ISO 45001 Maintenance and Continual Improvement: The Complete Operations Guide
You’ve designed an ISO 45001 system. You’ve documented your processes, trained your people, and secured management commitment. Now what?
This is where most organisations stumble. They treat ISO 45001 as a certification project with a finish line. In reality, Clauses 9 and 10 form the engine of your entire system — the mechanism that separates genuine safety leadership from compliant mediocrity.
Clauses 9 (Performance Evaluation) and 10 (Improvement) are not separate add-ons. They form a closed-loop cycle that feeds on itself. Your monitoring reveals gaps. Your audits uncover weaknesses. Your incidents trigger investigations that expose systemic failures. Management review synthesises all this intelligence. Corrective action tackles root causes. And continual improvement drives everything forward.
Without these clauses functioning together, your OH&S system slowly calcifies. Hazards multiply in the cracks. Your certification auditor sees a system on life support.
This pillar post synthesises everything you need to know about Clauses 9 and 10 — not as separate compliance boxes, but as an integrated operational practice that transforms safety from a compliance burden into a business advantage.
Understanding Clause 9: Performance Evaluation
Clause 9 is about knowing what’s happening. It answers a deceptively simple question: Is your OH&S system actually working?
The answer comes from four sources: monitoring and measurement (Clause 9.1), internal audit (Clause 9.2), management review (Clause 9.3), and the underlying data about your legal compliance. Each operates at a different level, with different lenses.
Clause 9.1: Monitoring, Measurement, Analysis and Performance Evaluation
This is your real-time feedback loop. You are monitoring three things simultaneously:
- Extent to which OH&S objectives are being achieved. Are your targets being met? Is your LTIFR trending in the right direction? Are specific department targets on track? This answers: What was supposed to happen?
- Effectiveness of operational controls. Are your engineered hazard controls actually working? Are your PPE programs reducing exposure? Are your inspection schedules being followed? This answers: Are we doing what we said we’d do?
- Progress with legal compliance evaluation. How many regulations have you assessed against? How many are compliant? Where are the gaps? This answers: Are we breaking any laws?
Most organisations fixate on lagging indicators — your LTIFR, TRIFR, total accident count. These are essential, but they arrive too late. An accident has already happened.
Leading indicators are where the leverage is. Safety observations, near-miss reporting rates, inspection compliance, hazard close-out cycle times — these predict future performance. A sharp drop in near-miss reports is a red flag. An increase in high-risk findings suggests your hazard identification process is losing effectiveness.
Clause 9.1.2 adds a specific requirement: you must evaluate compliance with applicable legal and regulatory requirements. This isn’t passive — you need documented procedures that systematically compare your operations against your legal obligations. How often? The standard doesn’t mandate frequency, but risk-based assessment suggests at least annually, with more frequent checks for high-risk operations or during significant changes.
The practical challenge: most organisations monitor everything and analyse nothing. You pile data into spreadsheets, generate charts, then file them away. Real analysis asks: What does this trend mean? What caused this spike? Is this performance sustainable? What should we do about it?
Clause 9.2: Internal Audit
Monitoring tells you what happened. Audit asks: Why didn’t we catch that?
Internal audit is your honest broker — the mechanism for critically examining whether your system works as designed. An effective audit program doesn’t just verify compliance with procedures. It asks uncomfortable questions about whether your procedures actually prevent harm.
ISO 45001 requires internal audits at planned intervals. The frequency should be risk-based, not calendar-based. A high-hazard operation might audit quarterly. A low-risk office might audit annually. But the critical requirement is that your audit program covers all elements of your system.
The audit should assess:
- Conformity with ISO 45001 requirements (all clauses)
- Effective implementation of your OH&S system
- Whether your system is achieving its intended outcomes
Auditors must be competent and, critically, independent from the function they audit. An audit conducted by the person responsible for the process is theatre, not audit. Your internal auditors should have direct access to top management, bypass the normal chain of command when raising serious findings, and have protection from retaliation.
The findings should be honest. If your audit reports nothing but minor observations, you either have a perfect system (unlikely) or a broken audit process (more likely).
Clause 9.3: Management Review
This is where the board looks the CEO in the eye and asks: What’s the real state of OH&S in this business?
Management review is not a compliance meeting. It’s a strategic decision-making forum. It brings together the critical inputs from your entire system — monitoring data, audit findings, incident statistics, worker feedback, legal changes — and converts them into decisions and actions.
The inputs required by Clause 9.3.2 are explicit:
- Status of previous management review actions (Have we done what we said we’d do?)
- Changes in external and internal context
- Information on OH&S performance, including trends in incidents, nonconformities, audit results
- Adequacy of resources and competence
- Relevant interested party feedback (worker consultation)
- Opportunities for continual improvement
The outputs required by Clause 9.3.3 are equally specific:
- Decisions and actions related to continual improvement
- Decisions and actions to address changes in the OH&S policy, objectives, or other elements of the system
- Resource needs
- Changes to the system itself
Management review must be documented. Minutes should record what was discussed, what decisions were made, who owns actions, and the target dates. Vague commitments are worthless. “We’ll focus more on safety” is not an action. “Safety Manager to implement revised pre-start checklist by 30 June, with audit verification by 31 July” is an action.
Understanding Clause 10: Improvement
Clause 10 answers the question: What do we do with what we’ve learned?
Improvement has three components: nonconformity and corrective action (Clause 10.2), continual improvement (Clause 10.3), and the foundational principle of proactive rather than reactive change.
Clause 10.2: Nonconformity and Corrective Action
A nonconformity is a failure to meet a requirement — either a requirement of ISO 45001 itself or a requirement in your own system.
But not all failures are equal. Some are minor (an inspection due date missed by a week). Others are critical (a hazard control bypassed, resulting in an incident). Your corrective action process must distinguish between levels of severity and respond proportionately.
The process has a rhythm: React and contain the immediate issue. Review what went wrong. Determine the root cause. Evaluate whether similar nonconformities exist elsewhere. Implement corrective action to prevent recurrence. Verify the action was effective.
Root cause analysis is where most organisations fail. The proximate cause (“The worker didn’t follow procedure”) is obvious but useless. The root cause might be: the procedure is incompatible with work conditions, the worker wasn’t trained, supervision is absent, or the hazard is inherent in the process. Until you understand the root cause, your corrective action is theatre.
Tools like the 5 Whys (ask “why” repeatedly until you reach the systemic cause), fishbone diagrams (map all contributing factors), and fault tree analysis (work backward from the failure to underlying causes) force structured thinking.
Your corrective action should always ask: Could this happen elsewhere? If a hazard control failed in Department A, does it work differently in Department B? If a procedure was misunderstood in one team, others probably misunderstand it too.
The corrective action should be verified as effective — not just implemented, but proven to work. This means collecting evidence after a reasonable period (usually 2-4 weeks) that the control is functioning as intended.
Clause 10.3: Continual Improvement
Continual improvement is the spiritual heart of ISO 45001. It’s the commitment that today’s system is never good enough.
Continual improvement isn’t a special program. It’s embedded in your normal operations. It comes from your monitoring data (we see this trend), your audits (we found this gap), your incident investigations (this exposed a systemic weakness), your management reviews (this isn’t sustainable), and your workforce (your people see opportunities we miss).
The PDCA cycle (Plan, Do, Check, Act) is the engine. You identify what could be better (sources: audit findings, incident data, worker consultation, benchmarking, regulatory changes). You plan how to improve it. You implement the change. You check whether it worked. And you act on what you learned — either consolidating the improvement or cycling back to try something different.
The distinction between leading and lagging improvement strategies matters. Lagging strategies react to what already happened — you improve because you had an incident. Leading strategies anticipate future harm — you improve because you see a pattern emerging or because other organisations have already learned from that mistake.
The Closed-Loop Cycle: How It All Connects
Here’s where the system becomes elegant. Your monitoring detects that near-miss reports have dropped. Management asks why. Audit discovers that your near-miss form is too complex, so workers don’t bother. Investigation reveals that one team eliminated near-miss reporting entirely after a worker was disciplined for reporting one. Management review decides that psychological safety is broken in that area and prioritises cultural change. You implement training, adjust how incidents are reviewed, and rebuild trust. Three months later, near-miss reports are up 40%, you’re catching hazards before they become incidents, and your LTIFR trend is improving.
That’s the system working. Monitoring triggers audit, which informs management review, which drives corrective action and improvement, which changes your monitoring picture. It’s not linear. It’s cyclical and continuous.
The alternative is fragmentation. Monitoring operates independently (you generate reports nobody reads). Audit complains but has no influence (findings are filed away). Management review happens once a year and makes no decisions (a box-ticking exercise). Incidents are investigated in isolation (root cause analysis is weak). Corrective actions are implemented inconsistently (nobody owns follow-up). And your organisation never learns.
You can tell which pattern your organisation follows by asking: When was the last time an audit finding directly shaped a management decision? When was the last time an incident investigation exposed a systemic weakness that triggered system-wide change? When was the last time a worker suggestion became an improvement?
Making Clauses 9 and 10 Real
So how do you move from theory to practice?
Build Clear Accountability
Someone must own monitoring (usually Safety Manager). Someone must own audits (often an external contractor for credibility). Someone must facilitate management review (sometimes Safety Manager, sometimes a board member to ensure independence). Someone must track corrective actions (Safety Manager with executive visibility). When accountability is clear, things get done. When it’s vague, nothing gets done.
Create Documented Procedures That Match Reality
Your procedures should describe how you actually respond to findings, not how you wish you responded. If your audit typically takes 3 days, don’t document 2 days and then always overrun. If management review realistically happens quarterly, don’t document annual and then struggle to make it happen. Procedures that match reality get followed. Procedures that are aspirational get ignored.
Use Metrics That Matter
Not every metric you collect is important. Select a smaller set — maybe 5-8 KPIs for small organisations, 10-15 for large ones — that actually indicate OH&S performance. Avoid vanity metrics (days without incident can incentivise under-reporting). Focus on meaningful leading and lagging indicators. A sales dashboard isn’t stuffed with 50 metrics; neither should your safety dashboard be.
Make Data Accessible
If your performance data lives in a spreadsheet that only one person understands, it’s not driving decision-making. Create a simple dashboard that Safety Manager updates monthly and that’s visible to all managers. Transparency drives accountability. What gets measured gets managed.
Enforce Follow-Up on Actions
A corrective action that isn’t followed up is just a documented failure. After you implement an action, schedule a verification check. Get evidence. Ask: Is it actually working? Do we see the expected improvement in related metrics?
Connect to Continual Improvement
Look for patterns, not just incidents. If three near-misses involve workers ignoring warning signs, that’s a training gap. If audits consistently find outdated procedures, your document control process is broken. Treat these patterns as improvement opportunities, not just findings to resolve.
One practical approach: at each management review, explicitly ask: “What continual improvement will we pursue this quarter?” Pick one area — maybe incident investigation effectiveness, or leading indicator development, or contractor safety. Assign ownership. Track progress. By year-end, you’ll have made 4 meaningful improvements rather than reacting to whatever crises emerged.
What Auditors Look For
Certification auditors examine Clauses 9 and 10 with particular rigour. Here’s what they’re evaluating:
Monitoring: Do you actually collect data? Is it recent? Is it analysed? Do trends trigger any action? Auditors will compare this quarter’s data to last quarter’s and ask what changed and why.
Audit: Do your auditors ask real questions or just tick boxes? Are findings specific and evidence-based or generic and vague? Are nonconformities separated from observations? Has management actually responded to audit findings in previous cycles?
Management Review: Do minutes exist and are they specific? Are attendees senior enough to make decisions? Are previous actions actually completed? Do decisions get communicated downward?
Corrective Action: Is root cause analysis credible or superficial? Is the corrective action proportionate to the severity? Has effectiveness been verified or just assumed? Can auditors see evidence that similar issues were investigated elsewhere?
Continual Improvement: Beyond responding to failures, do you proactively improve? Can you point to improvements made in the past two years that came from worker suggestions, benchmarking, or leading indicator analysis?
Organisations that fail audits typically stumble in one of two ways: either they have processes but don’t follow them (audit reports findings that are never resolved; management review happens annually but makes no decisions), or they have no processes and operate ad hoc (incident handling varies, some areas are monitored and others aren’t, there’s no consistency).
Linking to the Broader System
Clauses 9 and 10 don’t operate in isolation. They depend on:
- Clauses 5-8 (Planning and Operation): If your hazard identification, operational controls, and change management are weak, then your monitoring won’t surface real performance, and your corrections will miss the point.
- Clause 4.3 (Stakeholder Engagement and Worker Consultation): Workers are your best source of early warning. If they don’t trust the system to act on their feedback without retaliation, you’ll never hear about real problems.
- Clause 5.5 (Leadership and Accountability): If top management treats OH&S as a delegated responsibility rather than a strategic priority, then management review becomes a formality and improvements stall.
An effective Clause 9 and 10 implementation pulls the entire system upward. It forces you to clarify priorities, allocate resources, and measure what matters.
The Business Case for Investment
Why does this matter beyond the certification audit?
Organisations that excel at Clauses 9 and 10 make better decisions faster. They don’t wait for catastrophes; they spot emerging risks. They don’t repeat mistakes; they investigate thoroughly and spread learnings. They don’t burn out their workforce; they proactively improve conditions. And yes, their incident rates are lower and their insurance premiums reflect it.
The cost of implementation is modest — time from your Safety Manager, training for auditors, templates for documentation. The cost of neglecting it is much higher: repeated incidents, failed audits, reputational damage, and constant fire-fighting.
Common Failures and How to Avoid Them
Failure 1: Monitoring Without Analysis
You generate dashboards but ask no questions. “Our LTIFR is 8.2 this quarter.” So what? Is that good or bad? Compared to what? Why did it move? Fix: Build analysis into your monitoring process. Require explanation when metrics move. Investigate outliers.
Failure 2: Audit as Inspection
Your auditors check whether procedures are being followed but don’t ask whether the procedures are effective or sufficient. Fix: Train auditors in systems thinking. Require them to ask: “This procedure works when conditions are ideal, but does it work when operations are under pressure?”
Failure 3: Management Review as Briefing
The Safety Manager presents data to disinterested executives. No discussion, no decisions, no challenge. Fix: Make management review a genuine board conversation. Have an agenda circulated in advance. Invite challenge. Demand accountability on previous actions.
Failure 4: Corrective Action Stops at Proximate Cause
A worker was injured because they didn’t follow procedure. You discipline them and move on. You never ask why the procedure was being ignored. Fix: Mandate root cause analysis for all significant incidents. Require multiple contributing factors to be identified.
Failure 5: Improvement Only Happens When Forced
You improve systems only when audits force you or after incidents. You never proactively ask: “What could we do better?” Fix: Build continual improvement into your strategy. Pick a quarterly improvement focus. Allocate resources. Track progress.
Conclusion: From Compliance to Excellence
Clauses 9 and 10 are where ISO 45001 transforms from a compliance checkbox into a genuine operational system. They create the feedback loops, the learning mechanisms, and the discipline that turn an OH&S system into an engine for continuous performance improvement.
An organisation that executes Clauses 9 and 10 well doesn’t just pass audits. It prevents incidents, engages its workforce, makes smarter decisions, and builds a competitive advantage through superior safety performance.
The articles that follow dive deep into each component: management review, corrective action, continual improvement, incident investigation, performance monitoring, and change management.
But start here: audit your Clauses 9 and 10 implementation honestly. Is your monitoring actually driving decisions? Are your audits finding real problems? Does management review produce concrete actions? Are your corrective actions preventing recurrence? Are you improving proactively or just reacting?
If the answer to any of these is “not really,” then investment here will yield immediate returns.
Ready to strengthen your ISO 45001 system? Our consulting team can audit your current Clause 9 and 10 implementation, identify gaps, and help you build systems that genuinely prevent harm and drive continuous improvement. Get in touch for a confidential consultation.
FAQ: Clauses 9 and 10 in Practice
Recent Comments