After an ISO 45001 audit, the step before the corrective action plan reaches management review is to check whether the system was audited against the right frame. The auditor tested conformance to the hazards, objectives and indicators the organisation chose, not whether those choices fit the site.

The close-out meeting ends with two minor nonconformities, an observation about lapsed training records and a recommendation to continue certification. The next slide shows the lost-time injury frequency rate trending towards zero.

ISO 45001 is the international standard that sets requirements for an occupational health and safety management system, from hazard identification and objectives to performance evaluation and improvement.

A clean ISO 45001 audit shows the system runs as designed

A certification audit against ISO 45001:2018 covers a lot of ground. The auditor checks that the organisation has set the scope of its occupational health and safety system, consulted workers, identified hazards and assessed the risks, listed its legal requirements, set objectives, planned controls and emergency responses, measured performance, investigated incidents, audited itself and held management reviews. Findings are graded, corrective action requests are issued, and the certificate is recommended or withheld.

The outputs are concrete. A hazard register with ratings and controls. A legal register. A set of OH&S objectives, usually written as injury-rate targets. A monitoring program that feeds a dashboard to the safety committee. A closed-out list of findings. For many sites the audit is the only time all of that is gathered in one place and checked by someone independent.

It changes behaviour as well. Training records get chased, contractor inductions tighten, and incident reports start naming causes instead of stopping at worker inattention. The pattern is familiar after an ISO 9001 audit and after an ISO 14001 audit: owners get named and the paperwork starts to match the site. The audit confirms the system does what it says it does.

What the audit does not do is choose. Every check is made against settings the organisation fixed before the auditor arrived: which activities are in scope, which hazards the identification method is able to find, what the objectives count. The standard requires those settings to exist and to be followed. Whether they are the right settings is a question for the organisation's own governance, not for the certification body.

Which hazards was the register ever built to find?

Every hazard register is the product of a method. A register built from workplace inspections, job safety analyses and incident reports fills with what those methods see: slips and trips, manual handling, mobile plant, work at height, hand injuries. Those hazards are frequent, visible and personal. The same limit runs through a workplace risk assessment. The inspection walks the floor, so the floor is what it records.

Process hazards sit somewhere else. Loss of containment, overpressure, a vessel pushed below the temperature its steel can tolerate. At any single site they are rare, often absent for a whole working life, and when they arrive they can kill several people at once. Finding them takes a risk assessment method built for the purpose, such as a hazard and operability study, applied to the process rather than to the task.

The indicators follow the register. If the objectives are a lost-time injury frequency rate and a total recordable rate, the safety committee receives numbers that move with personal injuries. Those numbers can fall for years while a major-hazard exposure grows, because nothing on the list counts it. An injury rate can only report on the hazards the frame already includes.

Personal-injury frame

  • The register lists task hazards found by inspections and job safety analyses
  • The indicators count lost-time and recordable injuries
  • The audit samples training records, inductions and incident close-outs
  • A year without injuries reads as a safe year

Major-hazard frame

  • The register adds rare process hazards found by a study of the plant itself
  • The indicators count process upsets, loss-of-containment events and overdue safety-critical maintenance
  • The audit samples whether each catastrophic scenario has a control that has been tested
  • A year without injuries prompts the question of what went unreported

The evidence that certification on its own improves outcomes is thin. Robson et al. (2007) reviewed the published studies of OH&S management systems and found too little evidence to recommend them either way.

What to do after an ISO 45001 audit: the system conforms to its own frame, so check the frame before the fix
A conforming system tracks injuries and assessed task hazards, while a process hazard outside its frame never reaches the register.Click to expand

The review weighs how systems perform in general, and says nothing about any one site. What a certificate records is conformance to a frame, not the quality of the frame.

Pick the indicator your safety committee watches most closely and write down which hazard on this site could kill several people without moving it. Start the Walk →

Esso Longford and the scoreboard that counted the wrong thing

On 25 September 1998 a heat exchanger in Gas Plant 1 at Esso's Longford site in Victoria fractured. Hydrocarbon vapour escaped and ignited. Two men, Peter Wilson and John Lowery, were killed and eight were injured. Gas supply across Victoria stopped and was not fully restored until 14 October. The Longford Royal Commission, chaired by Sir Daryl Dawson with Brian Brooks, reported in June 1999.

The failure was a problem of cold. The pumps circulating warm lean oil tripped and stayed off for hours. Cold liquid kept flowing through the exchanger, GP905, which fell to as low as minus 48 degrees Celsius against a normal 100. When the pumps were restarted, warm oil entered a vessel whose steel had turned brittle, and it cracked. The Commission found that neither the operators nor their supervisors knew the danger.

Nobody on site was placed to tell them. Esso had moved all its plant engineers to Melbourne in 1992, without the risk assessment its own management of change process required. Gas Plants 2 and 3 were given HAZOP studies in 1994; the one planned for Gas Plant 1 was budgeted from 1995 to 1998 and never done. The Commission found it inconceivable that such a study would not have revealed factors that contributed to the accident.

By its own measure, Esso's safety was excellent. Hopkins, whose analysis of the accident builds on his book Lessons from Longford (2000), records that Esso measured safety by its lost-time injury rate and had driven it effectively to zero. Its incident system took reports with injury potential, so a loss of warm oil flow a month earlier, with ice on pipes normally too hot to touch, was never reported.

The management system was checked too. An external assessment in March and April 1998 concluded that Esso had successfully applied its Operations Integrity Management System. The Commission found its methodology flawed: it failed to identify significant deficiencies, particularly at Gas Plant 1. Esso never held ISO 45001, published only in 2018; the point is the frame, not the certificate. Every measure Esso watched said the plant was safe.

Each of those measures was built to count harm to individuals, not a gas plant losing containment. A root cause analysis that stopped at the operators who restarted the pumps would have found people and left the frame intact.

Test the frame before the close-out reaches management review

The step after the audit comes before the corrective action plan goes to the next management review or board safety committee. Three artefacts carry the frame: the OH&S objectives, the indicators the committee actually receives, and the hazard register together with the method used to build it. Put them on one table and ask what they assume the worst day at this site looks like.

Then test that assumption. Name the worst credible event for the operation, the one that kills several people or stops the business. Check whether it appears in the register, which method found it, and when that method was last applied. Check which indicator in the committee pack would move if the site were getting closer to it. If no indicator would move, the frame is personal injury, whatever the policy says.

A note on OHSAS 18001

OHSAS 18001, the certifiable standard ISO 45001 replaced, was first published in 1999, the year the Royal Commission reported. Neither version tells an organisation what to count: ISO 45001 leaves the choice of what to monitor and measure to the organisation being audited.

This is Frame, the first step in the Universal Decision-Making Method: settle what the decision is about before choosing what to measure. A corrective action plan written inside the old frame will close every finding and leave the frame where it was. Closing findings also needs a check that the problem stays closed: what to do after a safety audit assigns an owner to watch for recurrence. The same discipline applies after an internal audit, where the audit scope decides what can be found at all.

If the worst credible event is missing, the corrective action plan gets one more line: a process hazard study of the plant, and an indicator that moves with the event it is meant to prevent. Close the findings, then check that the system is looking at the hazard that could end the site.

You could close every finding from an ISO 45001 audit and still leave the frame that chose your indicators untested.

Work through your decision

No sign-up. Just pick your decision and start.


Grant Purdy is the co-author, with Roger Estall, of Deciding (2020), and the architect of the Universal Decision-Making Method.