Request a Demo

Fill in the form below and we will contact you shortly to organised your personalised demonstration of the Noggin platform.

The Noggin Platform

The world's leading integrated resilience workspace for risk and business continuity management, operational resilience, incident & crisis management, and security & safety operations.

Learn More
Resilience Management Buyers Guide - Thumbnail
A Resilience Management Software Buyer's Guide
Access the Guide

Who We Are

The world’s leading platform for integrated safety & security management.

Learn More
Whitepaper

Guide to Understanding ISO 45001

Noggin

Safety Management Software

Updated August 10, 2026

The state of occupational health and safety today

ISO 45001 is the international standard organizations use to build a certifiable occupational health and safety (OHS) management system. And it's about to change. With nearly 3 million workers dying from work-related accidents and diseases every year, the stakes behind getting OHS management right have never been higher.

ISO 45001 is now mid-revision, following the same update already rolled out for ISO 14001 and coming soon for ISO 9001, with the new version expected in 2027. Here's what the standard covers today, how it compares to the OHSAS 18001 standard it replaced and (most importantly) what's changing as the revision takes shape.

Workplace safety remains one of the most persistent (and undercounted) global health crises. According to the International Labour Organization's most recent estimates, nearly 3 million workers die every year from work-related accidents and diseases, an increase of more than five percent compared to 2015.

Of that total, roughly 2.6 million deaths stem from work-related diseases like circulatory conditions, cancer and respiratory illness, while work accidents account for an additional 330,000 deaths. On top of the fatalities, the ILO estimates 395 million workers sustain non-fatal injuries serious enough to require time off work each year.

The hazard isn't evenly distributed, either. Agriculture, construction, forestry, fishing and manufacturing account for roughly 63% of all fatal occupational injuries worldwide. Men die from work-related causes at nearly three times the rate of women (51.4 vs. 17.2 per 100,000 working-age adults).

The economic toll compounds the human one. Lost productivity, workers' compensation, regulatory penalties and reputational damage from serious incidents all fall on individual organizations. That’s exactly the gap ISO 45001 was built to close.

What is ISO 45001?

Published by the International Organization for Standardization in March 2018, ISO 45001 is the world's first international standard dedicated exclusively to occupational health and safety (OHS) management. It gives organizations of any size, sector or location a common, certifiable framework for managing OHS risk, replacing a patchwork of national standards, the most widely adopted of which was the British standard OHSAS 18001.

Today, more than 300,000 sites worldwide are certified to ISO 45001, making it one of the most widely adopted management system standards globally, alongside ISO 9001 (quality) and ISO 14001 (environmental management).

Key business benefits of ISO 45001

What’s behind the standard’s popularity? Key benefits include:

  • Establishes a structured, auditable OHS management system
  • Requires active senior leadership involvement, not just frontline compliance
  • Takes a proactive, risk-based approach rather than a reactive one
  • Aligns OHS risk management with other business processes and ISO standards (9001, 14001, 22000)
  • Improves regulatory compliance and reduces legal exposure
  • Strengthens a company's reputation as a safe employer, which supports morale, retention and lower insurance costs
  • Reduces costly disruptions from incidents, absenteeism and downtime

How ISO 45001 differs from OHSAS 18001

What about OHSAS 18001? Organizations already familiar with the national standard have a head start to ISO 45001 certification. However, the two standards differ in some important ways:

Area

OHSAS 18001

ISO 45001

Structure

Standalone, procedure-based

Follows ISO's Harmonized Structure, integrates easily with ISO 9001, 14001, 22000

Leadership

Delegated to OHS/EHS staff

Requires direct senior management ownership

Risk approach

Reactive hazard identification

Proactive, strategic risk and opportunity management

Scope

Focused on internal hazards

Extends to organizational context, e.g., suppliers, contractors, clients, regulators

Documentation

Documented procedures and records

"Documented information," i.e., more flexible, digital-friendly

Emergency management

Focused on evacuation drills and logging

Requires active OHS involvement across the full emergency lifecycle, including mitigation, preparedness, response, recovery

Emergency management under ISO 45001

ISO 45001 asks considerably more of organizations when it comes to emergency preparedness. Rather than treating emergency planning as a box-ticking exercise, the standard requires organizations to:

  • Identify and plan for potential emergency situations
  • Prepare and periodically test emergency response capabilities
  • Evaluate and revise preparedness measures, especially after real incidents
  • Train personnel on emergency prevention, preparedness and response duties
  • Communicate with contractors, visitors, emergency services, regulators and the local community as part of the response plan

The PDCA cycle

Like its predecessor, ISO 45001 is structured around the Plan–Do–Check–Act cycle:

  • Plan: establish OHS objectives and the processes needed to deliver them
  • Do: Implement those processes
  • Check: Monitor and measure performance against your OHS policy and regulatory requirements
  • Act: Close gaps and drive continual improvement

What's changing: the ISO 45001 revision, explained

Here's what most guides to ISO 45001 miss: the standard itself is currently being revised. So, what’s changing, exactly?

ISO 45001, ISO 9001 and ISO 14001 are all going through updates as part of a coordinated effort to bring the "Annex SL" family of management system standards closer together under ISO's Harmonized Structure.

ISO 14001's revised version has already been published, and certified organizations have been given until early 2029 to transition.

ISO 9001's revision is expected to be published in late 2026.

That makes ISO 45001 the last of the three to update. The Draft International Standard has been released for review, and the final revised standard is currently expected to publish in 2027, with a transition period (typically around three years) to follow.

While the final text isn't locked yet, proposed and expected changes include:

  • Closer alignment with ISO 9001 and ISO 14001 through the shared Harmonized Structure, making integrated management systems easier to run and audit
  • Explicit attention to mental health and psychosocial risk, extending OHS obligations beyond physical hazards
  • Recognition of remote work and digitization as factors affecting worker safety and wellbeing
  • Stronger emergency preparedness requirements, with closer ties to ISO 22301 (business continuity)
  • Closer alignment with ESG principles, connecting OHS performance to broader sustainability and governance reporting
  • A shift from harm prevention toward opportunity, encouraging organizations to treat OHS as a source of continuous improvement rather than pure risk mitigation

What this means for your organization

If you're already certified to ISO 45001:2018, nothing changes immediately. However, this is the moment to start paying attention.

That’s because the organizations that got ahead of the ISO 14001 revision by tracking the Draft International Standard, briefing leadership early and treating the update as a strategic planning item (rather than a last-minute compliance scramble) had a far smoother transition.

The same playbook applies here. So, we’d recommend monitoring the DIS as it develops, and start thinking now about how psychosocial risk, remote-work safety and ESG reporting fit into your existing OHS management system, since these are likely to become formal requirements rather than optional additions.

Getting started with ISO 45001

Whether you're pursuing initial certification or preparing for the upcoming revision, the starting point is fundamentally the same. You’ll need a thorough OHS risk assessment, not just of internal hazards, but of the wider organizational context, including contractors, suppliers and other interested parties.

From there, you'll need to assess whether your existing tools can support the standard's requirements, specifically integrated emergency management, documented information and senior leadership visibility into OHS performance. This is where a lot of organizations discover the gap: spreadsheets and disconnected systems make it difficult to demonstrate the kind of proactive, auditable risk management ISO 45001 calls for.

This is also squarely where senior leadership needs to be engaged directly, not briefed after the fact. ISO 45001 puts accountability for OHS outcomes at the top of the org chart. This means leaders are also the ones who carry the reputational and legal consequences when a system doesn't hold up during an audit or, worse, an actual incident.

Common questions about ISO 45001

Who needs ISO 45001 certification?

Any organization can pursue ISO 45001 certification, regardless of size or industry. It's most common in higher-risk sectors like construction, manufacturing, energy and logistics, but adoption is growing across healthcare, education, government and professional services as well.

Is ISO 45001 replacing OHSAS 18001?

It already has. ISO 45001 formally replaced OHSAS 18001, and the migration period for existing OHSAS-certified organizations closed back in March 2021. Any organization still operating under OHSAS 18001 today is working from a retired standard.

When is the next version of ISO 45001 coming out?

A revised version is currently in development, following the same Harmonized Structure update already applied to ISO 9001 and ISO 14001. The Draft International Standard has been published, and the final revision is expected in 2027.

How long does ISO 45001 certification take?

Timelines vary by organization size and existing maturity, but most organizations move through gap analysis, implementation and a two-stage external audit over the course of several months to a year.

Conclusion

ISO 45001 has already reshaped how organizations think about workplace safety by moving OHS from a reactive, compliance-driven function to a proactive, leadership-owned discipline. But the standard isn't static. With a revision underway and expected by 2027, now is the time to build an OHS management system flexible enough to absorb what's coming, whether that’s tighter integration with your other management systems, more attention to psychosocial risk or closer ties to your organization's broader ESG commitments.

Getting there requires the right foundation – one that gives leadership real visibility into risk, supports documented, auditable processes and can adapt as the standard evolves. That's exactly what Noggin's security management software is built to do.

To learn more about its worker protection capabilities, Request a demo.

Go ahead - request a demo of Noggin today.