Our own servers in Europe · GDPR · Support in your language

Software for ISO 45001

ISO 45001, without folders or surprises

Risk assessment, training, PPE, accidents and investigations, with traceability by employee.

What it is and which edition applies

ISO 45001 is the international standard for occupational health and safety management systems. It replaced OHSAS 18001, whose migration ended in September 2021, and added two elements the older document lacked: the context of the organisation and, above all, the consultation and participation of workers in clause 5.4 — where most systems stumble, because it demands real evidence rather than committee minutes.

Content reviewed on

Current edition
ISO 45001:2018 With Amd 1:2024 on climate change
Standard replaced
OHSAS 18001 Migration completed September 2021
Distinctive requirement
Consultation and participation, cl. 5.4 Must reach non-managerial workers and be documented
Spanish framework
Law 31/1995 and RD 39/1997 The standard does not replace the legal duty: it organises it
Very serious penalty in Spain
Up to 983,736 euros Top band of art. 40.2 LISOS after Law 12/2022

Document control

Versions, approvals and distribution with read receipts.

Connected to your document cloud

Publish and version documents by connecting to OneDrive, Google Drive or SharePoint, without duplicating folders.

Audits

Annual program, checklists per standard, findings linked to actions.

Non-conformities

Root cause, action, owner, deadline and effectiveness check.

KPIs

Process objectives fed with real operating data.

Legal requirements

A register of legal and other requirements, with validity and compliance evaluation per standard.

Corrective actions

Root cause, action, owner, deadline and effectiveness check, all linked to the nonconformity.

Improvement actions

Improvement opportunities with an owner and tracking, beyond just fixing what already failed.

Management review

A pre-built report with indicators, audits and nonconformities, ready for the meeting.

PPE and expiry

Protective equipment issued with alerts before it expires.

Contractor coordination

Contractor coordination with contractors and subcontractors.

Risk assessment

Risks identified by role with preventive measures.

Accident investigation

Root cause and investigation report linked to the role and the employee.

Requirements covered


What it solves for ISO 45001

  • Risk assessment by role
  • PPE delivery and expiry
  • Health-and-safety training and information
  • Accident and incident investigation
  • Health surveillance and fitness checks
  • Contractor coordination
ISO 45001 · RISK ASSESSMENT BY JOB SEVERITY × LIKELIHOOD MATRIX 1 2 3 SEVERITY LIKELIHOOD JOBS WITH AN OPEN CRITICAL RISK 1 Press operator Entrapment — guard and interlock still pending 2 Forklift driver Being struck — aisle marking under review 3 Maintenance Work at height — harness inspection overdue Tolerable Moderate Critical CONSULTATION AND PARTICIPATION · CL. 5.4 It must reach non-managerial workers and be documented; committee minutes are not enough RISK, CONTROL AND EVIDENCE, WORKER BY WORKER

Frequently asked questions


What people ask us before getting started

Which edition of the standard is current?

The edition in force is ISO 45001:2018, with Amd 1:2024. When the issuing body publishes a new one, a transition period opens; once it closes, certificates issued against the previous edition stop being valid.

Does this work if we are already certified?

Yes. Your existing system — processes, documents, records, audit history — is loaded in and kept alive from day one. Nothing needs redesigning and the certification cycle does not restart.

Will the auditor accept digital records?

Yes, provided they are traceable, controlled and able to show who did what and when. No standard requires paper; every standard requires reliable evidence, and a properly controlled electronic record provides it better than a folder.

Can it be combined with other standards?

Yes, and that is the sensible route. The common Annex SL structure lets a single integrated system share the process map, document control, internal audits, nonconformities and indicators between ISO 45001 and the rest, leaving only the standard-specific parts separate.

How long does it take to be ready for an audit?

It depends on the starting point. An organisation already working with written procedures is usually ready in two or three months; one starting from scratch needs longer. The bottleneck is rarely the tool — it is the availability of the people who know the processes.

What happens to the documentation we already have?

It is migrated. Existing procedures, forms and records are loaded with their version and approver, so the history is not lost and the system starts with the memory the organisation already had.

Can the auditor look directly at the system?

Yes. They are given read-only access with a defined scope and an expiry date. It is more comfortable for both sides than preparing a folder of screenshots and exports.

What is the difference between a major and a minor nonconformity?

A major one compromises the system's ability to meet a requirement — a required process missing altogether, systematic failure, or a failure affecting the product — and usually blocks certification until it is closed. A minor one is a specific lapse resolved with an action plan.

Are the indicators calculated automatically?

Yes, from the data the processes themselves generate. That is the difference between a dashboard that reflects what is happening and a spreadsheet somebody fills in the week before the management review.

Does it work across several sites or legal entities?

Yes. The model is multi-company and multi-site: what makes sense to share is shared, and what belongs to each location stays separate — including the certificate scope where it differs.

Get ready for your ISO 45001

We'll show you the module running with data similar to yours.

Request a demo

Sources


Where each figure comes from

References to the official text in force. If a standard is revised, this page is updated and the review date says so.

  1. ISO 45001:2018 — Occupational health and safety management systems ISO · 2018 ed., with Amd 1:2024
  2. Ley 31/1995, de Prevencion de Riesgos Laborales BOE-A-1995-24292 · Consolidated text

Software for ISO 45001 — Occupational health and safety

Kimobox is a software for ISO 45001 that digitizes the requirements of the standard: risk assessment by role, ppe delivery and expiry, health-and-safety training and information, accident and incident investigation, with full traceability and evidence ready for the auditor.

The platform lets you run an integrated management system that combines ISO 45001 with other ISO standards and sector protocols, sharing the process map, document control, internal audits, non-conformities and KPIs.