Occupational safety and health management cannot only pursue responsibility after an accident occurs, nor can it rely solely on the care of on-site personnel. Equipment, work methods, working hours, contractor relationships, management decisions and organizational culture may all affect worker safety and health. ISO 45001 provides an occupational safety and health management system structure to assist enterprises in establishing a sustainable prevention system from the source of hazards, risk control to incident improvement.
As of July 2026, ISO 45001:2018 is still the current official version. ISO will confirm this version and issue climate action amendments in 2024; the second version is still in the draft stage. Enterprises should operate in accordance with formal standards and local regulations, and continue to pay attention to subsequent official revisions, rather than directly treating the contents of the draft as verification requirements.
The goal of ISO 45001 is to prevent injuries and health damage
The standards apply to all types of organizations that want to improve occupational safety and health, eliminate hazards, reduce risks and address system deficiencies. It does not limit factories or high-risk operations. Offices, medical care, logistics, construction, schools and service industries may also face human factors, violence, stress, infection, transportation or contracting risks.
The results of the system cannot be judged solely by “zero accidents this year”. The low number of accidents may result from risks being truly controlled, or from lack of notification. Companies also need to look at leading indicators such as hazard improvement, near misses, health monitoring, contractor performance, regulatory compliance and worker engagement.
Core 1: Leadership Responsibility and Worker Participation
Occupational safety and health cannot be fully delegated to safety and health units. Senior managers need to integrate safety and health into business decisions, provide resources, remove barriers, and ensure that performance requirements do not encourage unsafe behavior. For example, if you only pursue work quickly without adjusting manpower and equipment, it is easy for safety procedures to become ineffective.
Workers know best about actual operations and exceptions, so consultation and participation are important cores of ISO 45001. Enterprises must provide appropriate channels for workers at different levels, shifts, and dispatched and contracted personnel to report hazards, participate in risk assessments and incident investigations, and avoid adverse treatment due to reporting.
Core 2: Comprehensive identification of hazards and assessment of risks
Hazard identification should cover routine and non-routine work, human factors, work organization, equipment, chemicals, transportation, contractors, visitors, emergencies and past events. It should also consider activities outside the workplace but under the control of the organization. Psychosocial hazards, such as workload, bullying, role conflict and lack of support, cannot be excluded.
Risk assessment methods should have consistent criteria, but there is no need to be superstitious about scores. Low-frequency events that may cause major harm cannot be ignored just because the probability of occurrence is low; the controls specified in the law cannot be implemented solely based on the scoring results. After the assessment, the responsibilities and deadlines for improvement should be clearly linked.
Core 3: Prioritize the elimination of hazards according to the control level
When controlling risks, priority should be given to eliminating hazards, followed by substitution with safer materials, equipment or methods, then engineering control and management measures, and finally reliance on personal protective equipment. If the improvement of each risk is “strengthening publicity and wearing protective gear”, it usually means that source control has not been fully evaluated.
For example, instead of only requiring safety belts when working at heights, it is better to first evaluate whether it can be completed at ground level, use a fixed platform, or set up guardrails. Management measures and protective equipment are still important, but are easily affected by human behavior, fatigue and maintenance conditions.
Core 4: Managing Change, Procurement and Contractors
New equipment, new materials, new processes, organizational adjustments or changes in construction schedules may create new hazards. Enterprises should complete risk assessment, regulatory confirmation, education and training, and control design before changes are implemented, rather than waiting for an incident to supplement documentation.
Safety specifications should be incorporated into equipment, chemicals and service conditions during the procurement phase. Contractor management must form a complete process from qualifications, admission, hazard notification, joint operation coordination, on-site supervision to performance evaluation. Issuing a contract does not mean that the original company completely transfers safety responsibilities. Unclear interfaces are often the source of accidents.
Core 5: Emergency response must be truly implemented
Enterprises need to establish notification, evacuation, rescue, external contact and recovery arrangements based on possible fires, chemical leaks, power outages, natural disasters, medical emergencies or other situations. Plans should consider night shifts, people with reduced mobility, visitors, contractors and neighboring units, rather than just regular day shift employees.
The purpose of the drill is not to complete the annual session, but to test whether the personnel know how to judge and act. After the drill, gaps in communications, equipment, routing, and decision-making should be recorded, and a responsible person should be designated to track improvements.
Core Six: Incident Investigation and Continuous Improvement
Accidents, health abnormalities and near misses are institutional learning opportunities. The investigation should not stop at “failure to pay attention” or “failure to comply with regulations.” It should also ask how work design, training, supervision, equipment, work schedule, fatigue and management decisions jointly caused the incident. After the corrective measures are completed, it is also necessary to confirm whether the risks have been reduced and whether new risks have arisen.
Companies can evaluate systems through on-site inspections, health monitoring, environmental measurements, targets, internal audits and management reviews. When workers report that similar problems continue to occur, even if they have not caused an accident, it should be regarded as an important management signal.
What processes can be improved after importing?
Originally, occupational safety information was often scattered in inspection forms, education and training, contract documents and accident records, and each unit only processed its own forms. After establishing a common process, hazards can be linked to control measures, responsible persons, deadlines and verification results; new equipment procurement and project contracting can also include risks in advance, instead of being remedied by safety personnel after the fact.
For workers, the reporting pipeline and processing results are more transparent; for supervisors, they can see overdue improvements, repeated hazards and high-risk contract activities, and allocate resources in advance.
Common misunderstandings
- Only manufacturing and construction industries require ISO 45001.
- The absence of accidents means that risk control is effective.
- Hazard identification is only done in the office by safety and health personnel.
- Each risk is addressed with education, training and personal protective equipment.
- The contractor is responsible for its own security, and the outsourcing company does not need a management interface.
Which companies are suitable for import?
- There are many high-risk operations, equipment, chemicals or contracting activities.
- Occupational safety practices at multiple locations are inconsistent and data is difficult to compile.
- Near misses and repeated deletions did not form a closed loop of improvement.
- Client requires occupational safety and health management system or supply chain evidence.
- Hope to incorporate personal safety, health and worker participation into business management.
Frequently asked questions when introducing occupational safety and health management
Can ISO 45001 replace occupational safety and health regulations?
cannot. ISO 45001 provides a management system framework, but companies must still identify and comply with applicable local occupational safety and health regulations, licensing, inspection, education and notification requirements. Systems can assist in assigning responsibilities, setting reminders, preserving evidence, and regularly assessing compliance, but obtaining verification does not mean that the competent authorities will not inspect, nor does it exempt the employer from legal liability.
Are work stress and bullying also within the scope of management?
yes. Work organization, unclear roles, overload, violence and harassment can affect mental and physical health and should be included in hazard identification. In addition to providing personal consultation, companies must also review workload, manpower, management methods, confidentiality of complaints and risks of adverse treatment. Simply asking individuals to improve their stress tolerance often fails to address the source of harm.
Data on psychosocial risks may come from employee surveys, separations, absences, grievances, working hours and interviews, but analysis must take into account privacy and confidentiality. Companies should avoid publishing average scores and instead look at risk patterns in specific departments, roles or job types and prioritize organizational-level measures such as adjusting workloads, improving supervisor support, clarifying roles and establishing safe grievance-handling processes. After improvement, data must be collected again to confirm whether the measures have truly reduced the risk.
Relevant results should also be returned to management for review to determine follow-up resources and improvement priorities.
How close can hazard identification be to the scene?
In addition to listing equipment and operations by department, companies can follow work steps and observe the interactions of people, tools, materials, environments, and adjacent operations. Non-routine tasks such as repairs, cleaning, commissioning, troubleshooting and rush jobs are often more easily missed than routine operations. Night shifts, maternity, physical and mental conditions, language and experience differences may also affect risks and the effectiveness of controls.
The identification process should involve actual workers, and information can be obtained through on-site inspections, pre-shift discussions, near misses and anonymous feedback. Supervisors should not just ask “Is there any danger?” but should ask specifically about what situations are most difficult to operate, when procedures will be bypassed, and where the equipment is likely to get stuck. The processing results must be reported back after collection, otherwise workers will gradually lose their willingness to report.
How to use control hierarchy correctly?
When facing a major risk, first ask whether the work is necessary and whether it can be eliminated in the design; if not, then evaluate how to replace it with safer materials, equipment or methods. Engineering controls such as isolation, shielding, ventilation, and automation are often more reliable than human memory alone. Administrative controls include procedures, scheduling, permissions, rotations and alerts, and personal protective equipment is the last line of defense.
Different controls can be combined, but make sure they do not conflict with each other. For example, thick protective gear may increase thermal stress, and working at night may reduce supervision and response. After the measures are completed, you should return to the site to observe and re-evaluate, rather than closing the case after seeing the purchase order or education records. If workers still need to frequently bypass controls to complete their tasks, the design is not yet truly feasible.
What interfaces should be managed by contractors working together?
The scope of work, hazards, qualifications and safety conditions should be confirmed before contracting out; hazard notification, education, licensing and emergency contact should be completed before entry; during construction, cross-operations, energy isolation, hot fire, heights, hanging and transportation in the same site should be coordinated. When subcontracting again, the contractor must also ensure that the requirements can be communicated to the actual workers.
The company’s on-site supervisor, procurement, engineering and occupational safety units need to have a clear division of labor. It cannot be assumed that the contractor will be responsible after the documents are signed. If the schedule or scope changes, risks should be reassessed. After completion, defects, near misses and cooperation can be included in the contractor’s performance as the basis for the next contractor selection and management intensity.
How do psychosocial risks move from investigation to improvement?
Employee questionnaires can only provide one of these signals, and can also be combined with working hours, absences, separations, grievances, violence and interviews. Both anonymity and confidentiality must be taken into consideration during analysis to avoid individual identification of small unit results. Risks may arise from overwork, role conflict, lack of autonomy, organizational change, bullying, discrimination and insufficient supervisor support.
Improvements to the work design and management environment should be prioritized, such as adjusting manpower and deadlines, clarifying responsibilities, improving scheduling, and establishing credible defenses for grievances and adverse treatment. Employee assistance programs and individual consultations have value but cannot replace source improvements. After the measures are taken, data should be collected again to observe whether the risk has decreased and whether it has been transferred to other groups.
How can incident investigations avoid being solely attributed to human error?
The investigation first ensures casualty care, scene safety and evidence preservation, and then reconstructs the working conditions, equipment, procedures, communications and decision-making before and after the incident. You can ask: why the personnel took this approach, whether normal work can be completed according to procedures, what restrictions the supervisor knows, and whether similar abnormalities have occurred before. These questions help identify institutional causes.
Improvement measures should be arranged according to the control level and confirmed to be applicable to other equipment, shifts and locations. Near misses should also be investigated based on their potential consequences and should not be dismissed simply because there were no injuries. Investigation results can be shared anonymously with relevant workers, allowing experience to be transformed into prevention; if they are only used to punish individuals, it may reduce future notifications.
Self-examination before establishing occupational safety and health system
- Are workers able to safely communicate hazards, near misses and psychosocial risks?
- Does hazard identification cover maintenance, cleaning, night shifts, changes and joint operations?
- Does risk control prioritize elimination, replacement and engineering measures?
- Are new equipment, materials, construction methods and construction schedule changes evaluated before implementation?
- Are the qualification, admission, coordination, supervision and performance of contractors integrated into the process?
- Do incident investigations examine institutional causes and extend to similar risks?
If there are many on-site records but improvements are repeatedly overdue, you can first put hazards, measures, responsibilities, deadlines and verification results in the same tracking process. Only managers can identify recurring problems and resource bottlenecks, not just inspection completion rates.
During the inspection, actual workers should be invited to participate and explain the processing results, so that the written system and on-site operations can verify each other, and the willingness to report should be maintained.
Conclusion
ISO 45001 is not a post-accident documentation system, but a management approach that identifies hazards before work begins, prioritizes risk elimination, engages workers, and enables continuous learning. Only if the system can enter into procurement, changes, contracting and daily decision-making can we have the opportunity to truly reduce injuries and health damage.
##Official reference material
- ISO 45001:2018 official standard page
- ISO 45001 official introduction
- ISO/DIS 45001 draft revision status
Data access date: July 20, 2026.
