Exemplar Global Certified Courses from USD 119. Ending Soon!

Roles, Responsibilities and Authorities: Clause 5.3 of ISO 45001 Explained

AW

Team @ Audit Workshop

13 min read
Roles, Responsibilities and Authorities: Clause 5.3 of ISO 45001 Explained

Why Clause 5.3 Is More Than an Org Chart Exercise

If you have ever walked into an OH&S audit and asked a manager who is responsible for maintaining the hazard register, only to receive a blank look or a vague gesture toward “the safety team,” you have witnessed a Clause 5.3 failure in real time. Roles, responsibilities and authorities in ISO 45001 are not a documentation exercise. They are the mechanism by which top management converts commitment into action.

Clause 5.3 sits in Section 5, which covers leadership. That placement is deliberate. ISO 45001 expects top management to assign OH&S roles, not delegate the task of assigning them. The distinction matters. When the safety manager writes their own position description and hands it to the CEO for a signature, that is not what the standard intends. The standard expects genuine leadership engagement in deciding who does what and making sure those people know it.

This article unpacks what Clause 5.3 actually requires, what auditors look for when they examine it, and where organisations consistently fall short. Whether you are preparing your organisation for a certification audit or developing your skills as an internal auditor, understanding this clause in practice is essential.

What Clause 5.3 Actually Requires

The clause is relatively brief in the standard itself, but its implications run deep. ISO 45001 Clause 5.3 requires top management to ensure that responsibilities and authorities for relevant roles within the OH&S management system are assigned and communicated within the organisation.

Specifically, the standard requires that top management assign responsibility and authority for:

  • Ensuring the OH&S management system conforms to the requirements of ISO 45001
  • Reporting on the performance of the OH&S management system to top management

Those two points sound simple. In practice, they create a chain of accountability that runs from the boardroom to the shop floor. Every element of the OH&S management system needs someone responsible for it, and that person needs to know they are responsible, have the authority to act, and have the resources to do so.

It is worth noting that ISO 45001 does not require a single “management representative” in the way that older standards like OHSAS 18001 did. The 2018 standard distributes responsibility more broadly. This reflects a genuine shift in thinking: safety is not owned by one person in a safety department. It is embedded across functions.

The Difference Between Assignment and Communication

One of the most common gaps auditors find under Clause 5.3 is that roles have been assigned on paper but never genuinely communicated. A position description sitting in a filing system does not constitute effective communication. A safety manager who has never been told they are responsible for ensuring the system conforms to ISO 45001 cannot be expected to fulfil that responsibility.

When auditing this clause, experienced auditors test both sides of the equation. They will review documented evidence of role assignment, then interview the people in those roles to see whether they understand what they are responsible for. The interview is where the real picture emerges.

Consider this scenario from a real audit context. A construction company had a detailed OH&S management plan. Every role was listed. Every responsibility was documented. But when the auditor asked the site supervisor what their specific responsibilities were under the OH&S management system, the supervisor referenced only their general site duties. They had no awareness of their documented OH&S responsibilities. The documents existed. The communication had not happened. That is a nonconformity against Clause 5.3.

Who Counts as “Top Management” for Clause 5.3

ISO 45001 defines top management as the person or group of people who directs and controls an organisation at the highest level. In a small business, that might be the owner. In a large corporation, it might be the board, the CEO, or a management committee. The key requirement is that the people with genuine authority over the organisation are the ones assigning and owning these responsibilities.

A common mistake is for the safety manager or quality manager to effectively self assign responsibilities and then present the documentation to top management for rubber stamping. Auditors will probe this. They may ask top management directly: how did you decide who was responsible for what? What was your involvement in that process? If top management cannot answer those questions, the clause has not been genuinely met.

This connects to the broader leadership requirements in Clause 5.1 of ISO 45001. Auditing leadership commitment under Clause 5.1 is closely related to Clause 5.3 work. The two clauses reinforce each other. You cannot demonstrate genuine leadership commitment without having meaningfully assigned and communicated roles.

Common Roles That Need to Be Addressed

ISO 45001 does not prescribe a specific list of roles that must exist in every organisation. The standard requires that relevant roles are addressed. What is relevant depends on the organisation, its size, its activities, and the complexity of its OH&S risks. That said, certain roles consistently appear in well functioning OH&S management systems.

Top Management

Top management retains ultimate accountability for the OH&S management system. Under Clause 5.3, they must ensure that responsibilities are assigned. They cannot delegate this responsibility away entirely, even if they assign the day to day management to others.

The OH&S Function

Whether this is a dedicated safety manager, a combined HSE manager, or a part time safety officer depends on the organisation. What matters is that whoever holds this role has clear authority to act, including authority to stop work if a hazard presents an immediate risk. That authority needs to be documented and known.

Line Managers and Supervisors

This is where Clause 5.3 gets practically important. Supervisors and line managers are often the people who actually implement OH&S controls on a day to day basis. Their responsibilities need to be explicit, not implied. A supervisor who thinks safety is “the safety department’s job” is a Clause 5.3 problem waiting to happen.

Workers

Workers also have responsibilities under the OH&S management system. ISO 45001 places significant emphasis on worker participation and consultation, and workers need to understand their role in hazard reporting, following controls, and participating in the system. This connects directly to worker participation and consultation requirements in ISO 45001.

Specific Function Owners

In larger organisations, there may be specific roles with OH&S responsibilities tied to particular processes. Procurement managers responsible for contractor prequalification, maintenance managers responsible for equipment inspection programmes, and HR managers responsible for induction and training are all examples. Each of these functional roles needs clarity around their OH&S responsibilities.

What Auditors Check Under Clause 5.3

When auditing Clause 5.3, a competent auditor goes beyond reviewing the documented roles and responsibilities. The audit trail for this clause typically includes the following evidence sources.

Documented Role Definitions

Position descriptions, organisational charts, the OH&S management plan, or a dedicated roles and responsibilities matrix. The format is less important than the content. The documentation needs to clearly show who is responsible for what, and it needs to be current. Outdated position descriptions that reference roles that no longer exist, or that omit recently created positions, are a common finding.

Evidence of Communication

Induction records, training records, toolbox talk records, signed acknowledgements, or meeting minutes that demonstrate roles have been communicated. Auditors will sample across levels of the organisation. They want to see evidence that the person at the top knows they are responsible for the system, and the person on the floor knows what their safety responsibilities are.

Interviews Across Levels

This is the most revealing part of the audit. Auditors will ask managers, supervisors, and workers questions like: What are your specific responsibilities under the OH&S management system? Who do you report safety concerns to? Who is responsible for reviewing the hazard register? The answers tell you whether the documented system reflects reality.

Evidence of Authority

Responsibility without authority is a setup for failure. Auditors will look for evidence that people with OH&S responsibilities also have the authority to act. This might include documented stop work authority, authority to approve corrective actions, or authority to allocate budget for safety improvements. If a safety manager is responsible for managing risks but has no authority to spend money or direct workers, there is a structural problem.

The Most Frequent Nonconformities Under Clause 5.3

After conducting hundreds of external audits, certain patterns repeat themselves. These are the most common Clause 5.3 findings.

Generic Position Descriptions Without OH&S Specifics

A position description that lists “comply with all WHS legislation” as a single bullet point does not constitute meaningful assignment of OH&S responsibilities. Auditors want to see specific responsibilities tied to specific elements of the OH&S management system. What does this person do in relation to hazard identification? What is their role in incident investigation? What are they responsible for in the management of change process?

Roles Assigned to Positions That No Longer Exist

Organisations restructure. People leave. New roles are created. When the documented responsibilities have not kept pace with organisational changes, the system breaks down. A role that is assigned to a position title that no one currently holds is a conformity gap.

Workers Who Cannot Describe Their OH&S Responsibilities

This is the most common interview finding. Workers can usually tell you what PPE to wear and where the first aid kit is. They often cannot articulate their specific responsibilities within the management system, such as their obligation to report hazards, their right to refuse unsafe work, or their role in the consultation process.

No Documented Reporting Lines for OH&S Performance

Clause 5.3 specifically requires that someone is assigned responsibility for reporting on OH&S system performance to top management. This reporting line needs to be clear and documented. If there is no defined mechanism for OH&S performance information to reach the people who need to act on it, the system is not functioning as intended.

Safety Responsibility Treated as the Safety Department’s Exclusive Domain

This is a cultural issue that manifests as a Clause 5.3 nonconformity. When operational managers believe safety is someone else’s job, it usually means their own responsibilities have not been adequately assigned or communicated. Auditors will probe this by asking operational managers what their personal accountability is for safety outcomes in their area.

How to Build a Clause 5.3 System That Actually Works

Getting Clause 5.3 right is not complicated, but it does require genuine effort from leadership. The following approach works in practice.

Start With a Responsibility Matrix

Map every element of the OH&S management system to a role. Use a simple table: system element in one column, responsible role in the next, accountable role in the next. Make sure every element has a clear owner. Gaps in the matrix are gaps in the system.

Integrate OH&S Responsibilities Into Position Descriptions

Rather than maintaining a separate OH&S responsibilities document, embed specific OH&S responsibilities into existing position descriptions. This makes it clear that safety accountability is part of every role, not an add on.

Brief People on Their Responsibilities Directly

Do not rely on people reading documents. Brief managers and supervisors directly on their OH&S responsibilities. Record that briefing. For workers, incorporate responsibility awareness into induction and regular safety communication. Test understanding through questions, not just information delivery.

Define Authority Explicitly

For every responsibility, identify the corresponding authority. If a supervisor is responsible for ensuring hazards in their area are controlled, they need the authority to take corrective action, stop work if necessary, and escalate to management. Document this authority and make sure the person knows they have it.

Review Responsibilities When the Organisation Changes

Every time a role changes, a person leaves, or the organisation restructures, review the responsibility assignments. Build this review into the management of change process. It should not be a separate exercise that happens only when an audit is approaching.

Clause 5.3 in the Context of an Integrated Management System

Many organisations operate an integrated management system covering ISO 9001, ISO 14001, and ISO 45001 simultaneously. In that context, Clause 5.3 requirements appear across all three standards. The approach to roles and responsibilities needs to be consistent across the system without creating unnecessary duplication.

In practice, a single responsibility matrix that covers quality, environmental, and OH&S responsibilities for each role is more useful than three separate documents. It also reflects how work actually happens. A site supervisor does not switch between quality hat and safety hat. They need to understand their full range of management system responsibilities in one coherent picture.

If you are auditing an integrated system and examining Clause 5.3 of ISO 45001, check whether the responsibilities are genuinely integrated or just assembled from three separate documents that may contradict each other. Contradictions between the quality and safety responsibilities of the same role are a real finding.

Preparing for a Clause 5.3 Audit

If you are a quality or safety manager preparing your organisation for an internal or external audit of Clause 5.3, the following practical steps will help.

First, pull together all documents that define roles and responsibilities: position descriptions, the OH&S plan, any responsibility matrices, and organisational charts. Check that they are current and consistent with each other.

Second, interview a sample of people across levels before the audit. Ask them what their OH&S responsibilities are. If they cannot answer clearly, you have found a gap that needs addressing before the auditor arrives.

Third, check the reporting line for OH&S performance. Can you demonstrate that OH&S performance information reaches top management through a defined mechanism? Management review records are one place to look for this evidence.

Fourth, look for evidence of authority alongside responsibility. Does the safety manager have documented authority to act? Does the supervisor have documented stop work authority? These are the kinds of details that distinguish a functioning system from a compliant document set.

For those looking to build their skills in auditing OH&S management systems, including how to effectively assess Clause 5.3 in practice, the guide to auditing occupational health and safety under ISO 45001 provides useful context. And if you are working toward formal auditor credentials, ISO 45001 auditor training levels explained will help you understand which level of training is appropriate for where you are in your career.

Audit Workshop delivers practical ISO 45001 auditor training at foundation, internal auditor, and lead auditor levels. The training is built around real audit scenarios, not abstract theory, so you come away knowing how to actually assess a clause like 5.3, not just recite what it says.

Frequently Asked Questions

No. ISO 45001 does not prescribe specific roles or require a dedicated safety manager. What it requires is that relevant roles within the OH&S management system have assigned responsibilities and authorities, and that those assignments are communicated. In a small organisation, one person might hold multiple roles. What matters is that every element of the system has a clear owner who understands their responsibilities.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2026 Lead Auditor Training Course
Launching on 22 Sept 20265+ enrolled
View Details
Exemplar Global certified
ISO 9001:2026 Lead Auditor Training Course badge
ISO 9001:2026 Lead Auditor

Quality Management Systems (QMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
USD 299USD 789
ISO 45001:2018 Lead Auditor Training Course
15+ enrolled
View Details
Exemplar Global certified
ISO 45001:2018 Lead Auditor Training Course badge
ISO 45001:2018 Lead Auditor

Occupational Health and Safety Management Systems (OHSMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
USD 249USD 789
ISO 14001:2026 Lead Auditor Training Course
10+ enrolled
View Details
Exemplar Global certified
ISO 14001:2026 Lead Auditor Training Course badge
ISO 14001:2026 Lead Auditor

Environmental Management Systems (EMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
USD 249USD 789
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Digital badges and a certificate
  • Access to webinars, events, and online resources

Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Instant Certificate

Download your digital certificate the moment you complete the course.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.