ISO 45001 comes up constantly in Australian workplace health and safety conversations, but most explanations stop at “it’s the international standard for OH&S management systems” and leave out the part that actually affects day-to-day operations: what it means for the people and businesses you buy from. This guide covers both — the standard itself, what changed when it replaced AS/NZS 4801, and the practical implications for how you select and manage suppliers once your organisation is certified.
What is ISO 45001?
ISO 45001:2018 is the international standard for occupational health and safety (OH&S) management systems, published by the International Organization for Standardization in March 2018. It sets out requirements for building a systematic framework to identify workplace hazards, manage risk, and continually improve safety performance — rather than prescribing specific safety procedures for specific tasks.
It replaced OHSAS 18001, the previous international OH&S management standard, with a formal migration window running from 2018 to September 2021 (extended to account for COVID-19 disruption to audit schedules). In Australia, it’s adopted directly as AS/NZS ISO 45001:2018, superseding the old Australian/NZ standard AS/NZS 4801.
Like ISO 9001 (quality) and ISO 14001 (environment), ISO 45001 follows the common “High Level Structure” (Annex SL) that all modern ISO management-system standards share. That’s a deliberate design choice: it means an organisation already certified to ISO 9001 or ISO 14001 can integrate an OH&S system into the same management framework rather than running a completely separate one.
What actually changed from AS/NZS 4801
AS/NZS 4801 hasn’t disappeared from every conversation — you’ll still see it referenced in older contracts and some legacy documentation — but it’s been superseded, and the changes ISO 45001 introduced are more than a rename. Based on the standard’s own stated intent and the certification-body guidance we cross-checked, the practical shifts are:
- Leadership commitment is more prominent and demanding. Top management now has direct, named accountability for the OH&S system rather than being able to delegate it entirely to a safety manager.
- Worker participation is stronger and more structured. Consultation with workers (and, where they exist, worker representatives) is now a built-in requirement across planning, not an afterthought.
- “Context of the organisation” is now explicit. You’re required to actually document the internal and external issues, and the interested parties (regulators, clients, insurers, suppliers), that affect your OH&S system — not just infer them.
- Risk-based thinking is more integrated and systematic, extending beyond physical hazard identification to include organisational and operational risk.
- Audit and continual-improvement rigour is more structured, with clearer expectations for how findings feed back into the system.
For a business already running a solid AS/NZS 4801 system, this is generally a gap-closing exercise — reviewing what you have against the new requirements and strengthening specific areas — rather than a rebuild from scratch. Most of the core safety work (hazard identification, risk assessment, incident investigation) carries across largely unchanged.
How the standard is structured
ISO 45001 has ten numbered clauses. The first three (Scope, Normative references, Terms and definitions) are introductory and don’t themselves impose requirements. The seven clauses that do — sometimes referred to informally as the standard’s “core elements” — are:
- Clause 4 – Context of the organisation
- Clause 5 – Leadership and worker participation
- Clause 6 – Planning (risks, opportunities, objectives)
- Clause 7 – Support (resources, competence, communication, documented information)
- Clause 8 – Operation (operational planning and control, including procurement, contractors and outsourcing)
- Clause 9 – Performance evaluation (monitoring, internal audit, management review)
- Clause 10 – Improvement (incident investigation, corrective action, continual improvement)
This is where our angle differs from most ISO 45001 explainers online: Clause 8 is the one that reaches outside your own organisation and into your supply chain — and it’s the part most generic guides skate past.
What Clause 8 means for your suppliers
Clause 8.1.4 of ISO 45001 requires a certified organisation to control the OH&S risk created by “externally provided processes, products and services” — in plain terms, the things and people you bring in from outside. That covers three related areas: procurement, contractors working on your site, and any outsourced processes.
If your business is certified (or working towards certification), that obligation doesn’t stop at your own front gate. It extends to the safety equipment, PPE, tools and consumables you procure, and to the suppliers you procure them from. In practice, certification bodies and auditors typically expect to see evidence that you’re actively managing this, not just assuming your suppliers have it covered.
Some practical things worth checking with any supplier of safety equipment, PPE or industrial consumables, whether or not you’re formally certified:
- Does the product meet the relevant AS/NZS standard for its category (footwear, eyewear, hearing protection, fall protection, etc.), and can the supplier point to that rather than just asserting it?
- Can the supplier provide current Safety Data Sheets for chemical products, and product documentation you can file as part of your own records?
- Does the supplier have consistent stock and lead times for safety-critical items — a stock-out on PPE or lockout/tagout gear is itself an OH&S risk if it forces a workaround?
- Is there a real point of contact if a product is recalled or a compliance issue is identified, rather than a generic sales inbox?
Getting certified in Australia
ISO 45001 certification in Australia is carried out by third-party certification bodies accredited (in most cases) through JAS-ANZ, the joint Australia–New Zealand accreditation authority. The typical path is a gap analysis against your existing system, closing identified gaps, then a two-stage external audit (a documentation review followed by an on-site assessment) before certification is granted, with periodic surveillance audits afterwards to maintain it.
Cost and timeframe vary significantly with organisation size, number of sites, and how much of the system already exists — there isn’t a meaningful single figure to quote, and we’d treat any guide that gives you one specific number with some scepticism. Certification bodies and WHS consultancies can provide a scoped quote based on your actual organisation.
Frequently Asked Questions
What is the ISO 45001 standard for?
It’s the international standard for occupational health and safety management systems — a framework for identifying workplace hazards, managing risk, and continually improving safety performance, rather than a set of task-specific safety rules.
Is ISO 45001 certification available in Australia?
Yes. It’s adopted in Australia as AS/NZS ISO 45001:2018, and certification is available through third-party certification bodies, most commonly accredited through JAS-ANZ, the Australia–New Zealand joint accreditation authority.
What does ISO 45001 replace?
Internationally, it replaced OHSAS 18001. In Australia and New Zealand specifically, it replaced AS/NZS 4801, with a transition period running from 2018 to September 2021.
How much does ISO 45001 certification cost?
There’s no fixed published figure — cost depends on organisation size, number of sites, industry risk profile, and how much of a compliant system already exists. Certification bodies quote based on a scoping conversation, not a standard price list.
What are the 10 clauses of ISO 45001?
Scope, Normative references, and Terms and definitions (clauses 1–3, introductory only), followed by the seven requirement clauses: Context of the organisation (4), Leadership and worker participation (5), Planning (6), Support (7), Operation (8), Performance evaluation (9), and Improvement (10).
What are the 7 elements of ISO 45001?
This usually refers to the seven clauses that carry actual requirements — clauses 4 through 10 above — as distinct from the three introductory clauses that don’t.
What are the 6 mandatory procedures in ISO 45001?
This phrase gets used loosely online, but it’s worth being precise: ISO 45001, like other modern ISO management-system standards, doesn’t mandate a fixed list of named “procedures” the way older standards did. It requires “documented information” in specific places instead — including the OH&S policy, objectives, the legal and other-requirements register, the risk assessment methodology, and incident investigation records. If you’ve seen a specific “6 mandatory procedures” list elsewhere, treat it as one training provider’s summary rather than a defined term in the standard itself.
Is ISO 45001 the same as AS/NZS 4801?
No — ISO 45001 (adopted in Australia as AS/NZS ISO 45001:2018) superseded AS/NZS 4801. It carries over the core intent but strengthens leadership accountability, worker participation, organisational context, and risk-based thinking, and aligns the structure with other ISO management-system standards.
Do I need ISO 45001 certification to sell to certified companies?
Not necessarily — certification isn’t usually a blanket legal requirement for suppliers. But a certified customer’s own obligations under Clause 8.1.4 mean they may reasonably ask about your safety documentation, product compliance, and processes as part of their own due diligence, whether or not you’re certified yourself.
What industries benefit most from ISO 45001?
It applies to organisations of any size or sector, but ISO itself flags higher-risk industries — construction, manufacturing, mining, oil and gas, and agriculture — as where the framework tends to deliver the clearest impact, simply because the underlying risk exposure is higher.
Does ISO 45001 apply to small businesses?
Yes — the standard is written to scale to organisations of any size. A small business’s system will look proportionally simpler than a multinational’s, but the same clause structure applies.
How long does ISO 45001 certification last?
A certification cycle typically runs three years, with periodic surveillance audits (usually annual) in between to confirm the system is still being maintained, followed by a recertification audit at the end of the cycle.

