ISO 45001, with worker consultation you can evidence
ISO 45001 made worker participation a requirement rather than good practice, and it is the clause auditors probe hardest. Dimeri holds the hazard register, the consultation record and the incident trail in one place, each against the clause it answers.
What ISO 45001 requires
ISO 45001 specifies requirements for an occupational health and safety management system. It replaced OHSAS 18001 and adopted the common management system structure, clauses 4 to 10, so it sits alongside ISO 9001, ISO 14001 and ISO 27001 without a separate architecture.
Two things distinguish it from the standard it replaced. First, clause 5.4 requires consultation and participation of workers, including non-managerial workers, in a list of specific activities: determining hazards, investigating incidents, establishing policy and objectives, and more. Second, clause 6.1.2 separates hazard identification from the assessment of OH&S risks and opportunities, and expects both to consider how work is organised, social factors, workload and leadership, not just physical hazards.
In South Africa the standard does not replace statutory duties. The Occupational Health and Safety Act and, on mines, the Mine Health and Safety Act remain the law. ISO 45001 provides the management system that makes those duties demonstrable, and clause 6.1.3 explicitly requires legal and other requirements to be determined and kept current. That overlap is why most South African organisations map the two together rather than running them apart.
The clauses Dimeri tracks
Dimeri holds the management system clauses alongside the statutory duties they evidence, so the same control answers both.
Context, leadership and worker participation
The scope of the system, top management accountability, and the consultation and participation of workers that clause 5.4 requires.
- Scope and interested parties recorded
- OH&S policy with approval and review dates
- Consultation activities logged with who took part
- Health and safety committee records held against the clause
Hazard identification and risk assessment
Ongoing and proactive identification of hazards, including how work is organised, social factors and workload, with OH&S risks and opportunities assessed.
- Hazard register maintained per site and activity
- Risks scored on criteria applied across the organisation
- Opportunities for improvement captured, not only risks
- Reassessment triggered by change and by incidents
Legal and other requirements
Statutory duties determined, kept current and accounted for in the system rather than tracked in a separate compliance file.
- OHSA and MHSA duties held as tracked obligations
- Regulations and codes linked to the controls satisfying them
- Change monitoring with owners for each duty
- Evidence of compliance attached as controls operate
Eliminating hazards and reducing risk
The hierarchy of controls applied and recorded, so the auditor can see why an administrative control was chosen over elimination.
- Control level recorded against each treatment
- Justification where a lower order control was selected
- Personal protective equipment as last resort, evidenced
- Effectiveness tested rather than assumed
Incident investigation and corrective action
Incidents and nonconformities investigated, root causes determined, and corrective action taken and evidenced.
- Incidents captured at the point they happen
- Each linked to the hazard and control that failed
- Root cause recorded, not just the immediate cause
- Actions carried until evidence closes them
Monitoring, audit and management review
Performance evaluated, internal audit run across the system, and management review held with the inputs the clause lists.
- Leading and lagging indicators tracked with thresholds
- Internal audit programme covering every clause
- Management review inputs gathered through the year
- Findings tracked to closure with owners
How Dimeri covers ISO 45001
The system and the statute ask for the same evidence in different words. Dimeri records it once.
Consultation you can show
Clause 5.4 is where certification audits most often find gaps, because participation happens but is never recorded. Consultation activities, who took part and what came of it are logged against the clause as they occur.
One hazard register, two masters
The hazards ISO 45001 requires you to identify are the same ones OHSA section 8 obliges you to address. Recorded once, they satisfy the standard and evidence the statutory duty together.
Incidents that close the loop
An incident links to the hazard it came from and the control that failed, so the corrective action addresses the cause. Repeat incidents are the clearest signal that a system is documented rather than operating.
Shared clauses across the ISO set
Context, leadership, competence, documented information, internal audit and management review are common to ISO 45001, 14001, 9001 and 27001. One management system carries all of them with separate scopes.
Getting ISO 45001 in place
- 1
Set the scope and the legal register
The scope is defined, and the statutory duties that apply, OHSA or MHSA and their regulations, are loaded as tracked obligations. Clause 6.1.3 requires this anyway, and doing it first means the rest of the system has something to hang on.
- 2
Build the hazard register
Hazards are identified per site and activity, including the organisational and social factors the 2018 edition added, and assessed against consistent criteria.
- 3
Apply the hierarchy of controls
Controls are selected and the level recorded, with a justification wherever a lower order control was chosen. Auditors ask about this specifically, and an unexplained reliance on PPE is a common finding.
- 4
Consult, measure and review
Worker consultation, indicator monitoring, internal audit and management review run on schedule with owners, and incidents feed straight back into the hazard register.
ISO 45001 questions
Does ISO 45001 replace the OHS Act?
No. The Occupational Health and Safety Act 85 of 1993 is South African law and applies regardless of whether you hold a certificate. ISO 45001 is a voluntary management system standard that makes those statutory duties demonstrable. Clause 6.1.3 actually requires you to determine and keep current the legal requirements that apply, so the two are designed to sit together.
What changed from OHSAS 18001?
ISO 45001 adopted the common management system structure, put much stronger emphasis on leadership accountability and on the consultation and participation of workers including non-managerial workers, and widened hazard identification to cover how work is organised, social factors and workload rather than physical hazards alone.
What does the hierarchy of controls mean in practice?
Clause 8.1.2 expects you to eliminate the hazard where you can, then substitute, then apply engineering controls, then administrative controls, and only then personal protective equipment. What auditors test is whether you recorded why you settled where you did. Reliance on PPE without a documented reason is a frequent finding.
Can this cover mines as well?
The standard applies to any organisation, but on a mine the Mine Health and Safety Act and its mandatory codes of practice govern, and the DMRE inspectorate enforces them. Dimeri holds MHSA duties alongside the ISO 45001 clauses so one control set serves both.
Is this a substitute for the standard or for legal advice?
No. ISO 45001 is a copyrighted ISO publication and should be obtained from ISO or a national standards body. Statutory health and safety duties carry criminal liability, so your legal advisers should confirm what applies to your operation.
Put ISO 45001 on one register
Every requirement mapped to a control with a named owner, the evidence held against it, and one view of where you stand.