- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Archlight is a vCISO / ISO 27001 consultancy based in Minneapolis, MN, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Framework Cross-Industry Management Systems
ISO 45001
ISO 45001 is the international standard for an occupational health and safety (OH&S) management system. It asks an organization to identify workplace hazards, assess and control risks, meet its legal obligations, involve workers in safety decisions, prepare for emergencies, investigate incidents, and keep improving.
The current edition is ISO 45001:2018 with Amendment 1 (2024), which added climate change considerations to the context clauses. A full revision has reached the Draft International Standard stage, with the DIS ballot open from June 18 to August 9, 2026; publication is expected in 2027 (verify).
In writing, the standard expects an OH&S policy, a scope statement, a hazard identification and risk assessment register, a legal and other requirements register, OH&S objectives and plans, operational control and permit-to-work style procedures where relevant, emergency preparedness and response procedures, worker consultation and participation records, incident investigation records, and the standard management system records for competence, internal audit, management review, and corrective action.
Who has to comply
Voluntary. It does not replace OSHA or other national safety law; it sits on top of it. Common in construction, manufacturing, energy, utilities, facilities services, and any contractor who must pass client prequalification (for example ISNetworld or Avetta) where an accredited OH&S certificate reduces questionnaire burden.
What the assessor asks to see
OH&S policy and scope; context and worker/interested party needs; hazard identification and risk assessment register with control hierarchy applied; legal and other requirements register and compliance evaluation; objectives and plans; operational controls, contractor and procurement controls, management of change; emergency plans and drill records; worker consultation and participation evidence (committee minutes, feedback channels); incident and near-miss reports and investigations; training and competence records; monitoring data (inspections, health surveillance where required); internal audit and management review records; corrective actions.
Where the requirement sits: 5.2 policy; 5.4 participation; 7.2/7.3; 7.5; 8.2 emergency; 10.2 incident investigation
Amendment and revision timeline
ISO 45001:2018/Amd 1:2024 was published in February 2024 and requires the organization to decide whether climate change is a relevant issue for its OH&S system. The full revision (ISO/DIS 45001) entered ballot on June 18, 2026 with voting closing August 9, 2026. ISO/TC 283 has not published a firm publication date; industry expectations point to 2027.
Until then, certification remains against ISO 45001:2018 plus the amendment.
What AllyMatter does here
Document control and communication layer.
AllyMatter publishes this site.
Assessors
Who assesses ISO 45001
Accredited certification body accredited to ISO/IEC 17021-1 for OH&S management systems (ISO/IEC TS 17021-10). Accredited by National accreditation bodies under the Global ACI (formerly IAF) multilateral arrangement, such as ANAB, UKAS, DAkkS, JAS-ANZ.
Public register of assessors: https://www.iafcertsearch.org/
No firm has claimed a ISO 45001 assessor listing yet. Claim yours →
Consultants
Who helps with ISO 45001
A broad safety consultant ecosystem exists, often the same firms that write OSHA written programs. Implementers run a gap analysis, build the hazard and risk register and legal register, write or reconcile procedures, set up worker participation mechanisms, train internal auditors, and coach through certification. Typical first-time engagements run four to nine months.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- BEMO is a vCISO / ISO 27001 consultancy based in USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Control and Function is a vCISO / ISO 27001 consultancy based in Denver, CO, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Coral Esecure is a vCISO / ISO 27001 consultancy based in New Jersey, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Cycore is a vCISO / ISO 27001 consultancy based in Miami, FL, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Genius GRC is a vCISO / ISO 27001 consultancy based in Woodstock, GA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Illumen is a vCISO / ISO 27001 consultancy based in Pacific Northwest, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Neutral Partners is a vCISO / ISO 27001 consultancy based in Miami, FL, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Securis360 is a vCISO / ISO 27001 consultancy based in Pittsburgh, PA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Soter Advisory is a vCISO / ISO 27001 consultancy based in USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Testpros is a vCISO / ISO 27001 consultancy based in Reston, VA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- TrustedCISO is a vCISO / ISO 27001 consultancy based in Remote, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Software
Tools for ISO 45001
Tools that name this framework in their own material.
Related reading
- ISO 45001: getting startedThe safety profession's own primer on what the standard asks of leadership and how worker consultation has to be evidenced.IOSH
- ISO 45001 certification for occupational safetyCertification body's account of the audit stages, the surveillance cycle and the records an OH&S assessor asks to see.TUV SUD
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for ISO 45001
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Run the Policy Side of ISO 45001 in AllyMatter
Approve the policies ISO 45001 asks for, keep every version, and record a named acknowledgment from each person who has to read them.