What an ISO 45001 gap assessment is
A gap assessment compares how your organisation manages health and safety today with what ISO 45001 expects. It tells you which arrangements are already in place, which are partly there and which are missing, and turns that into a prioritised plan. It is not a certification audit and it does not predict the outcome of one, but it shows you the size of the job before you commit to it.
Who needs one
- Organisations considering ISO 45001 that want to know how much work is involved
- Businesses facing a client or tender requirement with a deadline
- Organisations whose earlier attempt at ISO 45001 stalled
- Organisations certified to ISO 14001 or ISO 9001 that are adding occupational health and safety
- Organisations preparing for a certification audit that want an independent view of readiness
What is reviewed
We review your arrangements against the applicable requirements of ISO 45001, grouped into these areas:
- The context of the organisation and the scope of the system
- Leadership, the OH&S policy, roles and the consultation and participation of workers
- Hazard identification, assessment of risks and opportunities, legal and other requirements, and objectives
- Resources, competence, awareness, communication and documented information
- Operational planning and control, including contractors, procurement, management of change and emergency preparedness
- Monitoring and measurement, evaluation of compliance, internal audit and management review
- Incident investigation, nonconformity, corrective action and continual improvement
How evidence is evaluated
Documents alone do not show that a system works. We look at four kinds of evidence: the documents that describe your arrangements, the records that show they are followed, conversations with managers, supervisors and workers, and, where the assessment includes a site visit, observation of the work itself. A requirement is only treated as met where the evidence supports it.
How findings are classified
| Status | Meaning |
|---|---|
| In place | The arrangement exists and there is evidence it operates. |
| Partly in place | Something exists, but it is incomplete, inconsistent or not evidenced. |
| Not in place | The arrangement does not yet exist. |
| Not applicable | The requirement does not apply to your scope, with the reason recorded. |
Each gap is then given a priority. High priority covers fundamental system gaps and anything suggesting a legal compliance or significant risk issue, which we flag separately because it matters whether or not you pursue certification. Medium priority covers gaps that must be closed before certification. Low priority covers improvement opportunities.
Remote review or on-site assessment
Remote document-based review
We review the documents and records you share and interview key people by video.
- Suits early planning and lower-risk, single-site organisations
- Efficient and lower cost
- Cannot confirm how controls work in practice
Assessment with operational verification
Adds time on site to observe work, speak with workers and supervisors and check controls.
- Suits higher-risk activities and multi-site organisations
- Recommended before a certification audit
- Gives a more reliable picture of readiness
What you receive
- A structured review against the applicable ISO 45001 requirements
- The gaps identified, with the evidence behind each finding
- Prioritised recommendations
- A written action plan
- An implementation roadmap
- An optional implementation proposal, if you would like our help
What happens after the assessment
We talk you through the findings. You can then implement the plan yourselves, ask us to support part of the work, or ask for a full implementation proposal. There is no obligation to continue with us.
A gap assessment is not a certification audit and cannot guarantee certification. Certification is decided by an independent, accredited certification body.
We are based in Oxfordshire and support London organisations remotely and on site by arrangement. We do not have a London office.
Why Featherstone Safety
Featherstone Safety Ltd is an independent UK occupational health and safety consultancy providing ISO management system consultancy and implementation support. Thomas Featherstone holds the NEBOSH International General Certificate in Occupational Health and Safety and IOSH Managing Safely, is a Technical Member of IOSH (TechIOSH), and has eight years in safety-critical work.
- Systems that match the work. We build processes around how your organisation actually operates, so they survive contact with an auditor and with day-to-day pressure.
- Independent of certification. We are not a certification body, we do not issue certificates and we have no commercial tie to any certification body.
- Practical site experience. Recent work includes on-site health and safety advisory and observation support during the delivery and installation of a 300 tonne super grid transformer. That was health and safety advisory work, not ISO consultancy, and it is not an endorsement of our ISO services.
Read more about Thomas Featherstone or see our case studies.
Frequently asked questions
What is an ISO 45001 gap analysis?
A structured comparison of an organisation’s current health and safety arrangements with the requirements of ISO 45001. It identifies what is in place, partly in place and missing, prioritises the gaps and sets out an action plan for closing them.
Can a gap assessment be done remotely?
Yes, as a document-based review with video interviews. It cannot confirm how controls work in practice, so for higher-risk activities, multi-site organisations or readiness before certification, an assessment that includes time on site is more reliable.
Will a gap assessment tell us whether we would pass certification?
It shows how close your arrangements are to the standard and what needs to change, but it is not a certification audit and cannot predict the certification body’s decision.
Does a gap assessment commit us to an implementation project?
No. You receive the findings and action plan and can use them however you choose, including implementing the plan yourselves.
What do we need to prepare?
Your health and safety policy, risk assessments, key procedures, training records, incident records, inspection records and any existing audit or review reports, plus access to the people who manage health and safety day to day.
