ISO 45001 Audit Checklist: What to Check Before Certification

ISO 45001 Audit Checklist: What to Check Before Certification

Quick Contact


ISO 45001 Audit Checklist: What to Check Before Certification

A practical, easy-to-follow ISO 45001 audit checklist covering Clauses 4–10, objective evidence, worker interviews, Stage 1 and Stage 2 readiness, and common gaps to fix before certification.

Clauses 4–10 Stage 1 + Stage 2 readiness Evidence-based checks
Quick idea: A completed checklist does not prove conformity by itself. Before certification, make sure your OH&S management system is documented where needed, implemented in real operations, understood by workers, and supported by objective evidence.

Current standard: ISO 45001:2018 remains the published edition, with Amendment 1:2024 adding climate-change consideration to the management-system context.

Evidence matters: Auditors may review documents, records, interviews, and workplace observations instead of relying on yes/no answers.

Worker awareness matters: Frontline workers should understand the hazards, controls, emergency actions, and reporting methods relevant to their own work.

Preparing for an ISO 45001 certification audit can feel complicated when policies, risk assessments, training records, legal requirements, contractor controls, emergency plans, internal audits, and management reviews all need attention at the same time.

This ISO 45001 audit checklist brings those areas together in one practical guide. It is designed for organizations carrying out a gap assessment, preparing an ISO 45001 internal audit, or checking readiness before an external certification audit.

The goal is not to memorize the standard. The goal is to ask simple questions: What should happen? What actually happens? What evidence proves it? What happens when something goes wrong?

What Is an ISO 45001 Audit Checklist?

An ISO 45001 audit checklist converts management-system requirements into practical questions that can be checked against evidence. A useful checklist helps an organization review whether its Occupational Health and Safety Management System (OH&S management system) is established, implemented, maintained, and capable of producing the intended results.

It can be used for a gap assessment, an internal audit, a final pre-certification review, or preparation for surveillance and recertification audits.

However, a checklist should not become a tick-box exercise. For example, answering “yes” to “Are workers consulted?” is only the beginning. An auditor may then ask workers how they participated, review meeting or consultation records, and check whether their input influenced a safety decision.

Simple audit rule: A “yes” answer is stronger when you can immediately show the record, person, workplace condition, or result that supports it.

ISO 45001:2018 Status and the 2024 Climate Amendment

ISO 45001:2018 remains the published international standard for occupational health and safety management systems. A revised second edition is under development, but organizations preparing for certification should continue using the currently published requirements unless an applicable transition is formally announced after a new edition is published.

ISO also published ISO 45001:2018/Amd 1:2024, which adds climate-action considerations to the management-system context.

In practical terms, an organization should be able to show that it has considered whether climate change is a relevant issue for its OH&S management system and whether relevant interested parties have climate-related requirements.

Depending on the organization, this could include issues such as extreme heat, severe weather, outdoor work, emergency preparedness, changing exposures, supply disruption, or other conditions that can affect worker health and safety.

Four Types of Evidence to Prepare

One of the biggest weaknesses in generic ISO 45001 checklists is that they focus only on documents. Certification audits can go much further.

1. Documents

Examples include the OH&S policy, scope, processes, procedures, risk-assessment methodology, emergency arrangements, and other controlled documented information.

2. Records

Examples include training and competence records, inspection results, legal-compliance evaluations, internal audit reports, management-review outputs, incident investigations, drill results, contractor records, and corrective-action evidence.

3. Interviews

Auditors may speak with top management, supervisors, safety personnel, frontline workers, contractors, and others to confirm that responsibilities and controls are understood in practice.

4. Workplace Observations

Actual work activities can be compared with documented controls. PPE, guarding, permits, access controls, housekeeping, emergency equipment, contractor practices, and safe-working methods may all provide evidence.

Consistency test: Your procedure, your records, what workers say, and what the auditor sees on site should tell the same story.

Clause 4: Context of the Organization

Clause 4 establishes the foundation of the OH&S management system. Before checking procedures, make sure the organization understands its operating environment, interested parties, and management-system boundaries.

Audit checklist

  • Have relevant internal and external issues been identified and reviewed?
  • Have workers and other relevant interested parties been identified?
  • Have their relevant needs and expectations been considered?
  • Is the OH&S management-system scope clearly defined and available?
  • Does the scope reflect actual sites, activities, processes, and organizational boundaries?
  • Has the organization considered whether climate change is relevant to the OH&S management system?
  • Is the context reviewed when important business, workforce, legal, site, or operational changes occur?

Evidence to prepare

  • Context analysis or equivalent records
  • Interested-party review
  • OH&S management-system scope statement
  • Management-review records showing relevant changes
  • Evidence that the 2024 climate amendment was considered

Common gap

A context analysis may exist from initial implementation but never be reviewed again. If operations, regulations, workforce conditions, sites, or major risks have changed, the context should still make sense today.

Clause 5: Leadership and Worker Participation

ISO 45001 gives strong importance to leadership and meaningful participation of workers. A signed policy alone is not enough to demonstrate that health and safety is integrated into management decisions.

Audit checklist

  • Can top management explain its responsibilities for the OH&S management system?
  • Is the OH&S policy current, appropriate, communicated, and understood?
  • Are OH&S roles, responsibilities, and authorities clear?
  • Are workers consulted on relevant OH&S matters?
  • Do non-managerial workers participate in hazard identification, risk assessment, investigations, or improvement where applicable?
  • Can workers raise hazards and safety concerns through a clear process?
  • Are barriers to participation considered, such as language, literacy, access, work schedules, or fear of negative consequences?

Evidence to prepare

  • OH&S policy
  • Management meeting or review records
  • Safety committee records and toolbox-talk records
  • Worker consultation records
  • Hazard reports and evidence of follow-up
  • Responsibility or authority records

Common gap

A company may hold regular safety meetings but still struggle to show what workers contributed or what changed because of their input. Strong evidence connects the worker’s concern or suggestion to a decision, action, or updated control.

Clause 6: Planning

Clause 6 is central to audit readiness because it connects hazards, OH&S risks, legal and other requirements, opportunities, objectives, and planned actions.

Audit checklist

  • Is hazard identification an ongoing process rather than a one-time exercise?
  • Are routine and non-routine activities considered?
  • Are workers, contractors, visitors, changes, emergencies, and relevant human or organizational factors considered where applicable?
  • Are OH&S risks assessed using defined criteria?
  • Are opportunities for improving OH&S performance considered?
  • Are applicable legal and other requirements identified and kept current?
  • Is compliance actually evaluated, not merely listed in a legal register?
  • Are OH&S objectives measurable where practicable and supported by action plans?
  • Do action plans identify responsibility, timing, resources, and how results will be evaluated?

Evidence to prepare

  • Hazard identification and risk-assessment records
  • Legal and other requirements register
  • Completed compliance evaluations
  • OH&S objectives and monitoring records
  • Action plans with owners and target dates
  • Change-related risk reviews
Important distinction: A legal register tells you what requirements apply. A compliance evaluation shows whether your organization is actually meeting those requirements.

Common gap

Risk assessments can become generic or outdated. Before certification, compare important assessments with current workplace conditions. If machinery, people, shifts, contractors, materials, layouts, or work methods have changed, the assessment should still reflect reality.

Clause 7: Support

A management system cannot operate effectively without suitable resources, competent people, awareness, communication, and controlled documented information.

Audit checklist

  • Are sufficient people, time, equipment, and other resources available for the OH&S management system?
  • Are competence requirements defined for roles that can affect OH&S performance?
  • Can the organization demonstrate competence through education, training, experience, assessment, or other suitable evidence?
  • Do workers understand relevant hazards, controls, responsibilities, and consequences of not following requirements?
  • Are internal and external OH&S communications appropriately managed?
  • Is documented information approved, current, identifiable, available where needed, and protected from unintended change?

Evidence to prepare

  • Competence matrix or role requirements
  • Training and qualification records
  • Competence assessments for safety-critical roles
  • Induction and awareness records
  • Communication records
  • Document revision and control records

Common gap

Training attendance does not automatically prove competence. For safety-critical activities, be ready to show how the organization knows the person can perform the work safely and correctly.

Clause 8: Operation

Clause 8 is where documented plans are tested against real work. This is a major reason workplace observation is so important during an ISO 45001 certification audit.

Audit checklist

  • Are operational controls established and implemented for significant hazards and OH&S risks?
  • Does the organization consider the hierarchy of controls when selecting controls?
  • Do procedures and actual work practices match?
  • Are planned and temporary changes assessed for OH&S impact?
  • Are relevant procurement requirements controlled?
  • Are contractor activities coordinated and controlled appropriately?
  • Are outsourced activities considered where they can affect OH&S performance?
  • Have credible emergency situations been identified?
  • Are emergency-response arrangements tested at planned intervals?
  • Are lessons from drills or actual emergencies translated into actions and verified?

Evidence to prepare

  • Safe-work procedures and permits
  • Inspection and maintenance records
  • Contractor assessments, inductions, and monitoring records
  • Management-of-change records
  • Emergency plans and drill reports
  • Follow-up actions from emergency exercises

Use the hazard-to-control trace

Select one important hazard and trace the complete chain:

Hazard identified → risk assessed → control selected → workers informed → control implemented → performance checked → change or improvement reviewed.

If the chain breaks at any point, investigate the gap before the external audit.

Clause 9: Performance Evaluation

Clause 9 asks whether the organization knows how well its OH&S management system is performing and whether leadership receives enough reliable information to make decisions.

Audit checklist

  • Has the organization defined what should be monitored and measured?
  • Are useful leading and lagging indicators reviewed where relevant?
  • Is applicable legal and other compliance periodically evaluated?
  • Is an internal audit programme established and implemented at planned intervals?
  • Do internal audits cover the management system and important operational processes?
  • Are internal auditors sufficiently competent, objective, and impartial?
  • Are audit findings reported, assigned, tracked, and closed?
  • Are management reviews conducted at planned intervals?
  • Do management-review outputs include real decisions, actions, resource needs, or improvement opportunities?

Evidence to prepare

  • OH&S performance reports and trends
  • Monitoring and measurement records
  • Compliance-evaluation records
  • Internal audit programme and reports
  • Auditor competence and independence evidence
  • Management-review inputs, outputs, decisions, and actions

Internal audit frequency: avoid a common misconception

ISO 45001 requires internal audits at planned intervals. It does not set one universal frequency for every organization. Your audit programme should consider process importance, risk, changes, and previous audit results. Higher-risk or poorly performing areas may need more attention than stable lower-risk areas.

Clause 10: Improvement

Clause 10 checks whether the OH&S management system learns from incidents, nonconformities, findings, and performance information instead of repeatedly correcting the same symptoms.

Audit checklist

  • Are incidents and nonconformities reported and investigated appropriately?
  • Are causes investigated rather than stopping at the immediate error?
  • Are corrective actions proportionate to the issue and focused on preventing recurrence?
  • Are actions assigned to owners and tracked to completion?
  • Is the effectiveness of corrective action checked before final closure?
  • Are recurring issues and trends analyzed?
  • Can the organization show evidence of continual improvement in the OH&S management system or OH&S performance?

Evidence to prepare

  • Incident and near-miss investigations
  • Root-cause analysis records
  • Nonconformity and corrective-action logs
  • Effectiveness checks
  • Trend reviews and improvement records

Common gap

Corrective actions are sometimes marked “closed” as soon as the action is completed. A stronger system also checks whether the action actually solved the underlying problem and reduced the chance of recurrence.

Questions Workers May Be Asked During an ISO 45001 Audit

Worker interviews are valuable because they show whether the OH&S management system is understood beyond the safety department. Employees should not memorize scripted answers. They should understand the arrangements relevant to their own jobs.

Practical worker interview questions

  • What are the main hazards associated with your work?
  • What controls protect you from those hazards?
  • What should you do if a control is missing or not working?
  • How do you report an unsafe condition, incident, or near miss?
  • What would you do in an emergency?
  • Have you participated in a risk assessment, toolbox talk, safety meeting, or incident investigation?
  • What happens after workers raise a safety concern?
  • Have any procedures or controls changed recently? How were you informed?
  • Where can you find the information you need to work safely?
Do not coach workers to recite the standard. Help them understand their real hazards, controls, reporting routes, and emergency responsibilities.

Stage 1 vs Stage 2 Readiness

The initial ISO 45001 certification process normally includes a Stage 1 audit followed by a Stage 2 audit. Guardian’s published certification audit procedure also describes this two-stage approach.

Stage 1: Is the system ready for deeper assessment?

Stage 1 focuses on readiness. The certification body needs enough understanding of the scope, documented management system, site conditions, key processes, legal and other requirements, internal audit, management review, and implementation status to plan Stage 2.

Before Stage 1, make sure important documents are complete, responsibilities are clear, key system processes are operating, and enough records exist to show that the management system is more than a draft.

Stage 2: Does the system work in practice?

Stage 2 goes deeper into implementation and effectiveness. Auditors may visit operational areas, sample records, interview workers and managers, trace processes, and compare written controls with actual work.

A useful final Stage 2 question is: If the auditor chooses an important process tomorrow, can we demonstrate how it works without creating new evidence for the audit?

Common Pre-Certification Red Flags

Before inviting a certification body, check these areas carefully:

  • Outdated risk assessments: the documents no longer reflect current equipment, people, sites, contractors, or work methods.
  • Weak worker-participation evidence: meetings exist, but there is little proof of worker input or resulting action.
  • Legal register without compliance evaluation: requirements are listed but actual compliance has not been checked.
  • Management of change is informal: new equipment, processes, layouts, or staffing changes occur without OH&S review.
  • Contractor control stops at induction: contractor risk, competence, coordination, or performance is not followed through.
  • Emergency drills produce no tracked actions: weaknesses are noted but not assigned and verified.
  • Internal audits are document-only: little workplace observation, interviewing, or process tracing occurs.
  • Management review is ceremonial: minutes exist but there are few clear decisions, actions, or resource commitments.
  • Corrective actions lack effectiveness checks: tasks are completed but recurrence risk is not evaluated.
  • Workers cannot explain their own controls: procedures exist but the system is not embedded in daily work.

Final ISO 45001 Readiness Test

Choose several important OH&S processes and ask the same four questions:

1. What is supposed to happen?
Check the requirement, process, control, or defined method.

2. What actually happens?
Observe real work and speak with the people doing it.

3. What proves it?
Find the record, result, interview, or observation that supports the answer.

Then ask one final question: What happens when the process does not work? A mature system should identify the issue, respond, investigate where needed, take corrective action, and verify that the action was effective.

If your documents, records, worker answers, and workplace conditions are consistent, your organization is much closer to genuine certification readiness.

ISO 45001 Certification with Guardian

When your organization is ready for independent third-party assessment, Guardian Certification provides ISO 45001 certification within its applicable accreditation scope and certification procedures.

Guardian Assessment Pvt. Ltd. describes itself as an independent and impartial certification body accredited by IAS and UAF. Certification decisions are based on audit evidence and the applicable certification process.

This checklist is intended as educational content to help organizations understand audit readiness. It is not a substitute for the ISO 45001 standard, legal advice, an organization’s own internal audit process, or the independent certification assessment.

Frequently Asked Questions (FAQs)

Ans) An ISO 45001 audit checklist is a structured set of questions used to review an Occupational Health and Safety Management System against relevant ISO 45001 requirements. A useful checklist also records objective evidence, findings, responsibilities, and follow-up actions instead of relying only on yes/no answers.

Ans) Yes. ISO 45001:2018 remains the published international standard. Amendment 1:2024 added climate-action considerations to the management-system context. A revised edition is under development, but it has not yet replaced the current published edition.

Ans) For certification readiness and internal auditing, the checklist normally focuses on the management-system requirements in Clauses 4 to 10: context, leadership and worker participation, planning, support, operation, performance evaluation, and improvement. The questions should also be tailored to your actual activities, hazards, sites, and legal requirements.

Ans) Evidence may include policies, risk assessments, legal and compliance records, training and competence records, worker-consultation records, operational-control records, contractor records, emergency-drill results, monitoring data, internal audit reports, management-review outputs, incident investigations, and corrective-action evidence. Auditors may also use interviews and workplace observations.

Ans) Internal auditing is a required part of the ISO 45001 management system. Before certification, the internal audit process should be operating and should provide useful evidence about conformity, implementation, and effectiveness. Management review should also be established and functioning as part of readiness.

Ans) ISO 45001 requires internal audits at planned intervals rather than setting one fixed frequency for every organization. The audit programme should consider process importance, risk, organizational changes, previous findings, and performance. Higher-risk or weaker areas may justify more frequent auditing.

Ans) Stage 1 is primarily a readiness and planning assessment. Stage 2 evaluates implementation and effectiveness in greater depth. During Stage 2, the auditor may review records, interview people, observe work, trace processes, and confirm that the OH&S management system works in practice.

Ans) No. A checklist is only a preparation and audit tool. Certification depends on the independent assessment of the organization’s actual OH&S management system against the applicable requirements. The system must be implemented and supported by objective evidence, not just completed checklist answers.

About Us

Guardian Assessment Private Limited, incorporated in 2018, is an independent company registered under the Ministry of Corporate Affairs (MCA), Government of India with CIN: U74999MH2018PTC307933. The company provides impartial ISO certification, Product certification, and GHG validation & verification services for organizations worldwide.
Ask AI About Guardian Certification

© 2026 Guardian Certification | All Copyright Reserved. 

Call Now Button