Morgan Compliance Group
ISO 45001 Health and Safety Management Support
Practical support to implement, improve or integrate an ISO 45001 occupational health and safety management system. We help businesses strengthen leadership, involve workers, identify hazards, manage risks and opportunities and establish proportionate controls that improve health and safety performance through normal operations.
Book a Free ConsultationLast updated: 27 September 2026
Who this service is for
Businesses seeking first ISO 45001 certification, improving an existing occupational health and safety management system, preparing for surveillance or recertification audits, responding to audit findings or integrating health and safety management with ISO 9001 or ISO 14001.
Common reasons to act
- A customer, framework or tender requires ISO 45001 certification
- Health and safety responsibilities, controls or performance measures are unclear
- Worker consultation and participation arrangements need strengthening
- Incidents, recurring hazards or inconsistent controls indicate weaknesses in the existing system
- Contractor, procurement or outsourced-activity controls require improvement
- An internal, customer or certification audit has identified findings
- Separate quality, environmental and health and safety systems need integrating
What you receive
- A written gap analysis against the applicable published ISO 45001 requirements
- A defined occupational health and safety management-system scope and prioritised implementation plan
- A review of leadership responsibilities and worker consultation and participation arrangements
- Support establishing systematic hazard identification and assessment of OH&S risks and opportunities
- Support identifying legal and other requirements and establishing a controlled register and evaluation process
- Support establishing OH&S objectives, performance measures and improvement plans
- Proportionate operational controls covering the hierarchy of controls, change, procurement, contractors and outsourced activities where applicable
- Support with emergency preparedness, incident reporting, investigation and corrective action
- Internal audit, management-review and certification-readiness support
- A practical maintenance plan for monitoring, review and continual improvement
Consultancy fees depend on the organisation’s size, locations, risk profile, operational complexity, existing arrangements, certification status and required timetable. Certification-body application, audit, surveillance, recertification and certificate fees are paid separately by the client.
View the Pricing GuidePractical support
How Morgan Compliance Group can help
We begin by defining the intended scope, organisational context, interested parties and current health and safety arrangements.
A gap analysis is then used to review:
- leadership
- worker consultation and participation
- hazard identification
- OH&S risks and opportunities
- legal and other requirements
- objectives
- competence
- operational controls
- management of change
- procurement
- contractors
- outsourced activities
- emergency preparedness
- monitoring
- incident investigation
- corrective action
- documented information
- internal audits
- management review
- certification preparation
The system is built around genuine risks and day-to-day activities rather than becoming a separate collection of documents.
Our consultancy supports, but does not replace, your legal health and safety duties. Advice is given within the agreed scope and relies on accurate information from you. Accreditation and certification decisions are made independently by the relevant bodies. See our Terms of Service for full details.
How the process works
Define the scope
Confirm the intended scope, locations, activities, interested parties, certification status, objectives and required timetable.
Assess hazards and requirements
Review existing arrangements, hazards, OH&S risks and opportunities, legal and other requirements and performance information against the applicable requirements.
Implement and involve
Agree priorities, develop proportionate controls and documented information and help embed responsibilities, worker participation, operational controls and performance records.
Audit and prepare
Complete internal audit and management-review activities, address corrective actions and prepare the organisation for independent certification assessment.
Frequently asked questions
What is ISO 45001 and is it suitable for our business?
ISO 45001 specifies requirements for an occupational health and safety management system. It can be used by organisations of different sizes and sectors to manage OH&S risks, improve performance, involve workers and provide a structured approach to continual improvement.
What is the current edition of ISO 45001?
ISO 45001:2018 remains the current published edition and is supplemented by Amendment 1:2024 concerning climate-action considerations. A revised standard is under development and has reached Draft International Standard stage, but the draft is not a published certification requirement and no formal transition programme to it currently exists.
What does the climate-action amendment require us to consider?
The amendment requires organisations to consider whether climate change is a relevant issue within their context and recognises that interested parties may have climate-related requirements. The significance and resulting action depend on the organisation, its activities, workforce and operating environment.
Is ISO 45001 certification compulsory?
Certification is generally voluntary, but it may be required by a customer, tender, framework, contract or supply-chain arrangement. An organisation can implement ISO 45001 without seeking certification where its objective is improved health and safety management rather than an external certificate.
Does ISO 45001 certification guarantee legal compliance or replace a competent person?
No. Certification may support a structured approach to managing legal requirements but does not prove that every legal duty is being met at all times. Employers remain legally responsible for controlling health and safety risks and must ensure suitable competent health and safety assistance is available in accordance with their legal duties. Certification does not transfer or remove those duties.
How are workers consulted and involved?
Workers and, where they exist, worker representatives should be consulted on relevant health and safety matters and enabled to participate in developing, implementing and improving the management system. Arrangements should reflect the workforce, work activities, risks, communication needs and any barriers to effective participation.
How does ISO 45001 address hazards and risk control?
The system requires a planned method for identifying hazards, assessing OH&S risks and opportunities and selecting suitable controls. Risk reduction should follow the hierarchy of controls, prioritising elimination and more effective control measures before relying on administrative controls or personal protective equipment.
How does ISO 45001 apply to contractors and outsourced activities?
The organisation must establish proportionate controls for procurement, contractors and outsourced activities where they affect its occupational health and safety performance. The controls depend on the work, risk, contractual arrangements and degree of control or influence available.
Can we use our existing health and safety documents and integrate the system with other standards?
Yes. Existing policies, risk assessments, procedures, registers and records are reviewed first and retained where suitable. ISO 45001 can also be integrated with ISO 9001 or ISO 14001 through shared arrangements for leadership, documented information, competence, audit, management review and corrective action while retaining the requirements specific to occupational health and safety.
What are internal audits and management reviews?
Internal audits assess whether the occupational health and safety management system conforms to planned arrangements and applicable ISO 45001 requirements and whether it is operating effectively. Management review is senior management’s formal evaluation of OH&S performance, incidents, worker consultation and participation, legal compliance, objectives, audit results, organisational changes, risks and opportunities and improvement needs.
How long does implementation take and can you guarantee certification?
Timescales depend on the organisation’s size, locations, hazards, risk profile, operational complexity, available resources, existing controls and required certification date. Morgan Compliance Group can help identify gaps, implement proportionate arrangements and prepare for assessment but cannot guarantee certification.
Should we use a UKAS-accredited certification body and what happens after certification?
Where recognised accredited certification is required, the certification body should hold suitable UKAS accreditation for ISO 45001 and the relevant technical scope, or equivalent recognised accreditation. Following certification, the organisation must continue operating, auditing, reviewing and improving its system and will normally undergo surveillance and later recertification audits.
Related guidance
Not Sure Where to Start?
Book a free consultation and explain what your business is trying to achieve. Morgan Compliance Group will help identify the most practical next step.
Book a Free Consultation
