Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 45001 Mandatory Documents — guide from Governance Docs

ISO 45001 Mandatory Documents and Records, Clause by Clause

ISO 45001:2018 uses the phrase “documented information” rather than documents and records, but the
practical question is unchanged: what must you actually be able to produce at audit? This is the list
of ISO 45001 mandatory documents, clause by clause, and the smaller list of things
that are not required but are always requested anyway.

ISO 45001 mandatory documents do not include a manual

Start with what the standard does not ask for. ISO 45001 does not require a
quality-manual-style OH&S manual
, and it does not require documented procedures for
their own sake. Clause 7.5 asks you to maintain the documented information the standard specifies,
plus whatever else you determine is necessary for the system to be effective. That second half is a
judgement call, not a loophole — if a process is complex, safety-critical or performed rarely,
an auditor will expect it written down whether or not a clause names it.

This is where effort is wasted on things that are not ISO 45001 mandatory documents at all. Organisations write a 90-page manual restating the
standard, and it earns nothing at audit because it evidences no activity.

The ISO 45001 mandatory documents, by clause

The ISO 45001 mandatory documents below are the items the standard requires you to maintain — the documents that
define how the system works.

  • 4.3 — the scope of the OH&S management system.
  • 5.2 — the OH&S policy.
  • 5.3 — roles, responsibilities and authorities.
  • 6.1.1 — the OH&S risks and opportunities, and the processes and
    actions needed to address them.
  • 6.1.2 — the methodology and criteria for assessing OH&S risks.
    Note that it is the method that must be documented, not only the results.
  • 6.1.3 — legal requirements and other requirements: the legal register.
  • 6.2.2 — the OH&S objectives and the plans to achieve them.
  • 8.1.1 — operational planning and control, to the extent necessary to have
    confidence the processes are carried out as planned.
  • 8.2 — the emergency preparedness and response process and plans.

The records ISO 45001 requires you to retain

These are the outputs — the evidence that the system ran. Auditors sample these far harder
than they read the documents above.

  • 7.2 — evidence of competence.
  • 7.4.1 — evidence of communications, internal and external.
  • 9.1.1 — results of monitoring, measurement, analysis and performance
    evaluation, and evidence that monitoring equipment is maintained, calibrated or verified where
    applicable.
  • 9.1.2 — results of the evaluation of compliance with legal and other
    requirements.
  • 9.2.2 — the internal audit programme and the audit results.
  • 9.3 — the results of management review.
  • 10.2 — incidents, nonconformities, the actions taken and their results,
    including the results of any corrective action and its effectiveness.
  • 10.3 — evidence of continual improvement.

Every document on this list, already drafted.

The ISO 45001 Toolkit provides the scope statement, policy, risk methodology, legal register, objectives plan, emergency procedures, audit set and incident forms in Word and Excel, cross-referenced to the clause each one satisfies.

Explore the ISO 45001 Toolkit →

Beyond the ISO 45001 mandatory documents: what auditors still ask for

A second tier exists that no clause names outright, and that no audit finishes without.
The hazard identification records themselves — 6.1.2 mandates the methodology,
but an auditor will want the assessments. Consultation and participation records
under 5.4: minutes, committee terms of reference, evidence that non-managerial workers were involved.
Contractor and procurement controls under 8.1.4, including how you evaluate
contractors and what you require of them. And change management records under 8.1.3,
which is where a surprising number of incidents originate.

Treating these as optional because no clause says “documented information” is the most common
route to an avoidable finding.

How much detail the ISO 45001 mandatory documents need

Clause 7.5.1 settles it: the extent of documented information can differ between organisations
based on size, activities, processes, and the competence of workers. A twelve-person joinery firm
does not need what a chemical plant needs. The test an auditor applies is whether someone competent
could run the process from what is written, and whether what is written matches what people actually
do. A document that describes an aspirational process nobody follows is worse than none, because it
is a nonconformity against your own system.

Keep the set of ISO 45001 mandatory documents tight and well maintained rather than voluminous. Sample documents are
available as free ISO templates if you want to see the format first.

References

More on ISO 45001

All of these are covered by the ISO 45001 Toolkit. To score where you stand first, use the ISO 45001 Assessment Tool, or browse the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.