BerkshireSafetyConsultants
Contact
Back to blogFeatured

ISO 9001 vs ISO 45001. Which does my business actually need?

Berkshire Safety Consultants·May 19·5 min read

If you've ever sat down to fill in a tender response, applied for a public sector contract, or had a larger client ask for your “management system documentation,” you've probably bumped into ISO 9001 and ISO 45001.

And if you're like most SME owners, you've probably also Googled some version of: do I actually need this, or is it one of those things consultants invent to sell me services?

Fair question. Here's a straight answer.

The 30-second version

What ISO 9001 actually is

ISO 9001 is the international standard for quality management systems. In plain English: it's a framework for proving that your business has documented, repeatable processes for delivering whatever it is you sell — and that you actually follow them.

When a client asks if you're ISO 9001 certified, what they're really asking is: do you have documented procedures for how you do the work? Do you measure whether those procedures are working? When something goes wrong, do you have a system for fixing it and stopping it happening again? Can you prove all of the above to an external auditor?

It's not about being good at your job. Plenty of brilliant tradespeople and consultants aren't ISO 9001 certified. It's about being able to prove, on paper, that the way you work is consistent, measured and improvable.

Who tends to need it:manufacturers and engineering firms, anyone supplying the public sector or NHS, construction firms tendering above a certain contract value, and service businesses where clients want assurance you won't drop the ball.

Who probably doesn't need it: sole traders and very small B2C businesses, and pre-revenue businesses where the cost outweighs the contract value it unlocks.

What ISO 45001 actually is

ISO 45001 is the international standard for occupational health and safety management systems. It replaced the older OHSAS 18001 in 2018 and is now the recognised global benchmark.

What it says you need to demonstrate: you've identified the H&S risks across your operations properly, not on a back-of-an-envelope; you have documented controls in place; your workers are involved in the process, not just informed; you measure, monitor and review performance; and when incidents happen, you investigate, learn, and adjust.

The thing that catches a lot of SME owners off guard: ISO 45001 isn't only about the obvious physical hazards. It also covers psychological safety, fatigue, contractor management, and whether your H&S culture survives when the boss isn't in the room.

Who tends to need it: construction, manufacturing, logistics, healthcare, and any industry with notable physical risk; anyone tendering for public sector, infrastructure, housing or NHS work; businesses with employees on multiple sites.

Who probably doesn't need it yet: office-only businesses with low operational risk, or very small teams where a properly executed risk assessment process is genuinely sufficient.

So which one do you need?

Honest answer: it depends on where your tenders are coming from.

Low-risk service business, referral or repeat clients?You probably don't need either — a solid set of risk assessments, a method statement template, and decent insurance covers you.

Tendering for mid-sized private sector contracts? ISO 9001 starts mattering — procurement teams use it as a shortlisting filter.

Tendering for public sector, NHS, housing association or infrastructure work? Both standards start showing up in PQQs. ISO 9001 is increasingly a baseline; ISO 45001 alongside SSIP membership (CHAS, SafeContractor, Constructionline) is what gets you onto framework agreements.

Higher-risk industry? ISO 45001 becomes effectively expected. Your clients will ask, your insurers will care, and the Building Safety Act has raised expectations around how you demonstrate safety management.

The tender shortlisting reality

When a procurement team is reviewing 30 tender responses, they're not reading every page — they're filtering. If you don't tick the accreditation boxes, you don't get to the section where they read your proposal. That's the actual commercial value of ISO certification for an SME: not the audit, not the process improvement — the fact that holding it means you make it past the first cut.

We hold both ISO 9001 and ISO 45001 at BSC, alongside SSIP, which is why we tend to pre-qualify on shortlists without a second pass.

What to do next

  1. Look at your last 12 months of tender losses. Were any blocked by missing accreditations? That's your answer.
  2. If yes, ISO 45001 is usually the higher-leverage starting point for higher-risk businesses; ISO 9001 for service-led ones.
  3. Before you spend anything on a certification body, get a gap analysis done. There's no point paying for an audit you're guaranteed to fail.

If you're not sure where you sit on the spectrum, that's the kind of thing we have free 20-minute calls about. No pitch, just an honest read on whether ISO certification is worth your time at this stage of your business.

Book a call