OHSAS 18001 is no longer valid. What happened to the certificates, what ISO 45001 changes, a step-by-step move for an OHSAS-style system, and UAE costs and timing.
Plenty of organisations still have a health and safety system that was built for OHSAS 18001. The manual is still on the shared drive, the hazard register still follows the 2007 clause numbers, and the certificate on the reception wall may carry a date from before 2021. The system may work perfectly well. The certificate does not.
This article answers the questions people usually have when they find that out: is OHSAS 18001 still valid, what happened to the certificates, what ISO 45001 changes, how to move an OHSAS-style system across, and what it costs in the UAE.
What OHSAS 18001 was
OHSAS 18001 was published in 1999 and revised in 2007, which is the edition most people know as OHSAS 18001:2007. It was written by the OHSAS Project Group, a mix of national standards bodies, certification bodies, accreditation bodies and safety institutions, with BSI, the UK national standards body, providing the secretariat. In the UK it was published as BS OHSAS 18001.
It is worth being precise about one thing, because it is often written wrongly: OHSAS 18001 was never an ISO standard. It was a specification developed outside ISO that became the de facto basis for certifying health and safety management systems around the world. There was no ISO standard for this subject until ISO 45001:2018, published in March 2018 and developed by ISO project committee ISO/PC 283, which used OHSAS 18001 as one of its starting points.
What happened to OHSAS 18001 certificates
When ISO 45001 was published, the International Accreditation Forum set the migration rules in IAF MD 21:2018. Organisations holding accredited OHSAS 18001 certificates had three years to move to ISO 45001. The deadline fell in March 2021. Certification bodies quoted dates a few days apart, but the effect was the same.
In April 2020, because of COVID-19, IAF allowed OHSAS 18001 certificates to be extended by up to six months, which moved the end of the migration period to 30 September 2021 (IAF COVID-19 FAQ 15, updated 11 April 2020; LRQA, 7 April 2020). The extension was there for organisations whose migration audit could not happen on time. It was not a general reprieve.
After 30 September 2021:
- No accredited OHSAS 18001 certificate remained valid. Accreditation bodies stopped recognising certification to it.
- Migration was no longer possible. Migration was a route for current certificate holders. An organisation whose certificate lapsed is treated as a new client.
- ISO 45001 certification starts from scratch. That means a full initial certification: a Stage 1 audit of readiness and documentation, then a Stage 2 audit of implementation, then the normal three-year cycle described in our article on how often ISO audits happen.
What is different in ISO 45001
ISO 45001 is not a rewrite for its own sake. Most of what a good OHSAS 18001 system did is still needed: hazard identification, risk assessment, legal compliance, operational control, emergency preparedness, incident investigation, internal audit and management review. What changes is where health and safety sits in the organisation and who is involved in it. Clause numbers below refer to ISO 45001:2018.
Context and interested parties (clauses 4.1 to 4.3)
The organisation must work out the internal and external issues that affect what its health and safety system can achieve, identify the interested parties other than workers that matter to it, and decide which of their needs and expectations are or could become legal or other requirements. The scope of the system is then set with those in mind. OHSAS 18001 had nothing equivalent.
Since February 2024, ISO 45001:2018/Amd 1:2024 also requires the organisation to decide whether climate change is a relevant issue, and notes that interested parties can have climate-related requirements. In a hot climate this is rarely a hard question.
Leadership and accountability (clauses 5.1 and 5.3)
OHSAS 18001 required a member of top management to be appointed with specific responsibility for the system. ISO 45001 drops the appointee. Instead, clause 5.1 lists what top management itself must do, including taking overall responsibility and accountability for preventing work-related injury and ill health, making sure the system is built into business processes, developing a culture that supports it, protecting workers from reprisals when they report incidents or hazards, and supporting health and safety committees. A note to clause 5.3 makes the point plainly: responsibility can be assigned, but top management remains accountable.
Consultation and participation of workers (clause 5.4)
This is the clause that changes most in day-to-day practice. The organisation must have a process for consultation and participation of workers at all relevant levels, and must provide the time, training and resources for it. It must identify and remove barriers to participation, and the standard names examples such as language or literacy, reprisals, and failing to respond to what workers raise.
It then singles out non-managerial workers. They must be consulted on matters including the health and safety policy, legal requirements, objectives, controls for contractors and outsourcing, what is monitored, and the audit programme. And they must take part in hazard identification and risk assessment, deciding controls, deciding training needs, and investigating incidents and nonconformities. A system where the HSE team writes the risk assessments in the office and presents them for signature does not meet this.
Risks and opportunities (clause 6.1)
OHSAS 18001 was built around hazards and risks to people. ISO 45001 keeps that, and adds two things. The organisation must assess other risks to the management system itself, such as losing a key competent person or a contractor model that the system cannot reach. And it must assess opportunities, including opportunities to adapt work, work organisation and the work environment to workers, and to eliminate hazards. Clause 6.1.1 also requires the risks and opportunities of planned changes to be assessed before the change happens.
Hierarchy of controls (clause 8.1.2)
OHSAS 18001:2007 already asked organisations to consider a hierarchy when choosing controls. ISO 45001 turns it into a process of its own for eliminating hazards and reducing risks, in a fixed order: eliminate, substitute, engineering controls and reorganisation of work, administrative controls including training, and then adequate PPE. The inclusion of reorganisation of work matters: changing shift length, staffing or work pace is a recognised control, not only a matter for HR.
Management of change (clause 8.1.3)
OHSAS 18001:2007 dealt with change inside its hazard identification and operational control clauses. ISO 45001 gives it a clause that sets out what counts as change: new or changed processes, workplaces, work organisation, working conditions, equipment and workforce, as well as changes in law, in knowledge about hazards, and in technology. It also covers unintended changes. We cover it in detail in ISO 45001 management of change.
Procurement, contractors and outsourcing (clause 8.1.4)
Procurement of products and services must be controlled so that what is bought fits the system. Contractors are covered in their own right: the organisation must coordinate with them on the risks their work creates for its people, the risks its work creates for theirs, and the risks to others in the workplace, and it must apply health and safety criteria when selecting them. Outsourced functions must be controlled, with the type and degree of control defined. For organisations that rely heavily on subcontracted labour, this can be the largest gap.
One structure across the ISO family
ISO 45001 follows the common clause structure for ISO management system standards, originally called the high level structure and now the harmonised structure. It shares its clause numbers, core text and terms with ISO 9001 and ISO 14001, which makes an integrated management system far simpler to run than it was with OHSAS 18001. Two smaller changes come with it. “Documents” and “records” become documented information, so the standard no longer prescribes a set of written procedures. And preventive action disappears as a separate requirement, because the whole system is meant to be preventive.
| OHSAS 18001:2007 | ISO 45001:2018 |
|---|---|
| No requirement to analyse context | Context, interested parties and scope (4.1 to 4.3), plus the climate question since 2024 |
| Management appointee with specific responsibility | Top management accountability that cannot be handed off (5.1, 5.3) |
| Participation and consultation inside the communication clause | A clause of its own, with named activities for non-managerial workers (5.4) |
| Hazards and risks | Risks and opportunities, including risks to the system itself (6.1) |
| Hierarchy considered when choosing controls | A process for eliminating hazards and reducing risks in a set order (8.1.2) |
| Change handled within hazard identification and operational control | Management of change as its own clause, including unintended changes (8.1.3) |
| Contractors mainly through operational control | Procurement, contractors and outsourcing (8.1.4) |
| Documented procedures and records | Documented information, to the extent needed |
| Corrective and preventive action | Incident, nonconformity and corrective action (10.2); preventive action built into the system |
Moving an OHSAS-style system to ISO 45001: step by step
If your system was built for OHSAS 18001 and is still in use, you are not starting from nothing. The work is to find what is missing, fix it, and then run the system long enough to show it works.
- Check where you actually stand. Confirm whether you hold any current certificate, and find out what your customers, main contractors and tender documents ask for. This sets the deadline.
- Run a gap assessment against ISO 45001, clause by clause. Not against your old manual. Look at evidence on site, talk to supervisors and workers, and read the registers, not only the procedures.
- Write down context, interested parties and scope. Keep it short and specific to your operations. Include the climate change question from Amd 1:2024, and think about heat, extreme weather and any work your climate plans create.
- Move accountability to top management. Retire the “management representative” model. Agree what the leadership team will do and how it will show it: site visits, review of incidents, decisions on resources, and a policy they actually own. Update the policy so it carries the commitments in clause 5.2, including eliminating hazards and consulting workers.
- Build consultation and participation that reaches non-managerial workers. A health and safety committee helps but is rarely enough on its own. Look at language and literacy, shift patterns and subcontracted labour. Make sure workers take part in risk assessments and incident investigations, and keep evidence that they did.
- Rework the risk process. Add opportunities and risks to the system. Apply the hierarchy of controls explicitly in the risk register, so an auditor can see why a control was chosen. Set up a management of change process with a register.
- Bring contractors and outsourcing inside the system. Add health and safety criteria to contractor selection, agree how risks are coordinated on shared sites, and define how outsourced work is controlled.
- Simplify the documentation. Keep what people use. Retire procedures that only existed because OHSAS 18001 asked for them, and keep the records that prove the system runs.
- Train, run, audit and review. Brief managers and workers on what has changed, run the updated system, complete a full internal audit and hold a management review that looks at real data.
- Choose an accredited certification body and book Stage 1 and Stage 2. Check that the body is accredited for ISO 45001 and for your type of work, and that the accreditation body is a signatory to the international recognition arrangements now run by the Global Accreditation Cooperation (Global ACI).
If you also hold or plan ISO 9001 or ISO 14001, do the work once. Context, leadership, competence, documented information, internal audit and management review can be shared across all three.
Cost and timeline in the UAE
There are two separate costs: the certification body’s audits and any help you buy to get ready.
- Certification body, initial certification: typically AED 10,000 to AED 20,000 for the Stage 1 and Stage 2 audits.
- Certification body, recertification: typically AED 7,000 to AED 15,000 in the third year of each cycle, with smaller surveillance audits in the two years between.
- ESGweise consultancy: AED 3,000 per consultant day, quoted as a fixed scope once a gap assessment has shown how much of the system already exists.
Headcount, number of sites and the risk of the work decide where you sit in the certification body’s range. The fixed scope matters: an open timesheet against an old OHSAS system can run on for months.
On timing, ISO certification from a standing start typically takes six to twelve months. A working OHSAS-era system usually shortens the build, because hazard registers, legal registers, operational controls and emergency arrangements already exist. It does not shorten the part that cannot be rushed: the certification body will want to see the updated system operating, including a completed internal audit and a management review, before Stage 2 can succeed.
Where ISO 45001 itself stands
As at October 2026, the edition certification bodies audit is ISO 45001:2018 with Amd 1:2024, the climate change amendment published in February 2024. The amendment was treated as a clarification: there was no transition programme and certificates were not reissued, but it is audited.
A full revision is under way. DNV reported in July 2026 that it had reached draft international standard stage, and LRQA reported a national ballot on the draft running from 16 June to 8 September 2026. Publication of a new edition is expected in 2027, and the transition rules have not been set. Certificate holders are expected to get a transition period, as they have for ISO 9001:2026 and ISO 14001:2026.
None of that is a reason to wait. A system that meets ISO 45001:2018 today will need adjusting for the new edition, not rebuilding, and the gap between an OHSAS-style system and either edition is much larger than the gap between the two editions.
Related reading
Our introduction to ISO 45001 explains the standard and why it matters for the social side of ESG. ISO 45001 management of change goes deeper on clause 8.1.3, and how often ISO audits happen explains the certification cycle, including what happens when a certificate expires.
How ESGweise helps
We run the gap assessment against ISO 45001, fix what is missing in the system you already have rather than replacing it, and prepare you for Stage 1 and Stage 2 with an accredited certification body. Our ISO certification and HSE systems services cover the move from OHSAS to ISO 45001, and for organisations with several sites we can run the system month by month so every site stays ready between audits.
Frequently asked questions
Is OHSAS 18001 still valid?
No. OHSAS 18001:2007 was replaced by ISO 45001:2018, and accredited OHSAS 18001 certificates had to migrate within three years of ISO 45001 being published in March 2018. The International Accreditation Forum allowed an extension of up to six months because of COVID-19, to 30 September 2021. After that, no accredited OHSAS 18001 certificate remains valid. An organisation can still run its system in the OHSAS style, but it cannot hold an accredited certificate for it.
Can an expired OHSAS 18001 certificate be transferred to ISO 45001?
No. Migration was only available while the OHSAS 18001 certificate was current. Once it lapsed, the organisation is treated as a new client and goes through initial ISO 45001 certification: a Stage 1 audit of readiness and documentation, then a Stage 2 audit of implementation. The good news is that a working OHSAS-era system usually covers a large part of what ISO 45001 needs.
What is the main difference between OHSAS 18001 and ISO 45001?
ISO 45001 moves health and safety from a specialist function into the way the organisation is run. Top management carries accountability that it cannot hand to a coordinator, non-managerial workers must be consulted and involved in named activities, the organisation must understand its context and interested parties, and it must address opportunities as well as risks. Hierarchy of controls, management of change and procurement, including contractors and outsourcing, each have their own clause.
Was OHSAS 18001 an ISO standard?
No. OHSAS 18001 was developed by the OHSAS Project Group, a mix of national standards bodies, certification bodies and safety institutions, with BSI providing the secretariat, and it was published in the UK as BS OHSAS 18001. It was widely used for certification, but it was never an ISO standard. ISO 45001:2018 was developed by ISO project committee ISO/PC 283 and used OHSAS 18001 as one of its starting points.
How much does ISO 45001 certification cost in the UAE?
Certification body fees typically run from AED 10,000 to AED 20,000 for initial certification and from AED 7,000 to AED 15,000 for recertification, with smaller surveillance audits in between. Headcount, number of sites and the risk of the work decide where you sit in that range. ESGweise charges AED 3,000 per consultant day and quotes a fixed scope after a gap assessment.
Should we wait for the new edition of ISO 45001?
No. As at October 2026 the revision is at draft international standard stage, with publication expected in 2027, and the transition rules have not been set. ISO 45001:2018 with Amd 1:2024 is the edition certification bodies audit today. When the new edition arrives, certificate holders are expected to get a transition period, as they have for ISO 9001 and ISO 14001.