Guidance · Reviewed August 2026
What a health and safety management system actually is, the legal basis for having one, how HSG65 and ISO 45001 relate, and how to judge what size of system your organisation needs.
The short answer
A health and safety management system is the set of arrangements by which an organisation plans, organises, controls, monitors and reviews its preventive and protective measures. Regulation 5 of the Management of Health and Safety at Work Regulations 1999 requires every employer to have such arrangements — and to record them if you employ five or more people. It does not require certification.
The phrase “management system” makes it sound like software, or a folder of documents. It is neither. It is how the organisation actually goes about keeping people safe — decisions, responsibilities, checks and corrections. The documents are evidence of the system, not the system itself, and that distinction is where most of them fail.
The Legal Basis
UK law requires appropriate arrangements for the management of health and safety at work. The general duty sits in section 2 of the Health and Safety at Work Act 1974 (HASAWA); the specific requirement for arrangements sits in the Management Regulations made under it.
Regulation 5, Management of Health and Safety at Work Regulations 1999
Employers must make and give effect to such arrangements as are appropriate — having regard to the nature of their activities and the size of the undertaking — for the effective planning, organisation, control, monitoring and review of the preventive and protective measures.
Where five or more people are employed, those arrangements must be recorded.
Two phrases in that are worth dwelling on. Appropriate, and having regard to the nature of their activities and the size of the undertaking. The law does not prescribe one system for everyone. A six-person joinery firm and a national contractor have the same duty and should not end up with the same paperwork.
Note also that five-or-more threshold. It is the same one that applies to your health and safety policy and to recording risk assessment findings — and it is a headcount, not full-time equivalents.
HSG65 and Plan, Do, Check, Act
HSE’s own framework is set out in Managing for Health and Safety (HSG65), built around the Plan, Do, Check, Act cycle. It replaced the older POPIMAR model, and it deliberately treats health and safety as part of general good management rather than a stand-alone system bolted to the side of the business.
Follow HSG65 and you will normally be doing enough to comply with the law. Inspectors may refer to it.
| Stage | What it covers | Evidence it exists |
|---|---|---|
| Plan | Set direction, aims and accountability. Decide what good looks like and who owns it. | Signed and dated policy, objectives, named responsibilities. |
| Do | Identify your risk profile, organise people and resources, and implement the controls. | Risk assessments, safe systems of work, training records, consultation. |
| Check | Active monitoring — inspections and audits before anything happens. Reactive monitoring — investigating what went wrong. | Inspection records, audits, incident investigations. |
| Act | Review performance, learn from it, and change something. Then round again. | Review records with actions, owners and dates. |
The third column is the honest test. If a stage has no evidence attached to it, that stage is not happening — and Check and Act are the two that quietly stop first.
It Must Be Built on Risk Assessment
A management system that isn’t grounded in a suitable and sufficient risk assessment is managing something other than your actual risks. The assessment tells you what the system has to control; everything else follows from it.
It also has to be proportionate to the hazards you face, and it has to reach people. Employees at every level need to be able to work safely and to raise problems without it taking nerve — a system nobody below management level can describe is not operating.
Do You Need ISO 45001?
ISO 45001 is the international standard for occupational health and safety management systems, published in March 2018. It replaced OHSAS 18001, which was formally withdrawn after the migration period ended — any certificate still citing OHSAS 18001 is long expired.
It uses the same high-level structure as ISO 9001 and ISO 14001, which makes it straightforward to integrate if you already hold either. Like HSG65, it is built on the Plan, Do, Check, Act cycle, so the two are compatible rather than competing.
Worth pursuing if…
Clients or tenders ask for it. You already hold ISO 9001 or 14001. You operate across multiple sites or countries and need one consistent framework. Or your supply chain position depends on demonstrable assurance.
Probably not, if…
You’re a small, lower-risk business with no client demanding it. Certification is voluntary and is not required by UK law — HSG65 is free, and following it is enough to satisfy the regulator.
Being plain about it: certification is a commercial decision, not a legal one. It can open doors on tenders and it imposes a discipline that many organisations benefit from. It does not, by itself, make anyone safer, and it does not reduce your duties under HASAWA one bit.
One recent change worth knowing about. In February 2024 ISO amended more than thirty management system standards, ISO 45001 among them, adding a requirement to consider whether climate change is a relevant issue in the organisation\’s context. It is a short addition rather than a new set of controls, but certification bodies audit against it, so anyone maintaining a system needs to have considered it and be able to show the reasoning — even where the answer is that it isn\’t material.
If you are heading that way, start with an introduction to ISO 45001 to understand what the standard asks, then ISO 45001 implementation if you are the one building the system. See all ISO training courses.
Where Management Systems Fail
| The problem | Why it matters |
|---|---|
| Documents instead of a system | A full folder and an unchanged workplace is the commonest failure. Paperwork is evidence of the system, not the system. |
| Stops after “Do” | Controls get implemented and never checked. Without Check and Act there is no cycle, and the system decays quietly. |
| Disproportionate | Regulation 5 says arrangements should suit the nature and size of the undertaking. An over-engineered system in a small firm gets ignored, which is worse than a simple one that’s used. |
| Owned by one person | If it lives with the safety adviser and nobody else can describe it, it leaves when they do. Section 37 puts liability with directors regardless. |
| Findings without owners | An audit finding with no named person and no date is an observation. Recorded and unactioned, it is also evidence you knew. |
| Certification mistaken for compliance | ISO 45001 is voluntary. It does not discharge any statutory duty, and holding it is no defence if the arrangements aren’t real. |
Find the gaps first
A health and safety risk review identifies what your arrangements are missing before you formalise anything. Or map training requirements by sector, hazard and job role — free, no account needed. The tools sit on envicourse.com, our course marketplace, and open in a new tab.
Training for Managing a System
| If you need to… | Usual route |
|---|---|
| Run the system for a team or site | IOSH Managing Safely — three days, covering the framework and risk assessment. |
| Own it for an organisation | NEBOSH General Certificate, or the International General Certificate for multi-country operations. |
| Go further | NEBOSH Diploma — the qualification for senior and chartered-track practitioners. |
| Cover a specific sector | NEBOSH Construction Certificate or Certificate in Fire Safety. |
| Build or audit a certified system | Introduction to ISO 45001 to understand the standard, or ISO 45001 Implementation to build it. Internal audit is a requirement of the standard, not optional — see ISO training courses. |
| Qualify on the job | NVQ in Health and Safety, or see health and safety officer courses. |
Frequently Asked Questions
What is a health and safety management system?
The arrangements by which an organisation plans, organises, controls, monitors and reviews its preventive and protective measures — in other words, how it actually manages risk day to day. It includes the policy, the risk assessments, the controls, the training, the monitoring and the review, and how those connect to each other.
Is one a legal requirement?
Arrangements are. Regulation 5 of the Management of Health and Safety at Work Regulations 1999 requires every employer to make and give effect to appropriate arrangements for planning, organisation, control, monitoring and review — and to record them if five or more people are employed. What is not required is certification to any particular standard.
What’s the difference between HSG65 and ISO 45001?
HSG65 is HSE’s free guidance on managing health and safety in Great Britain — following it will normally satisfy the regulator. ISO 45001 is an international, certifiable standard used to demonstrate assurance to third parties. Both are built on Plan, Do, Check, Act, so they align rather than conflict. HSG65 is about compliance; ISO 45001 is mostly about proving it to someone else.
Is OHSAS 18001 still valid?
No. ISO 45001 was published in March 2018 and replaced it. Organisations were given a three-year migration period, later extended slightly because of COVID, and OHSAS 18001 has since been withdrawn. Any certificate still referencing it is out of date.
How big does the system need to be?
Proportionate to your activities and the size of the undertaking — that’s the wording in regulation 5. A small, lower-risk business may need little more than a written policy, current risk assessments, training records and a scheduled review. Complexity should follow risk, not ambition.
Can a person be “ISO 45001 certified”?
No. Certification applies to organisations and their management systems, and is issued by an independent certification body — in the UK normally accredited by UKAS. Individuals take training and receive a training certificate. The distinction matters on CVs and tenders: a request for someone “ISO 45001 trained” means a course; a request for a supplier “certified to ISO 45001” means an audited management system, which is a much larger undertaking. See ISO training courses.
Does certification protect us if something goes wrong?
Not in itself. Your duties under HASAWA and the Management Regulations are unaffected by holding a certificate, and enforcement looks at whether the arrangements were real and effective. A well-run system will help you show you did what was reasonably practicable; a certificate over a system nobody follows will not.
Related Guidance
Health and safety policy →
Risk assessment →
Monitoring, review and audit →
HASAWA 1974 explained →
All guidance topics →
General guidance only, reviewed against HSE guidance, HSG65 and the Management of Health and Safety at Work Regulations 1999 in August 2026. Envico is an independent training intermediary and is not affiliated with the HSE, ISO or any certification body.
