ISO 45001 · Step-by-step series · Article 1 of 7
ISO 45001 Clause 4: Context of the Organization for OH&S Management
Clause 4 is the foundation on which the entire ISO 45001 occupational health and safety (OH&S) management system is built. Before you write a single procedure or plan a single risk assessment, the standard requires you to step back and understand the organization you are actually operating: what internal and external factors shape your safety performance, who has a stake in the outcome, and where exactly the boundaries of your management system sit. Skip this step or treat it as a paperwork formality, and every later clause — planning, support, operation, evaluation, improvement — inherits a weak foundation. This guide opens our seven-part series on ISO 45001 and breaks down each subclause of clause 4 with practical detail.
A weak clause 4 analysis is one of the most common root causes of scope disputes during ISO 45001 audits
Auditors consistently report that organizations struggle to justify why certain sites, contractors, or activities were excluded from the OH&S management system scope. When the context analysis in clause 4 is superficial, the scope statement in 4.3 tends to be arbitrary rather than evidence-based, which becomes a recurring finding across surveillance audits.
Structure of clause 4: four building blocks
Clause 4 of ISO 45001:2018 is organized into four subclauses that build on each other logically:
- 4.1 Understanding the organization and its context: identifying the internal and external issues relevant to your OH&S purpose and performance.
- 4.2 Understanding the needs and expectations of workers and other interested parties: who matters to your OH&S system and what they require.
- 4.3 Determining the scope of the OH&S management system: drawing the boundaries — which sites, activities, and functions are covered.
- 4.4 OH&S management system: establishing, implementing, maintaining, and continually improving the system in line with the standard's requirements.
4.1 Understanding the organization and its context
Clause 4.1 requires the organization to determine the external and internal issues relevant to its purpose that affect its ability to achieve the intended outcomes of its OH&S management system — namely, preventing work-related injury and ill health to workers, and providing safe and healthy workplaces. This is not a generic SWOT exercise borrowed from strategic planning; it is specifically about the issues that influence, positively or negatively, your capacity to manage occupational risk.
External issues typically include: the regulatory and legal environment for OH&S in your jurisdiction and sector, the physical environment where work is carried out (climate, terrain, seismic risk, urban vs. remote location), market and competitive conditions that affect staffing levels and workload, technological developments that introduce new hazards or new controls, and the presence and influence of contractors, suppliers, or clients who share the workplace.
Internal issues typically include: the organization's governance structure and lines of authority for OH&S decisions, the nature of the workforce (age profile, experience level, use of temporary or agency workers, shift patterns), the complexity and layout of facilities and equipment, the organizational culture around safety reporting and near-miss disclosure, and the maturity of existing management systems that the OH&S system must integrate with, such as ISO 9001 or ISO 14001.
Practical tip
You do not need a separate, lengthy document titled "Context Analysis." Many organizations integrate this into the management review agenda or the annual risk register review, provided the outputs are documented and demonstrably used as an input to clauses 6.1 (risk and opportunity planning) and 4.3 (scope). What matters to an auditor is traceability: can you show that a specific external or internal issue identified here actually shaped a decision downstream — a control measure, a training program, or a scope exclusion?
4.2 Understanding the needs and expectations of workers and other interested parties
Clause 4.2 is where ISO 45001 diverges most visibly from ISO 9001 and ISO 14001. The standard explicitly singles out workers as an interested party — not just "interested parties" generically — and requires the organization to determine the needs and expectations of workers, plus other relevant interested parties, and identify which of those needs and expectations are, or could become, legal requirements and other requirements.
Interested parties relevant to an OH&S management system typically include:
- Workers and their representatives: employees, temporary staff, agency workers, and — where applicable — union or worker safety representatives. Their needs include safe working conditions, participation in decisions that affect their safety, and protection from reprisal when reporting hazards.
- Regulators and enforcement authorities: labor inspectorates, occupational health authorities, and licensing bodies whose requirements are typically legal requirements rather than mere expectations.
- Contractors and subcontractors working on-site: their safety performance directly affects the host organization's OH&S outcomes and legal exposure.
- Clients and visitors: anyone who enters the workplace and is exposed to its hazards, even without being an employee.
- Insurers: whose risk assessments and premium conditions often set de facto operational requirements.
- Local communities: particularly relevant where the organization's activities carry off-site risk, such as chemical storage or heavy transport.
A common gap auditors flag under 4.2 is treating "worker consultation" as a box-ticking exercise — a single annual survey — rather than an ongoing mechanism. Clause 5.4 later requires consultation and participation of workers as an operational requirement, but the seed of that requirement is planted here in 4.2, where you first identify what workers actually need from the system in order to trust and engage with it.
4.3 Determining the scope of the OH&S management system
Clause 4.3 requires the organization to determine the boundaries and applicability of the OH&S management system to establish its scope, and to make that scope available as documented information. Unlike some other management system standards, ISO 45001 is explicit that the scope must consider the activities, products, and services within the organization's control or influence that can impact its OH&S performance — and, critically, the standard states that the scope shall not be used to exclude an activity, product, or service that has, or could have, an impact on the organization's OH&S performance.
In defining scope, the organization must take into account:
- The external and internal issues identified in 4.1.
- The requirements identified in 4.2 relating to workers and other interested parties.
- The planned or performed work-related activities across all sites and functions.
A frequent audit finding is a scope statement that excludes a warehouse, a satellite site, or a category of contract labor with no documented justification tracing back to 4.1 or 4.2. If a site or activity is within the organization's control — even partial control, such as a leased facility where the organization manages worker safety but not the building's structural maintenance — it generally needs to be addressed within the scope, with the boundaries of control clearly defined rather than silently omitted.
4.4 The OH&S management system itself
Clause 4.4 is short in wording but broad in consequence: the organization shall establish, implement, maintain, and continually improve an OH&S management system, including the processes needed and their interactions, in accordance with the requirements of the standard. In effect, 4.4 is the bridge from context analysis (4.1–4.3) to everything that follows in clauses 5 through 10. It signals that the outputs of understanding context and interested parties are not academic — they must be embedded into a living, operating system with defined processes, not just a policy statement on a wall.
For organizations that already run ISO 9001 or ISO 14001, clause 4.4 is also where the integration opportunity is greatest. Because all three standards share the same Annex SL high-level structure — the same clause numbers and titles from 4 through 10 — many organizations choose to build a single integrated management system manual, integrated risk registers, and shared document control processes, with OH&S-specific content layered in at each clause. This is not a requirement of ISO 45001 itself, but it is the most common and cost-effective practice observed across certified sites.
How clause 4 connects to the rest of the standard
| Clause 4 subclause | Feeds directly into | Typical evidence |
|---|---|---|
| 4.1 Context | Clause 6.1 (risks and opportunities), clause 5.1 leadership review | Context register, management review minutes referencing external/internal issues |
| 4.2 Interested parties | Clause 5.4 (worker consultation), clause 6.1.3 (legal requirements) | Interested parties register, worker consultation minutes |
| 4.3 Scope | Clause 4.4 (system boundaries), certification audit scope | Published scope statement (documented information) |
| 4.4 OH&S system | All of clauses 5–10 | Process map, integrated management system manual |
Common audit findings under clause 4
Across ISO 45001 certification and surveillance audits, these are among the most frequently cited gaps related to clause 4:
- 4.1 — Generic, unreviewed context analysis: the same context document is carried over year after year without evidence it was revisited when circumstances changed (new site, new regulation, new type of contractor).
- 4.2 — No formal register of interested parties: worker needs are assumed rather than documented, with no clear link from a specific need to a specific control or process.
- 4.2 — Worker consultation treated as a formality: a single annual survey used as sole evidence, with no ongoing mechanism for workers to raise needs between reviews.
- 4.3 — Undocumented scope exclusions: a site, shift, or contractor category left out of the stated scope with no justification tied back to the context or interested-party analysis.
- 4.3 — Scope statement not available as documented information: the scope exists informally in a manager's head or an old proposal document, not published as controlled documented information as the standard requires.
// Demo IgeraIndustria — OH&S context and scope query
OH&S Manager: Which internal issues from our clause 4.1 register haven't been reviewed in the last 12 months?
IgeraIndustria: 2 internal issues flagged as overdue for review. "Increase in agency/temporary workforce ratio" — last reviewed 14/06/2025, 13 months overdue, linked to risk register entries RR-2025-014 and RR-2025-019. "Integration of new automated packaging line" — last reviewed 02/03/2025, 16 months overdue, no linked risk assessment on file. Recommended action: schedule context review in next management meeting and confirm whether risk assessments need updating for the packaging line.
Auditor: Show me the justification for excluding the offsite storage facility from the OH&S scope.
IgeraIndustria: No documented justification found for excluding "Offsite Storage Facility — Ref. SF-03" from the published scope statement (v.4, approved 10/01/2026). The facility appears in the site register with 4 assigned workers and is referenced in interested-party entry IP-011 (facility staff). Flag: this exclusion is not traceable to clause 4.1 or 4.2 analysis and should be reviewed before the next surveillance audit.
Frequently asked questions about ISO 45001 clause 4
Why does ISO 45001 name "workers" separately instead of folding them into "interested parties"?
ISO 45001 is unique among the major Annex SL standards in explicitly singling out workers because the entire purpose of the standard is to prevent injury and ill health to the people doing the work. Treating workers as just one interested party among many risks diluting the requirement to consult and involve them directly. By naming them separately in clause 4.2, the standard makes worker input a distinct, non-negotiable input to the management system, which later becomes an operational requirement in clause 5.4 on consultation and participation.
Can we exclude a hazardous activity from the OH&S management system scope if it's outsourced?
Generally no, not simply because it is outsourced. ISO 45001 clause 4.3 is explicit that scope cannot be used to exclude an activity that has, or could have, an impact on the organization's OH&S performance. If an outsourced activity is performed on your premises, or if your organization retains any influence over how it is carried out, it typically needs to be addressed — either within the scope directly or through the control mechanisms required under clause 8.1.4 on procurement and contractors.
How often should the context analysis in clause 4.1 be reviewed?
ISO 45001 does not set a fixed frequency. The common practice is to review context as part of the periodic management review (typically annually) and additionally whenever a significant change occurs — a new site, a merger, new regulation, a major change in workforce composition, or the introduction of new equipment or processes. What auditors look for is evidence that the review actually happens and that it demonstrably feeds into risk planning, not just that a document exists.
Does clause 4.2 require us to survey every interested party formally?
No. The standard requires the organization to determine relevant interested parties and their needs and expectations, but it does not prescribe a specific method such as a formal survey. What is required is that the determination be documented, that it identify which needs and expectations are or could become legal requirements, and that it be genuinely used as an input to planning. Methods can range from structured worker consultation meetings to review of regulatory correspondence and contractor agreements.
What is the difference between clause 4.3 scope and the scope statement on the certificate?
They should be the same, or the certificate scope should be a faithful summary of the documented scope required under 4.3. A common nonconformity arises when an organization's internal documented scope (say, including three manufacturing sites and a distribution center) doesn't match what's actually stated on the certification body's certificate, often because a site was added or removed without updating both documents in parallel.
How does clause 4 differ in practice between ISO 45001, ISO 9001, and ISO 14001?
All three standards share the identical clause 4 structure and titles under the Annex SL high-level structure, but the content each expects is different. ISO 9001's clause 4 focuses on issues affecting product and service quality and customer satisfaction. ISO 14001's clause 4 focuses on environmental conditions, aspects, and impacts, including a life cycle perspective. ISO 45001's clause 4 focuses specifically on issues, needs, and scope relevant to preventing work-related injury and ill health — which is why workers are named explicitly as an interested party in 4.2, a feature not present in the equivalent clauses of the other two standards.
Struggling to keep your OH&S context and interested-party analysis current across multiple sites?
IgeraIndustria centralizes clause 4 documentation — context registers, interested-party analysis, scope statements — and flags overdue reviews automatically, without digging through spreadsheets before every audit.
See the ISO 45001 solutionExpert ISO 45001 · Updated 2026-07-31 · ISO 45001 step-by-step series: Article 2 — Clause 5 · Article 3 — Clause 6 · Article 4 — Clause 7 · Article 5 — Clause 8 · Article 6 — Clause 9 · Article 7 — Clause 10