Industry

ISO 45001 Internal Audit Checklist (Downloadable)

Equip IgeraSolutions
September 25, 2026
9 min read
ISO 45001 Internal Audit Checklist (Downloadable)
🎧 Listen with AI Voice

2-minute executive summary

⚡ Quick Answer in 30s

Self-assess ISO 45001 readiness with a clause-by-clause internal audit checklist covering all 7 mandatory clauses, plus worker consultation evidence.

✓ Citing current regulationsSee detailed guide below ↓

ISO 45001 Internal Audit Checklist (Downloadable)

A practical ISO 45001:2018 internal audit checklist walks an OH&S manager through all seven mandatory clauses — 4 (Context), 5 (Leadership & Worker Participation), 6 (Planning), 7 (Support), 8 (Operation), 9 (Performance Evaluation), and 10 (Improvement) — so gaps surface before a certification or surveillance auditor finds them. Use it as a structured self-assessment ahead of every internal audit cycle, not as a substitute for the standard itself.

ISO 45001 differs from most other management system standards in one important respect: it places worker participation and consultation at the centre of the standard rather than treating it as a supporting clause. An OH&S manager who prepares for an internal audit the same way they would for ISO 9001 or ISO 14001 — checking documents and records — will often miss exactly the evidence a certification body looks for hardest: proof that workers were genuinely consulted, not just informed. This guide turns the seven mandatory clauses into a checklist you can run against your OH&S management system before your next internal audit, surveillance visit, or recertification.

Why an internal audit checklist matters

ISO 45001:2018 Clause 9.2 requires organisations to conduct internal audits at planned intervals to determine whether the OH&S management system conforms to the organisation's own requirements and to the standard, and is effectively implemented and maintained. Certification body auditors are trained to trace evidence end to end — from a hazard identified on the risk register, through the control measures applied, to the incident records (or near-miss reports) that show whether those controls actually worked in practice. Your internal audit should do the same tracing before an external auditor does.

A checklist-based approach also creates a defensible audit trail of its own: dated records showing what was checked, what was found, and what corrective action followed. That trail is itself audit evidence for Clause 9.2 and 9.3 (management review), and it is often the first thing an auditor asks to see.

The checklist: Clauses 4 to 10

Clause 4 — Context of the Organisation

  • Are internal and external issues relevant to OH&S outcomes identified and reviewed on a defined schedule?
  • Are the needs and expectations of interested parties (workers, regulators, contractors, neighbours) documented, including which are legal or other requirements the organisation must comply with?
  • Is the scope of the OH&S management system documented, available, and does it match what the organisation actually does on site?
  • Does the OH&S management system account for activities, products, and services the organisation controls or influences, including those of contractors and visitors?

Clause 5 — Leadership & Worker Participation

  • Can top management demonstrate accountability for the OH&S management system, beyond delegating it entirely to a safety officer?
  • Is the OH&S policy documented, communicated, and understood by workers at all levels, not just posted on a noticeboard?
  • Are roles, responsibilities, and authorities for OH&S assigned and communicated, with evidence people understand what is expected of them?
  • Is there a documented process for worker participation and consultation that covers the areas Clause 5.4 specifies — see the dedicated section below.

Clause 6 — Planning

  • Hazard identification: Is there a documented, ongoing process for identifying hazards, including routine and non-routine activities, past incidents, and changes to processes or equipment?
  • Risk assessment: Are OH&S risks assessed using a defined methodology, with the assessment kept current as conditions change?
  • Legal and other requirements: Is there a register of applicable legal and regulatory requirements, and can the organisation demonstrate how it evaluates compliance against it?
  • Opportunities: Are OH&S opportunities (not just risks) identified, such as improved ways to eliminate hazards or redesign work?
  • Are OH&S objectives documented, measurable where practicable, and linked to action plans with owners and timeframes?

Clause 7 — Support

  • Are resources for the OH&S management system (people, budget, equipment) identified and allocated, not just assumed available?
  • Are competence requirements defined for roles affecting OH&S performance, with training records current for every relevant worker?
  • Is there evidence workers are aware of the OH&S policy, their contribution to it, and the consequences of not following procedures?
  • Are internal and external OH&S communications documented, including how and when workers are informed of changes affecting their safety?
  • Is documented information controlled — current versions in use, obsolete versions removed from circulation, and retention periods followed?

Clause 8 — Operation

  • Are operational controls implemented to eliminate hazards or reduce OH&S risks, following the hierarchy of controls (elimination, substitution, engineering controls, administrative controls, PPE)?
  • Is management of change documented for new equipment, processes, or organisational changes that could introduce new OH&S risks?
  • Are procurement processes controlled so that contractors and purchased goods/services meet the organisation's OH&S requirements?
  • Is there a documented emergency preparedness and response process, tested at planned intervals, with evidence of drills or exercises?
  • Are contractors' and visitors' OH&S obligations defined, communicated, and monitored while they are on site?

Clause 9 — Performance Evaluation

  • Is OH&S performance monitored, measured, and evaluated against defined indicators, with results reported to relevant workers and management?
  • Is compliance with legal and other requirements evaluated at planned intervals, with records of the evaluation and any resulting action?
  • Has an internal audit programme been planned and executed, covering all applicable clauses and the full scope of certification?
  • Has management review taken place at the planned interval, with all required inputs (audit results, incident data, worker consultation feedback, changes to context) addressed and outputs actioned?

Clause 10 — Improvement

  • Are incidents, non-conformances, and near misses reported, investigated, and root-caused, with evidence corrective action addressed the actual cause?
  • Are workers involved in incident investigations and corrective action decisions where they are affected, consistent with the participation requirements in Clause 5?
  • Is there evidence of continual improvement to the OH&S management system, not just closure of individual corrective actions?
  • Are lessons from incidents and audits fed back into hazard identification and risk assessment (Clause 6), closing the loop rather than treating each event in isolation?

Worker participation & consultation: a dedicated checklist

Worker participation is one of the features that sets ISO 45001 apart from other Annex SL-structured standards such as ISO 9001 or ISO 14001. Clause 5.4 requires organisations to establish, implement, and maintain a process for worker participation and consultation, and to remove or minimise barriers to it — such as language, literacy, fear of reprisal, or policies that discourage worker input. Auditors treat this as substantive evidence, not paperwork, so it deserves its own preparation pass rather than being folded into the general Clause 5 review above.

Worker participation evidence checklist

  • Can workers describe, in their own words, how they are consulted on hazard identification, risk assessment, and control measures that affect them?
  • Are non-managerial workers involved in developing and reviewing the OH&S policy and objectives, with dated records of their input?
  • Is there a documented mechanism (safety committee, toolbox talks, suggestion scheme, worker representatives) through which workers raise concerns, and can you produce minutes or logs showing it is actually used?
  • Are workers consulted on incident investigations that affect them, and on changes to work organisation, equipment, or procedures before those changes take effect?
  • Have barriers to participation (language, shift patterns, contractor status, literacy, fear of reprisal) been identified and actively addressed, rather than assumed not to exist?
  • Is there evidence workers were consulted on the selection of PPE and on the determination of competence, training needs, and evaluation criteria that affect them?
  • Do consultation records show two-way engagement — worker input that visibly influenced a decision — rather than one-way notices dressed up as consultation?

The distinction auditors look for is between informing workers and consulting them. A noticeboard announcement or a signed-off toolbox talk register shows communication; it does not, on its own, show that worker input shaped a decision. Auditors interview shop-floor workers directly and often ask them to describe a recent example of raising a concern and what happened next — an OH&S manager who cannot produce a matching record on the day risks a finding even if the management system documentation looks complete.

Practical impact: what auditors actually check

Certification auditors rarely work clause by clause in isolation — they trace a sample of hazards, incidents, or risk assessments back through the whole chain: was the hazard identified, was it risk-assessed using the defined methodology, were controls applied following the hierarchy of controls, were affected workers consulted, and did any resulting incident get investigated and closed out with evidence the corrective action worked? A single broken link anywhere in that chain — a risk assessment that was never updated after a process change, or a corrective action with no evidence of worker involvement — typically becomes a finding, even if every other document in the file is correct.

This is why the checklist above is organised by clause but should be executed by tracing a handful of real hazards or incidents end to end, not by ticking boxes in isolation. Pull three to five recent incident reports or risk assessments at random, and walk each one back through hazard identification, risk assessment, control measures, worker consultation, and any resulting corrective action — exactly as an auditor would.

Common mistakes organisations make before an audit

  • Treating worker participation as a one-way communication exercise. Posting information is not consultation; auditors want to see evidence that worker input changed a decision.
  • Auditing documents instead of evidence. A procedure that exists on paper but isn't followed in practice is a bigger risk than a missing procedure — auditors interview workers and observe work specifically to catch this gap.
  • Losing traceability between hazard, risk assessment, and incident records. When these live in separate folders or systems, it becomes hard to reconstruct the chain quickly — both for your own internal audit and for an external auditor.
  • Closing corrective actions without addressing root cause. A recurring incident type is one of the clearest signals to an auditor that the management system isn't functioning as intended.
  • Leaving internal audits until just before recertification. Clause 9.2 expects audits at planned intervals throughout the certification cycle, not a single pre-assessment scramble.

Making audit evidence instantly searchable

The chain-tracing exercise above — matching a hazard to its risk assessment, control measures, worker consultation record, and any related incident — is usually the slowest part of audit preparation, simply because the documents live in different folders, formats, and systems. IgeraIndustria is built to answer questions directly from an organisation's own OH&S documents — the standard, risk assessments, incident records, and audit history — with an exact citation back to the source document and clause, so an OH&S manager can ask "which risk assessments haven't been reviewed since the last process change?" or "what was the corrective action for the last near miss on the loading bay?" and get a traceable answer in seconds rather than an afternoon of file searching.

Frequently asked questions

How often should ISO 45001 internal audits be conducted?

The standard requires internal audits "at planned intervals" without specifying a fixed frequency, so the organisation must define this itself — typically annually, covering the full scope of certification across the cycle, though many organisations stagger clause-by-clause or site-by-site audits throughout the year.

Why does ISO 45001 emphasise worker participation more than other management system standards?

ISO 45001 is built on the principle that the people doing the work are best placed to identify hazards and evaluate whether controls are practical, so Clause 5.4 makes participation and consultation a distinct, explicit requirement rather than an implicit part of communication, which is how comparable Annex SL standards typically treat stakeholder input.

Who can perform an ISO 45001 internal audit?

Internal audits should be conducted by personnel who are competent to audit against the relevant requirements and, wherever resources allow, are independent of the activity being audited to avoid auditing their own work.

Does this checklist replace the official ISO 45001:2018 text?

No. This checklist is a practical preparation aid and should always be used alongside the current official standard and your certification body's specific requirements, which may include additional national or sector-specific criteria.

What happens if an internal audit finds a non-conformance?

Non-conformances found during internal audits should be logged, root-caused, and corrected through the organisation's documented corrective action process, with evidence retained that the action was effective — this record itself becomes an input to management review.

Can a small organisation use this same checklist?

Yes — the seven clauses apply regardless of organisation size, though how each requirement is met (for example, how worker participation is structured with a small headcount) will vary. Smaller organisations may need to bring in an external, qualified internal auditor to maintain independence.

How does this checklist relate to management review?

Internal audit results are a mandatory input to management review under Clause 9.3, so completing this checklist and documenting findings feeds directly into that review, closing the loop between day-to-day OH&S checks and the organisation's strategic oversight of its management system.

Disclaimer: This checklist is provided for general informational and preparatory purposes only and does not constitute certification, legal, or regulatory advice. Requirements and their interpretation can vary by certification body, jurisdiction, and sector. Organisations should consult the current official text of ISO 45001:2018, their certification body, and a qualified OH&S consultant before making decisions that affect certification status or worker safety.

#ISO 45001 internal audit checklist#ISO 45001 audit preparation#occupational health and safety audit#worker participation ISO 45001#ISO 45001 clauses 4-10#OH&S management system audit#ISO 45001 certification audit#safety management system checklist

Ask this article

IA 2026

Igera's AI answers questions citing the facts and regulations in this article

2 of 2 free queries

Suggested questions (click to test):

Diagnóstico Interactivo 60s

Technical Compliance & Industrial Operations Diagnostic

Analyze speed of access to regulations (CTE, OSH, CE) in your plant or jobsite

Pregunta 1 de 3

How do technicians and operators access safety protocols and manuals?

Was this article helpful?

⚙️IgeraIndustriaOperations Template
GUÍA DESCARGABLE (TXT)

Preventive Maintenance & ISO 9001/45001 Industrial Checklist

Floor inspection template for machine operations, failure tracking and unplanned downtime reduction.

  • Shift inspection standardization for plant operators
  • Up to 40% faster anomaly response times
  • Full traceability for ISO audits and HSE compliance

Instant download · No card · 100% spam-free

Share this article

Help spread knowledge by sharing this content with your network