ISO 45001:2018 · Occupational Health and Safety
The proof that you manage health and safety responsibly
Customers, procurement and regulators increasingly ask how you manage occupational health and safety: which hazards you control, who is responsible, what risks are known. ISO 45001 gives a structured answer to this. Eucerta will soon offer certification to this standard — get in touch if you're interested and we'll let you know as soon as certification starts.
- Hazard identification, risk and opportunity assessment with guided templates
- Hierarchy of controls worked through systematically — with a reasoned decision for each hazard, from elimination to PPE
- Conditions published at launch, audit and monitoring included — interested companies get them first on request
- Aligned with the Arbeitsschutzgesetz, DGUV rules and EKAS 6508: documented management instead of individual checklist answers
Often bundled with ISO 9001 or ISO 14001 — quality, environment and occupational health and safety share half of the system requirements. We check beforehand, free of charge, whether Express works for you.
A management system for OH&S — not a safety inspection of the workplace
The most common misconception: ISO 45001 checks whether a workplace is safe. It doesn't. What is checked is whether your organization knows which hazards its activities involve, what risks and opportunities are associated with them, who is responsible for controlling them, and whether the measures taken are effective.
Identify hazards
An inventory of all hazards across your sites and activities — with source, affected work areas and those responsible for control.
Assess risks
A risk and opportunity assessment for each hazard: Who is affected, what could go wrong, how serious is it? For workers, contractors and visitors.
Address risks
A hierarchy-of-controls approach with reasoned decisions on which measures — elimination, substitution, engineering, administrative controls, PPE — you implement, and which not, and why.
Control operations and change
Traceable rules for procurement, contractors and outsourcing, management of change, and emergency preparedness and response.
Involve the workforce
Workers are consulted and participate in decisions that affect their safety; concerns can be raised and acted on. Roles and responsibilities are documented.
Monitor and improve
Performance and conditions are continuously monitored. Incidents are investigated, insights flow back into the system.
What companies want to know before certification
If contractors' work is integrated into your operations or your own workers share the same site and risks, yes. ISO 45001 distinguishes between the duties of the organization itself and those it places on contractors and outsourced work; the requirements for a company that only brings in contractors are lighter, but not zero.
No. The law is a legal requirement, the standard is a management system. But it covers a large part of the organizational obligations — hazard identification, risk assessment, worker participation, emergency preparedness — and makes the answers auditable.
We examine your system, not your workplace measurements. Auditors ask how you identify hazards, assess risks, control them and who decides. You need to be able to demonstrate this, not reinvent it.
Then you have already accomplished more than half. Context, leadership, risk approach, document control and internal audits are structured identically. We add the hazard identification and OH&S risk assessment, worker consultation and participation, and the operational controls — the hierarchy of controls — of ISO 45001.
Where proof decides the contract
ISO 45001 pays off where clients, insurers or authorities want to see how you control health and safety risks — and a questionnaire is no longer enough.
Construction and trades
Main contractors and public tenders often require a certified OH&S management system before subcontractors are approved.
Manufacturing and metal
Machinery, hazardous substances and repetitive tasks make hazard control and worker involvement a daily requirement.
Logistics and transport
Vehicle fleets, warehouses and shift work create accident risks that customers expect to see under control.
Energy and utilities
Work on plants and networks combines high hazards with strict legal duties and contractor oversight.
Chemicals and process industry
Process safety and hazardous substances demand a documented Gefährdungsbeurteilung and emergency preparedness.
Facility management and cleaning
Staff work across many client sites, so clients want assurance that hazards are controlled wherever people are deployed.
Healthcare and care homes
Physical strain, infection risks and shift work make the health of Beschäftigte part of daily operations.
Public bodies and municipal utilities
Municipal employers must show elected bodies and citizens that their occupational health and safety duties are actually met.
Four steps — at the pace that suits you
After certification, a surveillance audit follows annually, and recertification after two years. The conditions for this will be published with the launch of ISO 45001 certification — interested companies can get in touch now to be informed first.
Register and clarify scope
You tell us how big your company is, where you work and what you do. We explain how extensive the audit will be.
1 to 2 daysOne registration meeting for all standards
Prepare
You use templates, task lists, and reminders about missing documents. You don't start with a blank page.
1 to 6 weeks, depending on paceOne shared documentation
Two-stage audit
First we review your documents and check if you're ready. Then we check whether the rules truly work in your everyday work.
1 to 4 daysOne combined audit plan, one appointment
Decision and certificate
An independent person makes the decision. Upon success, you receive your digital certificate, visible in the online register.
1 to 3 daysOne certificate document with multiple standards
Step 2 is the only step whose duration depends on the chosen pace: with Express it's skipped, because the system is already running. With Standard it takes one to three weeks, with Guided up to six.
You set the pace. We tell you which one is realistic.
We don't audit more superficially or briefly than others. Above all, we save waiting time. All three paces are audited according to the same rules.
48 hours
Express
Change of certification body or a very tight deadline
- What happens: Audit, decision and certificate
- Your system is already running, your documents are complete
- Internal audit and management review have been carried out
2–4 weeks
Standard
Most small and medium-sized enterprises
- What happens: Documents are organized and prepared with AI. The audit follows afterward.
- Your processes already work
- Documents are missing or not yet complete
2–8 weeks
Guided
Initial certification without preparation
- What happens: You build your system with an independent partner. The audit follows afterward.
- So far only a few rules, processes, or documents
- Independent consulting partners from our network
For ISO 45001, Express is less often realistic. Hazard identification, assessment of OH&S risks and opportunities, the register of legal and other requirements, and the operational controls following the hierarchy of controls — elimination, substitution, engineering, administrative measures, PPE — must be in place and lived, together with genuine worker consultation and participation. This is often the case when switching from another certification body or with an existing ISO 9001 or ISO 14001 system, but almost never when starting from scratch. Whether this applies to you, we clarify in advance — just get in touch and we'll assess it with you.
How extensive the audit will be depends on your number of employees, your locations, and the type of your work. Are you unsure which column applies to you? Write to us — we'll tell you in a brief conversation what's possible for you.
Scope of services
What certification includes — no asterisks
Preparation platform with templates for all required documented information
Real-time gap analysis: you can see at any time what's missing for audit readiness
Certification audit Stage 1 and Stage 2 by our specially qualified and audited auditors
Certificate digital, multilingual, validated with entry in the public transparency register
Annual surveillance audits over the entire certificate term
Our auditors are specially qualified in occupational health and safety management (ISO 45001)
Personal point of contact — no ticketing system as the only door
Recertification after three years
Legal context
What ISO 45001 delivers in relation to occupational health and safety law — and what it doesn't
We phrase this deliberately carefully, because a lot of nonsense is claimed in the market: an ISO 45001 certificate is not proof that you comply with occupational health and safety law, and it does not replace the statutory risk assessment. Compliance is established through national law and its enforcement — in Germany the Arbeitsschutzgesetz and DGUV rules, overseen by the Berufsgenossenschaften; in Switzerland the UVG, the ArG and EKAS guideline 6508; across the EU the Framework Directive 89/391/EEC — not through certification alone, and certification stays voluntary.
Nevertheless, what ISO 45001 delivers is substantial: it forces you into exactly the structures those laws require — hazard identification and risk assessment, consultation and participation of your workers, tracking of legal and other requirements, operational controls following the hierarchy of controls, emergency preparedness, incident investigation. Anyone who has implemented 45001 doesn't stand empty-handed before an inspectorate or a major client, but with audited proof of organizational maturity.
- Yes — structured, externally audited proof of your occupational health and safety management
- Yes — covers a large part of the management obligations employers already carry under OH&S law
- Yes — solid starting position when authorities, insurers or clients ask for proof of due diligence
- No — does not replace the statutory risk assessment (Gefährdungsbeurteilung)
- No — does not exempt you from your own duty to identify hazards and involve your workers on site
Frequently asked questions about ISO 45001
The conditions for ISO 45001 will be published at launch. Interested companies can register their interest now and will be the first to receive them. The audit scope depends on the number of employees, locations, and the number and complexity of the hazards in your operations.
With running processes, typically 2 to 8 weeks. If your system is already in operation — for example when switching certification bodies — Express is possible in 48 hours.
No. National occupational health and safety law stays fully in force regardless of certification — in Germany the Arbeitsschutzgesetz, DGUV rules and the Berufsgenossenschaften, in Switzerland the UVG, ArG and EKAS guideline 6508. ISO 45001 is a voluntary way to prove that the management system behind these duties actually works and is externally audited.
No. For each hazard you assess which level — elimination, substitution, engineering controls, administrative controls or personal protective equipment — is appropriate and justify your choice. What is audited is the justification and the effectiveness of the measures you choose.
No. We audit your management system: whether you know your hazards, what risks and opportunities exist, who is responsible, and whether your controls are effective. We don't measure the workplace ourselves or replace the labour inspectorate — that stays with you and with the authorities and accident insurers.
Contractors, outsourced work and procurement also belong in scope. You assess the hazards and risks arising from their activities and regulate how you select, coordinate and monitor external workers.
Yes — this is the classic combination: quality, environment and occupational health and safety in one integrated system. ISO 45001 shares the same High Level Structure as ISO 9001 and ISO 14001, so much of the system overlaps. Eucerta will offer certification to ISO 45001 soon — get in touch if you're interested, and we'll let you know as soon as it's available.
We are an independent, non-accredited certification body. No accreditation is required for ISO 45001. We ensure our quality through qualified and specially trained OH&S auditors, our own management system according to ISO 9001, and a public certificate register.
Yes. Your system lives on in the platform; the IMS Radar captures new hazards, changes in operations, and role changes and reminds you what needs to be updated before the next surveillance audit.
The platform and AI guide you through preparation. If you need additional help, we connect you with independent consulting partners. They advise — Eucerta audits later.
Register your interest in ISO 45001 now
No obligation — Eucerta will let you know as soon as ISO 45001 certification starts.
