8 min read
How do you write an ISO 45001 audit plan and checklist?
A practical guide for auditors: what goes into the plan, how to build a clause-by-clause checklist, and how to use both without letting the list run the audit.
3FOLD Training is a CQI IRCA Approved Training Partner (ATP 6039853) · Licensed by KHDA, Dubai
If you are about to audit an occupational health and safety (OH&S) management system, the plan and the checklist decide how much of the real workplace you see. This guide is for auditors working to ISO 45001:2018, the international standard for OH&S management systems, and for anyone preparing for the CQI and IRCA ISO 45001 Lead Auditor course. It settles what belongs in each document and how to build them.
An ISO 45001 audit plan states the objectives, scope, criteria, team and schedule of an audit. An ISO 45001 audit checklist is the working document of questions and evidence to sample under each clause from 4 to 10. Write the plan first, using risk and earlier audit results to decide where to look hardest, then build the checklist from the clauses in scope. Treat the checklist as a guide, and follow the evidence.
| Standard audited | ISO 45001:2018, Occupational health and safety management systems |
| Audit guidance | ISO 19011:2026, Guidelines for auditing management systems |
| The plan sets | Objectives, scope, criteria, team, sites and schedule |
| The checklist covers | Clauses 4 to 10, with questions and evidence to sample |
| Best question style | Open-ended, such as “show me” and “how do you” |
| Written | Before the on-site activities begin |
| Related course | ISO 45001 Lead Auditor · PR357 · CQI and IRCA |
What is an ISO 45001 audit plan, and how is it different from a checklist?
The audit plan describes what the audit will do and when, and the checklist lists the questions you will ask to do it.
The plan is the document the auditee sees. It tells them the objectives, scope, criteria, people and timing, so they can arrange the right people and areas. The checklist is usually your own working document. It turns each clause in scope into open questions and notes the evidence you expect to sample.
| Feature | Audit plan | Audit checklist |
|---|---|---|
| Purpose | Sets out how the audit will be run | Guides what you ask and sample |
| Main reader | Auditee and audit team | The auditor |
| Built from | Objectives, scope, criteria and risk | ISO 45001 clauses and the organization’s own documents |
| Can change during the audit? | Only by agreement with the auditee | Yes, as evidence points you elsewhere |
Want to practice planning a full audit? The course includes a full audit simulation on a realistic case study.
Which standard guides ISO 45001 audit planning?
ISO 45001:2018 sets the requirements you audit against, and ISO 19011:2026 gives the guidance on how to audit.
ISO (the International Organization for Standardization) lists ISO 19011:2026 as the current edition of its guidelines for auditing management systems, published in May 2026. It replaces ISO 19011:2018, which ISO now shows as withdrawn. ISO says the update responds to the growing impact of technology, digitization and virtual environments, and to an increased focus on risk analysis and mitigation.
ISO 45001:2018 itself does not include an audit checklist. It requires organizations to plan, establish and maintain an internal audit programme (clause 9.2), so the checklist is something you build from the standard’s clauses and the organization’s own documented information.
What should an ISO 45001 audit plan include?
An audit plan should state what the audit is for, what it covers, what it is measured against, who does it and how it is scheduled.
- Objectives: why the audit is happening, such as verifying conformity or checking that the OH&S system is effective.
- Scope: the sites, activities, shifts and processes included, including contractor work under the organization’s control.
- Criteria: ISO 45001:2018, the organization’s own OH&S procedures, and applicable legal requirements.
- Team: the audit team leader and members, with any technical experts.
- Schedule: time allocated to each area, including opening and closing meetings and time to interview workers.
- Methods and sampling: how you will gather evidence through interviews, observation and record review, and where you will sample more deeply.
- Reporting: how and when findings will be communicated.
Check the exact contents in the current ISO 19011 edition, since the wording of the guidance is updated between editions.
How do you write an ISO 45001 audit plan step by step?
Write the plan in 6 steps, moving from what you want to learn to how the auditee will support you.
- Confirm the audit objectives and scope with the audit programme owner.
- Set the criteria: the clauses of ISO 45001:2018, the organization’s procedures and its legal requirements.
- Review the OH&S documents and earlier audit results. Our guide to the documents required for an ISO 45001 audit lists the 13 categories to look at.
- Use risk to decide where to look hardest, and note the higher-risk areas for deeper sampling.
- Assign the team and build the schedule, including time on the shop floor and with workers.
- Share the plan with the auditee before the audit and agree any changes.
How do you use risk to focus the plan?
Give more time to the activities that can hurt people most. Look for hazardous processes, past incidents, recent changes, contractor work and areas with weak earlier results. A low-risk office and a chemical store should not get the same audit time.
A good plan tells you where to look; a good checklist tells you what to ask; evidence tells you what is true.
How do you build an ISO 45001 audit checklist?
Build the checklist clause by clause from 4 to 10, using open questions and listing the evidence you expect to sample.
Each row below gives you a starting point. Open questions such as “show me how” and “how do you decide” make people explain their real practice, whereas yes/no questions invite yes/no answers. For the wider audit flow, see our guide on how an ISO 45001 audit works from start to finish.
| Clause | Audit focus | Evidence to sample |
|---|---|---|
| 4 Context | Scope of the OH&S system and needs of workers and other interested parties | Scope statement, stakeholder analysis |
| 5 Leadership and worker participation | Top management commitment, policy, roles and worker consultation | Policy, committee minutes, worker interviews |
| 6 Planning | Hazard identification, risk assessment, legal requirements and objectives | Risk registers, legal register, objectives plan |
| 7 Support | Competence, awareness, communication and documented information | Training records, induction, document control |
| 8 Operation | Operational controls, change, contractors and emergency preparedness | Work instructions, permits, contractor records, drill reports |
| 9 Performance evaluation | Monitoring, internal audit and management review | Inspection results, audit reports, review minutes |
| 10 Improvement | Incidents, nonconformity, corrective action and continual improvement | Investigation reports, corrective action records |
Should you follow the checklist exactly?
No. Use the checklist as a guide, and follow the evidence. If a worker describes a workaround that is not in the procedure, note it, ask why, and trace it to the clause it affects. Record what you saw, who told you and what document or area it relates to, so that each finding can be traced back to evidence.
Learning to lead audits, not just follow lists? Two full mock exams are included with the ISO 45001 Lead Auditor course.
What mistakes weaken ISO 45001 audit plans and checklists?
The most common mistakes are treating the checklist as the audit, planning without risk, and asking questions that only need a yes or no.
- Auditing paperwork only. Documents show intent; observation and interviews show what happens. Our guide on the skills you need to become an ISO 45001 auditor covers this.
- Equal time for every area. The plan should weight time by risk.
- Yes/no questions. They produce short answers with little evidence.
- Skipping worker voices. Clause 5 is about consultation and participation, so include time to interview workers, not only managers.
- No trace from finding to evidence. Every finding should point to a clause and to the evidence that supports it.
Audit checklist builder
For practice only. Pick the clauses in scope and get open-ended starter questions. Adapt them to the organization you are auditing.
Clause 6 Planning
- How are hazards identified for routine and non-routine activities?
- Show me how legal and other requirements are identified and kept up to date.
- How were the OH&S objectives set, and how is progress tracked?
Clause 8 Operation
- How are operational controls applied at the workplace, starting with eliminating hazards?
- Show me how changes and contractor work are assessed before they start.
- Show me the last emergency drill and what was improved afterward.
Preloaded example: clauses 6 and 8 give the questions an auditor would ask about hazard identification, legal requirements, operational controls, contractors and emergencies. Notice that each question starts with “how” or “show me”, so the answer must come with evidence.
Frequently asked questions
What is the difference between an ISO 45001 audit plan and an audit checklist?
In an ISO 45001:2018 audit, the audit plan sets out the objectives, scope, criteria, team and schedule, while the checklist is a working document listing questions and the evidence to sample. A lead auditor working to CQI and IRCA ISO 45001 Lead Auditor practice treats the checklist as a guide, not a script.
What should an ISO 45001 audit plan include?
An ISO 45001:2018 audit plan should include the audit objectives, scope, criteria, team, sites, schedule, methods and sampling approach, and how findings will be reported. Confirm the exact contents in the current edition of ISO 19011, the auditing guidelines that support ISO 45001:2018 audits.
Is there an official ISO 45001 audit checklist?
No. ISO 45001:2018 sets requirements and does not include an audit checklist. Auditors build their own checklist from clauses 4 to 10 and the organization’s documented information.
Which ISO 45001 clauses should an audit checklist cover?
An ISO 45001:2018 audit checklist should cover the clauses in the audit scope, which for a full audit are clauses 4 to 10: context, leadership and worker participation, planning, support, operation, performance evaluation and improvement. Each clause is audited against evidence, not paperwork alone.
Should an ISO 45001 audit checklist use yes/no questions?
Open-ended questions work better in an ISO 45001:2018 audit, because questions such as “show me how” or “how do you decide” make the auditee explain real practice and produce evidence. Save yes/no questions for confirming simple facts.
Is ISO 19011:2018 still current for ISO 45001 audit planning?
No. ISO shows ISO 19011:2018 as withdrawn, and ISO 19011:2026, published in May 2026, replaces it as the guidelines for auditing management systems. ISO 45001:2018 remains the standard audited, so auditors should use the current ISO 19011 edition for planning guidance.
Do I review documents before writing an ISO 45001 audit plan?
Yes. Reviewing the OH&S policy, risk assessments, legal register and earlier audit results before writing an ISO 45001:2018 audit plan helps you focus on higher-risk areas. Our guide to the documents required for an ISO 45001 audit lists what to review.
Where 3FOLD Training fits
3FOLD Training is a CQI IRCA Approved Training Partner (ATP 6039853), licensed by the Knowledge and Human Development Authority (KHDA) in Dubai. The ISO 45001 Lead Auditor course is delivered as 40 hours of Virtual Instructor Led Training (VILT), with learning management system (LMS) access for recordings and mock exams, and you can check the next available batch on the course page. We prepare you for the exam; CQI and IRCA examine and certify. If you plan to move toward a formal auditor grade afterward, read the steps to become a certified ISO 45001 Lead Auditor.
Ready to plan audits with confidence? Check the next batch and see how exam application support works.




Leave a Reply
Your email is safe with us.