Occupational health and safety compliance is becoming a growing priority for organisations across every industry. As more companies adopt structured OH&S management systems, understanding how to properly evaluate these systems has become essential. This is exactly why ISO 45001 OHSMS frameworks rely so heavily on internal audits — they provide organisations with a reliable way to catch weaknesses before they turn into accidents or compliance failures. Internal audits help prevent workplace risks by systematically checking whether safety procedures are actually being followed in practice, not just documented on paper.
This guide breaks down the ISO 45001 internal audit process explained step by step, making it accessible for beginners. Whether you're an HSE officer, safety coordinator, or someone new to auditing responsibilities, understanding this process is essential for maintaining a compliant and effective safety management system.
What Is an ISO 45001 Internal Audit?
An ISO 45001 internal audit is a systematic, planned evaluation conducted by an organisation to assess its own Occupational Health and Safety Management System (OHSMS). Unlike a certification audit, which is performed by an external, accredited body to grant or maintain certification, an internal audit is conducted by the organisation itself — often by trained employees — purely for internal improvement purposes.
The core purpose of this process is to verify that the OHSMS is functioning as intended and genuinely protecting workers, not just meeting paperwork requirements. This ties directly into ISO 45001 Clause 9.2 Internal Audit requirements, which call for the collection of objective audit evidence and thorough compliance verification against defined criteria.
What is an ISO 45001 internal audit? An ISO 45001 internal audit is a planned, systematic review conducted by an organisation to check whether its occupational health and safety management system conforms to ISO 45001 requirements and is being effectively implemented and maintained across the workplace.
Why Is ISO 45001 Internal Audit Important?
Internal audits serve several critical functions within an organisation's safety strategy. They play a central role in identifying workplace hazards before they lead to incidents and support checking legal compliance against relevant occupational safety regulations. Beyond compliance, regular audits contribute to improving safety performance over time by highlighting weak points in existing procedures.
Perhaps most importantly, internal audits directly support reducing incidents by catching gaps between documented policy and actual workplace practice. They also play a practical role in preparing for certification audits, helping organisations identify and resolve issues before an external auditor ever steps on site.
The value of this process is visible across industries. In construction, audits help verify site-specific risk controls are actually being followed. In manufacturing, they assess whether machinery safety procedures are consistently applied. In healthcare, audits check infection control and occupational hazard management. In oil and gas, they evaluate high-risk activity controls and emergency preparedness readiness.
ISO 45001 Internal Audit Requirements
Several key requirements form the foundation of an effective internal audit process. These include:
-
Audit programme planning — establishing a structured, recurring audit schedule
-
Defined audit scope — clearly outlining what areas, processes, or departments will be reviewed
-
Competent auditors — ensuring those conducting audits have appropriate training and objectivity
-
Objective evidence collection — gathering verifiable proof rather than relying on assumptions
-
Audit reporting — documenting findings clearly and accurately
-
Corrective actions — ensuring identified issues are properly addressed and closed out
As referenced earlier, ISO 45001 Clause 9.2 requires organisations to conduct planned internal audits to verify whether the OHSMS conforms to requirements and is effectively implemented, making this clause the foundation for everything covered in this guide. The methodology for conducting these audits — including auditor competence, evidence-gathering principles and programme management — is further detailed in ISO 19011, Guidelines for auditing management systems, the companion standard widely used alongside ISO 45001 for planning and conducting internal audits.
ISO 45001 Internal Audit Process: Step-by-Step Guide
Step 1: Develop an ISO 45001 Audit Programme
The process begins with building a structured ISO 45001 audit programme. This involves determining audit frequency based on organisational risk levels, establishing a clear audit schedule, and applying risk-based planning to prioritise higher-risk areas. Organisations must also carefully select which departments and processes will be included in each audit cycle, ensuring coverage across the entire OHSMS over time.
Step 2: Prepare the ISO 45001 Internal Audit Plan
Once the programme is established, the next step involves detailed audit planning. This ISO 45001 audit preparation guide stage includes defining clear audit objectives, setting the scope of what will be reviewed, establishing audit criteria against which conformity will be measured, assembling a qualified audit team, setting a realistic timeline, and identifying which documents will be required during the audit.
Step 3: Review Documents and Previous Records
Before conducting on-site audit activities, auditors must review existing documentation thoroughly. This includes examining safety policies, past risk assessments, incident records, training records, emergency procedures, and legal compliance documents. Following a structured ISO 45001 audit documentation checklist at this stage ensures nothing important is overlooked and gives auditors the context needed to conduct a thorough, evidence-based evaluation once the audit begins.
Step 4: Conduct the ISO 45001 Internal Audit
With planning complete, the audit moves into its active phase. This typically begins with an opening meeting, where auditors explain the scope, objectives, and process to relevant staff. From there, auditors conduct employee interviews to understand how safety procedures work in practice, combined with direct workplace observation to see whether documented controls are actually being followed on the ground.
Auditors also perform document verification, cross-checking records against real workplace conditions, and gather evidence collection throughout to support their findings. These practices reflect audit principles set out in ISO 19011, including evidence-based auditing and objectivity. Well-structured ISO 45001 audit questions help guide this process, such as:
- Are workplace hazards identified?
- Are corrective actions completed?
- Are workers involved in safety decisions?
These questions help auditors move beyond surface-level compliance checks and evaluate whether the OHSMS is genuinely functioning as intended.
Step 5: Identify Nonconformities and Audit Findings
Once evidence is gathered, auditors categorise their findings. Understanding these ISO 45001 audit findings examples helps clarify how issues are typically classified:
Major Nonconformity — serious issues such as missing safety controls or serious legal compliance failures that pose significant risk.
Minor Nonconformity — smaller issues such as incomplete records or documentation gaps that don't pose immediate danger but still require correction.
Improvement Opportunities — areas that aren't strictly noncompliant but could still be strengthened, such as better safety communication or improved monitoring processes.
These ISO 45001 non conformity examples help auditors and organisations understand the varying severity levels involved in audit findings, guiding how quickly and thoroughly each issue needs to be addressed.
Step 6: Prepare the ISO 45001 Audit Report
After the audit concludes, findings must be documented in a clear, structured report. A typical ISO 45001 audit report example includes the audit scope, detailed findings, evidence collected, identified nonconformities, recommended corrective actions, and general recommendations for improvement. This report becomes the primary reference document for both management review and future audit planning.
Step 7: Corrective Actions and Follow-Up
The final stage of the audit cycle involves resolving identified issues. This begins with root cause analysis to understand why a nonconformity occurred, followed by action planning to determine how it will be fixed. Organisations must assign clear responsibility for each corrective action and later conduct effectiveness verification to confirm the fix actually worked. This structured ISO 45001 corrective action process ensures audits lead to real improvement rather than simply identifying problems without resolution.
ISO 45001 Internal Auditor Responsibilities and Skills
Internal auditors carry several core responsibilities, including planning audits, collecting evidence, interviewing employees, reporting findings, and maintaining objectivity throughout the process.
Key skills for this role include ISO 45001 knowledge, strong communication skills for interviewing staff effectively, solid risk assessment knowledge, and analytical thinking to interpret evidence accurately. For those wondering how to become an ISO 45001 internal auditor, building this skill set through structured training is typically the most effective starting point.
How Often Should ISO 45001 Internal Audits Be Conducted?
There's no fixed universal frequency for internal audits — the right schedule depends on several factors. Organisations should consider their overall risk level, any recent changes in operations, results from previous audit results, and relevant legal requirements specific to their industry or region. This flexible approach to ISO 45001 internal audit frequency allows organisations to audit higher-risk areas more often while maintaining reasonable oversight elsewhere.
Common ISO 45001 Internal Audit Mistakes
Several recurring mistakes can weaken audit effectiveness:
- Auditing only documents without observing actual workplace conditions
- Ignoring worker feedback during interviews
- Poor evidence collection that lacks objectivity
- Lack of follow-up on corrective actions
- Using untrained auditors who miss important details
ISO 45001 Internal Audit Checklist for Beginners
- Safety policy reviewed
- Hazard identification completed
- Risk assessments updated
- Legal requirements checked
- Emergency plans verified
- Training records reviewed
- Incident investigations analysed
- Corrective actions followed up
Become a Certified ISO 45001 Internal Auditor
Readers can develop practical auditing knowledge, understand ISO 45001 requirements, and build professional HSE auditing skills through the ISO 45001 Internal Auditor course. Start your ISO 45001 Internal Auditor training and strengthen your workplace safety career.
Internal audits are essential for improving workplace safety and maintaining an effective OHSMS. ISO 45001 audits help organisations identify risks early and continuously improve compliance across all levels of operation. Proper planning, thorough evidence collection, and consistent follow-up on corrective actions all work together to create stronger, more resilient safety systems over time.
Take the next step in your HSE career with the ISO 45001 Internal Auditor course.