ISO 45001 certification is how an organisation demonstrates that its occupational
health and safety management system meets the international standard. This guide covers what the
process involves, how long it takes, what it costs, and why first attempts fail — plus the
revision now working its way through ISO.
What ISO 45001 certification actually proves
Certification is an independent audit of your OH&S management system against
ISO 45001:2018, carried out by an accredited
certification body, resulting in a certificate covering a defined scope: legal entity, sites and
activities. Unlike a product mark, ISO 45001 certification is awarded to the management system
itself rather than to anything it produces.
It is worth being precise about what it does not prove. ISO 45001 certification is not a
statement that your workplace is safe, and it is not a substitute for meeting national
health and safety law. It says a system exists to identify hazards, control risks and improve
— and that the system was working on the days the auditor sampled it. Regulators treat it as
supporting evidence of due diligence, not as a defence. Organisations that pitch the certificate
internally as proof of safety tend to stop looking, which is exactly the behaviour the standard is
designed to prevent.
The stages of ISO 45001 certification
- Gap analysis. Compare current practice against the clauses before anyone
external does. The cheapest step in ISO 45001 certification. Optional, and the single highest-return step. - Implementation. Hazard identification, risk assessment, legal register,
objectives, competence records, consultation arrangements, emergency plans, incident process. Most
of the elapsed time goes here. - Internal audit and management review. Both are mandatory before the
certification audit, not after it. A certification body will ask for the records and will raise a
nonconformity if they do not exist. - Stage 1 audit. A readiness and documentation review, usually short. The auditor
checks scope, policy, the hazard identification process, the legal register, and whether internal
audit and management review genuinely ran. - Stage 2 audit. The full assessment on site: sampling records, walking the
workplace, and — distinctively for this standard — interviewing non-managerial
workers about whether they are consulted and how they raise concerns. - Nonconformity closure. Majors corrected and verified before the certificate
issues; minors on a corrective action plan. - Surveillance and recertification. Surveillance annually, full recertification on
a three-year cycle.
Everything the audit asks to see, already written.
The ISO 45001 Toolkit covers the policy, hazard identification and risk assessment process, legal register, consultation records, emergency plans and the full internal audit set, all mapped to the clause they satisfy.
How long ISO 45001 certification takes
From no formal system to certificate, six to twelve months is realistic for a
small or mid-sized organisation, and nine to eighteen where there are multiple sites or high-hazard
work. The gate is rarely the audits. It is accumulating enough operating history that internal audit
and management review have something real to examine, and building a legal register that genuinely
reflects the jurisdictions you work in.
ISO 45001 certification is quicker if you already hold ISO 9001 or ISO 14001, because clauses 4, 5, 7, 9 and 10
share the same harmonized structure. What does not transfer is the hazard and risk machinery in
clause 6.1.2, the hierarchy of controls in 8.1.2, and worker consultation under 5.4 — and those
are the clauses auditors spend their time on.
What drives the cost of ISO 45001 certification
- Audit days, which scale with headcount, number of sites and risk category.
A high-hazard operation is audited for longer than an office at the same headcount. - Number of sites, and whether multi-site sampling is permitted.
- Consultancy, usually the largest single line if you use it.
- Internal documentation effort, routinely underestimated, and the cost a template
set reduces most directly. - Remediation after stage 1 or stage 2 — avoidable with an honest gap
analysis first.
Certification body fees are the visible cost of ISO 45001 certification. Internal time is almost always the larger one.
For a fuller breakdown, see our ISO 45001
implementation guide.
A second edition is on its way
ISO 45001:2018 is now marked on iso.org as an International Standard to be revised, and the draft second edition, ISO/DIS 45001, has reached the DIS ballot stage (40.20) — a twelve-week vote by national member bodies. The draft runs to 48 pages against the current 41.
Two things follow from that, and they pull in opposite directions. A draft is not a standard: DIS text can and does change before publication, so nothing in it should be built into a management system yet. But a revision does mean a transition period will follow publication, as it did when OHSAS 18001 gave way to ISO 45001. A system that is documented cleanly, with a maintained clause cross-reference, transitions in weeks. One held together by tribal knowledge does not. That is an argument for getting the documentation right now rather than after the second edition lands.
The separate climate action amendment is already in force. ISO 45001:2018/Amd 1:2024, published in February 2024 and issued free of charge, adds climate change to clause 4.1 and to the interested-party expectations in clause 4.2. It is short, but it is a live requirement and auditors do ask about it.
Choosing a certification body for ISO 45001 certification
Check that the body is accredited by a recognised national accreditation body and that its
accreditation scope covers ISO 45001 and your industry sector codes. An unaccredited certificate is
cheaper and, for most customers and tender processes, worthless. Ask how many auditor days they are
quoting and against what basis; wide variation between quotes usually means the scope has been
interpreted differently, not that one is better value.
Why first attempts at ISO 45001 certification fail
- Worker consultation asserted but not evidenced. Clause 5.4 requires
consultation and participation of workers, with emphasis on non-managerial workers. Auditors test it
by asking them directly. A toolbox talk register is not consultation. - A legal register that lists statutes but records no evaluation of compliance.
Clause 9.1.2 requires you to evaluate compliance, not merely to know the law exists. - Risk assessments with no link to the hierarchy of controls. If every control is
PPE and training, clause 8.1.2 is not being applied. - No internal audit or management review yet. Prerequisites of ISO 45001
certification, not follow-ups. - Contractors out of scope in practice. Clause 8.1.4 covers procurement,
contractors and outsourcing; contractor management is one of the most common major findings.
References
- ISO 45001:2018 — the standard itself on iso.org.
- ISO 45001:2018/Amd 1:2024 — the climate action amendment, published free of charge by ISO.
- ISO/DIS 45001 — the draft second edition, currently at DIS ballot.
More on ISO 45001
- ISO 45001 certification — you are here
- ISO 45001 implementation guide
- ISO 45001 mandatory documents
- ISO 45001 risk assessment
- ISO 45001 internal audit checklist
- ISO 45001 gap analysis
All of these are covered by the ISO 45001 Toolkit. To score where you stand first, use the ISO 45001 Assessment Tool, or browse the free ISO templates.