ISO 45001:2018 "Occupational health and safety management systems – Requirements with guidance for use" is applicable to any organization that wishes to establish, implement, and maintain an OH&S management system to improve occupational health and safety, eliminate hazards, minimize OH&S risks, take advantage of OH&S opportunities, and address OH&S management system nonconformities related to its activities.
"Documented information" consists of information that must be controlled and maintained by an organization and the media on which it resides. This information can, in fact, be in any format and reside on any medium. We can have documented information on paper, on magnetic or electronic media, on photographic media, or on a combination of these. Examples of documented information can be records, specifications, procedures, drawings, etc. Documented information is divided into two types, even if the new version of the standard no longer distinguishes them:
1. records – are the documented information that provides “proof” that a process has taken place in a certain way and that must be kept to demonstrate it. Once prepared and compiled, they are no longer updated because they provide evidence of the results achieved or the activities carried out such as, for example, evidence of training activities, operational control of processes, corrective actions, how the internal audit took place, the management review, etc.
2. documents – documents are, generically, all the documented information that does not fall under records. They can easily be updated, indeed they must be to follow the evolution of the health and safety at work system. It is the information created so that the organization can operate such as, for example, procedures, work instructions, specifications, guidelines, and criteria
If a company wants to obtain ISO 45001 certification, it must, obligatorily, prepare some documents which are not necessarily enough to describe how it manages the health and safety of its workers but which constitute the minimum "package" required by the standard.
Let's see together what documents are involved:
- Paragraph 4.3 "Determining the scope of the OH&S management system" – The scope of the management system must be provided as documented information.
- Paragraph 5.2 "OH&S Policy" – The Occupational Health and Safety Policy must be prepared and made available.
- Paragraph 5.3 "Organizational roles, responsibilities and authorities" – Responsibilities and authorities within the OH&S must be assigned and maintained as documented information.
- Paragraph 6.1.1 "Actions to address risks and opportunities - General" – In this case, the documented information must include the list of risks and opportunities and the processes necessary to determine and address them.
- Paragraph 6.1.2.2. "Assessment of OH&S risks and other risks to the OH&S management system" – The methodology and criteria for the assessment of OH&S risks must be documented.
- Paragraph 6.1.3 "Determination of legal requirements and other requirements" – Documented information on its legal requirements and other requirements must be produced and updated over time.
- Paragraph 6.2.2 "Planning to achieve OH&S objectives" – Documented information on the OH&S objectives and plans to achieve them must be kept.
- Paragraph 7. 2 "Competence" – Documented information must be kept regarding the skills of people who influence or may influence the organization's performance in terms of managing health and safety at work.
- Paragraph 7.4.1 "Communication - General" – Documented information must be kept that highlights communications relating to the OH&S.
- Paragraph 8.2 "Emergency preparedness and response" – The documented information in this case will concern the processes and plans for responding to potential emergency situations.
- Paragraph 9.1.1. "Monitoring, measurement, analysis and performance evaluation - General" – Documented information must be kept relating to the results of the monitoring, measurement, analysis, and evaluation of performance as well as those of the maintenance, calibration or verification of the equipment used for the measurements.
- Paragraph 9.1.2 "Compliance evaluation" – The results of the compliance evaluation must be kept as documented information.
- Paragraph 9.2.2 "Internal audit program" – The results of internal audits and the implementation of the audit program must be kept as documented information.
- Paragraph 9. 3 "Management review" – In this case, the documented information will be the results of the management reviews.
- Paragraph 10.2 "Incidents, nonconformities and corrective actions" – Documented information must be kept as evidence of the nature of the incidents or nonconformities and of the subsequent actions taken as well as of the results of any action taken, including their effectiveness.
- Paragraph 10.3 "Continuous improvement" – Documented information must be kept showing the continuous improvement made to the OH&S system.
As you can see, if you have a little familiarity with the other management system standards that have been published in recent years such as, for example, ISO 9001 which deals with quality management or ISO 14001 on the environment, the same approach is also applied in ISO 45001 with regard to documents: the mandatory ones are reduced and space is left to the individual organizations to decide independently what they need to best document and make the management system work effectively.
ISO 45001 allows flexibility on "how", "what" and "when" to document an element of the occupational health and safety management process to accommodate more modern forms of communication such as video, audio, and other electronic records and to allow an organization the flexibility to reuse the appropriate information, keep the versions in force as simple as possible, provide wider access/distribution and reduce the costs associated with documentation management.
The important thing for ISO 45001 is that the organization still achieves its overall objectives.
Of course, preparing the documents listed above is only a small part of the work to be done to prepare to be certified according to the ISO 45001 standard. Processes and procedures must be designed and implemented, but this list of mandatory documents can be used as a guide to make your task easier.