Skip to content

HSE inspections up 47% - HSE carried out over 13,200 workplace inspections in 2024/25.

ISO 45001 Certification: The Two Audits, the Seven Clauses, and What Actually Stands Between You and the Certificate

A
Arinite Health & Safety Consultants
July 27, 2026
6 min read
ISO 45001 Certification: The Two Audits, the Seven Clauses, and What Actually Stands Between You and the Certificate

Businesses arrive at ISO 45001 certification from somewhere specific: a tender that requires it, a client questionnaire that scores it, a board that wants the flag planted, or a safety lead who wants the discipline it enforces. Whatever brought you here, the useful next step is the same: understanding what certification actually involves, because the process is more knowable than the mystique suggests, and knowing it turns a vague ambition into a plannable project.

One clarification first, and it is the most important sentence on this page: certification is granted by accredited certification bodies, independent auditors accredited by bodies such as UKAS in the UK, and never by consultants, including us. Anyone offering to sell you the certificate directly is describing a document not worth its frame. What consultants legitimately do is build and prepare the management system the certification body will audit, and that division of labour is exactly why this guide can be honest about the whole journey: our part ends where the auditor's begins. With that established, here is what stands between a business and the certificate: seven clauses and two audits.

What you are actually being audited against

ISO 45001 is the international standard for occupational health and safety management systems, and its requirements live in seven operative clauses that follow the same architecture as ISO 9001 and 14001, which is deliberate and convenient if you already hold either. In plain English, the seven:

Context: you understand your organisation, the internal and external issues that affect safety, and the needs of workers and other stakeholders, and you have defined what your system covers. Leadership: top management visibly owns the system, sets policy, and, distinctively in 45001, workers are consulted and participate, not merely informed. Planning: risks and opportunities are identified and assessed, legal requirements are known and tracked, and objectives are set with plans behind them. Support: the system is resourced, people are competent, communication works, and documented information is controlled and current. Operation: the planning becomes practice, controls implemented in the hierarchy's order, change managed, procurement and contractors covered, emergencies prepared for. Performance evaluation: you monitor, measure and internally audit the system, and management reviews it with intent. Improvement: incidents and nonconformities drive correction, and the system demonstrably gets better.

Read the list again and notice what it is: not a paperwork exercise, but a description of managed safety, the same plan-do-check-act discipline this blog documents hazard by hazard, formalised to an auditable standard. If your risk assessments are genuine, your training recorded, your incidents investigated and your reviews real, you are further along than you think; the clauses mostly demand that what should already be true is documented, systematic and provable.

Stage one: the documentation audit

Certification arrives through two audits, and the first is the desk-based one: the certification body reviews your documented system against the clauses, your policy, scope, risk methodology, legal register, objectives, procedures and records structure, and assesses whether you are ready for the real test. Stage one's findings are a gift: a formal list of gaps while gaps are still cheap.

The classic stage-one failures are structural: a system written for the auditor rather than the business, in language nobody internally uses; scope drawn carelessly; the legal register generic or stale; worker consultation asserted but nowhere evidenced. Businesses that treat stage one as a rehearsal rather than a formality pass stage two; businesses that bought a template folder discover at stage one exactly what the folder was worth.

Stage two: the implementation audit

Stage two is the audit that matters: the certification body comes to where the work happens and tests whether the documented system is the lived one. Auditors interview workers, not just managers, walk floors, pull records against reality, and follow threads: the risk assessment to the control on the floor, the training record to the person who supposedly received it, the incident to the investigation to the change it produced.

The single idea that predicts stage-two success is the one running through everything Arinite writes: the gap between paper and practice. An auditor can forgive an imperfect system that is genuinely operating; they cannot certify a beautiful one that exists only in the folder. Which is why the businesses that pass comfortably are the ones whose system lives where people work, assessments current, actions owned, records producible in minutes, and why pairing consultants and software has become the standard preparation model: qualified health and safety consultants building the system right, and the platform keeping every clause's evidence live across every site, so stage two examines a working machine rather than an archaeology project.

After the certificate: the cycle that keeps it

Certification is not an event but a cycle: the certificate runs on a three-year period with surveillance audits along the way and recertification at the end, which means the system must keep operating, keep improving and keep evidencing between visits. The businesses for whom this is a burden are the ones who built the system for the audit; the ones for whom it is routine simply kept doing what the system said. Internal health and safety audits are the connective tissue here, both a clause requirement and the honest rehearsal that keeps surveillance visits boring, in the best sense.

Is it worth it, and for whom

Honestly: not every business needs the certificate, and the standard's discipline is available to anyone without it. Certification earns its cost where the certificate itself unlocks value, tenders and procurement that require or score it, clients and insurers who trust it, group structures that mandate it, and, most powerfully, for international businesses, where one globally recognised standard does what no single country's compliance can: demonstrates the same managed safety in every jurisdiction at once. That is precisely the terrain of international health and safety consultants, for whom ISO 45001 is the natural spine of a world-class multi-country system, and our guide to what the standard is covers the foundations this journey builds on.

Where Arinite fits

Arinite prepares businesses for ISO 45001 certification the honest way: building management systems that pass stage two because they genuinely run, not folders that pass stage one and die there. For 15+ years, as global health and safety consultants, we have supported 1,500+ businesses across 50+ countries, helping protect 100,000+ employees, with a 95% client retention rate, and our consultants-plus-software model means the evidence the auditor asks for is the same live system leadership sees every day.

If certification is on your horizon, the first question is how far your current arrangements already reach toward the seven clauses, and that has a fast answer. Our free gap analysis reviews your system against exactly this standard's expectations and tells you plainly what stands and what is missing. Book your free gap analysis and start the journey knowing the distance.

Share this article
A

Written by

Arinite Health & Safety Consultants

Health & Safety Expert at Arinite

Free Resources

Health & Safety Factsheets

Download our comprehensive library of expert guides, checklists, and templates.

Get Professional Help

Need Expert H&S Advice?

Our qualified consultants are ready to support your specific business needs.