Planning Actions to Address OH&S Risks Under ISO 45001

ISO 45001 Clause 6.1.4

Plan the actions that flow from hazards, risks, legal requirements and emergencies - and how to evaluate them.

ISO 45001 Clause 6.1.4 - Planning Action

ISO 45001:2018 Clause 6.1.4 takes the outputs from earlier sub-clauses - hazards and risks identified at Clause 6.1.2, legal and other requirements at Clause 6.1.3, and the potential emergency situations - and turns them into planned actions. The clause asks the organisation to plan how those actions will be integrated into the OH&S management system or other business processes, and how their effectiveness will be evaluated.

When planning actions the organisation considers the hierarchy of controls established at Clause 8.1.2, the outputs from the OH&S management system itself, best practices, technological options, and financial, business and operational requirements. In other words, the organisation chooses controls that are sensible in context, not the most expensive option for its own sake.

How Planning Action Works in Practice

For most organisations the planning happens through an actions or improvement register. Each significant risk, legal requirement or emergency response need is recorded as an action with a clear owner, a target date, the resources needed and a way to check whether the action has been effective. The register links back to the source - the risk assessment, the legal register entry or the emergency response plan - so the rationale is traceable.

The actions are then integrated into normal business activity. A health and safety improvement is not run as a separate project that ends when the box is ticked. It becomes part of the way the organisation works, with the new control built into procedures, training and routine checks. Effectiveness is evaluated through monitoring and measurement under Clause 9.1 - the action register entry stays open until there is evidence the control is working.

This clause does not say any particular document must be retained, but in practice an actions register is the easiest way to comply. A simple table tracking the action, the source, the owner, the target date, the status and the evidence of effectiveness covers the requirement and gives the organisation visibility of what is in flight.

The trap to avoid is treating actions as a one-off list. Things move on, controls weaken, new risks emerge. The actions register is a working tool, not a one-shot document.

I look at the actions register at most audits. I want to see actions linked to a clear source - a specific risk assessment, a legal register entry, an audit finding. I want owners and dates. And I want evidence the actions have been evaluated, not just marked closed because the date passed.

Practical Compliance Guidance

The IMS1 Manual sets out how planned actions are recorded and tracked. The actions register is the central evidence for this clause.

The following alphaZ documents support compliance with ISO 45001:2018 Clause 6.1.4.

alphaZ document How to use it
ISO 45001 Toolkit The full set of documents needed to build an OH&S management system that meets ISO 45001:2018.
ER1 Issues and Actions Register Records actions arising from risks, legal requirements, audits and incidents. Use to track owners, dates, status and effectiveness of each action.
ER14 Hazard Risk Assessment Register Lists the organisation's risk assessments. Use as the index for risk-driven actions and to track which assessments are current.
ER18 Accident Statistics Records accident and incident data. Trends in this register often drive new planned actions to address recurring causes.

Note - all the above files can be downloaded with an alphaZ subscription.

Frequently Asked Questions

The standard does not require a specific actions register, but it does require the organisation to plan actions and to evaluate their effectiveness. In practice, an actions register is the simplest way to evidence both. Without one, an auditor will have to look across multiple sources to confirm actions have been planned and tracked.
Clause 6.1.4 covers planned actions arising from risks, requirements and emergency planning. Corrective action under Clause 10.2 covers reactive actions that follow incidents and nonconformities. Many organisations use the same register for both, with a category field to distinguish them.
It means checking the action achieved what it was supposed to. If the action was to reduce manual handling injuries through new lifting aids, effectiveness is evaluated through subsequent injury data and worker feedback. Marking the action closed because the equipment was bought is not enough.

UK Legislation

Clause 6.1.4 is a planning clause that does not map to specific legislation, but the broader UK statutory framework establishes the duty to act on identified risks. Organisations outside the UK should identify equivalent legislation in their jurisdiction.

Further Resources

payment logos