ISO 45001 Internal Audit Checklist: Health and Safety
An ISO 45001 internal audit checklist helps you verify that your Occupational Health and Safety (OH&S) management system conforms to the standard and actively protects workers. This complete guide covers Clause 4–10 audit questions, hazard identification review, incident investigation, worker consultation evidence, and legal compliance verification.
ISO 45001:2018 is the international standard for OH&S management systems. It replaces OHSAS 18001 and follows the Annex SL framework, making it compatible with ISO 9001 and ISO 14001. Internal audits are a mandatory requirement of Clause 9.2 and provide assurance that the OH&S system is effectively implemented, maintained, and continually improved.
What Is an ISO 45001 Internal Audit Checklist?
An ISO 45001 internal audit checklist is a structured set of audit questions, document requests, and evidence criteria aligned to the standard’s requirements. It guides the auditor through each clause, ensuring no critical area is missed. The checklist also serves as documented evidence of the audit for external certification bodies and regulatory inspectors.
The checklist should be tailored to your organisation’s specific hazards, risks, legal requirements, and operational context. A generic checklist is a starting point, but a customised checklist that reflects your actual workplace conditions delivers far more value.
OH&S Audit Planning
Before auditing, ensure your OH&S audit programme includes the following planning activities. The audit programme should be risk-based, prioritising high-hazard areas and activities.
| Planning Element | Requirement | Verification Method |
|---|---|---|
| Audit scope | Includes all OH&S processes, locations, shift patterns, and activities | Review scope document against organisational activity register |
| Audit criteria | ISO 45001:2018 clauses, legal requirements, OH&S policy, contractor requirements | Confirm criteria are documented and understood by the audit team |
| Risk-based scheduling | High-risk areas (construction, chemical handling, confined spaces) audited more frequently | Review risk assessment register and align audit schedule with risk levels |
| Auditor competence | Auditors trained in OH&S management, risk assessment, and ISO 45001 | Check training certificates, OH&S qualifications, and auditing experience |
| Stakeholder notification | Workers, managers, and worker representatives informed of audit schedule | Review communication records, safety committee meeting minutes |
| Previous findings | All nonconformities from previous audits reviewed and closure verified | Previous audit report, corrective action status tracker |
Clause-by-Clause Audit Checklist
Clause 4 – Context of the Organisation
This clause establishes the external and internal context of the organisation as it relates to OH&S. The auditor must verify that the organisation understands its operating environment and the needs of workers and other interested parties.
| Audit Question | Documents to Review | Evidence to Collect |
|---|---|---|
| How does the organisation determine external and internal OH&S issues? | OH&S context analysis, business environment assessment | Identified issues related to health and safety, both internal and external |
| Who are the interested parties and what are their OH&S needs? | Interested party register, worker consultation records | Requirements from regulators, workers, unions, contractors, visitors, emergency services |
| What is the scope of the OH&S management system? | OH&S scope document | Scope boundaries, exclusions with justification, covered locations and activities |
| How are OH&S processes integrated into the organisation’s business processes? | OH&S process map, IMS integration diagram | Process interactions, inputs, outputs, and integration with quality and environmental management |
Clause 5 – Leadership and Worker Participation
Worker participation is a defining feature of ISO 45001. Unlike ISO 9001, this standard places strong emphasis on consulting and involving workers at all levels. This clause often reveals the most significant gaps in an internal audit.
| Audit Question | Documents to Review | Evidence to Collect |
|---|---|---|
| Has top management demonstrated leadership and commitment to OH&S? | OH&S policy, management review minutes, resource allocation records | Signed policy, budget approvals, visible management involvement in safety walks and meetings |
| Is the OH&S policy appropriate, communicated, and reviewed? | OH&S policy document, review records | Policy displayed in workplace, included in induction, discussed in team meetings, translated as needed |
| How does the organisation ensure worker participation and consultation? | Worker participation procedure, safety committee charter, hazard reporting system | Safety committee minutes, worker representatives identified, hazard report trends, participation records |
| Are OH&S roles, responsibilities, and authorities defined and communicated? | OH&S responsibility matrix, job descriptions, organogram | Top management accountability, HSE officer role, supervisor responsibilities, worker OH&S duties |
Clause 6 – Planning
Planning covers risk assessment, legal compliance, and OH&S objectives. The auditor should verify that the organisation has a systematic approach to identifying hazards, assessing risks, and planning improvements.
| Audit Question | Documents to Review | Evidence to Collect |
|---|---|---|
| How are OH&S risks and opportunities identified and assessed? | Risk assessment methodology, risk register, task-specific assessments | Completed risk assessments for all tasks, activities, equipment, and locations |
| How are legal and other OH&S requirements identified and maintained? | Legal register, regulatory monitoring procedure | Updated legal register, compliance obligations tracking, change monitoring process |
| How are OH&S objectives planned, monitored, and achieved? | OH&S objectives register, action plans | SMART objectives with targets, timelines, resource allocation, progress reviews, completion status |
| How does the organisation plan for changes that affect OH&S? | Change management procedure | Change impact assessments, pre-change risk assessments, consultation records |
Clause 7 – Support
Support includes resources, competence, awareness, communication, and documented information. Weaknesses here directly affect the organisation’s ability to manage OH&S risks.
| Audit Question | Documents to Review | Evidence to Collect |
|---|---|---|
| How does the organisation provide necessary OH&S resources? | Resource planning, PPE budget, HSE staffing plan, training budget | PPE availability and condition, qualified HSE staff numbers, safety equipment maintenance records |
| Are workers competent in OH&S for their roles? | OH&S competence matrix, training records, job specifications | Safety training certificates, competency assessments, refresher training records, competence gaps addressed |
| How is OH&S awareness ensured across all levels? | Awareness programme records, induction content | Worker understanding of hazards, emergency procedures, their OH&S duties, and consequences of noncompliance |
| How does the organisation communicate OH&S information internally and externally? | Communication procedure, toolbox talk records, safety alert logs | Toolbox talk topics and attendance, safety alerts, noticeboard updates, contractor communication |
| How is OH&S documented information controlled? | Document and record control procedures | Controlled document list, version control, obsolete document removal, retention periods |
Clause 8 – Operation
Operations is where OH&S risks are actually controlled. The auditor must verify that operational controls are implemented, that emergency preparedness is effective, and that procurement and outsourcing do not introduce uncontrolled risks.
| Audit Question | Documents to Review | Evidence to Collect |
|---|---|---|
| How are operational planning and control implemented for OH&S? | Operational control procedures, safe work instructions, permit-to-work systems | Permit-to-work records, lockout/tagout procedures, confined space entry logs, hot work permits |
| How are emergency situations identified, prepared for, and tested? | Emergency response plan, drill schedule, emergency equipment inventory | Evacuation drill logs and observations, first aid equipment inspection records, emergency contact lists, drill improvement actions |
| How does the organisation manage procurement, contractors, and outsourcing for OH&S? | Contractor management procedure, procurement specifications, outsourcing agreements | Contractor safety evaluations, contractor induction records, purchased equipment safety checks, outsourced activity OH&S assessments |
Clause 9 – Performance Evaluation
The organisation must evaluate OH&S performance through monitoring, measurement, compliance evaluation, internal audit, and management review. This clause connects operational data to strategic decision-making.
| Audit Question | Documents to Review | Evidence to Collect |
|---|---|---|
| How is OH&S performance monitored, measured, and evaluated? | OH&S KPI dashboard, inspection schedule, safety observation programme | Leading and lagging indicators, inspection reports, safety observation data, trend analysis |
| How is compliance with legal requirements evaluated? | Compliance evaluation procedure, legal register, evaluation schedule | Compliance evaluation reports, regulatory inspection results, enforcement notices, permit conditions |
| How are internal audits of the OH&S system planned and conducted? | Internal audit procedure, audit schedule, auditor qualifications | Completed audit checklists, audit reports, nonconformity findings, audit programme effectiveness |
| How does management review the OH&S system? | Management review procedure, agenda template | Management review minutes covering all required inputs, decisions, resource commitments, action item resolution |
Clause 10 – Improvement
This clause addresses incident investigation, nonconformity handling, corrective actions, and continual improvement. It is the ultimate test of whether the OH&S system is driving real safety improvements.
| Audit Question | Documents to Review | Evidence to Collect |
|---|---|---|
| How are incidents and nonconformities investigated and corrected? | Incident investigation procedure, corrective action procedure, incident register | Incident reports, root cause analysis quality, corrective action completion, effectiveness verification |
| How does the organisation drive continual improvement in OH&S? | Improvement register, safety suggestion scheme, OH&S committee improvement log | Implemented improvement projects, worker suggestions actioned, safety campaign results, before/after metrics |
Hazard Identification and Risk Assessment Review
A critical part of every ISO 45001 internal audit is verifying that hazard identification and risk assessment processes are effective and comprehensive. The auditor should review whether:
- All activities, processes, and locations are covered by risk assessments, including non-routine tasks and maintenance work
- Hazards are identified for all worker categories: employees, contractors, temporary workers, and visitors
- Risk assessments cover routine, non-routine, and emergency situations
- The hierarchy of controls is applied correctly: elimination, substitution, engineering controls, administrative controls, PPE
- Risk assessments are reviewed and updated when changes occur (new equipment, process changes, after incidents)
- Workers participate in hazard identification and risk assessment activities
- Risk assessments are documented, accessible, and communicated to affected workers
- Specific high-risk activities have dedicated assessments (confined space, working at height, electrical work, manual handling, hazardous substances)
Incident Investigation Review
Review the incident investigation process against ISO 45001 Clause 10.2. The quality of incident investigations is a strong indicator of OH&S system maturity. A mature organisation learns from every incident and near miss.
| Audit Check | Expected Practice | Evidence of Compliance |
|---|---|---|
| Incident reporting | All incidents reported promptly, including near misses and first aid cases | Incident log completeness, near-miss register, reporting time analysis |
| Investigation timeliness | Investigations begin within 24 hours for serious incidents | Investigation start dates, initial response records, scene preservation evidence |
| Root cause analysis | Root causes identified (not just immediate causes) using structured methods | RCA reports using 5 Whys, fishbone diagrams, fault tree analysis, or bowtie analysis |
| Corrective actions | Actions address root causes and prevent recurrence | Action tracker with ownership, completion dates, closure evidence, effectiveness checks |
| Worker involvement | Workers and their representatives participate in investigations | Investigation team membership records, witness statements, safety committee review |
| Lessons learned | Findings shared across the organisation to prevent similar incidents | Safety alerts, toolbox talks on incident findings, bulletin board postings, briefing records |
Worker Consultation Evidence
ISO 45001 places strong emphasis on worker consultation and participation. Unlike ISO 9001 and ISO 14001, this standard requires explicit evidence that workers are involved in the OH&S system. Auditors should look for:
- Safety committee meeting minutes with worker representative attendance and contributions
- Evidence that worker representatives are involved in hazard identification, risk assessment, and incident investigation
- Worker consultation records for changes that affect OH&S (new equipment, process changes, facility modifications)
- Hazard reporting system data showing worker engagement
- Safety suggestion scheme records with management responses
- Evidence that workers are consulted on OH&S policy and objectives
- Toolbox talk records demonstrating two-way communication, not just one-way instruction
Legal Compliance Review
Your ISO 45001 internal audit must assess how the organisation meets legal and other requirements related to OH&S. Legal compliance is a fundamental expectation of the standard and regulatory authorities.
- Is a legal register maintained and updated with changes in OH&S legislation?
- Are changes to OH&S regulations monitored and communicated?
- Are compliance evaluations conducted at planned intervals?
- Are noncompliances identified, corrected, and prevented from recurring?
- Are permits, licenses, and registrations current (e.g. dangerous goods storage, fire safety, environmental permits)?
- Are statutory inspection records maintained (lifting equipment, pressure vessels, electrical installations, fire extinguishers)?
- Are required notices displayed (health and safety law poster, fire evacuation plan, first aid notices)?
- Are regulatory reports submitted on time (incident notifications, statistical returns)?
Frequently Asked Questions
How often should ISO 45001 internal audits be performed?
At least annually, with higher-risk areas audited more frequently. Construction sites, chemical handling areas, confined space operations, and manufacturing floors should be audited quarterly. Administrative offices can be audited annually.
Who can perform an ISO 45001 internal audit?
Any competent person with ISO 45001 auditor training and knowledge of OH&S management. Auditors must be independent of the area being audited. Many organisations use cross-departmental internal auditors or external OH&S specialists.
Do I need to audit every department in every audit cycle?
Not necessarily. Use a risk-based approach. High-risk departments (production, maintenance, logistics, laboratories) should be audited each cycle. Lower-risk areas (administrative offices, remote sales offices) can be audited less frequently.
How do I audit worker consultation and participation?
Review safety committee records, interview worker representatives, check hazard reporting system usage data, observe whether workers participate in risk assessments, and verify their involvement in incident investigations and safety inspections.
What records must be kept from an ISO 45001 internal audit?
Audit programme documentation, audit schedule, completed checklists, audit report, nonconformity records, corrective actions, and evidence of corrective action effectiveness. These serve as evidence for external certification audits and regulatory inspections.
Can ISO 45001 be audited together with ISO 9001 and ISO 14001?
Yes. Integrated management system (IMS) audits are common and efficient. An integrated checklist covering quality, environment, and health and safety reduces duplication, saves audit time, and provides a holistic view of organisational performance.
What is the most common ISO 45001 audit finding?
The most common finding is inadequate worker consultation and participation. Many organisations have a safety committee on paper but cannot demonstrate meaningful worker involvement in hazard identification, risk assessment, and incident investigation.
How do I close an ISO 45001 nonconformity?
Perform root cause analysis, implement corrective action addressing the root cause, verify effectiveness through follow-up, and document the entire process. Present closure evidence to the audit team for review and acceptance.
Get ISO 45001 Internal Audit Support
Bitrixme provides complete ISO 45001 internal audit services across the Middle East. From custom checklists and auditor training to full audit outsourcing, our OH&S specialists help you build a safer workplace and achieve certification.
Our consultants have extensive experience across construction, manufacturing, oil and gas, healthcare, and logistics sectors. We understand the specific OH&S challenges faced by organisations in the GCC region and tailor our services accordingly.
Contact Bitrixme for ISO 45001 OH&S audit services or reach out on WhatsApp for a free consultation.