Exemplar Global Certified Courses from USD 99. Ending Soon!

ISO 45001 Clause 4.4: Building the OH&S Management System and Its Processes

AW

Team @ Audit Workshop

15 min read
ISO 45001 Clause 4.4: Building the OH&S Management System and Its Processes

What Clause 4.4 Actually Requires

Clause 4.4 of ISO 45001:2018 is short. It reads, in essence, that the organisation shall establish, implement, maintain, and continually improve an occupational health and safety management system, including the processes needed and their interactions, in accordance with the requirements of the standard. That is it. No tables, no lists, no detailed sub-requirements. Just one clause that ties everything together.

Do not let the brevity fool you. Clause 4.4 is the architectural statement of the entire standard. Everything that follows in Clauses 5 through 10 is the detail that gives this clause its substance. When an auditor asks whether your OH&S management system is genuinely established and functioning, they are testing Clause 4.4 whether they name it or not.

This article breaks down what the clause demands in practice, how it connects to the rest of ISO 45001, and what auditors actually look for when they assess it during a certification or internal audit.

The Four Verbs That Define the Obligation

The clause uses four specific verbs: establish, implement, maintain, and continually improve. Each one represents a distinct obligation, and organisations often satisfy some while neglecting others.

Establish

Establishing the system means designing it. This includes defining the scope (Clause 4.3), identifying the processes that make up the system, and setting up the structure that will allow the system to function. At this stage, the organisation is making decisions about what the OH&S management system will cover, how processes will interact, and what documented information will support it.

A common mistake at this stage is treating establishment as a documentation exercise. Organisations produce policies, procedures, and registers, then assume the system is established. Establishment is about creating something real, not just creating paperwork. The documents should describe how work actually happens, not how someone imagines it might happen.

Implement

Implementation means putting the system into practice. The procedures are followed, the hazard identification process runs regularly, workers are consulted, training is delivered, and controls are applied. If the system exists on paper but not in operation, it has been established but not implemented. This is one of the most common findings in certification audits.

Auditors test implementation by going to the work. They talk to workers on the floor, observe how tasks are performed, and check whether the controls described in the system are actually in use. A risk assessment that sits in a folder and has never been reviewed by the people doing the work is a sign of a system that has been established but not implemented.

Maintain

Maintaining the system means keeping it current and functional over time. Processes change, legislation changes, the workforce changes, and new hazards emerge. A system that was well implemented three years ago but has not been updated since is a system that is failing its maintenance obligation.

Maintenance is tested through things like the currency of the hazard register, whether the legal register reflects current WHS legislation, whether training records are up to date, and whether the internal audit programme is being run as planned. Maintenance is the verb that most organisations struggle with in the years between certification audits.

Continually Improve

Continual improvement means the system gets better over time, not just stays the same. ISO 45001 places considerable emphasis on this through Clause 10, but the obligation begins here in Clause 4.4. Improvement should be driven by data: audit findings, incident investigations, worker consultation, performance monitoring, and management review outputs. Organisations that cannot demonstrate improvement over time will struggle to satisfy this part of the clause.

The Process Approach in an OH&S Context

The second part of Clause 4.4 refers to the processes needed and their interactions. This is a direct reference to the process approach, which underpins all ISO management system standards built on the harmonised structure.

In an OH&S context, the processes that make up the system typically include hazard identification and risk assessment, legal compliance evaluation, worker consultation and participation, training and competence management, operational controls, emergency preparedness and response, incident investigation, and internal auditing. Each of these is a process with inputs, outputs, resources, and responsibilities.

The interactions between processes matter as much as the individual processes. Consider how hazard identification feeds into risk assessment, which feeds into control selection, which feeds into training needs, which feeds into competence records. If any link in that chain is broken, the system will not function as intended even if each individual process looks fine in isolation.

Auditors who understand the process approach will trace these connections during an audit. They will not just check that a hazard register exists. They will ask how hazards identified through that process flow into the risk assessment, how the risk assessment informs the selection of controls, and how those controls are communicated to workers. If the answer to any of those questions is vague, there is likely a gap in the system.

How Clause 4.4 Connects to the Rest of ISO 45001

Understanding Clause 4.4 requires understanding how it sits within the overall structure of the standard. The clause does not operate in isolation. It draws on the outputs of Clauses 4.1, 4.2, and 4.3, and it sets the foundation for everything in Clauses 5 through 10.

The Context Clauses Feed Into 4.4

Clause 4.1 requires the organisation to understand its context, including internal and external issues that affect its ability to achieve its OH&S objectives. Clause 4.2 requires the identification of workers and other interested parties and their relevant needs and expectations. Clause 4.3 requires the organisation to determine the scope of the OH&S management system.

These three clauses are not separate exercises. They are inputs to Clause 4.4. The system you build in Clause 4.4 should reflect the context you identified in Clause 4.1, address the needs of the interested parties identified in Clause 4.2, and operate within the scope defined in Clause 4.3. If there is a disconnect between those earlier clauses and the actual system, the system has not been properly established.

For a deeper look at how organisational context shapes the foundation of an OH&S system, see our article on Clause 4.1 of ISO 45001: Understanding Organisational Context.

Leadership and Worker Participation Drive the System

Clause 5 of ISO 45001 is notable for the emphasis it places on top management and on worker participation. The OH&S management system described in Clause 4.4 cannot function without genuine leadership commitment and without workers being involved in the processes that affect their safety. An OH&S system that sits in the hands of a single safety manager and is invisible to everyone else is not a system in the sense the standard intends.

Top management must demonstrate that the system is integrated into the business, not bolted on. That means OH&S considerations are part of how decisions are made, how resources are allocated, and how performance is evaluated. Workers must be consulted in the development and review of the system, not just handed a policy to sign.

Planning, Support, Operation, and Evaluation Are the System in Action

Clauses 6 through 9 describe how the system operates. Planning (Clause 6) addresses how risks and opportunities are identified and how objectives are set. Support (Clause 7) addresses the resources, competence, awareness, communication, and documented information that enable the system to function. Operation (Clause 8) addresses how hazards are controlled and how the organisation prepares for emergencies. Performance evaluation (Clause 9) addresses how the system monitors its own effectiveness.

All of this is what Clause 4.4 means when it refers to the processes needed and their interactions. The system is not a document. It is the sum of these operating processes, running consistently, connected to each other, and producing measurable outcomes.

What Auditors Look for When Assessing Clause 4.4

When auditors assess Clause 4.4 during a certification audit, they are not usually looking at it in isolation. They are looking at the overall coherence and functionality of the system. The questions they are asking, even if they do not frame them explicitly against Clause 4.4, include the following.

Is the System Actually Operating?

The most fundamental question is whether the OH&S management system is real. Does it run? Are the processes being executed? Are workers aware of it and participating in it? Auditors answer this through interviews, observation, and sampling of records. A system that produces consistent evidence across these three sources is a system that is genuinely operating.

Are the Processes Defined and Understood?

Auditors will look for evidence that the key processes of the system are defined, that responsibilities are assigned, and that the people responsible understand what they are expected to do. This does not require a complex process map for every activity. It requires that the organisation can explain how its OH&S processes work and demonstrate that explanation with evidence.

Do the Processes Interact as Intended?

This is where many systems fall apart. Individual processes may be well defined, but if they do not connect properly, the system will produce gaps. Auditors will trace the flow of information and action between processes. For example, they might follow an incident from initial report through investigation to corrective action to see whether the system actually learns from events. If the investigation sits in a folder and nothing changes as a result, the interaction between incident investigation and continual improvement has broken down.

Is the System Being Maintained and Improved?

Auditors will look at the history of the system. How long has it been since the hazard register was reviewed? When was the last management review? What improvements have been made in the past twelve months? A system that cannot show evidence of maintenance and improvement over time is a system that is stagnating, and that is a finding.

For practical guidance on what auditors examine during an ISO 45001 audit, our article on Auditing Occupational Health and Safety Under ISO 45001 covers the key areas in detail.

Common Weaknesses Found Against Clause 4.4

After conducting hundreds of ISO 45001 audits across a range of industries, certain patterns emerge in how organisations fail to satisfy the intent of Clause 4.4. These are not necessarily raised as nonconformities against Clause 4.4 specifically, but they reflect a failure to establish, implement, maintain, or improve the system as required.

The System Is Owned by One Person

When the OH&S management system lives entirely in the head and the files of a single safety manager, it is fragile and incomplete. If that person leaves, the system collapses. More importantly, a system that is not understood and owned across the organisation is not integrated into the business. Clause 4.4 requires a system, not a safety officer.

Processes Exist on Paper but Not in Practice

This is the most common weakness. Procedures are written, registers are created, and policies are signed. But when you go to the work and ask workers how they identify hazards before starting a task, they look blank. Or the toolbox talk records show meetings that workers do not remember attending. The documented system and the operating system are two different things.

The System Has Not Been Updated Since Certification

Many organisations invest heavily in building their system before the initial certification audit, then let it drift. Legislation changes, new equipment is introduced, processes change, and the workforce turns over. But the hazard register still reflects the site as it was three years ago. This is a failure of the maintenance obligation.

Interactions Between Processes Are Not Managed

Organisations sometimes treat each element of the system as a standalone requirement. They have a hazard register, a training matrix, an incident register, and a corrective action register, but these are managed as separate documents rather than as connected parts of a system. When a new hazard is identified, it does not automatically trigger a review of training needs. When an incident occurs, the corrective action does not feed back into the hazard assessment. The processes exist but do not interact.

Practical Steps for Strengthening Clause 4.4 Compliance

If you are a safety manager, quality manager, or internal auditor looking to assess or strengthen your organisation's compliance with Clause 4.4, the following steps will help.

Map Your OH&S Processes

Start by identifying all the processes that make up your OH&S management system. For each process, document the inputs, outputs, responsible parties, and connections to other processes. This does not need to be a complex exercise. A simple table or process map that your team can understand and use is more valuable than a sophisticated diagram that nobody looks at.

Test the System Against Reality

Walk the floor. Talk to workers. Ask them how they identify hazards, how they report incidents, how they know what controls apply to their work. Compare what they tell you with what the documented system says should happen. The gaps you find are your improvement priorities.

Review the Connections Between Processes

Take one process, such as incident investigation, and trace it forward and backward. What feeds into it? What does it feed into? Is there documented evidence that the outputs of the investigation process are actually used to update the hazard register, the risk assessment, or the training programme? If not, the interaction between processes is not functioning.

Make Maintenance a Scheduled Activity

Build a calendar of system maintenance activities. This should include scheduled reviews of the hazard register, the legal register, the training matrix, the emergency response plan, and the internal audit programme. Assign ownership for each review. If maintenance is not planned and owned, it will not happen consistently.

Use Management Review to Drive Improvement

Management review is one of the most powerful mechanisms for continual improvement, and one of the most underused. If your management reviews are producing outputs like system is performing well, no actions required, they are not functioning as intended. Real management reviews identify trends, set improvement priorities, and allocate resources to address them.

For those wanting to build deeper auditing skills around the OH&S management system, understanding how the system's processes connect is a core competency. Our article on OHS Management System: Components and Setup provides a useful foundation for understanding how the pieces fit together.

Clause 4.4 in the Context of an Integrated Management System

Many Australian organisations operate integrated management systems that combine ISO 9001, ISO 14001, and ISO 45001. In that context, Clause 4.4 of ISO 45001 mirrors Clause 4.4 of ISO 9001 and Clause 4.4 of ISO 14001. All three clauses use the same language and the same four verbs.

This creates an opportunity to build a single integrated system that satisfies all three standards through shared processes. Document control, internal auditing, management review, competence management, and communication processes can all be designed once and applied across all three management systems. The OH&S-specific content, such as hazard identification, risk assessment, and operational controls, will always need to be addressed in the context of the OH&S standard, but the system architecture can be shared.

When auditing an integrated system, auditors will assess whether the OH&S processes are genuinely integrated or just labelled as such. An integrated system should show that safety considerations are embedded in operational planning, procurement, and performance evaluation alongside quality and environmental considerations, not managed in a separate silo.

If you are working with an integrated system and want to understand how the clause structures align across standards, our article on ISO 9001 vs ISO 14001 vs ISO 45001: Key Differences Explained is worth reading alongside this one.

Building Auditor Competence Around Clause 4.4

For internal auditors and lead auditors, understanding Clause 4.4 at this level of depth is not optional. It is the clause that gives the audit its purpose. Every audit question you ask, every piece of evidence you gather, and every finding you raise should connect back to whether the system is established, implemented, maintained, and continually improved.

The most effective auditors approach Clause 4.4 not as a box to tick but as a lens through which the entire audit is conducted. When you walk into an audit, you are asking one overarching question: does this organisation have a functioning OH&S management system? Every other question you ask is a way of answering that one.

At Audit Workshop, our ISO 45001 Internal Auditor and Lead Auditor courses are built around this kind of practical, process-based understanding of the standard. Dilawar Laghari brings over 14 years of compliance experience and more than 500 external ISO certification audits to the training, so the content reflects what actually happens in real audits, not just what the standard says on paper. If you are preparing to audit against ISO 45001 or working to strengthen your organisation's OH&S management system, our courses will give you the skills to do it properly.

Frequently Asked Questions

Clause 4.4 requires an organisation to establish, implement, maintain, and continually improve an OH&S management system, including the processes needed and their interactions, in accordance with the requirements of ISO 45001. It is a short clause but it is the foundational statement of the entire standard. Everything in Clauses 5 through 10 provides the detail that gives this clause its substance.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2015 Lead Auditor Training Course
  • Lead Auditor
  • Self-Paced Online
  • Exemplar Global
  • USD 199USD 789
ISO 45001:2018 Lead Auditor Training Course
  • Lead Auditor
  • Self-Paced Online
  • Exemplar Global
  • USD 199USD 789
ISO 14001:2026 Lead Auditor Training Course
  • Lead Auditor
  • Self-Paced Online
  • Exemplar Global
  • USD 199USD 789
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Access to self-coaching assessment
  • Access to webinars, events, and online resources
Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Instant Certificate

Download your digital certificate the moment you complete the course.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.