iso-45001-hazard-identification

By July 25th, 2026ISO Audit And Certificate7 min read

ISO 45001 Hazard Identification and Risk Assessment

ISO 45001:2018 is the international standard for Occupational Health and Safety (OH&S) management systems. At its core is the requirement to identify hazards and assess risks in the workplace. Clause 6.1.2 specifically requires organisations to establish, implement, and maintain a process for hazard identification that is proactive, systematic, and ongoing. This article explains the hazard identification requirements of ISO 45001, the categories of hazards you must consider, risk assessment methodology, the hierarchy of controls, and how to maintain a risk register.

Hazard Identification Requirements: Clause 6.1.2 Explained

Clause 6.1.2 of ISO 45001:2018 requires organisations to establish a process for hazard identification that considers:

  • Work activities, including routine and non-routine situations
  • Human factors and the way work is organised
  • Workplace situations and installations
  • Hazards arising from product design, including materials used
  • Hazards arising from the design of work areas, processes, and facilities
  • Changes in the organisation or its activities
  • Legal requirements and industry codes of practice
  • Incidents, near-misses, and ill health history
  • Emergency situations
  • People who could be affected, including visitors, contractors, and the public

The process must be proactive rather than reactive. You cannot wait for an accident to happen before identifying hazards. The standard also requires that the process be documented and maintained as documented information.

Hazard Categories in ISO 45001

Workplace hazards fall into five main categories. A thorough hazard identification process covers all of them.

CategoryDescriptionExamples
Physical hazardsEnvironmental factors that can cause harm without direct contactNoise, vibration, radiation, extreme temperatures, poor lighting, slips and trips, moving machinery, electrical hazards
Chemical hazardsHazardous substances in solid, liquid, or gas formSolvents, acids, fumes, dusts, vapours, carcinogens, sensitisers, flammable liquids
Biological hazardsLiving organisms or their by-products that can cause harmBacteria, viruses, mould, blood-borne pathogens, animal waste, fungi
Ergonomic hazardsFactors that place strain on the body’s musculoskeletal systemRepetitive motion, awkward postures, heavy lifting, poor workstation design, prolonged standing
Psychosocial hazardsFactors that affect mental health and well-beingWork-related stress, bullying, harassment, violence, excessive workload, lack of control, shift work

Risk Assessment Methodology

ISO 45001 does not prescribe a specific risk assessment methodology. You are free to choose a method that suits your organisation’s size, complexity, and risk profile. Common methodologies include:

MethodBest Suited ForHow It Works
Risk matrix (5×5)General workplace risk assessmentLikelihood x Severity = Risk rating (low, medium, high, extreme)
HAZIDComplex or high-hazard operationsStructured workshop with cross-functional team to identify hazards systematically
JSA / JHASpecific tasks or jobsBreak task into steps; identify hazards and controls for each step
Bow-tie analysisMajor hazard scenariosVisual diagram showing causes, controls, consequences, and recovery measures

Risk Scoring and Prioritisation

Once hazards are identified, each is assessed for likelihood and severity. A typical 5×5 risk matrix multiplies the likelihood score (1–5) by the severity score (1–5) to produce a risk rating between 1 and 25. The matrix is divided into zones that guide priority for action:

Risk RatingCategoryRequired Action
1–4LowNo immediate action required; monitor periodically
5–9MediumAssign responsibility; implement controls within a defined timeframe
10–16HighUrgent action required; implement controls before work continues
17–25ExtremeStop work immediately; eliminate hazard or apply multiple controls before resuming

The Hierarchy of Controls

ISO 45001 requires that organisations use the hierarchy of controls to determine appropriate risk reduction measures. The hierarchy ranks controls from most effective to least effective:

  • Elimination – Remove the hazard entirely (e.g., replace a hazardous chemical with a non-hazardous alternative).
  • Substitution – Replace the hazard with something less hazardous (e.g., use a less toxic cleaning agent).
  • Engineering controls – Isolate people from the hazard (e.g., machine guards, ventilation systems, acoustic enclosures).
  • Administrative controls – Change how people work (e.g., procedures, training, job rotation, warning signs).
  • Personal protective equipment (PPE) – Protect the worker as a last resort (e.g., safety glasses, gloves, respirators).
  • Elimination is always preferred. PPE should only be used when higher-level controls are not feasible or as a supplementary measure. Relying on PPE alone is not acceptable under ISO 45001 if a higher-level control is available.

    Maintaining a Risk Register

    A risk register is the documented output of the hazard identification and risk assessment process. It serves as a central record that is reviewed and updated regularly. A comprehensive risk register includes:

  • Unique hazard reference number
  • Description of the hazard
  • Location and activity associated with the hazard
  • Who might be harmed and how
  • Existing controls in place
  • Risk rating before controls (inherent risk)
  • Additional controls required
  • Risk rating after controls (residual risk)
  • Action owner and target completion date
  • Review date and status
  • The risk register is a living document. It should be reviewed whenever changes occur, after incidents or near-misses, and at least annually. The register is a key input to management review.

    Review and Continual Improvement

    Hazard identification and risk assessment is not a one-off activity. ISO 45001 emphasises continual improvement. The review process should be triggered by:

  • Changes to the organisation, its processes, or its legal context
  • Incidents and near-misses
  • Results of workplace inspections and audits
  • Employee feedback and hazard reports
  • New information about hazards or control technologies
  • Changes in work patterns or personnel
  • Effective review ensures that your OH&S management system remains current and continues to protect workers.

    Frequently Asked Questions

    How often should hazard identification be carried out?

    Hazard identification should be an ongoing process. Formal reviews are typically conducted annually, but the process should also be triggered by specific events such as introducing new equipment, changing processes, or after an incident.

    Who should be involved in hazard identification?

    Workers at all levels should participate. ISO 45001 emphasises consultation and participation of workers. Include employees who perform the tasks, safety representatives, supervisors, and subject matter experts such as occupational health professionals or engineers.

    What is the difference between a hazard and a risk?

    A hazard is anything with the potential to cause harm (e.g., a trailing cable). Risk is the combination of the likelihood of that harm occurring and the severity of its consequences. Hazard identification is the first step; risk assessment follows.

    Do we need to assess risks to the public, not just employees?

    Yes. ISO 45001 requires consideration of all persons who could be affected by your organisation’s activities, including contractors, visitors, and members of the public.

    How do we handle psychosocial hazards under ISO 45001?

    Psychosocial hazards such as stress, bullying, and excessive workload must be included in the hazard identification process. Common assessment tools include employee surveys, absence data analysis, and focus groups. Controls may include workload management, training for managers, and employee assistance programmes.

    Is a risk assessment enough for ISO 45001 compliance?

    No. Risk assessment is a critical element, but ISO 45001 also requires leadership commitment, worker participation, operational planning, performance evaluation, and continual improvement. The risk assessment informs these other elements but does not replace them.

    Build a Safer Workplace with Bitrixme

    Hazard identification and risk assessment are the foundation of a compliant and effective OH&S management system. Bitrixme provides ISO 45001 consultancy, training, and implementation support to organisations in Bahrain and across the Gulf region. Our practical approach helps you build a safer workplace while achieving certification.

    Prefer instant communication? Reach us on WhatsApp.