A safety manager I spoke with a while back told me something that stuck with me.
Her company had just lost out on a supplier contract. It wasn’t because of the price or the quality. But because the buyer's procurement team asked for proof of ISO 45001 certification, and she didn't have it.
Her first reaction was confusion, not concern.
"We're OSHA compliant," she said. "Isn't that the same thing?"
It isn't. But she’s not the only one to assume it is.
OSHA and ISO 45001 both deal with workplace safety, but they're built on completely different ideas of what "compliance" actually means.
One is a US law you can't opt out of. The other is a global management standard you choose to build, whether or not a client is asking for it yet. Confusing the two, or assuming one replaces the other, is exactly how a business ends up in the same spot.
For years, the international benchmark for the workplace wasn't ISO 45001 at all. It was a standard called OHSAS 18001. Companies certified under it had until September 11, 2021. Organizations that didn't make the switch lost their accredited occupational health and safety management system. OHSAS 18001 has been fully retired now.
Businesses should be preparing for further changes to ISO 45001:2027, but for now, let's actually separate OSHA and ISO 45001.

OSHA stands for the Occupational Safety and Health Administration. It's a federal agency, created under the Occupational Safety and Health Act of 1970, and its job is to set and enforce workplace safety rules across the United States.
If you employ people in the US, OSHA applies to you. There's no opting out and no certification to earn. You're either meeting the requirements, or you're not.
The rules themselves are spread across a few major areas. General industry falls under 29 CFR 1910.
Construction has its own set under 1926. There are additional standards for maritime and agricultural work. And where a specific standard doesn't exist for a hazard, OSHA's General Duty Clause still applies, requiring employers to keep the workplace free of recognized hazards likely to cause serious harm.
In practice, this shows up as things like the following:
Inspections happen, sometimes scheduled, sometimes triggered by a complaint or an incident, and penalties follow when violations are found. As per the OSHA penalties, a serious violation can cost up to $16,550. Willful or repeated violations can run as high as $165,514 per violation.
Not every business in the US operates under federal OSHA directly. Under Section 18 of the OSHA Act, states are allowed to run their own occupational safety program as long as it's at least as protective as the federal one.
Currently, 22 states and territories run a full OSHA-approved state plan covering both private employers and state or local government workers, and a handful of others run plans that cover public sector workers only.
If your business operates in one of these states, your actual legal obligation might go beyond what federal OSHA requires.

ISO 45001 is an international standard for an occupational health and safety management system (OHSMS). It was published in 2018, and it's the standard that replaced OHSAS 18001 as the OHS management system standard, but it does not replace OSHA or other mandatory safety laws.
There’s no government agency behind it and no legal mandate forcing your hand. It's a voluntary framework, built on the same high-level structure ISO uses across its other management standards, including ISO 9001 certification and ISO 14001 certification.
That structure follows a Plan-Do-Check-Act cycle. You plan your approach to safety, you carry it out, you check whether it's working, and then you act on what you find. Then the cycle starts again.
Where OSHA tells you what specific outcome you need to hit, like keeping a walking surface clear or maintaining a permissible exposure limit, ISO 45001 gives you a system for figuring out your own risks, building controls around them, and ensuring that the whole thing actually works, not just on paper but in practice.
It applies to organizations of any size, in any country, in any industry. As of the 2024 ISO survey, 542,527 organizations worldwide hold ISO 45001 certification, a number that’s nearly tripled since 2020.

One distinction that gets blurred constantly: being compliant with ISO 45001 and being certified to ISO 45001 are not the same thing.
You can build a management system that follows the clauses of ISO 45001 without ever paying an accredited body to audit and certify you. That gets you the internal benefits, better hazard identification, and more consistent processes, but not the third-party proof that a client or regulator can point to.
Certification is the add-on. An accredited verification body reviews your system, visits your site, talks to your workers, and if everything checks out, issues a certificate that’s typically valid for three years, with surveillance audits in between.

The easiest way to look at ISO 45001 vs OSHA is this: OSHA is about the safety rules you’re required to follow, while ISO 45001 is a framework you can use to manage workplace safety more systematically.
OSHA isn't optional. If you have employees in the US, you're covered. ISO 45001 is something you opt into, either because you want the internal discipline it creates or because a client, investor, or contract requires it.
OSHA enforcement comes from the outside, in the form of a government inspector who can walk onto your site, look around, and issue a citation. ISO 45001 enforcement, if you can call it that, comes from an auditor you hired, checking whether your own system matches what you said it would do.
If you miss the mark with OSHA, you get a fine. But if you miss the mark with ISO 45001, you may need to address nonconformities before certification is granted or maintained.
OSHA standards exist largely because something went wrong somewhere, and a rule was written in response. That's not a criticism; it's just how the regulatory process works.
ISO 45001 asks a different question upfront: before anything happens, what could go wrong here, and what are we doing about it now?
OSHA cares about specific, documented outcomes tied to its standards: incident rates, recordable injuries, and whether your machine guarding meets specs.
ISO 45001 cares about whether your system as a whole is functioning, whether hazards are being identified, whether workers are actually involved in safety decisions, and whether leadership is engaged rather than just signing off on a policy once a year.
OSHA has no authority outside the United States. If your business operates internationally, or you're trying to win contracts with companies that source globally, OSHA compliance alone won't mean much to a buyer in another country.
ISO 45001 is recognized everywhere, which is part of why it's becoming close to a "cost of entry" requirement in industries like manufacturing and construction that rely on international supply chains.

For as different as they are structurally, it's worth pausing on what actually overlaps, because it's more than most comparisons give credit for.
Both exist to prevent the same basic thing: people getting hurt at work.
Both rely on identifying hazards and applying some version of the hierarchy of controls: eliminate the risk first, then substitute, then engineer it out, then fall back on administrative controls and PPE.
Both expect you to keep records that show your safety process is real, not just a policy sitting in a binder.
And there's a newer overlap that's becoming harder to ignore: psychosocial hazards.
Excessive workload, poor management practices, job insecurity, and chronic stress. ISO 45001's Clause 6.1.2 explicitly treats these as hazards to be identified and controlled, the same way you'd treat a slip risk or a chemical exposure.
OSHA doesn't have a dedicated psychosocial standard yet, but the OSHA General Duty Clause has increasingly been interpreted to cover workplace conditions that put people at genuine risk, physical or otherwise.
If you're building an OHSMS, this is a place where ISO 45001 is arguably ahead of where US regulation currently sits, and it's worth building into your risk register regardless of what's formally required.

A few beliefs come up often enough that they're worth addressing directly.
Not true.
Certification has no bearing on whether OSHA shows up. Inspections are triggered by complaints, referrals, high-hazard industry targeting, or just being selected.
Your certificate doesn't exempt you from anything.
Also not true, and this is the one that tends to catch people off guard.
OSHA compliance gets you a portion of the way there, mainly around hazard-specific controls, but ISO 45001 expects a full management system: documented leadership commitment, worker participation in decision-making, a formal legal register, internal audits, and a management review process.
Most companies that assume they're most of the way there discover a real gap once they measure their actual ISO 45001 compliance against the full standard.
It's not.
The scope of the system scales with the size of the business.
A ten-person operation has a much smaller documentation load than a thousand-person manufacturer, and the case for certification is often stronger for a small business because a single serious injury or a single lost contract hits much harder when you don't have the size to absorb it.
The clearest connection is Clause 6.13, which requires you to maintain a current, documented list of every legal and regulatory requirement that applies to your operations. Covering these requirements requires understanding the broader framework outlined in ISO 45001 certification, which aligns state and federal compliance into a single system.
For a US business, this register should cover the OSHA standards that apply to you, your state’s OSHA plan if you have one, DOT requirements if you transport hazardous materials or operate vehicles, and any EPA rules related to worker safety.
The second connection shows up during an actual inspection. A company running a mature OHSMS tends to have organized records, workers who can clearly explain the hazards in their own area, and documented procedures that match what's actually happening on the floor.
None of that guarantees a clean inspection, but it's the difference between an inspector finding a scattered paper trail and finding a system that was clearly built to hold up to scrutiny.
Two warehouses can have the same layout, equipment, and day-to-day operations, but their approach to safety can be very different. One may only update its safety binder before an audit.
The other keeps reporting hazards, runs quarterly internal audits, and reviews its legal register whenever regulations change. Both may be OSHA compliant today.
The difference is that one is actively maintaining its safety system, so it can keep up when conditions change or something goes wrong.

This is the real question behind “OSHA vs ISO 45001." It deserves a detailed breakdown; let’s get into it. While evaluating workplace standards often requires navigating frameworks like ISO 9001 vs ISO 45001, deciding between regulatory baselines and voluntary management systems comes down to operational scope and business maturity.
Yes, but OSHA compliance is still something you have to follow. ISO 45001 doesn’t replace OSHA requirements or give you a way around them. What it can do is give you a more organized way to manage your safety requirements, so you’re not scrambling whenever a regulation changes or an inspector turns up.
If you already have ISO 9001 or ISO 14001 in place, you can also make things easier by bringing your systems together. As explained in ISO 14001 vs ISO 45001, both standards follow the same Annex SL structure. So instead of managing document control, internal audits, management reviews, and corrective actions separately, you can handle them through one integrated system.

On the OSHA side, the numbers are straightforward. A serious violation runs up to $16,550. Willful or repeated violations climb to $165,514, and that's per violation, not per inspection.

On the ISO 45001 side, the cost of not having it is harder to put a single number on, but it's real.
The safety manager from the start of this blog lost a contract over it, a loss that likely outweighed a typical ISO 45001 certification cost several times over.
The NSC’s Work Injury Costs Overview estimates that a single medically consulted workplace injury costs a business around $48,000 on average, and a workplace fatality averages roughly $1.54 million once you account for the full impact.
A structured OHSMS doesn't guarantee you avoid these outcomes, but it's built specifically to catch the conditions that lead to them before they turn into a claim, a fine, or a lost account.
OSHA's Voluntary Protection Program, or VPP. It recognizes employers with strong safety and health management systems, and participants who maintain their status are exempt from OSHA's programmed inspections while enrolled.
VPP and ISO 45001 aren't the same thing. VPP is government-run and US-only, while ISO 45001 is a global, third-party certified standard, but they share the same underlying idea: a business that runs a real management system, not just a compliance checklist, earns some form of recognition for it. Some organizations base their VPP application directly on an existing ISO 45001 system, since the groundwork overlaps heavily.
ISO 45001 isn’t mandatory, but OSHA won’t differentiate you from your competitors.
One is the law you can't avoid. The other is the proof that you're doing more than the minimum, and increasingly, that proof is what gets you through the door with clients who have a choice of who to work with.
You don't have to build these as two separate efforts, pulling your team in different directions. A single legal register, one set of documentation, and one audit calendar that covers OSHA and ISO 45001 together are a lot easier to maintain than two systems running in parallel.
That’s exactly what P3 LogiQ was built to simplify. Compliance to certification is a journey in itself; we help you cross this journey with ease.

If you are looking to get started with ISO 45001 compliance effectively, P3 LogiQ can help you streamline your safety processes and keep your system active year-round.
Sign up to get started or book a demo to see how it works in practice.
OSHA is a mandatory US law enforced through government inspections and fines. ISO 45001 is a voluntary international standard for building a full safety management system, verified through third-party certification audits instead of legal penalties. One sets minimum requirements; the other builds the system around them.
No. OSHA sets legally mandatory safety requirements for US employers, enforced through inspections and fines. ISO 45001 is a voluntary management system standard that helps you meet those requirements more consistently, but it doesn't remove or replace your obligation to comply with OSHA in any way.
No. It's entirely voluntary, unlike OSHA, which every US employer is legally required to follow. That said, ISO 45001 is increasingly expected by larger clients, government contracts, and international supply chains, even though no federal agency requires or enforces it directly.
Not directly. Certification doesn't lower a fine once a violation is found. What it can do is reduce the odds of violations happening in the first place, since a mature OHSMS is built to catch gaps before an inspector does.
OSHA compliance is enforced by federal or state government inspectors who can issue citations and fines. ISO 45001 certification is issued by independent, accredited certification bodies that audit your management system against the standard. One answers to the government; the other answers to a private auditor whom you hire.
State plans don’t change ISO 45001 itself, but they can affect your legal register under Clause 6.1. 3. If you operate in a state with its own OSHA-approved plan, such as California or Washington, your compliance obligations may go beyond OSHA requirements and should be reflected in your system.
Often, yes. The documentation and audit scope scale with the size of your operation, so the investment is proportionally smaller. And for a small business, a single serious injury or a single lost contract can have an outsized financial impact, which makes the case for a structured system even stronger.
They're separate programs, but they reward similar behavior. VPP is a US government recognition program that exempts participants from programmed inspections. ISO 45001 is a global, third-party certified standard. Some businesses use their existing ISO 45001 system as the foundation for a VPP application, since the groundwork overlaps.
Yes, and this is one of its biggest advantages over OSHA. ISO 45001 has no geographic limit at all. OSHA only has legal authority within the United States, so if your business operates internationally, ISO 45001 is the framework that travels with you wherever you go.
ISO 45001 certification runs on a three-year cycle, with annual surveillance audits in between. OSHA inspections don't run on a schedule at all. They can be triggered by a complaint, a referral, an incident, or targeted programs for high-hazard industries, with no predictable timeline like certification has.