Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 45001 readiness assessment explained

ISO 45001 Readiness Assessment: 6 Proven Checks Before the Audit

An ISO 45001 readiness assessment answers one question: if the certification body arrived next month, would the occupational health and safety management system pass? It is narrower than a gap analysis, which compares the system against every requirement, and later — it assumes the system has been built and operated, and checks whether the evidence exists in the form an auditor will test. Six checks decide the answer for most organizations, and they are the six that produce the majority of stage 1 and stage 2 findings under ISO 45001:2018. This guide sets them out, explains what “ready” looks like for each, and shows how to score the assessment so the decision to book the audit is made on evidence rather than optimism.

ISO 45001 readiness assessment: six checks before you book the audit
Worker participation, hazard identification and the hierarchy of controls, legal compliance evaluation, incident and corrective action, internal audit, and management review.

ISO 45001 readiness assessment vs gap analysis vs self-assessment

The three are often confused and are run at different times. A gap analysis is run before implementation, against all of clauses 4 to 10, to plan the work; our guide to the ISO 45001 gap analysis covers it. A self-assessment scores every requirement Yes or No with a reference to where it is met, and can be run at any point; our guide to the ISO 45001 self-assessment covers the clause-by-clause version. A readiness assessment is run last, on an operating system, and concentrates on the requirements that fail audits — because an auditor does not test every clause equally, and neither should the final check.

The six ISO 45001 readiness assessment checks

# Check Clause Ready looks like Common failure
1 Worker consultation and participation 5.4 A documented mechanism; records of consultation on hazards, risks, controls, objectives and the policy; workers who can describe it A safety committee that management chairs and workers attend without input
2 Hazard identification and the hierarchy of controls 6.1.2, 8.1.2 A live hazard register covering routine and non-routine work, human factors, organization of work; controls chosen by the hierarchy with the reasoning recorded A risk assessment that jumps to PPE; hazards from contractors and change not covered
3 Legal and other requirements, and evaluation of compliance 6.1.3, 9.1.2 A current legal register; compliance evaluated against each requirement on a defined frequency, with results and actions A register that has never been evaluated; ‘compliance’ asserted by the HSE manager
4 Incidents, nonconformities and corrective action 10.2 Every incident investigated with worker participation; root causes found; corrective actions closed and their effectiveness reviewed; near misses reported Investigations that stop at ‘operator error’; no effectiveness review
5 Internal audit 9.2 A programme covering all clauses and all sites; objective auditors; results reported to management and workers; findings closed One audit, by the HSE manager, of their own system
6 Management review 9.3 Held with all inputs including worker consultation and incident performance; outputs with decisions and resources; communicated to workers Minutes that record discussion but no decisions

1. Worker consultation and participation

ISO 45001 is the only harmonized-structure standard with a clause dedicated to worker involvement, and it is the first thing an experienced OH&S auditor tests by talking to workers away from managers. Clause 5.4 requires consultation of non-managerial workers on nine listed matters — needs and expectations of interested parties, the policy, roles, how legal requirements are fulfilled, objectives, controls for outsourcing, procurement and contractors, what is monitored, the audit programme and continual improvement — and their participation in seven, including hazard identification, actions to reduce risks, competence and training, control measures and incident investigation. Readiness means a mechanism that works, records that show it working, and workers who confirm it.

2. Hazard identification and the hierarchy of controls

Clause 6.1.2.1 lists what hazard identification must consider, and the list is wider than most registers: how work is organized, social factors including workload, hours, harassment and bullying, leadership and culture; routine and non-routine activities; incidents, past and potential; emergencies; people, including contractors, visitors and those near the workplace; the design of work areas and equipment; changes; and human factors. Clause 8.1.2 then requires controls to be chosen using the hierarchy — eliminate, substitute, engineering controls and reorganization, administrative controls including training, PPE — and readiness means the register shows that order was considered, not that PPE was assigned.

3. Legal requirements and evaluation of compliance

Two clauses, two records, and the ISO 45001 readiness assessment checks both. The legal and other requirements register (6.1.3) must be current, and clause 9.1.2 requires the organization to evaluate compliance with it at a defined frequency, act on the results and retain the evidence. Our guide to evaluation of compliance under ISO 45001 covers the evaluation record auditors ask for. A register with no evaluation is the single most common ISO 45001 major finding.

4. Incidents and corrective action

Clause 10.2 requires reaction, investigation with the participation of workers, root cause, corrective action, effectiveness review and, where needed, changes to the risk assessment and the system. Readiness is tested on the last twelve months’ incidents: pick three, follow each to a closed and reviewed corrective action, and check that the hazard register changed as a result.

5. Internal audit

The programme must cover every clause and every location, be performed by auditors independent of the area audited, and report to management and — a 45001-specific point — to workers and their representatives. A single audit performed by the person who runs the system fails the objectivity test, and the ISO 45001 readiness assessment should score it 0.

6. Management review

Clause 9.3 inputs include the OH&S-specific items — incidents, evaluation of compliance results, consultation and participation, risks and opportunities — and outputs include decisions on improvement, resources and system changes, communicated to workers. A review held before the first internal audit has no audit results to consider and does not count.

Scoring the ISO 45001 readiness assessment

Score each of the six on a three-point scale: 2 where the evidence exists and a sampled worker or record confirms it; 1 where the mechanism exists but the evidence is thin or recent; 0 where it is missing. The decision rule is strict because these six are where audits fail: book the certification audit when all six score 2, or five score 2 and the remaining 1 has a dated action that will complete before stage 2. Any 0 means the system has not completed a cycle, and a stage 1 audit will say so at your expense. Record the assessment in the same clause-by-clause format as the self-assessment — reference in your system, verification, area of concern — so the readiness result reads as the final column of the assessment the auditor will see.

Frequently asked questions

What is an ISO 45001 readiness assessment?
A final check, on an operating OH&S management system, of the requirements that decide certification audits — worker participation, hazard identification and controls, legal compliance evaluation, incident and corrective action, internal audit and management review — to decide whether to book the audit.

How is it different from a gap analysis?
A gap analysis runs before implementation against every requirement to plan the work. A readiness assessment runs after implementation, on evidence, against the six checks that most often fail audits.

How long before the audit should it be run?
Two to three months before the intended stage 1, so that a 1 can be closed and a 0 can be rescheduled without losing the certification body’s date.

Who should run it?
Someone other than the HSE manager — an internal auditor from another function, a corporate colleague, or a consultant — because the checks include whether the system’s owner has been audited independently.

What score means ready?
All six checks at 2 (evidence exists and is confirmed by a sampled worker or record), or five at 2 with the sixth at 1 and a dated action to close it before stage 2.

Where this leaves you

Run the ISO 45001 readiness assessment on the six checks that decide audits, score each on evidence a sampled worker or record confirms, and book the certification body only when the scores say so. The check that most often surprises organizations is the first one: if workers cannot describe how they are consulted, nothing else on the list will carry the audit.

References

  • ISO 45001:2018 — Occupational health and safety management systems — requirements with guidance for use.

More on ISO 45001 assessment

The clause-by-clause questionnaire with reference, verification and area-of-concern columns that the readiness result is recorded in is the ISO 45001 Self-Assessment Tool, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.