1.3 The PDCA Cycle & Risk-Based Thinking in OH&S

Key Takeaways

  • The ISO 45001 PDCA cycle maps directly across auditable clauses: Plan (Clauses 4, 5, 6), Do (Clauses 7, 8), Check (Clause 9), and Act (Clause 10).
  • Clause 5 (Leadership and worker participation) is positioned at the central core of the PDCA framework, continually driving, resourcing, and overseeing each phase of the cycle.
  • Risk-based thinking operates at two distinct tiers: strategic system-level risks/opportunities (Clause 6.1.1) and operational workplace OH&S risks/opportunities (Clause 6.1.2).
  • The intended outcomes of an OH&S MS include preventing injury and ill health, providing safe workplaces, fulfilling legal obligations, and continually improving OH&S performance.
  • Clause 5.1(c) mandates that top management integrate OH&S requirements directly into core business processes including capital budgeting, procurement, human resources, and operations.
Last updated: September 2026

1.3 The PDCA Cycle & Risk-Based Thinking in OH&S

The PDCA Architecture in ISO 45001:2018

The operational philosophy of modern management systems rests upon the Plan-Do-Check-Act (PDCA) cycle, originally conceived by Walter Shewhart and popularized globally by W. Edwards Deming. In ISO 45001:2018, PDCA serves as the underlying structural engine governing the management system.

PDCA provides an iterative mechanism that enables an organization to systematically establish, implement, control, and continually improve its OH&S performance. However, ISO 45001 introduces a fundamental architectural design: Clause 5 (Leadership and worker participation) is positioned at the central geometric hub of the cycle. Rather than acting as a static initial step, leadership and worker engagement sit at the core, continually driving, resourcing, and evaluating every phase:

  • Leadership provides strategic direction, resource allocation, and accountability;
  • Non-managerial workers provide direct front-line consultation and participation across all four quadrants;
  • The cycle operates continuously to drive continual improvement rather than functioning as an annual check-the-box exercise.

Mapping ISO 45001 Clauses to Plan-Do-Check-Act

A lead auditor must thoroughly understand how the requirements of Clauses 4 through 10 map directly into the four PDCA quadrants:

PDCA StageISO 45001 ClausesFocus and Core Auditor Verifications
PlanClause 4: Context of the organization<br>Clause 5: Leadership & worker participation<br>Clause 6: PlanningUnderstand external/internal context and stakeholder expectations; establish OH&S policy; assign roles; identify physical and psychosocial hazards; assess OH&S risks and opportunities; determine legal compliance obligations; set measurable OH&S objectives with action plans.
DoClause 7: Support<br>Clause 8: OperationAllocate financial and technological resources; ensure worker competence and training; maintain awareness and internal/external communication; control documented information; implement operational controls via the hierarchy of controls; execute management of change; enforce procurement/contractor controls; maintain emergency response readiness.
CheckClause 9: Performance evaluationMonitor and measure operational parameters, health surveillance, and safety metrics; evaluate compliance with legal and other requirements (9.1.2); plan and execute internal audits (9.2); conduct top management reviews (9.3).
ActClause 10: ImprovementReact promptly to incidents and nonconformities (10.2); conduct root-cause investigations; implement corrective actions to prevent recurrence; manage continual improvement initiatives to enhance overall OH&S performance (10.3).

Dynamic Closed-Loop Interplay

The PDCA cycle is continuous rather than linear. Evaluation outputs from the "Check" stage (such as legal compliance evaluation results under 9.1.2 or internal audit findings under 9.2) feed directly into the "Act" stage (executive management review decisions under 9.3 and corrective actions under 10.2). These outputs immediately cycle back into "Plan," modifying organizational context (Clause 4.1), updating hazard registers (Clause 6.1.2), and establishing new measurable OH&S objectives (Clause 6.2).

Operationalizing Risk-Based Thinking (RBT)

Risk-based thinking (RBT) enables an organization to determine the factors that could cause its processes and its OH&S management system to deviate from planned results. RBT mandates that organizations put preventive controls in place to minimize negative effects (threats) and capitalize on positive circumstances (opportunities).

In ISO 45001:2018, risk-based thinking operates across two interconnected tiers:

  1. Strategic System-Level Risks and Opportunities (Clause 6.1.1): These arise from strategic organizational context (Clause 4.1), the evolving needs of interested parties (Clause 4.2), and system scope (Clause 4.3):
    • Negative System Risk: Rapid corporate expansion or high staff turnover eroding safety supervisory competence and institutional safety memory.
    • Positive System Opportunity: Adopting an enterprise cloud safety management software enabling real-time hazard reporting across multiple remote operating sites.
  2. Operational Workplace OH&S Risks and Opportunities (Clause 6.1.2): These stem directly from physical, chemical, biological, ergonomic, and psychosocial hazards encountered in daily work:
    • Negative OH&S Risk: Worker exposure to high-pressure steam lines during boiler room maintenance.
    • Positive OH&S Opportunity: Installing automated robotic valve-turners that eliminate worker entry into high-risk confined spaces.

Risk-Based Auditing under ISO 19011:2018 (Principle 7)

In accordance with ISO 19011 Principle 7 (Risk-based approach), lead auditors must apply risk-based thinking to the audit itself. An audit team does not allocate equal time to every department. Audit sampling, interview depth, and on-site observation time are prioritized toward high-hazard operations, areas undergoing major organizational changes, processes with recent incidents, and areas with past nonconformities.

The Intended Outcomes of an OH&S Management System

According to ISO 45001:2018 Clause 1 (Scope), an OH&S management system exists to achieve concrete, measurable results. The intended outcomes include:

  1. Prevention of work-related injury and ill health to workers;
  2. Provision of safe and healthy workplaces;
  3. Continual improvement of OH&S performance;
  4. Fulfilment of legal requirements and other requirements;
  5. Achievement of OH&S objectives.

Auditor Takeaway: Results vs. Paperwork. An auditor does not merely inspect procedural documentation. If an organization maintains pristine manuals, signed forms, and glossy policy posters, but exhibits recurring severe injuries, chronic occupational illnesses, or systemic regulatory citations, the management system is failing its intended outcomes. This provides clear objective evidence of breakdown in Clause 6.1 (Planning), Clause 8.1 (Operational control), or Clause 5.1 (Leadership commitment).

Leading vs. Lagging Indicators in the "Check" Phase

To evaluate whether the OH&S MS is functioning effectively, organizations must monitor a balanced blend of leading and lagging performance indicators under Clause 9.1.1:

Metric CategoryCharacteristics & PurposeCommon Industry ExamplesLead Auditor Verification
Lagging IndicatorsMeasure past safety outcomes, failures, and harm after events occur; reactive- Lost Time Injury Frequency Rate (LTIFR)<br>- Total Recordable Incident Rate (TRIR)<br>- Days Away, Restricted, or Transferred (DART)<br>- Workers' compensation claims costVerify accurate reporting without concealment; ensure data feeds into Clause 10.2 investigations
Leading IndicatorsMeasure proactive safety activities, operational barrier health, and preventive inputs; predictive- Near-miss and hazard observation reporting volume<br>- Timely closure rate of corrective actions (% on time)<br>- Worker safety training completion and competence rates<br>- Safety walkabout frequency by top managementVerify that leading metrics are tracked, discussed in safety committees, and reviewed in management reviews

Immature management systems rely almost exclusively on lagging metrics (e.g., celebrating "1,000,000 hours without a lost-time injury" while near-miss reporting is suppressed). Mature ISO 45001 systems utilize leading metrics to identify deteriorating barriers before catastrophic failure occurs.

Integrating OH&S into Organizational Business Processes (Clause 5.1c)

A frequent root cause of management system failure is treating safety as an isolated, administrative silo disconnected from commercial reality. ISO 45001 Clause 5.1(c) explicitly requires top management to ensure "the integration of the OH&S management system requirements into the organization’s business processes."

Lead auditors evaluate business process integration by auditing cross-functional workflows:

  • Capital Expenditure (CapEx) & Design: Ensuring engineering and safety sign-off are required prior to purchasing new production machinery or approving plant modifications.
  • Human Resources: Verifying that job descriptions, employee onboarding, supervisory competence matrices, and performance appraisal bonuses incorporate safety responsibilities.
  • Procurement & Supply Chain: Confirming that contractor selection criteria evaluate vendor safety performance records, safety plans, and incident rates alongside commercial pricing.
  • Production Planning & Operations: Ensuring production quotas and shift schedules are calculated realistically to prevent worker fatigue, rushed shortcuts, and safety bypasses.

Lead Auditor Scenario: Broken Feedback Loops in a Manufacturing Facility

During a Stage 2 surveillance audit of a sheet-metal stamping facility, the Lead Auditor examines an OH&S objective established under Clause 6.2: "Reduce musculoskeletal disorders (MSDs) across stamping lines by 25% within 12 months."

The auditor tracks the audit trail across the PDCA cycle:

  1. Plan (Clause 6.2): The objective was documented with a plan to procure ergonomic scissor-lift tables for manual blank loading.
  2. Do (Clauses 7.1 & 8.1): To meet a sudden 30% surge in commercial automotive orders, executive management reallocated the capital budget away from the ergonomic lift tables toward a new stamping press. Line operators were required to manually lift 22 kg metal blanks at accelerated cycle times.
  3. Check (Clause 9.1): On-site clinic records documented a 45% increase in lumbar strain injuries and wrist tendinitis over a six-month period.
  4. Act (Clauses 9.3 & 10.2): Minutes from the recent executive management review omitted the clinic injury data. The review concluded: "OH&S objectives on track; zero lost-time fatalities achieved." No corrective action was initiated.

Lead Auditor Evaluation: The Lead Auditor raises a Major Nonconformity against Clause 9.3 (Management review) and Clause 10.3 (Continual improvement), combined with a Minor Nonconformity against Clause 5.1(c) (Failure to integrate OH&S requirements into business decisions). The organization broke the PDCA loop: top management sacrificed planned ergonomic controls for commercial volume, ignored adverse health surveillance data during management review, and failed to take corrective action to prevent worker injury.

Common Candidate Traps & Exam Pitfalls

  • The Linear PDCA Conception: Treating PDCA as an annual, sequential checklist rather than a continuous, dynamic loop where Clause 9 evaluation outputs directly drive Clause 6 planning revisions.
  • The Lagging-Only Metric Fallacy: Assuming that an organization with zero lost-time injuries automatically conforms to ISO 45001. A zero-injury rate often masks underreporting or suppressed hazard communication.
  • Silo Auditing: Restricting audit interviews solely to safety managers. ISO 45001 requires auditing procurement, maintenance, human resources, production planners, and executive directors to verify business process integration.
  • Treating Clause 5 as Step 1: Viewing leadership as an initial hurdle rather than the central operational engine that must actively drive, resource, and oversee all PDCA phases.
Loading diagram...
The ISO 45001:2018 PDCA Cycle Centered on Leadership and Worker Participation
Test Your Knowledge

How are the clauses of ISO 45001:2018 mapped across the Plan-Do-Check-Act (PDCA) framework?

A
B
C
D
Test Your Knowledge

Which set of items accurately reflects the primary intended outcomes of an OH&S management system as stated in ISO 45001:2018 Clause 1?

A
B
C
D
Test Your Knowledge

During an on-site certification audit, how does a Lead Auditor obtain objective evidence that top management has integrated OH&S MS requirements into core business processes under Clause 5.1(c)?

A
B
C
D