iso-45001-internal-audit-checklist

By July 25th, 2026ISO Audit And Certificate13 min read

ISO 45001 Internal Audit Checklist: Health and Safety

An ISO 45001 internal audit checklist helps you verify that your Occupational Health and Safety (OH&S) management system conforms to the standard and actively protects workers. This complete guide covers Clause 4–10 audit questions, hazard identification review, incident investigation, worker consultation evidence, and legal compliance verification.

ISO 45001:2018 is the international standard for OH&S management systems. It replaces OHSAS 18001 and follows the Annex SL framework, making it compatible with ISO 9001 and ISO 14001. Internal audits are a mandatory requirement of Clause 9.2 and provide assurance that the OH&S system is effectively implemented, maintained, and continually improved.

What Is an ISO 45001 Internal Audit Checklist?

An ISO 45001 internal audit checklist is a structured set of audit questions, document requests, and evidence criteria aligned to the standard’s requirements. It guides the auditor through each clause, ensuring no critical area is missed. The checklist also serves as documented evidence of the audit for external certification bodies and regulatory inspectors.

The checklist should be tailored to your organisation’s specific hazards, risks, legal requirements, and operational context. A generic checklist is a starting point, but a customised checklist that reflects your actual workplace conditions delivers far more value.

OH&S Audit Planning

Before auditing, ensure your OH&S audit programme includes the following planning activities. The audit programme should be risk-based, prioritising high-hazard areas and activities.

Planning ElementRequirementVerification Method
Audit scopeIncludes all OH&S processes, locations, shift patterns, and activitiesReview scope document against organisational activity register
Audit criteriaISO 45001:2018 clauses, legal requirements, OH&S policy, contractor requirementsConfirm criteria are documented and understood by the audit team
Risk-based schedulingHigh-risk areas (construction, chemical handling, confined spaces) audited more frequentlyReview risk assessment register and align audit schedule with risk levels
Auditor competenceAuditors trained in OH&S management, risk assessment, and ISO 45001Check training certificates, OH&S qualifications, and auditing experience
Stakeholder notificationWorkers, managers, and worker representatives informed of audit scheduleReview communication records, safety committee meeting minutes
Previous findingsAll nonconformities from previous audits reviewed and closure verifiedPrevious audit report, corrective action status tracker

Clause-by-Clause Audit Checklist

Clause 4 – Context of the Organisation

This clause establishes the external and internal context of the organisation as it relates to OH&S. The auditor must verify that the organisation understands its operating environment and the needs of workers and other interested parties.

Audit QuestionDocuments to ReviewEvidence to Collect
How does the organisation determine external and internal OH&S issues?OH&S context analysis, business environment assessmentIdentified issues related to health and safety, both internal and external
Who are the interested parties and what are their OH&S needs?Interested party register, worker consultation recordsRequirements from regulators, workers, unions, contractors, visitors, emergency services
What is the scope of the OH&S management system?OH&S scope documentScope boundaries, exclusions with justification, covered locations and activities
How are OH&S processes integrated into the organisation’s business processes?OH&S process map, IMS integration diagramProcess interactions, inputs, outputs, and integration with quality and environmental management

Clause 5 – Leadership and Worker Participation

Worker participation is a defining feature of ISO 45001. Unlike ISO 9001, this standard places strong emphasis on consulting and involving workers at all levels. This clause often reveals the most significant gaps in an internal audit.

Audit QuestionDocuments to ReviewEvidence to Collect
Has top management demonstrated leadership and commitment to OH&S?OH&S policy, management review minutes, resource allocation recordsSigned policy, budget approvals, visible management involvement in safety walks and meetings
Is the OH&S policy appropriate, communicated, and reviewed?OH&S policy document, review recordsPolicy displayed in workplace, included in induction, discussed in team meetings, translated as needed
How does the organisation ensure worker participation and consultation?Worker participation procedure, safety committee charter, hazard reporting systemSafety committee minutes, worker representatives identified, hazard report trends, participation records
Are OH&S roles, responsibilities, and authorities defined and communicated?OH&S responsibility matrix, job descriptions, organogramTop management accountability, HSE officer role, supervisor responsibilities, worker OH&S duties

Clause 6 – Planning

Planning covers risk assessment, legal compliance, and OH&S objectives. The auditor should verify that the organisation has a systematic approach to identifying hazards, assessing risks, and planning improvements.

Audit QuestionDocuments to ReviewEvidence to Collect
How are OH&S risks and opportunities identified and assessed?Risk assessment methodology, risk register, task-specific assessmentsCompleted risk assessments for all tasks, activities, equipment, and locations
How are legal and other OH&S requirements identified and maintained?Legal register, regulatory monitoring procedureUpdated legal register, compliance obligations tracking, change monitoring process
How are OH&S objectives planned, monitored, and achieved?OH&S objectives register, action plansSMART objectives with targets, timelines, resource allocation, progress reviews, completion status
How does the organisation plan for changes that affect OH&S?Change management procedureChange impact assessments, pre-change risk assessments, consultation records

Clause 7 – Support

Support includes resources, competence, awareness, communication, and documented information. Weaknesses here directly affect the organisation’s ability to manage OH&S risks.

Audit QuestionDocuments to ReviewEvidence to Collect
How does the organisation provide necessary OH&S resources?Resource planning, PPE budget, HSE staffing plan, training budgetPPE availability and condition, qualified HSE staff numbers, safety equipment maintenance records
Are workers competent in OH&S for their roles?OH&S competence matrix, training records, job specificationsSafety training certificates, competency assessments, refresher training records, competence gaps addressed
How is OH&S awareness ensured across all levels?Awareness programme records, induction contentWorker understanding of hazards, emergency procedures, their OH&S duties, and consequences of noncompliance
How does the organisation communicate OH&S information internally and externally?Communication procedure, toolbox talk records, safety alert logsToolbox talk topics and attendance, safety alerts, noticeboard updates, contractor communication
How is OH&S documented information controlled?Document and record control proceduresControlled document list, version control, obsolete document removal, retention periods

Clause 8 – Operation

Operations is where OH&S risks are actually controlled. The auditor must verify that operational controls are implemented, that emergency preparedness is effective, and that procurement and outsourcing do not introduce uncontrolled risks.

Audit QuestionDocuments to ReviewEvidence to Collect
How are operational planning and control implemented for OH&S?Operational control procedures, safe work instructions, permit-to-work systemsPermit-to-work records, lockout/tagout procedures, confined space entry logs, hot work permits
How are emergency situations identified, prepared for, and tested?Emergency response plan, drill schedule, emergency equipment inventoryEvacuation drill logs and observations, first aid equipment inspection records, emergency contact lists, drill improvement actions
How does the organisation manage procurement, contractors, and outsourcing for OH&S?Contractor management procedure, procurement specifications, outsourcing agreementsContractor safety evaluations, contractor induction records, purchased equipment safety checks, outsourced activity OH&S assessments

Clause 9 – Performance Evaluation

The organisation must evaluate OH&S performance through monitoring, measurement, compliance evaluation, internal audit, and management review. This clause connects operational data to strategic decision-making.

Audit QuestionDocuments to ReviewEvidence to Collect
How is OH&S performance monitored, measured, and evaluated?OH&S KPI dashboard, inspection schedule, safety observation programmeLeading and lagging indicators, inspection reports, safety observation data, trend analysis
How is compliance with legal requirements evaluated?Compliance evaluation procedure, legal register, evaluation scheduleCompliance evaluation reports, regulatory inspection results, enforcement notices, permit conditions
How are internal audits of the OH&S system planned and conducted?Internal audit procedure, audit schedule, auditor qualificationsCompleted audit checklists, audit reports, nonconformity findings, audit programme effectiveness
How does management review the OH&S system?Management review procedure, agenda templateManagement review minutes covering all required inputs, decisions, resource commitments, action item resolution

Clause 10 – Improvement

This clause addresses incident investigation, nonconformity handling, corrective actions, and continual improvement. It is the ultimate test of whether the OH&S system is driving real safety improvements.

Audit QuestionDocuments to ReviewEvidence to Collect
How are incidents and nonconformities investigated and corrected?Incident investigation procedure, corrective action procedure, incident registerIncident reports, root cause analysis quality, corrective action completion, effectiveness verification
How does the organisation drive continual improvement in OH&S?Improvement register, safety suggestion scheme, OH&S committee improvement logImplemented improvement projects, worker suggestions actioned, safety campaign results, before/after metrics

Hazard Identification and Risk Assessment Review

A critical part of every ISO 45001 internal audit is verifying that hazard identification and risk assessment processes are effective and comprehensive. The auditor should review whether:

  • All activities, processes, and locations are covered by risk assessments, including non-routine tasks and maintenance work
  • Hazards are identified for all worker categories: employees, contractors, temporary workers, and visitors
  • Risk assessments cover routine, non-routine, and emergency situations
  • The hierarchy of controls is applied correctly: elimination, substitution, engineering controls, administrative controls, PPE
  • Risk assessments are reviewed and updated when changes occur (new equipment, process changes, after incidents)
  • Workers participate in hazard identification and risk assessment activities
  • Risk assessments are documented, accessible, and communicated to affected workers
  • Specific high-risk activities have dedicated assessments (confined space, working at height, electrical work, manual handling, hazardous substances)

Incident Investigation Review

Review the incident investigation process against ISO 45001 Clause 10.2. The quality of incident investigations is a strong indicator of OH&S system maturity. A mature organisation learns from every incident and near miss.

Audit CheckExpected PracticeEvidence of Compliance
Incident reportingAll incidents reported promptly, including near misses and first aid casesIncident log completeness, near-miss register, reporting time analysis
Investigation timelinessInvestigations begin within 24 hours for serious incidentsInvestigation start dates, initial response records, scene preservation evidence
Root cause analysisRoot causes identified (not just immediate causes) using structured methodsRCA reports using 5 Whys, fishbone diagrams, fault tree analysis, or bowtie analysis
Corrective actionsActions address root causes and prevent recurrenceAction tracker with ownership, completion dates, closure evidence, effectiveness checks
Worker involvementWorkers and their representatives participate in investigationsInvestigation team membership records, witness statements, safety committee review
Lessons learnedFindings shared across the organisation to prevent similar incidentsSafety alerts, toolbox talks on incident findings, bulletin board postings, briefing records

Worker Consultation Evidence

ISO 45001 places strong emphasis on worker consultation and participation. Unlike ISO 9001 and ISO 14001, this standard requires explicit evidence that workers are involved in the OH&S system. Auditors should look for:

  • Safety committee meeting minutes with worker representative attendance and contributions
  • Evidence that worker representatives are involved in hazard identification, risk assessment, and incident investigation
  • Worker consultation records for changes that affect OH&S (new equipment, process changes, facility modifications)
  • Hazard reporting system data showing worker engagement
  • Safety suggestion scheme records with management responses
  • Evidence that workers are consulted on OH&S policy and objectives
  • Toolbox talk records demonstrating two-way communication, not just one-way instruction

Legal Compliance Review

Your ISO 45001 internal audit must assess how the organisation meets legal and other requirements related to OH&S. Legal compliance is a fundamental expectation of the standard and regulatory authorities.

  • Is a legal register maintained and updated with changes in OH&S legislation?
  • Are changes to OH&S regulations monitored and communicated?
  • Are compliance evaluations conducted at planned intervals?
  • Are noncompliances identified, corrected, and prevented from recurring?
  • Are permits, licenses, and registrations current (e.g. dangerous goods storage, fire safety, environmental permits)?
  • Are statutory inspection records maintained (lifting equipment, pressure vessels, electrical installations, fire extinguishers)?
  • Are required notices displayed (health and safety law poster, fire evacuation plan, first aid notices)?
  • Are regulatory reports submitted on time (incident notifications, statistical returns)?

Frequently Asked Questions

How often should ISO 45001 internal audits be performed?

At least annually, with higher-risk areas audited more frequently. Construction sites, chemical handling areas, confined space operations, and manufacturing floors should be audited quarterly. Administrative offices can be audited annually.

Who can perform an ISO 45001 internal audit?

Any competent person with ISO 45001 auditor training and knowledge of OH&S management. Auditors must be independent of the area being audited. Many organisations use cross-departmental internal auditors or external OH&S specialists.

Do I need to audit every department in every audit cycle?

Not necessarily. Use a risk-based approach. High-risk departments (production, maintenance, logistics, laboratories) should be audited each cycle. Lower-risk areas (administrative offices, remote sales offices) can be audited less frequently.

How do I audit worker consultation and participation?

Review safety committee records, interview worker representatives, check hazard reporting system usage data, observe whether workers participate in risk assessments, and verify their involvement in incident investigations and safety inspections.

What records must be kept from an ISO 45001 internal audit?

Audit programme documentation, audit schedule, completed checklists, audit report, nonconformity records, corrective actions, and evidence of corrective action effectiveness. These serve as evidence for external certification audits and regulatory inspections.

Can ISO 45001 be audited together with ISO 9001 and ISO 14001?

Yes. Integrated management system (IMS) audits are common and efficient. An integrated checklist covering quality, environment, and health and safety reduces duplication, saves audit time, and provides a holistic view of organisational performance.

What is the most common ISO 45001 audit finding?

The most common finding is inadequate worker consultation and participation. Many organisations have a safety committee on paper but cannot demonstrate meaningful worker involvement in hazard identification, risk assessment, and incident investigation.

How do I close an ISO 45001 nonconformity?

Perform root cause analysis, implement corrective action addressing the root cause, verify effectiveness through follow-up, and document the entire process. Present closure evidence to the audit team for review and acceptance.

Get ISO 45001 Internal Audit Support

Bitrixme provides complete ISO 45001 internal audit services across the Middle East. From custom checklists and auditor training to full audit outsourcing, our OH&S specialists help you build a safer workplace and achieve certification.

Our consultants have extensive experience across construction, manufacturing, oil and gas, healthcare, and logistics sectors. We understand the specific OH&S challenges faced by organisations in the GCC region and tailor our services accordingly.

Contact Bitrixme for ISO 45001 OH&S audit services or reach out on WhatsApp for a free consultation.