Workplace safety stopped being a soft topic in India the day the Occupational Safety, Health and Working Conditions Code, 2020 extended criminal liability to directors and designated officers for workplace deaths and grievous injuries. If something goes badly wrong on your site, the question that gets asked isn't whether you cared about safety — it's what documented system you had in place to prevent it.
ISO 45001:2018 is the international standard for an Occupational Health and Safety Management System (OH&SMS). It gives you a Plan-Do-Check-Act framework for identifying hazards, controlling risks, meeting your legal obligations under Indian labour law, and — critically — proving you did all of it.
OHSAS 18001:2007 was formally withdrawn in March 2021. Every certificate issued against it has expired. There is no valid OHSAS 18001 certification anywhere in the world today.
If your safety documentation, tender submissions, or website still reference OHSAS 18001, you're effectively operating without a recognised OH&S certification. That's worth checking before your next client audit or tender qualification, because procurement teams do verify this.
Transitioning isn't just a paperwork swap either. ISO 45001 introduced requirements OHSAS 18001 never had, which brings us to the part most organisations underestimate.
Worker participation and consultation. This is the single biggest change, and the one that trips up Indian organisations most often. Workers must be consulted — given a genuine opportunity to influence OH&S decisions — not simply informed after the fact. Auditors look for evidence: safety committee minutes with worker representatives actually present, near-miss reporting that front-line staff use, HIRA workshops involving the people who do the job rather than just the EHS manager.
Leadership accountability under Clause 5. Top management commitment is explicit and mandatory. You can't delegate the whole OH&SMS to a safety officer and call it done — leadership has to demonstrate involvement.
Context of the organisation (Clause 4). A new requirement covering internal and external issues affecting OH&S performance, and the needs of interested parties — workers, contractors, regulators, clients, neighbouring communities.
Risks and opportunities, not just risks. OHSAS 18001 addressed hazards. ISO 45001 also asks what opportunities exist to improve OH&S performance.
Contractors and agency workers are explicitly in scope. This matters enormously in India, where contract and migrant labour is common. Excluding contract workers from your HIRA and training records is one of the most frequent major nonconformities raised — and under the OSH Code, it's also your largest legal exposure.
Annex SL structure. ISO 45001 shares the high-level structure used by ISO 9001 and ISO 14001, which makes an integrated management system considerably cheaper than certifying each standard separately.
Hazard Identification and Risk Assessment is the foundation of the whole system. Done properly, it covers every hazard type — physical, chemical, ergonomic, biological, and psychosocial — across every activity, including routine work, maintenance, non-routine tasks, and emergency scenarios.
Each hazard gets rated by likelihood and severity, and controls get applied in the hierarchy of controls order: eliminate the hazard, substitute it, apply engineering controls, apply administrative controls, and only then rely on PPE.
That order matters more than it sounds. A HIRA that lists "provide helmets and safety shoes" as the control for most hazards will get flagged, because PPE is the last line of defence, not the first. Auditors specifically look for whether you considered elimination and engineering controls before defaulting to PPE.
This is where the standard earns its keep for Indian businesses, and it's worth being specific rather than vague:
ISO 45001 doesn't replace any of these legal obligations. What it does is give you a system that satisfies them systematically instead of reactively, with the paper trail to prove it.
The standard is sector-neutral, but it matters most where physical risk is highest:
For an organisation with existing safety practices and reasonable statutory compliance, 3 to 6 months is realistic. Multi-site operations, construction contractors with large contract workforces, or businesses starting from minimal documentation should plan for longer.
The constraint is usually evidence. Worker participation records, training completion, mock drills, and incident investigations need to exist over a period — you can't generate three months of safety committee minutes in a week, and auditors can tell when someone has tried.
Certification body fees — priced on audit man-days, driven by headcount, number of sites, and risk profile. A single-site small to mid-sized Indian organisation typically lands in the ₹70,000 to ₹2.5 lakh range across the three-year cycle including surveillance audits. High-risk sectors and multi-site operations cost more.
Implementation costs — consulting, documentation, training, and any physical safety improvements the gap analysis identifies. For older facilities, the engineering controls portion is often the larger number.
Worth framing against what incidents actually cost. A single permanent total disability case at a mid-sized unit runs into tens of lakhs in direct and indirect costs, before accounting for production disruption, regulatory scrutiny, and litigation.
On accreditation: certificates are issued by certification bodies, and those bodies are accredited — in India, by NABCB under ISO/IEC 17021, or internationally by another IAF member. Confirm your certifier's accreditation status before engaging them. An unaccredited certificate costs less and is worth exactly nothing in a tender evaluation.
The failures we see most often aren't dramatic. A HIRA written in an office rather than on the floor. Contract workers left out of training records. A safety committee that exists on paper but has never met. Worker consultation that amounts to a notice board.
LegalDev's approach starts with a gap analysis covering documentation and physical conditions together, so you know upfront what the project actually involves. We run the HIRA on-site with your supervisors and operators, build the legal register against the Factories Act, BOCW, and OSH Code provisions that apply to you specifically, set up worker participation mechanisms that will hold up under auditor questioning, and prepare your floor staff for the interviews that happen during Stage 2. If you're also pursuing ISO 9001 or ISO 14001, we'll structure it as an integrated management system rather than three separate projects.
No. OHSAS 18001:2007 was formally withdrawn in March 2021, and all certificates issued against it have expired. ISO 45001:2018 is now the only internationally recognised occupational health and safety management system standard.
No, it isn't a legal requirement. Your statutory obligations come from the Factories Act, BOCW Act, and the OSH Code, 2020. ISO 45001 is voluntary, but it's increasingly required in government tenders, enterprise procurement, and export contracts.
Hazard Identification and Risk Assessment is the foundational document of the system. It identifies every hazard across routine, non-routine, and emergency activities, rates the risk, and assigns controls using the hierarchy of controls. Everything else in the OH&SMS follows from it.
The required order for applying controls: eliminate the hazard, substitute it with something safer, apply engineering controls, apply administrative controls, and use PPE last. Defaulting to PPE without considering the higher levels is a common audit finding.
Yes, explicitly. Contractors, subcontractors, and agency workers fall within the OH&SMS scope under ISO 45001. Excluding them from HIRA and training records is one of the most common major nonconformities, and it's also the largest legal exposure under the OSH Code, 2020.
Workers must be consulted and given a real opportunity to influence OH&S decisions, not just informed. Auditors look for functioning safety committees with worker representatives, near-miss reporting used by front-line staff, and involvement in hazard identification.
Typically 3 to 6 months for an organisation with existing safety practices. Multi-site operations or those starting with minimal documentation take longer, mainly because evidence of the system operating has to accumulate over time.
Three years, with surveillance audits usually conducted annually and a full recertification audit at the end of the cycle.
Yes, and it's usually cheaper. All three share the Annex SL high-level structure, so an integrated management system with combined audits costs less than certifying each separately.
Organisations get certified; certification bodies get accredited. Confirm your certifier holds accreditation from NABCB in India or another IAF member accreditation body. A certificate from an unaccredited provider won't survive a tender evaluation.