It is the international standard for Occupational Health and Safety Management Systems and is designed to help organisations identify workplace hazards, manage health and safety risks, involve workers, improve operational controls and continually improve OH&S performance.
For South African organisations, ISO 45001 can also provide a stronger framework for managing occupational health and safety responsibilities alongside applicable legal obligations.
The important distinction is this:
ISO 45001 is a management-system standard. South African health and safety legislation creates legal duties.
ISO 45001 certification does not replace compliance with the Occupational Health and Safety Act or other applicable legislation.
Instead, it helps organisations build a more systematic way to identify hazards, manage risks, evaluate obligations, involve employees and improve safety performance.
ISO Specialist South Africa helps organisations develop and implement practical Occupational Health and Safety Management Systems and prepare for independent ISO 45001 certification.
ISO 45001 is the international standard for an Occupational Health and Safety Management System, commonly referred to as an OH&S management system or OHSMS.
The current published edition is ISO 45001:2018.
The standard provides a structured framework for managing occupational health and safety risks and improving workplace safety performance.
Its focus includes areas such as:
ISO 45001 is not limited to high-risk industries.
It can be used by organisations of different sizes and sectors.
A construction company, manufacturer, logistics operation, warehouse and professional-services organisation will all have different health and safety risks.
An Occupational Health and Safety Management System is the framework an organisation uses to manage workplace health and safety systematically.
A functioning OH&S management system helps the organisation understand:
This is what separates a management system from a collection of safety files.
The goal is not to maintain safety documents for an auditor.
For South African organisations, occupational health and safety is both a legal responsibility and a practical business issue.
Poorly managed safety risks can lead to:
ISO 45001 creates a framework for managing those risks proactively.
Instead of asking only:
“What happens if someone gets hurt?”
the organisation asks:
Depending on the organisation, ISO 45001 may address areas such as:
South African businesses need to clearly understand the difference between ISO 45001 certification and legal health and safety compliance.
The Occupational Health and Safety Act 85 of 1993 creates duties for employers and other parties in relation to workplace health and safety.
A core employer responsibility is to provide and maintain, as far as reasonably practicable, a working environment that is safe and without risk to employees’ health.
The legal framework also addresses areas such as:
ISO 45001 does not replace those duties.
The distinction can be summarised simply:
This means that an organisation can pursue ISO 45001 certification while still remaining responsible for all applicable legal requirements.
Certification does not automatically prove that every legal obligation has been satisfied.
Nor does it replace permits, statutory appointments, regulatory requirements, inspections or other legal obligations where those apply.
Where specialist legal interpretation is required, appropriate occupational health and safety or legal expertise should be obtained.
ISO 45001 certification is generally voluntary.
It is not a blanket legal requirement for every South African organisation.
However, voluntary does not always mean commercially optional.
An organisation may pursue ISO 45001 because:
The important distinction is:
ISO 45001 can be used by organisations of different sizes and sectors.
It is particularly relevant where workplace health and safety risk, contractor management or customer requirements materially affect the business.
Construction organisations often operate across changing sites, use contractors, work with machinery and equipment and face risks associated with working at height, excavation, lifting, temporary work and site-specific conditions.
ISO 45001 helps create a consistent management framework across those changing environments.
Manufacturing operations may need to manage:
A structured OH&S management system helps integrate those risks into daily operations.
Industrial organisations often operate with more complex equipment, maintenance activities, contractor interfaces and operational hazards.
ISO 45001 can provide clearer ownership, controls and monitoring.
Relevant risks can include:
Warehouses can involve risks associated with forklifts, racking, loading areas, traffic movement, manual handling and contractor activity.
Maintenance, cleaning, contractors, access, electrical work and emergency preparedness can all create safety responsibilities.
Lower physical-risk environments still have health and safety obligations.
Potential issues may include:
Many large organisations expect suppliers and contractors to demonstrate effective health and safety management.
ISO 45001 can strengthen supplier qualification and tender readiness where certification is requested.
ISO 45001 should create value beyond the certificate itself.
A well-implemented OH&S management system can improve how the organisation identifies, controls and learns from workplace risk.
The strongest ISO 45001 systems therefore do two things at the same time:
ISO 45001 follows the established ISO management-system structure.
The main requirements sit within Clauses 4 to 10.
These requirements should not be implemented as seven separate documentation folders.
They form one management cycle.
Hazard identification is one of the most important parts of ISO 45001.
A hazard is a source or situation with the potential to cause injury or ill health.
Examples could include:
Once hazards are identified, the organisation evaluates the associated OH&S risks and determines appropriate controls.
The purpose is not to build the largest possible risk register.
It is to understand:
The strongest hazard assessments involve the people who understand the work.
That often means including:
A risk assessment created entirely in an office can easily miss what actually happens in operations.
ISO 45001 encourages organisations to use stronger controls where possible rather than immediately relying on personal protective equipment.
A practical hierarchy is:
The higher the control sits in the hierarchy, the more it generally aims to remove or reduce the hazard before relying on individual behaviour.
Consider excessive workplace noise.
PPE may still be necessary.
But it should not automatically be the first answer.
Worker consultation and participation is one of ISO 45001’s defining features.
Workers are not simply expected to receive safety instructions.
They should be appropriately consulted and involved in the management system.
That can include involvement in areas such as:
This matters because workers often have the best understanding of how work actually happens.
A manager may know the formal procedure.
The employee performing the activity knows where the procedure does not reflect reality.
That information is essential for effective risk management.
Consultation should not exist only on paper.
An effective system gives workers appropriate opportunities to raise concerns and contribute to safer ways of working.
A practical ISO 45001 implementation usually begins by understanding what the organisation already has.
Many organisations already operate safety processes such as:
These should be assessed before creating anything new.
Determine which sites, activities and operations fall within the OH&S management system.
Compare current safety-management practices against ISO 45001 requirements.
Identify relevant internal and external issues, workers and other interested parties.
Determine where harm could occur and which risks require control.
Establish which occupational health and safety obligations apply.
Management sets direction and measurable priorities.
Responsibilities are defined and worker involvement is built into the system.
Create or improve the management processes needed to control risks.
Employees need the knowledge and skills necessary for their roles.
Controls are put into everyday practice.
The organisation gathers evidence about whether safety arrangements work.
The management system is evaluated internally.
Leadership reviews performance and determines actions.
Remaining gaps are addressed before the independent audit.
An independent certification body performs the certification assessment.
Businesses change.
New equipment is introduced.
Processes change.
New contractors are appointed.
Sites expand.
Employees move into new roles.
Materials change.
Temporary work is introduced.
These changes can create new safety risks.
ISO 45001 therefore requires a structured approach to relevant change.
Before making a change, organisations should ask:
Health and safety risk does not stop with permanent employees.
Contractors, suppliers and outsourced processes can introduce significant risk.
Depending on the organisation, this may involve:
ISO 45001 encourages organisations to integrate OH&S considerations into procurement and contractor-management processes.
This might include:
The objective is not to transfer risk onto a contractor and assume the issue is solved.
Organisations need to identify potential emergency situations and prepare appropriate responses.
Depending on the business, emergencies could include:
The organisation should establish:
Emergency planning should reflect real operational risks.
Incidents provide information.
The worst outcome is to treat them only as paperwork.
When an incident occurs, the organisation should respond appropriately and determine what needs to change.
There is an important difference between:
responding to the incident
and
preventing recurrence.
An employee slips on oil.
Cleaning up the oil addresses the immediate hazard.
But the organisation should also ask:
That is where corrective action begins.
The goal is not to find someone to blame.
Employees need appropriate competence for work that affects occupational health and safety.
The level of competence depends on the role.
A forklift operator, supervisor, office employee, maintenance technician and internal auditor do not need the same training.
The organisation should determine what competence each role requires and how that competence will be achieved.
This may involve:
Employees should also understand:
The goal is not to make every employee an ISO expert.
Internal audit helps the organisation determine whether its OH&S management system:
A useful internal audit looks beyond documentation.
It can include:
Internal audit should provide management with a reliable view of system performance.
Top management needs to periodically review the OH&S management system.
The purpose is to evaluate whether the system remains suitable, adequate and effective.
Management review may consider:
There is no single credible timeline that applies to every South African organisation.
The time required depends on factors such as:
An organisation with mature safety processes and an existing ISO 9001 or ISO 14001 management system may progress more efficiently than an organisation starting from scratch.
The correct question is therefore:
A gap assessment provides the clearest starting point.
There is no single ISO 45001 price that applies to every organisation.
The overall investment normally has two main parts:
This covers the work required to develop and implement the OH&S management system.
The amount depends on:
The certification body charges for the external certification process.
These costs can be influenced by:
The certification-body fee should not be confused with consultancy.
They are separate services.
A properly scoped quotation should make clear what is included and what remains separate.
Once the OH&S management system has been implemented and internally evaluated, the organisation can proceed to independent certification.
A typical certification path includes:
The system is operating and producing evidence.
Weaknesses are identified internally.
Leadership formally reviews the system.
The organisation selects an appropriate independent certification body.
The certification body evaluates readiness and key management-system information.
The auditor assesses implementation in practice.
Relevant nonconformities are corrected according to the certification body’s requirements.
A positive independent certification decision leads to certification.
Ongoing audits confirm the management system remains effective.
The organisation undergoes recertification towards the end of the certification cycle.
Certification should confirm a working system.
ISO itself does not issue ISO 45001 certificates.
An implementation consultant also does not make the certification decision.
An independent certification body conducts the certification audit and issues the certificate following a positive certification decision.
In South Africa, SANAS, the South African National Accreditation System, is the national accreditation body.
SANAS accredits conformity-assessment bodies for defined scopes.
It does not directly certify individual organisations against ISO 45001.
When selecting a certification body, verify the body’s current accreditation and applicable scope.
This is especially important where certification is required for:
ISO 45001 can be integrated with other ISO management-system standards.
The most common combination is:
These standards share a common management-system structure.
That means processes such as:
can often be integrated.
An organisation does not necessarily need three separate systems.
A well-designed Integrated Management System can reduce duplication and create a clearer operating framework.
For example, one contractor-management process could address:
ISO 45001 replaced OHSAS 18001.
The change went beyond the title.
ISO 45001 introduced a management-system approach more closely aligned with other ISO standards.
Important differences include stronger emphasis on:
ISO 45001 can become unnecessarily complicated when implementation starts with clauses and templates instead of the workplace.
Our approach starts with your organisation.
We look at:
From there, the management system can be built around the business.
The goal is an OH&S management system that:
We believe the certificate should demonstrate the system.
ISO 45001 is the international standard for Occupational Health and Safety Management Systems. It provides a framework for organisations to identify hazards, manage OH&S risks, involve workers, monitor performance and continually improve workplace health and safety.
The current published edition is ISO 45001:2018, together with the applicable 2024 climate-action amendment.
ISO 45001 certification is generally voluntary. However, it may be required by customers, tenders, contractors or supply-chain arrangements. Legal occupational health and safety obligations can still apply regardless of whether the organisation chooses certification.
The Occupational Health and Safety Act creates legal duties in South Africa. ISO 45001 provides a management-system framework for systematically identifying and managing workplace health and safety risks and applicable compliance obligations. ISO 45001 certification does not replace legal compliance.
The main requirements cover organisational context, leadership and worker participation, planning, support, operation, performance evaluation and improvement. Important operational areas include hazard identification, risk assessment, legal obligations, operational controls, emergency preparedness, internal audit and corrective action.
Organisations of different sizes and sectors can pursue ISO 45001 certification where the standard is appropriate to their activities and occupational health and safety risks.
There is no single standard price. Costs depend on factors such as organisation size, sites, certification scope, hazard complexity, current system maturity, implementation support required and independent certification-body audit fees.
The timeframe depends on the organisation’s starting point, safety-management maturity, number of sites, hazard complexity, internal resources and certification-body availability. A gap assessment is the most reliable way to determine the likely implementation effort.
Hazard identification is the process of determining what workplace conditions, activities or situations have the potential to cause injury or ill health.
The hierarchy of controls prioritises stronger risk controls where possible: eliminate the hazard, substitute it, use engineering controls, use administrative controls and then use personal protective equipment.
Yes. Consultation and participation of workers is a major part of ISO 45001. Workers should be appropriately involved in relevant parts of the OH&S management system.
An independent certification body conducts the external certification assessment and makes the certification decision. ISO itself does not certify organisations.
ISO 45001 replaced OHSAS 18001 as the international Occupational Health and Safety Management System standard.
Yes. The standards use aligned management-system structures and can be combined within an Integrated Management System to reduce unnecessary duplication.
You do not need to start by rewriting your safety system.
Start by understanding what already works.
Your organisation may already have:
The first step is to determine how those existing arrangements compare with ISO 45001 requirements.
ISO Specialist South Africa can help you assess your current position, identify the gaps, develop a practical OH&S management system and prepare for independent ISO 45001 certification.
The objective is not more safety paperwork.
Tell us where your organisation is today and where you need to get to.
We will help determine a practical route towards an ISO 45001 management system that works in daily operations and is ready for independent certification.