Migrating from OHSAS 18001 to ISO 45001: a transition roadmap

A procurement manager forwards the prequalification pack for a large infrastructure tender, and a single line decides whether the bid goes any further: the client expects a current ISO 45001 certificate. The position is familiar. The company built its occupational health and safety system around OHSAS 18001 years ago, the certificate quietly lapsed, and nobody rebuilt it on the new standard. That gap now sits between the business and the work it wants to win.
OHSAS 18001 has been withdrawn. The formal migration window, which ran for three years after ISO 45001 was published in 2018 and was extended by six months because of the pandemic, closed in September 2021. So this is no longer a relaxed upgrade with a countdown to plan around. Any organisation still running its safety system on the old British Standard layout is working from a framework that certification bodies can no longer certify, and the route back to a recognised certificate runs through ISO 45001. The encouraging part is that most of the safety substance you already hold, your hazard registers, your training records, your incident process, carries straight over. What changes is the structure built around it.
ISO 45001 is not OHSAS 18001 with a new cover
The first thing to accept is that a clause-by-clause copy of the old manual will not pass. ISO 45001 is written on the High-Level Structure, the common ten-clause skeleton shared by ISO 9001 and ISO 14001. OHSAS 18001 followed the same Plan-Do-Check-Act logic, but its clauses were numbered and grouped differently. Because the new standard speaks the same structural language as the other management-system standards, this is also the moment many organisations choose to align everything and run an integrated management system rather than maintain three separate manuals. Migration and integration are two decisions, yet they sit naturally inside the same project.
Start with an honest gap analysis
The transition begins with a gap analysis, not with new paperwork. Map every part of your existing OHSAS 18001 system against the ISO 45001 clauses and mark each item as keep, revise, or build from scratch. Resist the urge to assume coverage. Auditors find the new requirements exactly where legacy systems stay silent, and four areas account for most of the findings: the context of the organisation, the strengthened leadership and worker-participation duties, the treatment of risks and opportunities, and operational controls that now reach into procurement and contractors. The output of this stage is a working register that drives the rest of the project. If your old system still carries the structure described on our OHSAS 18001 reference page, this is the document that shows you the distance to close.
The clause most teams underestimate: context and interested parties
Clause 4 has no real equivalent in OHSAS 18001, and that is why it is so often treated as a formality. It should not be. You are asked to determine the internal and external issues that affect your safety performance, to identify your interested parties, the workers, contractors, regulators, clients, unions, and the people who live near your operations, and to use that picture to set the scope of the system. Done properly, this shapes what the system actually covers. A logistics firm that ignores its subcontracted drivers, or a factory that leaves agency staff out of scope, will see that gap surface as a finding later. Context is the foundation the rest of the standard is built on.
Leadership and worker participation: the real shift
If one change defines this migration, it is here. OHSAS 18001 let organisations lean on a management representative who owned the system. ISO 45001 removes that crutch. Top management is now accountable for the safety system, has to fold it into the way the business is run, and cannot hand the whole thing to a single safety officer. Clause 5.4 then makes consultation and participation of workers a firm requirement, with particular weight on non-managerial workers. They have to be involved in hazard identification, in setting policy and objectives, in investigating incidents, and in reviewing what the system finds.
The standard goes further and asks you to remove the barriers that stop people taking part: language, literacy, time pressure, and the fear of reprisal for raising a concern. For a company shaped by the OHSAS habit of top-down safety, this is the largest cultural change of the whole transition, and it is the area auditors probe hardest. Building it means real safety committees with genuine worker representation, consultation that is recorded rather than assumed, and channels that reach the shop floor rather than the noticeboard.
From hazard control to risk and opportunity
OHSAS 18001 was already strong on hazard identification and risk assessment, and that work stays. ISO 45001 widens the lens. You assess OH&S risks and OH&S opportunities, and separately the risks and opportunities to the management system itself. The standard also formalises the management of change, so that new equipment, new processes, and changes in the law get assessed before they create hazards rather than after. This is where the risk-based thinking that runs through the modern ISO family lands in safety, and teams that already apply formal risk management elsewhere will recognise the approach. Pair it with a refreshed register of legal and other requirements, which clause 6 expects you to keep current.
Operational control now reaches your contractors and suppliers
Clause 8 is where the new requirements meet daily operations. ISO 45001 expects you to control OH&S risk across procurement, outsourcing, and contractor coordination, not only inside your own gates. A change at a supplier, a new contractor on site, or an outsourced maintenance crew all sit inside the system now. If you also run an ISO 14001 environmental system, you will notice how closely these operational-control and management-of-change requirements track, which is another argument for handling them once across both standards.
A transition roadmap that survives contact with reality
With the gaps mapped and the big changes understood, the migration becomes a sequenced project rather than a scramble. The order matters: leadership commitment and scope come before the risk work, and the system needs to run long enough to generate records before anyone books the certification audit. The phases below are the backbone most successful transitions follow.

How long each phase takes depends on honest variables, not a fixed number. The maturity of your existing OHSAS system, the number of sites, the size of your workforce, and how much genuine worker-participation infrastructure already exists all move the timeline. A mid-sized single-site manufacturer with a well-kept OHSAS system can often complete the work in a few months. A multi-site group, or a business that let its old system drift, should plan for longer and resource the worker-consultation strand early, because that is the part that cannot be rushed into existence the week before the audit.
One sequencing point is worth holding onto: leave time for a shake-down period. ISO 45001 conformity is shown through records, and an internal audit and a management review need real evidence to examine. Running the new processes for a stretch before the certification audit is what turns a well-written manual into a working system. The transition, or certification, audit itself should be carried out by an accredited certification body, because an unaccredited certificate rarely satisfies the tender clauses that prompted the migration in the first place.
The mistakes that send teams back to the start
A handful of errors account for most failed transitions. The first is renumbering the old manual and calling it ISO 45001, which leaves every genuinely new requirement unaddressed. The second is treating context and interested parties as a single page filed and forgotten. The third, and the most common, is leaving worker participation as a poster rather than a practice, which an auditor will see through in the first interview on the floor. The fourth is booking the certification audit before the system has produced enough evidence to audit. Avoid those four, sequence the work as above, and the move from a withdrawn standard to a recognised one becomes a project you can actually finish. If you want a second set of eyes on the gap, our team can walk the old system against ISO 45001 with you before you commit to a timeline.
Picked for You
Related Articles

ISO 27001 and data-protection law: linking information security to legal compliance
Read More →
Preparing for an ISO 9001 audit: the 10 most common nonconformities and how to prevent them
Read More →
