Most SMEs don’t ignore health and safety on purpose. They’re busy, short-staffed, and juggling customers, cashflow, and delivery. So H&S becomes a folder of templates, a few risk assessments, and a hope that nothing goes wrong.

Then one of these happens:

  • An incident or near miss that exposes gaps
  • A client asks for proof of competence, training, and controls
  • A tender requires a recognised health and safety management system
  • An audit (or site inspection) turns into a panic

ISO 45001 is the standard that helps you get control of all of that — without turning your business into a paperwork factory.

This is the plain-English version of what ISO 45001 actually does, what typically goes wrong in SMEs, and what you can fix this week to become “audit-ready” in a practical way.

What ISO 45001 really is

ISO 45001 is a health and safety management system. Not a badge. Not a stack of policies. It’s a simple way to prove you can:

  • Identify hazards and risks properly (not just copy/paste)
  • Put sensible controls in place
  • Train people for the work they actually do
  • Record incidents and learn from them
  • Check the system works (internal audits, reviews, actions)
  • Improve over time (so issues don’t keep repeating)

If ISO 9001 is “how you run the business consistently,” ISO 45001 is “how you keep people safe consistently.”

The 7 most common ISO 45001 gaps we see in SMEs

Most failures come down to evidence and consistency, not effort.

1) Risk assessments exist, but they’re generic

  • Not task-specific
  • Not reviewed when things change
  • Controls listed, but not implemented or checked

2) Training records are messy or meaningless

  • Attendance sheets, but no competence checks
  • No link between role and required training
  • Subcontractor competence not evidenced

3) Incidents are under-reported

  • Near misses not logged
  • “We dealt with it on the day” but nothing recorded
  • No trend analysis, so the same issues repeat

4) Contractor and supplier controls are weak

  • RAMS collected but not reviewed
  • Insurance and competence not monitored
  • No clear rules for onboarding and re-approval

5) H&S responsibilities are unclear

  • Everyone is “responsible,” so no one is accountable
  • No clear escalation route
  • Actions get agreed verbally and then disappear

6) Legal compliance is assumed

  • No simple register of applicable H&S requirements
  • No evidence of periodic checks/updates
  • No proof that changes are communicated

7) The system isn’t checked

  • No internal audits (or they’re tick-box)
  • No management review
  • Corrective actions aren’t tracked to completion

What “good” looks like — a simple ISO 45001 checklist

You don’t need a corporate H&S department. You need a system that’s easy to run.

A solid SME-ready ISO 45001 setup usually includes:

  • Scope: what parts of the business the system covers
  • H&S policy: short, real, and relevant
  • Hazard identification + risk assessment process: how you do it, how often you review it
  • Operational controls: what you do to prevent harm (PPE, permits, supervision, maintenance, etc.)
  • Competence and training: role-based requirements + records
  • Communication: how you brief staff, toolbox talks, updates, contractor comms
  • Incident management: reporting, investigation, corrective action
  • Emergency preparedness: what you do if things go wrong
  • Monitoring and measurement: simple KPIs (not 50 spreadsheets)
  • Internal audits + management review: how you check and improve
  • Corrective actions: tracked, owned, closed, verified

How long does ISO 45001 take?

At CAW:

  • systems can be built within 48 hours
  • typically delivered in 72 hours

Certification timing depends on the certification body’s audit schedule, but the system build and prep doesn’t need to drag on.

Why CAW

  • 100% pass rate across all standards and certification bodies (including UKAS)
  • fastest turnaround in the country
  • at least 50% cheaper than other UK consultancies
  • ISO consultancy package price: £999

Ready to get ISO 45001 done right?

If you want a health and safety system that’s practical, auditable, and actually usable on the ground, message us at craig@cawconsultancy.co.uk.

We’ll tell you exactly what you need (and what you don’t), then get you audit-ready fast.

Leave a comment

I’m Craig

Meet Craig Willetts

Welcome to the ISO and Compliance Blog, I have spent over 20 years in compliance specialising in accreditation and business growth, I own a number of compliance related businesses including CAW Consultancy, Global ISO Services, CAW Digital, Screen my staff and fusion consultancy worldwide and this blog is designed to help SME’s on their journey to top notch compliance, any questions feel free to drop me an email at Craig@CAWConsultancy.co.uk

Let’s connect