ISO 45001 OH&S Software

ISO 45001 compliance software, built by an auditor.

Run your full Occupational Health and Safety Management System in PICMS — hazard register, RIDDOR-aware incident command centre, legal register, training matrix, internal audits, management review. UK-built around HSE expectations.

Start 14-Day Trial Book a Demo

A working OH&S management system, evidenced

ISO 45001:2018 sits at the centre of UK construction, manufacturing, and service-sector tender packs. Auditors expect to see workers consulted, hazards identified and controlled, UK statutory law mapped, incidents handled with RIDDOR awareness, and a programme of continual improvement.

The audit conversation is fundamentally about three things: do you understand the OH&S risks workers face (hazard ID + assessment), do you know what UK law requires of you (Health and Safety at Work etc Act 1974, Management Regulations 1999, sector-specific regs), and can you prove you're actually controlling risks day-to-day (operational controls, incidents, drills, training records)?

Most UK SMEs come to 45001 with a hazard register from their first cert that hasn't been refreshed since the lockdown years, an incident book that lives in reception, RAMS produced for tenders but never reviewed in service, and a training matrix in someone's HR spreadsheet. The standard isn't asking for perfection — it's asking for a living system. PICMS makes that practical.

The clauses your auditor will reference

Clause 4 + 5.4

Context + worker consultation and participation

The 45001-specific addition: you must consult workers (not just managers) on the OH&S system. Auditors check the consultation mechanisms, the records, and what changed because of worker input.

Clause 6.1.2.1

Hazard identification

Ongoing identification — not a one-time exercise. Routine and non-routine activities, contractor work, emergencies, human factors, organisational change. Auditors test whether your hazard register reflects current operations or last year's snapshot.

Clause 6.1.2.2

Risk assessment

Risk evaluation methodology applied consistently. UK practice uses the 5×5 matrix (Likelihood × Severity); 45001 doesn't mandate it but auditors expect a defensible methodology with decision criteria.

Clause 6.1.3

Determination of legal and other requirements

UK statutory law (HSWA 1974, Management Regs 1999, COSHH 2002, CDM 2015 if applicable, Manual Handling Operations Regs, etc.), permit conditions, contractual H&S clauses, voluntary commitments. Must be current.

Clause 8.2

Emergency preparedness and response

Identified emergency situations. Response procedures. Drill records. Lessons learned feeding back into procedures. Periodic review.

Clause 10.2

Incident, nonconformity, corrective action

The incident-handling clause auditors care most about. Reporting, investigation (including root cause), corrective action, effectiveness verification. RIDDOR-reportable incidents must be flagged and notified to HSE within statutory deadlines.

Every ISO 45001 obligation, mapped to a working module

Hazard Register + Risk Guardian AI

Hazard ID with 5×5 inherent + residual scoring, control linkage, owner assignment. AI-assisted hazard suggestion based on activity descriptions.

RAMS Library

Risk Assessments + Method Statements drafted with project context, refined via supervisor textarea, sent to clients with PDF + audit log. Version-controlled.

Incident Command Centre

Voice-enabled on-site incident logging, 5-Whys investigation, automatic CAPA, RIDDOR-reportable flagging, evidence chain-of-custody.

Legal Register + Regulatory Feed

UK H&S legal register pre-loaded (HSWA, Management Regs, COSHH, CDM, etc.). Auto-bridges new HSE updates with severity scoring.

Training Matrix

Per-person competency matrix with expiry tracking. Inductions, toolbox talks, refresher courses. Matrix import from spreadsheet on day one.

Worker Consultation Records

Consultation events logged, attendees recorded, outcomes tracked. Evidence of clause 5.4 worker participation, audit-ready.

Internal Audit + Management Review

Audit programme, finding tracker, CAPA generation. Management review with the H&S-specific clause 9.3.2 inputs (incident statistics, audit findings, programme effectiveness, worker concerns).

Golden Thread

Hazard → control → RAMS → training → incident → CAPA → audit finding → management review. The traceability auditors look for.

What PICMS does not do

Auditor-credible vendors don't pretend software replaces safety culture. PICMS does not:

  • Replace your H&S Manager / SHEQ Lead. The standard requires accountable, competent people; software supports their work.
  • Submit RIDDOR reports for you. PICMS flags incidents that meet the RIDDOR criteria and tracks the notification deadline; the actual HSE RIDDOR portal submission is yours.
  • Replace your competent-person duties under CDM 2015 (Principal Designer, Principal Contractor) — those roles still need real people.
  • Issue your certificate. Only an accredited certification body does that.

What PICMS does is give you, your team and your auditor a single source of truth for everything else — so the certification visit is a verification exercise, not a documentation hunt.

Who PICMS is built for

  • UK construction contractors — 45001 alongside CHAS, Constructionline, SafeContractor for tender qualification. See the Construction Pack.
  • UK manufacturers + waste handlers — 45001 alongside 14001 + 9001 in the EHSQ triad.
  • UK commercial diving contractors — 45001 sits alongside DWR 1997, IMCA D018, ACoP L103/L104. See the Diving Pack.
  • Multi-site organisations needing federated H&S reporting — central legal register, harmonised incident handling, fleet-wide training matrix.
  • ISO consultants managing multiple 45001 clients — see PICMS Partners.

Pricing for ISO 45001 organisations

45001 is rarely deployed alone in the UK; the typical pattern is the 9001+14001+45001 EHSQ triad, often with 27001 added for B2B supply-chain qualification:

  • Essentials — £199/month. One ISO standard, 5 users. Right for very small operations with 45001 only.
  • Professional — £449/month. Three ISO standards (the EHSQ triad), 15 users, autonomous AI evidence agents, one industry pack. The most common 45001 starting point.
  • Certification — £699/month. Five ISO standards, 30 users, unlimited AI queries, two industry packs.
  • Enterprise — £1,199/month. Multi-site groups, unlimited standards + users.

See full pricing →

Related reading

Stop assembling your H&S system from spreadsheets.

14 days free, full feature access, no credit card surprise. Built by an IRCA Registered Principal Auditor who's stood in front of your auditor more times than they can count.

Start Free Trial Book a Demo