Whenever an international management standard is revised, organisations tend to respond predictably. A gap analysis is commissioned, procedures are reviewed, training is scheduled and document owners begin replacing references to the previous edition. That work may be necessary. But it can also become a convenient distraction.

ISO 45001 is undergoing its first revision since publication in 2018. The revised standard has reached the Draft International Standard stage, with the international ballot and comment period closing on 9 August 2026.[1]

The immediate question for many organisations will be: “What do we need to change?” There is a more important question:

Has our safety management system ever delivered what the existing standard requires?

Before examining what is changing

ISO 45001:2018 already contains substantial expectations concerning leadership, worker participation, proactive hazard identification, management of change, contractors, outsourced work and the evaluation of safety performance.[2] These are not peripheral requirements. Clause 5 requires leadership and commitment from top management. It also requires consultation and participation processes that give workers timely access to information, remove barriers to participation and involve non-managerial workers in decisions affecting health and safety.

That is considerably more demanding than conducting an annual engagement survey or inviting workers to attend a safety meeting. The practical test is whether workers can influence how risks are understood and controlled. It is whether they can raise concerns without being dismissed, disadvantaged or told that the procedure has already been approved.

Clause 6 requires hazard identification to be ongoing and proactive. The existing standard already directs organisations to consider how work is organised, including workload, working hours, harassment, leadership and organisational culture. In other words, psychosocial and organisational risks were not absent from the 2018 standard. The question is whether organisations genuinely incorporated them into their risk picture.

Many did not. They continued to maintain registers dominated by physical hazards while workload, conflicting priorities, production pressure, poor supervision and deteriorating decision-making remained outside the formal safety system.

The standard already expects change to be controlled

Clause 8 requires organisations to manage planned temporary and permanent changes that may affect health and safety. This is particularly important because risk controls are often designed for a stable version of work. The procedure describes the equipment, workforce, supervision and operating conditions that existed when the assessment was completed.

Actual work does not remain stable. Technology changes. Experienced workers leave. Contractors are introduced. Rosters are altered. Maintenance is deferred. Production targets increase. Software begins allocating work or recommending decisions. A temporary workaround gradually becomes the accepted method.

A management system can remain fully documented while the work it was designed to control changes around it. If the management-of-change process only captures major engineering projects, it may miss the accumulation of smaller operational changes that progressively weaken a control.

Outsourcing does not outsource the risk

The 2018 standard also requires organisations to control procurement, contractor activities and outsourced functions. This matters because organisations often confuse contractual allocation with operational control. A contract may state that a supplier is responsible for safety, but that does not establish whether the supplier has the resources, competence, authority or information required to perform the work safely. Nor does it demonstrate how interfaces between the organisation and the contractor are being managed.

The most serious risks frequently sit between organisational boundaries: between the asset owner and maintainer, principal contractor and subcontractor, scheduler and driver, designer and operator, or head office and the people performing the work. A contract can allocate responsibility. It cannot make a critical control effective.

What the proposed revision appears to strengthen

Current summaries of the Draft International Standard indicate that the revision will broaden and clarify several areas rather than replace the existing framework.[3] The proposed changes reportedly include stronger or more explicit consideration of:

  • new and changing technologies;
  • digital platform-based work;
  • remote workers;
  • psychosocial and occupational health hazards;
  • climate-related impacts;
  • worker diversity;
  • work-related wellbeing;
  • return to work following injury or illness; and
  • externally provided processes, products and services.

These proposed changes remain subject to the ISO ballot and subsequent drafting process. They should not yet be presented as final requirements. Nevertheless, the direction is clear. The risk picture is becoming broader.

A safety system cannot remain focused only on visible physical hazards while the organisation introduces algorithmic decision-making, remote supervision, contingent labour, changing weather conditions and increasingly complex contractor arrangements. Nor can occupational health be treated as a collection of health-promotion activities disconnected from how work is designed and managed.

The certification trap

Certification can provide useful independent assurance that a management system conforms to specified requirements. It cannot, by itself, prove that a critical control will work when needed. An audit may confirm that a procedure exists, that workers have completed training and that inspections were recorded. Those findings do not necessarily establish that the control is technically capable, available, used correctly and resilient under abnormal operating conditions.

That distinction matters to boards and officers. The governance question is not simply whether the organisation has an ISO 45001-certified system. It is whether leaders receive reliable information about the effectiveness of the controls protecting people from the organisation’s most serious risks.

A high-performing system should be capable of showing:

  • which controls prevent or mitigate each critical risk;
  • who is accountable for each control;
  • what performance standard the control must achieve;
  • how its effectiveness is verified;
  • what happens when the control is unavailable or degraded;
  • whether information from workers changes management decisions; and
  • how control failures and weak signals are escalated to executives.

If the organisation cannot answer those questions, updating the management-system manual will not address the underlying weakness.

Audit the effectiveness of the controls

The ISO 45001 revision creates an opportunity, but only if organisations resist reducing it to a compliance project. A useful review should begin with the work, not the documents.

Select the organisation’s most serious risks. Identify the controls relied upon to prevent a fatality or life-altering harm. Observe how those controls are used under normal and difficult conditions. Speak with the people who depend upon them. Examine what happens during contractor work, staff shortages, equipment failure, production disruption and changes in operating conditions.

Then compare that evidence with what the management system says should happen. The gap between those two pictures is where the most valuable learning will be found.

The question for leaders

The revised standard will eventually require organisations to review their systems, documentation and certification arrangements. Boards and executives should use the opportunity to ask something more consequential:

Does our safety management system help us understand whether the controls protecting people are effective, or does it mainly help us demonstrate that the required documents exist?

The standard is changing. The more important question is whether the organisation is prepared to change how it understands, verifies and governs safety.

This article provides general information. The proposed ISO 45001 revision remains subject to the ISO ballot and subsequent drafting process; the final requirements may change.

References

  1. ISO/TC 283, “ISO 45001 Revision Reaches Draft International Standard Ballot Stage”, 18 June 2026. The ballot and comment period closes on 9 August 2026.
  2. International Organization for Standardization, ISO 45001:2018, Occupational health and safety management systems: Requirements with guidance for use. Relevant provisions include clauses 5.1, 5.4, 6.1.2.1, 8.1.3, 8.1.4, 9.1 and 9.3.
  3. DNV, “Revision ISO 45001: Occupational Health & Safety Management System”, summary of proposed changes in ISO/DIS 45001. The draft may change before reaching the Final Draft International Standard stage.
  4. International Organization for Standardization, ISO 45001:2018/Amd 1:2024, Climate action changes.