What Are the Common Documents Required for an ISO 45001 Audit?
A practical guide to the documented information and records commonly reviewed during an ISO 45001 Occupational Health and Safety Management System audit.
The documents required for an ISO 45001 audit depend on the organisation, its activities, risks, and audit scope. Common documented information may include the OH&S policy, scope of the OHSMS, hazard identification and risk assessment information, OH&S objectives, legal and other requirements, operational controls, emergency preparedness information, training and competence records, incident records, internal audit records, and management review records.
However, an ISO 45001 audit is not only a document review. Auditors also collect evidence through interviews, observations, records and other sources to determine whether the Occupational Health and Safety Management System (OHSMS) is effectively implemented.
Why Are Documents Important in an ISO 45001 Audit?
Documented information helps an organisation demonstrate how its Occupational Health and Safety Management System is established and maintained.
During an audit, an auditor may review relevant documents and records to understand how the organisation manages its OH&S risks and meets applicable requirements.
The auditor may also compare documented information with what is actually happening in the workplace. This helps determine whether the system is implemented as planned.
What Documents Are Commonly Reviewed During an ISO 45001 Audit?
1OH&S Policy
The OH&S policy describes the organisation's overall commitment to occupational health and safety.
An auditor may review the policy to understand whether it provides an appropriate framework for the organisation's OH&S objectives and management system.
The policy should also be communicated and available as required within the organisation.
2Scope of the OHSMS
The organisation should define the scope of its Occupational Health and Safety Management System.
The scope helps establish which activities, products, services, locations and organisational areas are covered by the management system.
An auditor may review the scope to understand what is included within the audit and whether it reflects the organisation's actual activities.
3Hazard Identification and OH&S Risk Assessment Information
Hazard identification and risk assessment are important parts of an ISO 45001-based OHSMS.
Auditors may review information showing how the organisation identifies hazards, assesses OH&S risks and determines appropriate controls.
This information can help the auditor understand how the organisation manages risks associated with its activities and workplaces.
4Legal and Other Requirements
Organisations need to determine applicable legal and other requirements related to their OH&S activities.
An auditor may review information showing how these requirements have been identified, maintained and considered within the OHSMS.
Evidence may also be reviewed to determine how the organisation evaluates whether applicable requirements are being fulfilled.
5OH&S Objectives and Plans
An organisation may establish OH&S objectives to improve its occupational health and safety performance.
Auditors may review the objectives, plans, responsibilities, resources and progress associated with them.
This helps demonstrate how the organisation translates its OH&S commitments into measurable activities and improvement efforts.
6Operational Control Information
Operational controls explain how the organisation manages activities associated with OH&S risks.
Depending on the organisation, this may include procedures, work instructions, control measures or other documented information related to specific operations.
Auditors may compare these documented controls with actual workplace practices to determine whether they are being implemented effectively.
7Emergency Preparedness and Response Information
Organisations need to consider potential emergency situations relevant to their activities.
An auditor may review emergency preparedness arrangements, response procedures, drills, exercises and related records where applicable.
The auditor may also examine whether workers understand their responsibilities during relevant emergency situations.
8Competence and Training Records
An organisation needs to ensure that people performing work that can affect OH&S performance are competent.
Training records, competency evidence, qualifications, induction records and other relevant information may therefore be reviewed during an audit.
Auditors may also speak with employees to determine whether they understand the work they perform and the relevant OH&S controls.
9Communication and Worker Participation Records
ISO 45001 places importance on communication and the participation and consultation of workers.
Depending on the organisation, relevant evidence may include meeting records, consultation records, safety committee information, communication records or other documented evidence.
The auditor may use this information together with employee interviews to understand how worker participation works in practice.
10Incident and Corrective Action Records
An auditor may review records relating to incidents, nonconformities and corrective actions.
These records can provide evidence of how the organisation responds when an OH&S problem or incident occurs.
The auditor may examine how the organisation investigated the issue, determined appropriate action and evaluated whether the action was effective.
11Monitoring and Measurement Records
Organisations may monitor and measure relevant OH&S performance indicators.
Records can include inspection results, monitoring information, performance measurements and other evidence relevant to the organisation's OH&S objectives and processes.
These records can help auditors understand how the organisation evaluates its OH&S performance.
12Internal Audit Records
Internal audits help organisations evaluate whether their OHSMS is conforming to applicable requirements and is effectively implemented and maintained.
An auditor may review the internal audit programme, audit plans, reports, findings and follow-up records.
This can help demonstrate how the organisation internally evaluates its management system and addresses identified issues.
13Management Review Records
Top management reviews are an important part of the management system.
Auditors may review management review records to determine whether relevant OHSMS performance information, objectives, audit results, incidents, opportunities for improvement and other applicable inputs have been considered.
The auditor may also examine evidence of decisions and actions resulting from the management review.
Does an ISO 45001 Auditor Check Every Document?
Not necessarily.
The auditor determines what information and evidence needs to be reviewed based on the audit scope, organisation, processes, risks and audit objectives.
Auditing is based on sampling, so an auditor may select representative documents, records, locations, activities and employees rather than reviewing every available record.
Are Documents Alone Enough to Pass an ISO 45001 Audit?
No. Having well-prepared documents does not by itself demonstrate that an OHSMS is effectively implemented.
An auditor may compare documented information with actual workplace practices. For example, a procedure may describe a particular safety control, but the auditor may also observe how that control is implemented and speak with workers who perform the activity.
Therefore, organisations should focus on both documented information and actual implementation.
How Should You Prepare Documents for an ISO 45001 Audit?
Organisations should first understand the audit scope and applicable ISO 45001 requirements.
Relevant documented information should be kept current, accessible and properly controlled. Records should also be organised so that appropriate evidence can be provided when requested by the auditor.
It is also useful to check whether documented procedures reflect what employees actually do in the workplace. If there is a significant difference between documented processes and actual practices, it may become an area requiring attention before the audit.
Conducting an internal audit can also help identify gaps before an external audit.
What Are Common Document-Related Problems During an ISO 45001 Audit?
One common problem is having documents that are outdated or do not reflect current workplace activities.
Another issue can be incomplete records. For example, an organisation may have a training procedure but insufficient evidence showing that required training was completed.
Documents can also become ineffective when employees are not aware of the procedures or when documented controls are not consistently followed.
What Is the Difference Between a Document and a Record?
In an ISO management system context, it is useful to understand the difference between information that describes how a process should work and information that provides evidence that an activity has been completed.
Documented Process
A procedure may describe how an internal audit is conducted.
Evidence of Completion
An internal audit report can provide evidence that the audit was actually performed.
Both types of documented information can be relevant during an ISO 45001 audit.
FAQs
What documents are required for an ISO 45001 audit?
Common documented information includes the OH&S policy, OHSMS scope, risk and hazard information, legal requirements, objectives, operational controls, emergency preparedness information, competence records, incident records, internal audit records and management review records. The exact documented information required depends on the organisation and its activities.
Does ISO 45001 require a specific document format?
Not necessarily. Organisations can determine the appropriate format and level of documented information based on their needs, processes and applicable requirements.
Do auditors check employee training records?
Yes, relevant competence and training evidence may be reviewed during an ISO 45001 audit. Auditors may also interview employees to verify competence and awareness.
Are risk assessments checked during an ISO 45001 audit?
Yes. Hazard identification and OH&S risk assessment information can be important audit evidence because they demonstrate how the organisation identifies and manages occupational health and safety risks.
Can an organisation pass an ISO 45001 audit with missing documents?
Missing or inadequate documented information can result in audit findings when the applicable requirement has not been adequately fulfilled. The significance of the finding depends on the specific requirement and evidence identified during the audit.
Should an organisation conduct an internal audit before an ISO 45001 certification audit?
An internal audit can help an organisation evaluate its OHSMS before an external certification audit and identify areas that may require corrective action or improvement.
Conclusion
The documents reviewed during an ISO 45001 audit can vary depending on the organisation, its activities, risks and audit scope. Common areas include OH&S policy, OHSMS scope, hazard and risk information, legal requirements, objectives, operational controls, emergency preparedness, competence records, incident records, internal audits and management reviews.
However, ISO 45001 auditing is not simply about checking paperwork. Auditors use documented information together with interviews, observations and other objective evidence to evaluate how the OHSMS is implemented.
Keeping documented information accurate, accessible and consistent with actual workplace practices can help an organisation prepare more effectively for an ISO 45001 audit.
Build Your ISO 45001 Auditing Knowledge
Develop practical knowledge of ISO 45001 auditing, audit evidence, findings and Occupational Health and Safety Management System requirements.
Explore ISO 45001 Lead Auditor Training




Leave a Reply
Your email is safe with us.