Are You Ready for an ISO 45001 Audit?
An auditor arrives tomorrow. Your risk assessments exist. Employees have received training. Procedures are stored somewhere. But can managers and workers actually explain how the OH&S management system works, or does the paperwork exist without the practice behind it?
This is where an ISO 45001 audit checklist becomes a practical readiness tool rather than a formality. Working through realistic ISO 45001 audit questions in advance helps identify gaps in ISO 45001 audit requirements before an actual auditor does, and it turns audit preparation into a genuine occupational health and safety audit exercise rather than a last-minute scramble. For the full standard, see the official ISO 45001 resource — note that ISO currently lists ISO 45001:2018 as the current edition, together with its 2024 climate-action amendment.
What Is Checked in an ISO 45001 Audit?
An ISO 45001 audit examines whether an organisation's OH&S management system meets applicable requirements and works effectively in practice. Auditors typically examine leadership, worker participation, hazard identification, risks, legal obligations, objectives, competence, operational controls, emergency arrangements, performance monitoring, internal auditing, management review and continual improvement. This is essentially what is checked in an ISO 45001 audit — an ISO 45001 compliance audit looks at the whole OHSMS audit checklist, not just isolated documents.
How Does the ISO 45001 Audit Process Work?
It helps to distinguish three related but different audit types: the internal audit an organisation runs on itself, the certification audit performed by an external certification body, and the ongoing surveillance/recertification audits that follow once certified.
Across all three, an auditor normally gathers evidence through interviews, document review, workplace observation, records, and sampling, rather than relying on any single source. ISO 19011:2026 is the current international guidance for management-system auditing, covering audit principles, audit programmes, conducting audits and auditor competence — a useful reference for anyone involved in the ISO 45001 audit process, ISO 45001 audit procedure or the handling of ISO 45001 audit evidence. See ISO 19011:2026 for the official guidance.
25 ISO 45001 Audit Questions
Clause 4 — Context of the Organisation
1. Has the organisation identified internal and external issues affecting its OH&S management system? Evidence: context analysis, risk registers, business plans, organisational changes.
2. Have workers' and other interested parties' needs and expectations been identified? Evidence: stakeholder assessment, consultation records, legal requirements.
3. Is the scope of the OH&S management system clearly defined and appropriate? Evidence: scope statement, locations, activities, outsourced processes.
Clause 5 — Leadership and Worker Participation
4. Can top management demonstrate leadership and accountability for OH&S? Evidence: management involvement, resources, meetings, decisions.
5. Is there a suitable OH&S policy that workers understand? Evidence: OH&S policy, communication records, interviews.
6. Are OH&S roles, responsibilities and authorities clearly assigned? Evidence: job descriptions, organisation charts, responsibilities.
7. How are workers consulted and encouraged to participate in safety decisions? Evidence: safety committees, toolbox talks, consultation records, worker interviews.
OSHA's recommended safety-management practices can support the discussion of management leadership and worker participation in U.S. workplaces. OSHA describes its recommended approach as proactive and focused on identifying and controlling hazards before injuries occur.
Clause 6 — Planning
8. How does the organisation identify workplace hazards? Evidence: hazard registers, inspections, incident data, job safety analysis.
9. How are OH&S risks and opportunities assessed? Evidence: risk assessments, methodologies, control measures.
10. How does the organisation identify and keep applicable legal requirements current? Evidence: legal register, regulatory updates, compliance reviews.
11. Are measurable OH&S objectives established and monitored? Evidence: objectives, targets, KPIs, action plans.
Clause 7 — Support
12. Are sufficient resources provided to operate the OH&S management system? Evidence: budgets, personnel, safety equipment, systems.
13. Are workers competent for the tasks that affect OH&S performance? Evidence: training records, qualifications, competency assessments.
Readers who need a clearer understanding of clauses, responsibilities and OH&S management-system principles can strengthen their foundation through the ISO 45001 Occupational Health & Safety Management System Awareness course.
14. Are workers aware of the OH&S policy, risks and consequences of non-compliance? Evidence: interviews, induction records, awareness training.
15. Are internal and external OH&S communications effectively controlled? Evidence: communication procedures, alerts, contractor communication.
16. Is required documented information properly controlled? Evidence: procedures, revision history, access controls, retained records.
Clause 8 — Operation
17. Are operational controls established for significant workplace hazards? Evidence: safe systems of work, permits, procedures, PPE controls.
18. Are OH&S risks assessed when changes are introduced? Evidence: management-of-change records, new equipment assessments.
19. Are procurement, contractors and outsourced activities appropriately controlled? Evidence: contractor assessments, purchasing specifications, inductions, monitoring.
20. Is the organisation prepared for foreseeable emergency situations? Evidence: emergency plans, drills, evacuation records, lessons learned.
Clause 9 — Performance Evaluation
21. Does the organisation monitor and measure OH&S performance effectively? Evidence: incident trends, inspections, leading indicators, KPIs.
22. Does the organisation evaluate compliance with applicable legal and other requirements? Evidence: compliance reviews, inspections, corrective actions.
23. Is the internal audit programme effective and independent enough to identify weaknesses? Evidence: audit programme, auditor competence, reports, findings.
24. Does top management review the OH&S management system at planned intervals? Evidence: management-review minutes, KPIs, objectives, improvement decisions.
Clause 10 — Improvement
25. How are incidents, nonconformities and corrective actions managed to prevent recurrence? Evidence: incident investigations, root-cause analysis, corrective-action records, effectiveness reviews.
What Documents Should You Prepare for an ISO 45001 Audit?
A quick ISO 45001 audit preparation checklist typically includes: an OH&S policy, OH&S objectives, risk and hazard assessments, applicable legal/compliance records, competence and training records, operational procedures, emergency plans and drill records, monitoring and inspection records, internal audit reports, management-review records, incident investigations, and nonconformity and corrective-action records. An auditor is looking for evidence that the system works — not simply a folder containing procedures nobody actually follows day to day.
How to Prepare for an ISO 45001 Audit
A concise five-step readiness process:
- Review ISO 45001 requirements clause by clause.
- Conduct an internal audit before the certification audit.
- Close outstanding nonconformities and corrective actions.
- Check whether workers and managers can explain their responsibilities.
- Verify that documented procedures match what actually happens in the workplace.
For wider international context on audit and continual-improvement practice, see the ILO's occupational safety and health management-system guidance, which describes its OSH-management guidance as a practical framework supporting continual improvement in occupational safety and health performance.
Common ISO 45001 Audit Findings to Watch For
Recurring issues include outdated risk assessments, weak worker consultation, missing competence evidence, procedures not followed in practice, contractor controls not demonstrated, poor corrective-action follow-up, internal audits treated as a paperwork exercise, and management reviews without meaningful decisions.
Build ISO 45001 Awareness Before the Audit
A successful audit depends on people understanding why the OH&S management system exists and what their responsibilities are. The ISO 45001 Occupational Health & Safety Management System Awareness course can help managers, employees and safety professionals build practical knowledge of the standard before audit preparation.
Treat the Checklist as a Readiness Tool
The goal of an ISO 45001 audit is not simply to produce documents. An organisation should be able to demonstrate that hazards are controlled, workers participate, responsibilities are understood, performance is reviewed and weaknesses lead to improvement. Use this ISO 45001 audit checklist before your next internal or certification audit to identify gaps while there is still time to correct them.