ISO 45001:2018 uses the phrase “documented information” rather than documents and records, but the
practical question is unchanged: what must you actually be able to produce at audit? This is the list
of ISO 45001 mandatory documents, clause by clause, and the smaller list of things
that are not required but are always requested anyway.
ISO 45001 mandatory documents do not include a manual
Start with what the standard does not ask for. ISO 45001 does not require a
quality-manual-style OH&S manual, and it does not require documented procedures for
their own sake. Clause 7.5 asks you to maintain the documented information the standard specifies,
plus whatever else you determine is necessary for the system to be effective. That second half is a
judgement call, not a loophole — if a process is complex, safety-critical or performed rarely,
an auditor will expect it written down whether or not a clause names it.
This is where effort is wasted on things that are not ISO 45001 mandatory documents at all. Organisations write a 90-page manual restating the
standard, and it earns nothing at audit because it evidences no activity.
The ISO 45001 mandatory documents, by clause
The ISO 45001 mandatory documents below are the items the standard requires you to maintain — the documents that
define how the system works.
- 4.3 — the scope of the OH&S management system.
- 5.2 — the OH&S policy.
- 5.3 — roles, responsibilities and authorities.
- 6.1.1 — the OH&S risks and opportunities, and the processes and
actions needed to address them. - 6.1.2 — the methodology and criteria for assessing OH&S risks.
Note that it is the method that must be documented, not only the results. - 6.1.3 — legal requirements and other requirements: the legal register.
- 6.2.2 — the OH&S objectives and the plans to achieve them.
- 8.1.1 — operational planning and control, to the extent necessary to have
confidence the processes are carried out as planned. - 8.2 — the emergency preparedness and response process and plans.
The records ISO 45001 requires you to retain
These are the outputs — the evidence that the system ran. Auditors sample these far harder
than they read the documents above.
- 7.2 — evidence of competence.
- 7.4.1 — evidence of communications, internal and external.
- 9.1.1 — results of monitoring, measurement, analysis and performance
evaluation, and evidence that monitoring equipment is maintained, calibrated or verified where
applicable. - 9.1.2 — results of the evaluation of compliance with legal and other
requirements. - 9.2.2 — the internal audit programme and the audit results.
- 9.3 — the results of management review.
- 10.2 — incidents, nonconformities, the actions taken and their results,
including the results of any corrective action and its effectiveness. - 10.3 — evidence of continual improvement.
Every document on this list, already drafted.
The ISO 45001 Toolkit provides the scope statement, policy, risk methodology, legal register, objectives plan, emergency procedures, audit set and incident forms in Word and Excel, cross-referenced to the clause each one satisfies.
Beyond the ISO 45001 mandatory documents: what auditors still ask for
A second tier exists that no clause names outright, and that no audit finishes without.
The hazard identification records themselves — 6.1.2 mandates the methodology,
but an auditor will want the assessments. Consultation and participation records
under 5.4: minutes, committee terms of reference, evidence that non-managerial workers were involved.
Contractor and procurement controls under 8.1.4, including how you evaluate
contractors and what you require of them. And change management records under 8.1.3,
which is where a surprising number of incidents originate.
Treating these as optional because no clause says “documented information” is the most common
route to an avoidable finding.
How much detail the ISO 45001 mandatory documents need
Clause 7.5.1 settles it: the extent of documented information can differ between organisations
based on size, activities, processes, and the competence of workers. A twelve-person joinery firm
does not need what a chemical plant needs. The test an auditor applies is whether someone competent
could run the process from what is written, and whether what is written matches what people actually
do. A document that describes an aspirational process nobody follows is worse than none, because it
is a nonconformity against your own system.
Keep the set of ISO 45001 mandatory documents tight and well maintained rather than voluminous. Sample documents are
available as free ISO templates if you want to see the format first.
References
- ISO 45001:2018 — the standard itself on iso.org.
- ISO 45001:2018/Amd 1:2024 — the climate action amendment, published free of charge by ISO.
- ISO/DIS 45001 — the draft second edition, currently at DIS ballot.
More on ISO 45001
- ISO 45001 certification
- ISO 45001 implementation guide
- ISO 45001 mandatory documents — you are here
- ISO 45001 risk assessment
- ISO 45001 internal audit checklist
- ISO 45001 gap analysis
All of these are covered by the ISO 45001 Toolkit. To score where you stand first, use the ISO 45001 Assessment Tool, or browse the free ISO templates.