Skip to main content
What must be documented series - #3 – ISO45001

What must be documented series - #3 – ISO45001

| admin | Blog

This is the third in my series about minimum documentation requirements for ISO standards. 

ISO45001 is all about Health and Safety.  It’s about saving lives, reducing accidents, and if you need documents to do that well, you just get them in place.

There are times, though, when people stop doing the right thing because of unnecessary paperwork.  Doing it their own way, ‘in case Health and Safety find out’.  And a common misconception is that ISO45001 adds to this demand for documentation.  It doesn’t.

In episode #1 of this series my focus was on ISO9001, episode #2 was ISO14001 and now I look at ISO45001.

Like ISO9001:2015 and ISO14001:2015, ISO45001:2018 now only refers to documented information.  There is no longer any reference to documented procedures, records, documentation or a manual.  Largely it is up to the individual organisation what they require.

Again, like ISO9001 & ISO14001, documented information has two prefixes in ISO45001:2018.  Where is says ‘maintain’ documented information, this means that the organisation needs to have a written document in place. 

ISO45001:2018 has thirteen times in where this is the case. 

Three of these are clear, in that the organisation must have a documented Scope of their activities (4.3); and Occupational Health & Safety (OHS) Policy (5.2), Organisational roles, responsibilities and authorities (5.3).  

In addition, organisations must maintain documented information of their risks and opportunities associated with their Context (6.1.1); Hazards and related risks (6.1.2); Compliance Obligations (6.1.3); and how these are all to be managed/reduced (6.1.4), OHS Objectives (6.2.1); their processes for emergency preparedness and response (8.2); and Improvement activities (10.3).

There are two related to documented information, however in the Documented information clause itself (7.5.1) ISO45001:2018 notes that the extent of documented information can vary due to the size and complexity of organisations, the need to demonstrate fulfilment of compliance obligations and the competence of the persons involved.  In other words, it is up to organisations. Indeed, if any documented information is to be maintained or retained, the organisation can choose what the most suitable format is, be that a flow-chart, a picture, a table of information, a website, a certificate or whatever suits them best.

The remaining one, being Operational planning and control (8.1), states that documented information is to be maintained ‘to the extent necessary to have confidence that processes are carried out as planned’.  In other words, it is up to the organisation how many or how few pieces of documented information are maintained to be conformant with this clause. 

Where it says ‘retain’ documented information, this means that the organisation needs to somehow, in whatever way is most suitable for them, keep some form of evidence that can be viewed.  In ISO45001:2018 retain documented information is stated sixteen times. 

In the majority of cases, the organisation decides the documented information it needs to demonstrate, for example, that it has complied with a piece of OHS legislation.  An example of this could be demonstrating compliance with the Lifting Operations and Lifting Equipment Regulations (Northern Ireland) 1999 for Forklifts by having a Report of Thorough Examination and Testing completed by a qualified person (where it could be documentation provided on the providers website that becomes the documented information).   ISO does not specify this.  It is up to the organisation.

I said at the start of this post that ISO45001 is all about saving lives.  This is true, the best organisations focus for health and safety is on reducing their health and safety hazards and risks and complying with any legal or other requirements.  However, it is noticeable that by doing so and demonstrating they comply with requirements, just how many of the pieces of documented information described in ISO45001:2018 they find that they need. 

Trevor Patterson is a QHSE Consultant and also conducts ISO audits on behalf of one of the main Certification Bodies.