What this is
What is a safety management plan under ISO 45001?
What is a safety management plan under ISO 45001?
It is the site-level document setting out how safety is actually managed: the policy, who is accountable for what, the core processes — hazard identification, risk assessment, incident reporting, investigation, audit, emergency response, contractor and change management — and how performance is measured. ISO 45001 cl.5.2 requires the policy; the plan carries the rest of clause 5, plus the measurement obligations of clause 9, in one place.
How is a safety management plan different from a safety policy?
A safety policy is a short statement of intent, often a single page, signed by senior leadership. The safety management plan is the operating document behind it — it names the processes that make the policy real, assigns owners, sets a measurement regime and records when it was last reviewed. A site can have a signed policy and still fail an audit if the plan behind it doesn't exist or hasn't been reviewed.
Who should own a safety management plan?
The site manager, per this template's Plan Owner field, with a named Approved By signature from a more senior role. Ownership at site level matters because the plan has to reflect what is actually running on that site — a corporate template signed off centrally and never adapted locally is one of the most common findings against this document.
Scope
When is a safety management plan required?
This plan is one step in a larger programme. Using it for work that belongs to a neighbouring template produces records that are hard to report on later.
Use this template when
- The site's overall safety governance is being established for the first time, or the current plan is a year or more old
- A new site is standing up its safety management system and needs the foundation document before any process-specific programme is authorised
- A new record is needed; each one gets its own ID in the form SMP-2026-000
- You are running the Safety Programme Management programme and this plan is the step that sets the year's structure
- A linked record needs this one to exist — objectives, management review and the process-specific programmes all reference the plan that authorises them
Do not use it for
- Annual Safety Objectives, which sets the safety goals for the year with measures, owners and target dates — the targets, not the governance structure they sit inside.
- Safety Program Review, which reviews how a specific programme, such as PPE or working at height, is performing — a narrower, recurring check, not the plan itself.
- Site Safety Rules, which is the short list of rules everyone on site must follow, including visitors and contractors — worker-facing, not a management document.
- Contractor Safety Plan, which covers contractor arrangements in enough depth that duplicating them here just creates two documents to keep in sync.
- Anything outside KnowSafe, which belongs in the workspace that owns that process.
Compliance mapping
Which ISO 45001 cl.5.2 requirements does this satisfy?
The plan is built mainly against ISO 45001 clause 5, with clause 6 and 9 obligations folded into the Measurement section rather than split into a separate document.
| Clause | Requirement | Where it lands |
|---|---|---|
| 5.2 | Establish, document and communicate a safety policy | Policy and leadership |
| 5.3 | Assign and communicate roles, responsibilities and authorities | Roles and resources |
| 5.4 | Establish arrangements for worker consultation and participation | Roles and resources |
| 6.1.2 | Define the process for hazard identification and risk assessment | Core processes |
| 8.1.4 | Define arrangements for controlling contracted work | Core processes |
| 8.2 | Define emergency preparedness and response arrangements | Core processes |
| 9.1 | Determine what is monitored, measured and reported, including leading indicators | Measurement |
| 9.3 | Set the cadence and inputs for management review | Measurement |
What it does not cover
- Safety Policy Signed By Senior Leader, which sits at Partial when the policy is dated and filed but was never actually countersigned by the leader the plan names as accountable.
- Worker Participation Arrangements, which scores No when the consultation forum the plan describes hasn't met once in the review period.
- Critical Risk Programme Defined, which is marked Fail when the plan names critical risks but has no linked programme record for any of them.
- Leading Indicators Defined, which fails when every measure in the plan is lagging — incident and injury counts — with nothing that would catch a problem before it produces one.
- Management Review Cadence Defined, which stays Partial when a cadence is stated but the linked Management Review Record shows no meeting held against it this cycle.
Global
Safety Management Plan requirements by country
ISO 45001 itself is voluntary everywhere, but the plan it produces gets pulled into statutory and contractual requirements that vary by where the site sits.
Health and Safety at Work etc. Act 1974, s.2(3)
Statutory duty on employers with five or more staff to prepare and keep up to date a written policy statement on health and safety.
The Policy and leadership section here does double duty — ISO evidence, and for a UK site, part of a legal document a regulator can ask to see directly.
Framework Directive 89/391/EEC, Art. 6
Requires a coherent overall prevention policy covering technology, work organisation and working conditions, not a single safety statement.
A plan copied from a corporate template without local adaptation is the specific gap this article targets — coherence must be shown at the site, not asserted at head office.
ISO 45001:2018 certification
Voluntary, but increasingly written into tender and supply-chain approval requirements rather than mandated by any regulator.
Where no domestic statute is this strict, the plan's real enforcement is commercial — losing certification because the plan doesn't reflect reality can cost a contract before it costs a fine.
How to complete it
How to complete a safety management plan, step by step
Most of the fields here are yes/no in form, but several carry a judgement call that decides whether the plan holds up when someone other than its author reads it.
The Pass/Partial/Fail scale runs across a dozen fields, and Partial covers two very different situations: a process that's half-built and one that decayed. The plan doesn't distinguish them, so the reviewer has to — a Partial with a remediation date is a different risk to a Partial that's stayed Partial for three review cycles running.
This is free text, and 'leadership will prioritise safety' isn't meaningfully different from a blank field. The judgement call is whether the commitments named are specific enough to check later — a named leader doing a named thing on a named cadence, not a sentiment.
Action Required can be marked Yes without immediately forcing a CAPA ID — that field only appears once Action Required is Yes, and it's text, not a hard link. A completed-looking plan can still carry open actions with no CAPA behind them at all.
Next Review Due is required, with nothing forcing it to relate to what changed. The judgement call sits with whoever approves the plan: does the date reflect an actual planned review, or arithmetic on the previous plan's date.
What auditors find
Most common safety management plan findings
The gaps that recur in practice sit less in missing fields and more in fields that are technically answered but not backed by anything.
| Finding | Clause | What fixes it |
|---|---|---|
| Policy is signed but was never actually communicated to the workforce, so Policy Communicated To All Workers is scored on assumption rather than evidence. | ISO 45001 cl.7.4 | Tie the field to a communication record — a toolbox talk register, induction sign-off, or notice board audit — rather than the site manager's word for it. |
| Roles are defined in the plan but the workers named against them have never seen their own accountability written down. | ISO 45001 cl.5.3 | Sample a handful of role-holders at review time and ask them to describe their accountability in their own words before scoring Accountabilities Defined By Role a Pass. |
| Hazard Identification Process Defined and Risk Assessment Process Defined are both marked Pass with no reference to an actual, current risk register. | ISO 45001 cl.6.1.2 | Require the Clause Reference or a risk register link before either field can be scored above Partial. |
| Audit Programme Defined is Pass despite no completed regulatory inspection or internal audit in the current cycle. | ISO 45001 cl.9.2 | Cross-check against the site's Regulatory Inspection Record for the period before accepting the score. |
| Leading Indicators Defined is Pass on paper but nothing downstream ever reports against the named leading measures. | ISO 45001 cl.9.1 | Require the named leading indicators to appear in the next Management Review Record before the plan's measurement section is treated as closed. |
| Contractor Management Defined is scored without reference to the site's actual contractor safety plan, so the two documents can silently drift apart. | ISO 45001 cl.8.1.4 | Link the field to the site's live Contractor Safety Plan record rather than scoring it as a standalone statement. |
Case in point
Case in point: the plan that passed every field and still missed the incident.
A site plan scored Pass or Yes across every field in Policy, Roles and Core processes going into its annual review, including Contractor Management Defined. Three months later a contractor was injured doing work that field claimed was covered.
The post-incident review found the contractor management process the plan pointed to hadn't been updated since the previous contractor left site eighteen months earlier — scored against a process that existed in name only. Only cross-checking the claim against the live Contractor Safety Plan record would have caught it.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
5 sections
- Reference
- SAF-121
- Archetype
- Plan
- Record ID
- SMP-2026-000
- Scoring
- Not scored
- Direction
- n/a
- Singleton
- No
- Basis
- ISO 45001 cl.5.2
- Links
- Links Site, Objectives
- Tags
- Programme, Governance
- Sections
- 5
- Fields
- 47
- Follow up fields
- 3
- Repeating sections
- 0
- Links out
- 5
Header
9 fieldsPlan ID*
Auto sequence. Format SMP-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Plan Version*
Issue Date*
Next Review Due*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Plan Owner*
Approved By*
Policy and leadership
4 fieldsSafety Policy Signed By Senior Leader*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Policy Communicated To All Workers*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Policy Reviewed This Year*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Leadership Commitments Defined*
Roles and resources
5 fieldsAccountabilities Defined By Role*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Safety Resource Adequate*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Budget Identified*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Competence Requirements Defined*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Worker Participation Arrangements*
- Yes3 pts
- Partly1 pt
- No0 pts
Core processes
12 fieldsHazard Identification Process Defined*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Risk Assessment Process Defined*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Critical Risk Programme Defined*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Incident Reporting Process Defined*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Investigation Process Defined*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Action Management Process Defined*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Inspection Programme Defined*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Audit Programme Defined*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Emergency Arrangements Defined*
- Yes3 pts
- Partly1 pt
- No0 pts
Contractor Management Defined*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Change Management Defined*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Document Control Defined*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Measurement
17 fieldsLeading Indicators Defined*
A plan measured only on injury rates measures the past.
- Yes3 pts
- Partly1 pt
- No0 pts
Lagging Indicators Defined*
- Yes3 pts
- Partly1 pt
- No0 pts
Reporting Cadence Defined*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Objectives ID
Links to SAF-122 Objectives ID
Management Review Cadence Defined*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Clause Reference
Clause ID
Format CLS-0000.
Links to FDN-009 Clause ID
Plan Document
Document ID
Format DOC-0000.
Links to FDN-008 Document ID
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Plan Owner*
Signature*
Site Manager*
Second Signature*
SAF-121 · record IDs look like SMP-2026-000 · Links Site, Objectives
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The form is the easy part. Keeping the plan current, tying its claims to the records that back them and getting the right people to actually sign is the work that slips.
Holds the safety management plan against the site's actual registers — risk, incidents, audits — and flags a field scored Pass with no linked evidence behind it.
Tracks the plan's review cadence and clause coverage against the certification scope, so a lapsed review shows up before an external auditor finds it first.
Keeps competence requirements and role accountabilities in the plan matched against who's actually trained and current, not just who's named.

Coordinates the crew across these workspaces, rolls completion and exceptions into one view, and holds every write for your approval before it touches a record.
This template lives in KnowSafe — safety and compliance. Incidents, hazards, permits, inspections and the critical controls behind them.
Meet KnowSafe→Glossary
Safety Management Plan definitions and key terms
- Safety management plan (SMP)
- The site-level document that sets out policy, roles, core processes and measurement for how safety is managed, reviewed on a fixed cycle and owned by the site manager.
- Leading indicator
- A measure that predicts risk before harm occurs — training completion, inspection closure rate, near-miss reporting volume — and that people can act on directly.
- Lagging indicator
- A measure of harm that has already occurred — injury rate, lost time, incident count — useful for trend but not for prevention.
- Worker participation
- Formal arrangements, beyond consultation, for workers to contribute to and influence safety decisions that affect them, required under ISO 45001 cl.5.4.
- Management review
- A scheduled, senior-level review of the safety management system's performance, inputs and outputs, required under ISO 45001 cl.9.3 and fed by this plan's measurement section.
FAQ
Frequently asked questions about safety management plan
Does a safety management plan need to be a single document?+
No — this template treats it as a single record with linked sections, but the underlying processes it points to (hazard ID, risk assessment, incident reporting) can and usually do live in their own registers. The plan is the index and the accountability layer, not a rewrite of every process it references.
How often should the plan actually be reviewed, beyond the stated yearly cycle?+
Yearly is the floor, not the target. Any material change — a new critical risk, a site reorganisation, a serious incident — should trigger an out-of-cycle review, which is why Next Review Due is a live field rather than a fixed anniversary.
Can a site pass an ISO 45001 audit without this plan?+
In principle an auditor only needs the documented information the standard requires, but in practice certification bodies expect something functionally equivalent — a single place showing policy, roles, processes and measurement connect. Without it, an auditor has to piece the system together from separate records, which rarely goes well.
Who signs off the plan — the site manager or someone more senior?+
Both. Plan Owner sits with the site manager, and Approved By is a separate, more senior signature. The template also carries a Site Manager and Second Signature field at the end, which is the actual sign-off event distinct from day-to-day ownership.
What happens if Action Required is marked Yes and never resolved?+
Nothing automatic — the field only reveals Priority, CAPA ID and Action Owner, none of which are hard-linked to a closure check. An open action with a low Priority can sit unresolved indefinitely unless someone tracks it outside the plan.
Does scoring the plan's fields actually measure safety performance?+
No, and the template doesn't claim to — catalogue scoring is marked 'Not scored' at the template level for a reason. The individual field scores are a completeness and quality check on the plan itself, not a proxy for how safe the site actually is.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Safety Programme Management
Regulatory Inspection Record
Records a visit by a regulator, including what was inspected, what was said and any orders issued
Management Review Record
Records the periodic review of the management system by senior leadership, covering performance, risks, resources and improvement
Interested Party Register
Holds the parties whose needs shape the management system, from regulators and customers to neighbours and the workforce
Annual Safety Objectives
Sets the safety goals for the year with measures, owners and target dates
Safety Program Review
Reviews how a specific programme, such as PPE or working at height, is performing
Site Safety Rules
The short list of rules everyone on site must follow, including visitors and contractors
More in Programs
Annual Safety Objectives
Sets the safety goals for the year with measures, owners and target dates
Safety Program Review
Reviews how a specific programme, such as PPE or working at height, is performing
Site Safety Rules
The short list of rules everyone on site must follow, including visitors and contractors
PPE Program Plan
Sets out what protective equipment is required for which task, how it is selected, issued, maintained and replaced
Hearing Protection Program Plan
Sets out how noise exposure is controlled, including monitoring, protection, training and hearing tests
Contractor Safety Plan
Sets out the safety requirements contractors must meet on your site, and how they are checked

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 45001:2018 — Occupational health and safety management systems, cl.5
- ISO 45001:2018 — cl.9.1 Monitoring, measurement, analysis and performance evaluation
- Health and Safety at Work etc. Act 1974, s.2(3)
- EU Framework Directive 89/391/EEC, Art. 6
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.