ISO 45001:2018 Explained: What Building Inspection Professionals Need to Know

If you work in building inspections, facilities management, or occupational health and safety, ISO 45001:2018 is a standard you need to understand. Whether your organisation is pursuing certification or you simply want to align your practices with international best practice, this guide breaks down what ISO 45001 is, how it is structured, and what sets it apart from what came before.
What Is ISO 45001?
ISO 45001:2018 is the international standard for occupational health and safety (OHS) management systems. It provides a framework that enables organisations to identify hazards, minimise risks, and improve occupational health and safety performance to provide a safe and healthy workplace.
The standard replaced the older OHSAS 18001 framework, bringing occupational health and safety in line with the same high-level structure used by other ISO management system standards such as ISO 9001 (quality) and ISO 14001 (environment). This shared structure makes it considerably easier for organisations that already hold one ISO certification to integrate an OHS management system alongside it.

The Business Case for OHS Management
Before diving into the structure, it is worth understanding why organisations invest in formal OHS management systems. Research spanning the last 15 to 20 years consistently shows that for every pound invested in a safety management system, the return to the organisation ranges from two to seven times that amount, depending on the organisation's size and context.
The motivation behind implementation also matters. Organisations that pursue OHS management purely to satisfy a customer requirement tend to do the bare minimum. Those driven by a genuine management commitment to improving health and safety outcomes are far more likely to succeed in building a culture of improved performance and worker engagement.
For building inspection professionals, this is particularly relevant. The properties and sites you inspect are only as safe as the management systems behind them. Understanding ISO 45001 helps you evaluate whether an organisation has a robust, proactive approach to safety or is merely ticking boxes.
Complete building inspections 3x faster with AI
AnyInspect uses AI to transcribe walkthroughs, extract key findings, and auto-generate compliant inspection reports.

The 10-Clause Structure
ISO 45001 follows the Annex SL high-level structure, which all ISO management system standards now share. This means 10 standardised sections with common terminology and definitions across standards.
The structure follows the familiar Plan-Do-Check-Act (PDCA) cycle:
Clause 1: Scope
This defines the intent of the standard itself (not your organisation's management system scope, which is covered separately). The standard's purpose is to enable organisations to identify hazards, minimise risks, and improve OHS performance.
Clause 2: Normative References
Unlike some other ISO standards, ISO 45001 does not have external normative references. All the terms and definitions needed to use the standard are contained within the document itself.
Clause 3: Terms and Definitions
Key definitions that underpin the standard include:
- Interested party: Any person or organisation that can affect, be affected by, or perceive itself to be affected by a decision or activity. This includes workers, employers, customers, regulators, neighbours, and even competitors.
- Participation: Involvement in decision-making. This is a mandatory requirement of the standard.
- Consultation: Seeking views before making a decision. Also mandatory, and primarily relates to workers.
- Hazard: A source with the potential to cause injury or ill health.
- Risk: The effect of uncertainty. In OHS terms, risk is typically assessed based on the likelihood of something happening combined with the severity of potential injury or harm.
- Opportunity: A circumstance or set of circumstances that can lead to improvement of OHS performance.
Understanding the distinction between hazard and risk is fundamental. The same activity can carry vastly different levels of risk depending on context. Operating a forklift, for example, carries lower risk for an experienced operator who knows the facility layout than it does for a new employee who is unfamiliar with the premises. Your controls need to reflect that context.
Clause 4: Context of the Organisation
This is one of the most significant additions in ISO 45001 and contains three crucial new requirements:
4.1 External and Internal Issues
Organisations must identify external issues (supplier reliability, market conditions, regulatory changes, extreme weather) and internal issues (management capability, IT security, workplace culture, equipment condition, communication effectiveness). These issues feed directly into planning.
A key insight is that risk and opportunity go hand in hand. A regulatory change, for example, is a risk if you are unprepared, but it is an opportunity if you are an early adopter who can get ahead of competitors.
4.2 Needs and Expectations of Interested Parties
You must determine who your interested parties are and what they need. Workers are the primary interested parties, but the list extends to owners, customers, regulators, the community, and others. This is a dynamic activity; perceptions and needs change over time, so your context assessment must be kept current.
4.3 Scope of the Management System
The scope must include all activities, products, and services within the organisation's control or influence that may impact OHS performance. Importantly, the standard discourages "de-scoping" difficult or costly elements. You cannot simply exclude a site, a function, or a group of workers because they are inconvenient. Doing so will compromise your certification and undermine the value of the management system.
Clause 5: Leadership and Worker Participation
This is one of the most important clauses in the standard. Certain actions must be taken by top management personally and cannot be delegated. Top management must:
- Develop, lead, and promote a culture that supports effective OHS management
- Be visibly engaged in health and safety matters
- Take accountability and responsibility
- Ensure adequate resources are provided
- Demonstrate evidence of consultation and participation at all levels
The focus on organisational culture is a standout requirement. It is no longer acceptable for health and safety to be the sole responsibility of one practitioner while senior leadership remains disengaged. The standard demands visible, evidenced engagement from the top.
The OHS policy must now include specific commitments to:
- Eliminate hazards and reduce OHS risks
- Support workers through consultation and participation
Responsibilities must be assigned and communicated at all levels and functions, from the chief executive through line managers and down to every worker.
Clause 6: Planning
With all the contextual information gathered from the earlier clauses, planning is where the work truly begins. This includes:
- Hazard identification: Ongoing and proactive, not a one-off exercise
- Risk assessment: Evaluating identified hazards in context
- Identifying opportunities: Looking for chances to improve, not just mitigate
- Determining legal requirements: Maintaining a process to stay informed of regulatory changes, not just reviewing annually
- Setting objectives: These must be specific, measurable, and accompanied by clear plans stating who is responsible, what resources are needed, what the timelines are, and how success will be measured
A vague objective like "improve our injury rate" is not adequate. A well-planned objective identifies the specific problem (e.g. cuts and lacerations from a particular process), investigates root causes, implements targeted controls, and measures the outcome against a defined baseline.
Clause 7: Support
This covers resources, competence, awareness, communication, and documented information. Communication requirements are enhanced compared to the predecessor standard, and the terminology around documentation has changed:
- Maintained documented information = procedures (how you do things)
- Retained documented information = records (evidence of what you have done)
Clause 8: Operations
Two notable additions:
- Management of change now has its own dedicated section, reflecting the importance of identifying risks and opportunities whenever changes occur
- Procurement is specifically addressed, with requirements for managing contractor and outsourced function risks
Clause 9: Performance Evaluation
Monitoring must include both proactive (leading) and reactive (lagging) indicators. Reactive indicators such as accident rates are valid but insufficient on their own. Proactive indicators include:
- Workplace inspections and safety tours
- Internal and external audits
- Training programme completion rates
- Safety meeting frequency and quality
- Engagement in OHS campaigns and well-being programmes
- Proactive maintenance schedules for premises and equipment
For building inspection professionals, this is directly relevant. The inspections you carry out can serve as proactive indicators within an organisation's OHS management system.
Clause 10: Improvement
Key changes include:
- Preventive action as a standalone concept has been removed in favour of risk-based thinking that permeates the entire standard
- Worker participation is required in incident investigation, nonconformity identification, and corrective action processes
- Continual improvement has been given significantly more prominence. The concept appears 36 times in ISO 45001, compared with 18 times in its predecessor
Integration with Other Management Systems
One of the practical advantages of ISO 45001's structure is its compatibility with other ISO management systems. If your organisation already operates ISO 9001 (quality) or ISO 14001 (environment), you will find that 40 to 60 percent of the concepts are closely aligned.
Shared mechanisms such as legal registers, incident reporting systems, nonconformity and corrective action processes, and internal auditing can all be utilised across multiple standards. This integrated approach delivers a consistent and efficient path to compliance while saving time, effort, and resources.
Why This Matters for Building Inspections
As a building inspection professional, understanding ISO 45001 gives you:
1. A framework for evaluating safety culture: When you inspect a site, you can assess whether leadership is genuinely engaged or merely delegating safety responsibilities downward.
2. Context for risk assessment: The standard's approach to hazard identification and risk-based thinking aligns directly with how building inspectors evaluate premises, from fire risk assessments to health and safety compliance reviews.
3. Credibility with clients: Many property managers and facilities operators are pursuing or maintaining ISO 45001 certification. Speaking their language and understanding their management system builds trust and demonstrates professional competence.
4. A proactive inspection mindset: ISO 45001 emphasises proactive, ongoing hazard identification rather than reactive responses to incidents. This aligns perfectly with the purpose of regular building inspections as a preventive measure.
Whether you are conducting fire risk assessments, HHSRS inspections, health and safety audits, or general building surveys, the principles of ISO 45001 provide a solid foundation for understanding how organisations should be managing the safety of their premises and the people within them.
