Summary Report on ISO 45001:2018 Clause 6.1: The Strategist

Actions to address risks and opportunities, across requirements, field, strategy, and evidence

Mission 45001 is our deep dive into ISO 45001:2018, a network of clauses working together to help organisations run safe, resilient operations. Our mission is to show how that network works from the inside. This is our summary report on 'The Strategist' of the safety syndicate, marking the completion of the Clause 6.1 review and looking back across its four elements.

This is a summary report marking the completion of the review of Clause 6.1. It looks back at the critical elements of the group codenamed The Strategist, comprising The Framer (6.1.1), The Analyst (6.1.2.1 through 6.1.2.3), The Advocate (6.1.3), and The Designer (6.1.4). This group forms the planning engine of the OH&S management system, converting what the organisation knows about itself into action it can be held to.

Clause 6.1 sits at the hinge of ISO 45001, where contextual understanding and leadership intent become planned action. Together, Clauses 6.1.1 through 6.1.4 determine what must be addressed, size it against resource, bind it to what the law and other commitments require, and commit it to owned, integrated, and measurable action before operation and assurance take over.

The Strategist at a Glance

Four Elements, One Determination

  • The Framer (6.1.1): General. Determines the risks and opportunities that must be addressed, built on context, interested parties, and scope
  • The Analyst (6.1.2): Three readings. Hazard identification (6.1.2.1), assessment of OH&S risks and other risks (6.1.2.2), and assessment of OH&S opportunities and other opportunities (6.1.2.3)
  • The Advocate (6.1.3): Determination of legal requirements and other requirements. The floor beneath the plan and the ceiling above it
  • The Designer (6.1.4): Planning action. Converts everything determined into action that is integrated, owned, and measured for effect
  • The group in one line: The planning engine of the OH&S management system, consuming what context and leadership supply and setting the terms every downstream clause delivers against

ISO 45001:2018 Clause 6.1.1 Requirements

General

Clause 6.1.1: When planning for the OH&S management system, the organisation shall consider the issues referred to in 4.1, the requirements referred to in 4.2 and 4.3, and determine the risks and opportunities that need to be addressed to:

  • a) give assurance that the OH&S management system can achieve its intended outcome(s)
  • b) prevent, or reduce, undesired effects
  • c) achieve continual improvement
  • In doing so, the organisation shall take into account its hazards (6.1.2.1), its OH&S risks and other risks (6.1.2.2), its OH&S opportunities and other opportunities (6.1.2.3), and its legal requirements and other requirements (6.1.3), and shall consider planned changes and their potential to introduce new hazards and risks
  • Documentation: The organisation shall maintain documented information on risks and opportunities, and on the process(es) and actions needed to determine and address them, to the extent necessary to have confidence they are carried out as planned

ISO 45001:2018 Clause 6.1.1 in the Field

Framing decides what the field looks for

  • Sets what is looked for: Inspections and hazard reporting follow the frame, and what the determination excluded is never looked for on site
  • Activates on change: New contracts, equipment, people, and processes reopen the determination before work starts rather than at the annual review
  • Felt through coverage: Work inside the frame is assessed and controlled; work outside it proceeds on habit alone
  • Reads the terrain back: Field conditions feed the issues and expectations the next determination is built from
  • Exposed by surprises: Incidents in activities the register never mentioned trace directly to a frame drawn too narrow

ISO 45001:2018 Clause 6.1.1 in Strategy

Framing selects the risks and opportunities to address

  • Concentrates scarce effort: The determination decides what must be addressed when not everything can be, under resource that is never enough
  • Built on Clause 4: Context (4.1), interested parties (4.2), and scope (4.3) supply the issues, the expectations, and the boundary the determination works within
  • Points both directions: Undesired effects are prevented and continual improvement is pursued out of the same determination
  • Sets the system's ambition: Shallow framing stops at statutory duty; deeper framing, in the context of better resourcing, reaches into optimisation and innovation
  • Sized to actual resource: A frame matched to capability can be defended in full; a frame sized to aspiration guarantees quiet defeats

ISO 45001:2018 Clause 6.1.1 in Evidence

Proving the framing is real and current

  • Verify the inputs: Confirm the risk procedure references context, interested parties, and scope rather than standing alone
  • Test currency: Check the determination was revisited when operations, structure, or external conditions changed
  • Confirm both directions: Ensure opportunities were determined alongside risks, not risk alone
  • Trace determinations downstream: Follow determined risks and opportunities into assessment, requirements, and planned action
  • Check the documented record: Documented information on risks and opportunities, and on the processes for addressing them, is maintained and current
ISO 45001 Clause 6.1 summary report: the Strategist's four elements walked across requirements, field, strategy and evidence

ISO 45001:2018 Clause 6.1.2.1 Requirements

Hazard identification

Clause 6.1.2.1: The organisation shall establish, implement and maintain a process(es) for hazard identification that is ongoing and proactive. The process(es) shall take into account, but not be limited to:

  • a) how work is organised, social factors (including workload, work hours, victimisation, harassment and bullying), leadership and the culture in the organisation
  • b) routine and non-routine activities and situations, including hazards arising from infrastructure, equipment, materials, substances and the physical conditions of the workplace, human factors, and how the work is actually done
  • . . .
  • h) changes in knowledge of, and information about, hazards
  • Documentation: There is no requirement for specific documented information within Clause 6.1.2.1 itself; identified hazards feed the documented risks and opportunities held under Clause 6.1.1

ISO 45001:2018 Clause 6.1.2.1 in the Field

Detection surfaces hazards where they live

  • Shared with the workforce: Hazard identification is the one element of the clause workers feed directly, through reporting, observation, and consultation
  • Reads work as done: The identification surface is what actually happens on site, not what the method statement describes
  • Covers everyone present: Contractors, visitors, and the surrounding environment carry hazards into scope alongside the payroll
  • Draws on precedent and foresight: Past incidents, internal and external, and potential emergency situations are live inputs rather than history
  • Strongest when targeted: Reporting dominated by opportunistic observation is weaker than intelligence from planned task observations and targeted inspections

ISO 45001:2018 Clause 6.1.2.1 in Strategy

Hazard intelligence decides what the plan can see

  • Ongoing and proactive by design: The process runs on change and anticipation; an annual cycle identifies a year late
  • Elevates organisational hazards: Workload, working hours, social factors, leadership, and culture are hazards in their own right, not background
  • Decides what can be sized: Assessment ranks only what identification produced, so an absent hazard scores zero and an unseen opportunity is never taken
  • Caps the quality of the plan: Every downstream element works from this intelligence, and no methodology can recover what was never seen
  • Widens with knowledge: Changes in knowledge of, and information about, hazards reopen identification without waiting for an incident

ISO 45001:2018 Clause 6.1.2.1 in Evidence

Proving hazard identification is ongoing and proactive

  • Check register movement: Confirm the hazard register grew after the last operational change rather than staying exactly as it was
  • Verify source breadth: Look for hazards arriving from workers, incidents, inspections, and consultation, not from a single channel
  • Confirm non-routine coverage: Ensure abnormal situations, maintenance, and foreseeable emergencies appear alongside routine work
  • Test coverage of people: Verify contractors, visitors, and others near the work are considered, not only employees
  • Trace incident learning: Check past incidents and their causes re-entered identification rather than closing with the report

ISO 45001:2018 Clause 6.1.2.2 Requirements

Assessment of OH&S risks and other risks to the OH&S management system

Clause 6.1.2.2: The organisation shall establish, implement and maintain a process(es) to:

  • a) assess OH&S risks from the identified hazards, while taking into account the effectiveness of existing controls
  • b) determine and assess the other risks related to the establishment, implementation, operation and maintenance of the OH&S management system
  • Documentation: The organisation's methodologies and criteria for the assessment of OH&S risks shall be defined with respect to their scope, nature and timing, and shall be maintained and retained as documented information

ISO 45001:2018 Clause 6.1.2.2 in the Field

Risk weighting visible on the ground

  • Visible in sequence: What is controlled first on site reveals the real ranking, whatever the register says
  • Judged as fitted: Risk is weighed against the controls actually operating, not the controls specified in the file
  • Context moves the score: The same forklift crossing weighs one way at ten movements a day behind a barrier, and another at a hundred behind a painted line
  • Re-scored when conditions move: Assessments follow hazards, controls, and conditions rather than the review calendar
  • Directs field attention: Supervision effort and control checks land where assessed consequence is highest

ISO 45001:2018 Clause 6.1.2.2 in Strategy

Weighing risk so effort follows consequence

  • Criteria before scoring: Methodology is defined in advance for scope, nature, and timing, so ratings survive challenge
  • Two risk families: Risks to workers and risks to the management system itself are both assessed, because they fail together
  • Proportionality over uniformity: Effort tracks consequence; treating every hazard identically looks thorough and functions as a failure of strategy
  • Arms the budget argument: A defensible ranking is what wins resources when production and cost arrive at the same table with numbers of their own
  • Hands sequence to planning: The running order it sets decides what is pursued first and what waits

ISO 45001:2018 Clause 6.1.2.2 in Evidence

Proving the risk assessment can be defended

  • Verify the methodology: Confirm methodologies and criteria are defined, maintained, and retained as documented information
  • Test reproducibility: Check whether two assessors reach the same score from the same facts
  • Read the spread: A register where everything is medium is a register with no criteria
  • Confirm controls as found: Ensure assessments reference the effectiveness of existing controls as operated, not as specified
  • Trace re-assessment: Look for scores that moved when hazards, controls, or conditions moved

ISO 45001:2018 Clause 6.1.2.3 Requirements

Assessment of OH&S opportunities and other opportunities

Clause 6.1.2.3: The organisation shall establish, implement and maintain a process(es) to:

  • a) assess OH&S opportunities to enhance OH&S performance, taking into account planned changes to the organisation, its policies, its processes or its activities, including opportunities to adapt work, work organisation and work environment to workers, and opportunities to eliminate hazards and reduce OH&S risks
  • b) assess other opportunities for improving the OH&S management system
  • Documentation: There is no requirement for specific documented information within Clause 6.1.2.3 itself; assessed opportunities join the documented risks and opportunities held under Clause 6.1.1

ISO 45001:2018 Clause 6.1.2.3 in the Field

Opportunities spotted where the work is done

  • Spotted by the people doing it: Opportunities to adapt work, its organisation, and its environment to workers surface from the workforce first
  • Elimination seen in operation: The floor is where chances to remove a hazard outright, rather than manage it, first show themselves
  • Gains beyond compliance: Field suggestions carry improvements in method, layout, and equipment that no risk assessment would raise
  • Same channels as hazards: Consultation, observation, and reporting carry opportunity upward exactly as they carry risk
  • Lost if not captured: An opening noticed but never assessed leaves the work exactly as it was

ISO 45001:2018 Clause 6.1.2.3 in Strategy

Leverage places scarce effort where it multiplies

  • Assessment is required: Opportunities are assessed in the same breath as risks, a requirement rather than an optional extra
  • Elimination outranks control: Opportunities to remove hazards sit above opportunities to manage them, mirroring the hierarchy of controls
  • The system is in scope: Improving the management system itself counts alongside improving the workplace
  • Speaks the language of gain: An opportunity recruits allies in the business that a cost of prevention never will
  • Same destination as risk: Assessed opportunities feed planned action exactly as assessed risks do

ISO 45001:2018 Clause 6.1.2.3 in Evidence

Proving opportunities are assessed, not assumed

  • Open the opportunity register: The most common finding is that it is empty, and the blank itself is the finding worth reporting
  • Verify assessment discipline: Confirm opportunities pass through a defined process rather than being listed when convenient
  • Check adaptation to workers: Look for assessed opportunities to adapt work, organisation, and environment to the people doing the work
  • Confirm system-level entries: Ensure improvement of the management system itself appears, not only workplace fixes
  • Trace opportunity to action: Follow assessed opportunities into planned action alongside the risks

ISO 45001:2018 Clause 6.1.3 Requirements

Determination of legal requirements and other requirements

Clause 6.1.3: The organisation shall establish, implement and maintain a process(es) to:

  • a) determine and have access to up-to-date legal requirements and other requirements that are applicable to its hazards, OH&S risks and OH&S management system
  • b) determine how these legal requirements and other requirements apply to the organisation and what needs to be communicated
  • c) take these legal requirements and other requirements into account when establishing, implementing, maintaining and continually improving its OH&S management system
  • Documentation: The organisation shall maintain and retain documented information on its legal requirements and other requirements, and shall ensure that it is updated to reflect any changes

ISO 45001:2018 Clause 6.1.3 in the Field

Legal and other requirements lived, not filed

  • Lived in procedures: Requirements change behaviour when operational procedures cite them; a register holding them alone governs nobody
  • Communicated to the governed: What binds is known by the people it governs, not only by whoever maintains the register
  • The floor is not negotiable: Determined requirements fix a minimum that no site judgement is free to argue below
  • Beyond statute on site: Client standards, contract conditions, and voluntary commitments bind field practice as firmly as law
  • Current against change: New law, new contracts, and new commitments reach the field before the work they govern begins

ISO 45001:2018 Clause 6.1.3 in Strategy

Advocacy sets the floor and raises the ceiling

  • Sets the floor: Determined requirements fix the minimum every planned action must clear, whatever else is being traded
  • Raises the ceiling: Voluntary pledges and adopted standards set aspiration above compliance, and leadership turns them into collective ambition
  • Fed by Clause 4.2: Expectations classified as being, or potentially becoming, legal or other requirements arrive here by design, not by accident
  • Determined, applied, and kept current: What binds is established, how it applies is worked out, and changes are tracked
  • Wins backing: Requirements carried into the business argue for the plan and return as resource

ISO 45001:2018 Clause 6.1.3 in Evidence

Proving legal and other requirements are current and applied

  • Verify the register: Documented information on legal and other requirements is maintained, retained, and updated for change
  • Read the update history: Confirm the register moved when law, contracts, or commitments moved
  • Test application: Check the organisation worked out how each requirement applies and what needed communicating
  • Trace into procedures: Find requirements cited in operational documents, training, and planning rather than filed
  • Confirm access: Ensure the people governed by a requirement can actually reach and understand it

ISO 45001:2018 Clause 6.1.4 Requirements

Planning action

Clause 6.1.4: The organisation shall plan:

  • a) actions to address these risks and opportunities, address legal requirements and other requirements, and prepare for and respond to emergency situations
  • b) how to integrate and implement the actions into its OH&S management system processes or other business processes, and how to evaluate the effectiveness of these actions
  • The organisation shall take into account the hierarchy of controls (8.1.2) and outputs from the OH&S management system when planning to take action
  • Documentation: There is no requirement for specific documented information within Clause 6.1.4 itself; planned actions are covered by the documented information held under Clause 6.1.1

ISO 45001:2018 Clause 6.1.4 in the Field

Planned actions that survive contact with the work

  • Actions live in the work: Planned actions appear in permits, maintenance schedules, and procurement, not in a spreadsheet beside the business
  • Owned and dated: Every action carries an owner, a date, and a measure the site can be held to
  • Emergencies planned for: Preparation and response for foreseeable emergency situations are planned actions, not assumptions
  • Hierarchy respected in practice: Elimination and substitution are weighed before administrative controls, and the record says which was chosen and why
  • Closed on effect: Actions close when evaluated as effective, not when delivered

ISO 45001:2018 Clause 6.1.4 in Strategy

Design commits the determination to planned action

  • Three duties at once: Risks and opportunities, legal and other requirements, and emergency preparedness all become planned action
  • Integration is the requirement: Actions enter the OH&S management system or other business processes; a parallel plan sits outside both
  • Effectiveness designed in: How effect will be evaluated is settled when the action is designed, not after it is delivered
  • Considers the hierarchy: The hierarchy of controls and the system's own outputs shape which action is chosen
  • Hands the clause over: What design produces passes to objectives (6.2), operational control (8.1), and evaluation (9.1)

ISO 45001:2018 Clause 6.1.4 in Evidence

Proving planned actions land and work

  • Trace action to determination: Every planned action leads back to a determined risk, opportunity, requirement, or emergency scenario
  • Confirm owners and dates: Check actions carry ownership, timing, and a planned measure of effectiveness
  • Verify integration: Find the actions inside business processes — permits, procurement, maintenance — rather than beside them
  • Test effectiveness evaluation: Confirm actions were evaluated for effect, and reopened where the effect failed
  • Check hierarchy reasoning: Look for evidence the hierarchy of controls was considered when the action was chosen

In Summary

Clause 6.1 of ISO 45001:2018 provides the planning core of an effective OH&S management system. By addressing the determination of risks and opportunities (6.1.1), hazard identification (6.1.2.1), the assessment of risks (6.1.2.2) and opportunities (6.1.2.3), legal and other requirements (6.1.3), and planning action (6.1.4), it ensures the system acts on what matters, within what binds, through actions that are owned, integrated, and measured.

Together The Strategist's elements comprising The Framer (6.1.1), The Analyst (6.1.2), The Advocate (6.1.3), and The Designer (6.1.4) serve as the hinge of the wider Safety Syndicate, consuming what context and leadership supply and setting the terms that operation, evaluation, and improvement deliver against.

Background Data on 'The Strategist', Clause 6.1

Focus: Actions to Address Risks and Opportunities

  • Codename: The Strategist. Clause 6.1, comprising The Framer (6.1.1), The Analyst (6.1.2), The Advocate (6.1.3), and The Designer (6.1.4)
  • Function: Converts what the organisation knows about itself into action it can be held to. Commands four elements rather than operating a single process
  • System Role: The hinge of the standard. Consumes context, interested parties, and scope, then sets the terms every downstream clause delivers against
  • Syndicate Caucus: Commands The Framer (6.1.1), The Analyst (6.1.2), The Advocate (6.1.3), and The Designer (6.1.4). Draws from The Scout (4.1), The Connector (4.2), and The Cartographer (4.3). Hands over to The Planner (6.2) and The Operator (8.1)
  • Modus Operandi: Sequential and cumulative. Each element depends on the one before it, so a weak link degrades everything downstream of it rather than only itself
  • Activation Threshold: Any change in context, stakeholder expectation, scope, legal duty, workplace hazard, or planned organisational change
  • Known For: Turning understanding into obligation. The clause where a system either commits to something or reveals that it has not
  • Field Signals: Hazard reports that produce no change, risk assessments that outlive the work they describe, controls with no traceable origin
  • Boardroom Signals: Risk registers presented without action status, opportunity absent from improvement papers, resourcing decided outside the determination
  • Audit Signals: Undefined risk criteria, empty opportunity assessment, legal registers disconnected from planning, actions with no effectiveness measure
  • PDCA Coordinates: Lives in Plan and reaches into Do. Designs the response and specifies how its effect will be measured

Frequently Asked Questions

What does ISO 45001 Clause 6.1 comprise?

Four elements: the determination of risks and opportunities at 6.1.1 (The Framer), hazard identification and the assessment of risks and opportunities at 6.1.2.1 through 6.1.2.3 (The Analyst's three readings), legal requirements and other requirements at 6.1.3 (The Advocate), and planning action at 6.1.4 (The Designer).

Which part of Clause 6.1 is most often missed?

Clause 6.1.2.3, the assessment of OH&S opportunities. Most systems assess risk thoroughly and opportunity not at all, even though assessing opportunities is a requirement rather than an optional extra.

Does Clause 6.1 require documented information?

In three places. Documented information is maintained on risks and opportunities and on the processes and actions needed to determine and address them (6.1.1); the methodologies and criteria for assessing OH&S risks are maintained and retained (6.1.2.2); and the register of legal and other requirements is maintained, retained, and kept updated (6.1.3).

How does Clause 6.1 connect to Clauses 4 and 5?

Clause 4 supplies what the determination consumes: context, interested party expectations, and scope. Clause 5 supplies the will — leadership commitment, the policy, and worker consultation — that the plan runs on. Clause 5 supplies the will, and Clause 6.1 supplies the plan.

What makes planned action under 6.1.4 compliant?

Actions must address risks, opportunities, legal and other requirements, and emergency preparedness; they must be integrated into the OH&S management system or other business processes; and the method for evaluating their effectiveness must be planned, with the hierarchy of controls taken into account.

← Back to Insights