Two mobile crane booms extended against a blue sky

ISO 45001 for Construction Companies: What a Contractor's Health and Safety Management System Actually Needs

Most UK contractors already have a health and safety system of sorts: a policy, a set of RAMS templates, permits, an accident book and a consultant who visits once a quarter. What they do not have is a management system in the sense that ISO 45001 means it, and the difference shows the first time a framework asks for certification. This article explains what ISO 45001:2018 actually requires of a construction company, where it overlaps with the law you are already complying with, which documents an auditor will look for, and what a bought-in system can and cannot do.

Why the standard has reached construction

ISO 45001:2018 is the international standard for occupational health and safety management systems. It replaced OHSAS 18001 and shares its structure with ISO 9001:2015 and ISO 14001:2015, so a contractor with a quality system already knows the shape: context, leadership, planning, support, operation, performance evaluation and improvement. In the UK it is published as BS EN ISO 45001:2023, which is identical in content to the 2018 text. Amendment 1 of 2024 added one line to clause 4.1 requiring the organisation to determine whether climate change is a relevant issue, and a note under 4.2 that interested parties can have requirements related to climate change. That is the only change since publication.

The reason it matters commercially is the same reason ISO 9001 matters: prequalification. Common Assessment Standard questionnaires, framework applications and Tier 1 supply chain audits all ask whether the contractor holds ISO 45001, and where they do not, they ask for the evidence that would support it anyway. The reason it matters beyond the tender is in HSE's own figures. HSE's provisional statistics for 2025/26 record 126 workers killed in work-related accidents in Great Britain, of whom 25 were in construction, the highest of any industry. Those figures are finalised in July 2027; the sector's position at the top of the table is not new.

What ISO 45001 asks for that the law does not

A UK contractor is already required to have most of what the standard describes. The Health and Safety at Work etc. Act 1974 section 2(3) requires a written policy with the organisation and arrangements for carrying it out. The Management of Health and Safety at Work Regulations 1999 regulation 3 requires suitable and sufficient risk assessments, regulation 5 arrangements for planning, organisation, control, monitoring and review, and regulation 7 competent assistance. CDM 2015 sets the duties of the client, designers, principal contractor and contractors, and regulation 6 fixes the notification thresholds: more than 30 working days with more than 20 workers at any one time, or more than 500 person-days. RIDDOR 2013 governs incident reporting; the Safety Representatives and Safety Committees Regulations 1977 and the Health and Safety (Consultation with Employees) Regulations 1996 govern consultation. HSG65, third edition 2013, describes the plan, do, check, act model HSE expects to see.

ISO 45001 does not add legal duties. It adds the discipline of a system. The difference is in four places:

  1. Leadership and worker participation (clause 5). The standard requires top management to take accountability, not to delegate it to the safety adviser, and it requires consultation and participation of workers at every stage, from hazard identification to the choice of controls to the investigation of incidents. Clause 5.4 lists the topics on which workers must be consulted and the topics in which they must participate. An auditor will ask for the record of that consultation, and "we have a safety committee" is not the answer unless the minutes show it.
  2. Hazard identification as a continuous process (clause 6.1.2). RAMS are task risk assessments. The standard wants a process that identifies hazards arising from how work is organised, from human factors, from past incidents, from emergencies, from changes in the organisation, and from people who are not the organisation's own employees. A company-level hazard and risk register, fed by the site risk assessments rather than duplicating them, is what this looks like.
  3. Legal and other requirements as a maintained register (clause 6.1.3). Every applicable statute, regulation, ACOP and client requirement, with what it requires, how the organisation complies and how compliance is evaluated. Most contractors hold this in the consultant's head. The standard wants it written down and reviewed.
  4. Performance evaluation and improvement (clauses 9 and 10). Monitoring against defined indicators, internal audit against the standard, management review with defined inputs, and a corrective action process that fixes the cause rather than the symptom, with an effectiveness check after the fix. This is where most systems fail at first audit, because they have inspections but not audits and accident reports but not corrective actions.

The clauses, in construction terms

Clause 4: context

Who the interested parties are (clients, principal contractors, the workforce including agency and self-employed, HSE, insurers, neighbours), what they require, and the scope of the system. A contractor who works both as principal contractor and as a subcontractor has two operating contexts and the scope should say so.

Clause 5: leadership, policy, roles, consultation

The policy under HSWA section 2(3) can be the same document as the ISO 45001 policy if it carries the six commitments clause 5.2 requires, including the commitment to eliminate hazards and reduce risks and the commitment to consultation and participation. Roles need to be assigned in writing, including the CDM roles on each project. Consultation needs a mechanism, a record and, importantly, protection from reprisal for anyone who raises a concern or stops work.

Clause 6: planning

The hazard and risk process described above, the legal register, and objectives with a plan to achieve them. Objectives that read "zero accidents" fail the test of being measurable in a useful way; objectives that read "100 per cent of supervisors holding SSSTS by March, close-out of corrective actions within 30 days, near-miss reporting rate above a stated ratio" do not.

Clause 7: support

Competence records for every role, including how competence is verified and not just which card is held. Awareness: everyone knows the policy, the hazards relevant to them, and their authority to remove themselves from danger. Communication: what is communicated, to whom, when and how, internally and to clients, HSE and the public. Documented information: what is controlled, where it is kept, for how long. Health records under COSHH and the Control of Noise and Vibration Regulations are retained for 40 years, which a general records procedure will not say unless it has been written for this purpose.

Clause 8: operation

Operational planning and control is where CDM lives: the construction phase plan, RAMS, permits, the hierarchy of controls in 8.1.2, management of change in 8.1.3, and procurement in 8.1.4, which covers products, contractors and outsourced processes. Clause 8.1.4.2 requires coordination with contractors, which in construction terms is the principal contractor's duty under CDM regulation 13 written as a management process rather than as a site rule. Clause 8.2 is emergency preparedness: not only fire and first aid but rescue from height, confined space rescue, services strikes and the specific scenarios each site creates.

Clause 9: performance evaluation

Monitoring and measurement with defined indicators: the accident frequency rate and lost-time injury frequency rate as lagging indicators; near-miss reporting rate, inspection completion, training completion and corrective action closure as leading ones. Then evaluation of compliance with the legal register, internal audit against the standard, and management review with the inputs clause 9.3 lists.

Clause 10: improvement

Incident investigation to root cause, not to "operative failed to follow the method statement". Corrective action with an effectiveness check, and a record of what changed.

What the auditor will actually open

A certification audit is a sampling exercise. In a construction company the sample typically includes:

  • The policy, signed and dated, and evidence it has been communicated.
  • The hazard and risk register and the link from it to the site risk assessments.
  • The legal register, its last review, and the compliance evaluation record.
  • Objectives and the KPI data behind them, month by month.
  • Consultation records: minutes, topics, who attended, what changed as a result.
  • The competence matrix and a sample of training records against it.
  • A project: the construction phase plan, a RAMS, a permit, an inspection record, an induction record, and the link from each to the procedure that requires it.
  • The incident register, one investigation report, the corrective action it generated and the evidence the action worked.
  • The audit programme, one audit report, and the management review minutes.
  • Health surveillance records, where the exposures require them.

The finding that catches most contractors is the missing link. The site has a good RAMS; the company has no process that says how RAMS are produced, reviewed and briefed. The accident was investigated; nothing changed at company level. The consultant's report lists the legislation; nobody has evaluated compliance against it. The standard is about the joins.

Integration with ISO 9001 and ISO 14001

The three standards share their structure deliberately. A contractor with a quality system can run one document control procedure, one internal audit procedure, one management review and one corrective action process for all three. The mistake is to buy three systems from three sources and run them in parallel; the audit will find three document registers and three versions of the same procedure, and the workforce will ignore all of them. Build the OH&S system alongside the quality system and add only what is specific to health and safety.

What a bought-in system can and cannot do

A documented system bought off the shelf gives you the manual, the procedures, the forms and the registers, written to the clause structure so that the gap between what you have and what the standard wants is visible on day one. It cannot give you the records, the consultation, the audits or the management review; those have to be lived for at least three months before a certification body will look at them. It cannot give you certification: only a UKAS-accredited certification body can, after a stage 1 and stage 2 audit. And it cannot replace the site-level documents you already need under CDM and MHSWR: the RAMS, permits, inspection registers and induction pack are the operational layer, and the management system sits above them and points at them.

What to look for in a bought-in system: procedures written for construction rather than for a factory; a legal register pre-populated with the UK construction instruments; the clause map, the gap analysis and the audit checklist derived from the same list so they agree with each other; worked entries in every register; and an explicit statement of what has been verified against the primary source and what has not.

A construction ISO 45001 system, written to sit on top of the site H&S pack

The StructAssure ISO 45001 Construction OHSMS is 45 documents: an OH&S manual with a 40-row clause map to ISO 45001:2018, the policy written to HSWA section 2(3) and clause 5.2, 18 procedures from hazard identification to health surveillance and fitness for work, 12 forms, 10 Excel registers including a legal register pre-populated with 32 UK instruments, a KPI tracker that calculates AFR and LTIFR, an 86-question internal audit checklist, a gap analysis tool with automatic scoring and a 90-day implementation roadmap. It cites the Site Health & Safety Pack's permits, RAMS templates and inspection registers by code rather than duplicating them. Native Word and Excel, unlocked, single-company licence. £995.

The operational layer it points at is the Site Health & Safety Pack (£295): 45 documents including ten permits, RAMS with worked examples, COSHH, noise and HAVS assessments and twelve inspection registers.

Certification note: these documents support your route to certification. They do not confer it. ISO 45001 certification can only be granted by an accredited certification body following audit. Written by StructAssure Ltd, a chartered construction assurance practice (MCIOB, CQP MCQI, MAPM).