Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 45001 Internal Audit Checklist — guide from Governance Docs

ISO 45001 Internal Audit Checklist: Clause 4 to 10

Clause 9.2 requires internal audits at planned intervals, and it requires them before your
certification audit. This is a working ISO 45001 internal audit checklist by clause,
plus how to build the programme itself — which is what auditors examine first.

The ISO 45001 internal audit programme comes before the checklist

Clause 9.2.2 asks you to plan, establish, implement and maintain an audit programme that takes
account of the importance of the processes concerned and the results of previous audits. That word
“importance” is what makes the programme risk-based. Auditing the stationery cupboard and the
confined-space permit system at equal depth on a rolling annual cycle satisfies the letter and misses
the point.

Build the ISO 45001 internal audit programme from your risk register. High-consequence activities, processes that generated
incidents or findings last cycle, and anything that changed get audited more often and in more depth.
Record the reasoning — an ISO 45001 internal audit programme that cannot explain its own
frequencies is a finding in itself.

Two further ISO 45001 internal audit requirements catch small organisations. Auditors must be objective and
impartial
, which means nobody audits their own work; in a ten-person firm that means
training a colleague from another function or buying in an auditor. And the results must be
reported to relevant managers and fed into management review under 9.3.

The ISO 45001 internal audit checklist by clause

Clause 4 — Context. Are internal and external issues identified and current,
including climate change under the 2024 amendment? Are workers and other interested parties and their
needs recorded? Is the scope documented, and does it match what the organisation actually does and
where?

Clause 5 — Leadership and worker participation. Can top management describe
the OH&S policy and their own accountability? Are roles and responsibilities documented and
understood by the people holding them? For 5.4, the real test: ask non-managerial workers how they
are consulted, how they raise a hazard, and what happened the last time they did. Look for evidence
that obstacles to participation — language, shift patterns, contractor status — have been
identified and removed.

Clause 6 — Planning. Is the risk assessment methodology documented, not just
the register? Does hazard identification cover non-routine work, human factors and emergency
situations? Is the legal register current, and does it name specific obligations rather than statute
titles? Are objectives measurable, resourced and owned?

Clause 7 — Support. Competence records against defined requirements, not
just attendance certificates. Awareness: can workers state the hazards relevant to them and their
right to remove themselves from imminent danger? Communication: what goes out, to whom, and is there
evidence? Document control: are people working from the current version?

Clause 8 — Operation. Trace the hierarchy of controls from a live risk
assessment into the actual workplace. Test management of change on something that changed recently.
Check contractor and procurement controls under 8.1.4 — how contractors are evaluated, what is
required of them, how it is verified on site. For 8.2, when was the last emergency drill, who
participated, and what was changed as a result?

Clause 9 — Performance evaluation. Are leading indicators monitored or only
lagging ones? Has compliance with each legal requirement actually been evaluated and recorded under
9.1.2? Does management review cover every required input and produce decisions with owners?

Clause 10 — Improvement. Pick an incident. Was it investigated, was root
cause reached, was the risk assessment updated, was effectiveness verified, and was the learning
shared beyond the site where it happened?

A ready-made audit programme, checklists and report forms.

The ISO 45001 Toolkit includes the internal audit procedure, a risk-based programme template, clause-by-clause checklists, and the nonconformity and corrective action forms your auditor will ask to see.

Explore the ISO 45001 Toolkit →

Findings that recur at almost every ISO 45001 internal audit

  • Consultation evidenced only by toolbox talks, which are communication to workers,
    not participation by them.
  • A legal register that has not been evaluated. Clause 9.1.2 requires evaluation of
    compliance, with records — listing the legislation is only half of it.
  • Contractors managed informally, with induction records missing for the people
    actually on site that week.
  • Corrective actions closed on completion rather than on verified effectiveness.
  • Risk assessments not reviewed after incidents, breaking the link between clause
    10.2 and clause 6.1.2.
  • Emergency drills held but never evaluated, so nothing changes.

Getting value from an ISO 45001 internal audit, not a paper exercise

The audits worth doing follow something real from end to end rather than marching down the clause
list. Take an incident from last quarter and trace it: the risk assessment that should have caught it,
the control that failed, the competence of the people involved, the investigation, the change made,
and whether that change reached other sites. You will test a dozen clauses at once and learn something
the checklist alone would never surface. Pair that with a walk-and-talk on the floor, and the
ISO 45001 internal audit starts earning its cost.

References

More on ISO 45001

All of these are covered by the ISO 45001 Toolkit. To score where you stand first, use the ISO 45001 Assessment Tool, or browse the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.