ISO 45001
ISO 45001 Audit Checklist: The Complete Guide to Preparing for Your Audit
A practical guide to preparing for an ISO 45001 audit, including key requirements, evidence to check, common findings and audit-readiness tips.
Preparing for an ISO 45001 audit can feel like a lot of work.
There are documents to review, risks to assess, workers to involve, legal requirements to check and evidence to gather. Then there is the question most organisations eventually ask:
Are we actually ready for the auditor?
A good ISO 45001 audit checklist can help answer that question before the auditor does.
But an audit checklist should be more than a list of documents to tick off. ISO 45001 is built around an occupational health and safety management system, so you need to demonstrate that your system is not only documented, but actually being implemented and working.
This guide provides a practical ISO 45001 audit checklist covering the key areas to review before an internal or certification audit.
What is an ISO 45001 audit?
An ISO 45001 audit is a systematic assessment of an organisation's occupational health and safety management system against the requirements of ISO 45001:2018.
An audit looks at more than whether you have the right policies and procedures.
An auditor may look for evidence that:
- Hazards are being identified.
- OH&S risks are being assessed and controlled.
- Workers are involved in the management system.
- Legal and other requirements are understood.
- People are competent to carry out their roles.
- Operational controls are actually being followed.
- Incidents and nonconformities are investigated.
- Corrective actions are effective.
- Internal audits are being completed.
- Management is reviewing the system.
- The organisation is continually improving.
The key point is simple:
**Having a document does not automatically demonstrate that the requirement is being met.**
You need evidence that the process is actually happening.
ISO 45001 audit checklist
The following checklist covers the main requirements in Clauses 4 to 10 of ISO 45001:2018.
Clause 4: Context of the organisation
Before your audit, check that you have considered the internal and external issues that could affect your OH&S management system.
- Have relevant internal and external issues been identified?
- Have relevant interested parties been identified?
- Have the needs and expectations of workers and other relevant interested parties been considered?
- Is the scope of the OH&S management system clearly defined?
- Does the scope accurately reflect the organisation's activities, products and services?
- Is the OH&S management system established, implemented, maintained and continually improved?
Don't just check that a context document exists.
Ask whether the information still reflects the organisation as it actually operates.
Have there been changes to your workforce, sites, activities, equipment, contractors or business operations?
If so, has your management system kept up?
Clause 5: Leadership and worker participation
ISO 45001 places significant emphasis on leadership and worker participation.
This is an area where an auditor may want to see evidence rather than simply read a policy.
- Has top management demonstrated commitment to the OH&S management system?
- Is the OH&S policy established and communicated?
- Are responsibilities and authorities clearly defined?
- Do workers understand their role in health and safety?
- Are workers consulted on relevant OH&S matters?
- Are workers given opportunities to participate in the development and improvement of the system?
- Are barriers to worker participation being addressed?
- Is there evidence that management acts on health and safety information raised by workers?
A useful test is to speak to people doing the work.
Ask a few workers:
**How do you report a hazard here?**
**What happens when you raise a safety concern?**
**Have you been involved in any recent safety decisions?**
If the answers don't match your documented processes, you may have a gap worth addressing before the audit.
Clause 6: Planning
Planning is one of the areas where organisations can uncover significant gaps.
Your audit preparation should include a review of how you identify hazards, assess risks and determine controls.
- Are hazards identified for routine and non-routine activities?
- Are risks assessed using a defined methodology?
- Are opportunities to improve OH&S performance considered?
- Are applicable legal and other requirements identified?
- Is information about legal and other requirements kept up to date?
- Are OH&S objectives established?
- Are objectives measurable where appropriate?
- Are plans in place to achieve the objectives?
- Are changes to the organisation assessed for their potential OH&S impact?
Don't forget changes
One common weakness is treating a risk assessment as a document that is completed once and then forgotten.
Ask:
**What has changed since our last review?**
New equipment?
New employees?
New contractors?
New chemicals?
Changes to working hours?
A new process?
A different workplace?
A change in legal requirements?
If something significant has changed, your risk assessment and associated controls may need to change too.
Clause 7: Support
Clause 7 covers the resources and supporting processes needed for the OH&S management system to work.
- Are sufficient resources available?
- Are workers competent for their roles?
- Are training and competence records maintained?
- Do workers understand the OH&S policy and relevant risks?
- Are relevant OH&S communications effective?
- Is documented information controlled?
- Are documents available where they are needed?
- Are obsolete documents prevented from unintended use?
- Are required records retained?
Again, don't stop at the paperwork.
If your training matrix says someone is competent, can you demonstrate how that competence was established?
If you have a procedure for a task, does the person actually carrying out the task know where to find it and understand it?
Clause 8: Operation
This is where your management system meets the real workplace.
Operational controls should be implemented and maintained for relevant activities.
- Are operational controls defined?
- Are controls appropriate for the organisation's risks?
- Are workers following the required procedures and controls?
- Is management of change being applied where necessary?
- Are procurement processes considering OH&S requirements?
- Are contractors appropriately controlled?
- Are outsourced processes controlled where applicable?
- Are emergency arrangements established?
- Are emergency plans tested?
- Are lessons from drills, incidents or exercises acted upon?
Walk the workplace
One of the best ways to prepare for an ISO 45001 audit is to stop looking at the system from behind a desk.
Walk around the workplace.
Look at what is actually happening.
Compare the documented controls with what you see.
For example, your procedure might say that a particular piece of equipment requires a specific control.
Is that control actually being used?
Your risk assessment might identify a particular hazard.
Is the control visible in the workplace?
Your emergency procedure might require regular drills.
Can you produce evidence that those drills happened?
This is where workplace inspections, photographs and observations can become valuable evidence.
Clause 9: Performance evaluation
You need to demonstrate that you are monitoring and evaluating whether your OH&S management system is working.
- Are relevant OH&S performance indicators monitored?
- Are monitoring and measurement methods defined?
- Are results analysed and evaluated?
- Are legal compliance evaluations carried out?
- Are internal audits planned?
- Is the internal audit programme based on relevant factors such as risk and previous audit results?
- Are internal auditors objective and impartial?
- Are audit results reported to relevant management?
- Are management reviews carried out?
- Are actions from management reviews followed up?
Internal audits are not just a tick-box exercise
An internal audit should ask:
**Is this requirement working?**
Rather than simply:
**Do we have a procedure?**
For example, instead of checking that an incident procedure exists, look at a recent incident.
Was it reported?
Was it investigated?
Were the causes identified?
Were workers involved where appropriate?
Were corrective actions completed?
Did the actions actually prevent the problem from happening again?
That gives you much stronger evidence of whether your system is effective.
Clause 10: Improvement
Finally, check how your organisation responds when things go wrong and how it identifies opportunities to improve.
- Are incidents investigated?
- Are nonconformities identified and recorded?
- Are immediate actions taken where necessary?
- Are root causes considered?
- Are corrective actions assigned?
- Are actions completed within appropriate timescales?
- Is the effectiveness of corrective action checked?
- Are lessons communicated to relevant workers?
- Is continual improvement demonstrated?
An auditor may be more interested in what happened after you found a problem than in whether you have a perfect-looking procedure.
A healthy management system finds problems, learns from them and improves.
Documents and evidence to have ready
There is no single folder containing everything an auditor will need.
The evidence required will depend on your organisation, activities, risks and management system.
However, it is sensible to review areas such as:
- OH&S policy
- Scope of the management system
- Context and interested parties
- Hazard identification and risk assessments
- Legal and other requirements
- OH&S objectives and plans
- Training and competence records
- Worker consultation records
- Communication records
- Operational procedures and controls
- Emergency preparedness records
- Contractor information
- Inspection records
- Incident records
- Corrective action records
- Monitoring and measurement results
- Compliance evaluation results
- Internal audit programme and reports
- Management review records
- Continual improvement evidence
Remember that evidence is not limited to formal documents.
Interviews, observations, inspection records, photographs, completed actions and other records can all help demonstrate how your OH&S management system operates in practice.
Common ISO 45001 audit findings
Getting the documents together is only part of the preparation.
Some of the biggest problems occur when the documented management system doesn't match what is happening in practice.
Risk assessments haven't kept up with changes
The organisation has introduced new equipment, processes or activities but the associated risks haven't been reviewed.
Workers aren't involved
The system says workers are consulted, but there is little evidence that workers actually participate in OH&S decisions.
Corrective actions are closed without checking effectiveness
An action is marked complete, but nobody checks whether it actually solved the problem.
Training records don't tell the whole story
A training record exists, but there is limited evidence that the person is competent to perform the task.
Procedures don't match reality
The documented process says one thing while employees actually do something different.
Internal audits are too superficial
Every audit results in "conforms" without properly testing whether the system is effective.
Old information is still being used
Documents, risk assessments or procedures haven't been reviewed after significant changes.
Management review becomes a paperwork exercise
The meeting happens, but there is little evidence of meaningful decisions, actions or follow-up.
How to prepare for an ISO 45001 certification audit
Don't leave your preparation until the week before the auditor arrives.
A better approach is to work backwards from the audit.
Review your previous findings
Start with previous internal and external audit findings.
Are they genuinely closed?
Has the corrective action been effective?
Review your highest-risk activities
Don't spend all your time checking low-risk paperwork.
Look at the activities that could have the greatest consequences if controls fail.
Carry out an ISO 45001 gap analysis
Compare your current management system against the ISO 45001 requirements.
Identify what is:
- Compliant
- Partially compliant
- Missing
- In place but lacking evidence
A gap analysis can help you prioritise the work instead of trying to fix everything at once.
Check the workplace
Go beyond documents.
Walk the site and compare what you see with your documented controls.
Take photographs where useful and record observations as you go.
Speak to workers
Ask people about the system in normal language.
Can they report hazards?
Do they know the relevant controls?
Do they understand what to do in an emergency?
Do they feel able to raise concerns?
Check your evidence
For every important requirement, ask:
**If an auditor asked me to prove this, what would I show them?**
If you don't have a good answer, investigate before the audit.
Find your ISO 45001 gaps before the auditor does
Preparing for an audit is much easier when you know where the gaps are.
ISO Comply AI can analyse your existing ISO documentation and help identify potential gaps, missing information and areas that may need attention before your audit.
Instead of manually working through every document, you can use AI to help review your documentation and highlight areas worth investigating.
**Start your ISO 45001 gap analysis →**
Final ISO 45001 audit readiness checklist
Before the auditor arrives, ask yourself:
- Have we reviewed all previous audit findings?
- Have we checked our highest-risk activities?
- Are our risk assessments current?
- Have we reviewed recent changes?
- Are workers involved in the OH&S management system?
- Can we demonstrate competence and training?
- Are operational controls actually being followed?
- Have emergency arrangements been tested?
- Are incidents properly investigated?
- Are corrective actions genuinely effective?
- Are legal and other requirements being evaluated?
- Are internal audits effective?
- Has management reviewed the OH&S management system?
- Can we produce evidence for the requirements we claim to meet?
If you can confidently answer those questions, you are in a much stronger position than simply having a folder full of policies.
Don't wait for the auditor to find the gaps
The purpose of preparing for an ISO 45001 audit isn't to make the organisation look perfect for a few days.
It's to find weaknesses before they become bigger problems.
A good audit readiness process should show you where your management system is strong, where evidence is missing and where action is needed.
That is why an **ISO 45001 gap analysis** can be such a useful starting point.
The earlier you identify potential gaps, the more time you have to investigate them, take corrective action and strengthen your management system.
Frequently asked questions
What is an ISO 45001 audit checklist?
An ISO 45001 audit checklist is a structured set of questions or checks used to assess an organisation's occupational health and safety management system against ISO 45001 requirements. It can be used during internal audits or as part of preparation for a certification audit.
Does ISO 45001 require an internal audit?
Yes. ISO 45001 includes requirements for organisations to conduct internal audits at planned intervals and establish an appropriate audit programme.
What clauses are audited in ISO 45001?
The main auditable requirements are contained in Clauses 4 through 10, covering context, leadership and worker participation, planning, support, operation, performance evaluation and improvement.
What evidence is needed for an ISO 45001 audit?
Evidence varies between organisations. It can include documented information, records, interviews, observations, inspection results, training records, audit reports, incident investigations, corrective actions and management review records.
How do I know if my organisation is ready for an ISO 45001 audit?
The best way is to test your management system before the certification audit. Conduct a structured gap analysis, review previous findings, inspect actual workplace controls, speak with workers and verify that you can produce objective evidence for the requirements that apply to your organisation.
Final thought
**Don't prepare for an ISO 45001 audit by asking, "Do we have the documents?"**
Ask:
**"Can we demonstrate that our system works?"**
That shift in mindset can make the difference between simply having an OH&S management system on paper and having one that genuinely supports safer work.
If you're preparing for certification, start with the gaps you already know about — then use a structured assessment to find the ones you don't.