ISO 45001:2018 Internal Audit Checklist — Clause-by-Clause Guide

ISO 45001:2018 is the international standard for Occupational Health and Safety (OH&S) management systems. Achieving and maintaining certification requires systematic internal audits that verify your management system is implemented, maintained, and continually improved. Certification auditors from registrars like BSI, DNV, Bureau Veritas, or SGS will examine the same clause-by-clause requirements your internal audit program should address — and they will interview frontline workers, not just review documentation.

This guide walks through Clauses 4–10 of ISO 45001:2018 with the specific evidence auditors look for, the most common nonconformities in each clause, and how to close them before your certification or surveillance audit.

Understanding the ISO 45001 Structure

ISO 45001 follows the Annex SL High Level Structure shared by ISO 9001:2015 and ISO 14001:2015, enabling integration with those management systems where multiple certifications are maintained. Clauses 1–3 (Scope, Normative References, Terms) are not audited for compliance. Clauses 4–10 contain all auditable requirements.

A critical point that surprises many organizations during first-time certification: ISO 45001 auditors conduct extensive worker interviews. The standard requires that worker participation be genuine, and auditors verify this by talking to frontline employees — not just the EHS manager. If workers cannot describe their role in hazard identification or explain how to raise a safety concern, that is evidence of a system failure regardless of what the documentation says.

Clause 4 — Context of the Organization

What auditors check

  • 4.1 Understanding the organization: Is there a documented analysis of internal and external issues relevant to the OH&S management system's purpose? Internal factors include organizational culture, workforce characteristics, existing safety controls, and the physical work environment. External factors include regulatory environment, industry standards, community expectations, and supply chain influences.
  • 4.2 Interested parties: Has the organization systematically identified workers, contractors, visitors, customers, regulators, unions, and other relevant interested parties? Are their needs and expectations (particularly OH&S-related) documented and periodically reviewed?
  • 4.3 Scope of the OH&S MS: Is the scope documented, and does it include all relevant sites, activities, and processes? Is the scope realistic — not artificially narrow to exclude high-risk operations or contractors?
  • 4.4 OH&S MS: Is there evidence that the management system is actively maintained and improved, not just a static set of documents?

Common nonconformities

The most frequent Clause 4 finding is a context analysis completed once for initial certification and never revisited. Auditors will ask: "When was this last reviewed? What changed in the business since then?" New regulations, new operations, acquisitions, or significant workforce changes should all trigger a context review. Treating the context analysis as a one-time deliverable rather than a living document is a systematic failure.

Clause 5 — Leadership and Worker Participation

What auditors check

  • 5.1 Leadership: Can top management demonstrate commitment beyond signing the OH&S policy? Auditors interview senior leaders to verify they can articulate OH&S objectives, describe their personal involvement in safety activities, and explain how OH&S considerations are integrated into business decisions (capital investment, staffing, scheduling).
  • 5.2 OH&S Policy: Is the policy specific to the organization's context, not a generic template? Is it communicated to and understood by all workers, including contractors and visitors? Is it available to external interested parties?
  • 5.3 Roles and responsibilities: Are OH&S responsibilities assigned at all levels, documented, and understood? Auditors will ask workers at various levels what their personal OH&S responsibilities are.
  • 5.4 Consultation and participation: Are workers meaningfully involved in hazard identification, risk assessment, objective-setting, and incident investigation? Is there a formal mechanism for workers to raise safety concerns? Do workers actually use it?

Common nonconformities

Clause 5.4 worker participation is the single most frequently cited gap in ISO 45001 audits. Many organizations have a safety committee that meets quarterly, but frontline workers report they have no meaningful way to raise safety concerns, or that suggestions are acknowledged and never acted upon. Auditors will interview frontline workers directly and ask: "When did you last participate in a hazard identification exercise? What was the outcome? Did your input change anything?" If workers describe a passive, top-down safety program, that is a systemic Clause 5.4 gap regardless of how the documentation is written.

Clause 6 — Planning

What auditors check

  • 6.1.1 Actions to address risks and opportunities: Is there a documented, systematic process for identifying OH&S risks and opportunities — including risks from external issues, the needs of interested parties, and potential changes to the management system?
  • 6.1.2 Hazard identification: Is hazard identification an ongoing, continuous process — not just an annual exercise? Does it cover routine activities, non-routine activities (maintenance, turnarounds, emergencies), and activities performed by contractors and visitors? Are workers involved in identifying hazards in their own work areas?
  • 6.1.3 Legal and other requirements: Is there a legal register that is kept current? Does the organization know which specific regulatory requirements apply to each of its operations? Has compliance been formally evaluated against each requirement, with evidence of the evaluation?
  • 6.2 OH&S objectives: Are objectives measurable, monitored at defined intervals, and linked to the OH&S policy? Are resources and responsibilities assigned for achieving each objective?

Common nonconformities

An outdated legal register is the most frequently cited Clause 6.1.3 gap. When OSHA issues a new standard, amends an existing one, or a state regulation changes, the legal register must be updated. Beyond maintaining the register, compliance evaluation is the other common gap — many organizations list applicable regulations but have no documented process for verifying whether they are actually in compliance with each one. The difference between having a legal register and evaluating compliance against it is the difference between 6.1.3(a) and 6.1.3(b) conformance.

Clause 7 — Support

  • 7.2 Competence: Are competence requirements defined for all roles with significant OH&S impact? Are qualifications verified before workers are assigned to high-risk tasks? Are training gaps assessed and addressed with documented plans?
  • 7.3 Awareness: Do workers at all levels — including temporary, contract, and part-time workers — know the OH&S policy, their contribution to OH&S management system effectiveness, and the consequences of not conforming to requirements?
  • 7.4 Communication: Is there a documented process for internal OH&S communication (from top management down and from workers up) and external communication (with contractors, visitors, emergency services, regulators)? Is communication happening in both directions?
  • 7.5 Documented information: Are required documents current, controlled, and accessible where needed? Are obsolete versions removed from use? Are external documents (regulatory standards, supplier SDSs) identified and controlled?

Clause 8 — Operation

  • 8.1 Operational planning and control: Are controls for identified OH&S risks implemented and maintained? Are they integrated into work processes, not just documented in the safety program? Are controls reviewed periodically for continued effectiveness?
  • 8.1.3 Management of change: Is there a formal process for evaluating OH&S impacts before making changes to operations, equipment, materials, or personnel? Are temporary changes managed the same way as permanent ones? Is the MOC process documented and followed consistently?
  • 8.1.4 Procurement and contractors: Are contractor OH&S requirements clearly defined in contracts? Is contractor compliance evaluated before and during work? Are contractors informed of site hazards specific to their work?
  • 8.2 Emergency preparedness and response: Are emergency response procedures in place for all credible emergency scenarios? Are procedures tested through drills? Are workers trained in emergency response roles?

Clause 9 — Performance Evaluation

  • 9.1 Monitoring and measurement: What OH&S performance metrics are tracked? Leading indicators (near-misses reported, training completion rates, inspection scores, hazard identification rates) should be monitored alongside lagging indicators (injury rates, TRIR, DART). Monitoring results must be analyzed and used to drive decisions.
  • 9.2 Internal audit: Is there a documented internal audit program with defined schedules and audit criteria? Are auditors competent and independent from the area being audited? Are findings documented, tracked, and closed within committed timeframes?
  • 9.3 Management review: Does top management review the OH&S MS at planned intervals, examining all required inputs (audit results, hazard identification outputs, incident investigation findings, objectives progress, legal compliance)? Are actions from management reviews implemented and tracked?

Clause 10 — Improvement

  • 10.1 Incidents, nonconformances, and corrective actions: Are all incidents (including near-misses and hazardous conditions) investigated? Are root causes determined using a structured methodology? Are corrective actions implemented and their effectiveness verified — not just closed on paper?
  • 10.2 Continual improvement: Is there evidence that OH&S performance is improving over time? Can the organization demonstrate favorable trends — declining injury rates, increasing near-miss reporting, improving inspection scores — that support a claim of continual improvement?

Internal Audit Checklist: Key Interview Questions by Clause

  • [4.1] When was the context analysis last updated? What business or regulatory changes triggered a review?
  • [5.4] Ask frontline workers: How did you participate in the last hazard identification exercise? What happened to your input?
  • [6.1.3] Show me your legal register. When was it last reviewed? Show me your compliance evaluation for the three most significant regulations that apply to this operation.
  • [7.2] For a high-risk role: Show me the competence requirements, the qualification verification, and the training record for the person currently in this role.
  • [8.1.3] Walk me through the last three significant changes made to this facility. Was an OH&S impact assessment completed for each one?
  • [9.1] What OH&S metrics does top management review monthly? Show me the trend data for the last 12 months.
  • [10.1] Show me your last three incident investigations. Was a root cause identified in each? Were corrective actions completed and effectiveness verified?

How POPProbe Supports ISO 45001 Internal Audits

POPProbe's ISO 45001 checklists are clause-mapped, allowing internal auditors to conduct clause-specific audits and generate findings reports that link directly to the standard's requirements. Digital audit trails show certification bodies that your internal audit program is systematic, evidence-based, and not just a checklist exercise.

Explore ISO 45001 clause-mapped checklists in our regulatory compliance checklist hub, including context analysis templates, hazard identification registers, legal compliance evaluation tools, and management review agenda templates in the checklist library.

Conclusion

ISO 45001 internal audits are most valuable when they go beyond document review to verify that the management system is actually working — that workers can describe their role in hazard identification, that legal register is current, that MOC is being used for all changes, and that incident investigations produce root causes and verified corrective actions. Certificate-winning programs treat internal audits as genuine improvement tools, not pre-audit rehearsals. The result is a surveillance audit that confirms what you already know: the system works.

Related Resources

POPProbe