Preparing for an ISO 45001 audit in Jordan does not begin a few days before the auditor arrives. Nor is it limited to organizing safety files or checking the availability of fire extinguishers and personal protective equipment.
In industrial facilities, an occupational health and safety management system examines the complete picture:
- Hazards arising from operations.
- Risk assessment.
- Operational controls.
- Compliance with applicable legal requirements.
- Emergency preparedness.
- Worker consultation and participation.
- Incident investigation.
- Training and competence.
- Monitoring and measurement.
- Internal auditing.
- Continual improvement.
This is particularly important for Jordanian factories because an organization must address more than the requirements of ISO 45001. It must also identify the Jordanian legislation applicable to its operations and demonstrate how it complies with it.
A factory that is ready for an audit is therefore not the one with the largest collection of safety files. It is the factory that can demonstrate that:
- Its hazards are known.
- Its risks have been assessed.
- Its controls are implemented.
- Its responsibilities are clear.
- Its legal requirements have been identified and are being monitored.
What Is ISO 45001?
ISO 45001 is an international standard for occupational health and safety management systems. It provides a framework for managing risks and improving occupational health and safety performance within organizations.
The standard addresses principal elements such as:
- Leadership commitment.
- Worker consultation and participation.
- Hazard identification.
- Risk assessment.
- Legal, regulatory, and other requirements.
- Emergency preparedness and response.
- Incident investigation.
- Performance review.
- Continual improvement.
As of 17 August 2026, ISO 45001:2018 remains the current published international edition, together with ISO 45001:2018/Amd 1:2024, which addresses climate-action changes. A new revision of the standard is currently under development.
For a factory, the objective is not to establish a system separate from its operations. Occupational health and safety management should be integrated into:
- Production.
- Maintenance.
- Warehousing.
- Contractor management.
- Procurement.
- Operational change.
- Human resources.
- Management decision-making.
What Is the Relationship Between ISO 45001 and Jordanian Legislation?
ISO 45001 is not a substitute for Jordanian legislation.
The standard requires an organization to identify the legal requirements and other requirements applicable to it, understand how they apply, and evaluate compliance systematically.
ISO also recognizes compliance with applicable legal and regulatory requirements as an essential element of an occupational health and safety management system.
A factory should therefore work through two connected pathways:
Pathway One: Implement the requirements of ISO 45001.
Pathway Two: Identify and implement the Jordanian legislation applicable to the factory’s activities, workers, and occupational hazards.
Holding ISO 45001 certification does not remove the employer’s legal responsibilities.
Likewise, implementing legal requirements alone does not necessarily mean that the factory has fulfilled every requirement of the management-system standard.
Which Jordanian Legislation Should Be Reviewed?
According to the current list published by the Jordanian Ministry of Labour, a factory developing its legal-requirements register should review the legislation applicable to its activity and scope.
Principal general references related to occupational health and safety include:
- Labour Law No. 8 of 1996 and its amendments.
- Occupational Safety and Health and Prevention of Occupational Hazards in Establishments Regulation No. 31 of 2023.
- Preventive and Curative Medical Care for Workers in Establishments Regulation No. 32 of 2023.
- Formation of Occupational Safety and Health Committees and Appointment of Supervisors in Establishments Regulation No. 33 of 2023.
The Ministry of Labour also lists, within the current occupational safety and health legislative framework:
- Instructions for Risk Assessment in the Work Environment of 2023.
- Instructions for Identifying Types of Occupational Hazard Sources and the Necessary Precautions and Preventive Measures of 2023.
- Decisions issued in 2024 concerning occupational safety and health policies.
- Decisions concerning required occupational safety and health records.
- Approved forms for reporting occupational accidents, injuries, and diseases.
- Requirements related to medical first-aid equipment and supplies.
- Instructions for Initial and Periodic Medical Examinations of Workers in Establishments of 2025.
This is not a universal legal checklist suitable for every factory.
Additional requirements may apply depending on:
- The industrial activity.
- Materials used.
- Types of machinery and equipment.
- Licensing conditions.
- Responsible regulatory authorities.
- Production processes.
- Number of workers.
- Classification and risk level of the activity.
The factory should therefore determine applicability rather than merely collect legislation.
Step One: Begin With a Genuine Gap Analysis
Before asking, “Are we ready for the audit?” ask:
What is the actual state of occupational health and safety in the factory today?
A Gap Analysis should compare:
- ISO 45001 requirements.
- Applicable Jordanian legal requirements.
- The factory’s documented arrangements.
- Actual practices on the factory floor.
For example:
- A written safety policy may exist, but workers may not understand it.
- A risk matrix may be available, but it may not have been updated after installing new machinery.
- Personal protective equipment instructions may be documented, while daily practices differ from those instructions.
A proper Gap Analysis does not merely search for missing documents. It identifies the difference between what is supposed to happen and what actually happens.
The assessment should include:
- Document review.
- Interviews with managers, supervisors, and workers.
- Workplace observations.
- Sampling of records.
- Tracing selected risks and controls from identification through implementation and monitoring.
- Review of incidents, near misses, and previous corrective actions.
Step Two: Establish a Legal and Other Requirements Register
One of the most important records that a factory should control before the audit is its Legal and Other Requirements Register.
It is not sufficient to list “Jordanian Labour Law.”
The register should identify:
- The applicable legislation or requirement.
- Why it applies to the factory.
- The specific obligation arising from it.
- The responsible person or function.
- The evidence demonstrating implementation.
- The method used to evaluate compliance.
- The required review frequency.
- The current compliance status.
- Any action needed to close a gap.
- How regulatory amendments are monitored.
In practical terms, the person responsible for the management system should be able to answer when the auditor asks:
- Which legal requirements apply to this factory?
- How did you determine that they apply?
- Who monitors legal and regulatory updates?
- When did you last evaluate compliance?
- What evidence supports that evaluation?
- What action was taken when a gap was identified?
A legal register should be a working control mechanism, not merely an index of legislation.
Step Three: Review the Occupational Health and Safety Policy
The policy should not be a general statement displayed at the factory entrance.
In Jordan, the Ministry of Labour lists a 2024 decision approving a model occupational safety and health policy for employers with 20 or more workers.
From an ISO 45001 perspective, the policy should also be appropriate to the organization’s purpose, context, and occupational health and safety risks.
It should address commitments relevant to:
- Providing safe and healthy working conditions.
- Preventing work-related injury and ill health.
- Eliminating hazards and reducing occupational health and safety risks.
- Fulfilling applicable legal and other requirements.
- Consulting workers and supporting their participation.
- Continually improving the occupational health and safety management system.
One question can quickly reveal whether the policy is functioning:
Can a worker or supervisor explain how the policy affects their daily work?
If the answer is no, the policy may exist only on paper.
The factory should ensure that the policy is:
- Approved by top management.
- Communicated effectively.
- Understood at appropriate levels.
- Available as required.
- Reflected in objectives, responsibilities, and operational decisions.
Step Four: Reassess Risks From the Factory Floor
This is one of the most sensitive areas in any ISO 45001 audit of a factory.
Begin with actual operations—not a generic template.
Observe:
- Production lines.
- Maintenance activities.
- Loading and unloading.
- Warehouses.
- Forklift and vehicle movement.
- Electrical work.
- Chemical handling.
- Noise.
- Heat exposure.
- Edges and moving machinery parts.
- Work at height.
- Non-routine activities.
- Contractor activities.
- Any other hazards arising from the nature of the factory.
The Jordanian Ministry of Labour publishes separate instructions for workplace risk assessment and for identifying sources of occupational hazards and the necessary preventive measures.
The Ministry also provides guidance referring to periodic review and updating of risk assessments and review whenever necessary.
The value of a risk assessment does not lie in the format of the matrix. It lies in whether the assessment reflects workplace reality.
If the risk register identifies a high-level risk, the auditor should be able to see controls proportionate to that risk.
The assessment should also reflect relevant changes, including:
- New machinery.
- New materials.
- Modified production methods.
- Changes in layout.
- New contractors.
- Changes in staffing or shifts.
- Previous incidents or near misses.
- New legal requirements.
Step Five: Do Not Treat Personal Protective Equipment as the First Solution
A common mistake in some factories is for every risk assessment to end with:
“Use personal protective equipment.”
Personal protective equipment is important, but it should not replace control at the source whenever more effective controls are reasonably available.
The factory should apply a systematic hierarchy of controls:
- Can the hazard be eliminated?
- Can the hazardous material, equipment, or method be substituted?
- Can engineering controls be introduced?
- Are administrative controls required?
- Which personal protective equipment is still necessary for the remaining risk?
This is where the strength of the management system becomes visible.
Risk management moves beyond distributing helmets and gloves and becomes a series of traceable engineering, operational, and administrative decisions.
For example, training and PPE should not be used as substitutes for a missing machine guard when an appropriate engineering safeguard is required.
Step Six: Connect Risks to Operational Controls
Once risks have been assessed, the response should be visible in operations.
Consider the following questions:
- If machinery creates a hazard, how is that hazard controlled?
- If a chemical creates a risk, how is it received, stored, used, and handled in the event of a spill?
- If a high-risk maintenance task is performed, who authorizes it?
- If a contractor enters the factory, how is competence verified and how is the contractor informed of relevant risks?
- If the production line changes, are risks reviewed before operations begin?
- If a control fails, who stops the activity and initiates corrective action?
The relationship should be traceable:
Hazard → Risk → Control → Responsible Person → Evidence → Monitoring
This connection is one of the clearest indicators of management-system maturity.
Operational controls may include, depending on the activity:
- Engineering safeguards.
- Preventive maintenance.
- Isolation and lockout arrangements.
- Safe operating instructions.
- Permit-to-work systems where appropriate.
- Inspection and testing.
- Traffic-management arrangements.
- Chemical-handling controls.
- Contractor controls.
- Supervision.
- Emergency arrangements.
- Competence requirements.
Step Seven: Verify Safety Committees and Supervisors
Jordanian requirements extend beyond assigning someone the title of “Safety Officer.”
The Formation of Occupational Safety and Health Committees and Appointment of Supervisors in Establishments Regulation No. 33 of 2023 links the applicable requirements to the number of workers and the degree of risk associated with the activity.
It requires an occupational safety and health committee to be formed in an establishment or branch employing 50 or more workers.
A factory should therefore assess precisely which provisions apply to it, including those related to:
- Occupational safety and health supervisors.
- Committee formation.
- Required approvals or recognition.
- Membership requirements.
- Roles and responsibilities.
- Meeting and record requirements.
The factory should not assume that appointing one HSE officer automatically closes this issue.
From an audit perspective, the committee should have a practical role in reviewing matters such as:
- Risks.
- Incidents.
- Worker observations.
- Complaints.
- Occupational health issues.
- Corrective actions.
- Improvement plans.
The committee should not exist solely through formal meeting minutes.
Step Eight: Demonstrate Worker Consultation and Participation
ISO 45001 places clear emphasis on consulting workers and enabling their participation.
A machine operator may identify a hazard before senior management does.
The factory should therefore provide genuine mechanisms that allow workers to:
- Report hazards.
- Raise safety observations.
- Report incidents and near misses.
- Participate in risk assessments.
- Contribute to incident investigations.
- Suggest improvements.
- Raise concerns without fear of retaliation.
The management system should not operate solely through instructions issued from the top.
An auditor may not limit interviews to the safety manager. They may speak with:
- A machine operator.
- A maintenance technician.
- A warehouse worker.
- A supervisor.
- A contractor.
The purpose is to determine whether the system is understood and applied at the operational level.
Worker participation should therefore be evident in both records and workplace practices.
Step Nine: Review Training and Competence
An attendance record does not, by itself, prove competence.
For every safety-critical role, determine:
- What knowledge is required?
- What training is necessary?
- How was the worker’s ability to perform the task safely evaluated?
- Are special qualifications or authorizations required?
- Are specific requirements applicable to supervisors or workers performing hazardous tasks?
- Does each new employee receive appropriate induction before beginning work?
- Is refresher training provided when risks, equipment, or procedures change?
Jordanian occupational safety and health regulations include obligations related to informing workers about sources of occupational hazards, explaining preventive measures, training them, and monitoring compliance with safety procedures.
Training records should therefore correspond to the actual risks of each role.
A stronger competence process follows this sequence:
Role Requirements → Training Need → Training Delivery → Practical Evaluation → Authorization Where Required → Periodic Review
Step Ten: Do Not Neglect Occupational Health
Occupational health and safety is not limited to immediate accidents.
Workers may also face exposures that cause health effects over time, depending on the factory’s activities. These may include:
- Noise.
- Chemical substances.
- Dust.
- Heat stress.
- Vibration.
- Ergonomic factors.
- Other occupational exposures.
The Ministry of Labour currently lists the Preventive and Curative Medical Care for Workers in Establishments Regulation No. 32 of 2023.
It also lists the Instructions for Initial and Periodic Medical Examinations of Workers in Establishments of 2025 within Jordan’s occupational safety and health legislative framework.
Occupational health surveillance should therefore be linked to the type and level of exposure identified through the factory’s risk assessment.
General medical examinations conducted without reference to occupational exposure may not adequately address the factory’s actual risks.
The organization should determine:
- Which workers are exposed?
- What examination or surveillance is required?
- How frequently should it be conducted?
- Who is authorized to conduct it?
- How are confidentiality and medical information handled?
- How are findings translated into preventive actions?
Step Eleven: Test the Emergency Plan
Displaying an evacuation plan does not mean that the factory is prepared for an emergency.
Emergency scenarios should arise from the facility’s actual risks.
Depending on the operation, relevant scenarios may include:
- Fire.
- Chemical release.
- Serious injury.
- Significant equipment failure.
- Utility interruption.
- An incident involving a particular material or production process.
- Another event identified through the factory’s risk assessment.
The system should define:
- Responsibilities.
- Communication arrangements.
- Alarm mechanisms.
- Assembly points.
- Emergency equipment.
- Coordination with external responders where relevant.
- Evacuation or containment procedures.
- Arrangements for people requiring assistance.
Practical drills should be conducted, their results recorded, and the emergency plan improved based on the weaknesses revealed.
ISO 45001 includes emergency preparedness and response as a core component of the occupational health and safety management system.
Step Twelve: Review Accidents, Injuries, Near Misses, and Occupational Diseases
An incident investigation should not become a search for an answer to one question:
“Who made the mistake?”
The objective is to understand why the incident was able to occur.
Ask:
- Was the procedure unsuitable?
- Was an engineering safeguard missing?
- Was training insufficient?
- Did production pressure affect compliance?
- Had the hazard been identified previously without effective action?
- Did supervision fail?
- Was the risk assessment incomplete or outdated?
- Did a change occur without prior assessment?
The Jordanian Ministry of Labour currently lists approved forms for reporting occupational accidents, injuries, and diseases issued in 2024, as well as defined occupational safety and health records that establishments are required to retain.
From an ISO 45001 perspective, investigation findings should lead, where necessary, to:
- Immediate correction or containment.
- Root-cause analysis.
- Corrective action.
- Review of risk assessments.
- Review of operational controls.
- Communication of lessons learned.
- Evaluation of action effectiveness.
Closing the incident report does not necessarily mean that the underlying problem has been resolved.
Step Thirteen: Prepare Evidence Before the Audit
Before the external audit, conduct a genuine readiness review.
Do not merely arrange the files. Walk through the factory from the auditor’s perspective.
Practical ISO 45001 Pre-Audit Checklist
- The occupational health and safety management-system scope is defined and consistent with actual operations.
- The occupational health and safety policy is approved, understood, and implemented.
- The legal and other requirements register is current.
- Compliance with applicable requirements has been evaluated.
- Risk assessments cover routine activities, non-routine activities, relevant changes, and emergency situations.
- Operational controls are implemented and can be observed on site.
- Requirements for supervisors and the safety committee are fulfilled where applicable.
- Training and competence are documented and proportionate to the relevant risks.
- Contractors, visitors, and relevant suppliers are subject to defined controls.
- Emergency scenarios have been identified and response arrangements tested.
- Incidents, injuries, occupational diseases, and near misses are investigated and addressed.
- Applicable occupational health and medical requirements have been identified and followed.
- Required occupational health and safety records are available and current.
- An internal audit has covered the system, workplace, and applicable legal requirements.
- Nonconformities have been closed or are subject to traceable corrective actions.
- Top management has reviewed the system and made clear improvement decisions.
The evidence should arise naturally from system operation. Records created retrospectively immediately before an audit may reveal that the system has not been operating as described.
Step Fourteen: Conduct an Internal Audit That Goes Beyond Paperwork
The internal audit is the factory’s best opportunity to identify weaknesses before the external audit.
It should combine:
- Document review.
- Interviews.
- Workplace observation.
- Sampling.
- Evidence tracing.
For example:
If the factory states that a forklift is inspected daily, the internal auditor should select samples from previous days and compare the records with current workplace conditions.
If a procedure requires specific protective equipment, actual practices on the factory floor should match the procedure.
If contractor induction is mandatory, the auditor should review a sample of contractor records and speak with contractors where appropriate.
IAC’s consulting and training framework for ISO 45001 includes:
- Hazard identification.
- Risk matrices.
- Operational-control measures.
- Workplace and desk-based auditing.
- Nonconformity management.
- Improvement planning.
A meaningful internal audit tests whether the system works—not merely whether documents exist.
Step Fifteen: Confirm That Management Review Has Taken Place
Before the external audit, the organization’s leadership should have genuinely reviewed the system’s performance.
Management review is not simply a presentation showing the number of accidents.
It should help management make decisions concerning:
- Overall performance.
- Principal risks.
- Compliance status.
- Audit results.
- Resources.
- Objectives.
- Relevant changes.
- Corrective actions.
- Opportunities for improvement.
- The continuing suitability, adequacy, and effectiveness of the system.
The outputs should identify:
Decision → Responsible Person → Required Resources → Target Date → Follow-Up
The auditor will look for evidence of leadership’s role in the system, not only the activities of the safety officer.
Common Weaknesses Identified During Factory Audits
The most significant problems are not always missing documents.
A factory may have excellent documentation while a site visit reveals a different reality.
Common examples include:
- An outdated risk assessment that does not reflect newly installed equipment.
- Written procedures that workers do not understand.
- Excessive reliance on personal protective equipment.
- Weak contractor control.
- Failure to update risk assessments following incidents.
- Documented training without evidence of competence.
- An outdated legal register.
- Emergency plans that have never been tested.
- Nonconformities closed administratively without addressing the root cause.
- Inconsistency between written controls and workplace practices.
- Safety responsibilities concentrated entirely in the HSE function.
- Insufficient worker participation.
- Performance indicators collected but not used for decision-making.
These weaknesses indicate that the organization may have a documented system without having a fully implemented management system.
Does a Legal Noncompliance Affect an ISO 45001 Audit?
ISO 45001 requires the organization to establish a method for:
- Identifying applicable legal requirements.
- Understanding how they apply.
- Evaluating compliance.
- Taking action when noncompliance is identified.
Ignoring an applicable legal requirement—or lacking a method to determine compliance status—may therefore create a significant management-system issue.
However, two distinct roles must be understood:
The Jordanian regulatory authority applies and enforces legislation within its statutory powers.
The ISO certification body assesses whether the management system conforms to ISO 45001 within the audit scope and according to its certification procedures.
ISO certification does not replace governmental inspection and does not provide immunity from legal responsibility.
What Is IAC’s Role in Preparing Factories for ISO 45001?
Ideal Additions Consulting & Training (IAC) approaches ISO 45001 as a system for managing risk, compliance, and performance—not as a set of files prepared shortly before an audit.
IAC’s documented scope of services includes:
- Hazard identification and risk assessment.
- Development of risk registers.
- Development of operational-control plans.
- Alignment of the system with relevant legislation and regulatory requirements.
- Support for occupational health and safety culture.
- Internal auditing.
- Continual-improvement programmes.
- Measurement of control effectiveness.
Engagements are managed according to IAC’s methodology:
Objective Diagnosis → Tailored Design → Phased Implementation → Internal Capability Building → Impact Measurement
The objective is not to promise that the organization will “pass the audit.”
The objective is to improve its readiness by establishing an implemented and auditable system and addressing the gaps identified before the external assessment.
Frequently Asked Questions
Must Every Factory in Jordan Establish an Occupational Safety and Health Committee?
Not necessarily under the same conditions.
Regulation No. 33 of 2023 links the applicable requirements to the number of workers and the degree of risk associated with the activity.
One of its principal thresholds requires a committee to be established in an organization or branch employing 50 or more workers.
The full regulation should be reviewed to determine precisely what applies to each establishment, including requirements related to supervisors and committee formation.
Is Appointing a Safety Officer Sufficient for ISO 45001?
No.
The management system covers leadership, workers, processes, risks, compliance obligations, emergency preparedness, incident investigation, internal auditing, performance evaluation, and improvement.
It is not limited to the role of the safety officer.
Can We Use a Risk Assessment From Another Factory?
This is not recommended.
The assessment should reflect the factory’s own:
- Activities.
- Machinery.
- Materials.
- Workers.
- Workplace conditions.
- Contractors.
- Non-routine activities.
- Operational changes.
A copied assessment may overlook the facility’s actual hazards.
Is OSHA a Substitute for Jordanian Law or ISO 45001?
No.
Selected OSHA practices may be used as professional guidance where appropriate. IAC’s materials expressly position such references as guidance when relevant—not as certification or as a substitute for national legal requirements.
Can Passing the Audit Be Guaranteed?
No professional consultant should guarantee the decision of an independent certification body.
The organization’s readiness can be improved, its gaps can be addressed, and internal audits can be conducted. The certification decision remains with the certification body, based on its audit findings and procedures.
Important 2026 Update
As of 17 August 2026, ISO 45001:2018 remains the current published edition.
ISO confirmed the standard’s review in 2024, and the related ISO 45001:2018/Amd 1:2024 amendment is also applicable. A new revision of the standard is currently under development.
When beginning a new implementation project or planning an audit during the coming period, the organization should therefore verify:
- The latest official status of the standard.
- Any officially published transition requirements.
- Requirements communicated by its certification body.
A draft revision should not be treated as an effective international standard before it is officially published.
Conclusion
Readiness for an ISO 45001 audit cannot be achieved by gathering files in a meeting room.
The factory that is most prepared can demonstrate that:
- Hazards have been identified.
- Risks have been assessed.
- Controls are implemented.
- The Jordanian legislation applicable to its activities is known and monitored.
- Workers participate in the system.
- Emergency arrangements have been tested.
- Lessons are learned from incidents.
- Internal auditing identifies problems before the external auditor does.
- Management uses the system to make decisions and improve performance.
At IAC, readiness begins by diagnosing the current state and comparing it with ISO 45001 requirements and the applicable legal obligations. The findings are then converted into an implementation plan that addresses priority gaps and enables the factory’s teams to manage the system continually.
To request an initial diagnostic session assessing your factory’s readiness for ISO 45001 and external auditing, contact IAC to define the scope of work and identify the priority gaps.
