2026 Trends
Aug 18, 2026
7 min read

ISO 45001 Audit Checklist: 25 Questions Every Organisation Should Prepare For

Prepare for an ISO 45001 audit with 25 practical audit questions covering Clauses 4–10, leadership, worker participation, risk assessment, operational controls, performance evaluation and continual improvement. Use the checklist to identify gaps, verify evidence and strengthen OH&S audit readiness.

Are You Ready for an ISO 45001 Audit?

An auditor arrives tomorrow. Your risk assessments exist. Employees have received training. Procedures are stored somewhere. But can managers and workers actually explain how the OH&S management system works, or does the paperwork exist without the practice behind it?

This is where an ISO 45001 audit checklist becomes a practical readiness tool rather than a formality. Working through realistic ISO 45001 audit questions in advance helps identify gaps in ISO 45001 audit requirements before an actual auditor does, and it turns audit preparation into a genuine occupational health and safety audit exercise rather than a last-minute scramble. For the full standard, see the official ISO 45001 resource — note that ISO currently lists ISO 45001:2018 as the current edition, together with its 2024 climate-action amendment.

What Is Checked in an ISO 45001 Audit?

Safety audit preparation process.

An ISO 45001 audit examines whether an organisation's OH&S management system meets applicable requirements and works effectively in practice. Auditors typically examine leadership, worker participation, hazard identification, risks, legal obligations, objectives, competence, operational controls, emergency arrangements, performance monitoring, internal auditing, management review and continual improvement. This is essentially what is checked in an ISO 45001 audit — an ISO 45001 compliance audit looks at the whole OHSMS audit checklist, not just isolated documents.

How Does the ISO 45001 Audit Process Work?

People, documents, and workplace evidence.

It helps to distinguish three related but different audit types: the internal audit an organisation runs on itself, the certification audit performed by an external certification body, and the ongoing surveillance/recertification audits that follow once certified.

Across all three, an auditor normally gathers evidence through interviews, document review, workplace observation, records, and sampling, rather than relying on any single source. ISO 19011:2026 is the current international guidance for management-system auditing, covering audit principles, audit programmes, conducting audits and auditor competence — a useful reference for anyone involved in the ISO 45001 audit process, ISO 45001 audit procedure or the handling of ISO 45001 audit evidence. See ISO 19011:2026 for the official guidance.

25 ISO 45001 Audit Questions

Clause 4 — Context of the Organisation

1. Has the organisation identified internal and external issues affecting its OH&S management system? Evidence: context analysis, risk registers, business plans, organisational changes.

2. Have workers' and other interested parties' needs and expectations been identified? Evidence: stakeholder assessment, consultation records, legal requirements.

3. Is the scope of the OH&S management system clearly defined and appropriate? Evidence: scope statement, locations, activities, outsourced processes.

Clause 5 — Leadership and Worker Participation

4. Can top management demonstrate leadership and accountability for OH&S? Evidence: management involvement, resources, meetings, decisions.

5. Is there a suitable OH&S policy that workers understand? Evidence: OH&S policy, communication records, interviews.

6. Are OH&S roles, responsibilities and authorities clearly assigned? Evidence: job descriptions, organisation charts, responsibilities.

7. How are workers consulted and encouraged to participate in safety decisions? Evidence: safety committees, toolbox talks, consultation records, worker interviews.

OSHA's recommended safety-management practices can support the discussion of management leadership and worker participation in U.S. workplaces. OSHA describes its recommended approach as proactive and focused on identifying and controlling hazards before injuries occur.

Clause 6 — Planning

8. How does the organisation identify workplace hazards? Evidence: hazard registers, inspections, incident data, job safety analysis.

9. How are OH&S risks and opportunities assessed? Evidence: risk assessments, methodologies, control measures.

10. How does the organisation identify and keep applicable legal requirements current? Evidence: legal register, regulatory updates, compliance reviews.

11. Are measurable OH&S objectives established and monitored? Evidence: objectives, targets, KPIs, action plans.

Clause 7 — Support

12. Are sufficient resources provided to operate the OH&S management system? Evidence: budgets, personnel, safety equipment, systems.

13. Are workers competent for the tasks that affect OH&S performance? Evidence: training records, qualifications, competency assessments.

Readers who need a clearer understanding of clauses, responsibilities and OH&S management-system principles can strengthen their foundation through the ISO 45001 Occupational Health & Safety Management System Awareness course.

14. Are workers aware of the OH&S policy, risks and consequences of non-compliance? Evidence: interviews, induction records, awareness training.

15. Are internal and external OH&S communications effectively controlled? Evidence: communication procedures, alerts, contractor communication.

16. Is required documented information properly controlled? Evidence: procedures, revision history, access controls, retained records.

Clause 8 — Operation

17. Are operational controls established for significant workplace hazards? Evidence: safe systems of work, permits, procedures, PPE controls.

18. Are OH&S risks assessed when changes are introduced? Evidence: management-of-change records, new equipment assessments.

19. Are procurement, contractors and outsourced activities appropriately controlled? Evidence: contractor assessments, purchasing specifications, inductions, monitoring.

20. Is the organisation prepared for foreseeable emergency situations? Evidence: emergency plans, drills, evacuation records, lessons learned.

Clause 9 — Performance Evaluation

21. Does the organisation monitor and measure OH&S performance effectively? Evidence: incident trends, inspections, leading indicators, KPIs.

22. Does the organisation evaluate compliance with applicable legal and other requirements? Evidence: compliance reviews, inspections, corrective actions.

23. Is the internal audit programme effective and independent enough to identify weaknesses? Evidence: audit programme, auditor competence, reports, findings.

24. Does top management review the OH&S management system at planned intervals? Evidence: management-review minutes, KPIs, objectives, improvement decisions.

Clause 10 — Improvement

25. How are incidents, nonconformities and corrective actions managed to prevent recurrence? Evidence: incident investigations, root-cause analysis, corrective-action records, effectiveness reviews.

What Documents Should You Prepare for an ISO 45001 Audit?

Auditors checking safety practices.

A quick ISO 45001 audit preparation checklist typically includes: an OH&S policy, OH&S objectives, risk and hazard assessments, applicable legal/compliance records, competence and training records, operational procedures, emergency plans and drill records, monitoring and inspection records, internal audit reports, management-review records, incident investigations, and nonconformity and corrective-action records. An auditor is looking for evidence that the system works — not simply a folder containing procedures nobody actually follows day to day.

How to Prepare for an ISO 45001 Audit

Preparing for a safety audit.

A concise five-step readiness process:

  1. Review ISO 45001 requirements clause by clause.
  2. Conduct an internal audit before the certification audit.
  3. Close outstanding nonconformities and corrective actions.
  4. Check whether workers and managers can explain their responsibilities.
  5. Verify that documented procedures match what actually happens in the workplace.

For wider international context on audit and continual-improvement practice, see the ILO's occupational safety and health management-system guidance, which describes its OSH-management guidance as a practical framework supporting continual improvement in occupational safety and health performance.

Common ISO 45001 Audit Findings to Watch For

Common safety audit gaps.

Recurring issues include outdated risk assessments, weak worker consultation, missing competence evidence, procedures not followed in practice, contractor controls not demonstrated, poor corrective-action follow-up, internal audits treated as a paperwork exercise, and management reviews without meaningful decisions.

Build ISO 45001 Awareness Before the Audit

A successful audit depends on people understanding why the OH&S management system exists and what their responsibilities are. The ISO 45001 Occupational Health & Safety Management System Awareness course can help managers, employees and safety professionals build practical knowledge of the standard before audit preparation.

Treat the Checklist as a Readiness Tool

The goal of an ISO 45001 audit is not simply to produce documents. An organisation should be able to demonstrate that hazards are controlled, workers participate, responsibilities are understood, performance is reviewed and weaknesses lead to improvement. Use this ISO 45001 audit checklist before your next internal or certification audit to identify gaps while there is still time to correct them.

Frequently Asked Questions

01 What is an ISO 45001 audit checklist? +

An ISO 45001 audit checklist is a practical tool used to review whether an organisation’s OH&S management system meets ISO 45001 requirements and works effectively in practice.

02 What questions are asked in an ISO 45001 audit? +

ISO 45001 audit questions typically cover organisational context, leadership, worker participation, hazard identification, risk assessment, legal requirements, competence, operational controls, emergency preparedness, audits and continual improvement.

03 What documents are needed for an ISO 45001 audit? +

Key ISO 45001 audit documents include the OH&S policy, objectives, risk assessments, legal records, training records, operational procedures, emergency plans, monitoring records, internal audits, management reviews and corrective-action records.

04 How do you prepare for an ISO 45001 audit? +

Prepare by reviewing ISO 45001 requirements, conducting an internal audit, closing nonconformities, checking worker and manager responsibilities, and confirming that documented procedures match actual workplace practices.

05 What are common ISO 45001 audit findings? +

Common findings include outdated risk assessments, weak worker consultation, missing competence evidence, ineffective contractor controls, incomplete corrective actions, weak internal audits and management reviews without meaningful decisions.

06 How many questions are on an ISO 45001 audit checklist? +

This checklist contains 25 practical ISO 45001 audit questions covering Clauses 4–10, from organisational context and leadership through performance evaluation and continual improvement.