Most SMEs don’t ignore health & safety on purpose. They’re busy, short-staffed, and juggling customers, cashflow, and delivery. So H&S becomes a folder of templates, a few risk assessments, and a hope that nothing goes wrong.
Then one of these happens:
– An incident or near miss that exposes gaps
– A client asks for proof of competence, training, and controls
– A tender requires a recognised health & safety management system
– An audit (or site inspection) turns into a panic
ISO 45001 is the standard that helps you get control of all of that — without turning your business into a paperwork factory.
This is the plain-English version of what ISO 45001 actually does, what typically goes wrong in SMEs, and what you can fix this week to become “audit-ready” in a practical way.
## What ISO 45001 really is
ISO 45001 is a health & safety management system. Not a badge. Not a stack of policies.
It’s a simple way to prove you can:
– Identify hazards and risks properly (not just copy/paste)
– Put sensible controls in place
– Train people for the work they actually do
– Record incidents and learn from them
– Check the system works (internal audits, reviews, actions)
– Improve over time (so issues don’t keep repeating)
If ISO 9001 is “how you run the business consistently,” ISO 45001 is “how you keep people safe consistently.”
## The 7 most common ISO 45001 gaps we see in SMEs
Most failures come down to evidence and consistency, not effort.
### 1) Risk assessments exist, but they’re generic
– Not task-specific
– Not reviewed when things change
– Controls listed, but not implemented or checked
### 2) Training records are messy or meaningless
– Attendance sheets, but no competence checks
– No link between role and required training
– Subcontractor competence not evidenced
### 3) Incidents are under-reported
– Near misses not logged
– “We dealt with it on the day” but nothing recorded
– No trend analysis, so the same issues repeat
### 4) Contractor and supplier controls are weak
– RAMS collected but not reviewed
– Insurance and competence not monitored
– No clear rules for onboarding and re-approval
### 5) H&S responsibilities are unclear
– Everyone is “responsible,” so no one is accountable
– No clear escalation route
– Actions get agreed verbally and then disappear
### 6) Legal compliance is assumed
– No simple register of applicable H&S requirements
– No evidence of periodic checks/updates
– No proof that changes are communicated
### 7) The system isn’t checked
– No internal audits (or they’re tick-box)
– No management review
– Corrective actions aren’t tracked to completion
## What “good” looks like — a simple ISO 45001 checklist
You don’t need a corporate H&S department. You need a system that’s easy to run.
A solid SME-ready ISO 45001 setup usually includes:
– Scope: what parts of the business the system covers
– H&S policy: short, real, and relevant
– Hazard identification + risk assessment process: how you do it, how often you review it
– Operational controls: what you do to prevent harm (PPE, permits, supervision, maintenance, etc.)
– Competence & training: role-based requirements + records
– Communication: how you brief staff, toolbox talks, updates, contractor comms
– Incident management: reporting, investigation, corrective action
– Emergency preparedness: what you do if things go wrong
– Monitoring & measurement: simple KPIs (not 50 spreadsheets)
– Internal audits + management review: how you check and improve
– Corrective actions: tracked, owned, closed, verified
## A practical 7-day starter plan
**Day 1: Pick 5 high-risk activities and make the risk assessments real**
– List your top 5 tasks where someone could realistically get hurt
– Update each risk assessment to include:
– Who is exposed (staff, contractors, public)
– What could go wrong (specific hazards)
– Current controls (what you actually do)
– What needs improving (actions + owner + date)
**Day 2: Build a simple competence matrix**
For each role, define:
– Required training (e.g., manual handling, first aid, site induction)
– Required competence evidence (tickets, experience, supervision sign-off)
– Refresher frequency
**Day 3: Fix incident reporting**
Set a rule:
– All incidents and near misses are logged within 24 hours
– Keep the form simple:
– What happened
– Why it happened (best guess)
– Immediate action taken
– What we’ll change to stop it repeating
**Day 4: Sort contractor onboarding**
Create a basic checklist:
– Insurance
– Competence evidence
– RAMS review (and who approves it)
– Site induction record
– Ongoing monitoring (re-approval dates)
**Day 5: Create a legal compliance list**
– List the key H&S requirements that apply to your work
– Set a monthly or quarterly review
– Record “checked / changes / actions”
**Day 6: Put 3 simple H&S KPIs in place**
Examples that work well in SMEs:
– Number of near misses reported (you want this to rise initially)
– Corrective actions overdue (you want this at zero)
– Training compliance % by role
**Day 7: Do a 30-minute management review**
Agenda:
– Incidents/near misses trends
– Actions status
– Training gaps
– Any changes (new sites, new services, new equipment)
– What to improve next month
## Why ISO 45001 helps you win work (not just “be safe”)
For many SMEs, ISO 45001 becomes a commercial advantage because it proves:
– You’re controlled and consistent
– You manage risk properly
– You’re less likely to cause disruption on client sites
– You take competence and supervision seriously
## Why CAW
– 100% pass rate across all standards and certification bodies (including UKAS)
– fastest turnaround in the country
– at least 50% cheaper than other UK consultancies
– ISO consultancy package price: £999
## CTA
If you want ISO 45001 without months of back-and-forth, message us. We build it in a way that fits how you actually operate — plain-English, no jargon, easy to run, and audit-ready.

Leave a comment