leading KPIs (near-miss reporting, inspection completion, corrective action timeliness) reviewed monthly; trends acted on; resources allocated by risk |
| 5 | Generative | Safety is how the organization works; workers improve the system unprompted | High near-miss reporting with low incident rates; worker-initiated improvements; contractors held to the same behaviours; leaders visible in the field |
The names echo the safety culture ladder used across high-hazard industries — pathological, reactive, calculative, proactive, generative — and the CMMI-style capability levels, and that is deliberate: an ISO 45001 maturity assessment borrows the level logic from both and applies it to the standard’s own clauses.
The seven dimensions of an ISO 45001 maturity assessment
A single overall score hides where the system is weak. Score seven dimensions separately, each anchored to the clauses it covers, and report the profile.
| Dimension | Clauses | Level 2 looks like | Level 4 looks like |
|---|---|---|---|
| Leadership and accountability | 5.1, 5.3 | Policy signed; roles documented | Leaders set OH&S objectives in their own plans; safety in performance reviews; leaders walk the floor with a record |
| Worker consultation and participation | 5.4 | A committee exists and meets | Workers initiate hazard reports and improvements; participation measured; representatives trained |
| Hazard identification and risk control | 6.1.2, 8.1.2 | Register complete; controls assigned | Register updated on change and after incidents; hierarchy-of-controls decisions recorded; risk reduction tracked |
| Legal compliance | 6.1.3, 9.1.2 | Register exists; compliance evaluated annually | Regulatory change monitored; evaluation by line functions; findings closed within target |
| Competence and awareness | 7.2, 7.3 | Training matrix; records | Competence verified on the job; refresher triggered by incidents and change; contractor competence assured |
| Incident learning | 10.2 | Incidents investigated; actions closed | Root causes trended; corrective action effectiveness reviewed; learning shared across sites; near-miss ratio rising |
| Performance measurement and review | 9.1, 9.3 | Lagging indicators reported; annual review | Leading and lagging indicators; quarterly review with decisions; objectives revised on evidence |
Running the ISO 45001 maturity assessment
- Anchor every level with evidence statements. Write, for each dimension, what a level 1 to 5 organization would be able to show. The statements above are the starting set; tailor them to the sector.
- Gather evidence three ways. Document and record review; interviews with leaders, line managers, workers and contractors; observation on the floor. Maturity is visible in behaviour, and behaviour is not in the files.
- Score each dimension independently. A dimension scores the highest level whose evidence statement is fully met. Partial credit is recorded as a note, not as a half-level.
- Report the profile, not the average. Seven scores on a radar or a bar chart. The lowest dimension is the priority, whatever the mean says.
- Set the target per dimension. Not every dimension needs to reach 5; a target of 4 across the board with 5 on incident learning and participation is a realistic three-year ambition for most organizations.
- Re-assess annually. Same statements, same method, ideally the same assessor. The movement is the measure.
Reading the profile
Three ISO 45001 maturity assessment patterns recur. A high leadership score with low participation means leaders are committed and workers have not noticed — communication and consultation mechanisms are the fix. High hazard-control scores with low incident-learning scores mean the system is good at preventing known risks and bad at finding new ones — near-miss reporting and root-cause quality are the fix. And a uniformly level-2 profile is a system that certification built and the HSE function carries: the fix is ownership, which means moving hazard identification, compliance evaluation and incident investigation to line management with HSE as support. Our guide to the safety culture assessment covers the methods that measure the behavioural side of that shift.
Frequently asked questions
What is an ISO 45001 maturity assessment?
A graded assessment of how deeply the OH&S management system is embedded — from reactive through managed, defined and measured to generative — scored on seven dimensions anchored to the standard’s clauses, rather than the pass/fail of a conformity audit.
Is maturity part of ISO 45001 certification?
No. Certification tests conformity to clauses 4–10. Maturity is an internal or consultant assessment used to set targets beyond the certificate; some clients and insurers ask for it.
How many levels should the scale have?
Five is the convention, matching both the safety culture ladder and capability maturity models. Fewer levels lose resolution; more invent distinctions the evidence cannot support.
Should we average the dimension scores?
Report the profile and use the lowest dimension as the priority. An average hides exactly the weakness the assessment exists to find.
How often should it be repeated?
Annually, with the same evidence statements and method so that the change is real. Most organizations move one level on one or two dimensions per year; a jump across the board is a sign the statements were not applied consistently.
Where this leaves you
Run the ISO 45001 maturity assessment as seven dimension scores on a five-level scale, each anchored to evidence statements and gathered from documents, interviews and observation. Report the profile, fix the lowest dimension first, set a target per dimension, and repeat annually. The certificate tells the world the system conforms; the maturity profile tells you whether it is keeping people safe.
References
- ISO 45001:2018 — Occupational health and safety management systems — the clauses each dimension is anchored to.
More on ISO 45001 assessment
- The ISO 45001 maturity assessment — you are here
- ISO 45001 assessment: the four types
- ISO 45001 gap analysis: what to check before you certify
- ISO 45001 readiness assessment: six checks
- Safety culture assessment: five methods
- ISO 45001 self-assessment: scoring clauses 4–10
The clause-by-clause questionnaire with reference, verification and area-of-concern columns that supplies the conformity baseline a maturity assessment builds on is the ISO 45001 Self-Assessment Tool, or start with the free templates.