ISO 45001: Lessons learned one year after publication

The ISO 45001 standard for occupational health and safety replaces OHSAS 18001. One year later, questions remain regarding how certain requirements are being addressed.

Marie Faucon
Consultante HSE
Publication : 
04.06.2019
Table of Contents
Request a demo

Set to replace the OHSAS 18001 standard by 2021, the ISO 45001 standard is proving highly successful among organizations looking to continuously improve and showcase their occupational health and safety practices. One year after its publication, the way certain requirements are being addressed is raising questions. Here are our insights and advice.

ISO 45001: A framework for occupational health and safety

The international ISO 45001 standard for occupational health and safety (OH&S) management systems was published in March 2018. It provides a framework for any organization looking to improve its OH&S performance. Structured around ten chapters, like the ISO 9001 and ISO 14001 standards, it allows companies to progressively implement an organization and practices aimed at reducing workplace accidents and occupational illnesses while promoting employee well-being.

This standard intentionally places workers at the heart of the risk prevention process by requiring extensive consultation with workers and their representatives, as well as their participation in the implementation, performance evaluation, and improvement actions of the OH&S management system.

Another distinction compared to other OH&S standards (ILO-OSH, OHSAS 18001, etc.) is that ISO 45001 requires much stronger involvement and commitment from management, including the need to define internal and external issues, risks and opportunities, and to identify the expectations of interested parties. Health and safety are therefore no longer just the responsibility of HSE specialists but become an integral part of the organization's management.

ISO 45001: Questions one year after publication

Since the publication of ISO 45001 just over a year ago, many companies have begun the certification process. However, addressing certain requirements is raising questions. Our assessment and advice follow below.

6.1: Actions to address risks and opportunities

According to ISO 45001, "when determining the risks and opportunities that need to be addressed for the OH&S management system and its intended outcomes, the organization shall take into account legal requirements and other requirements."

Key takeaway: legal and other requirements can be addressed by, among other things, carrying out monitoring of European directives as well as applicable requirements with deferred implementation dates.

6.1.2.2: assessment of other risks related to the OHS management system

In addition to OHS risk assessment, ISO 45001 requires the organization to "determine and assess other risks related to the establishment, implementation, operation, and maintenance of the OHS management system."

What are these other risks and how can this requirement be met? Is it during the management review, when leadership evaluates the OHS management system to ensure its continuing suitability, adequacy, and effectiveness? A system assessment matrix with scoring criteria could help meet this requirement and evaluate risks such as an insufficient audit program or a lack of ATEX expertise.

Since point 6.1.2.2 is written under the Planning chapter, it is not a tool for reaction or improvement, but rather a preventive tool.

Could these other risks be related to the organization's context—that is, its issues, interested parties, and scope? If so, is there not redundancy between requirements 4.1 (understanding the organization and its context), 4.2 (understanding the needs and expectations of workers and other interested parties), and 4.3 (determining the scope)? It would appear so.

Key takeaway: addressing requirements 4.1, 4.2, 4.3, and 9.3 (management review) helps satisfy requirement 6.1.2.2. Other risks related to the OHS management system could include, for example: insufficient resources due to their reallocation for setting up a new production line, or the implementation of a new document management system.

6.1.3: process for determining legal and other requirements

ISO45001 requires that "the organization shall establish, implement, and maintain a process to determine and have access to up-to-date legal requirements and other requirements that are applicable to its hazards and risks." This requirement calls for the creation of a "process," as is the case in other chapters.

How should this concept of a process be understood? Is it necessary, as it was in the 2004 version of ISO 14001, to establish and maintain a procedure? To meet this requirement, the organization can establish a procedure, a process (a set of interrelated or interacting activities that transform inputs into outputs), or a diagram describing the activity of determining legal and other requirements. It is mandatory to retain documented information as evidence of the results of compliance evaluations.

Key takeaway: an effective response could involve deploying an application to inventory compliance obligations andevaluate the organization's compliance with them, as well as implementing a communication plan to satisfy the ISO 45001 requirement to "determine what it needs to communicate about."

8.1.4.2: control of risks related to external providers

ISO 45001 includes the requirement to identify and control OHS risks and hazards related to external providers, such as subcontractors and suppliers. The standard stipulates that "the organization shall coordinate its procurement process with its external providers to identify hazards and to assess and control the OHS risks arising from the contractors' and suppliers' activities and operations that impact the organization. The organization shall ensure that the requirements of its OHS management system are met by external providers and their workers."

Unlike ISO 14001, ISO 45001 does not include the concept of influence. Which subcontractors and suppliers should be included? Tier n, n+1, n+2, or n+3 suppliers? Based on what OHS performance criteria? How can you verify that these criteria are being met?

Key takeaway: determining which suppliers to include depends on characterizing the influence the organization has over those suppliers that impact its operations.