ISO 45001 · Step-by-step series · Article 3 of 7
ISO 45001 Clause 6: Planning — Hazard Identification and OH&S Risk Assessment
Clause 6 of ISO 45001:2018 is where the occupational health and safety management system stops being a policy statement and becomes an operating plan. It requires the organization to identify hazards proactively, assess the OH&S risks and opportunities that follow from them, determine which legal and other requirements apply, and translate all of this into concrete, resourced actions with measurable objectives. Get clause 6 wrong and every downstream control in clause 8 ends up addressing the wrong hazards. This guide walks through each subclause with the practical detail an implementer needs.
Hazard identification is the foundation clause auditors probe hardest in ISO 45001
Across sector guidance and certification body experience, incomplete hazard identification — missing routine, non-routine, and emergency scenarios, or excluding contractors and visitors from scope — is consistently cited as one of the most common root causes behind OH&S nonconformities and, more importantly, behind real incidents that a proper 6.1.2 process should have anticipated.
Structure of clause 6: from hazard to action
Clause 6 follows a logical chain: first you identify what could go wrong (hazards), then you assess how serious that is (risk) and whether there's upside to capture (opportunities), then you check what the law and other commitments require, and finally you turn all of that into a plan with objectives and resources. The subclauses are:
- 6.1 Actions to address risks and opportunities: the umbrella requirement — general planning considerations before any hazard-specific work.
- 6.1.1 General: what the organization must consider when planning the OH&S management system.
- 6.1.2 Hazard identification and assessment of risks and opportunities: the operational core — identifying hazards (6.1.2.1), assessing OH&S risks and other risks to the management system (6.1.2.2), and assessing OH&S opportunities and other opportunities (6.1.2.3).
- 6.1.3 Determination of legal requirements and other requirements: mapping applicable law, regulations, and voluntary commitments.
- 6.1.4 Planning action: deciding what to actually do about the risks, opportunities, and requirements identified.
- 6.2 OH&S objectives and planning to achieve them: setting measurable targets (6.2.1) and the concrete action plans to reach them (6.2.2).
6.1.1 General: planning with the whole system in view
Before hazard identification even starts, clause 6.1.1 requires the organization to consider the issues referenced in clause 4 (context of the organization — internal and external issues) and the requirements referenced in clause 4.2 (needs and expectations of workers and other interested parties), and to determine the risks and opportunities that need to be addressed to give reasonable assurance that the OH&S management system can achieve its intended outcomes, prevent or reduce undesired effects, and achieve continual improvement.
In plain terms: you don't jump straight to a hazard checklist. You first ask what's happening in and around the business — new processes, new sites, ageing workforce, changing regulation, worker concerns raised through consultation — because these context factors shape which hazards matter most and which risks deserve the most planning effort.
6.1.2.1 Hazard identification: routine, non-routine, and the scenarios people forget
This is the subclause that does the heavy lifting. The organization must establish, implement, and maintain a process for hazard identification that is ongoing and proactive, and that considers, as a minimum, the sources listed in the standard:
- How work is organized and social factors — workload, work hours, victimization, harassment, and bullying.
- Routine and non-routine activities and situations — including hazards arising from infrastructure, equipment, materials, substances, and the physical conditions of the workplace.
- Past relevant incidents — internal or external, including emergencies, and their causes.
- Potential emergency situations.
- People — including access, exposure to those in the vicinity of work, people not directly performing work activities but affected by them, workers at locations not under direct organizational control, and people in the vicinity of workplaces who can be affected by the organization's activities.
- Other issues — design of work areas, processes, installations, machinery/equipment, operating procedures, and work organization, including their adaptation to human capabilities.
- What has happened, internally or externally, including emergencies, and their causes.
- How the work is actually done versus how it is documented — the gap between the procedure on paper and behavior in the field.
- Changes — actual and proposed changes in the organization, its operations, processes, activities, and the OH&S management system.
- Changes in knowledge of, and information about, hazards.
Practical tip
Build hazard identification around three buckets you can walk through with any work team: routine tasks (what happens every shift), non-routine tasks (maintenance, changeover, cleaning, one-off jobs), and emergency scenarios (fire, chemical spill, evacuation). Most gaps auditors find sit in the non-routine and emergency buckets — a maintenance technician entering a confined space once a quarter is a far higher-risk moment than the operator running the line every day, yet it's the one hazard log that often gets skipped because "it's not routine work."
6.1.2.2 Assessment of OH&S risks and other risks: turning hazards into numbers you can act on
Once hazards are identified, clause 6.1.2.2 requires the organization to establish, implement, and maintain a process to assess OH&S risk from identified hazards, taking into account the effectiveness of existing controls, and to assess other risks related to the establishment, implementation, operation, and maintenance of the OH&S management system.
ISO 45001 deliberately does not prescribe a specific risk assessment methodology. What it does require is that the methodology and criteria are defined with respect to the scope, nature, and timing of the risk assessment, to ensure it is proactive rather than reactive, and applied in a systematic way. Common approaches used in industry include:
- Likelihood × severity matrices — the most widely used method, scoring probability of occurrence against potential consequence severity to produce a risk level (low/medium/high or a numeric score).
- Job Safety Analysis (JSA) / Job Hazard Analysis (JHA) — breaking a specific task into steps and assessing the hazard at each step, well suited to non-routine or high-risk tasks.
- HAZOP (Hazard and Operability Study) — used in process industries for systematic examination of deviations from design intent.
- Bowtie analysis — mapping causes and consequences on either side of a top event, useful for major-hazard scenarios with multiple barriers.
Whatever method is chosen, the assessment must account for the effectiveness of controls already in place — a machine with a well-maintained interlock guard is a different risk than the same machine with a guard that's routinely bypassed. This is also where the hierarchy of controls (elimination, substitution, engineering controls, administrative controls, PPE) becomes relevant for planning the response in 6.1.4.
6.1.2.3 Assessment of OH&S opportunities and other opportunities
ISO 45001 is unusual among management system standards in explicitly requiring the assessment of OH&S opportunities, not just risks. Clause 6.1.2.3 asks the organization to assess opportunities to enhance OH&S performance, considering planned changes to the organization, its policies, its processes, or its activities, and opportunities to adapt work, work organization, and work environment to workers.
In practice this means looking beyond "how do we stop this hazard from hurting someone" and asking "is there a way to redesign the task so the hazard doesn't exist at all, or so performance improves at the same time." Examples include eliminating a manual handling task through mechanization (which removes a musculoskeletal risk and often increases throughput), or consolidating maintenance shutdowns to reduce the frequency of high-risk confined space entries. The standard also requires assessment of "other opportunities" for improving the OH&S management system itself — process efficiencies, better data collection, or improved worker consultation mechanisms.
6.1.3 Legal requirements and other requirements: knowing what applies before you plan
Clause 6.1.3 requires the organization to establish, implement, and maintain a process to determine and have access to up-to-date legal requirements and other requirements applicable to its hazards, OH&S risks, and OH&S management system; to determine how these requirements apply and what needs to be communicated; and to take these requirements into account when establishing, implementing, and maintaining the OH&S management system.
"Legal requirements" covers national, regional, and local occupational health and safety legislation and regulations that apply to the organization's activities. "Other requirements" is broader and typically includes:
- Requirements from industry codes of practice or sector-specific technical standards.
- Contractual requirements imposed by clients (particularly common in construction and industrial services).
- Agreements with worker representative bodies, trade unions, or works councils.
- Voluntary principles or codes of practice the organization has agreed to follow.
- Corporate group policies that go beyond local legal minimums.
Documented information demonstrating compliance with 6.1.3 must be kept up to date — this typically means a legal register with review dates, an owner responsible for each regulatory area, and a mechanism to catch legislative changes before they take effect, not after an inspector points them out.
6.1.4 Planning action: closing the loop
Clause 6.1.4 requires the organization to plan actions to address the risks and opportunities identified in 6.1.2, the legal and other requirements identified in 6.1.3, and to prepare for and respond to emergency situations (as detailed further in clause 8.2). Critically, the standard requires that when planning these actions, the organization considers the hierarchy of controls and the outputs from the OH&S management system, and evaluates how effective the planned actions will be.
This is also where 6.1.4 explicitly requires integration: the actions planned must be integrated into the organization's OH&S management system processes or other business processes, and their effectiveness must be evaluated. A risk assessment that produces an action plan nobody funds or schedules is a paper exercise; 6.1.4 is the clause that ties planning to real resourcing and follow-through.
6.2 OH&S objectives and planning to achieve them
Clause 6.2.1 requires the organization to establish OH&S objectives at relevant functions and levels, to achieve maintenance and continual improvement of the OH&S management system and OH&S performance. Objectives must be consistent with the OH&S policy, measurable (if practicable) or capable of performance evaluation, take into account applicable requirements, take into account the results of risk and opportunity assessment, take into account the results of consultation with workers, and be monitored, communicated, and updated as appropriate.
Clause 6.2.2 then requires an action plan for each objective, defining: what will be done; what resources will be required; who will be responsible; when it will be completed; and how the results will be evaluated, including indicators for monitoring, with consideration of how actions to achieve OH&S objectives can be integrated into the organization's business processes.
Example of a well-formed OH&S objective under 6.2
"Reduce confined-space entry incidents in the maintenance department to zero by Q4, by installing gas detection interlocks on entry points (responsible: maintenance manager, budget approved, due end of Q2) and completing refresher confined-space training for all authorized entrants (responsible: HSE coordinator, due end of Q1), monitored monthly via the permit-to-work log and incident register." This objective is measurable, tied to specific actions with owners and dates, and traceable back to a hazard identified in 6.1.2.1 and a risk assessed in 6.1.2.2.
| Subclause | What it requires | Typical evidence |
|---|---|---|
| 6.1.1 | Consider context and worker needs before planning | Context analysis linked to planning inputs |
| 6.1.2.1 | Identify hazards — routine, non-routine, emergency | Hazard register / JSA library |
| 6.1.2.2 | Assess OH&S risk and other management system risks | Risk matrix / assessment records |
| 6.1.2.3 | Assess OH&S opportunities and system opportunities | Opportunity log tied to planned changes |
| 6.1.3 | Determine legal and other requirements | Legal register with review dates and owners |
| 6.1.4 | Plan actions using hierarchy of controls | Action plans linked to risk register entries |
| 6.2.1 / 6.2.2 | Set measurable OH&S objectives and action plans | OH&S objectives tracker with owners, dates, KPIs |
Common audit findings on clause 6
Recurring gaps seen across OH&S management system audits when it comes to clause 6:
- 6.1.2.1 — Non-routine and emergency scenarios missing from the hazard register: the log covers daily operations well but has nothing on shutdown maintenance, contractor work, or emergency response.
- 6.1.2.1 — Contractors and visitors excluded from scope: hazard identification only considers direct employees, missing people affected by the organization's activities who aren't on payroll.
- 6.1.2.2 — Risk assessment not accounting for existing controls: a hazard is rated as if no mitigation exists, or conversely a control is assumed effective without verification it's actually maintained and used.
- 6.1.3 — Legal register out of date: no defined process or owner for tracking regulatory changes, so new requirements are only discovered reactively.
- 6.2.1 — Objectives that aren't measurable: vague statements like "improve safety culture" with no indicator, target, or evaluation method attached.
// IgeraIndustria demo — clause 6 planning query
HSE Coordinator: Which identified hazards still don't have a completed risk assessment under 6.1.2.2?
IgeraIndustria: 3 hazards pending risk assessment. HZ-2026-014 — confined space entry, tank cleaning bay 2, identified 12/06/2026, no assessment recorded, flagged high-priority due to non-routine classification. HZ-2026-018 — manual handling, new pallet configuration in warehouse B, identified 20/06/2026, assessment overdue by 9 days per internal SLA. HZ-2026-021 — contractor electrical work near live panels, identified 25/06/2026, no assessment, contractor scheduled on-site in 5 days. Recommendation: prioritize HZ-2026-021 given the imminent contractor date.
Auditor: Show me the legal register entries reviewed in the last quarter.
IgeraIndustria: Legal register — Q2 2026 review cycle: 14 applicable regulations reviewed, owner: HSE Manager S. Torres. 1 update identified: revised confined-space entry permit requirements effective 01/09/2026, action assigned to update SOP-CS-004, due 15/08/2026. All other 13 requirements confirmed current with no changes. Next scheduled review: Q3 2026.
Frequently asked questions about ISO 45001 clause 6
Does ISO 45001 require a specific risk assessment methodology?
No. ISO 45001 clause 6.1.2.2 requires the organization to define its own methodology and criteria for OH&S risk assessment, appropriate to the scope, nature, and timing of the assessment, and applied proactively and systematically. Common choices are likelihood/severity matrices, Job Safety Analysis, HAZOP, and bowtie analysis, but the standard leaves the choice to the organization as long as it's consistently applied and considers existing controls.
What is the difference between hazard identification (6.1.2.1) and risk assessment (6.1.2.2)?
Hazard identification is finding the sources of potential harm — a rotating shaft, a chemical, a working-at-height task. Risk assessment is evaluating how likely that hazard is to cause harm and how severe the consequence would be, factoring in the controls already in place. You can't do 6.1.2.2 properly without a thorough 6.1.2.1 — an incomplete hazard list guarantees an incomplete risk picture, no matter how sophisticated the scoring method is.
Why does ISO 45001 ask organizations to assess opportunities, not just risks?
Clause 6.1.2.3 reflects the standard's intent that OH&S management should be more than damage limitation. By requiring organizations to look for opportunities — redesigning a task to remove a hazard entirely, adapting equipment to reduce physical strain, or improving how the management system itself functions — ISO 45001 pushes planning beyond reactive control selection toward genuine improvement of working conditions and performance.
Who counts as an "other requirement" under clause 6.1.3 besides legislation?
Other requirements include industry codes of practice, contractual obligations from clients (common in construction and industrial services contracts), agreements with worker representatives or unions, voluntary commitments the organization has made publicly, and internal corporate group standards that exceed local legal minimums. All of these must be tracked and factored into planning alongside statutory legal requirements.
Must every OH&S objective under 6.2.1 be numerically measurable?
The standard requires objectives to be measurable if practicable, or otherwise capable of performance evaluation. Most OH&S objectives can and should carry a numeric target (incident rate, percentage of overdue actions closed, number of confined-space entries requiring a specific control), but where a numeric measure genuinely isn't practicable, the organization must still be able to demonstrate a clear method for evaluating whether the objective was achieved.
How does clause 6 planning connect to clause 8 operational controls?
Clause 6 is where hazards are identified, risks assessed, and control actions planned using the hierarchy of controls. Clause 8 (Operation) is where those planned actions are actually implemented — operational controls, management of change, procurement, contractor management, and emergency preparedness and response. An auditor will typically trace a specific hazard from the 6.1.2.1 register through its 6.1.2.2 risk rating, its planned action in 6.1.4, and finally to the operational control implemented under clause 8 — a broken link anywhere in that chain is a nonconformity.
Struggling to keep your hazard register, risk assessments, and legal register in sync?
IgeraIndustria centralizes clause 6 records — hazard identification, OH&S risk assessments, legal requirement tracking, and objective action plans — with real-time status instead of scattered spreadsheets.
View ISO 45001 solutionExpert ISO 45001 · Updated 2026-07-31 · ISO 45001 step-by-step series: Article 1 — Clause 4 · Article 2 — Clause 5 · Article 4 — Clause 7 · Article 5 — Clause 8 · Article 6 — Clause 9 · Article 7 — Clause 10