There is no fixed timescale for ISO 45001. Some organisations already manage health and safety well and mainly need to formalise what they do. Others need to build most of the system from scratch. What every organisation shares is a sequence of steps that cannot be skipped, and the time each step needs to produce real evidence.
The stages that set the timescale
- Gap assessment and planning. Establishing how far current arrangements are from the standard and planning the work.
- Building the system. Context, leadership, worker consultation, hazard identification, legal requirements, objectives, operational controls and competence.
- Operating the system. Running the processes for long enough to generate records: inspections, incidents, training, objectives and corrective actions.
- Checking it. Completing internal audits and a management review.
- Certification audits. A two-stage audit by an accredited certification body, followed by its certification decision.
Why the system needs time to run
A certification body is assessing whether the system has been implemented and is effective, not whether documents exist. Before it recommends certification it will normally expect to see the system operating, including a completed cycle of internal audit and management review. That is the step organisations most often underestimate, and it cannot be compressed by writing documents faster.
The certification audit itself
Initial certification is carried out in two stages. Stage 1 reviews whether the system is ready, including its documentation and planning. Stage 2 assesses whether it has been implemented effectively, through records, interviews and observation of work. If the auditor raises nonconformities, they need to be addressed before certification is granted. After certification, surveillance audits continue during the three-year certificate cycle.
Audit dates depend on the certification body’s availability, so it is worth contacting certification bodies early.
What makes it faster or slower
- Faster: sound existing risk assessments and records, an internal owner with time and authority, committed top management, and an existing ISO 14001 or ISO 9001 system to build on.
- Slower: many sites or higher-risk activities, a system built from templates that has to be reworked, limited internal resource, and leaving internal audit and management review until the end.
A realistic way to plan
Plan in months rather than weeks, start with a gap assessment to size the work, and build the timetable backwards from any client or tender deadline, allowing time for the system to operate before the Stage 2 audit. See how we approach ISO 45001 implementation.
Frequently asked questions
Can ISO 45001 be done in a few weeks?
Documents can be written quickly, but a certification body needs evidence that the system has been implemented and is effective, including internal audit and management review. That evidence takes time to generate, so short timescales are rarely realistic.
How long is an ISO 45001 certificate valid?
Certification runs on a three-year cycle, with surveillance audits during that period and a recertification audit before it ends.
What usually delays ISO 45001 certification?
Common causes are limited internal time, documents that do not match how the work is actually done, and internal audit and management review being left until just before the certification audit.
