Planning Actions to Address OH&S Risks Under ISO 45001
ISO 45001 Clause 6.1.4
Plan the actions that flow from hazards, risks, legal requirements and emergencies - and how to evaluate them.
ISO 45001 Clause 6.1.4 - Planning Action
ISO 45001:2018 Clause 6.1.4 takes the outputs from earlier sub-clauses - hazards and risks identified at Clause 6.1.2, legal and other requirements at Clause 6.1.3, and the potential emergency situations - and turns them into planned actions. The clause asks the organisation to plan how those actions will be integrated into the OH&S management system or other business processes, and how their effectiveness will be evaluated.
When planning actions the organisation considers the hierarchy of controls established at Clause 8.1.2, the outputs from the OH&S management system itself, best practices, technological options, and financial, business and operational requirements. In other words, the organisation chooses controls that are sensible in context, not the most expensive option for its own sake.
How Planning Action Works in Practice
For most organisations the planning happens through an actions or improvement register. Each significant risk, legal requirement or emergency response need is recorded as an action with a clear owner, a target date, the resources needed and a way to check whether the action has been effective. The register links back to the source - the risk assessment, the legal register entry or the emergency response plan - so the rationale is traceable.
The actions are then integrated into normal business activity. A health and safety improvement is not run as a separate project that ends when the box is ticked. It becomes part of the way the organisation works, with the new control built into procedures, training and routine checks. Effectiveness is evaluated through monitoring and measurement under Clause 9.1 - the action register entry stays open until there is evidence the control is working.
This clause does not say any particular document must be retained, but in practice an actions register is the easiest way to comply. A simple table tracking the action, the source, the owner, the target date, the status and the evidence of effectiveness covers the requirement and gives the organisation visibility of what is in flight.
The trap to avoid is treating actions as a one-off list. Things move on, controls weaken, new risks emerge. The actions register is a working tool, not a one-shot document.
I look at the actions register at most audits. I want to see actions linked to a clear source - a specific risk assessment, a legal register entry, an audit finding. I want owners and dates. And I want evidence the actions have been evaluated, not just marked closed because the date passed.
Practical Compliance Guidance
The IMS1 Manual sets out how planned actions are recorded and tracked. The actions register is the central evidence for this clause.
The following alphaZ documents support compliance with ISO 45001:2018 Clause 6.1.4.
| alphaZ document | How to use it |
|---|---|
| ISO 45001 Toolkit | The full set of documents needed to build an OH&S management system that meets ISO 45001:2018. |
| ER1 Issues and Actions Register | Records actions arising from risks, legal requirements, audits and incidents. Use to track owners, dates, status and effectiveness of each action. |
| ER14 Hazard Risk Assessment Register | Lists the organisation's risk assessments. Use as the index for risk-driven actions and to track which assessments are current. |
| ER18 Accident Statistics | Records accident and incident data. Trends in this register often drive new planned actions to address recurring causes. |
Note - all the above files can be downloaded with an alphaZ subscription.
Frequently Asked Questions
UK Legislation
Clause 6.1.4 is a planning clause that does not map to specific legislation, but the broader UK statutory framework establishes the duty to act on identified risks. Organisations outside the UK should identify equivalent legislation in their jurisdiction.
