Delegate Handbook - ISO 45001 - V0
Delegate Handbook - ISO 45001 - V0
HANDBOOK
ISO 45001 : 2018
ANNEX SL
• ISO 45001:2018, like most other ISO standards, has adopted the
Annex SL High Level Structure (HLS).
• Understanding Annex SL isn't just crucial for ISO 45001 - it's the
core of any modern ISO standard you can expect to accredit to in
the future, so you should start your reading as soon as possible.
TRAINING COURSE
OVERVIEW
• PDCA approach
• Risk based thinking
• Understanding the standard’s requirements
• Skill enhancement for auditing
OBJECTIVES OF THIS
RESOURCE MATERIAL
• Continual Improvement
Resource Material
• ISO 31000 : Risk Management- Principles and Guidelines
• ISO 31010 : Risk Management -Risk assessment techniques
KEY CHANGES
• Introduction of High Level Structure ( HLS ) meaning revised
clause structure .
Standard released on 12
March 2018
Must Refer to Note : For this Must Refer to Note : Legal requirements
purpose of document Legal and other requirements include those
requirements and other that determine the person who is
requirements are those which are worker’s representative in accordance
relevant to OH & S management with laws, regulations , collective
System agreements and practice
LETS UNDERSTAND
THIS THOROUGHLY
• Occupational Health & safety objective 3.17 -objectives set by
organisation to achieve specific results consistent with OH&S
policy
• To prevent work related injury & ill health to workers & to provide
safe & healthy workplace.
• Check : Monitor and measure the activities and report the results
4.1Understanding 5.1 Leadership 6.1 Actions to address 7.1 Resources 8.1Operational 9.1 Monitoring, 10.1 General
the organisation &commitment risks and planning and control measurement,
and its context opportunities analysis and
performance
evaluation
5.3 OH&S policy 6.2 OH&S objectives 7.2 Competence
4.2 Understanding the 8.2 Emergency 10.2 Incident , non
needs & expectations and planning to preparedness and conformity and
of worker & other achieve OH&S response 9.2 Internal Audit corrective action
interested parties objectives
4.2 OH&S MS
7.5 Documented
information
1.0 SCOPE
• ISO 45001 : 2018 provides requirements for OH&S management
system that organisation can use to enhance the OH&S
performance.
4.3 Determining the Is the scope of the OH&S management system defined and documented?
scope of the OH&S
management system When defining the scope have you:
Guidance 2: Your auditor will gather evidence that the scope has been
correctly defined and considers context and applicable legal and other
requirements and your organisations activities, products and services.
Auditors will also evaluate the accuracy of the scope to ensure that it does
not mislead interested parties.
4.3 AUDIT
EVIDENCES
• Outsourcing
• Logistics
• Multiple sites
• Service centres
• Servicing at customer premises
• Collaborative products and services
4.4 OH&S
MANAGEMENT SYSTEM
Context of the organisation - The context of an organisation refers to the combination of internal
and external factors and conditions that can have an effect on an organisation’s approach to its
products and or services. As a result, the design and implementation of your organisation’s
occupational health and safety management system will be influenced by its context.
5.2 OH&S Policy Have top management established an OH&S policy that is consistent
with the purpose and context of the organisation? Does the established
policy include a commitment to:
Provide safe and healthy working conditions?
A. Fulfil legal and other requirements
B. Eliminate hazards and reduce OH&S risks
C. Consultation and participation of workers (and if applicable workers
representatives)
Guidance: Worker includes all persons working under the control of the
organisation including visitors, contractor’s
personnel and personnel carrying out an outsourced process.
5.3 AUDIT
EVIDENCES
• Organisational Charts
• Roles and Responsibilities for Emergency
Positions and ensure that personnel are aware of
such duties
• Should include contractors
5.4 CONSULTATION
AND PARTICIPATION
OF WORKERS
• The organisation shall establish processes for consultation and
participation of workers and where they exist worker’s
representative
Leadership and worker participation - There is an emphasis on leadership rather than just
management. Top management are required to demonstrate greater direct involvement in your
organisation’s OHSMS. The removal of the need for a specific management representative is to
ensure that ‘ownership’ of your organisation’s OHSMS is not simply focused on one individual but
on that person or group of people who directs and controls your organisation at the highest level.
This is a key clause and is fundamental to the whole standard. If it is not followed in its basic and
profound meaning, the whole management system may still achieve some good results, but fail to
reach its full potential.
5.4 Consultation and Has a process been developed and implemented for consultation and
Participation of workers participation of workers at all applicable levels and functions and where
they exist workers representatives, in the development, planning,
implementation, performance evaluation and actions for improvement of
the OHSMS?
Guidance: Worker includes all persons working under the control of the
organisation including visitors, contractor’s
personnel and personnel carrying out an outsourced process.
5.4 AUDIT
EVIDENCE
• Minutes of safety committee meetings
• Observation & intervention process
• Employee and contractors feedback & surveys
• Interviews with employees & contractors
6.0 PLANNING
6.1 ACTIONS TO
ADDRESS RISKS AND
OPPORTUNITIES
• When planning for OHAS management system
Consider
• External and internal issues
• Requirements of interested parties
• Scope of OH&S management system
When determining the risks & opportunities for OH&S management system ,
the organisation shall consider
• Hazards
• OH&S risks and other risks
• OH&S opportunities and other opportunities.
• Legal requirements and other requirements
6.1 ACTIONS TO
ADDRESS RISKS AND
OPPORTUNITIES
• The organisation shall maintain documented information on
Planning - Although planning has always been an integral part in establishing and maintaining an
OHSMS, ISO 45001:2018 now places a greater emphasis on the planning that your organisation
does to proactively identify any circumstances which could lead to any undesired occurrences that
could prevent the achievement of continual improvement. Your organisation is now required to
consider both its context and interested parties when planning and implementing its OHSMS.
6.1 Actions to address Considering the organisations context (clause 4.1) and requirements of
risks and opportunities relevant interested parties (clause 4.2) have the risks and opportunities
been considered and have actions been defined to take advantage of the
opportunities and mitigate the risks?
Does this include consideration of hazards, risk, opportunities and legal
and other requirements that may be applicable? Is documented
information available on risks and opportunities and the processes and
actions needed to determine and address the risks and opportunities?
Have hazards (sources of potential to cause injury or ill health)
associated with operational processes throughout the organisation been
identified?
6.1 ACTIONS TO
ADDRESS RISKS AND
OPPORTUNITIES
Planning - Although planning has always been an integral part in establishing and maintaining an
OHSMS, ISO 45001:2018 now places a greater emphasis on the planning that your organisation
does to proactively identify any circumstances which could lead to any undesired occurrences that
could prevent the achievement of continual improvement. Your organisation is now required to
consider both its context and interested parties when planning and implementing its OHSMS.
6.1 Actions to Guidance: When identifying hazards organisations should take account
address risks and the definition of “workplace”. Workplace is not limited to the site where
opportunities organisations perform their activities. Workplace also covers any place
Continued under the full or partial control of the organisation, where workers need
to be present or go to for work purposes.
Have risk assessments been completed and the methodology used for
risk assessment and the criteria applied been documented? Has
documented information been retained on the results of your
determination and assessment of risks and opportunities?
Is there a process in place to determine and have access to legal and
other requirements applicable to the OHSMS and how the requirements
apply within the OHSMS?
Is documented information maintained and retained on this process and
on the organisations legal and other requirements? Has the organisation
determined how to address risks and opportunities including the actions
required (including how to address legal and other requirements and to
prepare for and respond to emergency situations)?
Note: when planning to take action you need to apply whenever possible,
the ‘hierarchy of controls’.
6.1 AUDIT
EVIDENCE
• Risk assessments – suitable & sufficient
• Methodology
• Review periods
• Competence of assessor
• All activities
• All work locations
• Physical, physiological, illness and COSHH
6.1.2 HAZARD
IDENTIFICATION AND
ASSESSMENT OF RISKS
AND OPPORTUNITIES
• Hazard identification is pro active & on going process to be
started at conceptional design stage of any new work place , facility
or product & continued during operations .
Legal Requirements :
• Legislation ( regional , national or international )
• Decrees and directives
• Orders issued by regulators
• Permits , license or other forms of authorisation
• Judgements of courts or administrative tribunals
• Treaties , protocols
Other requirements :
• The organisational requirement
• Contractual conditions
• Employment agreements
• Agreements with interested parties
• Agreements with health authorities
6.1.4 PLANNING
ACTION
• The organisation shall plan actions to actions to address to
• What is to be done ?
• What resources required ? Typically
financial , human , infrastructure , Management
equipment etc programmes , isn’t it ?
• Who is responsible ?
• When it will be completed ?
• How results will be evaluated
including the indicators for
monitoring
6.2 OH&S objectives Have (SMART) objectives been established at relevant functions and
and planning to levels within the organisation in order to maintain and continually improve
achieve them the OHSMS and OH&S performance?
Are the objectives consistent with the policy, OH&S risks and
opportunities, business context and adequately resourced, monitored,
communicated and updated as appropriate?
Are workers able to remove themselves from work situations that they
consider present an imminent and serious danger to their life and health
without fear of reprisal?
7.4 COMMUNICATION
• 7.4.1 The organisation shall establish processes for internal and
external communications relevant to OH&S management system.
Elimination
Substitution
Engineering Control
Administrative control
Use of PPEs
8.1 OPERATIONAL
PLANNING AND CONTROL
• Examples of measures at level hierarchy level
Does the organisation ensure that the requirements of the OHSMS are met
by contractors and their workers?
Does the organisation ensure that outsourced functions and processes are
controlled and outsourced arrangements are
consistent with legal and other requirements and with achieving the
intended outcome of the OHSMS?
8.2 EMERGENCY
PREPAREDNESS
• The organisation should establish , implement and maintain
processes needed to prepare for and respond to potential
emergency situations
9. Performance evaluation - The newly introduced ISO 45001:2018 recognizes the importance
of managing through the gathering and analysis of data and there is increased requirement placed
on you to implement indicators. This will lead to a far more structured assessment of OH&S
management systems and you will be expected to establish monitoring and measuring that is
relevant and reliable and that the results are evaluated and analysed.
9.1 Monitoring, Has a process (es) been established and implemented for monitoring,
measurement, analysis measurement, analysis, performance evaluation and
and performance for evaluating compliance with legal and other requirements?
evaluation
• The competencies that are needed for and applied to the audit,
• Objectivity and impartiality of the internal audit process
• The risk based thinking performed by the organization in planning internal
audits,
• The degree of management involvement in the internal audit process
• The guidance provided by ISO 19011
• The way the outcome of the internal audit process is used by the
organization to evaluate the effectiveness of its DMS and to identify
opportunities for improvements
• How reports are communicated to management, and for OH&SMS, to workers
and interested parties
9.3 MANAGEMENT
REVIEW
• Top management shall review the organisation’s OH&S
performance at planned intervals to ensure suitability , adequacy
and effectiveness.
MRM INPUTS
• Information of OH&S performance trends including
- incidents , nonconformities , corrective action and continual improvement
- Monitoring and measurement results
- Results of evaluation of compliance with legal requirements and other
requirements
- Audit results
- Consultation and participation of workers
- Risks and opportunities
9.3 MANAGEMENT
REVIEW
• The output of management review should include decisions related
to:
• Containment - take action to control it and correct it, deal with the consequences
• Evaluate with participation of worker
• Determine causes
• Determine if similar incidents have occurred , if nonconformities exits or if they
could potentially occur
• Review of existing assessment of OH&S risks
• Determine and implement any action needed , including corrective action in
accordance with hierarchy of controls and management change & varying the
effectiveness.
10.1 INCIDENT,
NONCONFORMITY AND
CORRECTIVE ACTION
• The organisation shall communicate the documented information to
relevant workers and where they exist worker’s representative and
worker’s representative and other relevant interested parties.
Take action to control and correct it and deal with the consequences in
a timely manner?
Evaluate, with the participation of workers and the involvement of
other relevant parties the need for corrective action to eliminate the
root cause(s) of the nonconformity?
Review existing assessments of OH&S risks and other risks as
appropriate (related to clause 6.1)?
Determine and implement any action needed in accordance with the
hierarchy of controls (clause 8.1.2) and the
management of change (clause 8.1.3)?
Assess OH&S risks that relate to new or changed hazards prior to
taking action?
Review the effectiveness of any action(s) taken?
If required make changes to the OHSMS?
• Internal Vs External
• Based on who conducts:
1. First Party
2. Second Party
3. Third Party
• Focus of the audit
1ST / 2ND / 3RD
PARTY AUDIT
Client Auditor Auditee
• Issues:
• Aspects / impacts
• Audit skills:
• Fair presentation
• Independence
• Evidence-based approach
PRINCIPLES -
ETHICAL CONDUCT
• Foundation of professionalism
• To ensure:
• Trust
• Integrity
• Confidentiality
• Discretion
• To ensure:
• To ensure:
• To ensure:
• To ensure:
• Personal attributes
• Auditor evaluation
STEPS IN AN AUDIT
PROCESS
Initiating audit
Reporting
Follow-up
• Objective
• Supported by Evidence
• Accurate
• Negative
1. non-conformances
2. observations
3. suggestions
VERIFY AND ASSESS FINDINGS
AMONGST AUDITORS’ TEAM