Exemplar Global Certified Courses from USD 99. Ending Soon!

Workers and Interested Parties: ISO 45001 Clause 4.2 Explained

AW

Team @ Audit Workshop

14 min read
Workers and Interested Parties: ISO 45001 Clause 4.2 Explained

What Clause 4.2 Is Actually Asking You to Do

ISO 45001 Clause 4.2 requires your organisation to determine who the interested parties are in relation to your OH&S management system, and then identify what their needs and expectations are. That sounds straightforward on paper. In practice, it trips up a lot of organisations because they treat it as a one-time exercise, produce a register that gathers dust, and then wonder why auditors keep raising findings against it.

The clause has a specific characteristic that sets it apart from the equivalent clause in ISO 9001 and ISO 14001. In ISO 45001, workers are called out explicitly as the primary interested party. The standard does not just mention workers in passing. It builds worker participation and consultation into the DNA of the entire system, starting here at Clause 4.2. If you understand that distinction, the rest of the clause becomes much easier to interpret.

This article walks through what the clause requires, who counts as an interested party in an OH&S context, what you need to determine about each of them, and how auditors assess whether your organisation has genuinely engaged with this requirement rather than just ticked a box.

Workers as the Primary Interested Party

Before you think about regulators, contractors, or clients, you need to think about workers. ISO 45001 defines workers broadly. It includes employees on the payroll, but also contractors working under the organisation’s control, labour hire workers, volunteers, agency staff, and anyone else whose work is directed by the organisation. If you control how, when, and where someone works, they are a worker under this standard.

Why does this matter so much? Because the whole purpose of ISO 45001 is to prevent work-related injury and ill health. Workers are the people most directly exposed to the hazards your system is designed to control. Their needs and expectations are not abstract. They are concrete and immediate: safe working conditions, proper training, functioning equipment, the right to raise safety concerns without fear of reprisal, and meaningful involvement in decisions that affect their safety.

A common mistake organisations make is listing workers as an interested party and then writing something generic like “workers expect a safe workplace.” That is technically true but practically useless. You need to go deeper. What specific hazards are workers exposed to? What do they expect from the organisation in terms of communication, consultation, and response to safety concerns? What legal rights do they have under Australian WHS legislation that translate into expectations of the management system?

In Australia, the Work Health and Safety Act (in most jurisdictions) gives workers the right to be consulted on matters that affect their health and safety, to be represented by health and safety representatives, and to cease unsafe work. These are not just legal obligations. They are the expressed needs and expectations of your worker interested party group, and your OH&S management system needs to reflect them.

Identifying All Relevant Interested Parties

Once you have properly addressed workers, you move to the broader landscape of interested parties. The standard defines an interested party as a person or organisation that can affect, be affected by, or perceive themselves to be affected by your OH&S decisions and performance.

That definition is deliberately wide. In an OH&S context, the following groups are commonly relevant:

  • Regulatory authorities: SafeWork NSW, WorkSafe Victoria, SafeWork SA, and equivalent bodies in other jurisdictions. These bodies set legal requirements that become compliance obligations under Clause 6.1.3. Their expectations are largely codified in WHS legislation and codes of practice.
  • Contractors and subcontractors: Organisations that perform work on your sites or under your direction. They have a dual status. They are both workers (in that their safety is your concern) and external parties with their own systems and obligations.
  • Clients and principal contractors: On construction and resource sector projects, your client or principal contractor will have OH&S requirements that flow down through contracts. These are legitimate interested party expectations.
  • Industry associations and peak bodies: Bodies like the Master Builders Association or the Australian Industry Group may publish codes or standards that your organisation has committed to follow.
  • Emergency services: Police, fire, and ambulance services have expectations about how your organisation manages emergency preparedness and communicates during incidents.
  • Unions and worker representative bodies: Where unions are present, they represent worker interests in formal and structured ways. Their expectations around consultation, incident reporting, and safe systems of work are legitimate inputs to your system.
  • Insurers: Workers compensation insurers have expectations around return-to-work programmes, incident reporting, and risk management that directly affect your OH&S system design.
  • Neighbours and local communities: Where your operations create noise, dust, traffic, or other amenity impacts, nearby residents and businesses may have legitimate safety-related concerns.
  • Shareholders and boards: Governance expectations around safety performance, reporting, and liability are increasingly prominent in Australian organisations following high-profile prosecutions under WHS legislation.

The key word in the clause is relevant. You do not need to list every conceivable stakeholder. You need to identify the ones whose needs and expectations genuinely matter to your OH&S system. A small civil works contractor will have a different list to a large mining operation. The process of determining relevance requires judgement, and that judgement needs to be documented.

Determining Needs and Expectations

Identifying who the interested parties are is only the first step. The clause also requires you to determine their relevant needs and expectations. This is where many organisations produce superficial outputs.

For each relevant interested party, you need to identify what they actually need or expect from your OH&S management system. Some of these will be explicit, particularly where they are captured in legislation, regulations, contracts, or published standards. Others will require you to actively engage with the interested party to understand their position.

Take workers as an example. You should be able to point to specific mechanisms through which worker needs and expectations have been identified. This might include health and safety committee minutes, hazard reports, toolbox talk records, worker surveys, or direct consultation records. If you cannot demonstrate that you have actually listened to workers and incorporated their input, the clause is not being met in substance, even if the register looks complete.

For regulators, the process is different. You do not typically consult with SafeWork to understand their expectations. Instead, you review the relevant WHS Act, regulations, and codes of practice for your jurisdiction and industry. Those documents define what regulators expect. Your compliance obligations register, required under Clause 6.1.3, captures this information and should link back to your interested party determination.

For clients and principal contractors, the expectations are often captured in contracts, project safety management plans, and prequalification requirements. Reviewing these documents and extracting the relevant OH&S requirements is a legitimate way to determine client expectations.

Which Needs and Expectations Become Legal or Other Requirements

Clause 4.2 does not require you to comply with every expectation of every interested party. It requires you to determine which of those needs and expectations become legal requirements or other requirements that the organisation has chosen to comply with.

This is an important distinction. A union might expect your organisation to implement specific fatigue management procedures beyond what the WHS regulations require. You need to determine whether you have committed to that expectation. If you have, through a workplace agreement or a voluntary commitment, it becomes an “other requirement” that your system must address. If you have not made that commitment, it remains an expectation you are aware of but have not adopted as a binding obligation.

The output of this determination feeds directly into Clause 6.1.3, which deals with legal requirements and other requirements. There is a clear logical thread running from Clause 4.2 through to how you plan your OH&S system, and auditors will follow that thread.

How Auditors Assess Clause 4.2

When an auditor sits down to assess Clause 4.2, they are not just looking at your interested parties register. They are testing whether the clause has been implemented in a way that actually influences your OH&S management system. Here is what a thorough auditor will typically do.

Review the Documented Output

Most organisations produce some form of interested parties register or stakeholder register. The auditor will look at this document and assess whether it is credible. Does it include workers as a distinct group? Does it go beyond generic statements to capture specific needs and expectations? Has it been reviewed recently, or does it look like it was created for the initial certification audit and never touched since?

A register that lists “employees” with the expectation that they want “a safe workplace” will prompt follow-up questions. A register that identifies workers, contractors, labour hire staff, and apprentices separately, with specific expectations linked to hazard types, consultation rights, and training requirements, demonstrates genuine engagement with the clause.

Test the Link to Planning

The auditor will trace the identified needs and expectations through to the planning clauses of the standard. If your register identifies that a principal contractor requires all workers to hold specific safety inductions before site access, the auditor will check whether your system actually delivers this. If your register identifies that workers expect meaningful consultation on changes to work procedures, the auditor will check Clause 5.4 to see whether your consultation mechanisms are functioning.

For more on how auditors assess worker consultation specifically, the article on worker participation and consultation in ISO 45001 covers that ground in detail.

Interview Workers Directly

One of the most revealing audit techniques for Clause 4.2 is simply talking to workers. An auditor who asks a production worker whether they know how to raise a safety concern, whether they have ever been involved in a safety consultation, and whether they feel their safety concerns are taken seriously will quickly get a sense of whether the organisation’s stated commitment to worker needs is genuine.

If workers are unaware of the health and safety committee, do not know who their health and safety representative is, or have never participated in a toolbox talk, that is evidence that the organisation has identified worker expectations on paper without actually meeting them in practice.

Check for Updates After Changes

The standard requires this determination to be maintained, which means it needs to be updated when circumstances change. A new major client with specific safety requirements, a change in WHS legislation, or the engagement of a new category of contractor should all trigger a review of the interested parties register. If the register has not been updated in two years despite significant operational changes, that is a finding waiting to happen.

Common Nonconformities Against Clause 4.2

Based on real audit experience across construction, manufacturing, and service industries in Australia, these are the most frequent problems found against this clause:

  • Workers not adequately identified: The register lists “employees” but fails to address contractors, labour hire workers, or other categories of worker under organisational control.
  • Generic expectations: Needs and expectations are stated at such a high level that they provide no useful input to system planning. “Workers want to be safe” is not a useful determination.
  • No link to compliance obligations: The register exists in isolation with no visible connection to the legal register or Clause 6.1.3.
  • No evidence of worker input: The register has been prepared by management without any documented evidence that workers were consulted in its development.
  • Stale documentation: The register was last reviewed at the time of certification and has not been updated despite changes in the organisation, its workforce, or its regulatory environment.
  • Missing key parties: Industry-specific interested parties such as principal contractors, WorkCover insurers, or unions are absent from the register without any documented rationale for their exclusion.

If you want to understand how these types of findings are graded and documented, the article on auditing occupational health and safety under ISO 45001 provides useful context on how auditors approach the standard as a whole.

Practical Steps to Implement Clause 4.2 Properly

If you are building or reviewing your OH&S management system, here is a practical approach to getting Clause 4.2 right.

  1. Start with workers: Map out every category of person who works under your control. Use your payroll, contractor registers, and labour hire agreements to build a complete picture. Do not assume all workers have the same needs.
  2. Engage workers directly: Use toolbox talks, health and safety committee meetings, or structured surveys to ask workers what they need from the safety management system. Document this process and the outputs.
  3. Review your legal obligations: Pull out the WHS Act and regulations relevant to your jurisdiction and industry. Identify the specific expectations these instruments place on your organisation. These feed directly into your compliance obligations register.
  4. Review your contracts: Check client contracts, principal contractor requirements, and subcontractor agreements for OH&S-related obligations. These are legitimate interested party expectations.
  5. Assess relevance: For each potential interested party, make a documented decision about whether they are relevant to your OH&S management system and why. Record your reasoning.
  6. Link to planning: Trace each identified need or expectation through to the part of your system that addresses it. This might be a procedure, a training requirement, a monitoring activity, or a compliance obligation.
  7. Set a review trigger: Define when the register will be reviewed. At minimum, this should happen annually and whenever there is a significant change in the organisation, its workforce, its operations, or the regulatory environment.

The Relationship Between Clause 4.2 and the Rest of the System

Clause 4.2 does not operate in isolation. It feeds into almost every other part of the ISO 45001 system. The interested parties you identify in Clause 4.2 shape your compliance obligations in Clause 6.1.3, your hazard identification process in Clause 6.1.2, your consultation and participation mechanisms in Clause 5.4, your communication processes in Clause 7.4, and your operational controls in Clause 8.1.

When an auditor finds a weak Clause 4.2, they often find downstream weaknesses in these other areas as well. The reverse is also true. An organisation that has genuinely engaged with Clause 4.2 tends to have a more coherent and effective system overall because the planning is grounded in real stakeholder needs rather than generic templates.

Understanding how Clause 4.2 connects to the broader context requirements is also important. If you want to see how this clause fits alongside Clause 4.1 on organisational context, the article on Clause 4.1 of ISO 45001: understanding organisational context covers that relationship clearly.

Building Auditor Competence in This Area

For auditors, Clause 4.2 is a deceptively simple clause to audit poorly and a genuinely revealing clause to audit well. The difference lies in knowing what questions to ask and how to follow the evidence trail from the register through to operational practice.

If you are developing your competence as an ISO 45001 internal auditor or preparing for lead auditor training, understanding how interested party needs translate into system requirements is one of the most transferable skills you can build. It applies across ISO 9001, ISO 14001, and ISO 45001, with variations in emphasis depending on the standard.

Audit Workshop delivers practical ISO 45001 internal auditor and lead auditor training that covers exactly this kind of clause-level analysis. The training is built around real audit scenarios, not just clause summaries, so you leave with the ability to audit this requirement in the field, not just describe it in a course. If you are working toward auditor credentials or want to sharpen your existing skills, the ISO 45001 auditor training levels explained article is a useful starting point for choosing the right course level.

Frequently Asked Questions

Yes. ISO 45001 explicitly identifies workers as a key interested party, and the standard is built around the principle that workers are the primary group affected by OH&S decisions. Your Clause 4.2 determination must address workers specifically, including all categories of worker under organisational control such as employees, contractors, labour hire staff, and volunteers. Generic references to “employees” without distinguishing between worker categories will typically attract auditor scrutiny.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2015 Lead Auditor

Quality Management Systems (QMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 45001:2018 Lead Auditor

Occupational Health and Safety Management Systems (OHSMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 14001:2026 Lead Auditor

Environmental Management Systems (EMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Access to self-coaching assessment
  • Access to webinars, events, and online resources
Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Instant Certificate

Download your digital certificate the moment you complete the course.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.