Skip to content
AUGUST SALE - TAKE 10% OFF ONLINE PURCHASES!
USE CODE "AUG26" AT CHECKOUT!
AUGUST SALE - 10% OFF ONLINE PURCHASES!
USE CODE "AUG26" AT CHECKOUT.

ISO 45001 Explained for Australian Businesses

Most people arrive at ISO 45001 the same way. A tender document lands, or a pre-qualification platform sends an email, and somewhere in it is a line saying your safety management system needs to be compliant with, aligned to, or certified against ISO 45001. Nobody explains what that means or what it will cost you.

This page explains it. What the standard is, what it asks for, whether you need certification or just a system that meets it, and what the whole thing realistically involves for a business with a handful of staff rather than a thousand.

What ISO 45001 is

ISO 45001 is the international standard for occupational health and safety management systems. It was published in March 2018 and it sets out what a management system has to contain: how you identify hazards, how you plan, who is accountable, how workers get a say, how you handle emergencies and incidents, and how you check the whole thing is working and improve it.

It does not tell you how to do the work safely. That is what your procedures and SWMS are for. ISO 45001 is a framework for running safety as a system rather than as a series of reactions.

Australia and New Zealand adopted it as AS/NZS ISO 45001:2018. The text is identical to the international standard. When an Australian tender says ISO 45001, this is what it means.

ISO confirmed the standard as current in 2024 and a revision is in development, so expect an updated edition at some point. Nothing in the current version is going away.

It replaced AS/NZS 4801, the older Australian standard, which has since been withdrawn. If your safety system was built to AS/NZS 4801 and has not been touched since, it is out of date and a prequalification assessor will notice.

Why businesses actually go looking for it

Very few small businesses set out to implement ISO 45001 because they read the standard and liked it. In our experience there are three triggers.

A tender requires it. Government work, tier one builders and large facility owners increasingly write it into their conditions.

A prequalification platform requires it. Avetta, Cm3, PICS, JobSafe and similar systems assess your documentation against a checklist, and that checklist is usually derived from ISO 45001.

A principal contractor asks for your system. You get sent a document request and realise what you have is a folder of SWMS, not a management system.

The commercial reality is that this is a gate. Businesses that can produce a compliant system get to bid on work that businesses without one never see. That is the return, and it is worth being clear-eyed about it rather than pretending the motivation is purely safety.

What the standard actually asks for

ISO 45001 is organised into clauses. Clauses 1 to 3 are scope, references and definitions. The requirements you have to meet sit in clauses 4 to 10, and they follow a Plan, Do, Check, Act cycle.

Clause 4. Context of the organisation

Work out what your business does, who it affects, and what external and internal issues bear on safety. Then define the boundaries of your system. For a subcontractor this is short. For a business with multiple sites and labour hire it is not.

Clause 5. Leadership and worker participation

The standard puts accountability on top management explicitly, and it goes further than the old standards on worker participation. You need to show workers were consulted, not just informed, and that barriers to participation were removed. Auditors look hard at this one.

Clause 6. Planning

Hazard identification, risk and opportunity assessment, legal and other requirements, and safety objectives with plans to achieve them. This is where your risk assessment process lives.

Clause 7. Support

Resources, competency, awareness, communication and documented information. In plain terms: the right people, trained, who know what is going on, with documents that are controlled and current.

Clause 8. Operation

Operational planning and control, the hierarchy of controls, management of change, procurement, contractors and outsourcing, and emergency preparedness. This is the biggest clause and where most of your day to day paperwork sits, including your SWMS.

Clause 9. Performance evaluation

Monitoring and measurement, internal audit, and management review. You have to check your own system on a schedule and record what you found.

Clause 10. Improvement

Incident and nonconformity handling, corrective action, and continual improvement. Finding problems is expected. Finding none is a red flag.

Certified or compliant? They are not the same thing

This is the question that costs businesses the most money when they get it wrong, so it is worth being blunt.

A compliant system means your documentation and practices meet what the standard requires. You build it, you run it, you can show it to anyone who asks. No external body is involved.

Certification means an accredited certification body audits your system, usually in two stages, and issues a certificate. It then returns for surveillance audits, typically annually, and recertifies on a cycle. There are audit fees, your own time, and usually some remediation between stages.

Here is the part nobody tells you: most tenders and pre-qualification platforms do not require certification. They require a system that meets the standard. Read the wording carefully. "Compliant with", "aligned to" and "in accordance with" do not mean certified. "Certified to ISO 45001 by a JAS-ANZ accredited body" does.

If the requirement is compliance, buying a certification you did not need is money that could have gone into the business. If the requirement genuinely is certification, no amount of good documentation substitutes for the audit.

Costs vary enormously with the size of your business, your number of sites and your certification body, so get two or three quotes rather than trusting a figure you read somewhere. What we can tell you is that the documentation is the same either way. A system built properly to the standard is the thing you present to an auditor if you later decide to certify.

What a compliant system contains

A WHS management system that meets AS/NZS ISO 45001 is not one document. At minimum it needs:

A safety policy signed by whoever runs the business. A manual or system overview that maps your documents to the clauses of the standard, so an assessor can find things. Procedures covering risk management, consultation, training and competency, incident reporting and investigation, emergency response, contractor management, purchasing, document control, internal audit and management review. Then the forms and registers those procedures generate: risk assessments, inductions, training records, toolbox talks, incident reports, corrective action registers, plant registers, audit schedules.

On top of that sit your task-level documents. For construction and trades that means SWMS for high risk construction work.

The mapping matters more than people expect. An assessor working through a checklist wants to open your system and find clause 5.4 worker participation without hunting. Systems that fail assessment often contain everything required and simply cannot prove it.

How long it takes

For a small trade business starting from a pre-written system, allow a few days of real work to customise the documents, get the policy signed, run the first consultation and set up your registers. The documentation is the quick part.

Where businesses come unstuck is the evidence. Clause 9 wants records of monitoring, an internal audit and a management review. Clause 10 wants corrective actions closed out. You cannot produce a history of a system operating on the day you buy it. If you are heading for certification, plan on running the system for two to three months before a stage 2 audit so there is something for the auditor to look at.

Building it from scratch instead is a different proposition. Most small businesses that try this stall somewhere around the internal audit procedure.

Where people go wrong

Buying a generic system and not customising it. Assessors have seen every template on the market. A system with another trade's hazards in it fails.

Treating it as a documentation exercise. If nobody in the business has read the policy, the first worker interview will expose it.

Skipping worker participation. Clause 5.4 is the most commonly raised nonconformity we see, and it is the hardest to fake after the fact.

Assuming ISO 45001 replaces your legal obligations. It does not. The WHS Act and Regulations in your state still apply in full. The standard is a framework for meeting them, not a substitute.

Our ISO 45001 systems

We have supplied these to Australian businesses since 2010. Every system is written to AS/NZS ISO 45001, supplied in Microsoft Word, and mapped to the clauses of the standard so an assessor can follow it.

Trade-specific versions that come with the SWMS for your work are under Industry Solutions. Browse everything under WHS Management Systems or OH&S Management Systems.

Questions we get asked

Is ISO 45001 mandatory in Australia?

No. It is a voluntary standard. What is mandatory is the WHS Act and Regulations in your state or territory. ISO 45001 becomes effectively mandatory only when a client or a prequalification platform makes it a condition of working for them, which is increasingly common.

What is the difference between ISO 45001 and AS/NZS 4801?

AS/NZS 4801 was the older Australian standard and has been withdrawn. ISO 45001 is international, gives top management explicit accountability, requires far more on worker participation, and takes a risk and opportunity based approach rather than a hazard based one. A system still built to 4801 will not pass a current assessment.

Do I need to be certified to win work?

Usually not. Most tenders and prequalification platforms ask for a system compliant with the standard, not a certificate. Read the exact wording before you spend anything. If it says certified by an accredited body, you need the audit.

How much does certification cost?

It depends on your headcount, your number of sites, your scope and which certification body you use. Get several quotes. The documentation cost is the same whether you certify or not.

How long does implementation take?

Days to customise a pre-written system, then two to three months of actually running it before you have the audit trail that clauses 9 and 10 require. Building from scratch takes considerably longer.

Does ISO 45001 replace my WHS legal duties?

No. Your duties under the WHS Act and Regulations are unchanged. A compliant system helps you meet them and demonstrate that you have, but the legal obligation sits with you either way.

We are a two person business. Is this overkill?

Sometimes. If nobody is asking you for a management system, a set of SWMS and the right forms may be all you need. Call us before you buy a system you do not have a use for.

Talk to someone who has done it

Call 1800 304 336, Monday to Friday, 8:30am to 5:00pm. Tell us who is asking and send us the wording if you have it. We will read the actual requirement and tell you what meets it.

We have been doing this since 2010 for more than 15,000 Australian businesses, and we will tell you when you do not need something. You can also email us.

This page is general information about AS/NZS ISO 45001 and Australian WHS requirements. It is not legal advice, and certification requirements vary between clients and certification bodies. Check the exact wording of what you have been asked for.