Most SMEs don’t ignore health & safety on purpose. They’re busy, short-staffed, and juggling customers, cashflow, and delivery. So H&S becomes a folder of templates, a few risk assessments, and a hope that nothing goes wrong.

Then one of these happens:

  • An incident or near miss that exposes gaps
  • A client asks for proof of competence, training, and controls
  • A tender requires a recognised health & safety management system
  • An audit (or site inspection) turns into a panic

ISO 45001 is the standard that helps you get control of all of that without turning your business into a paperwork factory.

This is the plain-English version of what ISO 45001 actually does, what typically goes wrong in SMEs, and what you can fix this week to become audit-ready in a practical way.

ISO 45001 Infographic

What ISO 45001 really is

ISO 45001 is a health & safety management system. Not a badge. Not a stack of policies.

It’s a simple way to prove you can:

  • Identify hazards and risks properly (not just copy/paste)
  • Put sensible controls in place
  • Train people for the work they actually do
  • Record incidents and learn from them
  • Check the system works (internal audits, reviews, actions)
  • Improve over time (so issues don’t keep repeating)

If ISO 9001 is how you run the business consistently, ISO 45001 is how you keep people safe consistently.

The 7 most common ISO 45001 gaps we see in SMEs

Most failures come down to evidence and consistency, not effort.

1) Risk assessments exist, but they’re generic

  • Not task-specific
  • Not reviewed when things change
  • Controls listed, but not implemented or checked

2) Training records are messy or meaningless

  • Attendance sheets, but no competence checks
  • No link between role and required training
  • Subcontractor competence not evidenced

3) Incidents are under-reported

  • Near misses not logged
  • We dealt with it on the day but nothing recorded
  • No trend analysis, so the same issues repeat

4) Contractor and supplier controls are weak

  • RAMS collected but not reviewed
  • Insurance and competence not monitored
  • No clear rules for onboarding and re-approval

5) H&S responsibilities are unclear

  • Everyone is responsible, so no one is accountable
  • No clear escalation route
  • Actions get agreed verbally and then disappear

6) Legal compliance is assumed

  • No simple register of applicable H&S requirements
  • No evidence of periodic checks/updates
  • No proof that changes are communicated

7) The system isn’t checked

  • No internal audits (or they’re tick-box)
  • No management review
  • Corrective actions aren’t tracked to completion

What good looks like a simple ISO 45001 checklist

You don’t need a corporate H&S department. You need a system that’s easy to run.

A solid SME-ready ISO 45001 setup usually includes:

  • Scope: what parts of the business the system covers
  • H&S policy: short, real, and relevant
  • Hazard identification + risk assessment process: how you do it, how often you review it
  • Operational controls: what you do to prevent harm (PPE, permits, supervision, maintenance, etc.)
  • Competence & training: role-based requirements + records
  • Communication: how you brief staff, toolbox talks, updates, contractor comms
  • Incident management: reporting, investigation, corrective action
  • Emergency preparedness: what you do if things go wrong
  • Monitoring & measurement: simple KPIs (not 50 spreadsheets)
  • Internal audits + management review: how you check and improve
  • Corrective actions: tracked, owned, closed, verified

A practical 7-day starter plan

Day 1: Pick 5 high-risk activities and make the risk assessments real

  • List your top 5 tasks where someone could realistically get hurt
  • Update each risk assessment to include: Who is exposed (staff, contractors, public), What could go wrong (specific hazards), Current controls (what you actually do), What needs improving (actions + owner + date)

Day 2: Build a simple competence matrix

For each role, define:

  • Required training (e.g., manual handling, first aid, site induction)
  • Required competence evidence (tickets, experience, supervision sign-off)
  • Refresher frequency

Day 3: Fix incident reporting

Set a rule: All incidents and near misses are logged within 24 hours. Keep the form simple:

  • What happened
  • Why it happened (best guess)
  • Immediate action taken
  • What we’ll change to stop it repeating

Day 4: Sort contractor onboarding

Create a basic checklist:

  • Insurance
  • Competence evidence
  • RAMS review (and who approves it)
  • Site induction record
  • Ongoing monitoring (re-approval dates)

Day 5: Create a legal compliance list

  • List the key H&S requirements that apply to your work
  • Set a monthly or quarterly review
  • Record checked / changes / actions

Day 6: Put 3 simple H&S KPIs in place

Examples that work well in SMEs:

  • Number of near misses reported (you want this to rise initially)
  • Corrective actions overdue (you want this at zero)
  • Training compliance % by role

Day 7: Do a 30-minute management review

Agenda:

  • Incidents/near misses trends
  • Actions status
  • Training gaps
  • Any changes (new sites, new services, new equipment)
  • What to improve next month

Why ISO 45001 helps you win work (not just be safe)

For many SMEs, ISO 45001 becomes a commercial advantage because it proves:

  • You’re controlled and consistent
  • You manage risk properly
  • You’re less likely to cause disruption on client sites
  • You take competence and supervision seriously

Why CAW

  • 100% pass rate across all standards and certification bodies (including UKAS)
  • Fastest turnaround in the country
  • At least 50% cheaper than other UK consultancies
  • ISO consultancy package price: £999

Get ISO 45001 without the panic

If you want ISO 45001 without months of back-and-forth, message us. We build it in a way that fits how you actually operate plain-English, no jargon, easy to run, and audit-ready.

CAW Consultancy | craig@cawconsultancy.co.uk | 01257 824481

Leave a comment

I’m Craig

Meet Craig Willetts

Welcome to the ISO and Compliance Blog, I have spent over 20 years in compliance specialising in accreditation and business growth, I own a number of compliance related businesses including CAW Consultancy, Global ISO Services, CAW Digital, Screen my staff and fusion consultancy worldwide and this blog is designed to help SME’s on their journey to top notch compliance, any questions feel free to drop me an email at Craig@CAWConsultancy.co.uk

Let’s connect