Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 45001 maturity assessment explained

ISO 45001 Maturity Assessment: A Clear Guide to 5 Levels

An ISO 45001 maturity assessment measures something certification does not: not whether the occupational health and safety management system meets the standard, but how deeply it has taken root. Two organizations can hold the same certificate with one running a compliance exercise owned by the HSE manager and the other running a system in which supervisors identify hazards, workers report near misses without being asked and directors read incident trends before financial ones. The certificate cannot tell them apart; a maturity assessment can. This guide sets out a five-level maturity scale for ISO 45001, the seven dimensions it is scored on, the evidence that distinguishes each level, and how the assessment is used to set a target that the standard itself never sets.

ISO 45001 maturity assessment: five levels across seven dimensions
From reactive to generative: each level is defined by evidence, and each dimension is scored separately before any average is taken.

ISO 45001 maturity assessment vs conformity audit

ISO 45001:2018 is a conformity standard. Clause 4.1 to 10.3 either are or are not met, and the certification audit reports nonconformities. It does not grade how well a requirement is met, and it deliberately allows a system that is documented, operated and evidenced at the minimum to be certified. A maturity assessment adds the grading: it asks, for each dimension of the system, whether the requirement is met because a procedure says so, because managers enforce it, because the organization measures and improves it, or because it is how people behave when nobody is checking. The distinction matters because incident rates track maturity, not certification. Our guide to the four types of ISO 45001 assessment places the maturity assessment among the others.

The five maturity levels

Level Name How the system behaves Typical evidence
1 Reactive Safety is what happens after an incident; the system exists to satisfy a customer or the certificate Procedures written by a consultant; hazard register not updated since certification; incidents recorded, not investigated
2 Managed Requirements are met because the HSE function makes them happen Current registers and records maintained by HSE; audits and reviews held on schedule; line managers comply when asked
3 Defined Line management owns OH&S in its area; the system is embedded in operations Supervisors run risk assessments and toolbox talks; managers chair safety meetings; KPIs cascade to departments
4 Measured Performance is measured with leading indicators and drives decisions Leading KPIs (near-miss reporting, inspection completion, corrective action timeliness) reviewed monthly; trends acted on; resources allocated by risk
5 Generative Safety is how the organization works; workers improve the system unprompted High near-miss reporting with low incident rates; worker-initiated improvements; contractors held to the same behaviours; leaders visible in the field

The names echo the safety culture ladder used across high-hazard industries — pathological, reactive, calculative, proactive, generative — and the CMMI-style capability levels, and that is deliberate: an ISO 45001 maturity assessment borrows the level logic from both and applies it to the standard’s own clauses.

The seven dimensions of an ISO 45001 maturity assessment

A single overall score hides where the system is weak. Score seven dimensions separately, each anchored to the clauses it covers, and report the profile.

Dimension Clauses Level 2 looks like Level 4 looks like
Leadership and accountability 5.1, 5.3 Policy signed; roles documented Leaders set OH&S objectives in their own plans; safety in performance reviews; leaders walk the floor with a record
Worker consultation and participation 5.4 A committee exists and meets Workers initiate hazard reports and improvements; participation measured; representatives trained
Hazard identification and risk control 6.1.2, 8.1.2 Register complete; controls assigned Register updated on change and after incidents; hierarchy-of-controls decisions recorded; risk reduction tracked
Legal compliance 6.1.3, 9.1.2 Register exists; compliance evaluated annually Regulatory change monitored; evaluation by line functions; findings closed within target
Competence and awareness 7.2, 7.3 Training matrix; records Competence verified on the job; refresher triggered by incidents and change; contractor competence assured
Incident learning 10.2 Incidents investigated; actions closed Root causes trended; corrective action effectiveness reviewed; learning shared across sites; near-miss ratio rising
Performance measurement and review 9.1, 9.3 Lagging indicators reported; annual review Leading and lagging indicators; quarterly review with decisions; objectives revised on evidence

Running the ISO 45001 maturity assessment

  1. Anchor every level with evidence statements. Write, for each dimension, what a level 1 to 5 organization would be able to show. The statements above are the starting set; tailor them to the sector.
  2. Gather evidence three ways. Document and record review; interviews with leaders, line managers, workers and contractors; observation on the floor. Maturity is visible in behaviour, and behaviour is not in the files.
  3. Score each dimension independently. A dimension scores the highest level whose evidence statement is fully met. Partial credit is recorded as a note, not as a half-level.
  4. Report the profile, not the average. Seven scores on a radar or a bar chart. The lowest dimension is the priority, whatever the mean says.
  5. Set the target per dimension. Not every dimension needs to reach 5; a target of 4 across the board with 5 on incident learning and participation is a realistic three-year ambition for most organizations.
  6. Re-assess annually. Same statements, same method, ideally the same assessor. The movement is the measure.

Reading the profile

Three ISO 45001 maturity assessment patterns recur. A high leadership score with low participation means leaders are committed and workers have not noticed — communication and consultation mechanisms are the fix. High hazard-control scores with low incident-learning scores mean the system is good at preventing known risks and bad at finding new ones — near-miss reporting and root-cause quality are the fix. And a uniformly level-2 profile is a system that certification built and the HSE function carries: the fix is ownership, which means moving hazard identification, compliance evaluation and incident investigation to line management with HSE as support. Our guide to the safety culture assessment covers the methods that measure the behavioural side of that shift.

Frequently asked questions

What is an ISO 45001 maturity assessment?
A graded assessment of how deeply the OH&S management system is embedded — from reactive through managed, defined and measured to generative — scored on seven dimensions anchored to the standard’s clauses, rather than the pass/fail of a conformity audit.

Is maturity part of ISO 45001 certification?
No. Certification tests conformity to clauses 4–10. Maturity is an internal or consultant assessment used to set targets beyond the certificate; some clients and insurers ask for it.

How many levels should the scale have?
Five is the convention, matching both the safety culture ladder and capability maturity models. Fewer levels lose resolution; more invent distinctions the evidence cannot support.

Should we average the dimension scores?
Report the profile and use the lowest dimension as the priority. An average hides exactly the weakness the assessment exists to find.

How often should it be repeated?
Annually, with the same evidence statements and method so that the change is real. Most organizations move one level on one or two dimensions per year; a jump across the board is a sign the statements were not applied consistently.

Where this leaves you

Run the ISO 45001 maturity assessment as seven dimension scores on a five-level scale, each anchored to evidence statements and gathered from documents, interviews and observation. Report the profile, fix the lowest dimension first, set a target per dimension, and repeat annually. The certificate tells the world the system conforms; the maturity profile tells you whether it is keeping people safe.

References

  • ISO 45001:2018 — Occupational health and safety management systems — the clauses each dimension is anchored to.

More on ISO 45001 assessment

The clause-by-clause questionnaire with reference, verification and area-of-concern columns that supplies the conformity baseline a maturity assessment builds on is the ISO 45001 Self-Assessment Tool, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.