What the ISO 45001 certificate actually certifies
Sort every nonconformity from your last three-year certification cycle into paperwork versus field exposure. If the field pile is empty, the audit is grading your filing.
A prequalification portal asks for one document. The ISO 45001 certificate goes up, the box is ticked, and the supplier score moves. The same PDF appears in a board pack under the heading “safety assurance”. A client’s own supplier review closes early because the certificate is on file. In all three cases the document is being read as a statement that the site is safe.
It is a statement about something narrower. A certificate records that a sampled subset of a management system was found conforming to the requirements of a standard, at the time of audit, by a body operating to a conformity assessment standard. That is a real finding. It is not a performance measurement, and it is not a legal compliance determination in any jurisdiction.
The standard draws the line itself
You do not have to argue this from outside. The published scope of ISO 45001:2018 sets out what the standard covers and then says plainly what it does not do. Reproduced in full in the Standards Council of Canada catalogue, the scope states that the document “does not state specific criteria for OH&S performance”, nor is it prescriptive about how a management system should be designed.
That sentence is the whole argument. A conforming system is one that meets the clause requirements, and the clause requirements are about process: policy, planning, hazard identification, operational control, performance evaluation, management review. The standard declines, on purpose, to set a threshold for injury rate, exposure concentration or control effectiveness. Two sites holding identical certificates can sit at opposite ends of any performance distribution, and nothing in the standard’s own scope claims otherwise.
The standard also requires an organisation to identify and fulfil the legal requirements that apply to it. Determining whether they have in fact been fulfilled is not a job the standard gives to a certification body. That authority sits with the regulator, in every jurisdiction, because it is a statutory power rather than a contractual one.
The arithmetic of an audit day
Certification is a third-party conformity assessment. ISO/IEC 17021-1:2015 sets the requirements for the bodies that perform it, covering competence, consistency and impartiality, and it describes management system certification as exactly that: a third-party conformity assessment activity, carried out by third-party conformity assessment bodies.
One document is frequently misattributed here, so it is worth being exact. ISO/IEC TS 17021-10:2018 is the OH&S-specific part, and its published abstract confirms it covers competence requirements for auditors, for the personnel who review audit reports and make certification decisions, and for other personnel. It runs to nine pages. It does not set audit duration.
Audit time comes from the accreditation side, in IAF MD 5:2023 (Issue 4, Version 3), the mandatory document on determination of audit time for quality, environmental and occupational health and safety management systems. It contains Table OH&SMS 1, which relates the effective number of personnel and the complexity category of OH&S risk to audit time for the initial audit, Stage 1 plus Stage 2.
The figures are modest. For a site with 426 to 625 personnel, the table gives 16 auditor days at high risk complexity, 12 at medium and 9 at low. For 5,451 to 6,800 personnel the figures are 30, 23 and 17. An audit day, the document notes, is normally eight hours. Surveillance is smaller again: MD 5 states that during the initial three-year cycle the total time spent annually on surveillance should be about one third of the time spent on the initial certification audit.
Put a plausible site through that. Five hundred workers, medium OH&S risk complexity, so roughly 12 auditor days for initial certification and roughly four auditor days a year of surveillance after that. Four days is about 32 auditor hours. The site itself runs something in the region of 900,000 worker hours a year. The annual surveillance sample is on the order of three thousandths of one percent of the exposure the certificate is being read as evidence about.
That is not a complaint about auditors, who are working to the time the document allows. It is a description of what sampling is. MD 5 treats its tables as a starting point, and multi-site programmes sample sites as well as activities. A clean surveillance visit is a statement about the sample that was drawn. Treating it as a statement about the rest of the year is a reading the document does not offer.
The diagnostic
Pull every nonconformity raised across your last full three-year certification cycle, majors and minors, initial and surveillance. Sort each into two piles. Pile one is documentation and process: a procedure not updated, a record missing, an internal audit overdue, a management review not minuted. Pile two is a physical exposure or a failed control found in the field: a guard defeated, an isolation not applied, extraction not performing to design, a permit written but not worked to. Then ask how many findings are in pile two? If pile two is a meaningful share of the total, your audit programme is reaching the floor and the certificate carries some evidentiary weight about conditions. If pile two is empty or close to it, your certification audit is testing your filing, and exposure verification has to come from somewhere else in your system.
What certification genuinely delivers
The honest case for certification is not the certificate. It is the forcing function.
Certification obliges document control, internal audit, management review and a hazard identification process to exist, to be written down, and to be exercised against an external date that nobody internally can quietly move. In a lot of organisations that external date is the only reason management review happens at all. It obliges a nonconformity to be closed with evidence rather than with an assurance. It obliges worker participation to be arranged rather than assumed. These are real, and a site that has been through a full cycle is usually more organised than one that has not.
What it does not do is measure whether the controls work on the day. Conformity of a process and effectiveness of a control are different claims, and the standard’s own scope is the source that says so.
Where the exposure check has to come from
In the United States, employer duties sit in the Occupational Safety and Health Act, and compliance findings sit with OSHA. The agency has stated in an interpretation letter (now archived, but the principle is unchanged) that it does not test, approve, certify or endorse any equipment, product or procedure, and it notes that the consensus standard process is not equivalent to OSHA rulemaking. A certificate is not a defence to a citation and is not a finding of compliance. The equivalent holds elsewhere: an accredited body is accredited to assess conformity with a standard, not to make findings under a statute.
So build pile two on purpose. Put a field verification programme next to the audit programme, with its own schedule, its own sample size and its own failure rate: isolations observed while being applied, guarding integrity checked against the drawing, local exhaust measured against design flow, permits audited at the work face while the work is happening. Report its findings separately from audit nonconformities, because they answer a different question.
Then put that failure rate in the board pack, on the same slide as the certificate. One of the two numbers describes the working year. The certificate describes about four days of it.