SHEMS stands for Safety, Health and Environment Management System — the single framework an organisation uses to manage occupational safety risks, worker health exposures and environmental impacts through one set of processes rather than three parallel ones.
Here is the distinction most explainers skip: you cannot be certified to SHEMS. SHEMS is your system. ISO 45001 and ISO 14001 are the yardsticks you measure it against and certify to. Confusing the two is why sites end up buying a certificate instead of building something that works.
I audit these systems for a living, and the certificate is rarely where they fail. In 70+ audits across 14 countries, the gap I write up most often is between what the system documents claim happens and what the shift on the ground actually does.
Scope: This article covers international practice with US, UK, EU and ISO positions compared. It is written for HSE managers, site leads and anyone tasked with building or fixing a management system. It is not legal advice for a specific site.
Key takeaways
The short version, before the detail:
- SHEMS is an organisation's own integrated system; ISO 45001:2018 and ISO 14001:2026 are the certifiable standards it is built and audited against.
- ISO 14001:2026 was published on 15 April 2026, starting a three-year transition — most SHEMS guidance online still cites the withdrawn 2015 edition.
- ISO 45001 is mid-revision: the Draft International Standard ballot ran from 16 June to 8 September 2026, with publication expected in 2027.
- There is no federal US requirement to have a safety and health management system; UK law compels the written core through HSWA s.2(3) and MHSWR 1999 Reg. 5.
- The elements are the easy part. What separates a working SHEMS from a documented one is whether each element produces evidence a stranger can trace.
What SHEMS stands for, and what it is not
SHEMS is an acronym for Safety, Health and Environment Management System. It describes an organisation-wide framework covering how hazards and environmental aspects are identified, how risks are evaluated and controlled, who is accountable, and how performance is measured and improved. What makes it a SHEMS rather than three systems is that safety, occupational health and environment share those processes instead of each running its own.
The acronym itself is unstable across the industry, which causes real confusion in tenders and audits. The letters shuffle by region and by employer, and none of the variants means anything different in substance.
Where you meet each version:
| Acronym | Full form | Typically seen in |
|---|---|---|
| SHEMS | Safety, Health and Environment Management System | Capital projects, oil and gas, Gulf and Asia-Pacific operators |
| HSEMS / HSE-MS | Health, Safety and Environment Management System | European industry, energy majors, IOGP-aligned contractors |
| EHSMS | Environment, Health and Safety Management System | US corporate structures, where environmental sits with legal |
| SMS | Safety Management System | Aviation, rail, maritime — usually excludes the environmental leg |
| IMS | Integrated Management System | Where quality (ISO 9001) is folded in alongside safety and environment |
Two things a SHEMS is not. It is not a certificate, for the reason above. And it is not a manual — a set of procedures with no assigned owners, no monitoring and no review cycle is a document library, not a management system, however thick it is.
One disambiguation worth clearing up, because it splits the search results: in the energy and utilities sector, SHEMS also stands for Smart Home Energy Management System, an unrelated domestic energy control technology. If that is what brought you here, this article is not about it.
The distinctions that matter when you are assessing whether an organisation genuinely has one:
- Ownership is named, not implied. Every process has a person accountable for it, and that person knows they own it.
- The three domains share machinery. One risk register, one audit programme, one corrective action tracker, one competence matrix — not three of each.
- It produces records as a by-product of operating, not records generated the week before a certification audit.
- It changes. A system that has not been revised in two years is not being used.

Is a SHEMS legally required?
This is the question competitor explainers skip, and the honest answer is: partly, and it depends entirely on where you operate. No jurisdiction requires you to hold an ISO certificate. Several require the documented core of a management system, and one large one does not.
United States
There is no federal OSHA standard requiring a safety and health management system. OSHA's Recommended Practices for Safety and Health Programs (OSHA 3885) set out seven core elements. They are management leadership, worker participation, hazard identification and assessment, hazard prevention and control, education and training, program evaluation and improvement, and coordination on multi-employer worksites. All of it is advisory, and none of it creates a new legal duty.
Individual standards do require written programmes for specific hazards: hazard communication, respiratory protection, permit-required confined spaces, lockout/tagout, bloodborne pathogens. So a US employer ends up with a shelf of mandatory programmes and no legal obligation to connect them. State plans differ. OSHA's own April 2016 review of state activity counted twenty-four states requiring a safety plan or programme of all or some employers, with five — California, Minnesota, Montana, Nebraska and Washington — requiring one of every employer; the rest tie the duty to headcount, industry or claims experience. California's Injury and Illness Prevention Program standard is the best known of them.
United Kingdom
The UK compels the written core. Section 2(3) of the Health and Safety at Work etc. Act 1974 requires a written statement of general policy plus the organisation and arrangements for carrying it out, with the 1975 Exception Regulations excusing employers of fewer than five employees. Regulation 5 of the Management of Health and Safety at Work Regulations 1999 then requires arrangements for the effective planning, organisation, control, monitoring and review of preventive and protective measures — recorded, again at five or more employees.
Read those five verbs again. Plan, organise, control, monitor, review. That is a management system described in statute without using the phrase, and it is the spine of HSE's Managing for health and safety (HSG65).
European Union and international
The EU Framework Directive 89/391/EEC obliges employers to implement preventive measures on the basis of general principles of prevention, with documented risk assessment — the same systematic duty expressed differently, transposed into each member state's national law. Internationally, ILO-OSH 2001 provides voluntary guidelines for OSH management systems, and ILO Conventions 155 and 187 set the framework obligations that member states legislate against.
How the four positions compare:
| Jurisdiction | Integrated system required? | Instrument | What must be written |
|---|---|---|---|
| United States (federal) | No | OSHA 3885 (advisory) | Hazard-specific written programmes only |
| United States (some states) | Yes, varies | e.g. California IIPP | A written injury and illness prevention programme |
| United Kingdom | The core is | HSWA s.2(3); MHSWR Reg. 5 | Policy, organisation and arrangements, at 5+ employees |
| EU member states | The duty is | Directive 89/391/EEC as transposed | Risk assessment and preventive measures |
| International | Voluntary | ILO-OSH 2001; ISO 45001, ISO 14001 | Per the standard adopted |
Environmental sits separately again: an environmental permit — under the Environmental Permitting Regulations in England and Wales, or an IED permit across the EU — will frequently require a written management system as a permit condition regardless of what safety law says. On the waste and treatment sites I have worked across, that permit condition, not ISO, is usually what forced the environmental leg into the system in the first place.
Before you decide what your system must contain, establish three things:
- Which regime you sit under — federal, state plan, national transposition of an EU directive, or an operator standard imposed by a client.
- Whether you hold an environmental permit, and what management-system wording its conditions carry.
- Whether a customer or framework contract requires certification — this obliges more than the law does on most sites I audit.

The key elements that build a SHEMS
Six elements do the building. They are broadly the same in every framework — ISO 45001, ISO 14001, OSHA 3885, HSG65 — because they describe the same logic. Decide what you are trying to control. Find out what could hurt people or the environment. Know what the law demands of you, put controls in, make people competent to use them, and plan for the day it goes wrong anyway.
SHE policy and leadership accountability. The policy sets the commitments; leadership makes them binding by allocating money and time. A policy signed by the HSE manager rather than the chief executive tells you where the system sits in the organisation, and it tells the workforce the same thing.
Hazard identification, environmental aspects and risk evaluation. Safety hazards, health exposures and environmental aspects are assessed through one methodology, so a single activity gets a single verdict. Assessing a solvent wipe-down operation properly means fire risk, inhalation exposure and VOC emission in the same document, not three documents that never meet.
Legal and other requirements. A maintained register of the legislation, permits, licences and consents that apply, plus a periodic evaluation confirming you actually meet each one. This is dull, and it is the element I have seen fail most consistently — a register compiled once at implementation and never touched again is worse than none, because it creates documented confidence in a compliance position nobody has checked.
Operational control. Procedures, permits and engineering controls that translate the risk assessment into what happens at the work face.
Competence, consultation and participation. Training records prove attendance. Competence means the person can do the task under real conditions, which is a different claim and needs different evidence.
Emergency preparedness and response. Scenario plans covering the emergencies your risk assessment actually predicts, exercised and reviewed — spill and release scenarios included, not just fire evacuation.
Auditing on the legal register scope for Ramboll Environment in Austria, I worked a register that ran past two hundred line items across workplace safety law, exposure limits, discharge consents and waste carrier licences. The discipline that made it useful was not its length. It was that each line named the person who checked it and the date they last did.
The order matters, and it is not the order most sites build in:
- Policy first — because it determines what gets resourced.
- Risk and aspects second — because everything downstream is prioritised from it.
- Legal register alongside it — a control can be adequate for risk and still illegal.
- Operational controls third — written from the risk assessment, not from a template pack.
- Competence fourth — controls that nobody is trained to operate are not controls.
- Emergency planning last — it plans for the residual risk the first five could not remove.

The elements that prove a SHEMS works
Three more elements exist purely to test the first six, and this is where I spend most of an audit. Anyone can produce a procedure. Far fewer organisations can produce evidence that the procedure was followed and that following it worked.
Monitoring, measurement and internal audit. Leading indicators tell you whether the system is being operated; lagging indicators tell you what it failed to prevent. An internal audit programme has to test effectiveness, not existence. That is the difference between asking "do you have a permit procedure?" and "show me the last twenty permits, then walk me to one of those jobs."
Incident investigation and corrective action. Findings that are logged but never closed are the clearest single predictor of a system in decline. Once a workforce learns that reporting produces no visible change, reporting stops, and you lose the data before you lose the control.
Management review. Senior leadership reviewing performance and making resourcing decisions. Minutes recording that a presentation was delivered are not a management review.
On an environmental systems assurance scope for SUEZ in Zurich, I found leadership walks scheduled and completed to plan — all of them on day shift. The night shift, which ran the same plant with fewer supervisors, had never been walked. The monitoring data looked healthy because the monitoring only sampled the half of the operation that was easiest to sample.
We changed the walk schedule to cover shift patterns proportionately, and the finding rate on nights went up sharply before it came down. If you are reviewing your own monitoring, check the times and shifts of your inspections before you look at the numbers they produced. A dataset drawn only from day shift will describe a plant you do not entirely have.
What each element must be able to hand an auditor:
| Element | Evidence that proves it | What the weak version looks like |
|---|---|---|
| Policy and leadership | Signed by top management; budget lines traceable to review decisions | Signed by the HSE manager; no resourcing trail |
| Hazard and aspects | One register covering S, H and E, revised after change and incident | Assessments dated at implementation only |
| Legal requirements | Register with named checker and check date per line | A list with no evaluation record |
| Operational control | Permits and procedures traceable to a specific assessed risk | Generic template pack, unattributed |
| Competence | Assessment of performance, not attendance sheets | Training matrix with no verification |
| Emergency response | Exercise reports with findings closed | Plans issued, never tested |
| Monitoring and audit | Audits that sample work, across shifts | Document-review audits, day shift only |
| Corrective action | Closure verified by someone other than the owner | Open backlog older than the last review |
| Management review | Minuted decisions with owners and dates | Minuted attendance |

SHEMS standards in 2026: what changed and what is changing
If you are building a SHEMS this year, the standards ground under it has moved, and most published guidance has not caught up. Check the edition dates on anything you are working from.
ISO 14001:2026 replaced the 2015 edition in April
ISO published ISO 14001:2026 on 15 April 2026, superseding ISO 14001:2015. A three-year transition applies: certificates issued to the 2015 edition remain valid until 14 April 2029 at the latest, subject to your certification body's own rules. The revision clarifies rather than reinvents — sharper expectations on top management accountability, environmental aspects tied more directly into decision-making, and climate change embedded in the standard rather than bolted on by amendment.
Practically, this means a gap analysis, a system update, training, and at least one internal audit cycle before your transition audit. Three years is less time than it reads.
ISO 45001 is in revision, not yet revised
ISO 45001:2018 remains the current occupational health and safety management system standard. The revision is underway — LRQA reports the Draft International Standard ballot running from 16 June to 8 September 2026, with publication anticipated in 2027 and a three-year transition expected to follow. The themes flagged for the revision include psychosocial health and wellbeing, climate-related risk, hybrid and digital ways of working, and supply chain control. Build against ISO 45001:2018 now; watch the DIS themes so the transition is not a surprise.
The 2024 climate amendment still applies
In February 2024 ISO amended more than thirty management system standards at once, adding climate change to the context and interested-parties clauses. ISO 45001:2018/Amd 1:2024 is the version you are audited against today. The amendment did not add controls; it removed the argument that climate change is somebody else's clause. For ISO 14001, the amendment has been absorbed into the 2026 edition.
Non-ISO routes
Certification is not the only route to a defensible system. ANSI/ASSP Z10.0-2019 gives US organisations a consensus OHS management system standard that does not require third-party certification. HSG65 gives UK organisations a Plan-Do-Check-Act framework aligned to what MHSWR already demands. ILO-OSH 2001 remains the reference for organisations working where neither applies.
Where the main instruments stand as of August 2026:
| Standard | Status | Covers | Certifiable |
|---|---|---|---|
| ISO 14001:2026 | Current from 15 Apr 2026; 2015 valid to Apr 2029 | Environmental management | Yes |
| ISO 45001:2018 (Amd 1:2024) | Current; revision at DIS, publication expected 2027 | Occupational health and safety | Yes |
| ISO 9001:2015 | Current; ISO 9001:2026 confirmed for 16 Sep 2026 | Quality — folded in for an IMS | Yes |
| ANSI/ASSP Z10.0-2019 | Current | OHS management system (US consensus) | No |
| HSG65 | Current HSE guidance | Plan-Do-Check-Act for UK duty holders | No |
| ILO-OSH 2001 | Current | International OSH-MS guidelines | No |
| OHSAS 18001 | Withdrawn | Superseded by ISO 45001 | No |
If you hold current certification, four things belong on this quarter's plan:
- Gap-analyse against ISO 14001:2026 and book the transition audit slot early — capacity tightens as 2029 approaches.
- Confirm your edition references. Procedures, the legal register and the audit checklist all cite edition numbers.
- Evidence the climate consideration in your context and interested-parties records, whatever conclusion you reached.
- Track the ISO 45001 DIS themes so the 2027 transition starts from a known position.

What integrating safety, health and environment actually costs
Integration is sold on efficiency, and the efficiency is real. It is not free, and the sites that struggle are usually the ones told it would be.
The genuine saving is in shared machinery. Both ISO 45001 and ISO 14001:2026 sit on ISO's Harmonised Structure, which means the same clause numbering and the same core requirements for context, leadership, competence, documented information, internal audit and management review. One document control process, one audit programme, one corrective action tracker, one management review agenda — that duplication is worth removing, and removing it is most of the business case.
What does not merge is the technical work underneath. Environmental aspects and safety hazards are assessed by different logic against different criteria. The regulators are different bodies with different inspection styles. The competence to evaluate a discharge consent is not the competence to evaluate a confined space entry, and pretending otherwise produces a system that is strong in whichever discipline the manager came from.
That imbalance is the failure I see most. In waste and treatment operations across Switzerland, Germany and Austria, the pattern repeated: safety got the walkdowns, the toolbox talks and the leadership attention, while environment got a monthly return to the regulator and nothing else. The environmental leg was in the manual and out of the routine.
Auditing a waste control scope for Biffa in Germany, I pulled a permit that had been approved without anyone walking the job first. The form was complete and correctly signed. The approval had happened at a desk. When I walked to the work face the conditions did not match what the permit described, and I stopped the work until the controls were reinstated and the crew re-briefed.
The transferable check costs nothing: before you sign, go and look. If you audit permits, ask the issuer where they were standing when they signed. That single question tells you more about whether operational control is real than reading fifty forms will.
What to share and what to keep separate:
- Share: document control, internal audit programme, corrective action tracker, management review, competence framework, contractor pre-qualification, incident reporting channel.
- Keep separate: aspect evaluation versus hazard evaluation criteria, legal register sections and their owners, monitoring methods and the competence to interpret them, regulator interface and notification routes.
- Watch: whichever discipline your system owner did not come from. Sample its records first at every internal audit.

Frequently asked questions
These are the questions that come up most often when a site starts building or transitioning its system.
What does SHEMS stand for?
SHEMS stands for Safety, Health and Environment Management System. It is an organisation's integrated framework for managing workplace safety risks, occupational health exposures and environmental impacts through shared processes rather than three separate systems.
Is SHEMS the same as HSE-MS or EHSMS?
Yes, in substance. SHEMS, HSEMS, HSE-MS and EHSMS all describe an integrated safety, health and environment management system. The letter order reflects regional and corporate convention. SMS usually means safety only, and IMS adds quality management alongside.
Can you be certified to SHEMS?
No. SHEMS is not a standard, so there is no SHEMS certificate. Organisations certify the safety and health parts of their system to ISO 45001:2018 and the environmental parts to ISO 14001:2026, often through a single integrated audit.
Which ISO 14001 version applies now?
ISO 14001:2026, published on 15 April 2026. Certificates issued to ISO 14001:2015 stay valid through a three-year transition ending no later than 14 April 2029, depending on issue date and certification body rules. Any guidance still citing the 2015 edition as current is out of date.
Is a SHEMS a legal requirement?
It depends on jurisdiction. There is no federal US requirement, though some state plans mandate a written programme. UK law requires the core through HSWA s.2(3) and MHSWR Reg. 5. Environmental permits often require a written system as a condition regardless.
How long does it take to implement a SHEMS?
Expect twelve to eighteen months to a first full Plan-Do-Check-Act cycle for a medium site with existing safety arrangements, longer where the environmental leg is being built from nothing. Certification bodies generally want one complete cycle of evidence before a certification audit.
What is the difference between ISO 45001 and ANSI/ASSP Z10.0?
Both describe an occupational health and safety management system with similar elements. ISO 45001 is internationally recognised and third-party certifiable; ANSI/ASSP Z10.0-2019 is a US consensus standard designed for self-assessment and improvement without certification.
Conclusion: the test a SHEMS has to pass
A SHEMS is the operating architecture connecting a safety policy to what happens on shift. Its elements are not controversial and have not changed much in twenty years — policy, risk and aspects, legal requirements, operational control, competence, emergency response, monitoring, corrective action, management review.
What has changed this year is the standards ground beneath it. ISO 14001:2026 is now the environmental standard, with a transition running to 2029. ISO 45001:2018 remains current with its 2024 climate amendment, and its own revision arrives in 2027. If your system documents cite ISO 14001:2015 as current, that is the first correction to make.
The rest is verification. Every element in this article can be produced on paper by an organisation that does none of it. The only test that separates the two is whether someone can trace a hazard reported last month through to a control that changed — and whether the person who verified the closure was not the person who owned the action.
If you are building a system from nothing, or your environmental leg has been orphaned for years, that work needs a competent person with genuine experience of both disciplines. It is not a documentation exercise, and treating it as one is how sites end up certified and exposed at the same time.
About the author
Ryan Foster is a Principal Environmental Management, ISO 14001 & Sustainability Assurance Consultant with 17 years of continuous field experience across ISO 14001 systems, waste management, spill control, air emissions and wastewater compliance. His focus is practical assurance — checking that controls still work where work actually happens, under night shift, contractor and schedule pressure. He has conducted 70+ audits across 14 countries, and led environmental systems and legal register work for SUEZ Recycling & Recovery, Remondis, Biffa, Veolia Environmental Services EU and Ramboll Environment. He currently leads Foster Environmental Assurance in Zurich, Switzerland.
Credentials: NEBOSH International General Certificate; ISO 45001 Lead Auditor; ISO 14001 Internal Auditor; IOSH Managing Safely.
Sources
- ISO — ISO 14001:2026 published
- ISO — ISO 45001:2018/Amd 1:2024, Climate action changes
- LRQA — ISO 45001 revision: DIS ballot dates
- OSHA — Recommended Practices for Safety and Health Programs (OSHA 3885)
- OSHA — Safety and Health Programs in the States
- legislation.gov.uk — Employers' Health and Safety Policy Statements (Exception) Regulations 1975
- legislation.gov.uk — MHSWR 1999, Regulation 5
- HSE — Managing for health and safety (HSG65)
- ANSI — ANSI/ASSP Z10.0-2019






























