Executive TL;DR
ISO 45001 defines requirements for an occupational health and safety (OH&S) management system with leadership, consultation, and worker participation, risk and opportunity management, emergency preparedness and response, and continual improvement. It does not replace NR-1, NR-7, NR-9, NR-12, or eSocial; when well implemented, it organizes evidence that legislation already requires. Certification has value only if it operationalizes real controls — not just consulting checklists photographed for marketing. In 2026, accredited auditors press for proof of corrective action effectiveness after accidents and for real representative participation in risk review.
Table of contents
- What ISO 45001 covers that NRs do not state in SMS format
- NR-1/PGR ↔ standard clause mapping
- Worker participation beyond the role title
- Certification: scope, multi-site, and pitfalls
- Integration with ESG and reporting
- Typical mistakes copying ISO 14001 without adaptation
- FAQ
- References
What ISO 45001 covers that NRs do not state in SMS format
NR-1 requires a PGR and controls by risk; ISO 45001 requires a system that plans, operates, monitors, and improves. The difference is process: stakeholder matrix, organizational context, measurable OHS objectives, resources, and competence with evidence (not just a training list).
NR-1/PGR ↔ standard clause mapping
- Ch. 6 planning ↔ PGR + opportunities to improve event indicators.
- Ch. 8 operation ↔ operational controls aligned with field procedures.
- Ch. 9 performance evaluation ↔ internal audit, inspection, exposure measurement.
- Ch. 10 improvement ↔ corrective action after incidents with lessons learned.
Worker participation beyond the role title
CIPA and SESVT already exist legally in certain bases; ISO requires consultation mechanisms and nonconformities raised by the front line. Recording a meeting where an operator flagged a missing guard before the accident is gold in certification and defense.
Certification: scope, multi-site, and pitfalls
Define certification scope by CNPJ and site; multi-site requires clear central and local roles in procedure. Do not exclude critical contractors from risk — the auditor may request interface evidence.
Integration with ESG and reporting
ISSB and GRI ask for safety metrics; ISO 45001 provides a data system when integrated with BI. LTIFR without an hours denominator is empty.
Typical mistakes copying ISO 14001 without adaptation
- Copying a waste procedure for machine risk.
- Not tying OHS objectives to budget.
- Treating psychosocial risk only in HR, outside the SMS.
- Internal audit without process specialists.
- Change management without review when M&A closes a plant.
FAQ
Does ISO 45001 exempt MTE enforcement?
No; certification is not a legal shield.
Is it worth certifying a single site?
Yes if materiality and clients require it.
Can it integrate with 9001?
Yes — high-level structure helps; do not mix indicators.
What is leadership's role?
Policy, resources, and accountability — clause 5.
References
- ISO 45001:2018 — Occupational health and safety management systems (via ABNT NBR ISO 45001).
- Brazil. NR-1 and other applicable NRs.
- IAF — accreditation rules and MD for OH&SMS.
Editorial note: ensure the NBR edition in force is adopted in the certifier contract.
