ISO 45001 Clauses Explained: A Complete Clause-by-Clause Breakdown

ISO 45001 can feel daunting at first. Ten clauses, multiple sub-clauses, dozens of requirements. How do you navigate this structure?

The key is understanding that beneath the complexity lies elegant simplicity: Plan-Do-Check-Act. The ten clauses organise systematically around this cycle. Understand the cycle, and the standard becomes navigable.

This article provides a detailed clause-by-clause breakdown, explaining each requirement, why it matters, and what auditors look for.

ISO 45001 Structure Overview

ISO 45001’s 10 clauses break into two groups:

Administrative Clauses (1–3): These define scope, reference normative documents, and define terminology. They’re important but don’t contain normative requirements your system must fulfill.

Operative Clauses (4–10): These contain the “shall” statements—normative requirements auditors assess for compliance. They map to PDCA:

    PLAN   →  Clauses 4, 5, 6
    DO     →  Clauses 7, 8
    CHECK  →  Clause 9
    ACT    →  Clause 10
    

This cyclical structure embeds continuous improvement. You plan, execute, measure, and improve—then repeat. Unlike a linear model (do it once, sign off), PDCA is perpetual.

Clauses 1-3: Administrative Foundation

Clause 1: Scope

Clause 1 states what ISO 45001 is: an international standard for OH&SMS. It briefly describes the standard’s purpose—to enable organisations to provide a safe, healthy work environment.

What you must do: Understand the scope. You don’t create a statement about scope; you’re simply acknowledging what ISO 45001 is and why.

What auditors assess: Whether you understand the standard’s boundaries and intent.

Clause 2: Normative References

Clause 2 lists documents that normatively support ISO 45001. Primarily, it references the standard itself and relevant ISO guidance documents.

What you must do: Be aware of the normative references (mainly the standard itself and ISO definitions). You don’t need to reference them explicitly in your system; you just need to know they exist.

What auditors assess: Whether you understand the referenced documents if they become relevant during audit.

Clause 3: Terms and Definitions

Clause 3 defines 68 key terms used throughout ISO 45001. Examples: hazard, risk, interested parties, OH&S performance, contractor, worker, competence.

Key definitions include:

  • Hazard: A source of potential harm or adverse health effect.
  • Risk: The combination of hazard likelihood and severity of potential consequence.
  • Worker: A person under the direct control of the organisation regarding work performed.
  • Interested party: A person or organisation whose interests are affected by the organisation’s OH&S performance (includes employees, contractors, suppliers, customers, regulators, community).
  • Competence: Ability to apply knowledge and skills to achieve intended outcomes.
  • OH&S performance: Measurable results of an organisation’s OH&S management system.

What you must do: Use these definitions consistently throughout your system. Ensure your team understands the terminology. Avoid conflating “hazard” with “risk” (common error).

What auditors assess: Whether you use defined terms correctly. If you conflate hazard and risk, or misuse “competence,” auditors will note it.

Clause 4: Context of the Organisation (PLAN)

Clause 4 requires you to understand your organisational context—the internal and external factors affecting your ability to achieve OH&S objectives.

Clause 4.1: Understanding the Organisation and Its Context

You must identify internal factors (organisational culture, structure, competence, strategy, resources, governance) and external factors (regulatory environment, market conditions, technology, suppliers, competitors, community expectations) relevant to your OH&S system.

Why? Because context shapes hazards. A manufacturing plant in an industrial zone faces different OH&S realities than a technology startup in a city center. Understanding context enables you to design an appropriate system.

What you must do: Conduct a documented context analysis. Interview leadership. Review strategic plans. Analyse regulatory requirements. Identify internal strengths/weaknesses and external opportunities/threats. Document findings.

What auditors assess: Whether you genuinely understand your context. If context analysis is generic, copy-pasted, or superficial, you’ll fail. Auditors ask: What’s unique about YOUR organisation? What context factors did you identify? How do they shape your OH&S system?

Clause 4.2: Understanding the Needs and Expectations of Interested Parties

You must identify interested parties (workers, contractors, suppliers, customers, regulators, neighbours, etc.) and understand their needs and expectations regarding your OH&S system.

Example interested parties: workers (expect safe conditions), contractors (expect site inductions), customers (expect you manage their safety on your premises), regulators (expect compliance with statutory duties), neighbours (expect no hazards affecting them).

What you must do: Identify interested parties systematically. Survey or interview them to understand their needs. Document findings. Incorporate these needs into your OH&S objectives and system design.

What auditors assess: Whether your interested parties analysis is realistic and comprehensive. If you’ve missed key stakeholders (e.g., failed to list contractors as interested parties), you’ll be questioned. Auditors verify you’ve actually engaged with interested parties, not just listed names on paper.

Clause 4.3: Determining the Scope of the Occupational Health and Safety Management System

You must define the scope of your OH&S management system—which parts of your organisation, which locations, which activities it covers.

Scope can be the entire organisation, or specific business units/locations. You might cover manufacturing but not administrative offices (though this is unusual—everything typically carries some OH&S risk).

What you must do: Write a scope statement defining what’s in and out of your OH&S system. Document it. Ensure it’s realistic (you actually manage OH&S within the declared scope) and complete (you’ve genuinely covered all material OH&S areas).

What auditors assess: Whether your declared scope is realistic. If you claim your system covers all operations but haven’t implemented OH&S at a major site, you’ll fail. Overstating scope is worse than understating it.

Clause 4.4: Occupational Health and Safety Management System

You must establish, implement, maintain, and continually improve an OH&S management system aligned to ISO 45001.

What you must do: Build a system covering all 10 clauses. Document policies. Establish processes. Assign responsibility. Allocate resources. Train your team. Measure effectiveness.

What auditors assess: Whether a genuine system exists and operates. A comprehensive audit covering all clauses, assessing whether each requirement is met.

Clause 5: Leadership and Commitment (PLAN)

Clause 5 mandates leadership accountability for OH&S. The tone at the top drives system effectiveness.

Clause 5.1: Leadership and Commitment

Leadership must demonstrate commitment to OH&S by: establishing policy and objectives; allocating resources; removing barriers; communicating the importance of OH&S; involving and consulting with workers; ensuring the system is established and operates effectively; promoting continual improvement; supporting other management roles in demonstrating leadership.

What you must do: Ensure your CEO visibly owns OH&S. Have leadership establish policy (in writing). Allocate resources (budget, staff, time). Demonstrate commitment through actions, not just words. Conduct management reviews. Communicate with the workforce about OH&S priorities.

What auditors assess: Whether leadership genuinely commits to OH&S. Auditors interview leadership and workers. Do workers perceive leadership commitment? Do leaders allocate resources? Do leaders attend management reviews? Do leaders visibly support improvement initiatives?

Clause 5.2: Occupational Health and Safety Policy

Leadership must establish a documented OH&S policy that: commits to comply with applicable legal and regulatory requirements; commits to prevent injuries and ill-health; establishes framework for OH&S objectives; commits to continual improvement; is accessible to interested parties; is periodically reviewed and updated.

What you must do: Write an OH&S policy. Have the CEO (or board) approve it. Ensure it commits to compliance, prevention, continual improvement. Communicate it to employees and interested parties. Review it annually or when context changes.

What auditors assess: Whether your policy is genuine, communicated, and reflected in practice. Copy-pasted generic policies fail.

Clause 5.3: Organisational Roles, Responsibilities and Authorities

Leadership must define and communicate roles, responsibilities, and authorities for OH&S. Someone must own OH&S overall; someone must be responsible for hazard identification; someone must manage incidents; etc.

What you must do: Create an organogram or responsibility matrix showing who owns what. Ensure roles are clearly defined (in writing). Communicate responsibilities to those holding them. Ensure people have authority to fulfill their roles (e.g., the OH&S manager can shut down unsafe work without waiting for approval).

What auditors assess: Whether roles are clear and communicated. If two people don’t know who’s responsible for incident investigation, you’ll be non-conformant.

Clause 6: Planning (PLAN)

Clause 6 requires systematic planning for OH&S management. Plan what you’ll do before you do it.

Clause 6.1: Actions to Address Risks and Opportunities

You must identify hazards, assess risks (likelihood and severity of potential consequences), and identify opportunities for improvement. Then you must plan how you’ll address risks and pursue opportunities.

Hazard Identification: Systematically identify what could harm people or cause illness. Methods: task analysis, checklist review, process walkthroughs, worker consultation, incident data analysis, industry data, expert consultation.

Risk Assessment: For each hazard, assess the likelihood of an incident occurring and the severity of potential consequence if it does. Many use risk matrices: likelihood (low/medium/high) × severity (low/medium/high) = risk level (low/medium/high).

Opportunity Identification: Explicitly identify opportunities to strengthen OH&S. Process improvements? Technology investments? Training enhancements? Design changes? Include these in planning.

Risk Control Planning: For each risk, plan controls using the hierarchy: eliminate the hazard entirely; substitute with less hazardous alternatives; engineer controls (guards, ventilation); administer controls (procedures, training); use PPE. Select proportionate controls (the severity of risk should match the effort invested in control).

What you must do: Document your hazard identification process. Maintain a hazard register listing all identified hazards. Conduct risk assessments with scores. For each risk, document planned controls. Review and update regularly (annually, minimum).

What auditors assess: Whether hazard identification is systematic and complete. If major hazards are missing (auditors check by reviewing incident data, injury trends, industry guidance), you fail. Whether risk assessment methodology is rational and applied consistently. Whether controls are proportionate to risk level. Whether opportunity-seeking is genuine or merely tokenistic.

Clause 6.2: Occupational Health and Safety Objectives and Planning to Achieve Them

You must establish measurable OH&S objectives aligned to policy and address significant risks/opportunities. For each objective, plan how you’ll achieve it: assign responsibility, allocate resources, set timelines, identify success measures.

Example objectives: “Reduce lost-time injuries by 25% within 12 months”; “Achieve 100% induction compliance for new workers”; “Eliminate exposure to asbestos by Q4”; “Implement incident investigation for all near-misses”.

What you must do: Establish 5–10 measurable objectives. Ensure they’re ambitious but achievable. Assign ownership. Plan actions to achieve them. Track progress. Report in management reviews.

What auditors assess: Whether objectives are genuine and measured against. If you set objectives then ignore them, auditors notice. Are objectives actually tracked? Is progress reported?

Clause 7: Support (DO)

Clause 7 addresses the resources and capabilities needed to operate your OH&S system.

Clause 7.1: Resources

You must determine and provide resources needed for the OH&S system to be established, implemented, maintained, and improved. Resources include people, infrastructure, technology, financial resources, and time.

What you must do: Budget for OH&S (staff, consultants, equipment, training, audits). Ensure you have sufficient people to manage the system. Provide infrastructure (meeting rooms, safety equipment, etc.). Allocate time for workers to participate in OH&S activities.

What auditors assess: Whether resources are genuinely allocated. If you can’t conduct hazard reviews because you lack time, or can’t investigate incidents because you lack people, you’re resource-constrained. Auditors ask: Do you have the resources to run this system effectively?

Clause 7.2: Competence

You must ensure people are competent to perform their OH&S roles. Competence includes knowledge, skills, and experience relevant to their responsibilities.

What you must do: Identify OH&S roles (OH&S manager, safety representatives, supervisors, etc.). For each role, define competence requirements (qualifications, training, experience). Assess whether current people meet requirements. Identify gaps. Provide training or hire qualified people. Document competence (records of training attended, qualifications held).

What auditors assess: Whether OH&S roles are filled by competent people. If your OH&S manager has no relevant qualification or training, or if supervisors have never received OH&S training, you’ll fail. Auditors review training records.

Clause 7.3: Awareness

You must ensure workers are aware of: the OH&S policy; relevant hazards and risks; their roles and responsibilities; the importance of complying with OH&S requirements; the procedures for incident reporting and investigation; potential consequences of non-compliance.

What you must do: Communicate OH&S policy to all workers. Conduct hazard awareness training (what hazards exist in their work area, how to control them, what to do if something goes wrong). Ensure workers understand their responsibilities. Make clear that incident reporting is valued. Emphasise that non-compliance carries consequences.

What auditors assess: Whether workers are genuinely aware. Auditors interview workers: Do you know the OH&S policy? What hazards are in your work area? Who’s responsible for what? Evidence of awareness includes training records, meeting minutes, posters, toolbox talks, and worker interviews.

Clause 7.4: Communication

You must establish processes for communicating OH&S information internally and externally. Communication should include: what’s communicated, when, to whom, how, and by whom.

What you must do: Establish communication mechanisms (team meetings, newsletters, notice boards, intranet, toolbox talks). Communicate new hazards, changes to controls, incident findings, improvement initiatives. Ensure two-way communication (leaders listen, not just broadcast). Communicate with external interested parties (contractors, customers) about relevant hazards and expectations.

What auditors assess: Whether communication is effective. Do workers know about recent hazards? Do contractors receive site-specific inductions? Do customers know your expectations of them?

Clause 7.5: Information and Documented Information

You must determine what information your system requires and how you’ll manage it (create, update, store, retrieve, control). This includes policies, procedures, records, registers, plans.

What you must do: Maintain key documents (policy, procedures, risk register, objectives, training records, incident reports, audit reports). Ensure documents are accessible, up-to-date, and controlled (so people access the current version, not outdated copies). Retain records as required by law (usually 5–7 years for incidents).

What auditors assess: Whether you maintain required documentation. If records are missing, outdated, or disorganised, you fail. Auditors check whether you can quickly access key documents during audit.

Clause 8: Operation (DO)

Clause 8 addresses how you operationalise your planned controls and OH&S activities.

Clause 8.1: Operational Planning and Control

You must plan, implement, and control processes needed to address risks and opportunities identified in Clause 6.

What you must do: For each significant hazard/risk, ensure controls are implemented. Control effectiveness should be verified (do guards work? are workers using PPE?). Changes to operations should be assessed for OH&S impact before implementation. Contractors should be managed (inductions, site rules, supervision). Procured products should be safe (machinery specifications reviewed, chemical safety data sheets obtained).

What auditors assess: Whether planned controls are actually in place and working. Do guards exist on machinery? Are workers trained in safe procedures? Are contractors inducted? For high-risk areas, auditors conduct walkthroughs to verify controls are in place and maintained.

Clause 8.2: Emergency Preparedness and Response

You must prepare for and respond to potential emergencies (fires, chemical spills, injuries, etc.). You must plan responses, test them, and continuously improve them.

What you must do: Identify potential emergencies (facility-specific). Develop emergency plans (evacuation procedures, first aid, emergency contacts). Conduct drills to test them. Maintain emergency equipment (fire extinguishers, first aid kits). Train workers on emergency procedures. Review and update plans periodically and after actual emergencies.

What auditors assess: Whether emergency plans are realistic and tested. Auditors ask: Have you conducted a fire drill? Do fire extinguishers have current tags? Do workers know evacuation assembly points? Is first aid equipment accessible?

Clause 9: Performance Evaluation (CHECK)

Clause 9 requires measuring whether your system is effective—whether you’re achieving OH&S objectives and managing risks.

Clause 9.1: Monitoring, Measurement, Analysis and Evaluation of Occupational Health and Safety Performance

You must monitor OH&S performance through: leading indicators (measurements of system effectiveness, like training completed, hazard reviews conducted, near-misses reported); lagging indicators (incidents, injuries, illnesses—what already happened); and other performance metrics aligned to your objectives.

What you must do: Define what you’ll measure (incident rate, training completion, hazard review frequency, near-miss reporting rate, audit compliance, objective progress). Establish baselines and targets. Measure regularly (monthly, typically). Analyse trends. Report results to management. Use insights to drive improvement.

What auditors assess: Whether you genuinely measure and analyse performance. If you track incidents but don’t analyse trends or use insights to improve, you fail. Do you know your incident rate? Are you trending toward objectives? Have you analysed why near-miss reporting is low or high?

Clause 9.2: Internal Audit

You must periodically audit your OH&S system against ISO 45001 requirements to verify conformity and effectiveness.

What you must do: Conduct internal audits at least annually (typically more frequently). Audits should cover all clauses. Use trained auditors (internal or external). Document findings (conformities, non-conformities, observations). Report results to management. Require corrective action for non-conformities.

What auditors assess: Whether you audit yourselves. If you haven’t conducted internal audits, you’ll fail. Auditors review your internal audit reports: Are they thorough? Do they cover all clauses? Have you actually corrected identified non-conformities?

Clause 9.3: Management Review

Leadership must periodically review the entire OH&S system to ensure ongoing suitability, adequacy, and effectiveness. Reviews should assess: changes in context/interested parties; progress toward objectives; incident trends; audit findings; improvement opportunities; resource adequacy.

What you must do: Conduct management reviews at least annually (often quarterly). Prepare a report covering performance, audit findings, incident trends, progress toward objectives. Present to leadership. Document discussion and decisions. Use findings to drive improvement (update policy, revise objectives, allocate resources).

What auditors assess: Whether leadership genuinely conducts reviews. Do minutes exist? Are findings acted upon? Is the review outcome visible in changed objectives, allocated resources, or policy updates?

Clause 10: Improvement (ACT)

Clause 10 drives continual improvement. The PDCA cycle loops back.

Clause 10.1: General

You must determine opportunities to improve and implement improvements to the OH&S system. This is ongoing—improvement is never complete.

What you must do: Establish a process for identifying improvement opportunities (from incident investigations, audit findings, worker suggestions, management reviews, industry developments). Evaluate opportunities. Prioritise based on risk or benefit. Implement improvements. Track effectiveness.

What auditors assess: Whether continuous improvement is genuine. Have you made improvements in the last 12 months? Can you demonstrate improvements? Is there evidence of a culture where improvement is valued?

Clause 10.2: Incident, Non-conformity and Corrective Action

When incidents occur or the system fails to achieve objectives, you must respond. You must investigate incidents, determine root causes, implement corrective actions, and verify their effectiveness.

What you must do: Establish an incident investigation procedure. When an incident occurs, investigate promptly. Identify the immediate cause (what directly caused the incident) and the root cause (why conditions existed that allowed the incident). Implement corrective actions addressing root causes. Verify actions prevented recurrence. Track effectiveness. Share lessons learned across the organisation.

What auditors assess: Whether investigations are thorough. If you investigate only obvious causes (worker error) without looking deeper (why was there no guard? why wasn’t the procedure followed? why wasn’t the risk identified initially?), you’ll fail. Auditors review incident reports and judge investigation quality.

Clause 10.3: Continual Improvement

Beyond corrective action, you must systematically pursue continual improvement. This is the loop back to PLAN, where you identify new opportunities, refine objectives, and improve the system further.

What you must do: Use performance data, audit findings, incident investigations, and worker input to identify improvement opportunities. Prioritise based on risk or benefit. Implement improvements. Measure effectiveness. Share results. Celebrate successes. Repeat.

What auditors assess: Whether your system spirals upward. Is performance improving? Are objectives being achieved or exceeded? Is the culture one of continuous improvement or static compliance?

Clause Summary Table

ClauseTitlePDCA PhaseFocus
1ScopeAdminDefine what ISO 45001 is
2Normative ReferencesAdminList referenced documents
3Terms and DefinitionsAdminDefine key terminology
4Context of the OrganisationPLANUnderstand internal/external context, interested parties, scope
5Leadership and CommitmentPLANLeadership accountability, policy, roles
6PlanningPLANHazard identification, risk assessment, objectives, planning
7SupportDOResources, competence, awareness, communication, documentation
8OperationDOImplement planned controls, manage contractors, emergency response
9Performance EvaluationCHECKMonitor performance, audit, management review
10ImprovementACTIdentify improvements, investigate incidents, correct actions, improve continuously

How to Use This Article in Your Audit Preparation

If you’re preparing for ISO 45001 audit, use this article as a checklist:

  1. For each clause, re-read the requirement and ask: Do we meet this?
  2. Gather evidence (documents, records, interview notes) demonstrating compliance.
  3. Where you’ve gaps, plan actions to address them.
  4. Share this article with your team. Ensure everyone understands what’s required.
  5. Use it in internal audit to standardise assessment language and criteria.

Conclusion: From Clauses to Culture

The 10 clauses can feel prescriptive on first reading. But they’re not a checklist to tick. They’re a framework for building a systematic, culture-driven approach to OH&S.

The organisations that excel at ISO 45001 internalise the clauses. They understand why context matters (Clause 4), why leadership must visibly commit (Clause 5), why planning is essential before action (Clause 6). They measure performance relentlessly (Clause 9) and pursue improvement continuously (Clause 10).

This systematic approach—embedded in the 10 clauses—is what drives the 35–50% incident reduction that certified organisations typically achieve within 18 months.

For implementation guidance, see our complete implementation guide.

Frequently Asked Questions

What are the 10 clauses of ISO 45001?

The 10 clauses are: 1) Scope, 2) Normative References, 3) Terms and Definitions, 4) Context of the Organisation, 5) Leadership and Commitment, 6) Planning, 7) Support, 8) Operation, 9) Performance Evaluation, and 10) Improvement. Clauses 1–3 are administrative; clauses 4–10 are operative and map to PDCA.

How do ISO 45001 clauses map to PDCA?

PLAN (Clauses 4–6): Understanding context, establishing leadership, and planning for hazards/opportunities. DO (Clauses 7–8): Providing support and implementing controls. CHECK (Clause 9): Monitoring performance and auditing. ACT (Clause 10): Investigating incidents and improving continuously. This cycle repeats, ensuring continuous improvement.

What does ISO 45001 Clause 6 require?

Clause 6 (Planning) requires: 6.1) Identify hazards, assess risks, identify opportunities, and plan controls; 6.2) Establish measurable OH&S objectives aligned to policy and address significant risks/opportunities. You must systematically identify what could go wrong, assess how likely and severe the consequences could be, and plan how you’ll control risks and pursue opportunities.

What is ISO 45001 Clause 4?

Clause 4 (Context of the Organisation) requires: 4.1) Understand your internal and external context (organisational factors affecting OH&S); 4.2) Identify interested parties and their needs/expectations; 4.3) Define the scope of your OH&S system; 4.4) Establish an OH&S management system. This foundational clause ensures your system is tailored to your organisation’s unique situation.

What is ISO 45001 Clause 10?

Clause 10 (Improvement) requires: 10.1) Identify and implement improvements; 10.2) Investigate incidents, identify root causes, implement corrective actions; 10.3) Pursue continual improvement. This clause drives the ACT phase of PDCA, completing the cycle and enabling the system to spiral upward over time.

What auditors look for in ISO 45001 audits?

Auditors assess: whether context analysis is genuine (not generic); whether leadership visibly commits; whether hazard identification is comprehensive and systematic; whether controls are in place and effective; whether workers are genuinely engaged and aware; whether performance is measured and analysed; whether internal audits are conducted; whether incidents are investigated and improve the system; whether the organisation is continuously improving. They interview workers and leaders, review documents, conduct facility walkthroughs, and analyse performance data.

Which clauses are most important in ISO 45001?

All clauses are normative (required for certification), but Clause 6 (Planning—hazard identification and risk assessment) and Clause 9 (Performance Evaluation—measurement and audit) are foundational. A robust Clause 6 process ensures you identify and control significant hazards. A robust Clause 9 process ensures you know whether the system works. Together, they drive most of the benefit you derive from ISO 45001.