Key Steps to Implement OHSAS 18001 Certification in Your Company

The OHSAS 18001 standard defined a framework for occupational health and safety management (OHS) applicable to any organization. Since 2021, it has been officially replaced by ISO 45001. Understanding the steps for implementing this system remains relevant for companies structuring their OHS approach, as the deployment logic largely persists in the current framework.

OHS Certification Scope: The Framing Most Guides Overlook

Before drafting any document, the first decision concerns the exact scope of certification. This involves determining which sites, activities, and operational units will be covered by the management system.

See also : Key Steps to Successfully Complete Your Real Estate Project with Peace of Mind

An overly broad scope dilutes resources and extends timelines. An overly narrow scope limits the certificate’s reach and can pose credibility issues with clients. The choice depends on the risk mapping: activities where hazards are most significant (construction sites, production workshops, logistics areas) should be prioritized in the scope.

This initial framing also includes analyzing the internal and external context of the organization. Specifically, this means identifying applicable regulatory constraints, stakeholder expectations (employees, subcontractors, labor inspections), and organizational factors that influence safety. This step, reinforced by ISO 45001, conditions the relevance of everything that follows.

See also : Discover innovative business solutions to boost your company's growth

For companies wishing to implement OHSAS 18001 certification or migrate to ISO 45001, this scope work prevents the construction of a system disconnected from on-the-ground realities.

Team of professionals in a meeting for the implementation of OHSAS 18001 certification in a company

Assessment of Occupational Risks and Legal Compliance

The technical foundation of the system relies on hazard identification and risk assessment. Each position, each process undergoes an analysis that prioritizes risks according to their severity and likelihood of occurrence.

This assessment is not limited to a documentary exercise. It involves observations on the ground, feedback on past incidents, and, most importantly, consultation with the workers themselves. This point deserves particular attention.

Employee Participation in Hazard Identification

OHS frameworks, particularly ISO 45001, require concrete evidence of worker participation in risk assessment. It is not merely about informing them during an annual meeting. Employees must actively contribute to identifying hazardous situations, defining preventive measures, and the continuous improvement of the system.

In practice, this involves working groups that include operators and management, formalized feedback from the field, and accessible reporting mechanisms. The auditor will verify that this consultation genuinely exists, not just that it appears in a procedure.

Regulatory Compliance Review

At the same time, the company must compile a comprehensive inventory of the legal requirements applicable to its activities: Labor Code, regulations on protective equipment, sector-specific standards. This compliance review constitutes a deliverable in its own right within the management system, updated regularly.

Documentary Construction of the OHS Management System

Once the risks are assessed and the regulatory framework identified, the organization formalizes its system. The documentation includes several levels:

  • The OHS policy, signed by management, which sets commitments regarding prevention, legal compliance, and continuous improvement. This document must be communicated to all personnel.
  • Operational procedures that describe how identified risks are managed daily: safety instructions, management of protective equipment, emergency response protocols.
  • Records that provide evidence of the system’s functioning: inspection reports, incident reports, internal audit results, corrective actions taken.

Management’s commitment is not limited to signing a policy. They must allocate resources (training budget, dedicated time, competent personnel) and demonstrate their involvement during periodic management reviews.

Trial Run in Real Conditions Before Certification Audit

This is probably the most underestimated step. The system must operate for several months before seeking a certifying body. This trial period allows verification that procedures are being followed, records are maintained, and the continuous improvement cycle produces measurable results.

During this phase, the company conducts at least one complete cycle of internal audit. The internal audit covers the entire initially defined scope and verifies compliance with the framework’s requirements. Any detected non-conformities must be addressed before the external audit.

A management review is also essential. It examines OHS indicators, results from internal audits, incidents that occurred, and corrective actions taken. This review formalizes improvement decisions and proves that management actively leads the system.

Safety auditor conducting a field inspection in a factory as part of OHSAS 18001 certification

OHS Certification Audit: Process and Follow-up

The certification audit generally takes place in two phases. The first phase, documentary, checks that the system is properly structured and that the documentation meets the framework’s requirements. The second phase, on-site, evaluates the actual implementation.

The auditor examines records, interviews employees at different hierarchical levels, and observes practices on the ground. Key points of vigilance include:

  • The consistency between identified risks and deployed control measures
  • The traceability of corrective actions following incidents or internal audits
  • The genuine involvement of management, beyond mere statements of principle
  • The actual participation of workers in OHS processes

In the case of major non-conformities, the certifying body grants a deadline to correct them before issuing the certificate. The certificate is then valid for three years, with annual surveillance audits that verify the maintenance and improvement of the system.

The transition to ISO 45001 has strengthened certain requirements, particularly regarding the analysis of the organizational context and the consideration of leadership. Companies that structure their system by integrating these dimensions from the outset position themselves favorably, whether the certificate bears the historical mention OHSAS 18001 or ISO 45001.

Key Steps to Implement OHSAS 18001 Certification in Your Company