What is ISO?
ISO (the International Organization for Standardization) is an independent, non-governmental body that develops and publishes international standards. Founded in 1947 and headquartered in Geneva, it brings together national standards bodies from more than 160 countries — the UK is represented by BSI.
Standards are developed by consensus between member countries and other stakeholders, then adopted voluntarily by organisations to demonstrate they work to recognised best practice. ISO covers quality management, environmental management, occupational health and safety, information security, food safety and a great deal else besides.
ISO is not a regulator and cannot enforce anything. Organisations adopt its standards because customers, tender processes and supply chains increasingly ask for them, and because the disciplines involved tend to improve how the business actually runs.
One thing worth being clear about. ISO does not certify anybody. Organisations are certified to a standard by an independent certification body, which in the UK is normally accredited by UKAS. Individuals are not “ISO certified” — people take training, organisations hold certification.
That matters when you are reading job adverts or tender documents. A request for someone “ISO 45001 trained” means a course like the ones below. A request for a supplier “certified to ISO 45001” means an audited management system, which is a different and much larger undertaking.
The standards these courses cover
Three management system standards account for most UK training demand. They share a common structure, which is why many organisations run them as one integrated system.
Quality
ISO 9001
Quality management systems — consistent processes, defined responsibilities and continual improvement. The most widely held ISO certification in the world, and the one most often named in tenders and supplier questionnaires.
Environment
ISO 14001
Environmental management systems — identifying environmental aspects and impacts, meeting compliance obligations and reducing them over time. Increasingly requested alongside quality on public sector and construction frameworks.
Health & safety
ISO 45001
Occupational health and safety management systems. Published in 2018 and the replacement for the old OHSAS 18001, with a much stronger emphasis on worker participation and top management involvement.
ISO 45001 — health and safety management
Start with the introduction if you need to understand the standard; take implementation if you are the one building the system.
An overview of the standard’s structure and requirements for anyone who needs to understand what ISO 45001 asks of an organisation without being responsible for delivering it. A sensible first step before implementation.
Building and running an occupational health and safety management system to the standard — context, worker consultation, hazard identification, operational controls and performance evaluation. Aimed at those doing the work rather than approving it.
ISO 14001 — environmental management
A three-step progression: awareness, then implementation, then auditing the system you have built.
◆ Awareness
What an environmental management system is and what the standard requires. Suits middle managers and anyone from a quality or health and safety background picking up environmental responsibilities.
■ Implementation
Developing and maintaining an EMS in practice — environmental aspects and impacts, compliance obligations, objectives and the areas where organisations most often need to concentrate their effort.
● Auditing
Planning, conducting and reporting internal audits of an environmental management system, including raising findings and following them through. Internal audit is a requirement of the standard, not an optional extra.
Internal auditing for any ISO standard
Auditing skills transfer across standards, because ISO management system standards share a common clause structure. These courses are not tied to one standard.
The principles and process of internal auditing applied to ISO management systems — audit planning, evidence gathering, objectivity and reporting.
The internal auditor role itself — competence expectations, conducting audits against a standard’s clauses, and handling nonconformities and corrective action.
The 2024 climate change amendment. In February 2024 ISO amended more than thirty management system standards, including ISO 9001, ISO 14001 and ISO 45001, adding a requirement to consider whether climate change is a relevant issue in the organisation’s context. It is a short addition rather than a new set of controls, but certification bodies audit against it, so anyone maintaining or auditing a system needs to have considered it and be able to show the reasoning — even where the conclusion is that it is not material.
ISO training questions
Can I become “ISO certified” as an individual?
No. Certification applies to organisations and their management systems, and is issued by an independent certification body following an audit — in the UK those bodies are normally accredited by UKAS. What an individual gets from a course is a training certificate showing they have completed it. The distinction matters on CVs and tenders, where claiming personal ISO certification will be spotted immediately.
Which ISO course should I start with?
Match it to what you have been asked to do. If you need to understand a standard, take an awareness or introduction course. If you are building or maintaining the system, take implementation. If you have been asked to audit an existing system, take an internal auditor course. Working through all three in order is common where one person ends up owning the whole system.
Is an internal auditor course the same as a lead auditor qualification?
No, and it is worth checking which one your employer means. Internal auditor training prepares you to audit your own organisation’s system as part of its internal audit programme. Lead auditor courses are longer, separately certificated and aimed at people who will audit other organisations on behalf of a certification body. If a job advert asks for a lead auditor, an internal auditor course will not cover it.
What is the difference between ISO 45001 and ISO 14001?
ISO 45001 covers occupational health and safety — protecting the people doing the work. ISO 14001 covers environmental management — the organisation’s impact on the world around it. They share the same underlying clause structure, so organisations commonly run them together with ISO 9001 as a single integrated management system rather than three separate ones.
Does ISO 45001 replace health and safety training like IOSH or NEBOSH?
No — they do different jobs. ISO 45001 training is about the management system: how safety is planned, documented, measured and improved across an organisation. IOSH and NEBOSH courses build individual competence in recognising and controlling hazards. Most organisations running a certified system need both, in different people.
Related training
NEBOSH courses
IOSH courses
NVQ health & safety
COSHH training
E-learning courses
Health & safety guidance
All health & safety courses
On-site group training
All courses listed here are delivered and certificated by independent training providers.
