An internal audit is how you prove your occupational health and safety management system works before a certification body checks it for you. Clause 9.2 of ISO 45001 makes it mandatory. The checklist below follows the standard's structure so nothing is missed, and tells you what evidence an auditor will expect to see.
How to run the audit
- 1Plan the audit: confirm scope, clauses, sites and an impartial auditor.
- 2Review documents before site work — policy, register, risk assessments, prior findings.
- 3Hold an opening meeting so the audited team knows scope, timing and reporting.
- 4Gather evidence by interview, observation and record sampling — never assumption.
- 5Classify findings as major nonconformity, minor nonconformity, or opportunity for improvement.
- 6Report within days, agree root cause and corrective actions with owners and dates.
- 7Verify effectiveness before closing, and feed results into management review.
Clause-by-clause ISO 45001 audit checklist
- Are internal and external issues affecting OH&S documented and reviewed?
- Are interested parties and their needs identified (workers, clients, regulators)?
- Is the scope of the OH&S management system defined and available?
Evidence to collect: Context/issues register, interested-party analysis, scope statement.
- Can top management demonstrate accountability for OH&S performance?
- Is the OH&S policy communicated and understood at every level?
- Are roles, responsibilities and authorities assigned in writing?
- Is there evidence of worker consultation and participation (non-managerial)?
Evidence to collect: Signed policy, org chart, safety committee minutes, consultation records.
- Are hazards identified continually, including routine and non-routine activities?
- Are OH&S risks and opportunities assessed with a documented methodology?
- Is the legal and other requirements register current and evaluated for compliance?
- Are OH&S objectives measurable, resourced and assigned an owner and date?
Evidence to collect: Risk assessments, legal register, objectives plan with KPIs.
- Are competence requirements defined per role and training records complete?
- Is awareness of hazards, incidents and the ability to remove themselves from danger evidenced?
- Is internal and external communication planned (what, when, who, how)?
- Is documented information version-controlled and protected?
Evidence to collect: Training matrix, induction records, communication plan, document control log.
- Is the hierarchy of controls applied (eliminate, substitute, engineer, administrate, PPE)?
- Is management of change controlled before changes take effect?
- Are contractors, outsourced processes and procurement controls verified?
- Are emergency preparedness plans tested and drills recorded?
Evidence to collect: Safe systems of work, permits, MoC forms, contractor approvals, drill reports.
- Is monitoring and measurement equipment calibrated where relevant?
- Is compliance with legal requirements periodically evaluated and recorded?
- Is the internal audit programme risk-based and are auditors impartial?
- Does the management review cover every required input and produce decisions?
Evidence to collect: KPI dashboards, compliance evaluation, audit programme and reports, review minutes.
- Are incidents and nonconformities investigated for root cause, not just symptoms?
- Is corrective action effectiveness verified and closed out on time?
- Is continual improvement of OH&S performance demonstrable over time?
Evidence to collect: Incident investigations, CAPA log with verification, trend analysis.
Scoring and closing out findings
Record each checklist line as conforming, a minor nonconformity (an isolated lapse), a major nonconformity (a missing or failed process, or a legal breach), or an opportunity for improvement. Majors must be fixed and verified before a certification body will recommend you. Every finding needs a root cause, an owner, a due date and evidence that the fix actually worked.
