Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 45001 Implementation — guide from Governance Docs

How to Implement ISO 45001: A Ten-Step Plan

ISO 45001 implementation fails for predictable reasons: it is run as a
documentation project, the workforce finds out about it at the audit, and the legal register is
written the week before stage 1. This is a ten-step plan that avoids those, with honest timings.

Before step one of ISO 45001 implementation: decide who owns it

ISO 45001 implementation starts higher up than it used to. The standard removed the concept of a “management representative” that OHSAS 18001 relied on, and
put accountability on top management directly under clause 5.1. You still need someone to run the
project day to day, but if the only person who can describe the system is the health and safety
adviser, stage 2 will go badly. Auditors interview senior managers.

The ten steps of ISO 45001 implementation

  1. Gap analysis (2–4 weeks). The first move in any ISO 45001
    implementation. Assess current practice against every clause and
    produce a costed action list. This is the step that makes the remaining nine estimable.
  2. Scope and context (1–2 weeks). Define what the system covers: sites,
    activities, workers, contractors. Record internal and external issues, including climate change as
    required by the 2024 amendment, and the needs of workers and other interested parties.
  3. Policy and leadership commitment (1 week). A short policy signed and meant,
    plus documented roles and responsibilities.
  4. Set up worker consultation (2–4 weeks, then ongoing). Clause 5.4 is the
    clause most often left until last and it is the one that cannot be retrofitted — you need a
    record of participation over time. Start it early.
  5. Hazard identification and risk assessment (4–10 weeks). Write the
    methodology first, then work through activities. See our guide to
    ISO 45001 risk assessment.
  6. Legal register and compliance evaluation (3–6 weeks). Identify the
    obligations that actually apply and record how you evaluate compliance with each.
  7. Objectives and operational controls (3–6 weeks). Measurable objectives
    with owners; operational controls applying the hierarchy in 8.1.2; management of change; contractor
    and procurement controls; emergency preparedness with drills scheduled.
  8. Competence, awareness and communication (3–6 weeks, overlapping). Define
    competence requirements, close the gaps, keep the records.
  9. Run the system (3–6 months). This is the step nobody puts in the plan.
    The system must generate real records — incidents, monitoring, consultation, drills —
    before an audit has anything to sample.
  10. Internal audit, management review, then certification. Both are prerequisites.
    See the ISO 45001 internal audit checklist and
    our guide to ISO 45001 certification.

Skip the blank page.

The ISO 45001 Toolkit supplies every document in this plan in editable Word and Excel — policy, risk methodology, legal register, objectives, operational controls, emergency plans, audit set — so implementation becomes editing rather than authoring.

Explore the ISO 45001 Toolkit →

The three steps ISO 45001 implementation plans always underestimate

Step 9, running the system. This is the single biggest scheduling error in ISO 45001 implementation. Plans routinely go from “documents complete” to
“certification audit” in a fortnight. It cannot work: clause 9.2 needs audit results, 9.3 needs
management review inputs, 10.2 needs incidents processed through the system. Budget three to six
months of genuine operation, and start the clock when the process goes live, not when the document is
signed.

Step 6, the legal register. A list of statute titles takes a day and is worthless.
A register that names the specific duties that bind your activities, in each jurisdiction you operate
in, with an evaluation of compliance against each, takes weeks and is what 6.1.3 and 9.1.2 actually
require.

Step 4, worker consultation. Retrofitting it late in an ISO 45001 implementation is impossible. The evidence is a trail
over months: committee minutes, hazard reports and what happened to them, workers involved in writing
the risk assessments for their own tasks.

ISO 45001 implementation alongside ISO 9001 or ISO 14001

If you already run either, roughly half of ISO 45001 implementation is done. Clauses 4, 5, 7, 9 and 10 follow the same
harmonized structure, so context, competence, document control, internal audit, management review and
improvement can be shared processes with OH&S content added rather than rebuilt. Budget the saving
against clauses 6.1.2, 8.1.2 and 5.4, which have no equivalent in the other two and will absorb it.
Our overview of ISO 45001 and workplace safety covers where the standard sits in a
wider management system.

A second edition is on its way

ISO 45001:2018 is now marked on iso.org as an International Standard to be revised, and the draft second edition, ISO/DIS 45001, has reached the DIS ballot stage (40.20) — a twelve-week vote by national member bodies. The draft runs to 48 pages against the current 41.

Two things follow from that, and they pull in opposite directions. A draft is not a standard: DIS text can and does change before publication, so nothing in it should be built into a management system yet. But a revision does mean a transition period will follow publication, as it did when OHSAS 18001 gave way to ISO 45001. A system that is documented cleanly, with a maintained clause cross-reference, transitions in weeks. One held together by tribal knowledge does not. That is an argument for getting the documentation right now rather than after the second edition lands.

The separate climate action amendment is already in force. ISO 45001:2018/Amd 1:2024, published in February 2024 and issued free of charge, adds climate change to clause 4.1 and to the interested-party expectations in clause 4.2. It is short, but it is a live requirement and auditors do ask about it.

A realistic total for ISO 45001 implementation

For a single-site organisation of fifty to two hundred people with no existing certification,
nine to twelve months from gap analysis to certificate is a plan you can defend.
Six months is possible where an ISO 9001 system already exists and health and safety practice is
mature. Anything under four months means either the scope is very small or step 9 has been skipped,
and step 9 is the one the auditor samples.

References

More on ISO 45001

All of these are covered by the ISO 45001 Toolkit. To score where you stand first, use the ISO 45001 Assessment Tool, or browse the free ISO templates.

Implementation guides for the other standards

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.