Requirements & evidence guide

OSHA vs ISO 45001 for Oil & Gas Operations

OSHA sets enforceable U.S. workplace safety duties. ISO 45001 is a voluntary standard for managing occupational health and safety. This guide explains how they differ and which records can support both.

The short answer

ISO 45001 certification does not replace OSHA compliance. OSHA sets duties an employer must meet when they apply. ISO 45001 provides a structured Plan-Do-Check-Act system for managing OH&S risks, involving workers, evaluating performance, and improving the program. Certification does not prevent an OSHA citation.

For each applicable rule or customer requirement, identify who is responsible, what work they must do, and which records to keep. Software can help organize those records. It cannot identify every legal obligation or certify your management system.

OSHA vs ISO 45001 at a glance

QuestionOSHAISO 45001
What it isFederal workplace-safety law, regulations, and enforcementInternational OH&S management-system standard
Is it mandatory?Applicable OSHA requirements are legally enforceableVoluntary unless a contract or other obligation requires it
Primary focusSpecific employer duties and worker protectionsA repeatable system for managing risks and improving OH&S performance
External assessmentOSHA inspections and enforcementOptional audit by an independent certification body
ResultCompliance with each applicable requirementA functioning management system; certification is optional
Does one replace the other?NoNo

What is current in 2026

ISO 45001:2018 remains the current published edition and includes Amendment 1:2024. ISO also lists a second-edition draft under development. Do not rewrite a management system around draft text; monitor ISO and your certification body for the final publication and any transition period.

OSHA obligations also change through rulemaking, interpretation, and enforcement. Build a requirements register that records the source, effective date, affected locations, owner, and last review. Assign someone to keep it current.

Requirements and supporting records

This is a planning map, not a clause-by-clause compliance checklist. Use it to test whether your process creates evidence a supervisor, auditor, customer, or regulator can retrieve and understand.

Program areaOSHA connectionISO 45001 connectionUseful evidence
Hazard identification and risk assessmentApplicable standards, the General Duty Clause, and OSHA recommended practicesPlanning and operational risk controlsJSAs/JHAs, inspection results, risk ratings, assigned controls, review history
Worker participationReporting procedures and anti-retaliation duties; worker involvement in recommended practicesConsultation and participation of workersHazard reports, toolbox talks, acknowledgements, meeting records, follow-up actions
Incident and injury recordsPart 1904 records when the employer and case are coveredIncident, nonconformity, and corrective-action processesIncident reports, investigations, OSHA 300/300A/301 records, approvals, privacy controls
Corrective actionsEvidence that identified hazards are corrected under applicable dutiesNonconformity, corrective action, and continual improvementOwner, due date, interim control, completion proof, effectiveness review
Competence and trainingTraining required by applicable standardsCompetence and awareness within the OH&S systemRole requirements, training completion, qualifications, refreshers, acknowledgements
Program oversightManagement leadership in OSHA recommended practicesObjectives, performance evaluation, internal audit, and management reviewObjectives, trend reports, internal audits, decisions, assigned improvements

What safety software can prove

It can support

  • • Consistent inspections, JSAs, and permits
  • • Timestamped incident and corrective-action records
  • • Assignment, escalation, and closure evidence
  • • Cross-site reporting and documented review
  • • Controlled exports for records and audits

It cannot establish

  • • That every applicable legal duty was identified
  • • That a control is effective merely because a form was closed
  • • ISO 45001 certification or auditor independence
  • • Compliance with site-specific contractual requirements
  • • Legal advice or professional safety judgment

BasinCheck is designed to support field evidence through digital audits, JSAs, incidents, corrective actions, and reporting. It is not a certification body and does not claim that using the platform alone makes an organization OSHA compliant or ISO 45001 certified.

A practical action plan

  1. 1

    Build the requirements register

    List applicable OSHA, state-plan, customer, operator, and voluntary requirements by location and activity.

  2. 2

    Map each requirement to evidence

    Define the workflow, responsible role, record, retention rule, and review schedule.

  3. 3

    Find disconnected controls

    Look for inspections that do not create corrective actions, training without competency evidence, and incidents without effectiveness review.

  4. 4

    Run a field trial

    Test one crew or site in real field conditions, including poor connectivity, photo capture, approvals, and retrieval.

  5. 5

    Review and improve

    Use audit findings and worker feedback to decide which procedures or controls need to change. Record the decision and check the result.

Test the work your crews need to do

Use the buyer's guide to compare offline work, corrective actions, incident records, audit trails, implementation, and evidence export.

Open the Buyer's Guide

Frequently asked questions

Is ISO 45001 legally required for oil and gas companies in the United States?

Generally, no. ISO 45001 is a voluntary occupational health and safety management-system standard, although a customer or contract may require certification. U.S. employers still must comply with applicable OSHA statutes and regulations regardless of whether they use or certify to ISO 45001.

Does ISO 45001 certification prove OSHA compliance?

No. Certification can provide independent evidence that an occupational health and safety management system meets the ISO standard, but it does not replace OSHA obligations, prevent citations, or prove compliance with every applicable federal or state requirement.

Can safety software make a company ISO 45001 certified?

No. Software can organize inspections, incidents, corrective actions, responsibilities, and records, but certification evaluates the management system as a whole. An independent certification body conducts certification. Software vendors and ISO itself do not certify the organization.

What records should an oilfield contractor maintain for OSHA and ISO 45001?

The exact records depend on applicable rules, contracts, and system scope. Common evidence includes hazard assessments and JSAs, inspections, incident investigations, OSHA 300/300A/301 records when required, corrective actions, training records, worker participation, emergency procedures, objectives, internal audits, and management reviews.

Is ISO 45001:2018 still current in 2026?

Yes. ISO lists ISO 45001:2018 as the current published edition, with Amendment 1:2024, while a second-edition draft is under development. Organizations should monitor ISO and their certification body for transition guidance after a replacement is published.

Primary sources