Synergy Nexus Group
Oil & Gas — Production

Engineering Readiness for ISO 45001 Certification

A mid-sized upstream operator preparing for ISO 45001 certification.

Synergy Nexus rebuilt the management system around field-validated requirements, achieving certification with zero re-audit findings.

0
Nonconformities raised at the Stage 2 certification audit
~33%
Reduction in safety documentation set
12 mo
To first surveillance audit, positioned to pass cleanly

Macro Context: Certification as a Commercial Gate, Not a Compliance Exercise

ISO 45001:2018 replaced OHSAS 18001 as the governing international standard for occupational health and safety management systems, built on the Annex SL high-level structure shared across ISO 9001 and ISO 14001 and organized around a Plan-Do-Check-Act cycle spanning leadership commitment (Clause 5), operational planning and control (Clause 8), performance evaluation (Clause 9), and continual improvement (Clause 10). For upstream operators, certification has moved well beyond a compliance signal: major operators and joint-venture partners increasingly require ISO 45001 certification as a contractor and counterparty prequalification gate, and insurers price OH&S risk differently for a certified management system than an uncertified one.

That commercial reality changes what "certification readiness" has to mean. A management system built to survive a single audit event is a materially different, and weaker, asset than one built to operate as the organization's actual daily safety discipline — the distinction this engagement was built around from the outset.

The Structural Challenge: Documentation Assembled Without Field Verification

The operator's safety management system had accreted over several years, authored incrementally by different personnel responding to different pressures — a new procedure added after an incident, a policy updated to reflect a regulatory change, a checklist inherited from a prior operator during an asset transfer. No single control owned document lifecycle management under Clause 7.5 (Documented Information), and no systematic process existed to verify that what was written matched what crews actually did on a rig floor or at a wellsite.

A near-miss the prior year — a permit-to-work step that field crews had been completing out of sequence relative to the documented procedure, without incident until it nearly wasn't — elevated this exposure to a board-level concern. The specific risk was not that the documentation was incomplete. It was that no one could say with confidence which of the operator's dozens of safety procedures reflected genuine field practice and which had drifted into fiction that would not survive an auditor asking a crew to walk through it.

The Methodology: Parallel Gap Assessment and Field-Verification Protocol

Synergy Nexus ran two workstreams concurrently rather than sequentially: a formal clause-by-clause gap assessment against ISO 45001 and relevant API recommended practices, and direct field verification — shadowing crews through permit-to-work cycles, lockout/tagout execution, and job safety analysis (JSA) briefings — to establish independently what was actually happening on site, without reference to what the documentation claimed.

The governing principle

Where field practice proved sound but undocumented, the procedure was rewritten to match the practice — not the reverse. Forcing crews to adopt a paper process that ignored how the work was safely and effectively already being done would have produced exactly the kind of gap the near-miss had already exposed.

Clause areaDocumentation status (before)Field-verified statusResolution
5.4 — Worker participationPolicy existed, undatedInconsistent across crewsStandardized participation protocol, field-tested
6.1.2 — Hazard identificationGeneric, site-wide JSA templateCrews improvised site-specific hazardsJSA template rebuilt per site class, crew-validated
8.1 — Operational control (permit-to-work)Sequence did not match practiceSteps reordered informally by crewsProcedure rewritten to the verified safe sequence
9.2 — Internal auditNo standing internal audit functionNo independent verification cycleInternal audit team recruited and trained

Following the rebuild, Synergy Nexus ran an internal mock audit — structured identically to the certification body's Stage 1 (documentation review) and Stage 2 (on-site implementation) audits — to pressure-test the system before the real certification audit rather than during it.

The Deterministic Outcome

Audit stageResult
Stage 1 — documentation reviewZero major nonconformities; two minor observations resolved before Stage 2 was scheduled
Stage 2 — on-site implementation auditZero nonconformities of any classification; certification granted
Documentation setReduced by approximately one-third — procedures without corresponding field practice were retired, not merely revised
Internal audit capabilityA trained internal team now runs the Clause 9.2 audit cycle independently ahead of each scheduled surveillance audit

Certification under ISO 45001 is granted following Stage 1 and Stage 2 audits and holds for a three-year cycle, subject to annual surveillance audits confirming the system remains in force as certified. The operator enters its first surveillance audit, twelve months out, with the same field-verified system that passed Stage 2 — not a system re-papered for the audit and left to drift again afterward.

Strategic Takeaways

  • Audit readiness is not documentation completeness — it is the demonstrated correspondence between what is written and what a crew actually does, which is precisely what a Stage 2 auditor tests by asking to see the work, not just read the procedure.
  • A smaller, field-verified documentation set outperforms a larger, unverified one under audit: fewer procedures with total fidelity beat a comprehensive library an auditor can sample-test and find drifting from practice.
  • Building an internal Clause 9.2 audit capability before certification, not after, converts the first surveillance audit from a fresh compliance event into a confirmation of a control the organization is already running on itself.
Results
01

Achieved ISO 45001 certification through the Stage 1 and Stage 2 audits with zero nonconformities, resolving field-practice gaps that would otherwise have surfaced as findings under review

02

Reduced the safety documentation set by approximately one-third, eliminating procedures without corresponding field practice

03

Trained an internal audit team to sustain ongoing compliance, embedding audit-readiness into standing operational governance ahead of the first surveillance cycle

Facing a comparable challenge?

Tell us about your organization and we will route you to the right partner.