KITE 2025 New Product Award โ€” Local IT | SACEEC
People and workplace

ISO 45001 coverage that protects people and proves it

Hazards, consultation records and incident investigations held in one place, with the statutory duties underneath evidenced alongside the management system.

app.dimeri.ai/compliance
87%Compliant
24Controls
3Pending
Access control policy
Incident response plan
Vendor assessments
Awareness training

Compliance at a glance

What ISO 45001 requires

Hazard register with hierarchy of controls

Hazards identified per site and activity, with the control level recorded and justified. Dimeri tracks the hierarchy so reliance on lower order controls is always documented.

Worker consultation on the record

Consultation activities, who participated and what came of it, logged as they occur. The record an auditor tests is built from practice, not reconstructed.

Incidents that close the loop

Each incident links to the hazard and control that failed, with root cause recorded and corrective actions carried until evidence closes them.

Statutory duties mapped alongside

OHSA and MHSA obligations sit beside the management system clauses. One control set serves both the standard and the law.

ISO 45001 compliance, covered by default

Hazard identification, worker consultation, incident investigation and the statutory duties that sit underneath, all in one platform so the management system and the law are evidenced together.

app.dimeri.ai/compliance
87%Compliant
24Controls
3Pending
Access control policy
Incident response plan
Vendor assessments
Awareness training

Hazard register with hierarchy of controls

Hazards identified per site and activity, with the control level recorded and justified, so reliance on PPE without a documented reason does not become an audit finding.

app.dimeri.ai/controls
RefControlStatus
A.5.1Information security policiesโœ“ Implemented
A.6.1Screeningโœ“ Implemented
A.7.4Physical security monitoringIn progress
A.8.2Privileged access rightsโœ“ Implemented

Worker consultation records

Consultation activities, who participated and what came of it, logged as they occur, not reconstructed for the auditor.

Exposure heatmapResidual
Likelihood
213114223512621431
LowImpactSevere
Critical 4High 10Medium 17Low 11

Incident investigation workflow

Incidents linked to the hazard and control that failed, with root cause recorded and corrective actions carried until evidence closes them.

Control libraryISO 31000
Segregation of duties92%Preventive
Exception reporting74%Detective
Incident escalation61%Corrective

Legal register for OHSA and MHSA

Statutory duties under the Occupational Health and Safety Act and Mine Health and Safety Act tracked as obligations with named owners and evidence.

Board packGenerated
Audit & risk committeeQ3 ยท 18 pp
12Above appetite โ†“ 387%Controls tested โ†‘ 9
01Risk appetite position3 pp02Movements since last meeting2 pp03Control effectiveness4 pp04Overdue treatment actions1 p

Leading and lagging indicators

Safety performance tracked with thresholds, from leading indicators like inspection completion rates to lagging indicators like injury frequency.

What Dimeri tracks

Dimeri holds the management system clauses alongside the statutory duties they evidence, so the same control answers both.

Context, leadership and worker participation

The scope of the system, top management accountability, and the consultation and participation of workers the standard emphasises.

  • Scope and interested parties recorded
  • OH&S policy with approval and review dates
  • Consultation activities logged with who took part
  • Health and safety committee records held in the system

Hazard identification and risk assessment

Ongoing and proactive identification of hazards, including how work is organised, social factors and workload, with OH&S risks and opportunities assessed.

  • Hazard register maintained per site and activity
  • Risks scored on criteria applied across the organisation
  • Opportunities for improvement captured, not only risks
  • Reassessment triggered by change and by incidents

Legal and other requirements

Statutory duties determined, kept current and accounted for in the system rather than tracked in a separate compliance file.

  • OHSA and MHSA duties held as tracked obligations
  • Regulations and codes linked to the controls satisfying them
  • Change monitoring with owners for each duty
  • Evidence of compliance attached as controls operate

Eliminating hazards and reducing risk

The hierarchy of controls applied and recorded, so the auditor can see why an administrative control was chosen over elimination.

  • Control level recorded against each treatment
  • Justification where a lower order control was selected
  • Personal protective equipment as last resort, evidenced
  • Effectiveness tested rather than assumed

Incident investigation and corrective action

Incidents and nonconformities investigated, root causes determined, and corrective action taken and evidenced.

  • Incidents captured at the point they happen
  • Each linked to the hazard and control that failed
  • Root cause recorded, not just the immediate cause
  • Actions carried until evidence closes them

Monitoring, audit and management review

Performance evaluated, internal audit run across the system, and management review held with the expected inputs.

  • Leading and lagging indicators tracked with thresholds
  • Internal audit programme covering every clause
  • Management review inputs gathered through the year
  • Findings tracked to closure with owners

Getting ISO 45001 coverage in place

4 steps from where you are today to a ISO 45001 position your auditor can rely on.

Book a demo

The scope is defined, and the statutory duties that apply, OHSA or MHSA and their regulations, are loaded as tracked obligations. The standard expects this anyway, and doing it first means the rest of the system has something to hang on.

How Dimeri covers ISO 45001

Consultation you can show

Worker consultation is where certification audits most often find gaps, because participation happens but is never recorded. Consultation activities, who took part and what came of it are logged as they occur.

One hazard register, two masters

The hazards ISO 45001 covers are the same ones the OHS Act expects you to address. Recorded once, they satisfy the standard and evidence the statutory duty together.

Incidents that close the loop

An incident links to the hazard it came from and the control that failed, so the corrective action addresses the cause. Repeat incidents are the clearest signal that a system is documented rather than operating.

ISO 45001 questions

Does ISO 45001 replace the OHS Act?

No. The Occupational Health and Safety Act 85 of 1993 is South African law and applies regardless of whether you hold a certificate. ISO 45001 is a voluntary management system standard that makes those statutory duties demonstrable. The standard actually expects you to determine and keep current the legal requirements that apply, so the two are designed to sit together.

What changed from OHSAS 18001?

ISO 45001 adopted the common management system structure, put much stronger emphasis on leadership accountability and on the consultation and participation of workers including non-managerial workers, and widened hazard identification to cover how work is organised, social factors and workload rather than physical hazards alone.

What does the hierarchy of controls mean in practice?

The standard expects you to eliminate the hazard where you can, then substitute, then apply engineering controls, then administrative controls, and only then personal protective equipment. What auditors test is whether you recorded why you settled where you did. Reliance on PPE without a documented reason is a frequent finding.

Can this cover mines as well?

The standard applies to any organisation, but on a mine the Mine Health and Safety Act and its mandatory codes of practice govern, and the DMRE inspectorate enforces them. Dimeri holds MHSA duties alongside the ISO 45001 clauses so one control set serves both.

Is this a substitute for the standard or for legal advice?

No. ISO 45001 is a copyrighted ISO publication and should be obtained from ISO or a national standards body. Statutory health and safety duties carry criminal liability, so your legal advisers should confirm what applies to your operation.

Ready to Transform Your GRC?

Join governance, risk, and compliance teams using AI to work smarter.