ISO 45001

Writing a Health and Safety Policy Statement for ISO 45001

A strong health and safety policy statement sets the direction for how an organisation protects people, manages risk and demonstrates leadership commitment.

By Principal Risk

17 min read

Abstract red and purple flowing lines.

For many organisations, a health and safety policy statement is created because it is required: required by law, required by a client, or required as part of ISO 45001 certification.

But when written well, it can do much more.

A health and safety policy statement is one of the clearest signals of leadership intent. It shows employees, contractors, customers, insurers and certification bodies that the organisation has made a visible commitment to safe and healthy working conditions. It also provides a foundation for responsibilities, risk controls, worker consultation and measurable health and safety objectives.

The challenge is that many policy statements are too generic. They use broad commitments, copy standard wording and sit untouched until the next audit or tender submission. That approach may produce a document, but it rarely creates meaningful accountability.

An effective ISO 45001 health and safety policy statement should be practical, proportionate and specific to the organisation’s risks. It should reflect how the business operates, who may be affected by its activities and what leadership is committed to improving.

This article explains what a health and safety policy statement is, what it should include, how ISO 45001 changes the conversation and how to keep the policy relevant over time.

What is a health and safety policy statement?

A health and safety policy statement is a written declaration of an organisation’s commitment to managing occupational health and safety.

It sets out the organisation’s overall intent. It should explain the importance of protecting workers and others who may be affected by the organisation’s activities. It should also provide a framework for responsibilities, arrangements and health and safety objectives.

It is useful to distinguish between the policy statement and the wider health and safety policy.

The policy statement is usually the high-level commitment. It is often one page, signed and dated by the most senior person in the organisation.

The wider health and safety policy may include more detail, such as responsibilities, risk assessment arrangements, training, consultation, emergency procedures, equipment controls, contractor management and monitoring.

HSE guidance describes a health and safety policy as setting out the organisation’s general approach to health and safety and explaining how health and safety will be managed in the business. HSE also advises that a policy should make clear who does what, when and how.

For ISO 45001, the policy statement also has a strategic role. ISO describes ISO 45001 as an international standard that provides a framework for organisations to manage OH&S risks and improve OH&S performance, with key elements including leadership commitment, worker participation, hazard identification, risk assessment, legal compliance, incident investigation and continual improvement.

Why the health and safety policy statement matters

A health and safety policy statement is not simply an administrative document. It is a leadership document.

It helps define the organisation’s expectations for safe working. It also gives employees and contractors a clear understanding of the organisation’s commitment to preventing work-related injury and ill health.

For SMEs, this can be particularly important. In growing businesses, responsibilities can become informal. Procedures may develop around individuals rather than systems. New equipment, sites, projects, contractors or services may introduce risks that are not fully reflected in existing arrangements.

A well-written policy statement helps create structure.

It shows that health and safety is not treated as a separate compliance activity, but as part of how the organisation plans work, manages people, controls risk and improves performance.

In ISO 45001 terms, the policy should support the occupational health and safety management system. It should connect leadership commitment with risk management, worker participation, legal compliance and measurable OH&S objectives.

When the policy is written clearly and communicated effectively, it can help answer four practical questions:

  1. What is the organisation committed to?
  2. Who has responsibility for health and safety?
  3. How are risks controlled?
  4. How will the organisation improve over time?

These questions matter because they move the policy from a document into a management discipline.

Part 1: What does the law require?

In Great Britain, every business must have a policy for managing health and safety. If the organisation has five or more employees, that policy must be written down. HSE also states that the policy, and any changes to it, must be shared with employees.

HSE guidance explains that a health and safety policy should cover three areas:

  • a statement of intent
  • responsibilities for health and safety
  • arrangements for health and safety

The statement of intent sets out the organisation’s general commitment to managing health and safety. HSE states that this should be signed by the employer or most senior person in the business and reviewed regularly.

The responsibilities section identifies who is responsible for health and safety. This may include directors, managers, supervisors, employees, appointed competent persons or others with specific roles.

The arrangements section explains the practical controls in place. This could include risk assessment, training, supervision, PPE, safe systems of work, emergency procedures, plant and equipment maintenance, contractor management and workplace inspections.

For smaller organisations, the policy does not need to be complex. It needs to be clear, accurate and proportionate to the nature of the business.

For higher-risk sectors, such as construction, manufacturing, engineering, logistics or facilities management, the policy should reflect the hazards and controls that are genuinely relevant to the work being carried out.

Part 2: What does ISO 45001 expect?

ISO 45001 places strong emphasis on leadership, worker participation and the proactive management of occupational health and safety risks.

The OH&S policy is part of that leadership requirement. It should show that top management is committed to providing safe and healthy working conditions, preventing work-related injury and ill health, and improving the OH&S management system.

For ISO 45001, the policy should include commitments to:

  • provide safe and healthy working conditions
  • prevent work-related injury and ill health
  • fulfil legal and other requirements
  • eliminate hazards and reduce OH&S risks
  • consult with workers and support worker participation
  • continually improve the OH&S management system
  • provide a framework for setting OH&S objectives

The policy should also be appropriate to the organisation’s purpose, size, context and level of OH&S risk.

That last point is important.

A construction company should not have a policy statement that reads like an office-based business. A manufacturer should not rely on generic wording that fails to reflect machinery, maintenance, manual handling, lifting operations, hazardous substances or production pressures.

The best policy statements are specific enough to feel credible, but concise enough to be understood.

Part 3: How to write an effective health and safety policy statement

A strong policy statement should be clear, concise and tailored to the organisation.

It does not need to explain every procedure in detail. The detailed arrangements can sit elsewhere in the health and safety management system. The policy statement should set the direction and make the organisation’s commitments clear.

A practical structure includes six elements.

1. Start with leadership commitment

The policy should begin with a clear statement from top management.

This should explain that the organisation is committed to protecting workers and others affected by its activities. It should also make clear that health and safety is a core management responsibility, not an optional add-on.

For example:

Principal ISO is committed to providing safe and healthy working conditions for our employees, contractors, clients and others who may be affected by our work.

The wording should be simple and direct. Avoid long, legalistic language that employees are unlikely to engage with.

2. Reflect the organisation’s real risks

The policy should be relevant to the work being carried out.

For example, a construction business may need to reference work at height, site traffic, subcontractor coordination, plant and equipment, lifting operations or emergency arrangements.

A manufacturing business may need to reference machinery guarding, maintenance, production controls, hazardous substances, manual handling, noise, workplace transport or quality-related safety risks.

A professional services business may focus more on office safety, lone working, travel, stress, workstation assessments and contractor arrangements.

The policy statement should not become a full risk assessment. However, it should show that the organisation understands the type of risks it needs to manage.

The policy should include a commitment to meeting legal requirements and other requirements that apply to the organisation.

“Other requirements” may include client requirements, certification requirements, contractual obligations, industry standards, insurer expectations or internal policies.

This is especially important for organisations seeking ISO 45001 certification, as auditors will expect to see that the policy aligns with the organisation’s legal and compliance obligations.

The policy should not simply say “we comply with all legislation” and stop there. It should be supported by a process for identifying, reviewing and meeting applicable legal and other requirements.

4. Commit to eliminating hazards and reducing OH&S risks

ISO 45001 places emphasis on eliminating hazards and reducing OH&S risks.

This does not mean that every hazard can be removed completely. In practice, it means the organisation should take a structured approach to identifying hazards, assessing risks and applying suitable controls.

The policy statement should make this commitment visible.

For example:

We are committed to eliminating hazards where reasonably practicable and reducing occupational health and safety risks through effective planning, risk assessment, training, supervision and consultation.

This wording connects the high-level commitment with practical management activity.

5. Commit to worker consultation and participation

Worker consultation and participation are central to ISO 45001.

This is because workers often understand operational risks in ways that senior management cannot see from documents alone. They know where workarounds happen, where controls are difficult to apply, where equipment creates problems and where procedures do not reflect reality.

A credible policy statement should therefore include a commitment to consulting workers and supporting their participation in health and safety matters.

This may include:

  • involving workers in risk assessments
  • discussing health and safety during toolbox talks or team meetings
  • encouraging hazard and near-miss reporting
  • seeking feedback before introducing new controls
  • involving worker representatives where they exist
  • communicating lessons learned after incidents or audits

The policy should make it clear that health and safety is not something done to workers. It is something developed with them.

The policy should provide a framework for setting OH&S objectives.

This is where the policy becomes more than a statement of intent. It should help the organisation define measurable priorities, such as reducing near misses, improving training completion, closing corrective actions faster, improving inspection scores or reducing manual handling risks.

For example, a policy commitment to “continual improvement” may be supported by an objective to reduce overdue corrective actions by 25% within six months.

A commitment to “worker participation” may be supported by an objective to increase near-miss reporting or complete monthly safety engagement meetings across all sites.

This link between policy and objectives is important. It helps demonstrate that the organisation is not only making commitments, but also measuring progress against them.

How long should the policy statement be?

The policy statement should usually be no longer than one page.

This is because its purpose is to communicate direction clearly. It should not contain every health and safety procedure, risk assessment or operational control.

A one-page policy statement can be supported by other documents, including:

  • risk assessments
  • safe systems of work
  • training records
  • emergency plans
  • inspection checklists
  • legal registers
  • contractor management procedures
  • incident reporting procedures
  • OH&S objectives
  • management review records

The policy statement sets the commitment. The wider management system provides the evidence.

Who should sign the health and safety policy statement?

The health and safety policy statement should be signed and dated by the most senior person in the organisation.

In many SMEs, this will be the Managing Director, CEO, owner or another member of top management with ultimate responsibility for the business.

The signature matters because it demonstrates leadership accountability. It shows that the policy is not owned only by a health and safety adviser, operations manager or external consultant.

For ISO 45001, this is especially important. The standard expects leadership from top management, not passive approval from a distance.

The policy should also include a review date or version control so that the organisation can demonstrate when it was last reviewed and whether it remains current.

Part 4: How to communicate the policy

A health and safety policy statement only creates value if people know it exists and understand what it means.

HSE states that employers must share the policy, and any changes to it, with employees. For ISO 45001, communication is also important because workers need to understand the policy and how it relates to their role.

Employees do not need to memorise the policy word for word. But they should understand the organisation’s commitments, their responsibilities and how they can participate in improving health and safety.

Practical ways to communicate the policy include:

  • employee induction
  • contractor onboarding
  • toolbox talks
  • team briefings
  • notice boards
  • SharePoint or intranet pages
  • staff handbooks
  • management system portals
  • project start-up meetings
  • annual refresher briefings
  • supplier or subcontractor communication

The policy may also need to be available to external interested parties, such as customers, certification bodies, insurers, accreditation schemes or principal contractors.

Many organisations choose to display their policy statement on their website, in reception areas, in site offices or within tender submissions.

The key point is that communication should be active. Uploading a PDF to a shared folder is useful, but it is not always enough.

Part 5: When should the policy be reviewed?

A health and safety policy should be reviewed regularly and updated when necessary. HSE specifically states that the statement of intent should be signed and reviewed regularly.

A common approach is to review the policy at least once a year as part of management review. However, organisations should also review the policy when there are significant changes that could affect health and safety management.

Examples include:

  • new equipment, plant or machinery
  • changes to premises or work locations
  • new products or services
  • changes to operational processes
  • changes in legal or client requirements
  • expansion into new sectors
  • leadership or organisational changes
  • significant incidents, near misses or enforcement action
  • audit findings
  • changes to contractor or supplier arrangements
  • changes in workforce size or structure

A policy review does not need to be complicated. The aim is to confirm whether the policy still reflects the organisation’s activities, risks, responsibilities and commitments.

A practical review process might include:

  1. Check whether the policy still reflects the organisation’s current operations.
  2. Review whether the commitments remain aligned with legal, client and ISO 45001 requirements.
  3. Consult managers, supervisors and workers on whether the policy is still accurate.
  4. Record any proposed changes.
  5. Update the policy, version number and review date.
  6. Ask top management to sign and approve the revised policy.
  7. Communicate the updated version to employees and relevant interested parties.

This process creates evidence that the policy is maintained, not simply filed.

Common mistakes when writing a health and safety policy statement

Many organisations have a policy statement in place, but it does not always support effective health and safety management.

The most common issue is generic wording. A policy that could apply to any organisation in any sector is unlikely to demonstrate that the business understands its own risks.

Other common mistakes include:

  • writing a policy that is too long
  • failing to identify top management commitment
  • not signing or dating the statement
  • using a template without adapting it
  • failing to communicate the policy to workers
  • not involving workers in relevant health and safety matters
  • making commitments that are not supported by arrangements
  • not linking the policy to OH&S objectives
  • failing to review the policy after business changes
  • keeping outdated versions in circulation

These issues can create problems during ISO 45001 audits, client prequalification or incident investigations. More importantly, they can weaken the link between leadership intent and day-to-day health and safety management.

Example ISO 45001 health and safety policy statement wording

The following example is intended as a starting point only. It should be adapted to reflect the organisation’s activities, risks, legal requirements and management structure.

[Company name] is committed to providing safe and healthy working conditions for our employees, contractors, visitors and others who may be affected by our activities.

We will take appropriate steps to prevent work-related injury and ill health by identifying hazards, assessing risks and implementing effective controls. We are committed to eliminating hazards where reasonably practicable and reducing occupational health and safety risks through planning, training, supervision, consultation and continual improvement.

We will fulfil applicable legal requirements and other requirements relevant to our occupational health and safety risks. We will also consult with workers and support their participation in matters affecting health and safety.

This policy provides a framework for setting and reviewing occupational health and safety objectives. It will be communicated to workers and relevant interested parties, reviewed regularly and updated when necessary.

Signed:

Name:

Position:

Date:

This statement should be supported by the wider health and safety policy, including responsibilities and arrangements.

How Principal ISO can help

Principal ISO supports small and medium-sized businesses with practical ISO consultancy and certification support across quality, environmental and occupational health and safety management systems.

For organisations working towards ISO 45001 certification, we can help you develop a health and safety policy statement that is clear, proportionate and aligned with the requirements of the standard.

That includes reviewing your existing policy, identifying gaps, aligning the policy with OH&S objectives, strengthening worker consultation and ensuring the right evidence is in place for certification audits.

We can also help you build the wider management system around the policy, including risk assessment arrangements, legal compliance processes, internal audits, management reviews and continual improvement planning.

Download our free ISO 45001 health and safety policy statement template

A template can be a useful starting point, particularly for smaller businesses that are building their health and safety management system for the first time.

However, the final policy should always be tailored to your organisation. It should reflect your activities, risks, people, responsibilities and legal obligations.

Download our free ISO 45001 health and safety policy statement template to get started.

Disclaimer: This template is for general guidance only and does not constitute legal advice.

Summary

An ISO 45001 health and safety policy statement should not be treated as a static document created only for compliance.

When written well, it sets the tone for the organisation’s approach to occupational health and safety. It demonstrates leadership commitment, supports legal compliance, provides a framework for OH&S objectives and helps workers understand their role in maintaining safe and healthy working conditions.

The strongest policy statements are concise, specific and actively communicated. They are signed by top management, reviewed regularly and supported by practical arrangements.

For organisations seeking ISO 45001 certification, the policy statement is a requirement. For organisations seeking stronger safety performance, it is an opportunity to turn leadership commitment into visible action.