Guide · ISO 45001 · 7 September 2026

ISO 45001 Certification: the Process, Step by Step

ISO 45001 certification is the step by step: the gap analysis, the system design, the implementation, the internal audit, the management review, the stage 1, the stage 2, and the certificate. This guide is the certification process in working form — the step, the time, the evidence, and the certificate: the map from the decision to the certificate, and the certificate to the recertification.

ISO 45001 Certification: the Process, Step by Step — HSE guide
The bottom line: The ISO 45001 certification is the step by step: the gap analysis, the system design, the implementation, the internal audit and the management review, the stage 1 (the document review), the stage 2 (the on-site), the certificate (the three years), the surveillance (the year one, the year two), and the recertification (the year three). The step runs the gap to the certificate, and the certificate runs the international.

The decision, and the certification body

The certification starts with the decision of the top management — the clause 5 (the leadership). The top management that decides to certify commits the resource: the time, the budget, the person who owns the system. The decision is the why — the client, the tender, the international market, or the system itself.

The certification body is the accredited one: the UKAS in the UK, the ANAB in the US, the JAS-ANZ in the Australia. The certification body works to the ISO/IEC 17021-1 (the requirement for the certification body) and the IAF MD 6 (the OHS scheme), and the mutual recognition (the IAF MLA) is what makes the certificate accepted across the border. The site selects the certification body on the scope, the time, and the cost.

The steps: the gap to the certificate

Step 1 — the gap analysis: the clause by clause, the current state against the standard, and the gap. The gap is the plan, and the plan is typically the 90 days. Step 2 — the system design: the manual, the policy, the risk register, the legal register, the procedure, the objective. The system is the clause, and the clause is the evidence. Step 3 — the implementation: the risk assessment on the floor, the permit to work, the training record, the near-miss log.

Step 4 — the internal audit and the management review: the clause 9.2 (the internal audit) and the clause 9.3 (the management review) — the system checks itself before the external one arrives. Step 5 — the stage 1 and the stage 2: the document review, then the on-site. Step 6 — the certificate: valid for three years, with the surveillance in the year one and the year two.

Stage 1 and Stage 2: the two audits

The stage 1 is the document review — the auditor reads the system: the manual, the policy, the risk register, the legal register, the procedure, the objective — and checks the readiness. The stage 1 finding is the gap that has to be closed before the stage 2. The stage 1 answers the question: is the system there?

The stage 2 is the on-site — the auditor walks the site, interviews the worker, and checks the evidence: the risk assessment, the permit, the training, the near-miss log. The stage 2 answers the question: is the system working? The certificate follows the stage 2 — subject to the major nonconformity, which has to be closed before the certificate is issued.

The certificate: valid for three years

The certificate is valid for three years. The year zero is the stage 1 and the stage 2 — the initial certification. The year one and the year two are the surveillance. The year three is the recertification — the full audit again, and the new certificate.

The certified site is listed in the public register of the certification body, and the register is the proof the client, the tender, and the customer can check. The certificate is the recognition: the client, the contract, the international market.

Surveillance and recertification: the cycle

The surveillance is the year one and the year two — the shorter audit that checks the system is still working. The surveillance checks the management review (the annual), the internal audit (the programme), the objective (the progress), the nonconformity (the closed), and the change (the re-assessment). The surveillance is the spot-check — the clause that has moved, not the full system.

The recertification is the year three — the full audit again, the stage 1 and the stage 2, and the new certificate. The cycle repeats every three years. The site that keeps the system alive between the audit is the site that passes the recertification without the pain.

Practical use of iso 45001 certification: the process, step by step in the workplace

How to Get ISO 45001 Certified (the Path in Six Steps)

The path to the certificate runs six steps: 1 the gap analysis against the clauses; 2 the system built to close the gap — the policy, the risk assessment, the objectives, the procedure, the emergency plan; 3 the internal audit and the management review; 4 the stage 1 audit (the document review, the readiness); 5 the stage 2 audit (the on-site, the evidence, the interview, the walk); and 6 the certificate, valid for three years, with the surveillance in year one and year two and the recertification in year three. The certification body is the accredited one — the UKAS or the equivalent — and the choice is on the first guide on this page.

Need the sign-off, not just the guide?

The guide is the preparation; the sign-off is the professional. For the ISO 45001 implementation and audits, the RIDDOR and CDM work, the statutory assessments and the training that comes with them, ask Muhammad Umer — 8+ years across Iraq, KSA and Pakistan, and the programme runs through umer-hse.pro. One message gets the written scope.

Common questions

ISO 45001 Certification — answered

What is the ISO 45001 certification process?

The step by step: the gap analysis, the system design (the manual, the policy, the risk register, the legal register, the procedure), the implementation (the risk assessment, the permit, the training, the near-miss log), the internal audit and the management review (the clause 9.2 and the clause 9.3), the stage 1 audit (the document review), the stage 2 audit (the on-site), and the certificate. Then the surveillance (the year one, the year two) and the recertification (the year three).

How long does ISO 45001 certification take?

Typically 9 to 18 months, from the decision to the certificate. The time depends on the site, the scope, and the readiness. The site that already runs a working system is the 9 months; the site that starts from zero is the 12 to 18.

How much does ISO 45001 certification cost?

The three parts: the certification body (the audit fee, quoted by the site-day), the consultant (the optional — the gap analysis, the system design), and the internal resource (the time of the person who implements). The cost varies by the site, the scope, and the country. The certification body quotes the audit fee; the consultant quotes the project; the internal cost is the time.

Who can certify ISO 45001?

Only the accredited certification body: the UKAS in the UK, the ANAB in the US, the JAS-ANZ in the Australia. The accreditation is what makes the certificate recognised, and the IAF mutual recognition is what makes it international. The site selects the certification body on the scope, the time, and the cost.

What is the difference between certification and registration in ISO 45001?

The certification is the external audit — the stage 1 and the stage 2 by the certification body, and the certificate that follows. The registration is the public record — the listing of the certified site in the register of the certification body. The certified site is the one the register shows; the registration is the proof the client can check.

Do you need a consultant for ISO 45001?

No — the consultant is the optional. The site that has the internal competence (the HSE manager, the ISO 45001 lead auditor) can run the system design and the implementation itself. The consultant buys the speed — the gap analysis and the system design, faster. The site that does it in-house takes longer, but the system stays with the people who run it.

Safety disclaimer

The guides on this site are practical guidance, built to the UK baseline with the US equivalents named in the text. They do not replace a competent person assessment for high-risk work, a statutory assessment, or the advice of your insurer. Where a duty has legal force — the RIDDOR report, the CDM plan, the ISO 45001 system — the responsible person or the responsible owner carries it. Read the guide as the preparation, and take the sign-off from the competent person.