The ISO 45001 revision — and what you can do now
Written by Nicolai Bjerknes Slinning, Founder, Sydera.io Technologies AS · Working Group Expert, ISO/TC 283/WG 6 and WG 10 · member of SN/K 551. Last reviewed .
ISO 45001 is under revision. The outcome is not settled, and nobody can say today what the finished text will contain. What can be prepared is the documentation: the parts of a management system that are weak whatever the outcome, and how to tidy them without waiting for a publication date.
What is happening, and what is not settled
Revising an ISO standard runs through several stages of national comments and votes before the text is final. ISO 45001 is in such a process now. Sydera takes part in the Norwegian work through SN/K 551, Standard Norway's mirror committee for occupational health and safety management systems. We do not reproduce draft content, and we do not state what the revision will require — it is not decided, and the text is not public.
Why preparing is still worthwhile
When a certification standard is revised, a transition period normally follows in which certified organisations update their system. The work rarely gets smaller by being postponed. And what usually takes time is not reading a new standard — it is working out what the organisation has actually decided, who owns it, and where the evidence of review is kept.
Where management systems are weak today
Whatever changes, documentation tends to fail in the same three places. Responsibility is written to a function with no name, so nobody owns it. Non-conformity handling is described as a form rather than a process with follow-up and closure. And the management review has no date and no note of what changed. That third point is what turns a system into something that learns.
The psychosocial side is where the work is hardest
Physical hazards have established measures: air quality is measured, protective equipment is inspected, incidents are logged. Psychosocial conditions have no equivalent gauge, and the attempt to build one often ends in questions about how individuals are feeling. At that point documentation runs into data protection law, where health data is a special category and data minimisation applies. This is the paradox we work on.
What you can do without waiting
Four things cost little and keep their value whatever the outcome. Write responsibility to named roles. Turn the non-conformity routine into a process with a place where findings are closed. Set a fixed review date with somewhere to record what changed. And move psychosocial measures from individual follow-up to arrangements that apply to everyone, so the documentation can describe something without describing someone.
How we help
We read one governance document free of charge and point to up to three areas for improvement with reference to relevant legal requirements, plus one suggested rewrite. For the management system as a whole there is the Sydera HSE review, which tests the documents as a single whole against control points with clause and date, without personal data.
One governance document reviewed free of charge. We read the document, never employees. The document must not contain personal data.
Sources
Frequently asked questions
- When will the revised ISO 45001 be published?
- It is not decided. An ISO revision runs through several stages of national comments and votes, and the date becomes known only once the process concludes. Follow ISO or your national standards body for status.
- What will change?
- Nobody can say today, and we do not reproduce draft content. What is safe to prepare is the documentation: responsibility, non-conformities, and review that leaves evidence.
- Will we have to recertify once it is published?
- A revision of a certification standard is normally followed by a transition period for certified organisations. Your certification body confirms what applies to your certificate.
- Is ISO 45003 part of this?
- ISO 45003 is a separate guidance standard on psychosocial risk, not a requirement in itself. It is used as guidance alongside relevant legal requirements.
- How do we prepare the psychosocial side without collecting health data?
- By describing conditions in the work at system level — workload, roles, breaks, participation — and keeping individual cases in a separate track with restricted access.