Exemplar Global Certified Courses from USD 119. Ending Soon!

Hazard Identification Under Clause 6.1.2.1: What ISO 45001 Requires

AW

Team @ Audit Workshop

13 min read
Hazard Identification Under Clause 6.1.2.1: What ISO 45001 Requires

Why Clause 6.1.2.1 Is the Foundation of Your OH&S System

Every ISO 45001 management system is built on a simple premise: you cannot control what you have not identified. Clause 6.1.2.1 is where that identification begins. It sets out what an organisation must do to systematically find hazards before they cause harm, and it does so with more specificity than many people expect when they first read the standard.

For quality managers, HSE professionals, and auditors working with ISO 45001, understanding exactly what this clause demands is not just an academic exercise. It determines whether your hazard identification process will survive scrutiny from a certification auditor or whether it will attract a nonconformity that takes weeks to close out.

This article walks through the full requirements of Clause 6.1.2.1, explains what a genuine hazard identification process looks like in practice, and highlights the common gaps that auditors find in the field. If you want a companion piece on how auditors evaluate this clause during an audit, the post on auditing hazard identification: is the process ongoing and proactive? covers that in detail.

What Clause 6.1.2.1 Actually Says

The clause opens by requiring the organisation to establish, implement, and maintain a process for the proactive identification of hazards. The word proactive is doing significant work here. ISO 45001 is not satisfied with a hazard register that was built during implementation and never updated. The process must be ongoing and forward looking, not reactive.

The clause then lists the specific inputs and situations that the hazard identification process must take into account. This list is where many organisations fall short, because they build a process that covers routine work but ignores everything else the clause requires.

Routine, Non-Routine and Emergency Situations

The process must consider how work is organised, including both routine and non-routine activities. Routine activities are the day to day tasks your workers perform regularly. Non-routine activities include maintenance shutdowns, infrequent tasks, and work that deviates from normal operations. Emergency situations are also explicitly required, meaning you need to think about what hazards arise when something goes wrong, not just when everything runs normally.

This is a common gap. Organisations document hazards for their standard operating procedures but forget to identify hazards for tasks like cleaning confined spaces, responding to a chemical spill, or working during a power outage. An auditor will ask to see evidence that these scenarios have been considered.

Human Factors

Clause 6.1.2.1 specifically calls out human factors as something the hazard identification process must address. This includes how people interact with the work environment, the tools they use, and each other. Fatigue, distraction, workload, shift patterns, and the design of workstations all fall under human factors.

In practice, this means your hazard identification process cannot focus solely on physical hazards like plant and equipment. If your hazard register has no entries related to human factors, that is a gap. For organisations in healthcare, transport, and aged care especially, human factors are often where the most serious risks sit.

New and Changed Hazards

The clause requires the organisation to consider new or changed hazards that arise from changes in work processes, equipment, or the work environment. This connects directly to your management of change process. When a change is planned, hazard identification must be part of the assessment before the change is implemented.

This is not optional. If your organisation introduces a new piece of equipment, changes a work procedure, or moves workers to a new location, Clause 6.1.2.1 requires that new hazards introduced by that change are identified. Auditors will look for evidence that this happened, not just that a change management form was completed.

Past Incidents

The clause also requires the process to consider past incidents, near misses, and the results of investigations. This creates a feedback loop: incidents generate information about hazards that were either not identified or not adequately controlled, and that information must feed back into the hazard identification process.

If your organisation has had incidents in the past and those hazards do not appear in your current hazard register, an auditor will want to understand why. Either the hazard was identified and controlled, or it was missed. Either way, the evidence should be visible in your documented information.

Who Must Be Involved in Hazard Identification

Clause 6.1.2.1 is explicit that hazard identification must involve workers at all levels and functions, and where they exist, workers representatives. This is not a suggestion. The standard requires workers to participate, and that participation must be genuine, not a checkbox exercise where management fills out a form and workers sign off.

In practice, this means involving frontline workers in identifying hazards in their own work areas. They know things that management does not. They know which tasks are awkward, which equipment behaves unpredictably, and which shortcuts get taken when time is short. A hazard identification process that happens entirely in a meeting room without input from the people doing the work will not meet this requirement.

Worker participation in hazard identification is also closely tied to Clause 5.4, which covers consultation and participation more broadly. The post on worker participation and consultation in ISO 45001 explains how these requirements interact and what genuine participation looks like to an auditor.

The Full List of Situations Clause 6.1.2.1 Requires You to Consider

The standard provides a detailed list of situations that must be considered during hazard identification. Working through this list is a useful way to test whether your current process is comprehensive. The situations include:

  • How work is organised, including social factors such as workload, work hours, victimisation, harassment, and bullying
  • Routine and non-routine activities and situations, including hazards arising from infrastructure, equipment, materials, substances, and the physical conditions of the workplace
  • Past relevant incidents, both internal and external to the organisation
  • Potential emergency situations
  • People, including consideration of those with access to the workplace such as contractors, visitors, and members of the public
  • Human factors
  • New or changed hazards introduced by organisational changes, new processes, or new equipment
  • Changes in knowledge and information about hazards

The inclusion of social factors is worth pausing on. ISO 45001 explicitly requires organisations to consider hazards arising from workload, work hours, and interpersonal issues like harassment and bullying. Psychosocial hazards are not optional extras. They are a required part of the hazard identification process, and organisations that treat OH&S as purely about physical safety will find this a significant gap.

What a Robust Hazard Identification Process Looks Like

A process that meets Clause 6.1.2.1 has several characteristics that distinguish it from a basic hazard register created at implementation and left unchanged.

It Is Proactive and Ongoing

The standard requires proactive identification, which means the process must run continuously, not just at the start of the certification cycle. In practice, this usually means a combination of scheduled hazard identification reviews, pre-task hazard assessments, workplace inspections, and trigger based reviews when changes occur or incidents happen.

The frequency of formal reviews should be risk based. Higher risk work environments warrant more frequent reviews. An auditor will look at when the hazard register was last reviewed and whether the timing makes sense given the nature of the work.

It Covers All Work and All Workers

The process must cover all activities, all locations, and all people who could be affected by the organisation's work. This includes contractors, visitors, and members of the public where relevant. A hazard register that covers only permanent employees doing routine tasks is incomplete.

For organisations that use contractors extensively, this is a common gap. The hazards associated with contractor activities must be identified, and the organisation cannot simply assume the contractor has done this. The interface between the organisation's work and contractor work is a hazard in its own right.

It Is Documented

Clause 6.1.2.1 requires the organisation to maintain documented information on hazards. The standard does not prescribe a specific format, but in practice this means a hazard register or equivalent document that records identified hazards, where they were identified, and when the identification occurred.

The documented information must be sufficient to support the subsequent risk assessment process under Clause 6.1.2.2 and the determination of controls. If the hazard register is so vague that it cannot inform a meaningful risk assessment, it is not meeting the intent of the clause.

It Uses Multiple Methods

No single method captures all hazards. A robust process typically combines workplace inspections, job safety analyses or task observations, consultation with workers, review of incident data, review of manufacturer information and safety data sheets, and assessment of new or changed activities. Using multiple methods increases the likelihood that significant hazards are found before they cause harm.

The post on hazard identification methods that auditors trust goes into detail on specific techniques and what makes each one credible from an audit perspective.

Common Nonconformities Against Clause 6.1.2.1

Having conducted hundreds of external certification audits, the gaps that come up repeatedly against this clause follow predictable patterns. Knowing them in advance gives you a significant advantage when preparing for an audit or conducting an internal audit against this clause.

The Hazard Register Has Not Been Updated

This is the most common finding. The organisation built a hazard register during implementation and has not reviewed it since. Meanwhile, the work environment has changed, new equipment has been introduced, and incidents have occurred. The hazard register reflects a snapshot of the past, not the current state of the workplace.

The fix is straightforward: establish a review schedule, link the register to the management of change process, and ensure incident investigations feed back into the register. The evidence auditors want to see is a register with recent review dates and a clear record of what triggered each review.

Psychosocial Hazards Are Missing

Many organisations still treat psychosocial hazards as outside the scope of their OH&S system. ISO 45001 does not allow this. Workload, shift patterns, fatigue, bullying, and harassment must appear somewhere in the hazard identification process. If they are absent, that is a nonconformity.

Non-Routine and Emergency Situations Are Not Covered

Organisations often document hazards for their standard operating procedures but miss non-routine work. Maintenance tasks, infrequent cleaning activities, emergency response, and tasks done by relief workers are all areas where hazards are frequently not identified. Auditors will specifically probe for evidence that these situations have been considered.

Worker Participation Is Superficial

If the evidence of worker participation in hazard identification is a single sign-off sheet, that is unlikely to satisfy an auditor. Genuine participation means workers contributed to identifying hazards, not just that they were informed about hazards identified by someone else. Look for records of toolbox talks, hazard identification walks with workers, or job safety analyses conducted with the people doing the work.

Contractors and Visitors Are Not Considered

The clause requires consideration of all people who could be affected, including contractors and visitors. Organisations that focus their hazard identification solely on direct employees will have a gap here. The hazards associated with contractor activities, and the hazards that contractors might create for the organisation's workers, must both be considered.

Linking Clause 6.1.2.1 to the Rest of the OH&S System

Hazard identification does not sit in isolation. It feeds directly into the risk assessment process under Clause 6.1.2.2, which determines the level of risk associated with each identified hazard. From there, the hierarchy of controls under Clause 8.1.2 determines how those risks are treated. The whole system depends on the quality of the hazard identification at the start.

This means that weaknesses in hazard identification cascade through the entire system. If significant hazards are not identified, they will not be assessed, and no controls will be put in place. This is why Clause 6.1.2.1 nonconformities are taken seriously by certification bodies. A weak hazard identification process undermines the entire purpose of the OH&S management system.

The connection between hazard identification and the audit trail is also important. Auditors will trace a hazard from its identification through to the controls in place and the monitoring of those controls. If that trail is broken, it suggests the system is not functioning as intended. The post on understanding the ISO 45001 hazard identification audit trail explains how auditors follow this thread and what they expect to find at each step.

Practical Steps to Strengthen Your Clause 6.1.2.1 Compliance

If you are preparing for a certification audit or conducting an internal audit against this clause, the following steps will help you identify and close gaps before the external auditor arrives.

  1. Map your activities comprehensively. List all work activities, including routine, non-routine, and emergency situations. For each activity, confirm that hazards have been identified and recorded.
  2. Check your last review date. If the hazard register has not been reviewed in the past twelve months, that is a risk. Establish a review schedule and document it.
  3. Look for psychosocial hazards. If they are absent from your register, add them. Start with workload, shift patterns, and any history of reported workplace conflict or harassment.
  4. Review your incident history. For every incident or near miss in the past two years, confirm that the associated hazard appears in the register and that controls have been updated where necessary.
  5. Check contractor coverage. Confirm that hazards associated with contractor activities are included in the register and that the interface between contractor and employee work has been considered.
  6. Gather evidence of worker participation. Collect records that show workers contributed to identifying hazards, not just that they were informed of the results.
  7. Confirm the register links to risk assessments. Every hazard in the register should have a corresponding risk assessment under Clause 6.1.2.2. If hazards are listed without risk assessments, that is a gap.

Building Auditor Competence for ISO 45001

For auditors, Clause 6.1.2.1 is one of the most substantive clauses to audit in an ISO 45001 system. It requires you to assess not just whether a hazard register exists, but whether the process behind it is genuinely proactive, comprehensive, and connected to the rest of the system. That takes knowledge of the standard, experience in asking the right questions, and the ability to recognise when documented compliance masks a system that is not functioning in practice.

If you are working towards ISO 45001 internal auditor or lead auditor credentials, understanding clauses like 6.1.2.1 in depth is exactly the kind of practical knowledge that separates competent auditors from those who simply work through a checklist. At Audit Workshop, the ISO 45001 Internal Auditor and Lead Auditor courses are built around this kind of clause level understanding, with real audit scenarios and worked examples drawn from actual certification audits. Whether you are new to OH&S auditing or looking to formalise existing experience, the training gives you the depth you need to audit this standard with confidence.

Frequently Asked Questions

Proactive hazard identification means finding hazards before they cause harm, rather than waiting for an incident to reveal them. ISO 45001 Clause 6.1.2.1 requires the process to be ongoing and forward looking, covering routine tasks, non-routine activities, emergency situations, and changes to work before they are implemented. It is the opposite of a reactive approach where hazards are only identified after something goes wrong.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2026 Lead Auditor Training Course
5+ enrolled
View Details
Exemplar Global certified
ISO 9001:2026 Lead Auditor Training Course badge
ISO 9001:2026 Lead Auditor

Quality Management Systems (QMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
USD 299USD 789
ISO 45001:2018 Lead Auditor Training Course
15+ enrolled
View Details
Exemplar Global certified
ISO 45001:2018 Lead Auditor Training Course badge
ISO 45001:2018 Lead Auditor

Occupational Health and Safety Management Systems (OHSMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
USD 249USD 789
ISO 14001:2026 Lead Auditor Training Course
10+ enrolled
View Details
Exemplar Global certified
ISO 14001:2026 Lead Auditor Training Course badge
ISO 14001:2026 Lead Auditor

Environmental Management Systems (EMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
USD 249USD 789
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Digital badges and a certificate
  • Access to webinars, events, and online resources

Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Instant Certificate

Download your digital certificate the moment you complete the course.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.