certifications7 min read

ISO 45001 support: is it worth it, from whom, and how far?

You are aiming for the ISO 45001 certificate and the question comes up immediately: should you get support? The honest answer has two parts. No, it is not compulsory — no requirement in the standard calls for a consultant. Yes, it is often useful — provided you know what support actually produces, and what it will never produce in your place.

The golden rule: your certification body cannot be your consultant

An accredited certification body operates under ISO/IEC 17021-1, the standard governing bodies that audit and certify management systems. Its impartiality clause is unambiguous: the certification body, any part of the same legal entity and any entity under its organisational control shall not offer or provide management system consultancy — including drafting manuals and procedures.

The consequence: you will have two distinct players. Whoever helps you build the system cannot be the one who audits it. This is not administrative fine print: it is what gives the certificate its value, an independent third party attesting to something it did not manufacture.

Hence a red flag: any provider hinting that it “supports and certifies” is selling a promise incompatible with accreditation. Same trap as on the market for support with Qualiopi certification, the French quality certification for training providers.

What support really delivers

Good support does not write a system: it speeds up the move from what you already have to a structured system. Four concrete contributions, in the order they arise.

1. The gap analysis, starting from the DUERP you already have

This is the most profitable deliverable, and often the only one a company genuinely needs: comparing your organisation against clauses 4 to 10 of the standard, listing the gaps, prioritising them. The recurring gaps are always the same — no structured legal watch, no measurable health and safety objectives, no formalised worker consultation, no internal audit.

In France, nobody starts from scratch: the DUERP, the mandatory French workplace risk assessment document, is required from the first employee, certificate or no certificate. A competent support provider starts there — DUERP, accidents and near misses, statutory safety training, periodic equipment checks — rather than opening a blank binder (ISO 45001, the DUERP and the law).

2. Hazard identification and the legal watch

On risk, the standard goes further than the statutory DUERP: emergency situations, organisational change, contractors on site, human factors. Add to that the inventory of applicable legal texts and keeping it current, where an outsider’s experience saves real time.

3. Consultation and participation of workers

This is the most distinctive requirement in ISO 45001, and the one auditors probe first. The standard requires consultation to be organised at all levels: hazard reporting, definition of preventive measures, feedback loops. Useful support helps design channels teams will actually use — toolbox talks, shop-floor reports that are handled and documented, a real place for employee representatives — rather than one more form.

4. Internal audits, management review and the two-stage audit

Internal audit and management review are two explicit requirements to satisfy before the certification audit; a support provider can train your internal auditors or run a mock audit — often the best value-for-money service of all. The initial audit then runs as a readiness review (stage 1) followed by the certification audit itself (stage 2): knowing what is examined at each stage avoids the classic mismatch between flawless documentation and a shop floor that has never seen it (the full sequence).

What support cannot do

Three limits, to state at the first meeting.

  • Write a system nobody will keep alive. A body of documents delivered and never adopted shows up within a few interviews: the auditor asks an operator how they report a near miss, and the answer says it all.
  • Guarantee the certificate. The decision belongs to an independent body; a serious professional commits to a method, never to an outcome that is not theirs to give.
  • Replace the involvement of senior management. ISO 45001 puts leadership at the heart of its requirements: the health and safety policy, resource trade-offs and the management review cannot be outsourced.

Four forms of support, not one

“Support” covers very different realities; the external consultant is only one of them. They combine, and the most robust set-up is often the lightest: a short diagnostic, a trained internal lead, a mock audit.

Form What it brings When it fits
External consultant Diagnostic, method, fresh eyes, mock audit No in-house health and safety competence, multi-site scope
Training an internal lead Competence that stays in the company A named employee has genuine time available
Pooling within a business group Shared costs and shared experience Membership of a grouping of firms in the same sector
Support from a sector body or OPCO Possible funding of the training component The need is primarily about building skills

Choosing a provider: five criteria

  1. References from companies of comparable size and sector. A system designed for an industrial site of three hundred people does not transfer to a twelve-employee trade business.
  2. Real knowledge of French employment law. ISO 45001 is international; your obligations are national — DUERP, prevention plan, statutory training, employee representative bodies.
  3. Skills transfer rather than binder delivery. The question to ask: “what will we be able to do alone once you have left?”
  4. Refusal of generic documentation systems. A template is a starting point, never a final deliverable.
  5. A written quote, with deliverables and days. Pricing opacity is a negative signal in itself.

And one central warning sign: the “turnkey system”, which promises precisely what the standard makes impossible — a management system its own users did not build.

What drives the budget

There is no reference price and we will not invent one. The variables that drive it, however, are stable and verifiable on a quote: size of the organisation in scope, number of sites, starting level (legal baseline up to date or neglected), an existing certified QSE system to graft onto, and the sector with its risk level.

This budget sits on top of the certification body’s, which follows its own audit-day logic: our article on the cost of ISO 45001 certification breaks down the full three-year cycle.

What the research says: the certificate is not enough

Two studies invite you to judge support on genuine adoption by the teams rather than on obtaining the paper.

Iñaki Heras-Saizarbitoria, Olivier Boiral, Germán Arana and Erlantz Allur published in 2019 in the Journal of Safety Research a study of 5,147 Spanish companies: OHSAS 18001 certification, the direct predecessor of ISO 45001, appears only weakly linked to better health and safety performance as measured by occupational accident rates (see the study).

McLeod and colleagues, in an evaluation published in 2025 in the American Journal of Industrial Medicine, reach a converging nuance: the effects of an occupational health and safety management system certification programme on injury rates vary by sector, with reductions observed in some and not in others (see the study).

The lesson is direct: the certificate does not bring accident numbers down, what counts is what the system changes in day-to-day behaviour. Judge your support against that yardstick. Are your teams reporting more hazardous situations than before? Are actions being closed out? If not, the binder is perfect and the exercise has failed.

If you are also aiming for MASE or an integrated system

If you work on industrial sites, your client organisations may ask for MASE instead, a French health and safety scheme deeply rooted in chemicals, petrochemicals and industrial maintenance: covering both routes in one support engagement avoids paying twice for the same risk identification work. Our comparison of ISO 45001 or MASE sets out the criteria, and the MASE scheme page describes how it works.

If you already hold ISO 9001 or ISO 14001, say so from the outset: the structure shared by management system standards lets you plug health and safety into existing processes — document control, internal audits, management review — instead of a parallel machine. Our article on integrating ISO 14001 with ISO 9001 and ISO 45001 into a QSE system shows where the savings are.

Take action

Before contacting a provider, do the first pass yourself: revisit your DUERP, list what you can already evidence, buy only what is missing. To frame your scope and timeline, see our guide to ISO 45001 certification: steps, frequently asked questions and a free ebook.

FAQ

Frequently asked questions

+Can my certification body also help me build the management system?

No. The accreditation standard ISO/IEC 17021-1 states that the certification body — and any entity under its organisational control — shall not offer or provide management system consultancy. You therefore need two distinct players: a support provider upstream, an accredited certification body downstream. Any provider promising both is blurring a line that is incompatible with its accreditation.

+Is external support mandatory to obtain the ISO 45001 certificate?

No, nothing requires it. ISO 45001 calls for an occupational health and safety management system that meets clauses 4 to 10 of the standard, not for a consultant. Support makes most sense when no health and safety competence exists in-house, when the scope covers several sites, or when nobody can free up the time to run the project.

+How much does ISO 45001 support cost?

There is no reference price: the consultancy market is unregulated and no two quotes contain the same deliverables. The variables that drive the price are stable, though: headcount, number of sites, risk level of the activities, maturity of your existing legal baseline and whether a QSE system is already certified. Always insist on a written quote listing deliverables and days.

Read next