Framework overlap

Does ISO/IEC 27003:2017 cover ISO 45001?

You hold ISO/IEC 27003:2017 and have been told to do ISO 45001. Here is how much overlaps, control by control.

41% of ISO 45001 you already have

ISO/IEC 27003:2017 already covers about 41% of ISO 45001, leaving 23 of 39 controls as genuinely new work.

Already covered 2 Likely covered 14 New work 23

What is genuinely new work

Nothing in ISO/IEC 27003:2017 reaches these. This is the list to scope.

ISO45001-01
OH&S policy and commitment
ISO45001-04
OH&S objectives and action plans
ISO45001-05
Worker consultation and participation
ISO45001-06
Elimination and substitution of hazards
ISO45001-07
Engineering and administrative controls
ISO45001-08
Personal protective equipment management
ISO45001-09
Emergency preparedness and response
ISO45001-10
Contractor and visitor safety management
ISO45001-11
Incident investigation and reporting
ISO45001-12
OH&S monitoring and measurement
ISO45001-13
Internal OH&S audit program
ISO45001-14
Management review and continual improvement
ISO45001-4.3
Determining scope of OH&S management system
ISO45001-5.2
OH&S policy
ISO45001-5.4
Consultation and participation of workers
ISO45001-6.1.2
Hazard identification and assessment of risks
ISO45001-6.1.3
Determination of legal and other requirements
ISO45001-6.1.4
Planning action
ISO45001-8.1.2
Eliminating hazards and reducing OH&S risks
ISO45001-8.1.3
Management of change
ISO45001-8.1.4
Procurement and contractors
ISO45001-8.2
Emergency preparedness and response
ISO45001-9.1.2
Evaluation of compliance
Show the 16 you already have
ISO45001-02
Hazard identification and risk assessment
ISO45001-15
Corrective actions and lessons learned
ISO45001-03
Legal and regulatory compliance
ISO45001-10.2
Incident, nonconformity and corrective action
ISO45001-10.3
Continual improvement
ISO45001-4.1
Understanding the organization and its context
ISO45001-4.2
Needs and expectations of workers and interested parties
ISO45001-5.1
Leadership and commitment
ISO45001-5.3
Roles, responsibilities and authorities
ISO45001-6.2
OH&S objectives and planning to achieve them
ISO45001-7.2
Competence
ISO45001-7.3
Awareness
ISO45001-7.4
Communication
ISO45001-9.1
Monitoring, measurement, analysis and evaluation
ISO45001-9.2
Internal audit
ISO45001-9.3
Management review

How this is calculated

Already covered means a mapping runs from a control in ISO/IEC 27003:2017 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition