Skip to content
KnowledgeCity

By KnowledgeCity

ISO 45001 Certification and the Competence Records Auditors Ask For First

10 min read

EHS manager in a hard hat and hi-vis vest reviewing competence records on a tablet

Key Takeaways

  • ISO says adoption of the standard will not in itself guarantee prevention of work-related injury.
  • Certification is optional, and organizations implementing ISO 45001 choose whether to pursue it.
  • A person cannot be ISO 45001 certified, because certification applies to an organization's system.
  • Clause 7.2 of ISO 45001:2018 is titled Competence, within clause 7, Support.
  • OSHA states its recommended safety and health program practices are recommendations only.

A principal contractor asks you to evidence that the 6 people arriving on Monday are competent for the work they will do. Your subcontractor sends a certificate and a folder of attendance records, and nobody in that exchange can say whether those 6 people are the 6 the records describe. The certificate cannot answer that question. The standards body that wrote it says so in its own introduction.

That introduction says implementation can assure workers a management system is in place, then adds that adoption will not guarantee prevention of injury and ill health. A certificate describes your organization on the day it was audited, and the question at the gate describes 1 person on 1 task. Firms in construction and engineering rotate crews weekly, so you meet that difference often, and ISO 45001 competence records are what close it.

Why a Certificate on the Wall Answers a Different Question

Certification and competence are separate claims, and ISO keeps them separate in its own material. The introduction to ISO 45001:2018 lists the key factors the system's effectiveness depends on, from top management leadership to compliance with legal requirements. Every item on that list is an organizational capability. None of them is a statement about a named individual on a named date.

ISO also treats certification itself as a discretionary step. Its guidance confirms that organizations can be certified by third-party certification bodies, then notes that companies implementing ISO 45001 can choose whether they want to go through a certification process at all. An organization can therefore run a conforming management system and never hold a certificate, and the reverse position is the one that causes trouble on site.

The confusion is between 2 questions about that system, and separating them is most of the work:

  • Does the organization operate a management system that meets the standard, which is what a certification audit examines.
  • Was this worker competent for this task on this date, which is what a client, a principal contractor, or a coroner asks.

An audit conducted every few years answers the first question. The second is answered by a record created on the day, and the certificate has no view on it either way.

What an ISO 45001 Certificate Covers

That certificate covers a management system, and the body doing the assessing is itself governed by a separate standard. ISO/IEC 17021-1:2015 sets requirements for the competence and impartiality of certification bodies, and it describes certification as a third-party conformity assessment activity. So there are 2 competence questions in play from the outset, one about the organization and one about the auditor examining it.

The 2 Competence Questions a Certification Audit Raises

ISO 45001:2018 itself is a first edition of 41 pages, developed by technical committee ISO/TC 283, and ISO publishes its structure openly. Clause 7 is titled Support, and it contains 7.1 Resources, 7.2 Competence, 7.3 Awareness, 7.4 Communication, and 7.5 Documented information. That structure shows competence has its own clause and documented information has another, which is useful before an audit.

Those clause titles tell a reader 2 useful things:

  • Competence has its own clause, so an auditor will ask how it was determined.
  • Documented information has another, so the answer is expected to exist on paper.

The counter-argument deserves a hearing. A certificate does convey genuine information, because an accredited body examined the system and found it conforming. The certificate cannot travel down to the individual, and that limit is where most disputes begin. ISO names competence among the standard's requirements, so a certified organization is expected to hold competence evidence of its own.

The Certificate Belongs to the Organization, Never to a Person

That limit is stated most bluntly by a government agency. The Canadian Centre for Occupational Health and Safety states that a person cannot be ISO 45001 certified, and the reason follows from what certification assesses, which is an organization's management system.

COMMON BUT WRONG

Our supervisors are ISO 45001 certified.

The Canadian Centre for Occupational Health and Safety puts it plainly, stating that a person cannot be ISO 45001 certified. Certification applies to an organization's management system, and it is issued by a third-party certification body. An individual can hold ISO 45001 auditor qualifications, which makes that person competent at ISO 45001 audits, and that is a different claim from being certified to the standard.

Source: CCOHS, Occupational Health and Safety Management Systems

CCOHS draws the distinction that site teams need. An individual can hold ISO 45001 auditor qualifications, which makes that person competent at ISO 45001 audits and says nothing about certification to the standard. The same logic applies to every other role on a project, so a supervisor described in a prequalification pack as ISO 45001 certified has been described wrongly.

That matters commercially as well as legally:

  • A prequalification questionnaire asking whether personnel are ISO 45001 certified is asking for something that cannot exist, and a truthful answer looks like a gap.
  • A subcontractor answering yes to that question has misdescribed either the certificate or the person, and either version becomes a problem during an incident investigation.

Getting the wording right costs nothing and removes an argument at the worst possible moment, which is why CCOHS states the position so bluntly. The organization holds the certificate, the individual holds competence evidence, and both are recorded in different places.

Keep competence evidence per person, per date, and ready to produce.

KC LMS records what each worker completed and when, so a competence question is answered from the record on the day it is asked.

Explore KC LMS

CERTIFICATE AND COMPETENCE ARE DIFFERENT CLAIMS THE CERTIFICATE covers the organization's management system THE COMPETENCE RECORD covers one person on one date PEOPLE ARE NOT CERTIFIED certification applies to an organization CLAUSE 7.2 competence has its own clause the organization holds one, the person holds the other

Both of those records exist above a legal floor that certification does not satisfy. OSHA is explicit about its own contribution, stating that its recommended practices for safety and health programs are recommendations only. Canadian law puts that floor in legislation, and CCOHS states that most employers must have a health and safety program. A US firm and a Canadian firm therefore arrive at ISO 45001 from different starting points.

Standard

Published by

What it is

ISO 45001:2018

ISO, technical committee ISO/TC 283

The international standard, first edition, 41 pages, amended by Amendment 1:2024 on climate action changes

CSA Z45001:19, reaffirmed 2023

CSA Group

An adoption of ISO 45001:2018 with Canadian deviations, in a first edition

ANSI Z10

American National Standards Institute

The American standard, which CCOHS describes as aligned with ISO 45001

The Canadian deviations are deliberate. CSA Group states that it surveyed stakeholders across Canada and concluded that Canadian organizations would benefit from adopting ISO 45001 with deviations for the Canadian context. A contractor working both sides of the border therefore needs to know which document its client means, because the titles are identical and the texts are not.

The Records That Make Competence Visible

Whichever document a client means, the records it expects are the same, and records exist to show a system is working. It describes records as the forms and registers used to gather evidence that the management system is functioning, and it lists competence among the common elements. Read together, those 2 points say competence evidence is a record about people that someone else can check.

An auditor checking those records works through the same short sequence every time:

  1. Which roles on this project affect health and safety outcomes.
  2. For each of those roles, what the organization decided competence requires.
  3. For each named worker in those roles, what evidence exists that they meet it.
  4. What the organization did where the evidence was missing.

A certificate answers none of those 4, and clause 7.2's title tells the auditor competence is in scope. The evidence itself comes from the register the organization keeps, which is why the register matters more than the certificate during an audit.

Why an Attendance Record Answers None of Them

Attendance records fail in a specific way. A signature on a sign-in sheet records that a person was present in a room, and presence is the weakest available proxy for capability. A record showing what the person completed, on what date, and against which role requirement answers question 3 directly, and it does so without anyone reconstructing the training calendar from memory.

Certification Tracking Before the Audit Is Booked

Firms that pass that examination comfortably built the register long before booking the audit. Certification tracking is the unglamorous name for it, and recertification 3 years on asks the same questions again. Training compliance of this kind is mostly clerical, and it means deciding which roles affect safety outcomes and recording what each person completed. Clause 7.2's title is the only part of ISO 45001:2018 you need to know this is in scope.

That register is built from a short checklist, worth working through before the audit date:

  1. List the roles on your project whose work affects health and safety outcomes.
  2. Write down, for each role, the competence your organization has decided it requires.
  3. Keep dated evidence, for each worker in the role, of what they completed.
  4. Maintain a gap list, and record what was done about each gap and when.
  5. Correct the wording in your prequalification answers, describing the organization as certified and the individual as competent.

Those 5 items are a records discipline, and each one needs an owner. KC LMS records what each worker completed and on what date, which turns question 3 into a query you can answer in seconds. Where the wider gaps need addressing first, our guidance on construction site compliance gaps and on EHS incident management describes what a contractor works through before an audit.

Frequently Asked Questions

1. Can a person be ISO 45001 certified?

No. The Canadian Centre for Occupational Health and Safety states that a person cannot be ISO 45001 certified, because certification applies to an organization's management system and is issued by a third-party certification body. An individual can hold ISO 45001 auditor qualifications, which makes that person competent at ISO 45001 audits. That is a claim about audit skill rather than certification to the standard.

2. Is ISO 45001 certification mandatory?

No. ISO states that organizations can be certified by third-party certification bodies, and that companies implementing ISO 45001 can choose whether they want to go through a certification process. OSHA separately states that its recommended practices for safety and health programs are recommendations only and that employers are not required to have a program meeting them.

3. Does ISO 45001 certification prove the workplace is safe?

ISO does not claim that. The introduction to ISO 45001:2018 states that demonstrating successful implementation can give assurance to interested parties that an effective management system is in place, and that adoption of the document will not in itself guarantee prevention of work-related injury and ill health, safe and healthy workplaces, or improved performance.

4. Which clause of ISO 45001 covers competence?

Clause 7.2, titled Competence, within clause 7, Support. ISO publishes the structure of ISO 45001:2018, in which clause 7 contains 7.1 Resources, 7.2 Competence, 7.3 Awareness, 7.4 Communication, and 7.5 Documented information. ISO also lists training, awareness and competence among the standard's key requirements.

5. What is the difference between ISO 45001 and CSA Z45001?

CSA Z45001:19, reaffirmed in 2023, is an adoption of ISO 45001:2018 with Canadian deviations, published by the CSA Group in a first edition. CSA Group states it surveyed Canadian stakeholders and concluded that Canadian organizations would benefit from adopting the ISO standard with deviations reflecting the Canadian context. The titles are identical, so a contractor should confirm which document a client means.

References

  1. International Organization for Standardization. "ISO 45001:2018, Occupational health and safety management systems, requirements with guidance for use."
  2. International Organization for Standardization. "ISO 45001:2018, table of contents and introduction, Online Browsing Platform."
  3. International Organization for Standardization. "ISO 45001 explained."
  4. International Organization for Standardization. "ISO/IEC 17021-1:2015, Conformity assessment, requirements for bodies providing audit and certification of management systems."
  5. CSA Group. "CSA Z45001:19 (R2023), Occupational health and safety management systems, adopted ISO 45001:2018 with Canadian deviations."
  6. Canadian Centre for Occupational Health and Safety. "Occupational Health and Safety Management Systems."
  7. Occupational Safety and Health Administration. "Recommended Practices for Safety and Health Programs, OSHA 3885."

Everything your workforce needs, on one platform.

A quick walkthrough tailored to your team — learning, compliance, skills, and performance in one place.