How do I ensure compliance with EU REACH and ISO 45001?
What REACH and ISO 45001 require from a company that uses chemicals, how the two overlap, and a map of the records you need: substance register, SDS, risk assessments, training, permits, incidents and audit trail.
Last reviewed: 14 September 2026
Short answer: REACH tells you what you must know and do about each chemical you use; ISO 45001 tells you how to run the management system that proves you know and do it. Compliance with both comes down to a small set of connected records: a hazardous substances register with current safety data sheets and GHS/CLP classification, activity-based risk assessments, training and competence records, permits and operational controls, incident investigations with corrective actions, a legal register, and an audit trail. Keep those records in one system and both audits become routine.
REACH in one paragraph for most companies
Regulation (EC) 1907/2006 (REACH) puts most obligations on manufacturers and importers. Most industrial companies are downstream users. Your duties are:
- Hold a current safety data sheet (SDS) for every hazardous substance or mixture (REACH Article 31; extended SDS with exposure scenarios where applicable).
- Use substances within the identified uses and apply the risk management measures in the SDS (Article 37).
- Classify, label and package correctly under the CLP Regulation (EC) 1272/2008, which implements GHS in the EU.
- Check the Candidate List of substances of very high concern (SVHC), the Authorisation List (Annex XIV) and restrictions (Annex XVII), and act on substitutions or authorisations.
- Inform workers about hazards and controls. In Germany this is reinforced by the Hazardous Substances Ordinance (GefStoffV) with its own register and instruction duties (§6 and §14).
ISO 45001 in one paragraph
ISO 45001:2018 is the management-system standard for occupational health and safety. An auditor checks whether you have: understood your context and legal requirements (4, 6.1.3), leadership and worker participation (5), hazard identification and risk assessment (6.1.2), objectives and KPIs (6.2), competence and awareness (7.2, 7.3), documented information (7.5), operational controls including permits and management of change (8.1), emergency preparedness (8.2), monitoring and internal audit (9), incident investigation and corrective action (10.2), and continual improvement (10.3).
Where the two overlap: the records you need
| Requirement | REACH / CLP / GefStoffV | ISO 45001 clause | Record in QuickInspect |
|---|---|---|---|
| Know your substances | SDS, classification, register | 6.1.2, 7.5 | Hazardous materials register with GHS/CLP classes, pictograms, H/P statements, PubChem lookup, SDS upload with AI extraction |
| Know the law | REACH, CLP, GefStoffV obligations | 6.1.3 | Legal register with AI-suggested entries you confirm |
| Assess the risk | Exposure and risk management measures | 6.1.2 | Activity-based risk assessment linked to substances |
| Control the work | Conditions of use | 8.1 | Permits to work with pre-checks, zone conflict checks and certificate checks |
| Instruct workers | GefStoffV §14 instruction | 7.2, 7.3 | Trainings, assessments, certificates, competency matrix |
| Investigate incidents | Exposure incidents | 10.2 | Incident reports, 5-Why, corrective actions |
| Prove it | Register and instruction records | 7.5, 9.2, 9.3 | Audit trail, controlled documents, ISO 45001 compliance report (Key User) |
A five-step compliance routine
- Build the substance register. Enter every hazardous substance with its safety data sheet. QuickInspect can fetch the GHS classification from PubChem by CAS number and extract hazard statements, exposure limits, PPE and storage information from the uploaded SDS with AI, showing a confidence level for each field for you to confirm. SDS versions are tracked, so you always reference the current sheet.
- Maintain the legal register. Record which regulations apply to which site and what they oblige you to do. QuickInspect's AI proposes applicable entries based on your company profile; it never writes to the register itself. Review it when the law changes or when a new substance or process arrives.
- Link substances to activities and risk assessments. Every activity that uses a substance gets the exposure hazard rated and the SDS risk management measures documented as controls. Record substitution decisions.
- Gate high-risk work with permits and training. Permits to work should only be issued when the risk assessment, hazardous materials data and required training are in place. QuickInspect's authorisation runs hard-stop pre-checks, checks conflicts with other permits in the same zone, and lets workers accept only after their certificates and induction are verified.
- Export the evidence. Before an internal or external audit, export the ISO 45001 compliance report (Key User plan) and review the audit trail.
Germany-specific notes
- GefStoffV §6 requires a hazardous substances register (Gefahrstoffverzeichnis) and a substance-specific risk assessment; §14 requires written operating instructions (Betriebsanweisungen) and instruction at least once a year.
- The technical rules (for example TRGS 400 on risk assessment and TRGS 555 on operating instructions) describe how.
- DGUV rules add sector-specific requirements and inspection intervals.
QuickInspect's legal register suggests which of these, together with the ArbSchG, BetrSichV, TRBS, REACH and CLP, apply to your company, and your team can add customer or industry standards. Start free on iOS, Android or the web.
Frequently asked questions
Does ISO 45001 cover chemical safety?
Indirectly. ISO 45001 requires you to identify hazards (including chemical ones), assess risks, apply the hierarchy of controls and keep documented information. REACH and CLP define the chemical-specific obligations. A hazardous materials register linked to risk assessments serves both.
What are my REACH obligations as a downstream user?
Use substances within the conditions described in the safety data sheet and exposure scenarios, keep current safety data sheets, apply the risk management measures, communicate hazards to workers, and check whether any substance is on the Candidate List, the Authorisation List (Annex XIV) or subject to restrictions (Annex XVII).
Can software make a company ISO 45001 certified?
No, certification is done by an accredited body. Software provides the evidence: risk assessments, objectives, training records, permits, incident investigations, actions and an audit trail. On the Key User plan, QuickInspect's compliance reports produce an ISO 45001 PDF from that evidence.
Is a safety data sheet enough for REACH compliance?
No. You must also implement the risk management measures it describes, keep it current, instruct workers and document where and how the substance is used. That is what a hazardous materials register is for.
Related guides
- How to compare EHS softwareWhat matters when choosing EHS or health and safety software: evaluation criteria, common mistakes in the selection process, and the questions to ask in a vendor demo.
- One platform for all HSE functionsWhy one HSE platform beats a stack of point tools: linked data from risk assessment to action, one audit trail, fewer logins, better reporting, lower cost, and what to check before you consolidate.
- Cost of an HSE system with AIRealistic cost ranges for HSE software with AI: per-user SaaS pricing versus enterprise EHS suites, hidden implementation costs, and a worked example for a 50-person site.
- Build a safety programA step-by-step plan for building a workplace safety program: risk assessment first, then an inspection schedule, actions, training, KPIs and review, aligned with ISO 45001 and German ArbSchG duties.