Compliance 11 min read

ISO 45001 and OSHA: Where They Overlap and Where They Don't

J

Jared Clark

August 20, 2026

Every few months a client tells me they got ISO 45001 certified, so they figure OSHA compliance is basically handled. I understand the assumption. Both frameworks are about keeping workers safe. Both ask you to find hazards before they hurt someone. Both want you to fix problems and keep records. But one is a voluntary, internationally recognized management system standard, and the other is federal law with inspectors who can fine you. Confusing the two, or assuming one substitutes for the other, is one of the more expensive mistakes I see companies make.

This article lays out exactly where ISO 45001:2018 and OSHA requirements line up, where they diverge, and how to build a program that satisfies both without duplicating effort.

What ISO 45001 Actually Is

ISO 45001:2018 is the international standard for occupational health and safety management systems, published by the International Organization for Standardization in March 2018. It replaced OHSAS 18001:2007, with a three-year migration window that closed in March 2021. Any organization still certified to OHSAS 18001 after that date lost a valid certificate.

ISO 45001 is a management system standard, not a set of technical safety rules. It doesn't tell you the permissible noise exposure limit in your plant or the guarding requirements for a specific machine. Instead, it tells you how to build a system that identifies hazards, assesses risk, sets objectives, allocates resources, and drives continual improvement. It shares the same Annex SL high-level structure as ISO 9001 and ISO 14001, which is why organizations running multiple management systems find it straightforward to integrate.

Certification to ISO 45001 is voluntary and comes from an accredited third-party certification body, not from a government agency. Nobody is required to certify. Companies pursue it because customers demand it in a bid package, because it strengthens a safety culture, or because it's genuinely good management practice.

What OSHA Actually Is

OSHA requirements originate in the Occupational Safety and Health Act of 1970, the federal law that created the Occupational Safety and Health Administration and gave it authority to set and enforce workplace safety standards. Unlike ISO 45001, OSHA compliance is not optional for covered employers. The standards live in 29 CFR 1910 for general industry and 29 CFR 1926 for construction, and they are enforceable through inspections, citations, and penalties.

Where no specific standard applies, OSHA falls back on the General Duty Clause, Section 5(a)(1) of the OSH Act, which requires employers to furnish a workplace "free from recognized hazards that are causing or are likely to cause death or serious physical harm." That clause is the catch-all that lets OSHA cite hazards even when no numeric standard exists for them.

OSHA also requires recordkeeping under 29 CFR 1904, covering the OSHA 300 log, the 300A summary, and 301 incident reports, for employers above the size threshold and outside the partially exempt low-hazard industries listed in Subpart B.

The Real Overlaps

The overlap between ISO 45001 and OSHA is conceptual, not clause-by-clause. Both frameworks converge on the same underlying logic: find the hazard, judge the risk, control it, verify the control worked, and keep evidence. Here's where they genuinely line up:

  • Hazard identification and risk assessment. ISO 45001 clause 6.1.2 requires an ongoing process for hazard identification and assessment of OH&S risks. OSHA's general industry standards and the General Duty Clause both assume employers know what hazards exist in their own operations. A mature ISO 45001 hazard register makes it far easier to demonstrate to an OSHA inspector that hazards were "recognized" and addressed proactively.

  • Worker participation. ISO 45001 clause 5.4 requires consultation and participation of workers in developing, planning, and reviewing the OH&S management system, including non-managerial employees. OSHA has parallel expectations under standards like Hazard Communication (29 CFR 1910.1200), and OSHA's own Recommended Practices for Safety and Health Programs list worker participation as a core element.

  • Incident investigation and corrective action. ISO 45001 clause 10.2 requires investigating incidents and nonconformities and taking corrective action to prevent recurrence. OSHA recordkeeping under 29 CFR 1904 requires documenting recordable injuries and illnesses, and standards like Process Safety Management (29 CFR 1910.119) explicitly require incident investigation.

  • Emergency preparedness. ISO 45001 clause 8.2 requires establishing processes to prepare for and respond to emergency situations. OSHA's Emergency Action Plan standard (29 CFR 1910.38) requires a written plan covering evacuation procedures, alarm systems, and training. Same intent, expressed in regulatory rather than management-system language.

  • Compliance evaluation. ISO 45001 clause 9.1.2 requires evaluating compliance with legal requirements. For a U.S. employer, that means OSHA standards get folded directly into the ISO management system as a compliance obligation to be tracked and periodically verified.

Where They Diverge

This is the part clients underestimate. The differences aren't cosmetic. They change what each framework can and can't do for you.

  • Legal force versus voluntary adoption. OSHA compliance is mandatory for covered employers under federal law. ISO 45001 certification is voluntary. You can be ISO 45001 certified and still be out of compliance with a specific OSHA standard, because certification audits sample the management system, not every technical control in the building.

  • Management system versus prescriptive limits. ISO 45001 tells you to have a process for controlling hazards. OSHA, in many of its standards, tells you the actual number: the permissible exposure limit for a chemical, the minimum guard height on a machine, the required distance for fall protection anchor points. ISO 45001 clause 8.1.2 asks you to establish a hierarchy of controls. It doesn't specify the technical threshold. You still need OSHA's substance-specific standards, like the lead standard at 1910.1025 or the respiratory protection standard at 1910.134, to know the actual number you're required to hit.

  • Certification versus enforcement. ISO 45001 conformance is verified by a certification body during a scheduled audit, and the consequence of nonconformity is a corrective action request or, in serious cases, suspension of the certificate. OSHA compliance is verified by a federal or state-plan compliance officer, often during an unannounced inspection triggered by a complaint, referral, or fatality. The consequence is a citation with a monetary penalty and abatement deadline.

  • Geographic reach. ISO 45001 is used by organizations in more than 100 countries and is the same standard whether you're certifying a plant in Ohio or one in Vietnam. OSHA only has jurisdiction in the United States. Even within the U.S., OSHA currently recognizes 22 State Plans that cover both private-sector and state/local government employees (Puerto Rico is one of these 22, not an addition to them), plus six public-sector-only State Plans covering state and local government workers in Connecticut, Illinois, Maine, New Jersey, New York, and the U.S. Virgin Islands. Several State Plans, like Cal/OSHA, impose requirements stricter than federal OSHA.

  • Scope of "safety." ISO 45001 explicitly folds in worker wellbeing considerations, including psychosocial risk, under its broader OH&S definition. OSHA has historically focused enforcement on physical and chemical hazards, with psychosocial and ergonomic hazards handled unevenly and mostly through the General Duty Clause or state-level rules, since OSHA withdrew its ergonomics standard in 2001.

Here's the comparison in a single view:

Dimension ISO 45001:2018 OSHA
Legal status Voluntary international standard Mandatory federal law (OSH Act of 1970)
Governing body ISO / accredited certification bodies U.S. Department of Labor / OSHA, State Plans
Verification method Third-party certification audit Government inspection, complaint, or referral
Content type Management system framework (Annex SL) Prescriptive standards + General Duty Clause
Geographic scope 100+ countries United States (federal + State Plans)
Consequence of failure Corrective action, certificate suspension Citations, monetary penalties, abatement orders
Recordkeeping Documented information per clause 7.5 OSHA 300/300A/301 logs (29 CFR 1904)
Worker involvement Explicit consultation & participation (clause 5.4) Varies by standard; emphasized in Recommended Practices

Why This Distinction Matters in Practice

I've reviewed audit files where a company's ISO 45001 certificate was current and their OSHA 300 log was a mess. Incidents were miscategorized, 301 forms were missing, and there was no evidence the required annual posting happened. The certification body's auditor wasn't looking at OSHA recordkeeping technicalities. They were sampling the management system's function. That gap is exactly where a real OSHA inspection finds citations that an ISO audit never would have flagged.

The reverse also happens. A plant can be fully OSHA-compliant on paper, with PELs respected, guards installed, and logs current, and still lack the systemic elements ISO 45001 requires: documented risk assessment methodology, leadership accountability under clause 5.1, or a genuine continual improvement loop under clause 10.3. OSHA doesn't require you to have a "safety policy" signed by top management the way ISO 45001 clause 5.2 does. Compliance and system maturity are related, but they are not the same measurement.

The practical answer is to treat OSHA standards as one of the "legal and other requirements" your ISO 45001 system tracks under clause 6.1.3. Let the ISO structure become the engine that keeps you continuously compliant, rather than compliant only on the day an inspector shows up. Done right, the ISO 45001 system becomes the operating structure, and the specific OSHA standard becomes one of the inputs that structure has to satisfy, not a separate program running in parallel.

It's also worth noting the closely related American national standard, ANSI/ASSP Z10:2019, which many U.S. companies use as a bridge because its structure and terminology map even more directly to OSHA's regulatory language while still tracking the same management-system logic as ISO 45001. Organizations that already have an ANSI/ASSP Z10 program generally find the move to ISO 45001 incremental rather than a rebuild.

Building One System That Satisfies Both

The organizations that get this right don't run "the ISO program" and "the OSHA program" as separate binders. They build a single hazard register, a single corrective action log, and a single management review that feeds both. A few things I tell clients directly:

  • Map your legal register first. Before you touch the ISO 45001 gap assessment, build the list of every OSHA standard that actually applies to your operations: general industry, construction, or the substance-specific standards relevant to your processes. That list becomes the "legal and other requirements" input ISO 45001 clause 6.1.3 asks for, and it's the single most useful document for keeping both systems aligned as regulations change.

  • Let incident investigation do double duty. A single investigation process that satisfies ISO 45001 clause 10.2 and produces the data OSHA recordkeeping needs under 29 CFR 1904 saves real time and reduces the chance of inconsistent numbers between your two systems.

  • Don't let certification create false confidence. I've said this to more than one plant manager: your ISO 45001 certificate is not a legal defense in an OSHA citation, and it was never meant to be. Use it as the structure that keeps you ahead of OSHA compliance, not as a substitute for knowing the specific standards that apply to your facility.

If you're building or auditing a safety management system and want a straight answer on whether your current program actually closes the gap between ISO 45001 conformance and OSHA compliance, that's exactly the kind of assessment my team at Certify Consulting runs for clients before certification audits and before OSHA inspections happen, not after.

FAQ

Does ISO 45001 certification exempt a company from OSHA inspections? No. ISO 45001 is a voluntary international standard verified by private certification bodies. OSHA is a federal regulatory agency with independent legal authority to inspect any covered workplace regardless of certification status.

Can a company be ISO 45001 certified and still receive OSHA citations? Yes, and it happens routinely. ISO 45001 audits sample the management system's function; they don't verify every technical detail against every applicable OSHA standard. A citation for a specific technical violation, like an unguarded machine or an expired respirator fit test, can coexist with a valid ISO 45001 certificate.

Is ISO 45001 recognized by OSHA as an official compliance framework? No. OSHA does not formally recognize or endorse ISO 45001 as satisfying any specific regulatory requirement. The two operate independently, though a well-run ISO 45001 system will generally make OSHA compliance easier to demonstrate and sustain.

What's the difference between ANSI/ASSP Z10 and ISO 45001? ANSI/ASSP Z10:2019 is the American national standard for occupational health and safety management systems, developed with closer alignment to U.S. regulatory terminology. ISO 45001 is the international equivalent. Many U.S. companies use Z10 as a stepping stone toward ISO 45001 certification because the underlying management system logic is similar.

Do I need both an ISO 45001 system and a separate OSHA compliance program? You need both sets of obligations met, but not as two separate programs. The most efficient approach builds one hazard register, one corrective action process, and one management review that treats applicable OSHA standards as inputs tracked under ISO 45001's legal requirements clause.

Last updated: 2026-08-20

J

Jared Clark

Principal Consultant, Certify Consulting

Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.