← Back to Blogs

ISO 45001

ISO 45001 Implementation Guide: Step-by-Step for Occupational Health & Safety

Workplace injuries and occupational illnesses cost businesses billions of dollars every year and, more importantly, they cost workers their health, livelihoods, and sometimes their lives. ISO 45001:2018 is the international standard that gives organisations a proven framework to prevent those outcomes.

Whether you are starting from scratch or transitioning from OHSAS 18001, this guide walks you through the ISO 45001 implementation process step by step, covering everything from the initial gap assessment to certification audit. At HSEQ Professionals, we have guided organisations across Saudi Arabia, Pakistan, and the USA through this exact journey. What follows is drawn directly from that experience.

What Is ISO 45001 and Why Does It Matter?

ISO 45001 is the world’s leading standard for Occupational Health and Safety Management Systems (OHSMS). Published in 2018 by the International Organization for Standardization, it replaced OHSAS 18001 and adopted the High-Level Structure (HLS) shared across ISO 9001 and ISO 14001, making it far easier to integrate with existing management systems.

Achieving ISO 45001 certification demonstrates to regulators, clients, and employees that your organisation takes worker safety seriously, not as a compliance exercise, but as a core business value. It is increasingly required for tendering in oil and gas, construction, manufacturing, and government contracts across the Middle East and beyond.

Before You Begin: Key Prerequisites

Successful ISO 45001 implementation depends on two things before a single document is written:

  •     Top management commitment:
    ISO 45001 places explicit responsibility on leadership. Without buy-in from the top, implementation stalls.
  •     A designated implementation lead:
    Assign an OH&S Manager or appoint an external consultant to own the process end-to-end.

How to Implement ISO 45001: Step-by-Step

Step 1 – Conduct a Gap Assessment

The first step in any ISO 45001 implementation is understanding where you currently stand. A gap assessment compares your existing health and safety practices against the requirements of the standard clause by clause.

  • Review current OH&S policies, procedures, and records.
  • Identify which clauses of ISO 45001 you already satisfy and which require new or updated documentation.
  • Prioritise gaps by risk level to build your implementation roadmap.

Step 2 – Define the Scope and Context of the Organisation

Clause 4 of ISO 45001 requires you to establish the context of your organisation. This means identifying internal and external issues that affect occupational health and safety, and determining which parts of the business, which sites, functions, and activities, fall within the scope of your OHSMS.

You must also identify all interested parties, employees, contractors, visitors, regulators, and neighbours, and understand their OH&S-related needs and expectations.

Step 3 – Establish Leadership and Worker Participation

ISO 45001 is explicit that leadership is not merely supportive, it is accountable. Top management must establish, communicate, and model an OH&S policy; assign roles and responsibilities; and ensure resources are available for the system to function.

Equally important is worker participation. Unlike its predecessor OHSAS 18001, ISO 45001 dedicates Clause 5.4 specifically to consultation and participation of workers,  because the people doing the work are best placed to identify hazards and propose controls.

Step 4 – Hazard Identification and Risk Assessment

This is the operational core of ISO 45001. Under Clause 6, you are required to systematically identify all hazards in your workplace, physical, chemical, ergonomic, psychosocial, and process-related, and assess the risk associated with each one.

  • Use a documented risk assessment methodology (likelihood × severity matrix is widely accepted).
  • Apply the hierarchy of controls: eliminate, substitute, engineer, administrate, and then PPE as a last resort.
  • Document your risk register and review it whenever operations, equipment, or personnel change.

Step 5 – Develop Documentation and Implement Controls

ISO 45001 is less prescriptive than OHSAS 18001 about what documented information is mandatory, but you will still need a clear OH&S policy, objectives, a risk register, operational controls, emergency response plans, and records of training and incidents.

Operational controls (Clause 8) translate your risk assessments into day-to-day procedures. These cover everything from permit-to-work systems and contractor management to emergency preparedness and change management protocols.

Step 6 – Run Internal Audits and a Management Review

Before inviting an external certification body, you must demonstrate that the system is working. Conduct at least one full cycle of internal audits (Clause 9.2) covering all clauses and all departments within scope.

Follow this with a formal management review (Clause 9.3). Top management must review OH&S performance data, audit findings, incident reports, and the status of objectives, and make decisions about any changes needed.

Step 7 – The ISO 45001 Certification Process

The ISO 45001 certification process involves two stages with an accredited third-party certification body:

  •     Stage 1 (Documentation Review): The auditor reviews your documented OHSMS to confirm it meets the standard’s requirements. Gaps identified here must be addressed before Stage 2.
  •     Stage 2 (Certification Audit): The auditor visits your workplace to verify that your OHSMS is fully implemented and effective. They will interview workers, review records, and observe operations.

Certification is typically valid for three years, with annual surveillance audits to confirm ongoing compliance.

Common Implementation Mistakes to Avoid

  • Treating documentation as the goal rather than evidence of a working system.
  • Skipping worker consultation, auditors will Investigate this specifically.
  • Performing a single internal audit the week before Stage 2, auditors can spot a system that has never been tested over time.
  • Defining an overly wide scope that the organisation cannot realistically maintain.

How Long Does ISO 45001 Implementation Take?

For most organisations, end-to-end implementation takes between four and twelve months depending on organisational size, the maturity of existing OH&S practices, and the number of sites in scope. Small organisations with a focused scope can move quickly; multi-site operations require more planning and internal audit cycles.

Ready to Start Your ISO 45001 Journey?

HSEQ Professionals offers full-cycle ISO 45001 consulting, from gap assessment and documentation through to certification audit support, across Saudi Arabia, Pakistan, and the USA. We also deliver the CQI-IRCA certified ISO 45001 Lead Auditor course for organisations that want to build in-house audit capability.

Contact our team to discuss your implementation timeline and get a tailored project plan.