Most SMEs don’t ignore health & safety on purpose. They’re busy, short-staffed, and juggling customers, cashflow, and delivery. So H&S becomes a folder of templates, a few risk assessments, and a hope that nothing goes wrong.
Then one of these happens:
- An incident or near miss that exposes gaps
- A client asks for proof of competence, training, and controls
- A tender requires a recognised health & safety management system
- An audit (or site inspection) turns into a panic
ISO 45001 is the standard that helps you get control of all of that without turning your business into a paperwork factory.
This is the plain-English version of what ISO 45001 actually does, what typically goes wrong in SMEs, and what you can fix this week to become audit-ready in a practical way.

What ISO 45001 really is
ISO 45001 is a health & safety management system. Not a badge. Not a stack of policies.
It’s a simple way to prove you can:
- Identify hazards and risks properly (not just copy/paste)
- Put sensible controls in place
- Train people for the work they actually do
- Record incidents and learn from them
- Check the system works (internal audits, reviews, actions)
- Improve over time (so issues don’t keep repeating)
If ISO 9001 is how you run the business consistently, ISO 45001 is how you keep people safe consistently.
The 7 most common ISO 45001 gaps we see in SMEs
Most failures come down to evidence and consistency, not effort.
1) Risk assessments exist, but they’re generic
- Not task-specific
- Not reviewed when things change
- Controls listed, but not implemented or checked
2) Training records are messy or meaningless
- Attendance sheets, but no competence checks
- No link between role and required training
- Subcontractor competence not evidenced
3) Incidents are under-reported
- Near misses not logged
- We dealt with it on the day but nothing recorded
- No trend analysis, so the same issues repeat
4) Contractor and supplier controls are weak
- RAMS collected but not reviewed
- Insurance and competence not monitored
- No clear rules for onboarding and re-approval
5) H&S responsibilities are unclear
- Everyone is responsible, so no one is accountable
- No clear escalation route
- Actions get agreed verbally and then disappear
6) Legal compliance is assumed
- No simple register of applicable H&S requirements
- No evidence of periodic checks/updates
- No proof that changes are communicated
7) The system isn’t checked
- No internal audits (or they’re tick-box)
- No management review
- Corrective actions aren’t tracked to completion
What good looks like a simple ISO 45001 checklist
You don’t need a corporate H&S department. You need a system that’s easy to run.
A solid SME-ready ISO 45001 setup usually includes:
- Scope: what parts of the business the system covers
- H&S policy: short, real, and relevant
- Hazard identification + risk assessment process: how you do it, how often you review it
- Operational controls: what you do to prevent harm (PPE, permits, supervision, maintenance, etc.)
- Competence & training: role-based requirements + records
- Communication: how you brief staff, toolbox talks, updates, contractor comms
- Incident management: reporting, investigation, corrective action
- Emergency preparedness: what you do if things go wrong
- Monitoring & measurement: simple KPIs (not 50 spreadsheets)
- Internal audits + management review: how you check and improve
- Corrective actions: tracked, owned, closed, verified
A practical 7-day starter plan
Day 1: Pick 5 high-risk activities and make the risk assessments real
- List your top 5 tasks where someone could realistically get hurt
- Update each risk assessment to include: Who is exposed (staff, contractors, public), What could go wrong (specific hazards), Current controls (what you actually do), What needs improving (actions + owner + date)
Day 2: Build a simple competence matrix
For each role, define:
- Required training (e.g., manual handling, first aid, site induction)
- Required competence evidence (tickets, experience, supervision sign-off)
- Refresher frequency
Day 3: Fix incident reporting
Set a rule: All incidents and near misses are logged within 24 hours. Keep the form simple:
- What happened
- Why it happened (best guess)
- Immediate action taken
- What we’ll change to stop it repeating
Day 4: Sort contractor onboarding
Create a basic checklist:
- Insurance
- Competence evidence
- RAMS review (and who approves it)
- Site induction record
- Ongoing monitoring (re-approval dates)
Day 5: Create a legal compliance list
- List the key H&S requirements that apply to your work
- Set a monthly or quarterly review
- Record checked / changes / actions
Day 6: Put 3 simple H&S KPIs in place
Examples that work well in SMEs:
- Number of near misses reported (you want this to rise initially)
- Corrective actions overdue (you want this at zero)
- Training compliance % by role
Day 7: Do a 30-minute management review
Agenda:
- Incidents/near misses trends
- Actions status
- Training gaps
- Any changes (new sites, new services, new equipment)
- What to improve next month
Why ISO 45001 helps you win work (not just be safe)
For many SMEs, ISO 45001 becomes a commercial advantage because it proves:
- You’re controlled and consistent
- You manage risk properly
- You’re less likely to cause disruption on client sites
- You take competence and supervision seriously
Why CAW
- 100% pass rate across all standards and certification bodies (including UKAS)
- Fastest turnaround in the country
- At least 50% cheaper than other UK consultancies
- ISO consultancy package price: £999
Get ISO 45001 without the panic
If you want ISO 45001 without months of back-and-forth, message us. We build it in a way that fits how you actually operate plain-English, no jargon, easy to run, and audit-ready.
CAW Consultancy | craig@cawconsultancy.co.uk | 01257 824481

Leave a comment