ISO 45001

How to Conduct an ISO 45001 Internal Audit: A Step-by-Step Guide

To conduct an ISO 45001 internal audit, establish a risk-based audit program, plan each audit with defined scope and criteria, prepare by reviewing your hazard identification and risk assessment register, gather evidence through document review, site observation, and worker interviews, document and classify findings, and follow up to verify corrective actions address root causes — not just symptoms.

An ISO 45001 internal audit is required under Clause 9.2 — but its real value lies in what it uncovers before your certification auditor does, and before a hazard results in harm. A well-run OHS audit tells management whether safety controls are actually protecting workers in practice, not just whether they exist on paper. This guide walks through each stage of the ISO 45001 internal audit process, drawing on the approach taught by Maria Falbo, a Lead Auditor with decades of ISO 45001 experience.

Maria Falbo | Lead Trainer, Logix ISO | July 2026 | 12 min read

What ISO 45001 Requires for Internal Audits

ISO 45001 Clause 9.2 requires organizations to conduct internal audits at planned intervals to determine whether the OHSMS conforms to requirements and is effectively implemented. The clause has two parts: Clause 9.2.1 sets the objective — conformity and effectiveness — and Clause 9.2.2 governs the audit program itself, requiring it to be planned, implemented, maintained, and risk-based.

One distinction worth understanding before you start: an internal audit assesses conformity to the management system — whether the OHSMS is documented, implemented, and maintained as required. It is not the same as an evaluation of compliance with occupational health and safety legislation, which is a separate obligation under Clause 9.1.2. Both are required, but they serve different purposes and should not be conflated. An organization can have a fully conforming OHSMS and still have unresolved legal compliance gaps — and vice versa.

ISO 45001 internal audits are conducted in accordance with ISO 19011, the international guidelines for auditing management systems, which sets out the principles, program management, and audit methods that make the process systematic and evidence-based. For a comprehensive overview of the full OHS internal audit lifecycle and how ISO 45001 auditing differs from ISO 9001 and ISO 14001, see our ISO 45001 Internal Audit: The Complete Guide.

Step 1 — Establish Your Audit Program

The audit program is the overarching framework that governs all internal audit activity across a defined period — typically a 12-month cycle. It is not a single audit. It is the arrangement that coordinates multiple audits across all processes, sites, and functions of the OHSMS to ensure full coverage over the cycle.

The program must be risk-based. Clause 9.2.2 requires it to account for the importance of the processes being audited and the results of previous audits. Areas with significant hazards — confined space entry, working at height, hazardous energy control, high-risk machinery — warrant more frequent and more rigorous audit attention than lower-risk processes. Areas where previous audits found nonconformities also need increased frequency.

The legal and other requirements register is another useful input to program planning: the more demanding the regulatory environment for a given process or location, the higher the audit priority.

In Practice

The most common audit program weakness is one that applies the same depth and frequency across all OHSMS processes regardless of risk. I regularly see programs where confined space entry and hazardous energy control — areas with significant hazards and serious injury potential — are audited at the same interval as document control or training records. The program needs to reflect where the real risk to workers sits. Building that profile requires someone who understands the operation, not just the clauses.

Step 2 — Plan the Individual Audit

Each audit within the program needs its own audit plan — a document that defines the scope, objectives, criteria, schedule, and methods for that specific audit. The scope sets the boundaries: which processes, locations, and functions are covered. The criteria are the requirements against which conformity will be assessed — the relevant ISO 45001 clauses, the organization's own procedures, and the applicable legal requirements for that area.

The plan also assigns auditors. Clause 9.2.2 requires impartiality — auditors must not assess areas they are personally responsible for. This does not mean they need to be external. A safety manager can audit the production department. A production manager can audit the safety function. What they cannot do is audit their own work.

Where the audit covers multiple processes or locations, the plan should include a realistic schedule. One of the most consistent causes of ineffective audits is time pressure — auditors rushing through high-risk areas because the plan doesn't allow adequate time for thorough worker interviews and evidence gathering.

Step 3 — Prepare for the Audit

Preparation is where audit quality is determined, before the audit begins. An auditor who has reviewed the right documents before walking onto the floor knows exactly where to look, what questions to ask, and who to talk to.

In preparation for the audit, the auditor should review the hazard identification and risk assessment register — focusing on which hazards are assessed as significant, whether the register reflects current operations, and whether any recent process changes could have introduced new hazards that haven't been captured. The legal and other requirements register should be reviewed to understand what occupational health and safety legislation applies to the area being audited. Previous audit reports and corrective action records reveal where nonconformities were found last time and whether they were properly closed. Incident and near-miss records show where things have already gone wrong or nearly gone wrong. Relevant operational control procedures show what controls are supposed to be in place and what records should demonstrate they are being followed.

From this review, the auditor develops checklists — not to follow rigidly line by line, but as a structured framework that ensures coverage and prompts the right questions while leaving room to follow evidence wherever it leads. For a deeper look at what a well-structured ISO 45001 internal audit checklist covers by clause, see our ISO 45001 internal audit checklist guide.

In Practice

Good preparation fundamentally changes what you find in the audit. Walking in having already reviewed the hazard register and summary of incidents and near-misses — you walk onto the floor already knowing what to look for and who to talk to. An auditor who walks in cold and works from a generic checklist will miss exactly the kinds of gaps that matter. The preparation is not preliminary work. It is part of the audit.

Build the skills to conduct credible, evidence-based ISO 45001 internal audits

Our ISO 45001 Internal Auditor course covers every stage of the audit process, from program planning through corrective action follow-up, built on ISO 45001 and ISO 19011.

View Course

Step 4 — Hold the Opening Meeting

An ISO 45001 internal audit typically begins with an opening meeting. Its purpose is to confirm that the audit is authorized and understood, establish ground rules, and align expectations before fieldwork begins.

A well-run opening meeting covers the audit scope, objectives, and criteria; the schedule and which areas will be visited; the methods the auditor will use — document review, site observation, worker interviews; how findings will be classified and communicated; who the auditor needs access to, including which workers; and the logistics for the closing meeting.

The opening meeting is also the right moment to surface any access or availability issues — not mid-audit. Keep it concise: fifteen to thirty minutes is typically sufficient. It is not a presentation. Its purpose is alignment, not formality.

Step 5 — Conduct the Audit

The audit itself is conducted through three methods: document and records review, physical observation of operations, and interviews with workers. All three are necessary. Each produces a different type of evidence, and together they give the auditor a complete picture of how the OHSMS is actually functioning — and, critically, whether it is protecting the people it's designed to protect.

Document and records review establishes what the system says. The auditor reviews OHSMS documentation — procedures, registers, monitoring records, training records, incident reports, corrective action records, management review minutes — to verify that required elements exist and that records demonstrate they are being applied. Key documents in an ISO 45001 audit include the hazard identification and risk assessment register, the legal and other requirements register, incident and near-miss records, operational control procedures, and emergency response plans.

Physical observation establishes what is actually happening. The most common root cause of ISO 45001 nonconformities is the gap between what procedures describe and what occurs in the operation. Site observation reveals whether machine guarding is in place and being used, whether lockout/tagout procedures are being followed, whether PPE is being worn correctly, and whether emergency equipment is accessible and inspected — not just documented as available. For a deeper explanation of how hazards are identified and evaluated to focus audit attention, see our guide to ISO 45001 hazard identification.

Worker interviews are the cornerstone of ISO 45001 auditing — and the technique that most organizations underestimate. Open-ended questions probe genuine understanding and genuine consultation rather than rehearsed answers. The answers reveal the real state of OHSMS awareness and worker participation far more reliably than documents alone.

The most important discipline throughout is following the evidence rather than the checklist. When an interview surfaces something unexpected — a hazard not reflected in the register, a near-miss that was never formally reported, a corrective action that was closed without verification — the auditor pursues that thread. A checklist followed rigidly at the expense of evidence will consistently miss the most significant findings.

In Practice

One pattern worth watching for is when the three evidence sources contradict each other. Documentation says a permit-to-work system is in place for hot work. Physical observation shows welding equipment set up with no permit available. The worker doing the welding says they've never filled one out. Any single source in isolation might not raise a flag — the auditor could assume the permit was filed elsewhere, or that this was a one-off. It's only when all three sources are checked and compared that the gap becomes undeniable. That's why relying on just one evidence-gathering method, even a thorough one, misses points that cross-checking all three catches immediately.

Step 6 — Document and Classify Findings

As evidence is gathered, the auditor records findings in real time. Every finding must be supported by objective evidence — something observed, a record reviewed, or a statement made by a worker and subsequently verified. Findings without objective evidence cannot be raised as nonconformities.

Findings fall into three categories. A major nonconformity is a systemic failure — either the complete absence of a required OHSMS element, observing an unsafe behavior that could lead to a serious accident, or a pattern of breakdown that shows the system is not functioning as intended. An example would be a significant hazard with no operational control in place at all, or no evidence that worker consultation has occurred on any topic in the past year. This is a major finding.

A minor nonconformity is an isolated departure with no evidence of a broader pattern — some training records missing for one employee, or an inspection not conducted on the required date. Isolated in itself, but worth tracking: multiple minor nonconformities in the same area across an audit cycle are often the early signal of a systemic issue.

An observation or opportunity for improvement is not a nonconformity — it is an area the auditor has identified as a potential risk or improvement opportunity that does not yet constitute a failure. Including opportunities for improvement in the audit report gives management a forward-looking picture alongside the findings.

Specificity is what makes a nonconformity report useful. "Machine guarding is inadequate" gives management nothing to act on. "The fixed guard on the packaging line conveyor was found removed during the floor walk on [date], with no work permit or risk assessment on file authorizing its removal, as confirmed by the line supervisor during interview" tells management exactly what failed, where, when, and what evidence supports the finding.

Step 7 — Hold the Closing Meeting and Issue the Report

The closing meeting formally concludes the on-site audit. It brings together the same management and key personnel who attended the opening meeting, and its purpose is to present findings before the formal written report is issued.

The closing meeting covers what was audited, the evidence reviewed, all findings — major nonconformities, minor nonconformities, and observations — each with supporting evidence, any areas of good practice observed, and the timeline for the written report and corrective action responses. Findings are presented based on objective evidence.

The audit report should be issued promptly after the closing meeting. A report that takes three weeks arrives too late to be useful — the findings are fresh, corrective action timelines need to start, and management needs the written record to assign accountability, particularly where worker safety could be directly at stake.

The audit report is a required documented output under Clause 9.2.2 and a mandatory input to management review under Clause 9.3. It is also one of the first things an external certification auditor will ask to see.

Step 8 — Follow Up on Corrective Actions

The audit does not end when the report is issued. Clause 10.2 requires that nonconformities be addressed through corrective action — and the audit program is responsible for verifying that those actions are implemented and effective, not merely submitted.

For each nonconformity, the responsible party must identify the root cause, define a corrective action that addresses that root cause, implement it, and provide evidence that it is working. The critical point is root cause, not symptom. A corrective action for "guard removed from conveyor" that consists only of replacing the guard has fixed the symptom. The root cause — why the guard was removed, whether it was interfering with a task that needed a better engineering solution, and what process failed to catch this — must be investigated and corrected. Otherwise the same nonconformity reappears at the next audit.

The auditor's role is to verify, not just accept, that corrective actions have been closed effectively. A corrective action marked closed without verification has not actually been closed. Audit program follow-up should include a defined interval check that confirms actions were implemented and are effective — and this status must be reported to management as a management review input under Clause 9.3.

FAQ

Frequently asked questions

How long does an ISO 45001 internal audit take?

The duration depends on the size and complexity of the organization and the scope of the audit. A small organization auditing its entire OHSMS might complete the process in a single day. A larger organization with multiple sites and significant hazards may require several days spread across multiple sessions. What matters is that the audit covers all required areas with sufficient depth — including adequate time for worker interviews — not that it is completed quickly.

Who can conduct an ISO 45001 internal audit?

Internal auditors can be employees of the organization, provided they do not audit their own work. Impartiality means auditors must not assess areas they are personally responsible for — not that they need to be external. Auditors must also be competent, meaning they have adequate knowledge of ISO 45001 requirements, the organization's OHSMS, and auditing techniques in line with ISO 19011.

Can workers themselves be involved in conducting the internal audit?

Yes — and it's a good practice. Some organizations include trained worker representatives as part of the internal audit team, which strengthens both the credibility of findings and worker trust in the audit process. This is distinct from — but complements — the requirement to interview workers as part of evidence gathering during any internal audit.

What documents does an auditor review during an ISO 45001 internal audit?

Key documents include the hazard identification and risk assessment register, the legal and other requirements register, previous audit reports and open corrective actions, incident and near-miss records, and the operational control procedures relevant to the area being audited. These documents tell the auditor where risk is concentrated and what evidence to look for during fieldwork.

What happens if nonconformities are found during an ISO 45001 internal audit?

Nonconformities must be addressed through the corrective action process under Clause 10.2. This requires identifying the root cause, implementing a corrective action that addresses that root cause, and verifying that the action is effective. The status of corrective actions must be reported to management as a management review input. Finding nonconformities during an internal audit is a sign the program is working — they should be found internally before your external certification auditor finds them.

About the Author
Maria Falbo — Lead Trainer, Logix ISO
Maria Falbo
Founder & Lead Trainer, Logix ISO · 25+ Years Global Experience

Maria Falbo has over 25 years of experience working as a Lead Auditor for certification bodies worldwide. She founded Logix ISO with the mission of making expert-level ISO training accessible to organizations of all sizes. Her work spans Quality, Environmental, Occupational Health and Safety, Food Safety, Automotive, and Energy management systems.

Learn more about Maria →
ISO 45001 Internal Auditor Training
Ready to become a qualified ISO 45001 internal auditor?

Self-paced · 365-day access · Training certificate included

View Course