Most SMEs don’t ignore health and safety on purpose. They’re busy, short-staffed, and juggling customers, cashflow, and delivery. So H&S becomes a folder of templates, a few risk assessments, and a hope that nothing goes wrong.
Then one of these happens:
- An incident or near miss that exposes gaps
- A client asks for proof of competence, training, and controls
- A tender requires a recognised health and safety management system
- An audit (or site inspection) turns into a panic
ISO 45001 is the standard that helps you get control of all of that — without turning your business into a paperwork factory.
This is the plain-English version of what ISO 45001 actually does, what typically goes wrong in SMEs, and what you can fix this week to become “audit-ready” in a practical way.
What ISO 45001 really is
ISO 45001 is a health and safety management system. Not a badge. Not a stack of policies. It’s a simple way to prove you can:
- Identify hazards and risks properly (not just copy/paste)
- Put sensible controls in place
- Train people for the work they actually do
- Record incidents and learn from them
- Check the system works (internal audits, reviews, actions)
- Improve over time (so issues don’t keep repeating)
If ISO 9001 is “how you run the business consistently,” ISO 45001 is “how you keep people safe consistently.”
The 7 most common ISO 45001 gaps we see in SMEs
Most failures come down to evidence and consistency, not effort.
1) Risk assessments exist, but they’re generic
- Not task-specific
- Not reviewed when things change
- Controls listed, but not implemented or checked
2) Training records are messy or meaningless
- Attendance sheets, but no competence checks
- No link between role and required training
- Subcontractor competence not evidenced
3) Incidents are under-reported
- Near misses not logged
- “We dealt with it on the day” but nothing recorded
- No trend analysis, so the same issues repeat
4) Contractor and supplier controls are weak
- RAMS collected but not reviewed
- Insurance and competence not monitored
- No clear rules for onboarding and re-approval
5) H&S responsibilities are unclear
- Everyone is “responsible,” so no one is accountable
- No clear escalation route
- Actions get agreed verbally and then disappear
6) Legal compliance is assumed
- No simple register of applicable H&S requirements
- No evidence of periodic checks/updates
- No proof that changes are communicated
7) The system isn’t checked
- No internal audits (or they’re tick-box)
- No management review
- Corrective actions aren’t tracked to completion
What “good” looks like — a simple ISO 45001 checklist
You don’t need a corporate H&S department. You need a system that’s easy to run.
A solid SME-ready ISO 45001 setup usually includes:
- Scope: what parts of the business the system covers
- H&S policy: short, real, and relevant
- Hazard identification + risk assessment process: how you do it, how often you review it
- Operational controls: what you do to prevent harm (PPE, permits, supervision, maintenance, etc.)
- Competence and training: role-based requirements + records
- Communication: how you brief staff, toolbox talks, updates, contractor comms
- Incident management: reporting, investigation, corrective action
- Emergency preparedness: what you do if things go wrong
- Monitoring and measurement: simple KPIs (not 50 spreadsheets)
- Internal audits + management review: how you check and improve
- Corrective actions: tracked, owned, closed, verified
How long does ISO 45001 take?
At CAW:
- systems can be built within 48 hours
- typically delivered in 72 hours
Certification timing depends on the certification body’s audit schedule, but the system build and prep doesn’t need to drag on.
Why CAW
- 100% pass rate across all standards and certification bodies (including UKAS)
- fastest turnaround in the country
- at least 50% cheaper than other UK consultancies
- ISO consultancy package price: £999
Ready to get ISO 45001 done right?
If you want a health and safety system that’s practical, auditable, and actually usable on the ground, message us at craig@cawconsultancy.co.uk.
We’ll tell you exactly what you need (and what you don’t), then get you audit-ready fast.

Leave a comment