Direct Answer
The ISO 45001 revision is underway, but ISO 45001:2018 is still the current occupational health and safety (OH&S) standard. The Draft International Standard is expected around 2026, with publication likely in 2027 and a three-year transition to follow — so nothing about your certification changes overnight. The revised standard is expected to sharpen its focus on mental health and psychosocial risk, worker participation, and modern work patterns like remote and hybrid work. You don’t need to wait for publication to act: strengthening worker participation and psychosocial-risk management under the 2018 standard now is the practical way to get ahead.
Prevent. Prepare. Protect. Occupational health and safety has always been about the day-to-day — whether the system actually keeps people safe while work is happening, not whether it looks complete on a shelf. The coming ISO 45001 revision leans into exactly that, broadening what “safe and healthy work” means to include the parts of modern work that older frameworks never really touched. This guide walks through what ISO 45001 is, where the standard stands today, what the revision is likely to bring, and the concrete steps forward-looking teams can take right now — well before the new edition publishes.
What ISO 45001 actually is
ISO 45001 is the international standard for an occupational health and safety management system. In plain terms, it gives an organization a structured, repeatable way to keep its people safe: identify the hazards in the work, assess the risk they create, put controls in place, involve the workers who face those hazards, and improve the whole system over time. It applies to any organization regardless of size, sector, or activity — a machine shop, a hospital, a software company with a hybrid workforce, a government contractor. Wherever people do work, there are OH&S risks to manage, and ISO 45001 provides the framework to manage them deliberately rather than reactively.
The current edition, ISO 45001:2018, was the first ISO standard specifically for occupational health and safety, replacing the older OHSAS 18001 specification. It is built on the same Harmonized Structure (sometimes called Annex SL or the High-Level Structure) that ISO 9001 and ISO 14001 use. That shared skeleton is what makes an integrated management system possible, and it’s worth understanding because the revision is expected to keep and reinforce it.
The standard organizes requirements across seven core clauses:
- Clause 4 — Context of the organization. Understand your organization, the internal and external issues that affect worker safety, and the needs and expectations of your workers and other interested parties. Define the scope of the OH&S system.
- Clause 5 — Leadership and worker participation. This is where ISO 45001 stands apart. It requires visible leadership commitment and genuine consultation and participation of workers — especially non-managerial workers — in the safety system. Safety cannot be delegated downward and forgotten.
- Clause 6 — Planning. Identify hazards, assess OH&S risks and opportunities, account for legal and other requirements, and set measurable objectives with a plan to achieve them.
- Clause 7 — Support. Provide the resources, competence, awareness, communication, and documented information the system needs to function.
- Clause 8 — Operation. Plan and control the work to eliminate hazards and reduce risks using the hierarchy of controls, manage change, control contractors and outsourced processes, and prepare for emergencies.
- Clause 9 — Performance evaluation. Monitor, measure, and analyze; evaluate legal compliance; run internal audits; and hold management reviews.
- Clause 10 — Improvement. Investigate incidents and nonconformities, take corrective action, and continually improve the system.
Read that list with the coming revision in mind and a pattern jumps out: the parts of ISO 45001 expected to grow — worker participation, the definition of a hazard, the reach of operational controls — are already in the standard. The revision sharpens them; it doesn’t invent them.
Where ISO 45001 stands right now
Nothing about your certification changes today. ISO 45001:2018 remains the standard you build and maintain your system against, and it will stay that way through the transition period after the new edition publishes. What’s changing is what comes next.
ISO’s technical committee for occupational health and safety (ISO/TC 283) has confirmed a revision and is working through the standard drafting stages. Based on the timelines circulating across the standards community, the sequence looks roughly like this:
- Draft International Standard (DIS): expected around 2026
- Publication of the revised standard: expected in 2027
- Transition period: typically three years from publication, so conformance to the new edition would be required by roughly 2030
These dates track ISO committee schedules and can shift — treat them as planning horizons, not fixed deadlines. The exact month of publication matters far less than the direction of travel, which is already clear enough to act on. It’s also worth noting how the broader revision wave fits together: ISO 14001 has already been revised, ISO 9001 is on its way, and ISO 45001 follows. Because all three share the Harmonized Structure, changes tend to echo across them — another reason organizations running more than one standard should watch the whole cycle, not just their own certificate.
What the ISO 45001 revision is likely to bring
Draft-stage discussion has been remarkably consistent across the standards community. The revised ISO 45001 is expected to broaden occupational health and safety beyond physical hazards and toward the fuller reality of how — and where — people actually work today. Here are the themes that keep surfacing.
Mental health and psychosocial risk
This is the headline change. Stress, excessive workload, burnout, bullying and harassment, job insecurity, and isolation are increasingly understood as genuine occupational hazards, not soft “people problems” that live in a different department. The revision is expected to treat these psychosocial factors as risks to be identified, assessed, and controlled within the OH&S management system itself.
The good news is that guidance already exists, and you can use it now. ISO 45003:2021 — Psychological health and safety at work: Guidelines for managing psychosocial risks — is a companion document to ISO 45001. It is guidance rather than a certifiable standard, and it walks through the categories of psychosocial hazard (how work is organized, social factors at work, and the work environment and equipment) and how to manage them using the same plan-do-check-act logic your safety system already runs on. An organization that begins applying ISO 45003 today will be well down the road the revision is heading toward.
Modern and changing work patterns
Remote work, hybrid schedules, gig and contract arrangements, and the digitalization of nearly every job have changed where hazards show up and who is exposed to them. A workforce spread across home offices, client sites, vehicles, and shared spaces still needs a safety system that reaches it. The revision is expected to reflect this reality — prompting organizations to think about ergonomics and isolation for remote staff, the boundary between work and personal life, and the safety of people who never set foot in the main facility. For many employers across technology, professional services, and other office-based sectors, this is the part of the revision that will feel most new, precisely because their old safety programs assumed everyone worked in one building.
Stronger worker participation
Safety culture is built from the ground up. Quality systems can be driven from the top, but a safety system only works when the people closest to the hazards are genuinely part of it — empowered to flag risks, report near-misses, and even stop work when something feels unsafe, without fear of blame. The 2018 standard already requires consultation and participation of workers; the revision is expected to reinforce it, pushing organizations past participation-as-a-signature-on-a-form toward participation that actually shapes the controls people work under. In practice this means real reporting channels, visible follow-through when workers raise something, and safety committees that include the shop floor, not just management.
Climate change and emergency preparedness
Severe weather, extreme heat, wildfire smoke, and other climate-driven events increasingly affect worker safety, and the revision is expected to strengthen how organizations anticipate and respond to disruptions. This dovetails with the emergency preparedness requirements already in Clause 8 and with the sustainability themes running through the parallel ISO 14001 and ISO 9001 revisions.
Closer alignment with the Harmonized Structure
Like the other revised standards, the new ISO 45001 is expected to align tightly with the latest version of ISO’s Harmonized Structure. The practical payoff is integration: if you run an integrated management system, the pieces are designed to fit together more cleanly, so a single well-run system can carry quality, environmental, and safety requirements without three separate sets of duplicate documentation. We’ll come back to why that matters.
The HR connection most teams miss
Look again at where the revision is heading: psychosocial risk, worker wellbeing, genuine participation, and changing work patterns. That is precisely the seam where occupational safety and human resources meet. Mental health, harassment, workload, remote-work boundaries — these have traditionally been treated as HR territory, sitting in a different binder from the safety manual. The revised ISO 45001 is expected to pull them squarely into the OH&S management system.
Organizations that already treat worker wellbeing and worker voice as part of how they operate will find the revised standard describes something they’re halfway to doing. Organizations that keep safety and people-management in separate silos will feel the gap most sharply. This is why the smart move is not to wait: the themes that make the revision new are things you can strengthen under the 2018 standard right now, and doing so makes your system better at protecting people today — quite apart from any future edition.
Consultation and participation: what ISO 45001 actually requires
One area worth understanding in detail — because the revision is expected to strengthen it — is the difference between consultation and participation. ISO 45001 treats them as two distinct requirements, not one.
Consultation means seeking workers’ views before the organization makes a decision. It’s a two-way exchange: management shares the relevant information and genuinely takes worker input into account. The standard specifically calls for consulting non-managerial workers on matters like their needs and expectations, the OH&S policy, roles and responsibilities, and how the organization will meet its legal obligations.
Participation goes further — it means workers are actively involved in the decisions and activities themselves. The standard calls for the participation of non-managerial workers in the areas closest to the work: identifying hazards and assessing risks, determining controls, investigating incidents, and shaping how the safety system runs day to day.
The distinction matters in practice because many organizations believe they’ve met the requirement by holding an annual meeting or posting a policy. Real consultation and participation look like reporting channels people trust, worker representatives with a genuine voice in risk decisions, and visible evidence that raising a concern leads to change. As the revision sharpens its focus on worker voice, organizations that have built these mechanisms authentically will be well positioned; those relying on a signature on a form will have work to do.
ISO 45001 and OSHA: how they fit together
For organizations in the United States — and most of MSI’s readers are — a common question is how ISO 45001 relates to OSHA. The short answer: they complement each other, and one does not replace the other. OSHA sets legally mandated minimum safety requirements enforced by regulation. ISO 45001 is a voluntary management-system standard that gives you a structured way to meet — and exceed — those obligations, and to manage the many risks that regulation doesn’t spell out.
Think of OSHA compliance as the floor and an ISO 45001 system as the structure you build on top of it. OSHA tells you what you must do; ISO 45001 gives you a repeatable system for doing it consistently, verifying that it’s working, and improving it over time. An organization can be OSHA-compliant on paper and still lurch from incident to incident because nothing connects hazard identification, worker input, corrective action, and management oversight into a system. That connective tissue is exactly what ISO 45001 provides.
The coming revision reinforces this relationship. As the standard broadens toward psychosocial risk and modern work patterns — areas where regulation is still catching up — an ISO 45001 system positions you ahead of where mandatory requirements are heading, not just level with where they are today. For contractors and suppliers, that’s increasingly a competitive advantage: many buyers now expect a demonstrable safety management system, not merely a clean regulatory record.
The hierarchy of controls still applies
Whatever the revision adds, the core logic of how ISO 45001 asks you to reduce risk — the hierarchy of controls — remains. It ranks risk-reduction measures from most to least effective, and it applies just as cleanly to a psychosocial hazard as to a physical one:
- Elimination — remove the hazard entirely. For physical risk, that might mean designing out a dangerous manual process. For psychosocial risk, it might mean removing an unreasonable workload driver rather than teaching people to cope with it.
- Substitution — replace the hazard with something less dangerous: a safer chemical in place of a hazardous one, or clear communication boundaries in place of an always-on expectation.
- Engineering controls — isolate people from the hazard through physical means such as guarding and ventilation, or, for remote staff, ergonomic equipment that prevents strain.
- Administrative controls — change how people work through procedures, training, rotation, and scheduling that limits fatigue.
- Personal protective equipment (PPE) — the last line of defense, used when higher-order controls can’t fully remove the risk.
The revision’s emphasis on psychosocial and remote-work hazards doesn’t change this ordering — it extends it to a wider set of risks. Organizations that already think in terms of the hierarchy of controls will find the new hazard categories slot naturally into a discipline they already know.
The business case: reactive costs more than planned
It’s tempting to treat a standard revision as a compliance chore to be dealt with when it lands. The organizations that get the most out of ISO 45001 see it differently — as a system that produces measurable results in practice.
Consider the difference between a procedure that works in practice and one that only works on paper. A safety system that genuinely functions catches a developing hazard before it becomes an incident, keeps experienced people on the job instead of on leave, and turns the scramble before an audit or a customer questionnaire into a routine pull of records that already exist. A system that exists only in a binder does none of that — and the costs of that gap are real: lost-time incidents, higher insurance and workers’ compensation exposure, disrupted production, turnover, and lost contracts when a customer’s supplier questionnaire asks for certification you don’t have.
Increasingly, occupational health and safety certification is also becoming a condition of doing business rather than a nice-to-have. Prime contractors, government buyers, and safety-conscious customers ask about it during qualification, and organizations without a credible system are sometimes disqualified before the conversation starts. Building the system deliberately — starting with a clear plan rather than a last-minute reaction — is consistently less disruptive and less expensive than remediating after an incident or a lost bid has already forced the issue.
ISO 45001 and the integrated management system
Here is where the Harmonized Structure pays off. Because ISO 45001, ISO 9001, and ISO 14001 share the same underlying framework — the same clauses for context, leadership, planning, support, operation, evaluation, and improvement — they can be run as one integrated management system rather than three parallel ones.
In an integrated system, you maintain one set of context and interested-party analysis, one leadership and policy structure, one internal audit program, and one management review that covers quality, environment, and safety together. Documentation stops multiplying. Auditors see a coherent system rather than three disconnected ones. And when a standard like ISO 45001 is revised, you’re updating one well-understood system instead of scrambling across silos. For an organization already certified to ISO 9001, adding ISO 45001 or ISO 14001 often means adding only a handful of new system elements — not standing up an entirely new infrastructure.
This is also where the value of a system extends well past the initial certificate. Certification is a milestone, not the finish line; the system has to be maintained, kept current as standards evolve, and continually improved to keep delivering results. An integrated system built with the coming revisions in mind is far easier to keep healthy over the years than three separate systems maintained by three separate efforts.
What to do now — without waiting for 2027
You don’t need the published revision to start moving in its direction. These steps strengthen your system under ISO 45001:2018 today and make the eventual transition a formality:
- Widen your risk picture. Begin treating psychosocial factors — workload, stress, harassment, isolation in remote roles — as identifiable OH&S risks, using ISO 45003 as your guide. Add them to your hazard identification and risk assessment process alongside physical hazards.
- Make worker participation real. Build simple, trusted routes for employees to raise hazards and near-misses, and close the loop visibly so people see that reporting leads to change. Participation that workers believe in is the single biggest predictor of a safety system that actually works.
- Extend the system to hybrid and remote work. Check that your hazard assessments and controls genuinely reach people who don’t work in one fixed location — home-office ergonomics, lone-worker considerations, and the wellbeing risks that come with always-on connectivity.
- Integrate rather than bolt on. If you already run ISO 9001 or ISO 14001, fold occupational health and safety into the same management system so you’re maintaining one integrated system, not three separate ones.
- Run a gap assessment against the direction of travel. Map your current system against both the 2018 requirements and the revision’s expected themes. The gaps you find are your roadmap, and closing them now spreads the work across years instead of compressing it into a transition deadline.
Done this way, the revision becomes a non-event when it publishes. You’re already operating in its spirit, and the transition is a documentation update rather than a scramble.
Common misconceptions about the ISO 45001 revision
A revision in progress tends to generate as much confusion as anticipation. A few of the misconceptions worth clearing up:
“We should wait to certify until the new version comes out.” Waiting leaves your workers without a structured safety system in the meantime and delays the benefits a live system delivers. Certify to the 2018 standard now and build with the revision’s themes in mind; the transition will be routine.
“The revision will force us to rebuild everything.” Revisions to ISO management-system standards refine and clarify existing requirements far more than they replace the fundamental structure. The core of your system stays intact and you extend it. Teams that lived through the 2015 revisions of ISO 9001 and ISO 14001 sometimes brace for that scale of change, but the signals so far point to a more measured update.
“Psychosocial risk is HR’s job, not safety’s.” That division is exactly what the revision is expected to close. Under the new thinking, worker mental health and wellbeing are occupational health and safety matters, managed within the same system as physical hazards.
“Our consultant will certify us.” No consultant certifies anyone. An independent registrar audits and issues the certificate; a good consultant helps you build and maintain a system that earns it. Keeping those roles distinct is what protects the integrity of your certification.
“The deadline is years away, so there’s no urgency.” The organizations that transition smoothly are the ones that started early and spread the work out. Treating a three-year window as runway rather than a last-minute deadline is what turns the revision into a non-event.
ISO 45001 revision: frequently asked questions
Is ISO 45001:2018 still valid?
Yes. ISO 45001:2018 is the current standard and remains fully valid. Certifications to it stay in force, and it will remain the standard organizations are certified against throughout the transition period after the revised edition publishes.
When will ISO 45001 be updated?
The revision is in progress at ISO/TC 283. A Draft International Standard is expected around 2026, with publication of the revised standard anticipated in 2027. Those dates depend on ISO committee schedules and can move.
How long is the transition period?
ISO management-system standards typically carry a three-year transition from the date of publication. If ISO 45001 publishes in 2027 and follows that pattern, certified organizations would need to conform to the new edition by roughly 2030.
Does ISO 45001 cover mental health?
The current standard requires organizations to identify and control hazards that can affect worker health, which can include psychosocial factors. The upcoming revision is expected to make that expectation more explicit. The companion guidance document ISO 45003:2021 already provides a detailed framework for managing psychosocial risks, and you can begin using it today.
How does ISO 45001 relate to ISO 45003?
ISO 45001 is the certifiable management-system standard. ISO 45003 is guidance — it doesn’t replace or add certification requirements, but it shows you how to apply your ISO 45001 system to psychological health and psychosocial risk. Think of 45003 as the practical playbook for one of the revision’s central themes.
Should we wait for the new version before pursuing certification?
No. Certify to ISO 45001:2018 now if it makes sense for your organization — a live, well-run safety system protects people today, and building it around the revision’s expected themes means the transition will be straightforward when it arrives. Waiting simply leaves your workers without a structured system in the meantime.
Will ISO 45001 certification still be recognized during the transition?
Yes. Once the revised standard publishes, accredited registrars continue to recognize existing ISO 45001:2018 certificates throughout the transition period, and they guide certified organizations on the steps to migrate to the new edition before the deadline.
What’s the first step if we’re starting from scratch?
A short strategic planning session is usually the most efficient starting point. It maps your current state against the standard, identifies the gaps that matter, and produces a realistic implementation roadmap before you commit to a full build — a planning-first approach that’s consistently less disruptive and less costly than diving straight into documentation.
How MSI helps
For 28 years, Management Systems International has helped organizations across manufacturing, technology, aerospace, medical device, government, and other regulated industries build occupational health and safety systems that hold up in practice — and keep holding up as standards evolve. MSI does not issue certificates; that’s the registrar’s role. What MSI does is help you achieve and maintain a system that’s genuinely certification-ready, and stay current as revisions like this one arrive. With 200+ audits attended, 80+ certifications achieved, and 600+ professionals trained, that support is built for the long haul rather than a one-time push — which is exactly what a standard in transition calls for.
If your leadership team needs a fast, clear picture of what ISO 45001 asks and why the coming changes matter, watch MSI’s free ISO 45001 Executive Decision Brief — a 16-minute leadership video, no registration, that lays out what the standard requires and what a sensible first step looks like. And if you’re already certified to ISO 9001 or ISO 14001, it’s worth reading how the standards fit together as one system before you add safety to the mix.
Ready to get ahead of the ISO 45001 revision?
Let’s look at your current OH&S system and map the practical steps to strengthen worker participation and psychosocial-risk management now — so the transition, when it comes, is a formality. Call MSI at 760-434-9141 to start the conversation.