6 min read
Is ISO 45001 Certification Mandatory?
A short answer, and the details that actually matter: where legal duties end, where customer requirements begin, and how to decide whether certification is worth pursuing.
In this guide
- What ISO Actually Says
- Optional Certificate, Non-Optional Safety Duties
- When Certification Stops Feeling Optional
- Can You Use ISO 45001 Without Certifying?
- A Company Certificate Isn’t a Personal Qualification
- Is the Standard About to Change?
- How to Decide Whether Your Organization Should Certify
- Conclusion
- Frequently asked questions
This question usually lands on someone’s desk for a specific reason. A client has added ISO 45001 to its supplier requirements, a tender asks for a certificate, or a manager simply wants to know whether the company is at risk without one.
The straight answer is no. ISO 45001 certification is a choice, not a legal obligation. But that answer on its own can be misleading, because the health and safety duties behind the standard are very much required, and the business pressure to certify can be real.
Below, we separate those threads so you can see exactly what’s optional, what isn’t, and how to decide what your organization needs.
Quick Answer
No, ISO 45001 certification isn’t mandatory. ISO itself says organizations can decide whether to go through certification. What you can’t opt out of is workplace health and safety law, which applies whether or not you use ISO 45001. In practice, certification becomes necessary only when a client, tender, contract or parent company asks for it.
What ISO Actually Says
You don’t have to rely on anyone’s interpretation here. ISO states that “companies implementing ISO 45001 can choose whether they want to go through a certification process or not”.
ISO also doesn’t hand out certificates itself. It says it “does not perform certification or issue certificates”. When organizations do certify, an independent certification body audits their system and issues the certificate.
So there are really two decisions. The first is whether to use ISO 45001 to structure your occupational health and safety management system (OHSMS). The second, quite separate, is whether to have that system independently certified. If the standard itself is still new to you, start with what an ISO 45001 OHSMS is and how it works.
Optional Certificate, Non-Optional Safety Duties
This is where most of the confusion comes from. An ISO 45001 certificate is optional. Protecting your workers isn’t.
Every country has its own occupational health and safety laws. They decide what an employer must do, such as assessing risks, controlling hazards, training people and reporting incidents. Those duties exist whether or not you’ve ever heard of ISO 45001, and no certificate replaces them.
What ISO 45001 adds is a structured way to manage those duties. Among other things, it expects you to identify the legal and other requirements that apply to you and to check how well you’re meeting them. That doesn’t mean a certified organization is automatically compliant with every law. It means its system for managing safety, including legal compliance, has been audited against the standard.
When Certification Stops Feeling Optional
Even though no law requires it, certification can become a practical necessity. In each of these situations, the requirement comes from a business relationship rather than from ISO or the government:
- Client requirements. Some clients, particularly in construction, oil and gas, manufacturing and facilities management, ask contractors and suppliers to hold ISO 45001 certification.
- Tenders and prequalification. A tender or supplier questionnaire may ask for a certified OHSMS, or score bidders higher when they have one.
- Contract clauses. A signed contract can make certification a condition of the work.
- Group policy. A parent company may require every site or subsidiary to certify.
Knowing where the requirement comes from tells you who to ask. If a client wants certification, the client decides what it will accept, including which certification bodies, which scope and by what date.
Occasionally you’ll still see older documents asking for OHSAS 18001. ISO 45001 has taken its place, and the differences between OHSAS 18001 and ISO 45001 are worth knowing if a client’s paperwork hasn’t caught up.
Can You Use ISO 45001 Without Certifying?
Yes, and plenty of organizations do exactly that. You can implement the standard, run internal audits and management reviews, and improve how you manage safety without ever booking a certification audit.
The trade-off is recognition. Without a certificate, there’s no independent confirmation that your system meets the standard, so a client or tender panel that asks for certification won’t accept a self-declaration. If nobody is asking, and your aim is simply better safety management, using the standard on its own is a sensible option.
Many organizations take it in stages. They build the system first, run it long enough to generate real records, and then certify when a client or market opportunity makes it worthwhile. Teams that are just starting out often use ISO 45001:2018 OHSMS training for beginners to get everyone working from the same understanding.
A Company Certificate Isn’t a Personal Qualification
People sometimes ask whether ISO 45001 is mandatory when they’re really asking about their own qualifications. These are different things. ISO 45001 certification belongs to an organization’s management system. Courses and qualifications belong to individuals.
An ISO 45001 Lead Auditor course, for example, develops a person’s ability to audit an OHSMS. It doesn’t certify their employer. Other safety qualifications have different purposes again, which is why the difference between NEBOSH and an OHSMS Lead Auditor course often comes up when people plan a safety career.
Whether a particular job requires a particular qualification depends on the employer, the client or local regulation. ISO 45001 doesn’t decide that.
Is the Standard About to Change?
Yes, a new edition is on its way, though it doesn’t change the answer to this question. ISO 45001:2018, with its 2024 climate action amendment, is still the current edition. ISO’s project page says the revised version is “expected to replace ISO 45001:2018 in the first half of 2027”. Until then, certification continues against the 2018 edition.
How to Decide Whether Your Organization Should Certify
A few honest questions usually settle it:
- Has a client, tender or contract asked for it? If so, certification is a business requirement. Find out exactly what they’ll accept.
- Are you bidding for work where certification is expected? Even an unwritten expectation can affect how you’re scored.
- How organized is your safety management already? If hazards, legal requirements and incidents are already managed systematically, certification may be closer than you think.
- Would independent assurance help? An external audit gives management and stakeholders an outside view of how the system is really working.
- Can you keep it going? Certification involves regular surveillance audits, so the system has to stay active, not just be set up once.
Conclusion
ISO 45001 certification isn’t mandatory. ISO leaves that decision to each organization. Health and safety law is mandatory, and ISO 45001 is a way of managing those duties well, not a substitute for them. Certification becomes a genuine requirement only when a client, contract, tender or parent company asks for it.
If you’re the person who’ll build or audit the system, the steps to become a certified ISO 45001 Lead Auditor show how training, the exam and audit experience fit together.
Frequently asked questions
Is ISO 45001 certification required by law?
No, ISO 45001 certification isn’t generally required by law. ISO says organizations can choose whether to certify. The health and safety laws where you operate still apply either way.
Can a client make ISO 45001 certification compulsory?
Yes, a client can make ISO 45001 certification a condition of a contract or tender. The requirement then comes from the client, not from ISO or the law.
Does an ISO 45001 certificate prove legal compliance?
No, an ISO 45001 certificate doesn’t prove full legal compliance. It shows the OH&S management system has been audited against the standard, which includes how legal requirements are identified and evaluated. The organization is still responsible for every legal duty.
Can an organization follow ISO 45001 without being certified?
Yes, an organization can implement ISO 45001 fully without certifying. It just won’t have independent confirmation that its system meets the standard.
Is ISO 45001 only for large or high-risk companies?
No, ISO 45001 isn’t limited to large or high-risk companies. ISO says it is applicable to any organization regardless of size, industry or geographic location.
Does an ISO 45001 Lead Auditor course certify my company?
No, an ISO 45001 Lead Auditor course is individual training and doesn’t certify a company. Only a certification body can certify an organization’s OH&S management system, after auditing it.
3FOLD Training is a CQI and IRCA Approved Training Partner (view the CQI IRCA profile). Its CQI and IRCA certified ISO 45001 Lead Auditor course is delivered 100% live online. The course helps individuals develop OHSMS auditing skills. It doesn’t certify an organization and isn’t a legal requirement for anyone.
Responsible for ISO 45001 in your organization? Learn to audit an OH&S management system on the live online ISO 45001 Lead Auditor course.





Leave a Reply
Your email is safe with us.