ISO 45001 Hazard Identification and Risk Assessment
ISO 45001:2018 is the international standard for Occupational Health and Safety (OH&S) management systems. At its core is the requirement to identify hazards and assess risks in the workplace. Clause 6.1.2 specifically requires organisations to establish, implement, and maintain a process for hazard identification that is proactive, systematic, and ongoing. This article explains the hazard identification requirements of ISO 45001, the categories of hazards you must consider, risk assessment methodology, the hierarchy of controls, and how to maintain a risk register.
Hazard Identification Requirements: Clause 6.1.2 Explained
Clause 6.1.2 of ISO 45001:2018 requires organisations to establish a process for hazard identification that considers:
- Work activities, including routine and non-routine situations
- Human factors and the way work is organised
- Workplace situations and installations
- Hazards arising from product design, including materials used
- Hazards arising from the design of work areas, processes, and facilities
- Changes in the organisation or its activities
- Legal requirements and industry codes of practice
- Incidents, near-misses, and ill health history
- Emergency situations
- People who could be affected, including visitors, contractors, and the public
The process must be proactive rather than reactive. You cannot wait for an accident to happen before identifying hazards. The standard also requires that the process be documented and maintained as documented information.
Hazard Categories in ISO 45001
Workplace hazards fall into five main categories. A thorough hazard identification process covers all of them.
| Category | Description | Examples |
|---|---|---|
| Physical hazards | Environmental factors that can cause harm without direct contact | Noise, vibration, radiation, extreme temperatures, poor lighting, slips and trips, moving machinery, electrical hazards |
| Chemical hazards | Hazardous substances in solid, liquid, or gas form | Solvents, acids, fumes, dusts, vapours, carcinogens, sensitisers, flammable liquids |
| Biological hazards | Living organisms or their by-products that can cause harm | Bacteria, viruses, mould, blood-borne pathogens, animal waste, fungi |
| Ergonomic hazards | Factors that place strain on the body’s musculoskeletal system | Repetitive motion, awkward postures, heavy lifting, poor workstation design, prolonged standing |
| Psychosocial hazards | Factors that affect mental health and well-being | Work-related stress, bullying, harassment, violence, excessive workload, lack of control, shift work |
Risk Assessment Methodology
ISO 45001 does not prescribe a specific risk assessment methodology. You are free to choose a method that suits your organisation’s size, complexity, and risk profile. Common methodologies include:
| Method | Best Suited For | How It Works |
|---|---|---|
| Risk matrix (5×5) | General workplace risk assessment | Likelihood x Severity = Risk rating (low, medium, high, extreme) |
| HAZID | Complex or high-hazard operations | Structured workshop with cross-functional team to identify hazards systematically |
| JSA / JHA | Specific tasks or jobs | Break task into steps; identify hazards and controls for each step |
| Bow-tie analysis | Major hazard scenarios | Visual diagram showing causes, controls, consequences, and recovery measures |
Risk Scoring and Prioritisation
Once hazards are identified, each is assessed for likelihood and severity. A typical 5×5 risk matrix multiplies the likelihood score (1–5) by the severity score (1–5) to produce a risk rating between 1 and 25. The matrix is divided into zones that guide priority for action:
| Risk Rating | Category | Required Action |
|---|---|---|
| 1–4 | Low | No immediate action required; monitor periodically |
| 5–9 | Medium | Assign responsibility; implement controls within a defined timeframe |
| 10–16 | High | Urgent action required; implement controls before work continues |
| 17–25 | Extreme | Stop work immediately; eliminate hazard or apply multiple controls before resuming |
The Hierarchy of Controls
ISO 45001 requires that organisations use the hierarchy of controls to determine appropriate risk reduction measures. The hierarchy ranks controls from most effective to least effective:
Elimination is always preferred. PPE should only be used when higher-level controls are not feasible or as a supplementary measure. Relying on PPE alone is not acceptable under ISO 45001 if a higher-level control is available.
Maintaining a Risk Register
A risk register is the documented output of the hazard identification and risk assessment process. It serves as a central record that is reviewed and updated regularly. A comprehensive risk register includes:
The risk register is a living document. It should be reviewed whenever changes occur, after incidents or near-misses, and at least annually. The register is a key input to management review.
Review and Continual Improvement
Hazard identification and risk assessment is not a one-off activity. ISO 45001 emphasises continual improvement. The review process should be triggered by:
Effective review ensures that your OH&S management system remains current and continues to protect workers.
Frequently Asked Questions
How often should hazard identification be carried out?
Hazard identification should be an ongoing process. Formal reviews are typically conducted annually, but the process should also be triggered by specific events such as introducing new equipment, changing processes, or after an incident.
Who should be involved in hazard identification?
Workers at all levels should participate. ISO 45001 emphasises consultation and participation of workers. Include employees who perform the tasks, safety representatives, supervisors, and subject matter experts such as occupational health professionals or engineers.
What is the difference between a hazard and a risk?
A hazard is anything with the potential to cause harm (e.g., a trailing cable). Risk is the combination of the likelihood of that harm occurring and the severity of its consequences. Hazard identification is the first step; risk assessment follows.
Do we need to assess risks to the public, not just employees?
Yes. ISO 45001 requires consideration of all persons who could be affected by your organisation’s activities, including contractors, visitors, and members of the public.
How do we handle psychosocial hazards under ISO 45001?
Psychosocial hazards such as stress, bullying, and excessive workload must be included in the hazard identification process. Common assessment tools include employee surveys, absence data analysis, and focus groups. Controls may include workload management, training for managers, and employee assistance programmes.
Is a risk assessment enough for ISO 45001 compliance?
No. Risk assessment is a critical element, but ISO 45001 also requires leadership commitment, worker participation, operational planning, performance evaluation, and continual improvement. The risk assessment informs these other elements but does not replace them.
Build a Safer Workplace with Bitrixme
Hazard identification and risk assessment are the foundation of a compliant and effective OH&S management system. Bitrixme provides ISO 45001 consultancy, training, and implementation support to organisations in Bahrain and across the Gulf region. Our practical approach helps you build a safer workplace while achieving certification.
Prefer instant communication? Reach us on WhatsApp.