ISO 45001 Certification: UK & Ireland Employer's Guide
ISO 45001 is the international standard for occupational health and safety management systems. It replaced OHSAS 18001 in 2018 and, after a three-year migration window, is now the only recognised standard for OH&S management-system certification. Whether it belongs on your site’s roadmap depends on what you actually want the certificate to do for you.
This is a chartered practitioner’s walkthrough. What the standard covers, how the certification process runs in Ireland and the UK, where it pays back the effort, and where it doesn’t.
What ISO 45001 Is
ISO 45001:2018, formally titled Occupational health and safety management systems: Requirements with guidance for use, was published in March 2018 by the International Organization for Standardization. It sets out the requirements an employer must meet to plan, run, monitor, and improve a system for controlling occupational health and safety risks. Our RAMS practitioner guide covers the hazard-identification foundations the standard rests on.
Three points worth being clear on:
- It is a management-system standard, not a technical standard. ISO 45001 does not tell you what PPE to issue or how to guard a machine. It tells you how to build the system that decides those things and keeps them under review.
- It is voluntary. ISO 45001 does not replace the underlying health and safety law an employer already has to comply with, such as the Safety, Health and Welfare at Work Act 2005 in Ireland, or the Health and Safety at Work etc. Act 1974 in the UK. It provides a structured, auditable framework for meeting those duties.
- It is the only game in town. OHSAS 18001, the predecessor standard, was formally withdrawn after a three-year migration window that closed in September 2021. Any employer still holding an OHSAS 18001 certificate has expired credentials for tender purposes.
The Annex SL Structure: Ten Clauses and PDCA Backbone
ISO 45001 follows the Annex SL high-level structure that all modern ISO management-system standards share. That structure matters because it means the standard slots cleanly into an existing ISO 9001 (quality) or ISO 14001 (environment) system rather than sitting apart from it.
ISO 45001:2018
Clauses 4–10 Mapped to PDCA
The first three clauses of ISO 45001 are administrative (Scope, Normative References, Terms and Definitions). The remaining seven — clauses 4 to 10 — group into the four Plan-Do-Check-Act phases below and slot into an existing ISO 9001 or ISO 14001 system rather than sitting apart from it.
Plan
Context, policy, hazards
Do
Operate, control, prepare
Check
Monitor, audit, review
Act
Correct, improve
Certification proves the system exists and is being run. It does not, on its own, prove workers are safer day to day. Employers who treat ISO 45001 as scaffolding for a serious behaviour-based programme get both.
Structure per ISO 45001:2018 Annex SL high-level structure and the Plan-Do-Check-Act cycle. Coyle Group
The ten clauses:
- Scope. What the standard covers.
- Normative references. Supporting standards.
- Terms and definitions.
- Context of the organisation. Internal and external issues, interested parties, scope of the OH&S management system.
- Leadership and worker participation. Top-management commitment, OH&S policy, roles and responsibilities, worker consultation.
- Planning. Hazard identification, risk assessment, legal and other requirements, OH&S objectives.
- Support. Resources, competence, awareness, communication, documented information.
- Operation. Operational planning and control, management of change, procurement, contractors, emergency preparedness.
- Performance evaluation. Monitoring, measurement, internal audit, management review, incident investigation.
- Improvement. Nonconformity, corrective action, continual improvement.
If your organisation already runs an ISO 9001 or ISO 14001 system, roughly half of clauses 4, 5, 7, 9, and 10 are already in place. The OH&S-specific work concentrates in clauses 6 and 8, which cover hazard identification, risk assessment, and operational control.
The Big Additions Over OHSAS 18001
Migrating from OHSAS 18001 is not a rebrand. Three additions in ISO 45001 have real teeth:
Context of the organisation (clause 4). The employer has to identify the internal and external issues that affect the OH&S system and the needs of interested parties including workers, contractors, regulators, clients, and local communities. This forces the system to be designed for the actual site conditions rather than lifted from a template.
Leadership and worker participation (clause 5). Top management has to demonstrate accountability, not just sign a policy. Worker consultation and participation is now a specific, auditable requirement, because the certification auditor will interview workers, not just review the paperwork.
Risk-based thinking, not just hazard identification (clause 6). The standard now requires the employer to consider both risks and opportunities to the OH&S management system itself, not only the hazards in the work. That means treating the system as something that can drift and be improved, not as a one-and-done design.
For any organisation still holding a legacy certificate, the three additions above are where the gap analysis effort concentrates.
How Certification Works in Ireland and the UK
Certification is issued by third-party certification bodies, not by ISO itself. Those bodies are accredited by a national accreditation body: the Irish National Accreditation Board (INAB) in Ireland, or the United Kingdom Accreditation Service (UKAS) in the UK. Any certificate worth putting in a tender pack carries the accreditation-body mark alongside the certification-body logo.
The best-known Irish certification body offering ISO 45001 is the National Standards Authority of Ireland (NSAI). Several international bodies (BSI, LRQA, DNV, Bureau Veritas, SGS) also certify Irish and UK sites and are equally valid for tender purposes.
The certification process runs through five broad stages:
- Gap analysis. An informal audit of the current system against the ISO 45001 clauses. Identifies which requirements are met, partially met, or missing.
- System build or upgrade. Close the gaps. For an OHSAS 18001 migration, this focuses on the three additions above. For a build from scratch, this covers the full ten clauses and typically takes six to twelve months.
- Internal audit and management review. The standard requires evidence that the system has been run through at least one full internal-audit cycle and one management review before the certification body will recommend a certificate. This is why “how fast can I get certified” answers are usually longer than the client wants to hear.
- Stage 1 audit (readiness). The certification body reviews the documented system, the internal-audit and management-review records, and confirms the organisation is ready for the Stage 2 audit.
- Stage 2 audit (certification). On-site audit against every clause. Interviews with workers, supervisors, and top management. Any nonconformities have to be closed before the certificate is issued.
After certification, the certification body runs annual surveillance audits and a full recertification audit every three years.
Realistic Timelines and Cost Drivers
Practical numbers, based on the projects we’ve supported in Ireland, the UK, and across the wind-and-power sector:
- Mature safety system already in place, OHSAS 18001 migration or greenfield ISO 45001 with strong existing controls: six to nine months from gap analysis to certificate.
- Building the system from scratch or upgrading a weak system: twelve to eighteen months.
- Certification-body fees: driven by organisation size (worker headcount), number of sites, and risk profile of the work. For a single-site SME (up to 100 workers), certification-body fees typically fall in the €4,000 to €8,000 range for the initial audit cycle, with annual surveillance around a third of that. Tier-one contractors with multiple sites and thousands of workers scale from there.
- Internal cost. Almost always dwarfs certification-body fees. The competent-person time to build, run, and evidence the system is the real cost. Employers who underestimate this are the ones whose Stage 1 audits go badly.
For UK employers weighing the return on investment, the HSE’s business benefits of health and safety guidance is a good starting point on the wider case for structured OH&S spending.
Where ISO 45001 Is Worth the Effort
Certification is worth doing where one of two conditions holds:
Commercial gate. Tier-one construction, utilities, wind, oil and gas, and public-sector supply chains routinely require ISO 45001 certification (or a directly equivalent standard) as a bid condition. If you are chasing that work, the certificate is a licence to operate.
Disciplinary gate. An organisation with a reasonable safety system that has plateaued sometimes benefits from the external cadence, such as a documented internal audit, a management review with defined outputs, or a certification-body auditor turning up on schedule. The pressure of an external audit forces continual improvement in a way the same team acting alone often cannot maintain.
Where certification does not help is proving the workforce is actually safe day to day. A certificate proves the system exists and is being run. The Coyle Approach to safety culture maturity is a better lens for that question. The certified organisations we have seen with the best outcomes used ISO 45001 as scaffolding for a serious behaviour-based safety programme, not as a replacement for one.
Where to Start
Three practical steps sit ahead of any certification-body engagement:
- Run an honest gap analysis against the ten clauses. Score each clause as “in place,” “partial,” or “missing.” This one exercise tells you how long a realistic path to certification is and where the cost concentrates.
- Line up the RAMS side of the house. Clause 6 (planning) and clause 8 (operation) hinge on risk assessments and method statements that reflect how the work is actually done.
- Sequence certification against the tender pipeline. If you’re certifying to win a specific bid, work backwards from the tender-submission date. Certification-body Stage 2 audits often slip; a nine-month buffer is prudent, twelve is safer.
Making ISO 45001 Work Beyond the Certificate
ISO 45001 is worth the effort when a tender requires it, when insurance or client audits are pushing for a recognised system, or when your safety programme has outgrown ad-hoc procedures and needs the Annex SL scaffolding to keep pace. The standard proves the system exists and is being run; what it does not prove is that the workforce is safe day to day. Employers who treat certification as scaffolding for a serious behaviour-based safety programme get both.
If you want an outside chartered practitioner (CMIOSH) to run the gap analysis, build the missing clauses, prepare the internal audit and management review, and stand alongside your team through the Stage 1 and Stage 2 audits, our safety consulting team does exactly that. We build ISO 45001 systems that will pass the audit and, more usefully, keep working after the certification-body auditor leaves.
Frequently Asked Questions (FAQs): ISO 45001
What is ISO 45001?
ISO 45001:2018 is the international standard for occupational health and safety (OH&S) management systems. It sets out the requirements an employer must meet to plan, run, measure, and improve a system for controlling workplace health and safety risks.
Is ISO 45001 a legal requirement?
No. ISO 45001 is a voluntary standard. It does not replace the underlying health and safety legislation an employer already has to comply with, such as the Safety, Health and Welfare at Work Act 2005 in Ireland, and the Health and Safety at Work etc. Act 1974 in the UK. It provides a framework for meeting those duties in a structured, auditable way.
What replaced OHSAS 18001?
ISO 45001:2018 replaced OHSAS 18001. OHSAS 18001 was formally withdrawn after a three-year migration window that closed in September 2021, and it is no longer available for certification. Any organisation still holding an OHSAS 18001 certificate has expired credentials for tender purposes.
How is ISO 45001 certified in Ireland?
Certification is issued by third-party certification bodies accredited by the Irish National Accreditation Board (INAB). NSAI is the best-known Irish certification body offering ISO 45001; several international bodies (BSI, LRQA, DNV, Bureau Veritas, SGS) also certify Irish sites. The process is a two-stage audit against the standard, then annual surveillance audits.
How long does ISO 45001 certification take?
For an organisation with a mature safety management system already in place, six to nine months from gap analysis to certificate is realistic. For an organisation building the system from scratch, twelve to eighteen months is more typical, because the standard requires documented evidence of the system running through at least one internal audit and management review cycle before the certification body will recommend a certificate.
Is ISO 45001 worth doing?
It is worth doing where an employer needs a recognised third-party mark for tenders because tier-one construction, utilities, wind, and public-sector supply chains routinely require it, or where the discipline of an external audit is what will drive the safety system forward. It is not the right way to prove the workforce is safe on its own.
How much does ISO 45001 certification cost in the UK and Ireland?
For a single-site SME with up to 100 workers, certification-body fees typically fall in the €4,000 to €8,000 range for the initial audit cycle, with annual surveillance audits costing roughly a third of that. Larger multi-site organisations scale from there based on worker headcount, site count, and the risk profile of the work. Internal cost, meaning the competent-person time to build and evidence the system, almost always dwarfs certification-body fees.
Does ISO 45001 replace COSHH or other UK regulations?
No. ISO 45001 sits alongside underlying UK regulations such as COSHH, the Management of Health and Safety at Work Regulations 1999, and the CDM Regulations 2015. The standard provides an auditable framework for meeting those legal duties in a structured way, but it does not replace the duties themselves. Legal duties remain even where certification lapses.
How does ISO 45001 relate to ISO 9001 and ISO 14001?
All three standards share the Annex SL high-level structure of ten clauses. Roughly half of clauses 4, 5, 7, 9, and 10 are common across the three, so an organisation already certified to ISO 9001 (quality) or ISO 14001 (environment) typically has the shared clauses covered. The OH&S-specific work then concentrates on clauses 6 (planning, hazard identification) and 8 (operation).
Do small businesses need ISO 45001?
Small businesses do not need ISO 45001 to be legally compliant, because the standard is voluntary. Certification is worth pursuing where a small business bids for contracts that require it, such as tier-one construction or public-sector work. For SMEs without those commercial drivers, the same underlying safety controls can be built and run without paying for third-party certification.