certifications7 min read

Getting ISO 45001 certified: the process step by step

ISO 45001 is the international standard for occupational health and safety (OH&S) management systems. Published in March 2018 to succeed the OHSAS 18001 scheme, it is voluntary, certifiable, and increasingly requested by client organisations — industry, construction and logistics first. Here is the complete process to obtain it, step by step, with no illusory shortcuts.

Before starting: understand what will be audited

The audit does not judge your intrinsic level of risk, but the robustness of the management system that frames it: hazard identification, risk assessment, worker consultation and participation, operational control, emergency preparedness, continual improvement. The standard follows the structure common to the major management standards (clauses 4 to 10), which makes it easy to integrate into an existing QSE system alongside ISO 9001 or ISO 14001.

Two requirements give ISO 45001 its distinctive character. First, leadership: top management owns the OH&S policy and cannot delegate the commitment to an isolated safety officer. Second, worker participation: the standard requires organising consultation at every level — hazard reporting, definition of measures, lessons learned. It is auditors’ favourite checkpoint, precisely because it cannot be improvised.

Step 1 — Start from the legal baseline

In France, you never start from zero: the Labour Code already imposes a prevention baseline, starting with the DUERP (the single occupational-risk assessment document), mandatory from the first employee. An up-to-date DUERP, an analysed history of accidents and near misses, traceable regulatory training and compliant periodic inspections are the raw material of the future system — the standard adds the steering layer. We cover this in detail in our article on ISO 45001 and the DUERP.

The first useful deliverable is a gap analysis: confronting your organisation with clauses 4 to 10 and listing what is missing. The most frequent gaps: no structured regulatory watch, no measurable OH&S objectives, no formalised worker-consultation arrangements, no internal audit.

Step 2 — Frame the project

Three decisions structure everything that follows:

  • The scope: sites and activities covered by the future certificate.
  • The project lead: an identified person with real time — not a mission added to a full agenda.
  • The budget over the full cycle: initial audit, annual surveillance, renewal at three years, possible external support and internal time. Our article on the cost of ISO 45001 certification details each item.

This is also the moment to secure top management’s effective commitment: validating the OH&S policy, arbitrating resources, attending the management review. A project carried only by “quality” quickly hits a ceiling.

Step 3 — Build the system

Construction typically covers, in the most common order:

  1. OH&S policy and objectives: signed by top management, broken down into measurable objectives with action plans.
  2. Hazard identification and risk assessment: building on the DUERP, work unit by work unit, with the participation of the teams concerned.
  3. Legal requirements: listing the applicable texts and organising the regulatory watch.
  4. Operational control: instructions, management of change, purchasing and subcontracting, coordination with external companies.
  5. Emergency situations: identified scenarios, procedures, recorded drills.
  6. Worker consultation: concrete channels (toolbox talks, reporting box, existing bodies) and evidence they work.

The documentation format is free: the standard requires evidence of operation, not a template manual. Concretely, the auditor will want to see dated traces: minutes of toolbox talks with the issues raised and how they were handled, event analyses with causes and actions, emergency drills carried out, action plans tracked to closure. Think “evidence of use” from the design of every document: a form nobody will ever fill in protects no one and will convince the auditor no further.

If you already hold ISO 9001 or ISO 14001, capitalise on it: the common structure lets you plug OH&S into existing processes — document control, internal audits, management review — rather than building parallel machinery.

Step 4 — Run in, audit internally, hold the review

This is the most underestimated step. The system must run for several months to produce real records: field reports handled, events analysed, indicators tracked, actions closed. A systematic review published by Robson and co-authors in Safety Science on the effects of OH&S management systems found favourable safety results, while showing those effects depend on implementation quality (see the study) — exactly what the audit sets out to verify.

Before the certification audit, two explicit requirements must have been met: an internal audit covering the scope, and a management review that analyses results and takes decisions. They are your best dress rehearsals — provided you play them seriously: a complacent internal audit that finds nothing deprives the organisation of its last chance to correct before the certifier’s scrutiny, and a management review with no recorded decisions will be read for what it is, a formality.

Step 5 — The certification audit and the three-year cycle

The initial audit, conducted by an accredited certification body (AFNOR Certification, Bureau Veritas, SGS, among others), unfolds in two stages: a readiness review (stage 1), which examines the documented system and confirms the organisation is ready, then the implementation audit (stage 2) — interviews with management and teams, site visits, examination of records. Findings do not mechanically mean refusal: you propose an action plan (causes, corrections, corrective actions) whose relevance conditions the issuing of the certificate.

The certificate then opens a three-year cycle: annual surveillance audits, then a renewal audit. A system that only comes alive as audits approach degrades by the first surveillance — continuity of steering is an integral part of the journey.

One last point of vocabulary useful in 2026: if a client still asks for an “OHSAS 18001” certificate, that scheme was withdrawn after ISO 45001 was published and the migration was completed in 2021 — our article on the move from OHSAS 18001 to ISO 45001 traces what changed. And if your activity includes safety training (SST first-aid-at-work courses, electrical authorisations), remember that their public funding falls under a different framework: see our overview of French regulated safety training.

Take action

Before launching your project, take stock on the full ISO 45001 certification page: status, steps, frequently asked questions and a free ebook to structure every stage, from baseline assessment to certificate.

FAQ

Frequently asked questions

+How long does it take to obtain ISO 45001 certification?

There is no regulatory duration. The dominant factor is the running-in period: the auditor cannot assess a system without an operating history, which means several months of real records before the audit. Depending on the organisation's size and maturity, the full journey typically spans several months to over a year.

+Do you need a consultant to get ISO 45001 certified?

No, it is not a requirement. External support often speeds up the initial diagnosis and the building of the system, especially without in-house OH&S expertise, but the system must be owned by your teams: a framework written entirely by a third party and unknown on the shop floor is detected within the first audit interviews.

+Can you certify only part of the company under ISO 45001?

Yes, the scope of the certificate is defined with the certification body: one site, one activity or the whole organisation. The scope must remain coherent and legible for your clients — a certificate that excludes precisely the highest-risk activities loses most of its value.

Read next