Implementation is about how you work, not a set of documents
An ISO 45001 system succeeds when the processes it describes are the ones people actually follow. Certification auditors look for evidence that the system operates: records, interviews with managers and workers, and observation of work. A folder of generic procedures that does not match the work tends to fail at that point, and fixing it costs more than building it properly the first time.
We therefore build on what already works in your organisation, add what is missing, and spend as much effort on embedding processes as on writing them.
The implementation journey
Every project is tailored, but most follow this sequence.
Scope and baseline
- Initial consultation and scope definition. Agree why you want ISO 45001, which activities and sites the system will cover, and who will own it internally.
- Gap assessment. Compare current arrangements with the standard and turn the findings into a prioritised plan. About gap assessments.
Foundations
- Organisational context and interested parties. Identify the internal and external issues that affect health and safety, and the needs of workers, clients, regulators and others.
- Leadership and worker consultation. Establish top management accountability, the OH&S policy, roles and responsibilities, and how workers will be consulted and take part in decisions.
- Hazard identification and OH&S risk assessment. Set up an ongoing process that covers routine and non-routine work, contractors, visitors and change, and applies the hierarchy of control.
- Legal and other requirements. Identify the legislation and other commitments that apply, how they affect your operations, and how compliance will be evaluated.
- Objectives and implementation planning. Set measurable objectives and plan the actions, resources and responsibilities needed to achieve them.
Build and embed
- Management system documentation. Produce the documented information the system needs, in a format that suits your organisation, and control it properly.
- Operational control arrangements. Put proportionate controls in place for higher-risk activities, contractors, procurement, management of change and emergencies.
- Competence and awareness. Define the competence each role needs, close training gaps and make sure people understand the hazards of their work and their part in the system.
Check
- Performance monitoring. Track leading and lagging indicators, inspections, incidents and progress against objectives.
- Internal audit arrangements. Plan and carry out internal audits with competent, impartial auditors.
- Management review. Top management reviews performance, audit results, legal compliance and worker input, and decides on actions.
Improve and certify
- Corrective action and improvement. Investigate incidents and nonconformities for root causes, act on them and check the actions worked.
- Preparation for independent certification. Help you choose an accredited certification body and prepare for the stage 1 and stage 2 audits.
What you will need to provide
- An internal owner with the time and authority to move the project forward
- Time from top management for leadership, objectives and management review
- Access to workers and supervisors so that consultation and participation are genuine
- Access to existing documents, records and sites
- Timely decisions when choices need to be made about processes and controls
Remote and on-site delivery
Usually remote
- Planning and progress meetings
- Process design workshops
- Drafting and reviewing documentation
- Review of records
- Management review facilitation
Usually on site
- Verifying operational controls
- Talking with workers where they work
- Observing higher-risk activities
- Checking emergency arrangements
- Readiness review before certification
We are based in Oxfordshire and support London organisations remotely and on site by arrangement. We do not have a London office. More on remote implementation.
How long implementation takes
It depends on your starting point, the number of people and sites, the hazards involved and how much time your team can give the project. Before a certification body recommends certification it needs to see that the system has actually been operating, including a completed cycle of internal audit and management review. We agree a realistic timetable in the proposal, rather than promising a date that ignores how long it takes to generate that evidence.
What we will not do
- Promise that you will be certified. Only the certification body can decide that.
- Issue certificates. We are a consultancy, not a certification body.
- Hand over a template system that does not match your work.
- Take on your legal duties. They remain with the employer and its dutyholders.
Optional software support
Some clients use Featherstone Safety Hub, our separate health and safety software, to keep parts of their management system running between audits. Its features include a document register with version control, corrective action tracking, inspection and incident records and training records, and the Professional plan adds an environmental aspect register and legal compliance log.
It is entirely optional. Using it does not make a management system conform to ISO 45001 or ISO 14001 on its own, and the software itself is not ISO certified.
Why Featherstone Safety
Featherstone Safety Ltd is an independent UK occupational health and safety consultancy providing ISO management system consultancy and implementation support. Thomas Featherstone holds the NEBOSH International General Certificate in Occupational Health and Safety and IOSH Managing Safely, is a Technical Member of IOSH (TechIOSH), and has eight years in safety-critical work.
- Systems that match the work. We build processes around how your organisation actually operates, so they survive contact with an auditor and with day-to-day pressure.
- Independent of certification. We are not a certification body, we do not issue certificates and we have no commercial tie to any certification body.
- Practical site experience. Recent work includes on-site health and safety advisory and observation support during the delivery and installation of a 300 tonne super grid transformer. That was health and safety advisory work, not ISO consultancy, and it is not an endorsement of our ISO services.
Read more about Thomas Featherstone or see our case studies.
Frequently asked questions
How long does ISO 45001 implementation take?
It depends on the starting point, the number of people and sites, the hazards involved and the time the organisation can commit. A certification body needs evidence that the system has operated, including internal audit and management review, before it recommends certification, so the timetable must allow for that. We agree a realistic timetable after scoping.
What documents are required for ISO 45001?
ISO 45001 requires specific documented information rather than a fixed set of documents. In practice that includes the scope, the OH&S policy and objectives, information on hazards, risks and how they are addressed, legal and other requirements, evidence of competence, monitoring results, emergency arrangements, internal audit and management review results, and records of incidents, nonconformities and corrective actions. The standard does not require a manual.
What happens during an ISO 45001 implementation project?
Typically: scope definition and a gap assessment; establishing context, leadership, worker consultation, risk assessment, legal requirements and objectives; building documentation, operational controls and competence; then monitoring, internal audit and management review; and finally corrective action and preparation for the certification audits.
Can ISO 45001 be implemented remotely?
Much of it can, including planning, workshops, documentation and management review. Verifying operational controls and consulting workers where they work usually needs time on site, so most projects use a hybrid approach.
Will we pass the certification audit?
No consultant can guarantee that. Certification is decided by an independent certification body. What we can do is help you build a system that genuinely operates and carry out a readiness review so that any remaining gaps are known before the audit.
