ISO 45001 – Occupational health and safety
ISO 45001 is the international standard for occupational health and safety management systems. It replaced the former OHSAS 18001 and follows the same high-level structure as ISO 9001 and ISO 14001. Its requirements apply to every sector and every size of business. How a company meets them is something the standard deliberately leaves open.
In Germany it lands in a dense legal environment: the Occupational Health and Safety Act (Arbeitsschutzgesetz), the Industrial Safety Ordinance (Betriebssicherheitsverordnung), the Hazardous Substances Ordinance (Gefahrstoffverordnung), the DGUV rules and so on. Much of that is compulsory anyway. The difference lies in the systematic approach. The standard requires an unbroken chain from the hazard through the control measure to the check that it works. It is precisely this chain that breaks in most audits. What is missing is not the technical knowledge, but the evidence that it takes effect.
Who it applies to
- Businesses with raised levels of hazard – production, construction, logistics, maintenance – where accident figures feed straight through into downtime and contributions
- Companies whose clients demand the evidence; ISO 45001 is increasingly asked about in tenders and supplier audits
- Organisations already certified to ISO 9001 or ISO 14001 – the shared high-level structure makes adding it leaner
- Businesses following a serious accident or a finding raised by the supervisory authority
Where it usually goes wrong
The risk assessment is out of date
It was usually drawn up thoroughly once, often with outside support. After that it was left alone. In the audit this becomes clear quickly: the site plan shows a machine that has not stood there for two years. A hazardous substance in the inventory was substituted long ago, and a new one appears nowhere.
The standard requires the assessment to be updated with every significant change. That means new plant, altered procedures, different substances, new activities. So in the audit we check the link to procurement and to maintenance. Where a new machine goes into service without triggering a risk assessment, the process is not effective, no matter how good the original document was.
Consultation and participation stay a formality
Clause 5.4 is the core that separates ISO 45001 from the old OHSAS 18001. Workers are meant to take a genuine part in risk assessment, in the choice of control measures and in the investigation of incidents. In practice this is often reduced to a single sentence: we have a health and safety committee.
The committee (Arbeitsschutzausschuss) is required by law above a certain size of business and then meets quarterly. It is no replacement for consulting the people at the machine. This only becomes solid through traces left in the business: minutes with contributions attributed by name, feedback from instruction sessions, and measures that can be traced back to a point raised by the workforce. Where those traces are missing, we record a nonconformity, even where the safety work itself is done well.
Near misses are not recorded
What gets reported is what leads to lost time, because that is when documentation is legally due. The stumble without a fall, the object that falls without hitting anyone, the guard switch bridged for a moment go unmentioned. That removes exactly the data that prevention could be built on. Events without injury are many times more frequent and point to the same causes.
What usually defeats this is not a reluctance to report, but the effort involved and the worry about consequences. We see markedly higher reporting figures where a report can be made anonymously, takes under a minute, and visibly triggers a response back to the shift that raised it.
How we support you
We begin with a baseline assessment. Risk assessments, records of instruction, safety operating instructions and legal registers exist in most businesses. They are simply not connected as a system. Comparing them produces a plan that separates two things: what is genuinely missing, and what is already in place and only needs to be findable.
Then comes building up or slimming down, the internal audit and preparation for the certification audit. Details under Building a management system and Internal audits & gap analyses.
Where instruction intervals, inspection dates and actions drift apart across scattered spreadsheets, we build the database that takes it over. That is the point at which we differ from purely advisory services.
Who handles this at our end
Marion Rammé – IRCA certified and registered QMS / EMS / OHSMS Lead Auditor #01194927
Rüdiger Rammé – IRCA certified and registered QMS / OHSMS Lead Auditor #01192806
Both are expressly certified and registered as OHSMS Lead Auditors, that is for occupational health and safety management systems and not for quality alone. The team in detail
Related standards
- ISO 9001 – quality management, same high-level structure and frequently the basis
- ISO 14001 – environmental management, often run within the same integrated system
- ISO 50001 – energy management, completes the set for energy-intensive operations
Frequently asked questions
How long does it take to reach certification?
Expect six to twelve months. Where a system to ISO 9001 already exists, it is often faster. The time is usually eaten by the risk assessment: it has to be current and complete, and that takes time out in the workplace rather than at a desk.
What does it cost?
Projects of this kind typically range between 10,000 and 50,000 euros. What decides it is the size of the business and the number of sites, the hazard level of the activities, and the share you take on yourselves. The certification body charges its fees separately.
Is an integrated system with ISO 9001 and ISO 14001 worth it?
In most cases, yes. The three standards share their structure and many clauses, among them context, leadership, competence, internal audit and management review. You then run one system instead of three. The certification body also assesses them in a combined audit, which noticeably reduces the effort on site.
Which documents and records do we need?
The central ones are the risk assessments, the register of legal obligations and the records on instruction and competence. Added to those are the health and safety policy, objectives, emergency plans with documented exercises, and the records on incidents, internal audits and management review. Much of this is required by the Occupational Health and Safety Act (Arbeitsschutzgesetz) in any case.
Does ISO 45001 replace the occupational safety specialist or the company doctor?
No. Their appointment under the Occupational Safety Act (Arbeitssicherheitsgesetz) remains compulsory, certificate or not. The standard builds on that and requires the results these specialists produce to arrive in the system, in actions, in objectives and in the management review.
Let us talk about it
The first conversation is free and without obligation.