ISO 45001 · Step-by-step series · Article 6 of 7
ISO 45001 Clause 9: Performance Evaluation — Monitoring, Internal Audit and Management Review
Clause 9 of ISO 45001:2018 is where an OH&S management system proves it actually works. It is not enough to plan hazard controls under clause 6 and operate them under clause 8 — the organization must monitor whether those controls are effective, check compliance with legal and other requirements, audit the system internally, and have top management formally review the results. This guide breaks down clause 9 subclause by subclause with practical tools you can implement in a mid-sized industrial site.
Clause 9 findings are consistently among the most common nonconformities in ISO 45001 certification audits
Across sector experience with OH&S audits, gaps in clause 9 typically concentrate in two areas: monitoring plans that exist on paper but are not followed with evidence, and management reviews that happen as a meeting without covering the mandatory inputs and outputs the standard requires. Both are avoidable with a structured, repeatable process.
Structure of clause 9: closing the loop on OH&S performance
Clause 9 has three subclauses that together close the Check part of the Plan-Do-Check-Act cycle for occupational health and safety:
- 9.1 Monitoring, measurement, analysis and performance evaluation: what data you collect on your OH&S performance and how you evaluate compliance with legal requirements.
- 9.2 Internal audit: a planned, systematic, independent verification that the OH&S management system conforms to the organization's own requirements and to ISO 45001, and that it is effectively implemented and maintained.
- 9.3 Management review: top management's periodic, structured evaluation of the OH&S management system's suitability, adequacy and effectiveness, feeding decisions on resources, priorities and continual improvement.
9.1.1 Monitoring, measurement, analysis and performance evaluation: what you need to track
Clause 9.1.1 requires the organization to determine what needs to be monitored and measured, including the extent to which legal requirements and other requirements are met; its activities and operations related to identified hazards, risks and opportunities; progress toward achieving the organization's OH&S objectives; and the effectiveness of operational and other controls.
The organization must also determine the methods for monitoring, measurement, analysis and performance evaluation, as applicable, to ensure valid results; the criteria against which it will evaluate its OH&S performance; when the monitoring and measuring will be performed; and when the results will be analysed, evaluated and communicated.
In practice, a mature OH&S monitoring plan combines several types of indicators:
- Lagging indicators: incident rate, lost-time injury frequency rate, severity rate, near-miss reports, first-aid cases.
- Leading indicators: percentage of scheduled safety inspections completed, training completion rate, corrective actions closed on time, number of hazards reported and resolved, hazard identification and risk assessment (HIRA) reviews completed on schedule.
- Operational control checks: calibration status of gas detectors and monitoring equipment, permit-to-work compliance rate, PPE availability and condition audits.
ISO 45001 explicitly requires that equipment used for monitoring and measurement is calibrated or verified, and used and maintained as appropriate. Where measuring equipment produces the evidence used to demonstrate compliance with legal requirements, an out-of-calibration instrument can invalidate an entire audit trail — this is why calibration records for gas detectors, noise dosimeters and similar equipment are a frequent audit focus point.
Practical tip
Do not rely solely on lagging indicators such as accident rate — a low accident rate can mean genuinely good performance, or it can mean under-reporting. Pair every lagging indicator with at least one leading indicator that measures whether preventive activity is actually happening (inspections completed, near misses reported, training delivered). A monitoring plan built only on outcomes gives you no early warning before something goes wrong.
9.1.2 Evaluation of compliance: proving you meet legal requirements
Clause 9.1.2 requires the organization to establish, implement and maintain a process to evaluate compliance with legal requirements and other requirements identified under clause 6.1.3. The organization must determine the frequency and methods for the evaluation, evaluate compliance and take action if needed, maintain knowledge and understanding of its compliance status, and retain documented information as evidence of the compliance evaluation results.
This is one of the clauses most often confused with a legal register review. A legal register lists which requirements apply to you; the compliance evaluation is the separate, ongoing exercise of checking, requirement by requirement, whether you actually meet each one — and keeping evidence of that check. In practice this typically takes the form of a compliance evaluation matrix reviewed on a defined cycle (commonly annual, or more frequently for high-risk requirements such as pressure equipment inspections or confined-space permits), with each line item marked compliant, partially compliant, or non-compliant, and an owner and due date assigned for any gap found.
9.2 Internal audit: verifying the system from the inside
Clause 9.2 is split into two subclauses: 9.2.1 sets the general requirement to conduct internal audits at planned intervals, and 9.2.2 details how the audit programme must be planned, established, implemented and maintained.
9.2.1 General — what internal audits must confirm
Internal audits provide information on whether the OH&S management system conforms to the organization's own requirements for its OH&S management system, including the OH&S policy and OH&S objectives; the requirements of ISO 45001 itself; and whether the system is effectively implemented and maintained. Effectiveness matters as much as conformity — an audit that only checks whether a procedure exists, without checking whether it is actually followed and produces the intended result, has not fully satisfied 9.2.1.
9.2.2 Internal audit programme — planning, selecting auditors, reporting
The organization must plan, establish, implement and maintain an audit programme including the frequency, methods, responsibilities, consultation, planning requirements and reporting, which must take into consideration the importance of the processes concerned and the results of previous audits. It must define the audit criteria and scope for each audit, select auditors and conduct audits to ensure objectivity and the impartiality of the audit process, ensure that the results of the audits are reported to relevant managers, ensure that relevant audit findings are reported to workers, workers' representatives and other relevant interested parties, take action to address nonconformities and continually improve OH&S performance, and retain documented information as evidence of the implementation of the audit programme and the audit results.
Two requirements in 9.2.2 are frequently underestimated in practice. First, auditor impartiality: an auditor cannot audit their own area of direct responsibility, which in smaller sites often means training a cross-functional pool of auditors or bringing in an external auditor for certain processes. Second, communicating audit findings to workers and their representatives, not only to management — this reflects the strong worker-participation ethos that runs through ISO 45001 as a whole, and is easy to overlook if the audit process is treated as a purely management-to-management exercise.
9.3 Management review: what top management must formally consider
Clause 9.3 requires top management to review the organization's OH&S management system at planned intervals to ensure its continuing suitability, adequacy and effectiveness. The standard lists the inputs that the review must take into account, and this list is one of the most commonly cited nonconformities when reviews are held as a general meeting rather than against the specific required agenda.
The mandatory management review inputs under ISO 45001 include:
- The status of actions from previous management reviews.
- Changes in external and internal issues relevant to the OH&S management system, including changes in the needs and expectations of interested parties, legal requirements and other requirements, and risks and opportunities.
- The extent to which OH&S policy and OH&S objectives have been met.
- Information on OH&S performance, including trends in incidents, nonconformities, corrective actions and continual improvement; monitoring and measurement results; results of evaluation of compliance with legal requirements and other requirements; audit results; consultation and participation of workers; and risks and opportunities.
- Adequacy of resources for maintaining an effective OH&S management system.
- Relevant communication(s) with interested parties.
- Opportunities for continual improvement.
The outputs of the management review must include decisions related to the continuing suitability, adequacy and effectiveness of the OH&S management system in achieving its intended outcomes; continual improvement opportunities; any need for changes to the OH&S management system; resources needed; actions if needed; opportunities to improve integration with other business processes; and any implications for the strategic direction of the organization. The organization must retain documented information as evidence of the results of management reviews, and communicate the relevant outputs to workers and their representatives.
| Management review input | Typical evidence source | Mandatory |
|---|---|---|
| Status of previous actions | Action tracker from the last management review, with open/closed status | Yes |
| Internal/external issues and interested parties | Updated clause 4.1/4.2 context register | Yes |
| OH&S objectives achievement | Objectives dashboard vs. targets set under clause 6.2 | Yes |
| Incident and nonconformity trends | Incident log, corrective action register, trend charts | Yes |
| Compliance evaluation results (9.1.2) | Compliance evaluation matrix with latest status | Yes |
| Internal audit results (9.2) | Audit programme summary and open findings | Yes |
| Worker consultation and participation | Minutes from OH&S committee or worker consultation records | Yes |
| Resource adequacy | Budget review, staffing levels for OH&S roles | Yes |
Most common audit findings in clause 9
These are the recurring gaps seen most often when clause 9 is examined in third-party audits of industrial sites:
- 9.1.1 — Monitoring plan without evidence of execution: a document lists what should be monitored and how often, but there are no dated records showing the monitoring actually took place.
- 9.1.1 — Uncalibrated monitoring equipment: gas detectors, noise meters or vibration monitors used to demonstrate compliance are past their calibration due date.
- 9.1.2 — Compliance evaluation confused with the legal register: the organization can show a list of applicable legal requirements but cannot show evidence of having checked, requirement by requirement, whether it currently complies.
- 9.2.2 — Auditor impartiality not addressed: the same person who manages a process also audits that process, with no compensating control such as a second reviewer or an external auditor.
- 9.2.2 — Audit findings not communicated to workers: results go to managers only, with no evidence that relevant findings reached workers or their representatives.
- 9.3 — Management review missing mandatory inputs: minutes show a general safety discussion but do not demonstrate that each of the required inputs (compliance evaluation, audit results, worker consultation, resource adequacy, and the others) was actually considered.
// Demo IgeraIndustria — Clause 9 performance evaluation query
OH&S Manager: Which compliance evaluation items are overdue for review this quarter?
IgeraIndustria: Compliance evaluation register (clause 9.1.2): 2 items overdue. Item CE-014 — Confined space entry permit procedure vs. local OH&S regulation, last reviewed 2025-10-12, due 2026-04-12, overdue 108 days. Item CE-021 — Fire extinguisher inspection frequency vs. applicable fire code, last reviewed 2026-01-08, due 2026-07-08, overdue 23 days. Recommended action: schedule both reviews before the next internal audit cycle and assign an owner in the compliance register.
Internal Auditor: Show me the open findings from the last internal audit that feed into the upcoming management review.
IgeraIndustria: Internal audit IA-2026-02, conducted 2026-05-14, scope: warehouse and maintenance workshop. Open findings: NC-09-011 — permit-to-work records incomplete for 3 of 12 sampled hot-work jobs, corrective action assigned to workshop supervisor, due 2026-08-15. OBS-09-004 — near-miss reporting rate in maintenance is below the site average, recommend targeted awareness session. Both items are flagged for inclusion in the next management review agenda under clause 9.3 input "internal audit results".
Frequently asked questions about ISO 45001 clause 9
How often must internal audits and management reviews be conducted under ISO 45001?
ISO 45001 does not fix a specific frequency for either internal audits or management review — it requires both to be conducted "at planned intervals" determined by the organization, based on factors such as the importance of the processes involved, changes affecting the organization, and results of previous audits and reviews. In practice, most certified organizations run a full internal audit cycle covering the entire OH&S management system at least once a year, often split into smaller audits of specific processes or areas throughout the year, and hold management review at least annually, frequently more often (quarterly or semi-annually) for higher-risk operations.
What is the difference between the compliance evaluation in 9.1.2 and the legal register from clause 6.1.3?
The legal register (built under clause 6.1.3, on determining legal requirements and other requirements) is the inventory of which requirements apply to the organization. The compliance evaluation under clause 9.1.2 is the separate, ongoing process of actually checking, requirement by requirement, whether the organization currently complies with each item on that register, and retaining evidence of the check. Having a legal register alone does not satisfy 9.1.2 — auditors specifically look for dated evidence that each requirement was checked against actual practice, not just listed.
Can an internal auditor audit their own department under ISO 45001?
Clause 9.2.2 requires the organization to select auditors and conduct audits to ensure the objectivity and impartiality of the audit process. An auditor generally should not audit their own area of direct responsibility, because this compromises independence. Small organizations that lack a large pool of trained internal auditors typically address this by cross-training auditors across departments so each audits a different area than the one they manage, or by bringing in an external auditor or a qualified auditor from a sister site for the areas where no independent internal option exists.
Does ISO 45001 require workers to be told the results of internal audits?
Yes. Clause 9.2.2 explicitly requires that relevant audit findings are reported not only to relevant managers but also to workers, and where they exist, workers' representatives and other relevant interested parties. This reflects the emphasis ISO 45001 places on worker consultation and participation throughout the standard, not only in hazard identification and risk assessment. A common gap found in audits is that findings are shared in a management report but never communicated downward to the workforce.
What must be included in the minutes of a management review to satisfy clause 9.3?
The minutes should demonstrate that top management considered each of the mandatory inputs listed in 9.3: status of actions from previous reviews, relevant internal and external issues, the extent to which OH&S objectives were met, OH&S performance data (incident trends, monitoring and measurement results, compliance evaluation results, audit results, worker consultation and participation, and risks and opportunities), adequacy of resources, relevant communications with interested parties, and opportunities for continual improvement. The minutes must also record the outputs: decisions on the system's continuing suitability, adequacy and effectiveness, any changes needed, resource decisions, and any implications for strategic direction. A generic "safety meeting" summary that does not map to these inputs and outputs is a frequent nonconformity.
Is monitoring only about accident statistics, or does it cover more than that?
Clause 9.1.1 covers far more than accident statistics. It requires monitoring of the extent to which legal requirements are met, of activities and operations related to identified hazards and risks, of progress toward OH&S objectives, and of the effectiveness of operational and other controls. A monitoring plan built solely around lagging indicators such as the accident rate misses most of what 9.1.1 asks for. A well-designed plan mixes leading indicators (inspection completion, training coverage, near-miss reporting, corrective action closure) with lagging indicators, so problems can be caught before they turn into incidents rather than only measured after the fact.
Struggling to keep monitoring plans, compliance evaluations and audit findings connected to your next management review?
IgeraIndustria centralizes clause 9 evidence — monitoring records, compliance evaluation status, internal audit findings and management review inputs — and shows you what is overdue in real time, without digging through spreadsheets.
See the ISO 45001 solutionExpert ISO 45001 · Updated 2026-07-31 · ISO 45001 step-by-step series: Article 1 — Clause 4 · Article 3 — Clause 6 · Article 4 — Clause 7 · Article 5 — Clause 8 · Article 7 — Clause 10