ISO requirements map
Every requirement of ISO 45001, ISO 14001 and ISO 9001 (latest editions), clause by clause — what documented information it needs and where the evidence lives in this app.
ISO 45001:2018 + Amd 1:2024
Current edition for certification: ISO 45001:2018 with Amendment 1:2024 (climate change in clauses 4.1 and 4.2). A revised edition is in draft (expected 2027) and is not yet certifiable.
76
Requirements
37
Clauses
14
Documents to keep
16
Records to retain
2
New / changed
76 of 76 requirements shown
4.1Understanding the organization and its context
Determine the external and internal issues that are relevant to the organization's purpose and affect its ability to achieve the intended outcomes of the OH&S management system.
Determine whether climate change is a relevant issue for the organization (Amendment 1:2024).
✨ New / changed in this edition
4.2Needs and expectations of workers and other interested parties
Identify the interested parties, in addition to workers, that are relevant to the OH&S management system.
Determine the relevant needs and expectations of workers and other interested parties (these can include climate-related requirements — Amendment 1:2024).
✨ New / changed in this editionDetermine which of these needs and expectations are, or could become, legal requirements and other requirements.
4.3Scope of the OH&S management system
Determine the boundaries and applicability of the system, considering internal/external issues, the requirements of interested parties and the planned or performed work-related activities; include all activities, products and services under the organization's control or influence; keep the scope available as documented information.
📄 Document to keep
4.4OH&S management system
Establish, implement, maintain and continually improve the OH&S management system, including the needed processes and their interactions.
5.1Leadership and commitment
Top management takes overall responsibility and accountability for preventing work-related injury and ill health and for providing safe and healthy workplaces and activities.
Top management ensures the policy and objectives fit the strategic direction, integrates the system into business processes, provides resources, communicates its importance, and directs and supports people to contribute to it.
Top management promotes continual improvement and supports other relevant management roles to show leadership in their areas.
Top management develops, leads and promotes a culture that supports the intended outcomes of the system.
Workers are protected from reprisals when they report incidents, hazards, risks and opportunities.
Top management ensures a process for consultation and participation of workers exists and supports health and safety committees where they exist.
5.2OH&S policy
The policy commits to safe and healthy working conditions suited to the organization's size, context and the nature of its risks; gives a framework for objectives; commits to fulfilling legal and other requirements, eliminating hazards and reducing risks, continual improvement, and consultation and participation of workers.
📄 Document to keepThe policy is available as documented information, communicated within the organization, available to interested parties as appropriate, and kept relevant and appropriate.
📄 Document to keep
5.3Organizational roles, responsibilities and authorities
Responsibilities and authorities for relevant roles are assigned and communicated at all levels and kept as documented information; workers at each level take responsibility for the OH&S aspects they control.
📄 Document to keep🔗 Personnel filesAuthority is assigned for ensuring the system conforms to ISO 45001 and for reporting its performance to top management.
5.4Consultation and participation of workers
A process exists for consultation and participation of workers (and worker representatives) at all applicable levels and functions in developing, planning, implementing, evaluating and improving the system.
Mechanisms, time, training and resources for consultation and participation are provided, with timely access to clear, understandable information.
Obstacles or barriers to participation (e.g. language, literacy, reprisals, policies) are identified and removed or minimized.
Non-managerial workers are consulted on: needs of interested parties, the policy, roles, legal requirements, objectives, controls for outsourcing/procurement/contractors, what to monitor, the audit programme and continual improvement.
Non-managerial workers participate in: consultation mechanisms, hazard identification and risk assessment, actions to eliminate hazards, competence and training needs, communication, control measures, and investigation of incidents and nonconformities.
6.1.1Actions to address risks and opportunities — General
When planning, consider context, interested parties and scope, and determine the risks and opportunities to be addressed (hazards, OH&S risks and other risks, OH&S opportunities and other opportunities, legal and other requirements).
📄 Document to keep🔗 Risk assessmentThe planning process takes planned permanent or temporary changes into account.
Documented information is kept on risks and opportunities and on the processes and actions needed to address them, to give confidence they are carried out as planned.
📄 Document to keep🔗 Risk assessment
6.1.2.1Hazard identification
An ongoing, proactive hazard identification process considers how work is organized, social factors (workload, working hours, victimization, harassment, bullying), leadership and culture.
Hazard identification covers routine and non-routine activities and situations: infrastructure, equipment, materials, substances, physical conditions, product/service design, research and development, human factors and how work is performed.
Past relevant incidents (inside or outside the organization), including emergencies and their causes, and potential emergency situations are considered.
People are considered: workers, contractors, visitors and others with access to the workplace, people nearby affected by the activities, and workers at locations not directly controlled by the organization.
Design of work areas, processes, installations, machinery, procedures and work organization (adapted to workers' needs and capabilities), situations near the workplace, and actual or proposed changes in organization, operations or knowledge about hazards are considered.
6.1.2.2Assessment of OH&S risks and other risks
OH&S risks from identified hazards are assessed taking into account the effectiveness of existing controls, and other risks to establishing and maintaining the system are determined and assessed.
📄🗂 Document + records🔗 Risk assessmentThe risk assessment methodology and criteria are defined for scope, nature and timing so they are proactive and systematic, and are kept and retained as documented information.
📄🗂 Document + records🔗 Risk assessment
6.1.2.3Assessment of OH&S opportunities and other opportunities
Opportunities to enhance OH&S performance are assessed (adapting work and environment to workers, eliminating hazards, reducing risks) together with other opportunities to improve the system.
6.1.3Determination of legal requirements and other requirements
A process determines and gives access to up-to-date legal and other requirements applicable to hazards, risks and the system, determines how they apply and what must be communicated, and takes them into account in the system; this is kept, retained and updated as documented information.
📄🗂 Document + records🔗 Legal registers
6.1.4Planning action
Actions are planned to address risks and opportunities, legal and other requirements, and emergency preparedness; how to integrate them into processes and how to evaluate their effectiveness is planned.
The hierarchy of controls, best practice, technological options and financial, operational and business requirements are considered when planning actions.
6.2.1OH&S objectives
OH&S objectives are established at relevant functions and levels to maintain and continually improve the system and OH&S performance.
Objectives are consistent with the policy, measurable (or able to be evaluated), take into account requirements, risk and opportunity assessment and consultation with workers, and are monitored, communicated and updated.
6.2.2Planning to achieve OH&S objectives
Plans to achieve objectives define what will be done, resources, responsibility, completion dates, how results are evaluated (including indicators) and how actions are integrated into business processes; objectives and plans are kept and retained as documented information.
📄🗂 Document + records🔗 Safety statistics
7.1Resources
The resources needed to establish, implement, maintain and continually improve the system are determined and provided.
7.2Competence
The competence needed by workers who affect OH&S performance (including the ability to identify hazards) is determined; workers are competent through education, training or experience; actions to acquire competence are taken and their effectiveness evaluated; evidence is retained.
7.3Awareness
Workers are aware of the policy and objectives, their contribution, the implications of not conforming, incidents and investigation outcomes relevant to them, and the hazards, risks and actions relevant to them.
Workers know they can remove themselves from work situations they consider an imminent and serious danger, and how they are protected from undue consequences for doing so.
7.4.1Communication — General
Communication processes define what, when, with whom (internally, with contractors and visitors, and other interested parties) and how to communicate, taking diversity (gender, language, culture, literacy, disability) and legal requirements into account; evidence is retained.
🗂 Record to retainViews of external interested parties are considered, communicated information is consistent and reliable, and relevant communications are responded to.
7.4.2Internal communication
Relevant information, including changes to the system, is communicated internally among levels and functions, and workers are enabled to contribute to continual improvement.
7.4.3External communication
Relevant information is communicated externally as established by the communication processes and as required by legal requirements.
7.5Documented information
The system includes the documented information required by ISO 45001 and that the organization decides is necessary for its effectiveness.
Documents are created with suitable identification (title, date, author, reference), format and media, and are reviewed and approved for suitability and adequacy.
Documented information is controlled: available and suitable where and when needed, protected, with control of distribution, access, storage, legibility, changes (version control), retention and disposal; documents of external origin are identified and controlled.
8.1.1Operational planning and control — General
Processes needed to meet system requirements are planned, implemented, controlled and maintained by setting criteria and implementing control in line with them; documented information is kept to the extent needed for confidence that processes are carried out as planned.
Work is adapted to workers.
At multi-employer workplaces, the relevant parts of the system are coordinated with the other organizations.
8.1.2Eliminating hazards and reducing OH&S risks
A process eliminates hazards and reduces risks using the hierarchy of controls: elimination; substitution; engineering controls and reorganization of work; administrative controls including training; personal protective equipment.
8.1.3Management of change
A process controls planned temporary and permanent changes (new products, services, processes, workplaces, equipment, organization, workforce, legal requirements, knowledge about hazards, technology).
The consequences of unintended changes are reviewed and action is taken to mitigate any adverse effects.
8.1.4.1Procurement — General
A process controls the procurement of products and services so they conform to the system.
8.1.4.2Contractors
Procurement is coordinated with contractors to identify hazards and control risks arising from contractor activities affecting the organization, the organization's activities affecting contractors' workers, and contractor activities affecting other interested parties.
Contractors and their workers meet the system's requirements, and OH&S criteria are defined and applied for selecting contractors.
8.1.4.3Outsourcing
Outsourced functions and processes are controlled, consistent with legal requirements, and the type and degree of control is defined within the system.
8.2Emergency preparedness and response
A process prepares for and responds to potential emergency situations: planned response including first aid, training for the planned response, periodic testing and exercising of the response capability.
📄🗂 Document + records🔗 Fire extinguishers & emergencyPerformance is evaluated and the planned response revised after tests and especially after emergencies; duties are communicated to all workers, and information is given to contractors, visitors, emergency services, authorities and the local community; needs of interested parties are considered; the process and plans are kept and retained as documented information.
📄🗂 Document + records
9.1.1Monitoring, measurement, analysis and performance evaluation — General
Determine what is monitored and measured (fulfilment of legal requirements, activities related to hazards and risks, progress toward objectives, effectiveness of controls), the methods, the criteria, when to monitor and when to analyse, evaluate and communicate the results.
Monitoring and measuring equipment is calibrated or verified and maintained; results of monitoring, measurement, analysis and performance evaluation and of equipment maintenance/calibration are retained.
🗂 Record to retain
9.1.2Evaluation of compliance
A process evaluates compliance with legal and other requirements at a set frequency and with set methods, action is taken where needed, knowledge of compliance status is maintained, and results are retained.
🗂 Record to retain🔗 Legal registers
9.2Internal audit
Internal audits are conducted at planned intervals to check the system conforms to the organization's own requirements and to ISO 45001 and is effectively implemented and maintained.
An audit programme sets frequency, methods, responsibilities, consultation, planning and reporting, considering the importance of processes and previous audit results; criteria and scope are defined for each audit; auditors are objective and impartial; evidence of the programme and results is retained.
🗂 Record to retain🔗 AuditsAudit results are reported to relevant managers, workers, worker representatives and other interested parties, and action is taken on nonconformities and to improve performance.
9.3Management review
Management review considers: status of previous actions; changes in issues, interested parties' needs, legal requirements, risks and opportunities; how far policy and objectives are met; OH&S performance (incidents, nonconformities, corrective actions, monitoring, compliance evaluation, audits, consultation and participation, risks and opportunities); adequacy of resources; communications with interested parties; opportunities for improvement.
🗂 Record to retainReview outputs cover the continuing suitability, adequacy and effectiveness of the system, improvement opportunities, needed changes and resources, actions, opportunities to improve integration with business processes and implications for strategic direction; relevant outputs are communicated to workers and their representatives; results are retained.
🗂 Record to retain
10.1Improvement — General
Opportunities for improvement are determined and the actions needed to achieve the intended outcomes are implemented.
10.2Incident, nonconformity and corrective action
A process manages incidents and nonconformities: react in a timely way to control and correct them and deal with the consequences.
The need for corrective action is evaluated with the participation of workers and other interested parties by investigating the incident or reviewing the nonconformity, finding the causes, checking for similar cases, and reviewing existing risk assessments.
Corrective actions follow the hierarchy of controls and management of change; risks of new or changed hazards are assessed before acting; effectiveness is reviewed; the system is changed if needed.
Records are retained of the nature of incidents and nonconformities, actions taken, and results including effectiveness; this information is communicated to relevant workers and interested parties.
10.3Continual improvement
The system is continually improved by enhancing OH&S performance, promoting a supportive culture and worker participation, and communicating the results to workers; evidence is kept and retained.
ℹ️ Requirements are summarised in our own words to help you plan and check your system; they do not replace the standard. ISO texts are copyrighted — use your purchased copy as the authoritative source and check the clause numbering of new editions against it.