3.2 Clause 6.1.2.2–6.1.2.3: Assessment of OH&S Risks & Opportunities
Key Takeaways
- ISO 45001:2018 Clause 6.1.2.2 requires a dual risk assessment: evaluating direct OH&S risks from identified hazards (factoring in existing controls) and other risks to the OH&S management system itself.
- Significant risks are defined through systematic criteria; lead auditors evaluate whether risk matrices and scoring criteria are objective, consistently calibrated, and free from artificial compression.
- Clause 6.1.2.3 establishes an equal obligation to assess OH&S opportunities, focusing on adapting work to workers, eliminating hazards, and continually improving the management system.
- Methodologies and criteria for assessing both risks and opportunities must be maintained and retained as documented information to ensure consistency across the organization.
3.2 Clause 6.1.2.2–6.1.2.3: Assessment of OH&S Risks & Opportunities
Following hazard identification, the organization must evaluate hazards to establish operational priorities and allocate resources. ISO 45001:2018 governs this through twin requirements: Clause 6.1.2.2 (Assessment of OH&S risks and other risks to the OH&S management system) and Clause 6.1.2.3 (Assessment of OH&S opportunities and other opportunities to the OH&S management system). Lead auditors must understand that while the standard does not mandate a specific mathematical model, it strictly requires documented, consistent, and objective assessment criteria.
1. The Dual Scope of Clause 6.1.2.2: OH&S Risks vs. System Risks
Clause 6.1.2.2 establishes a dual evaluation requirement:
- OH&S Risks Arising from Hazards (Clause 6.1.2.2.a): The traditional safety assessment evaluating the combination of the likelihood of occurrence of a hazardous event and the severity of injury or ill health that can be caused (Clause 3.20). The standard explicitly mandates taking into account the effectiveness of existing controls.
- Other Risks to the OH&S Management System (Clause 6.1.2.2.b): Strategic, financial, or organizational factors that could prevent the management system from achieving its intended outcomes. Examples include:
- Severe capital expenditure cuts compromising safety maintenance schedules;
- Corporate restructuring or downsizing that eliminates safety-critical expertise;
- Ineffective management communication leading to cynicism and non-reporting;
- Mergers introducing incompatible procedures and conflicting safety cultures;
- Supply chain disruptions that delay critical safety components or PPE.
Organizations that focus solely on physical workplace hazards while neglecting organizational risks to the management system fail Clause 6.1.2.2(b).
2. Risk Evaluation Methodologies and Defining 'Significant Risks'
Clause 6.1.2.2 requires that methodologies and criteria be defined with respect to scope, nature, and timing to ensure they are proactive and systematic.
Risk Matrices and Scoring
Organizations commonly apply qualitative or semi-quantitative matrices plotting Likelihood against Severity:
- Severity Categories: Graded from 1 (minor first aid) to 5 (fatalities or permanent irreversible health damage).
- Likelihood Categories: Graded from 1 (rare / improbable) to 5 (frequent / continuous exposure).
Tolerability Criteria and Significant Risks
Documented criteria must establish clear risk bands:
- Low / Acceptable Risk (Scores 1–4): Managed via routine operating procedures; no immediate capital controls required.
- Medium / Tolerable Risk (Scores 5–12): Requires planned risk reduction, standard operating procedures, and regular monitoring.
- High / Significant Risk (Scores 15–25): Intolerable risk; work must not proceed without interim controls; requires formal OH&S objectives (Clause 6.2) and engineering controls (Clause 8.1.2).
Control Effectiveness in Residual Risk
Organizations often commit the error of assuming existing controls function flawlessly. An auditor must verify whether residual risk ratings evaluate real-world control reliability. If an interlock is frequently bypassed or maintenance is overdue, the likelihood rating must reflect actual operational conditions.
3. Clause 6.1.2.3: Assessment of OH&S Opportunities
ISO 45001 introduced the assessment of OH&S opportunities to drive safety advancement beyond mere compliance. Clause 6.1.2.3 itemizes three distinct categories:
- Adapting Work and Work Environment to Workers (6.1.2.3.a): Ergonomic modifications, automated lifting devices, adjusting work heights, flexible shift scheduling to alleviate fatigue, and configuring workstations to individual physical capabilities.
- Eliminating Hazards and Reducing Risks (6.1.2.3.b): Substituting toxic chemicals with biodegradable alternatives, automating dangerous confined-space inspections via drones, or installing low-noise machinery.
- Improving the OH&S Management System (6.1.2.3.c): Implementing digital near-miss mobile apps, integrating safety criteria into early equipment design, partnering with academic institutions for ergonomics research, or benchmarking against industry safety leaders.
OH&S opportunities must not remain theoretical; they must feed into the concrete action plans required by Clause 6.1.4.
4. Assessment Methodologies Across Industrial Contexts
| Assessment Domain | Primary Tool | Key Operational Parameters | Auditor Scrutiny Focus |
|---|---|---|---|
| Workplace OH&S Risks | 5×5 Matrix / Kinney Method | Likelihood, exposure frequency, potential consequence severity | Verifying consequence ratings are not artificially deflated to avoid capital control triggers. |
| Management System Risks | SWOT / PESTLE / Risk Register | Budget stability, staffing capacity, organizational change | Ensuring safety is integrated into strategic business planning and leadership reviews. |
| Work Adaptation Opportunities | Ergonomic Assessments (RULA/REBA) | Biomechanical loads, posture angles, task repetition rates | Checking that ergonomic evaluations extend beyond office desks to production lines. |
| System Improvement Opportunities | Digital Maturity Gap Analysis | Incident reporting speed, worker engagement rate | Confirming documented opportunities have assigned owners, budgets, and target deadlines. |
5. Auditor Evaluation: Consistency, Objectivity, and Calibration
When evaluating Clause 6.1.2.2 and 6.1.2.3, lead auditors apply specific scrutiny:
- Inter-Departmental Calibration: Cross-check ratings across different departments. If Department A scores an unguarded belt drive as 'High Risk' while Department B scores an identical machine as 'Low Risk' based on informal worker experience, the criteria lack objectivity and consistency.
- Chronic Health Hazard Evaluation: Check whether methodologies evaluate long-latency occupational health risks (e.g., crystalline silica, noise, ergonomic strain) or only immediate acute injuries (slips, trips, cuts).
- Worker Consultation in Scoring: Confirm that frontline workers who perform the tasks participated in evaluating likelihood and severity (Clause 5.4).
- Documented Information: Ensure risk and opportunity assessment methodologies and criteria are formally maintained as documented information.
6. Real-World Audit Scenario: The Calibrated Matrix Manipulation
Context: During an audit of a metal foundry, the auditor examines the risk register for furnace tapping operations. Molten metal splashes are rated as Likelihood = 2 (Unlikely) and Severity = 2 (Minor First Aid), generating a low risk score of 4. As a result, no flash barriers were installed, and operators received only standard leather aprons.
Finding: Past incident logs reveal two severe second-degree burn incidents requiring hospital skin grafts within the last 18 months. Furthermore, the company's documented risk criteria classify any injury requiring hospitalization as Severity = 4 (Irreversible).
Evaluation: The auditor issues a Major Nonconformity under Clause 6.1.2.2. The organization failed to apply its documented criteria objectively and consistently, arbitrarily downgrading severity to bypass engineering controls and ignoring past incident evidence.
7. Common Exam Traps and Candidate Errors
- Trap 1: Assuming Quantitative Models are Mandatory. ISO 45001 does not require probabilistic risk modeling. Qualitative matrices are fully acceptable provided criteria are clearly defined and consistently applied.
- Trap 2: Confusing Commercial Opportunities with OH&S Opportunities. Business cost reductions or sales growth are commercial opportunities, not OH&S opportunities under Clause 6.1.2.3, unless they directly improve worker safety or the management system.
- Trap 3: Neglecting Control Effectiveness. Clause 6.1.2.2 explicitly requires assessing OH&S risks taking into account the effectiveness of existing controls, rather than theoretical control capability.
Under ISO 45001:2018 Clause 6.1.2.2, in addition to assessing direct OH&S risks arising from workplace hazards, what other category of risk must the organization systematically evaluate?
Which of the following directly represents an 'OH&S opportunity' as explicitly defined and categorized under ISO 45001:2018 Clause 6.1.2.3?
During an audit across two manufacturing plants owned by the same company, an auditor notices that Plant 1 rates high-voltage electrical panels without arc-flash protection as 'High Risk' requiring immediate interlocks. Conversely, Plant 2 rates the identical condition as 'Low Risk' without implementing controls, asserting that their electricians are exceptionally skilled. How should the lead auditor evaluate this finding?