ISO 45001 IMPLEMENTATION · Saudi Arabia

How to Implement ISO 45001 in Saudi Arabia — A Practical Guide for HSE Managers

ISO 45001 implementation is a project that most Saudi HSE managers have heard about but fewer have led through to successful certification. The gap between knowing the standard and building a system that survives a Stage 2 audit and three years of surveillance is significant. This guide covers the full implementation sequence — from initial gap analysis to certification — with a focus on the Saudi context: the hazards, the regulatory requirements, and the Aramco supply chain expectations that shape how the standard applies here.

PITC KSA has supported over 940 Saudi corporate clients through safety management system journeys. With TVTC-accredited ISO 45001 training in Riyadh, Jeddah, Dammam, and Jubail, our courses are built around the implementation questions that Saudi HSE managers actually face.

Phase 1: Gap Analysis — Understand Where You Are Starting From

Before you write a single procedure or attend a single training course, you need an honest assessment of your current position. The gap analysis compares your existing safety management practices against every clause of ISO 45001:2018 and categorises each element as: fully implemented, partially implemented, or not implemented.

For Saudi companies, the gap analysis should specifically assess:

Clause 4 (Context): Have you formally documented the internal and external issues affecting worker safety? For a Saudi construction company, this includes working in extreme heat, the demographics of your workforce (often a high proportion of migrant workers with language barriers), and the specific Saudi regulatory requirements under the Labour Law and MHRSD guidelines.

Clause 5 (Leadership): Does top management actively participate in the OH&S management system, or has it been entirely delegated to the HSE department? ISO 45001 requires demonstrable leadership commitment — management review, resource allocation, and visible safety leadership on site.

Clause 6 (Planning): Do you have a systematic hazard identification process that covers all your activities? In Saudi Arabia, this must specifically address heat stress, H2S exposure, confined space entry, working at height, and fire risk in the context of your specific operations.

Clause 9 (Performance evaluation): Do you have a planned internal audit programme and a formal management review process? These are the areas where most Saudi companies have the largest gaps because they require structured, documented processes rather than informal oversight.

Phase 2

Documentation: What ISO 45001 Actually Requires You to Write

One of the most common misconceptions about ISO 45001 is that it requires a library of procedures. In practice, the standard requires you to have documented information where it is needed to support the operation of the management system. Four core documents are needed at minimum:

OH&S Policy

A brief, specific statement of top management’s commitment to worker safety and continual improvement. It must reference compliance with applicable legal requirements and be communicated to all workers. Avoid generic corporate language — auditors look for a policy that is clearly written for your specific operations.

Hazard Register and Risk Assessment

A documented register of all significant hazards in your operations, with risk assessments covering the likelihood and severity of harm, existing controls, and the residual risk after controls. In Saudi Arabia, heat stress and H2S exposure must appear in virtually every industrial company’s hazard register. Update when operations or work environments change.

OH&S Objectives and Action Plans

Measurable targets aligned with your OH&S policy, with documented action plans showing how they will be achieved. Examples: reduce lost-time injury frequency rate by fifteen percent, achieve one hundred percent completion of planned toolbox talks, complete training gap closure for all safety-critical roles by Q3.

Documented Procedures

The specific procedures required by ISO 45001 include: hazard identification, risk assessment, legal compliance evaluation, emergency response, incident investigation, corrective action, internal audit, management review, and worker participation. These do not need to be complex — clear, practical procedures that your workforce actually uses are more valuable than comprehensive manuals that no one reads.

Phase 3: Training — Build the Internal Competence Your System Needs

ISO 45001 requires that people doing work affecting OH&S performance are competent. But competence is not just about attending a course — it means having the education, training, or experience to perform the task safely. For the implementation team, this means two specific roles need to be filled by trained individuals.

Lead Auditor: At least one person in your organisation needs to be competent to plan and conduct ISO 45001 internal audits, write nonconformance findings, verify corrective action effectiveness, and liaise with the certification body. PITC KSA’s ISO 45001 Lead Auditor course in Jubail and our national programmes deliver this competence in a five-day intensive format recognised by TVTC.

HSE Manager or Coordinator: The person responsible for day-to-day system maintenance needs to understand all ten clauses and how they apply to your operations. They will manage the hazard register, track OH&S objectives, coordinate the internal audit programme, prepare for management review, and be the primary contact for the certification body.

Worker awareness training is also required — all workers need to understand the OH&S policy, their contribution to the OH&S management system, and what to do in an emergency. For Saudi companies with a multilingual workforce, this training must be delivered in appropriate languages, which is a practical implementation challenge that needs to be planned for early.

Phase 4 and 5: Internal Audits and Management Review

These two processes are where many Saudi ISO 45001 implementations fall apart. Internal audits need to be planned across the full scope of the management system — not just the easy areas — and auditors need to raise real findings rather than green-washing the system. Certification body auditors are experienced at identifying rubber-stamp audit programmes, and they will probe heavily if internal audit findings are uniformly minor.

Management review must cover a defined set of inputs: OH&S performance data, audit results, legal compliance status, incident statistics, achievement of objectives, and risks and opportunities. The outputs must include decisions — particularly decisions about resource allocation and changes to the system. Minutes that record the meeting happened but show no decisions being made will be flagged as a major nonconformance at Stage 2.

PITC KSA’s ISO 45001 training includes practical management review simulation exercises. We also offer audit support services where a PITC KSA certified lead auditor conducts a pre-certification readiness assessment of your system before you engage the certification body — identifying gaps before they become Stage 1 findings.

Phase 6: Certification Audits — What to Expect at Stage 1 and Stage 2

The Stage 1 audit typically takes one to two days at your site. The auditor reviews your documented information — policy, hazard register, objectives, procedures, audit records, management review minutes — and conducts an on-site review to confirm your scope is appropriate. Stage 1 generates a list of observations and any major nonconformances that must be closed before Stage 2 can proceed.

Plan for a gap of two to six weeks between Stage 1 and Stage 2. Use this time to close any Stage 1 findings, complete any documentation gaps, and brief your team on what auditors will ask during Stage 2 interviews. Brief every person the auditor is likely to speak to: supervisors, safety officers, and team leaders should all be able to explain how hazard identification works on their site, what they do if they identify a new hazard, and where to find the emergency response procedure.

Stage 2 lasts two to five days depending on company size and scope. Auditors will sample records, conduct worker interviews, walk the site, and check that your documented system is operating as described. After Stage 2, the auditor raises a report. Major nonconformances must be closed before the certificate is issued. Minor nonconformances are typically closed at the first surveillance audit. Your certificate is then valid for three years, with annual surveillance audits in years two and three.

For companies combining ISO 45001 with ISO 9001 or ISO 14001 in an Integrated Management System, Stage 1 and Stage 2 audits are conducted simultaneously for all standards, reducing total audit days and cost significantly.

Common Questions

Frequently Asked Questions: Implementing ISO 45001 in Saudi Arabia

Where do you start when implementing ISO 45001 in Saudi Arabia?

Start with a gap analysis. Compare your current safety management practices against the requirements of ISO 45001:2018 clause by clause. Identify what is already in place, what is partially implemented, and what is completely missing. Most Saudi companies find that clauses 7 (Support), 8 (Operation), and 9 (Performance evaluation) have the most gaps because they require documented processes and formal audit programmes that many organisations have not formalised.

How long does ISO 45001 implementation take in Saudi Arabia?

Six to eighteen months depending on your starting position. Companies that already have OHSAS 18001 or a robust internal safety management system can typically transition to ISO 45001 in four to six months. Companies starting from scratch need twelve to eighteen months to build adequate system maturity before a Stage 2 certification audit. Rushing the process produces a fragile system that fails at the first surveillance audit.

Do we need an external consultant to implement ISO 45001 in Saudi Arabia?

Not necessarily. Companies that invest in training their own staff through an ISO 45001 Lead Auditor course can handle gap analysis, procedure writing, and internal audits in-house. This is significantly cheaper than external consultancy over a three-year certification cycle and builds permanent internal competence. PITC KSA’s lead auditor courses are specifically designed to equip Saudi HSE professionals with full implementation competence, not just auditing skills.

What is the difference between ISO 45001 Stage 1 and Stage 2 audits?

The Stage 1 audit is a document review — the certification body visits to check that you have the required documented information in place and that you understand the requirements. Stage 1 typically lasts one to two days and identifies any major gaps that must be addressed before Stage 2. The Stage 2 audit is the full certification audit where auditors verify that your system is operational — they interview staff, review records, and check that documented procedures are actually being followed. Both nonconformances from Stage 1 must be closed before Stage 2 proceeds.

What are the most common reasons Saudi companies fail their ISO 45001 Stage 2 audit?

The five most common reasons are: 1) internal audits were conducted but nonconformances were not properly closed out; 2) management review was held but no decisions or actions were recorded; 3) hazard identification did not cover all significant hazards for the specific Saudi context (heat stress, H2S, confined spaces); 4) worker participation in hazard identification was documented on paper but not evidenced in practice; 5) competency records for safety-critical roles were incomplete or out of date.

Can we implement ISO 45001 for just one site in Saudi Arabia?

Yes. ISO 45001 certification can be scoped to a single site, a department, or a specific range of activities. The scope statement on the certificate must accurately reflect what is included. Many Saudi companies start with one site or their Jubail/Dammam operations and expand the scope at recertification. The risk is that clients may require the scope to cover the site where their work takes place, so define scope carefully against your key tender requirements from the start.

References

Implementation timelines and audit processes described are based on general ISO 45001 practice. Specific requirements vary by certification body, company size, and scope. Always verify with your chosen certification body.

Start Your Implementation

Implement ISO 45001 Right with PITC KSA Training

PITC KSA’s TVTC-accredited ISO 45001 Lead Auditor and awareness courses are designed for Saudi HSE managers who need to build a real system, not just pass a knowledge test. Delivered in Riyadh, Jeddah, Dammam, and Jubail, our courses cover the Saudi regulatory context, heat and H2S hazard management, and the internal audit skills needed to maintain your system through surveillance audits. With 9 years of in-Kingdom experience and over 1,350 professionals trained, PITC KSA is the practical choice for ISO 45001 implementation training.

Latest Posts

Contact Us

9 + 8 =