ISO 45001 Clause 6: Planning, Risk and Opportunity in Practice
Clause 6 is where most ISO 45001 management systems either hold together or quietly fall apart. It is the clause that connects the context you defined in Clause 4 to the operational controls you run in Clause 8 — and when auditors find a system that looks compliant on paper but cannot demonstrate how decisions were made, the gap almost always traces back to weak planning. If your hazard register, your legal register, and your objectives do not visibly link to one another, Clause 6 is where that disconnection shows.
This article breaks down what Clause 6 actually requires, where organizations most often fall short, and how to build planning processes that survive an audit and produce a safer workplace rather than a thicker binder.
Build planning that holds up to audit. WhyTrace Plus links hazards, risks, legal requirements, and corrective actions into one traceable record — so your Clause 6 planning is connected, not scattered across spreadsheets. See how WhyTrace Plus structures OH&S planning →
What ISO 45001 Clause 6 Actually Requires
Clause 6, titled "Planning," sets out how an organization determines what could affect its occupational health and safety (OH&S) management system and decides what to do about it. It is divided into two main parts: 6.1 (Actions to address risks and opportunities) and 6.2 (OH&S objectives and planning to achieve them).
The structure matters because it defines a sequence. You cannot set meaningful objectives (6.2) without first determining your risks, opportunities, and legal requirements (6.1). Planning in ISO 45001 is not a one-time exercise completed at certification — the standard frames it as an ongoing process that anticipates changing circumstances and continually re-evaluates what could go wrong and what could be improved.
Here is how Clause 6 breaks down:
| Sub-clause | Title | Core obligation |
|---|---|---|
| 6.1.1 | General | Determine risks and opportunities to the OHSMS, considering Clause 4 context and interested parties |
| 6.1.2 | Hazard identification and assessment | Identify hazards, assess OH&S risks, and assess OH&S opportunities |
| 6.1.3 | Determination of legal and other requirements | Identify applicable legal and other requirements and how they apply |
| 6.1.4 | Planning action | Plan actions to address risks/opportunities and legal requirements, integrate them, and evaluate effectiveness |
| 6.2.1 | OH&S objectives | Establish measurable objectives consistent with the OH&S policy |
| 6.2.2 | Planning to achieve objectives | Define what, who, when, resources, and how results are evaluated |
A point auditors emphasize: planning must be proportionate to the level of risk. A high-hazard manufacturing site and a low-risk office do not need the same depth of analysis. Over-engineering planning for low-risk activities is as much a system weakness as under-planning for serious hazards, because it dilutes attention and creates documentation no one maintains.
As of 2024, there were 542,527 ISO 45001 certificates worldwide covering more than 941,000 sites — a near-tripling since 2020, according to the ISO Survey 2024 released in September 2025. Clause 6 is the section that auditors across all of those certifications scrutinize most closely, because it is where intent becomes a defensible plan.
Clause 6.1.2: Hazard Identification and Risk Assessment
Clause 6.1.2 requires you to establish processes that identify hazards on an ongoing basis, assess the OH&S risks arising from those hazards, and — distinct from older standards — assess OH&S opportunities as well. This is the analytical core of the entire management system.
The hazard identification process under 6.1.2.1 must account for more than the obvious physical dangers. ISO 45001 explicitly expands the scope of what counts as a hazard:
- Routine and non-routine activities and situations
- How work is organized, social factors, leadership, and workplace culture
- Past incidents, internal and external, including emergencies and their causes
- Potential emergency situations
- People — workers, contractors, visitors, and anyone affected by your activities
- Changes in knowledge about hazards
- Design of work areas, processes, equipment, and the way work is actually performed versus how it is documented
That last point — actual versus documented work — is where many organizations create exposure. A hazard identification that only reflects the written procedure misses the workarounds, shortcuts, and adaptations that workers use in practice. ISO 45001 expects worker participation in hazard identification precisely because the people doing the work see hazards that supervisors and procedures do not.
Once hazards are identified, Clause 6.1.2.2 requires assessment of the OH&S risks against defined criteria and methods. The assessment method must be proactive rather than purely reactive — you cannot wait for incidents to reveal your risks. Common methods include risk matrices, job safety analysis, and bow-tie analysis, but the standard does not mandate a specific tool. What it requires is that your method is defined, consistent, and produces results that drive the hierarchy of controls.
Clause 6.1.2.3 introduces the assessment of opportunities — a feature that separates ISO 45001 from OHSAS 18001. Opportunities include ways to improve OH&S performance through changes to processes, technology, work organization, or culture. This is not optional reflection; it is a required input to the planning process. An organization that documents only risks and no opportunities is not fully meeting 6.1.2.
Stop maintaining your risk register in disconnected spreadsheets. WhyTrace Plus captures hazards, links them to incidents and root cause analyses, and ties each risk to the controls and corrective actions that address it. Explore risk assessment in WhyTrace Plus →
Clause 6.1.3: Determining Legal and Other Requirements
Clause 6.1.3 requires you to determine and have access to the legal requirements and other requirements that apply to your OH&S hazards, risks, and management system — and to determine how those requirements apply to you. A list of regulations is not enough; the standard wants the applicability documented.
"Other requirements" extends beyond statute. It includes:
| Category | Examples |
|---|---|
| Legal requirements | OSHA standards (e.g. 29 CFR 1910), national and regional OH&S law, permit conditions |
| Industry codes | Voluntary consensus standards, sector codes of practice |
| Contractual obligations | Client safety requirements, contractor agreements |
| Organizational commitments | Collective agreements, corporate policies, voluntary pledges |
| Interested party requirements | Requirements from unions, regulators, or community agreements |
The frequent failure here is a legal register that exists but is stale. Regulations change, and Clause 6.1.3 requires you to maintain and retain this information and communicate relevant requirements to workers and interested parties. A register last reviewed two years ago, with no record of monitoring for changes, is a finding waiting to happen.
The link to 6.1.4 is direct: identifying a legal requirement is meaningless unless you plan how to meet it and verify that you do. Auditors will trace a sample requirement from your register through to the operational control that satisfies it. If that thread breaks, the planning process is judged incomplete regardless of how thorough the register looks.
For organizations operating across jurisdictions, this sub-clause carries weight. A site in a state with a federal OSHA program faces different obligations than one under a state-plan program, and multinational operations layer national OH&S frameworks on top of one another. The register has to reflect what applies where, not a generic national summary.
Clause 6.1.4: Planning to Take Action
Clause 6.1.4 requires you to plan the actions that address the risks, opportunities, and legal requirements you identified, integrate those actions into your management system processes, and evaluate their effectiveness. This is the bridge between analysis and operation.
The standard specifies that when planning these actions, you must consider the hierarchy of controls and the outputs from your management system. The hierarchy of controls is not a suggestion within ISO 45001 — it is the prescribed order of preference for addressing OH&S risks:
- Elimination — remove the hazard entirely
- Substitution — replace with something less hazardous
- Engineering controls — isolate people from the hazard
- Administrative controls — change the way people work (procedures, training, signage)
- Personal protective equipment — the last line, not the first
A corrective action plan that reaches for PPE or retraining before considering elimination or engineering controls is a recurring audit finding. The hierarchy exists because administrative controls and PPE depend on continuous human compliance, while elimination and engineering controls reduce risk regardless of behavior.
Clause 6.1.4 also requires integration. Actions must be built into existing processes — change management, procurement, operational control — rather than tracked as a separate list that lives outside the way work actually happens. An action plan that sits in a parallel document, disconnected from the procedures it is meant to change, fails the integration requirement even if the actions themselves are sound.
Finally, the clause requires you to evaluate the effectiveness of these actions. Implementing an action is not the end point. The system has to confirm that the action achieved what it was meant to achieve — which connects Clause 6 planning forward to the corrective action and evaluation requirements elsewhere in the standard.
Clause 6.2: Setting and Achieving OH&S Objectives
Clause 6.2 requires you to establish OH&S objectives at relevant functions and levels, and to plan how you will achieve them. Objectives are how the abstract intent of your OH&S policy becomes specific, measurable, and accountable.
Under 6.2.1, objectives must be:
- Consistent with the OH&S policy
- Measurable (where practicable) or capable of performance evaluation
- Monitored
- Communicated
- Updated as appropriate
The "measurable where practicable" qualifier is important. Not every meaningful objective reduces cleanly to a number, but the standard expects you to be able to evaluate whether the objective is being met. An objective like "improve safety culture" fails 6.2.1 unless you define how you will assess progress.
Clause 6.2.2 is where most objectives programs are exposed. For each objective, you must determine:
| Planning element | Question it answers |
|---|---|
| What | What will be done? |
| Resources | What resources are required? |
| Responsibility | Who is responsible? |
| Timeline | When will it be completed? |
| Evaluation | How will results be evaluated, including indicators for monitoring? |
The common weakness is objectives without the supporting plan — a stated target with no named owner, no resourcing, no deadline, and no defined measure of success. That is an aspiration, not an objective. Auditors test 6.2.2 by asking who owns a given objective and how progress is tracked; vague answers indicate the planning element is missing.
Strong objectives also connect back to the risks identified in 6.1.2. An objectives program that ignores the organization's highest-rated risks signals that planning is being done as a formality. The most defensible objectives are the ones an auditor can trace directly to a significant risk, a legal requirement, or a documented improvement opportunity.
This is the same closed-loop discipline that governs corrective action management. For a deeper look at how to keep actions connected to findings through verified completion, see our guide to corrective action and CAPA management.
Common Clause 6 Audit Findings and How to Avoid Them
The deficiencies auditors record against Clause 6 are consistent enough across industries to anticipate. Most stem from treating planning as documentation rather than as a connected, living process.
| Finding | Root issue | What prevents it |
|---|---|---|
| Risk register disconnected from incidents | Hazards identified once, never updated from real events | Link incident investigations back to the risk register |
| Hierarchy of controls not applied | Actions default to PPE/training | Document why higher-order controls were ruled out |
| Stale legal register | No monitoring for regulatory change | Assign ownership and review cadence to the register |
| Objectives without 6.2.2 plans | Targets stated without owner, resource, timeline | Require the full planning set for every objective |
| No worker participation in hazard ID | Planning done by EHS in isolation | Build worker input into the identification process |
| Opportunities not assessed | 6.1.2.3 treated as optional | Require an opportunities review alongside risk assessment |
| Effectiveness never evaluated | Actions closed on completion, not outcome | Schedule effectiveness verification before closure |
The single most common thread is traceability. Clause 6 works as a chain: context feeds hazards, hazards feed risks, risks and legal requirements feed actions and objectives, and actions feed evaluation. When auditors can follow that chain end to end, the system passes. When the links are kept in separate spreadsheets that no one reconciles, the chain breaks somewhere — and that break becomes the finding.
This is the practical case for a connected system over disconnected documents. The difference between a binder of planning records and a functional planning process is whether the records reference each other and stay current.
Make your Clause 6 chain traceable. WhyTrace Plus connects hazards, risks, legal requirements, corrective actions, and objectives in one system — so an auditor can follow any thread from finding to verified outcome. Request a WhyTrace Plus demo →
Frequently Asked Questions
Q. What is the difference between ISO 45001 Clause 6.1 and 6.2?
Clause 6.1 covers the determination of risks, opportunities, and legal requirements, and the planning of actions to address them. Clause 6.2 covers OH&S objectives — the specific, measurable targets you set to improve performance — and the detailed plans to achieve them. In sequence, 6.1 establishes what needs attention and 6.2 defines what you will accomplish about it.
Q. Does ISO 45001 require a specific risk assessment method?
No. Clause 6.1.2.2 requires that your risk assessment method and criteria be defined, consistent, proactive, and applied systematically — but it does not mandate a particular technique. Risk matrices, job safety analysis, and bow-tie analysis are all acceptable. What matters is that the method drives the hierarchy of controls and produces repeatable results.
Q. How is ISO 45001 Clause 6 different from OHSAS 18001 planning?
The most significant additions are the requirement to assess OH&S opportunities (6.1.2.3), the explicit emphasis on worker participation in hazard identification, and stronger integration of planning into the broader management system and Clause 4 organizational context. OHSAS 18001 focused primarily on risks; ISO 45001 frames planning as a continual, opportunity-aware, worker-involved process.
Q. How often should Clause 6 planning be reviewed?
ISO 45001 treats planning as ongoing rather than periodic. Hazard identification and risk assessment should be triggered by changes — new equipment, processes, incidents, or regulatory updates — not only by an annual cycle. The legal register requires monitoring for regulatory change, and objectives are reviewed and updated as appropriate. Many organizations align a formal review with management review, but the underlying processes run continuously.
Q. What is the most common Clause 6 audit finding?
Broken traceability. Organizations frequently maintain risk registers, legal registers, and objectives as separate documents that do not reference one another. When an auditor cannot follow the thread from an identified hazard through to the control and the objective addressing it, the planning process is judged incomplete — even when each individual document looks thorough.
Key Takeaways
- Clause 6 is the planning backbone of ISO 45001, splitting into 6.1 (risks, opportunities, legal requirements, and actions) and 6.2 (objectives and the plans to achieve them).
- Clause 6.1.2 requires ongoing hazard identification that reflects how work is actually performed, proactive risk assessment, and — unlike OHSAS 18001 — assessment of OH&S opportunities.
- Clause 6.1.3 demands a maintained, applicable legal and other requirements register, with documented applicability and a monitoring process for change.
- Clause 6.1.4 requires actions that follow the hierarchy of controls, integrate into existing processes, and have their effectiveness evaluated — not just their completion recorded.
- Clause 6.2 objectives must carry the full planning set: what, resources, who, when, and how results are measured. A target without an owner and a plan is an aspiration, not an objective.
- The most common audit finding is broken traceability between registers; a connected system that links hazards, risks, requirements, actions, and objectives is what survives certification scrutiny.
Related Resources
| Resource | Description | Best For |
|---|---|---|
| ISO 45001 Incident Investigation: Requirements and Best Practices | How Clause 10.2 investigation obligations feed back into Clause 6 hazard and risk planning | EHS managers connecting investigations to the planning chain |
| Corrective Action Management: Stop Losing Track of Your CAPA Items | Closed-loop corrective action that verifies effectiveness, not just completion | Teams turning Clause 6.1.4 actions into verified outcomes |
| Safety Management Trends 2026: AI, IoT, and Regulatory Changes | The regulatory and technology shifts shaping OH&S planning in 2026 | Safety leaders updating their legal register and risk approach |