2026 Trends
Aug 13, 2026
6 min read

ISO 45001 Requirements Explained

ISO 45001:2018 is the international standard for occupational health and safety management systems. This guide breaks down ISO 45001 requirements across Clauses 4–10 in plain English, with a practical checklist, implementation steps, and a clear look at how certification actually works - for HSE professionals and newcomers alike.   

Workplace safety cannot depend only on inspections after something goes wrong. Organizations need a structured way to identify hazards, control risks, involve workers and continually improve safety performance. That structure is exactly what ISO 45001 requirements provide. Published by the International Organization for Standardization, ISO 45001:2018 is the world's leading standard for occupational health and safety management systems. This guide explains ISO 45001 requirements, Clauses 4–10, implementation, documentation, audits and certification preparation.

HSE professional using a tablet during workplace assessment, representing ISO 45001 occupational health and safety management system preparation, hazard identification, risk assessment, and safety compliance training.

What Is ISO 45001?

ISO 45001 is the international standard for occupational health and safety (OH&S) management systems. It gives organizations of any size or industry a structured way to identify hazards, manage OH&S risks and improve safety performance over time.

The standard applies across sectors - from construction sites to hospitals - and is built on the Plan-Do-Check-Act (PDCA) cycle. ISO identifies leadership, worker participation, hazard identification, risk assessment, regulatory compliance, emergency planning, auditing and continual improvement as key elements of an effective OH&S management system (ISO 45001:2018 standard).

Which ISO 45001 Version Applies in 2026? As of August 2026, ISO 45001:2018 remains the current published edition. ISO has also published Amendment 1:2024, addressing climate-action considerations, while ISO/DIS 45001 - a proposed second edition - is still under development and has not replaced the 2018 standard.

ISO 45001 PDCA cycle infographic explaining workplace safety management system requirements.

What Are the Main ISO 45001 Requirements?

ISO 45001 requirements are organized into Clauses 4 through 10, covering context, leadership, planning, support, operation, performance evaluation and improvement. Together, these clauses form a continual-improvement cycle rather than a one-time checklist.

Clause

Focus

4

Context of the organization

5

Leadership and worker participation

6

Planning

7

Support

8

Operation

9

Performance evaluation

10

Improvement



 

ISO 45001 Clauses 4–10 staircase infographic explaining OH&S management system requirements.

ISO 45001 Clauses 4–10 Explained

Clause 4: Context of the Organization

Clause 4 requires an organization to understand itself, its stakeholders and the environment its OH&S management system operates in. A construction company, for example, must consider workers, subcontractors, clients, regulators and site-specific conditions when defining its scope. This clause also covers identifying internal and external issues, along with the needs and expectations of interested parties.

Clause 5: Leadership and Worker Participation

This clause centers on leadership commitment, a documented OH&S policy, clear responsibilities, and genuine worker consultation and participation. Management cannot simply delegate the entire system to the HSE department — top management must demonstrate visible ownership. This mirrors OSHA's emphasis on management leadership and worker participation as pillars of effective safety programs.

Clause 6: Planning

Clause 6 is where ISO 45001 risk assessment and ISO 45001 hazard identification take shape. Organizations must identify hazards, assess OH&S risks and opportunities, determine applicable legal and other requirements, and set measurable ISO 45001 objectives with action plans to achieve them.

A practical example: in a warehouse, forklift movements are identified as a hazard, the collision risk is assessed, controls such as pedestrian barriers and speed limits are introduced, and their effectiveness is monitored over time. OSHA similarly places systematic hazard identification and assessment at the center of preventive safety management.

Clause 7: Support

Clause 7 covers the resources an OH&S management system needs to function: competence, awareness, communication and documented information. This is where organizations often ask, what documentation does ISO 45001 require? The honest answer is that the standard specifies certain documented information as mandatory, while organizations must also generate the evidence needed to demonstrate their own system is working - avoid treating a generic internet checklist as an official "mandatory documents" list.

Clause 8: Operation

Clause 8 is the practical "doing" stage: operational planning and control, eliminating hazards, reducing OH&S risks, managing change, and controlling procurement, contractors and outsourced work, alongside emergency preparedness and response. A construction contractor's onboarding process, or a machinery lockout/tagout procedure during maintenance, are typical examples of Clause 8 in action - core to ISO 45001 implementation and a genuine workplace safety management system.

Clause 9: Performance Evaluation

Clause 9 asks organizations to monitor, measure, evaluate, audit and review their OH&S performance. An ISO 45001 internal audit asks whether the management system is both implemented and functioning as intended - not merely whether documents exist. Findings then feed into ISO 45001 management review, where top management assesses whether the system remains suitable and effective.

Clause 10: Improvement

Clause 10 closes the loop: incidents and nonconformities are investigated, corrective actions are taken, and the system is adjusted to prevent recurrence. The narrative is simple - incident, investigate cause, correct problem, prevent recurrence, assess effectiveness, improve system - reflecting ISO 45001 continual improvement in practice.

ISO 45001 Requirements Checklist: What Should You Have in Place?

Use this ISO 45001 requirements checklist as a quick self-assessment before deeper implementation or audit preparation:

  • OH&S management-system scope defined
  • Leadership responsibilities established
  • Worker consultation and participation process
  • Hazard identification process
  • OH&S risk and opportunity assessment
  • Applicable legal/other requirements identified
  • OH&S objectives and controls
  • Competence/training and documented information
  • Emergency arrangements
  • Performance monitoring, internal audit and management review
  • Incident/corrective-action process
  • Continual improvement process

ISO 45001 implementation checklist infographic for occupational health and safety management system audit readiness.

How Do You Implement ISO 45001?

ISO 45001 implementation typically follows this sequence: gap analysis, defining scope, securing leadership commitment, identifying hazards, assessing risks, establishing controls, training and involving workers, documenting the system, monitoring performance, auditing and improving.

Professionals who want to understand the standard before supporting implementation or audit preparation can build their foundation through the ISO 45001 Awareness & Preparation Course - self-paced training covering OH&S management systems, risk controls and certification-readiness concepts.

How Does ISO 45001 Certification Work?

Implementation and certification are different - an organization can implement ISO 45001 without ever seeking third-party certification. For organizations that do pursue it, the usual journey runs: implement the system, complete an internal audit, hold a management review, choose a competent certification body, undergo external assessment, address any findings, receive a certification decision, then maintain surveillance audits and ongoing improvement.

Importantly, ISO develops the standard; it does not itself certify organizations. ISO explains that independent certification bodies conduct certification, and accreditation of those bodies can provide additional confidence in their competence (ISO guidance on certification).

ISO 45001 skills infographic explaining OH&S knowledge, workplace safety, compliance, audits, and HSE career development.

ISO 45001 and OSHA: Are They the Same?

No. ISO 45001 is an international voluntary management-system standard, while OSHA administers and enforces occupational safety and health requirements within the United States. Organizations can use ISO 45001's structured management practices while still needing to satisfy whatever national or local law applies to them - ISO 45001 does not replace legal compliance obligations.

OSHA's own recommended framework echoes similar principles: management leadership, worker participation, hazard identification, prevention and control, and training (OSHA Recommended Practices for Safety and Health Programs). For broader international guidance beyond any single country, the International Labour Organization's ILO-OSH framework similarly promotes systematic management and continual improvement of occupational safety and health performance.

Final Thoughts: Turning ISO 45001 Requirements Into Safer Workplaces

ISO 45001 is not simply an audit checklist. Its purpose is to embed systematic hazard prevention, worker involvement, leadership accountability, performance evaluation and continual improvement into everyday operations.

Want to strengthen your understanding before supporting implementation or certification preparation? Explore the ISO 45001 Awareness & Preparation Course.

Safety professional wearing a hard hat and high visibility vest inspecting a warehouse environment as part of ISO 45001 occupational health and safety management system awareness and preparation training.

Frequently Asked Questions

01 What are the main requirements of ISO 45001? +

 ISO 45001 requires organizations to address context and stakeholders, leadership and worker participation, planning (hazard identification and risk assessment), support, operation, performance evaluation, and continual improvement — structured across Clauses 4 through 10 using the Plan-Do-Check-Act cycle.

02 Is ISO 45001 certification mandatory? +

No. ISO 45001 is a voluntary international standard. Organizations can implement the framework without pursuing certification, though certification may be required by specific clients, contracts, or industry procurement requirements.

03 What is an ISO 45001 audit? +

 An ISO 45001 audit evaluates whether an OH&S management system is both implemented and functioning effectively. Internal audits are conducted by the organization; certification audits are conducted by an accredited external certification body.

04 How long does ISO 45001 implementation take? +

There's no fixed timeframe. Implementation duration depends on organizational size, existing safety processes, identified gaps, and available resources - ranging from several months to over a year for complex organizations.

05 Does ISO certify organizations directly? +

 No. ISO develops and publishes the standard but does not perform certification itself. Independent, accredited certification bodies conduct assessments and issue ISO 45001 certification.

06 Is ISO 45001 the same as OSHA? +

No. ISO 45001 is a voluntary international OH&S management-system standard, while OSHA is a U.S. federal agency that enforces legally binding occupational safety and health regulations within the United States.