Systematic OHS management

    Written by Nicolai Bjerknes Slinning, Founder, Sydera.io Technologies AS · Working Group Expert, ISO/TC 283/WG 6 and WG 10 · member of SN/K 551. Last reviewed .

    Systematic occupational health and safety management means health, safety and the working environment are something the organisation steers with, not something handled once an incident has happened. Internal control rules describe what has to exist in writing — objectives, responsibilities, hazard identification with risk assessment, plans and measures, non-conformity handling, and review of the system itself. This guide looks at what those requirements mean for the governance document, and where a document typically starts too late.

    What has to exist in writing

    Objectives for health and safety. How responsibilities and tasks are allocated. Hazards and problems identified, with a risk assessment. Plans and measures. A process for finding and correcting breaches. And systematic monitoring and review of the internal control itself. Employee participation is part of the requirement, not an optional extra. The order matters: it describes a chain from objective to action to learning. When one link is missing from the document, the chain falls back on individual initiative.

    Handbook, routine, and what makes it systematic

    The handbook states what the organisation has decided. The routine states how it is done. Systematic means the two hang together — and that what happens leaves a trail that can be reviewed. A handbook with no routine below it is a statement of intent; a routine with no handbook above it is local practice.

    Where documents start too late

    The most common weakness is not a missing paragraph but a missing trigger. The document describes what happens after someone reports something, and says nothing about what exists before that. Responsibility sits with an unnamed function. Non-conformity handling is described as a form rather than a process with follow-up and closure. And the review of the system has no date and no note of what changed.

    Documentation that does not become personal data

    Systematic work needs a trail, and the trail should be about arrangements rather than people. Describe what exists, for whom, how it is triggered, who owns it, and when it was last reviewed. Individual matters belong in a separate track with restricted access. Written this way, the documentation is designed to avoid holding special category data under GDPR Article 9.

    Size does not change the requirement, only the length

    A small organisation does not need a large system. It needs the same links, written shortly: three sentences per element is often enough. What auditors and inspectors look for is not volume but whether the chain holds and whether the last review is dated.

    Standards as guidance alongside the legal requirements

    ISO 45001 is a certifiable management system standard; ISO 45003 and ISO 45010:2026 are guidance standards and cannot be certified against. All three are useful as guidance alongside relevant legal requirements. None of them replaces the legal duty or an assessment of your lawful basis for processing.

    Start with one routine

    Pick one routine and read it with two questions: does anything happen on its own, and does the text require someone to record something about a named person for it to work? Send it in and get up to three areas for improvement with reference to relevant legal requirements, plus one suggested rewrite.

    Check one routine — free

    One governance document reviewed free of charge. We read the document, never employees. The document must not contain personal data.

    Sources

    Frequently asked questions

    What does systematic OHS management mean?
    That objectives, responsibilities, hazard identification, plans, non-conformity handling and review exist in writing and hang together — and that what happens leaves a reviewable trail.
    How much documentation does a small organisation need?
    Enough to show the chain from objective to action to review. Three sentences per element is often enough; length is not the requirement.
    How often should the system be reviewed?
    On significant change and at least once a year, with a date and one line on what changed.
    Does ISO 45001 certification replace the legal requirement?
    No. Certification says something about the management system; the legal duty applies regardless. ISO 45003 and ISO 45010 are guidance and cannot be certified against.
    What does the free review look at?
    One governance document, up to three areas for improvement with reference to relevant legal requirements, and one suggested rewrite. We read the document, never employees.

    Related