8 min read
How do you audit management of change under ISO 45001?
How to sample changes, trace them from request to review and judge whether the organization controlled the OH&S risks that change creates.
3FOLD Training is a CQI IRCA Approved Training Partner (ATP 6039853) · Licensed by KHDA, Dubai
Most workplace harm does not come from the way things have always been done. It comes from the day something changed: a new machine, a new layout, a new contractor or a new shift pattern. Clause 8.1.3 of ISO 45001:2018 asks organizations to control those moments, and an auditor needs to know how to test it. This guide is for auditors working to the standard and for anyone preparing for the CQI (Chartered Quality Institute) and IRCA (International Register of Certificated Auditors) ISO 45001 Lead Auditor course.
To audit management of change under ISO 45001, take a sample of recent changes and trace each one from the request to the review after it was made. Check that OH&S risks were assessed before the change, that controls, communication and training were in place, and that the organization reviewed unintended consequences. Clause 8.1.3 of ISO 45001:2018 covers planned temporary and permanent changes.
| Standard audited | ISO 45001:2018, Occupational health and safety management systems |
| Clause | 8.1.3, Management of change |
| Scope | Planned temporary and permanent changes that affect OH&S performance |
| Also covered | Reviewing the consequences of unintended changes |
| Evidence to use | Change records, risk assessments, interviews and observation |
| Related course | ISO 45001 Lead Auditor · PR357 · CQI and IRCA |
What does ISO 45001 require for management of change?
It requires processes to implement and control planned temporary and permanent changes that affect OH&S performance.
Clause 8.1.3 sits inside operational planning and control, so it works alongside the controls auditors check on the shop floor. In plain terms, the organization needs a way to spot a change, think through its OH&S effects before it happens and manage it. It also has to review what happens when a change turns out differently from plan, and act to reduce any adverse effects. Always check the exact wording in the current ISO 45001:2018 text. Our guide to operational control in ISO 45001 shows the wider clause, and our guide to how an ISO 45001 audit works shows where this check fits in an audit.
Which changes should an auditor expect to see?
Expect changes to products, services and processes, to legal requirements, to knowledge about hazards and to technology.
The standard lists the kinds of change the process should cover. The table below turns that list into audit prompts.
| Type of change | Workplace example | What to look for |
|---|---|---|
| Workplace and surroundings | A new layout or a relocated work area | Risk assessment before the move |
| Work organization | A new shift pattern or staffing level | Consideration of fatigue and supervision |
| Equipment | A new machine or a changed guard | Hazard review, controls and operator training |
| Workforce | New hires, agency staff or contractors | Induction and competence checks |
| Legal and other requirements | A new regulation that affects a task | How the change reached the people affected |
| Knowledge and technology | New information about a hazard | Whether risk assessments were updated |
A change that nobody assessed is a hazard nobody has looked at yet.
Want to practice auditing a real process? The course includes editable audit working documents and a case study.
How do you plan an audit of management of change?
Ask for the list of recent changes, choose a sample that covers different types and risks, and plan the evidence you will check.
Start with the change log or any equivalent record of what has changed since the last audit. Pick changes of different types, such as one equipment change, one change in work organization and one involving contractors, and favor the ones with the highest OH&S risk. Then write your questions into your checklist. Our ISO 45001 audit plan and checklist guide shows how to do this, and our guide to the documents required for an ISO 45001 audit helps you decide what to read first.
How do you trace a change from request to review?
Follow the change step by step and look for evidence at each stage.
- The trigger. Find how the change was identified and who approved it.
- Before the change. Look for hazard identification and an OH&S risk assessment that covers the change.
- Controls. Check that the controls the assessment calls for were put in place, in line with the hierarchy of controls.
- People. Check communication, training and competence for the workers affected, and whether workers were consulted.
- After the change. Look for a review that confirms the change works as planned, and see what happened if it did not.
Each stage gives you a different type of evidence, so use all three methods: documented information for the records, observation for the controls and interviews for communication. Where the change involved outside parties, our guide to how ISO 45001 manages contractors adds useful context.
Who should you interview about management of change?
Interview the person who approved the change, the supervisors who ran it and the workers it affected.
The change owner can describe how the process is meant to work. The workers who live with the change can tell you whether anyone explained it, trained them or asked their view. Compare the two accounts. A gap between them is a lead, and you confirm it with records or observation before you write a finding. Our guide to worker consultation and participation in ISO 45001 explains the consultation requirement that applies here.
Not sure whether to start as an internal or lead auditor? Compare the two roles in our guide.
How do you audit temporary and unintended changes?
Treat temporary changes like permanent ones, and look for a review of anything that did not go as planned.
Clause 8.1.3 covers planned temporary changes as well as permanent ones. Examples include a closed walkway, a rerouted forklift route or a short-term staffing change. Ask how the organization finds such changes, and what happens to the risk assessment while the change lasts. For unintended changes, ask how the organization learns about them, for example through an incident report or a near miss, and whether it reviewed the consequences and acted. Our guide to incident investigation in ISO 45001 and our guide to continual improvement in ISO 45001 show where that learning should go.
What gaps do auditors commonly find in management of change?
Common gaps are changes that never reach the process, risk assessments that are not updated and workers who are not told.
- No trigger. Small changes, such as a new product or a moved bench, never enter the change process.
- Assessment after the fact. The risk assessment is written once the change is finished.
- Records without people. The paperwork is complete, but the affected workers say they were never told.
- Temporary becomes permanent. A short-term arrangement is never reviewed and stays in place.
- No review. Nobody checks whether the change created new hazards.
Treat these as prompts, not conclusions, and confirm each one with evidence before you raise a finding. For the wider skill set, see our guide on the skills you need to become an ISO 45001 auditor.
Change audit simulation: choose the best auditor action
For practice only. Read each situation and choose the best response. These scenarios were written by 3FOLD Training and are not real exam questions.
1 scenario answered: 1 of 1 correct
Preloaded example: Situation 1 is already answered. Tracing one change from request to review tests the whole process, while reading a procedure or asking one manager does not.
Frequently asked questions
What does ISO 45001 require for management of change?
Clause 8.1.3 of ISO 45001:2018 requires the organization to establish processes to implement and control planned temporary and permanent changes that affect OH&S performance. It also requires the organization to review the consequences of unintended changes and act to reduce any adverse effects.
Which clause of ISO 45001 covers management of change?
Management of change is covered by clause 8.1.3 of ISO 45001:2018, which sits within operational planning and control in clause 8. Auditors check it together with risk assessment, communication, competence and worker consultation.
What changes does ISO 45001 management of change cover?
According to ISO 45001:2018 clause 8.1.3, covered changes include new or modified products, services and processes that affect workplace locations, work organization, working conditions, equipment or the workforce. They also include changes to legal requirements, changes in knowledge about hazards and developments in knowledge and technology.
Does ISO 45001 cover temporary changes?
Yes. Clause 8.1.3 of ISO 45001:2018 covers planned temporary changes as well as permanent ones. Examples include a closed walkway, a rerouted forklift route or a short-term staffing change, and auditors check that the organization identified and controlled them.
What evidence do auditors look for when auditing management of change in ISO 45001?
Auditors look for change records, OH&S risk assessments completed before the change, evidence that controls were put in place, communication and training records, and a review after the change. They confirm interview comments against records or observation before they raise a finding.
How do you sample changes in an ISO 45001 audit?
Ask for the list of recent changes, then choose a sample that covers different types, such as equipment, work organization and workforce, and favor the changes with the highest OH&S risk. Trace each sampled change from the request to the review after it was made.
What are unintended changes in ISO 45001?
Unintended changes are changes that happen without being planned, or that turn out differently from plan. ISO 45001:2018 clause 8.1.3 requires the organization to review their consequences and take action to mitigate any adverse effects, so auditors look for the review and the action taken.
Where 3FOLD Training fits
3FOLD Training is a CQI IRCA Approved Training Partner (ATP 6039853), licensed by the Knowledge and Human Development Authority (KHDA) in Dubai. The ISO 45001 Lead Auditor course is delivered as 40 hours of Virtual Instructor Led Training (VILT), with learning management system (LMS) access for class recordings and mock exams, and you can check the next available batch on the course page. We prepare you for the exam; CQI and IRCA examine and certify. Before you book, read what you need in our eligibility guide.
Ready to audit with confidence? Check the next batch and see what the course fee includes.
UAE mobile and WhatsApp: +971 50 481 9989
India mobile: +91 91762 57536
Chennai: Plot No: 1342, HIG, TNHB Main Road, Sithalapakkam, Chennai 600126
Monday to Friday 9:00 am to 5:00 pm, Saturday 9:00 am to 2:00 pm. See the 3FOLD Training contact page for all details.





Leave a Reply
Your email is safe with us.