Engineering Readiness for ISO 45001 Certification
A mid-sized upstream operator preparing for ISO 45001 certification.
Synergy Nexus rebuilt the management system around field-validated requirements, achieving certification with zero re-audit findings.
Macro Context: Certification as a Commercial Gate, Not a Compliance Exercise
ISO 45001:2018 replaced OHSAS 18001 as the governing international standard for occupational health and safety management systems, built on the Annex SL high-level structure shared across ISO 9001 and ISO 14001 and organized around a Plan-Do-Check-Act cycle spanning leadership commitment (Clause 5), operational planning and control (Clause 8), performance evaluation (Clause 9), and continual improvement (Clause 10). For upstream operators, certification has moved well beyond a compliance signal: major operators and joint-venture partners increasingly require ISO 45001 certification as a contractor and counterparty prequalification gate, and insurers price OH&S risk differently for a certified management system than an uncertified one.
That commercial reality changes what "certification readiness" has to mean. A management system built to survive a single audit event is a materially different, and weaker, asset than one built to operate as the organization's actual daily safety discipline — the distinction this engagement was built around from the outset.
The Structural Challenge: Documentation Assembled Without Field Verification
The operator's safety management system had accreted over several years, authored incrementally by different personnel responding to different pressures — a new procedure added after an incident, a policy updated to reflect a regulatory change, a checklist inherited from a prior operator during an asset transfer. No single control owned document lifecycle management under Clause 7.5 (Documented Information), and no systematic process existed to verify that what was written matched what crews actually did on a rig floor or at a wellsite.
A near-miss the prior year — a permit-to-work step that field crews had been completing out of sequence relative to the documented procedure, without incident until it nearly wasn't — elevated this exposure to a board-level concern. The specific risk was not that the documentation was incomplete. It was that no one could say with confidence which of the operator's dozens of safety procedures reflected genuine field practice and which had drifted into fiction that would not survive an auditor asking a crew to walk through it.
The Methodology: Parallel Gap Assessment and Field-Verification Protocol
Synergy Nexus ran two workstreams concurrently rather than sequentially: a formal clause-by-clause gap assessment against ISO 45001 and relevant API recommended practices, and direct field verification — shadowing crews through permit-to-work cycles, lockout/tagout execution, and job safety analysis (JSA) briefings — to establish independently what was actually happening on site, without reference to what the documentation claimed.
Where field practice proved sound but undocumented, the procedure was rewritten to match the practice — not the reverse. Forcing crews to adopt a paper process that ignored how the work was safely and effectively already being done would have produced exactly the kind of gap the near-miss had already exposed.
| Clause area | Documentation status (before) | Field-verified status | Resolution |
|---|---|---|---|
| 5.4 — Worker participation | Policy existed, undated | Inconsistent across crews | Standardized participation protocol, field-tested |
| 6.1.2 — Hazard identification | Generic, site-wide JSA template | Crews improvised site-specific hazards | JSA template rebuilt per site class, crew-validated |
| 8.1 — Operational control (permit-to-work) | Sequence did not match practice | Steps reordered informally by crews | Procedure rewritten to the verified safe sequence |
| 9.2 — Internal audit | No standing internal audit function | No independent verification cycle | Internal audit team recruited and trained |
Following the rebuild, Synergy Nexus ran an internal mock audit — structured identically to the certification body's Stage 1 (documentation review) and Stage 2 (on-site implementation) audits — to pressure-test the system before the real certification audit rather than during it.
The Deterministic Outcome
| Audit stage | Result |
|---|---|
| Stage 1 — documentation review | Zero major nonconformities; two minor observations resolved before Stage 2 was scheduled |
| Stage 2 — on-site implementation audit | Zero nonconformities of any classification; certification granted |
| Documentation set | Reduced by approximately one-third — procedures without corresponding field practice were retired, not merely revised |
| Internal audit capability | A trained internal team now runs the Clause 9.2 audit cycle independently ahead of each scheduled surveillance audit |
Certification under ISO 45001 is granted following Stage 1 and Stage 2 audits and holds for a three-year cycle, subject to annual surveillance audits confirming the system remains in force as certified. The operator enters its first surveillance audit, twelve months out, with the same field-verified system that passed Stage 2 — not a system re-papered for the audit and left to drift again afterward.
Strategic Takeaways
- Audit readiness is not documentation completeness — it is the demonstrated correspondence between what is written and what a crew actually does, which is precisely what a Stage 2 auditor tests by asking to see the work, not just read the procedure.
- A smaller, field-verified documentation set outperforms a larger, unverified one under audit: fewer procedures with total fidelity beat a comprehensive library an auditor can sample-test and find drifting from practice.
- Building an internal Clause 9.2 audit capability before certification, not after, converts the first surveillance audit from a fresh compliance event into a confirmation of a control the organization is already running on itself.
Achieved ISO 45001 certification through the Stage 1 and Stage 2 audits with zero nonconformities, resolving field-practice gaps that would otherwise have surfaced as findings under review
Reduced the safety documentation set by approximately one-third, eliminating procedures without corresponding field practice
Trained an internal audit team to sustain ongoing compliance, embedding audit-readiness into standing operational governance ahead of the first surveillance cycle
Facing a comparable challenge?
Tell us about your organization and we will route you to the right partner.
Engineering Contractor HSE Prequalification and Monitoring
Read case study →Repositioning Safety Culture Beyond Compliance Metrics
Read case study →Rebuilding Emergency Response After a Well Control Incident
Read case study →Closing the Gap Between Documented and Actual Process Safety
Read case study →Engineering Barrier Management Across Aging Grid Assets
Read case study →Process Safety and Asset Integrity Beyond the Checklist
Documentation and hazard control are structurally distinct disciplines; treating them as equivalent is where major-accident risk accumulates.
Contractor Safety Management for an Outsourced Workforce
Subcontractor safety performance becomes the principal's liability the moment work begins on a shared site.
Why Safety Culture Metrics Can Mislead Leadership
A declining incident rate is equally consistent with genuine safety improvement and with a workforce that has stopped reporting.









