ISO 45001 Gap Analysis: How to Assess Your Current OH&S Position
A gap analysis sits at a critical inflection point. Complete it well, and your implementation roadmap becomes clear and achievable. Rush through it, and you’ll discover mid-implementation that you’ve grossly underestimated effort or missed foundational requirements entirely.
I’ve led dozens of gap analyses across industries—manufacturing, construction, healthcare, professional services—and I can tell you confidently: the quality of your gap analysis directly predicts the quality of your certification outcome. It’s that important.
This guide shows you how to conduct a gap analysis that reveals reality, not just compliance theatre.
What is an ISO 45001 Gap Analysis and Why Is It Essential?
A gap analysis is a systematic assessment of your current OH&S position against ISO 45001 requirements. It answers three fundamental questions: Where are we now? Where do we need to be? What effort will it take to get there?
Without gap analysis, you’re implementing blindly. You might discover during your certification audit that you’ve spent six months building documentation when your real gap is in operational control embedding. Or you might assume your existing OH&S programme is “basically compliant” only to find during Phase 8 internal audit that your HIRA is incomplete or your worker participation mechanism is ineffective.
A disciplined gap analysis prevents these surprises. It also builds stakeholder buy-in: when you show the executive team a prioritised list of gaps and the effort required to address them, they understand the commitment they’re making. No one likes hidden surprises mid-project.
Three Types of ISO 45001 Gap Analysis
Effective gap analyses operate at three levels. The strongest approach uses all three.
Type 1: Clause-by-Clause Compliance Assessment
This is the most straightforward approach: evaluate your current state against each requirement in Clauses 4-10 (context, leadership, planning, support, operation, performance evaluation, improvement).
For each clause, you ask: Do we have documented information as required? Is it communicated? Is it being followed operationally? Are we collecting evidence of effectiveness?
Example—Clause 7.2 (Competence): You assess whether you’ve defined competence requirements for each role, whether training is documented, whether competence is verified before workers perform high-risk tasks, and whether competence is maintained through refresher training. If any of these is missing or weak, you identify the specific gap and effort to close it.
Strength: Comprehensive, ensures nothing is missed. Weakness: Can feel like a checklist exercise; doesn’t assess how well practices work in reality.
Type 2: Process-Based Assessment
Rather than clause-by-clause, you assess key processes that span multiple clauses: hazard management (Clauses 6.1, 6.2, 8.1), incident management (Clauses 8.2.3, 10.2), competence management (Clause 7.2), and change management (Clause 8.1.3).
For each process, you evaluate maturity: Do we have a defined process? Is it documented? Are roles clear? Is it being followed consistently? Are we measuring effectiveness? Are we improving it?
This reveals whether you have siloed compliance (“we have a HIRA checklist”) or integrated management (“hazard identification feeds into objectives feeds into operational controls feeds into management review”).
Strength: Reveals operational maturity and integration. Highlights whether systems are truly connected. Weakness: Requires more analytical effort; less straightforward checklist approach.
Type 3: Risk-Based Assessment
This asks the hardest question: Given your identified hazards and risks, are your current controls actually managing them effectively? This is different from asking whether you’ve done a HIRA—it’s asking whether the HIRA findings have translated into real operational control.
For example: You’ve identified psychosocial hazards (workload, role ambiguity) in your HIRA, but have you implemented specific controls? Are managers trained in early intervention? Do you have a mental health support programme? Is psychological safety measured in worker surveys?
Risk-based assessment reveals when compliance and risk management diverge. You might be compliant on paper (you have a HIRA) but not risk-effective operationally (hazards persist because controls are weak).
Strength: Aligns implementation to actual risk. Prevents compliance-only thinking. Weakness: Requires deep understanding of your operations and hazards.
The 5-Level OH&S Maturity Model
To structure your gap analysis meaningfully, apply a maturity framework. Here’s the 5-level model I use with clients:
Level 1 (Ad Hoc): No formal processes. OH&S is reactive—you respond to incidents. Documentation is sporadic. Responsibility is unclear.
Level 2 (Basic): Some processes are documented. Compliance with legal requirements is attempted but incomplete. Reactive focus dominates. Management awareness is limited.
Level 3 (Structured): Processes are defined and mostly followed. Compliance is substantial. Some proactive elements (HIRA, training) are in place. Management is engaged but not deeply accountable.
Level 4 (Integrated): Processes are embedded operationally. Compliance is achieved. HIRA informs objectives. Worker participation is genuine. OH&S is integrated into business decision-making. Data drives improvement.
Level 5 (Excellence): Continuous improvement culture. Predictive hazard management. Worker engagement in safety innovation. Industry-leading metrics. OH&S is a strategic business enabler.
ISO 45001 certification requires Level 3+ (some organisations might argue Level 4 is the true bar). Your gap analysis should rate current maturity and target maturity across key processes.
Structuring Your Gap Analysis: Step-by-Step
Step 1: Define Scope and Assemble Your Team
Decide upfront: Which legal entities, locations, and processes will you assess? Will scope align with your intended certification scope, or will you assess broader than you certify?
Many organisations assess their entire operation but certify a subset initially (e.g., certify head office and manufacturing, exclude field operations). This is valid; just be explicit.
Assemble a cross-functional team: OH&S manager (process owner), operations manager (understands practical reality), HR (knows competence and culture), legal/compliance (understands regulatory obligations), IT (if document management is relevant), and ideally a frontline worker who can reality-check assumptions.
External perspective helps—a consultant or auditor who understands ISO 45001 across industries can benchmark against what “good” looks like and challenge internal assumptions.
Step 2: Establish Clear RAG Scoring Criteria
Define your rating scale explicitly before you start scoring. Ambiguity here creates inconsistency and disputes later.
Green (Compliant): Requirement is fully met. Evidence exists. Process is being followed operationally.
Amber (Partially In Place): Requirement is partially met. Some evidence exists. Process is followed inconsistently or incompletely. Clear remediation path exists.
Red (Non-Compliant): Requirement is not met. No evidence, or fundamentally misaligned approach. Significant remediation required.
NA (Not Applicable): Requirement doesn’t apply to your scope or operations. Document the rationale (e.g., “No outsourced processes, so Clause 8.1.4 NA”).
Train your assessment team on these definitions using examples relevant to your industry. Consistency matters—a scattered set of RAG ratings is useless.
Step 3: Clause-by-Clause Assessment (Clauses 4-10)
Work through each clause systematically. For each requirement, assess current state and document evidence sources.
Clause 4: Context
4.1 Understanding the organisation: Do you have a documented context analysis? Internal and external issues? Scope boundaries clearly stated?
4.3 Determining scope: Is scope documented? Does it align with your business? Are any process exclusions justified?
Clause 5: Leadership and Commitment
5.1 Leadership and commitment: Is top management accountability clear? Do they allocate resources? Do they participate in management review?
5.2 OH&S policy: Is a policy document in place? Is it signed by top management? Does it reflect your context? Is it communicated and understood?
5.3 Organisational roles, responsibilities, authorities: Is a responsibility matrix documented? Do people know their OH&S roles? Are accountabilities clear?
5.4 Consultation and participation: Do workers have voice in OH&S decisions? Is there a formal mechanism (committee, survey, toolbox talks)? Do workers feel heard?
Clause 6: Planning
6.1 Actions to address risks and opportunities: Is a HIRA completed? Does it include all hazard categories? Is worker input documented? Are controls defined and prioritised?
6.2 Objectives and targets: Are OH&S objectives set? Are they SMART? Do they cascade from HIRA? Are resources allocated?
Clause 7: Support
7.1 Resources: Are adequate resources (people, budget, equipment) available? Can OH&S priorities compete with business priorities?
7.2 Competence: Are competence requirements defined per role? Is training documented? Are skills verified before high-risk work?
7.3 Awareness: Do workers understand the OH&S policy? Do they know their roles? Do new starters get inducted on OH&S?
7.4 Communication: Are OH&S issues communicated? Do workers know where to report hazards/incidents? Is feedback provided?
7.5 Documented information: Is your documentation complete and accessible? Is document control applied? Are records retained per retention schedule?
Clause 8: Operation
8.1 Operational planning and control: Are operational controls defined for identified hazards? Are contractors managed? Is procurement controlled for safety?
8.1.3 Management of change: Is there a change control process? Are OH&S implications assessed before changes?
8.2 Emergency preparedness and response: Are emergency procedures documented? Are workers trained? Are drills conducted?
Clause 9: Performance Evaluation
9.1 Monitoring and measurement: Are OH&S metrics defined? Are they tracked? Are trends analysed?
9.2 Internal audit: Is an internal audit programme in place? Are audits planned and scheduled? Are findings addressed?
9.3 Management review: Are management reviews conducted? Is data reviewed? Are decisions documented?
Clause 10: Improvement
10.1 Non-conformity and corrective action: Is there a process for non-conformities? Are root causes identified? Are corrections effective?
10.2 Incident investigation: Are incidents investigated? Are root causes identified? Are preventive actions implemented?
10.3 Continual improvement: Is continuous improvement embedded? Are objectives updated based on performance data?
Step 4: Score Implementation Effort for Each Gap
Beyond RAG status, estimate the effort required to address each gap. Rate effort on a scale: Low (1-40 hours), Medium (41-160 hours), High (161+ hours).
This is crucial for prioritisation. A Red gap that requires 5 days of effort to close is very different from a Red gap that requires 3 months of process redesign.
Consider: Do we have an existing process we can enhance, or do we need to build from scratch? What training and change management is required? How complex is the change?
Step 5: Document Current State Evidence and Remediation Approach
For each gap, document what evidence currently exists: “We have a HIRA spreadsheet from 2022, but it hasn’t been updated since production line 3 was installed.” Be specific and honest.
Then outline the remediation approach: “Update HIRA to include new hazards from production line 3. Re-facilitate with floor workers. Update risk register and operational controls.”
Sample Gap Analysis Output: Assessment Matrix
Your final deliverable should be an assessment matrix like this:
| Clause | Requirement | Current State | RAG | Effort | Remediation Approach |
|---|---|---|---|---|---|
| 6.1.2 | HIRA including psychosocial hazards | HIRA spreadsheet exists. Covers physical/chemical hazards. Psychosocial not addressed. | AMBER | Medium (80 hrs) | Add psychosocial hazard category. Facilitated workshop with managers and workers. Update risk register. |
| 5.4 | Worker consultation and participation | Ad-hoc communication. No formal mechanism. Workers feel information is top-down. | RED | High (200 hrs) | Establish OH&S committee with worker reps. Define participation protocol. Train managers on consultation. Establish hazard reporting system with feedback loop. |
| 7.5.2 | Document control | Procedures on network drive. Version control inconsistent. Approval workflow unclear. | AMBER | Low (30 hrs) | Implement document control procedure. Establish approval authority. Move to ISO management platform with version control and audit trail. |
Creating Your Implementation Priority Matrix
Plot your gaps on a 2×2 matrix: X-axis is implementation effort (Low to High), Y-axis is gap severity (Red vs. Amber).
This reveals your implementation sequencing:
Quadrant 1 (High Severity, Low Effort): Do these first. Quick wins that build momentum. Example: Strengthen document control (administrative change, high impact on audit readiness).
Quadrant 2 (High Severity, High Effort): Tackle second. These are fundamental. Example: Redesign worker participation mechanisms (significant change, foundational to system).
Quadrant 3 (Low Severity, Low Effort): Background work. Example: Refine emergency procedure documentation.
Quadrant 4 (Low Severity, High Effort): Question whether to pursue. Example: Implementing advanced risk assessment software when a spreadsheet-based HIRA is adequate. These don’t usually justify the effort.
DIY vs. External Consultant: When to Engage Support
Do Gap Analysis Internally If:
You have someone with ISO 45001 knowledge or prior audit experience. Your operation is straightforward (single location, simple processes). You want to build internal capability. You have 6-8 weeks available.
Engage an External Consultant If:
No one internally has ISO 45001 expertise. Your operation is complex (multiple sites, diverse processes). You want objectivity and benchmarking against best practice. You need a compressed timeline. You want someone to challenge internal assumptions.
External consultants typically complete a thorough gap analysis in 2-3 weeks, vs. 6-8 weeks internally. Cost is usually €3,000-€8,000 for a comprehensive assessment. The return is high: an external consultant often identifies gaps internal teams miss because they’re too close to operations.
From Gap Analysis to Implementation Roadmap
Your gap analysis is only valuable if it informs action. Here’s how to convert findings into a roadmap:
1. Prioritise gaps using your priority matrix (severity × effort).
2. Sequence phases based on dependencies. Clause 4 (context) should be clarified early. Clause 6.1 (HIRA) must be complete before Clause 8 (operational controls). Clause 5.4 (participation) should be embedded from Phase 1.
3. Estimate timeline by summing effort hours across Quadrants 1-2 and dividing by available team capacity. A 500-hour remediation plan with one full-time resource = ~3 months.
4. Allocate resources and assign ownership for each remediation action.
5. Define success criteria for each gap closure: What evidence will prove remediation is complete?
Frequently Asked Questions
What is an ISO 45001 gap analysis and why is it essential?
A gap analysis assesses your current OH&S position against ISO 45001 requirements, identifying what you have, what’s missing, and the effort required to achieve compliance. It’s essential because it prevents surprises during certification audit and informs your implementation roadmap.
What are the three types of ISO 45001 gap analysis?
Clause-by-clause (checklist against each requirement), process-based (assessment against operational processes like procurement and incident management), and risk-based (evaluation of whether your current controls actually address your identified hazards).
How do we score gaps effectively?
Use a four-level RAG system: Green (compliant or near-compliant), Amber (partially in place, needs enhancement), Red (absent or fundamentally misaligned), and Not Applicable. Include implementation effort scoring (effort hours) so you can prioritise.
Can we do gap analysis internally or should we hire a consultant?
Internal teams familiar with ISO 45001 can conduct gap analysis, but external consultants bring objectivity and efficiency. They typically complete analysis in 2-3 weeks versus 6-8 weeks internally, though internal analysis builds capability.
What should we do with gap analysis results?
Convert gap analysis into an implementation priority matrix: plot gaps by severity (Red/Amber) versus implementation effort (low/high). Address high-severity, low-effort gaps first for quick wins, then tackle high-severity, high-effort gaps systematically.
How often should we update our gap analysis?
Conduct initial gap analysis before implementation begins. Update it if major process changes occur during implementation, and schedule a pre-audit gap review 8 weeks before certification audit to ensure readiness.
What’s the difference between gap analysis and internal audit?
Gap analysis assesses current state before implementation and informs your roadmap. Internal audit (Phase 8) assesses implementation effectiveness after procedures are live. Both are important; they serve different purposes at different stages.
Conclusion: Making Gap Analysis Actionable
Your gap analysis is only as valuable as the decisions it informs. A thorough gap analysis identifies what needs to change, the effort required, and the sequence that makes sense. From there, your implementation roadmap becomes clear and achievable.
The strongest gap analyses involve cross-functional teams, external perspective, and honest assessment of current state rather than aspirational state. They also convert findings into actionable priorities, not just a list of problems.
If you’re preparing for a gap analysis or want external validation of your findings, contact Anitech Group. We conduct comprehensive gap analyses that reveal both compliance gaps and operational maturity opportunities, helping you build a realistic, sequenced implementation roadmap.
Recent Comments