Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 45001 self-assessment explained

ISO 45001 Self-Assessment: A Clear Guide to Scoring Clauses 4–10

An ISO 45001 self-assessment is a clause-by-clause check of an occupational health and safety management system against ISO 45001:2018, run by the organization on itself, with three columns that make it useful: where in the system each requirement is met, how that was verified, and whether it is an area of concern.

It is the instrument that sits between reading the standard and being audited against it, and — unlike a maturity assessment or a culture survey — it follows the standard’s own structure exactly, clauses 4 to 10, so its output maps directly onto what a certification auditor will ask. This guide explains how to score each clause, walks through the requirements in each of the seven that most often surprise self-assessors, and sets out the rules that keep a self-assessment honest.

ISO 45001 self-assessment: clauses 4 to 10, three columns per requirement
Reference in your system, verification, area of concern — recorded against every requirement from context to continual improvement.

What an ISO 45001 self-assessment is for

Three uses. Before implementation it is the gap analysis — every “No” is work to do. During implementation it is the progress record — the reference column fills in as documents and processes are built. Before certification it is the evidence index — the reference and verification columns are what the auditor will follow. The standard does not require a self-assessment by that name, but clause 9.1.1 requires the organization to evaluate its OH&S performance and the effectiveness of the management system, and a documented self-assessment against the standard is the simplest evidence that it has.

The three columns

Column What to record What not to record
Reference in your system The document, register, record or process that meets the requirement — by name and location ‘Yes’ with nothing behind it; ‘HSE manager’ as a reference
Verification How it was confirmed: document reviewed, record sampled, person interviewed, activity observed, with a date ‘Confirmed’; verification by the person who wrote the document
Area of concern? Yes where the reference is missing, the verification failed or the evidence is thin; a note on what is missing Blank where the honest answer is Yes

Each requirement is answered Yes or No. A Yes needs a reference and a verification; a No is automatically an area of concern. The value of the format is that it cannot be completed by assertion: the reference column forces the assessor to name the evidence, and the verification column forces someone to have looked at it.

Clause by clause: where ISO 45001 self-assessments find concerns

Clause 4: Context

4.1 and 4.2 ask whether external and internal issues, and the needs and expectations of workers and other interested parties, have been determined and are monitored — the second half is the usual gap. 4.3 requires the scope to account for planned and performed work-related activities; a scope that names sites but not activities scores No. 4.4 is met by the system as a whole.

Clause 5: Leadership and worker participation

5.1 lists thirteen things top management must demonstrate, including taking overall responsibility for the prevention of work-related injury and ill health, and developing, leading and promoting a supportive culture. 5.2 requires the policy to commit to eliminating hazards and reducing OH&S risks, to consultation and participation of workers, and to fulfilling legal and other requirements. 5.4 — consultation and participation — is the clause with the longest list in the standard and the most frequent concern: consultation on nine items and participation in seven, with mechanisms, time, training and access provided, and barriers removed. A committee that meets does not by itself score Yes on any of them.

Clause 6: Planning

6.1.2.1 hazard identification must consider organization of work and social factors, routine and non-routine activities, past incidents, emergencies, all people at the workplace, workplace design, changes and human factors. 6.1.2.2 requires the risk assessment methodology to be defined; 6.1.2.3 requires opportunities to be assessed as well as risks. 6.1.3 requires legal and other requirements to be determined and kept up to date. 6.2 requires OH&S objectives that are measurable, monitored, communicated and updated. The common concerns are the breadth of 6.1.2.1 and the absence of OH&S opportunities.

Clause 7: Support

7.2 competence includes the ability to identify hazards; 7.3 awareness includes the policy, the implications of nonconformity, incidents and their outcomes, and — specific to 45001 — workers’ ability to remove themselves from situations they consider dangerous, with protection from reprisal. 7.4 communication must take diversity aspects into account and ensure workers’ views are considered. 7.5 documented information follows the harmonized structure.

Clause 8: Operation

8.1.2 requires the hierarchy of controls to be used to eliminate hazards and reduce risks: eliminate, substitute, engineering controls and reorganization of work, administrative controls including training, PPE — in that order. 8.1.3 management of change, 8.1.4 procurement including contractors and outsourcing, and 8.2 emergency preparedness with planned response, testing and worker participation each need their own reference. Contractors (8.1.4.2) are the usual concern: the requirement is to coordinate with contractors, to identify and control the hazards their work introduces, and to use OH&S criteria in selecting them.

Clause 9: Performance evaluation

9.1.1 requires monitoring of legal compliance, operational controls, progress on objectives and effectiveness of controls, with calibrated equipment where used. 9.1.2 requires compliance to be evaluated at a defined frequency with action on the results — our guide to evaluation of compliance covers the record. 9.2 internal audit and 9.3 management review each have OH&S-specific inputs, including worker consultation and incident performance, and outputs communicated to workers.

Clause 10: Improvement

10.2 requires incidents and nonconformities to be reacted to, investigated with the participation of workers, root-caused, corrected, and the corrective action’s effectiveness reviewed, with the risk assessment updated where needed. 10.3 continual improvement must involve workers and be communicated. The concern is nearly always the effectiveness review: corrective actions closed on completion, never on result.

Five rules for an honest ISO 45001 self-assessment

  1. The reference must be findable by someone else. “See procedure” is not a reference; “OHS-PR-04 Hazard Identification, rev 3, section 5” is.
  2. Verification is done by someone who did not write the reference. The HSE manager assessing the HSE manager’s documents is a self-assessment in the wrong sense.
  3. Sample records, not templates. A blank incident form proves the form exists. Three completed investigations prove the process runs.
  4. Ask a worker. Clauses 5.4, 7.3 and 10.2 are answered on the floor. Two interviews per site turn assertions into verification.
  5. Count the concerns before deciding anything. The self-assessment produces a list; the readiness assessment decides whether to book the audit. Our guide to the ISO 45001 readiness assessment covers the six checks that decision turns on.

Frequently asked questions

What is an ISO 45001 self-assessment?
A clause-by-clause check of the OH&S management system against ISO 45001:2018, answering each requirement Yes or No with a reference to where it is met, how that was verified, and whether it is an area of concern.

Is it required by the standard?
Not by name. Clause 9.1.1 requires evaluation of OH&S performance and system effectiveness, and a documented self-assessment against the standard is straightforward evidence of it. It is also the usual first step before certification.

Who should complete it?
The owners of each area supply the references; someone independent of them — an internal auditor, a corporate colleague or a consultant — performs the verification. Worker interviews are part of verification for clauses 5.4, 7.3 and 10.2.

How is it different from a gap analysis?
The same instrument at a different time: a self-assessment run before implementation is the gap analysis; run on an operating system it is the evidence index for the audit.

Which clauses most often score No?
5.4 consultation and participation, 6.1.2.1 hazard identification breadth, 6.1.2.3 OH&S opportunities, 8.1.4.2 contractors, 9.1.2 evaluation of compliance and the effectiveness review in 10.2.

Where this leaves you

Run the ISO 45001 self-assessment as the standard is written — clauses 4 to 10, every requirement, Yes or No — and make each Yes carry a findable reference and an independent verification. The concerns it lists are the work plan; the references it records are the evidence index the auditor will follow; and the discipline of naming the evidence is what separates a self-assessment from a checklist.

References

  • ISO 45001:2018 — Occupational health and safety management systems — requirements with guidance for use.

More on ISO 45001 assessment

The clause-by-clause ISO 45001:2018 questionnaire with exactly these three columns — reference in your system, verification, area of concern — is the ISO 45001 Self-Assessment Tool, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.