An ISO 45001 internal audit is a planned, evidence-based assessment of whether an organization's Occupational Health and Safety Management System conforms to ISO 45001 requirements and is effectively implemented. Required under Clause 9.2, it verifies that hazards are being identified, risks controlled, and workers meaningfully involved — before an external certification auditor makes that same assessment.
An ISO 45001 internal audit is one of the most important tools an organization has for verifying that its Occupational Health and Safety Management System is genuinely protecting workers — not just documented to look like it does. Done well, it identifies hazards and gaps in operational control before your certification auditor does, drives real safety performance improvement, and gives management the evidence it needs to make informed decisions about worker health and safety. This guide is written by Maria Falbo, a Lead Auditor with decades of ISO 45001 experience, and covers the full internal audit lifecycle — from planning through corrective action follow-up.
An ISO 45001 internal audit is a planned, evidence-based assessment of an organization's Occupational Health and Safety Management System. Its purpose is to determine whether the OHSMS conforms to the requirements of ISO 45001 and to the organization's own procedures, and whether it is effectively implemented and maintained — as required by Clause 9.2 of the standard.
The key distinction is that an internal audit is a first-party audit — conducted by or on behalf of the organization itself, not by a certification body. It is not a compliance inspection, and it is not meant to catch people out. Its value lies in giving management verified, objective information about how the OHSMS is performing — and, most fundamentally, whether workers are actually being protected — before an external auditor arrives to make that same assessment.
What sets OHS internal auditing apart from quality or environmental auditing is the nature of what's at stake when the system fails. A nonconformity in a quality management system typically results in a defective product or a dissatisfied customer. A nonconformity in an environmental management system typically results in an unmanaged environmental impact. A nonconformity in an occupational health and safety management system can result in a worker being seriously injured or killed. That distinction shapes how seriously internal auditing needs to be taken — the internal audit is not a bureaucratic exercise, it is one of the organization's primary mechanisms for catching a gap between documented control and actual worker exposure before that gap results in harm.
ISO 45001 internal audits are conducted in accordance with ISO 19011, the international guidelines for auditing management systems. Auditors are expected to apply its principles throughout: integrity, fair presentation, due professional care, confidentiality, independence, evidence-based approach, and risk-based approach.
With 542,527 organizations certified to ISO 45001 globally — covering over 941,546 sites worldwide — the internal audit requirement under Clause 9.2 represents one of the fastest-growing auditing obligations anywhere. The trajectory from 190,429 certificates in 2020 to 542,527 in 2024 represents a near-tripling of globally certified organizations in just four years, driven by regulatory pressure, customer expectations, and a growing recognition that occupational health and safety management is inseparable from operational risk management. For a full explanation of what ISO 45001 is, who needs it, and what certification involves, see our complete guide to ISO 45001.
One of the most consistent patterns in ISO 45001 audits is the gap between what an organization documents about worker safety and what workers actually experience on the floor. Procedures describe controls for significant hazards — machine guarding, confined space entry, lockout/tagout — but when you audit the operation, you find that workers haven't been consulted on how those controls were designed, or that the controls exist but nobody explained why they matter. An internal audit that only reviews documentation misses the entire point. The audit has to reach the people actually exposed to the hazard.
ISO 45001 shares the same Harmonized Structure as ISO 9001 and ISO 14001, which means the overall audit process — planning, conducting, reporting, and follow-up — is broadly the same. But the subject matter of an OHS audit is fundamentally different, and auditors who come to ISO 45001 from a quality or environmental background need to understand those differences clearly.
In a QMS audit, the central concern is process performance and customer satisfaction. In an EMS audit, the central concern is environmental impact. In an OHSMS audit, the central concern is worker health and safety — specifically whether the organization has correctly identified hazards in its operations, assessed the associated risks, put controls in place following the hierarchy of controls, and can demonstrate those controls are actually protecting people in practice. For a full comparison of what separates ISO 45001 from ISO 9001 and where the two can be integrated, see our article on ISO 45001 vs ISO 9001.
Worker consultation and participation is the single most distinctive requirement in ISO 45001 auditing, with no direct equivalent in ISO 9001 or ISO 14001. Clause 5.4 requires organizations to establish processes for consulting and involving workers — including non-managerial workers — in the development, planning, implementation, performance evaluation, and improvement of the OHSMS. An ISO 45001 internal audit must verify not just that consultation mechanisms exist on paper, but that workers are genuinely being heard and involved — in hazard identification, incident investigation, and even the audit program itself. This is a fundamentally different auditing exercise than reviewing a quality procedure or an environmental register: it requires the auditor to talk directly to workers and assess whether their input is actually shaping decisions.
The hazard-based approach is the other defining difference. Where ISO 14001 auditing centers on environmental aspects and impacts, ISO 45001 auditing centers on hazard identification and risk assessment under Clause 6.1.2 — evaluating whether the organization has proactively and systematically identified hazards across routine and non-routine activities, and whether the resulting risk assessments have actually driven the hierarchy of controls (elimination, substitution, engineering controls, administrative controls, and PPE) rather than defaulting straight to PPE. For a detailed breakdown of what this clause requires, see our guide to ISO 45001 hazard identification.
Compliance obligations are handled similarly to ISO 14001, but the legal landscape an OHS auditor must understand — occupational health and safety legislation, industry-specific safety regulations, incident reporting obligations to regulators — is entirely distinct from environmental obligations. An auditor moving from ISO 14001 to ISO 45001 will find the clause structure very familiar, but the substantive knowledge required — occupational hygiene, ergonomics, hazardous energy control, confined space protocols — is a genuinely different technical domain.
It's also worth understanding how ISO 45001 came to exist in the first place. The standard replaced OHSAS 18001 in 2018, and organizations that transitioned had to adapt to genuinely new requirements including worker participation. For the full history of that transition and what changed, see our article on ISO 45001 vs OHSAS 18001.
Understanding where OHS audits most frequently find nonconformities is essential background for any internal auditor. The patterns are well documented across certification bodies globally, and an effective internal audit program targets these areas deliberately.
1. Worker consultation that's procedurally present but not substantively real. Organizations establish safety committees, worker representative roles, and consultation procedures — then fail to demonstrate that workers were actually consulted on specific hazards, changes, or investigations. The documented mechanism exists; the genuine two-way engagement does not. This is consistently the hardest finding to identify through document review alone, because the paperwork looks compliant.
2. Hazard registers that default straight to PPE without considering the hierarchy of controls. A significant hazard is identified, and the control recorded is "wear appropriate PPE" — with no evidence that elimination, substitution, or engineering controls were ever considered. ISO 45001 requires organizations to apply the hierarchy of controls in order, not to jump to the least effective and lowest-cost option by default.
3. Incident and near-miss investigations that don't reach root cause. A near-miss is reported, and the corrective action is "retrained the employee" — without investigating why the deviation occurred in the first place. Time pressure, procedures that don't match how the work is actually performed, and inadequate equipment are common underlying causes that surface-level investigations miss entirely.
4. Contractor and visitor hazards excluded from the scope of hazard identification. Organizations frequently limit hazard identification to their own employees, missing hazards that affect contractors performing work on site, visitors, or hazards the organization's own activities create for people in the surrounding area. Clause 6.1.2 explicitly requires consideration of all persons who could be affected.
5. Management review that produces minutes but no decisions. A management review meeting occurs on schedule, covers the required inputs, and is documented — but produces no evidence of any actual decision, resource allocation, or action arising from it. A management review that never changes anything is a formality, not a functioning governance mechanism.
Effective ISO 45001 internal auditing starts well before the audit itself. The audit program — required by Clause 9.2.2 — is the overarching arrangement that schedules and coordinates all internal audits over a defined period, typically a 12-month cycle. The individual audit plan then defines the scope, criteria, schedule, and methods for each specific audit within that program.
Building the Audit Program — The audit program must be risk-based. Clause 9.2.2 requires it to account for the importance of the processes concerned, changes affecting the organization, and the results of previous audits. In practice, this means processes with significant hazards — confined space entry, working at height, hazardous energy control, high-risk machinery operation — should be audited more frequently than lower-risk administrative functions. A facility with significant hazards related to heavy machinery, chemical exposure, or working at height should be auditing those controls at least annually, and potentially more often if previous audits have found nonconformities. For a deeper look at how ISO 45001 requires organizations to identify and act on risks and opportunities during the planning phase, see our guide to how to address risks and opportunities in ISO 45001.
Auditor Competence and Independence — Clause 7.2 requires auditors to be competent, and Clause 9.2.2 requires that they conduct audits impartially — meaning they must not audit their own work. This does not mean auditors must be completely independent of the organization. Internal auditors can be employees, provided they are auditing areas they are not responsible for managing. A safety manager can audit the production department; someone from production can audit the safety function.
Competence for OHSMS auditing means knowledge of ISO 45001 requirements, familiarity with the organization's operations and significant hazards, understanding of applicable occupational health and safety legislation, and training in auditing techniques in line with ISO 19011. Where internal auditors lack specific technical expertise — for example, understanding complex occupational hygiene or ergonomic risk factors — organizations should either provide training or supplement with external specialist support.
Pre-Audit Preparation — Before the audit begins, the auditor should review the hazard identification and risk assessment register, the legal and other requirements register, previous audit reports and corrective actions, incident and near-miss records, and the operational control procedures relevant to the area being audited. This review tells the auditor where risk is concentrated, where previous nonconformities were found, and whether corrective actions from the last audit have been effectively closed. It is also the point at which the auditor develops audit checklists — not as a rigid script, but as a structured framework that ensures coverage. For a detailed breakdown of what a well-structured ISO 45001 internal audit checklist covers, see our ISO 45001 internal audit checklist guide.
Good preparation fundamentally changes what an audit finds. When you walk in having already reviewed the hazard register, noted lack of follow up to a near-miss incident six months ago, and seen that the risk assessment for a specific work area hasn't been updated since new equipment was installed — you walk into the facility already knowing what to look for. An auditor who walks in cold and works from a generic checklist will miss the specific risks that matter for that organization. Preparation is not a preliminary step. It is where audit quality is determined.
The ISO 45001 Internal Auditor course covers the full audit process, from program planning through corrective action follow-up, built on ISO 45001 and ISO 19011.
An ISO 45001 internal audit is conducted through three primary evidence-gathering methods: document and records review, observation of physical operations, and interviews with workers. All three are necessary. Document review alone is not sufficient — it tells the auditor what the system says, not what actually happens. Physical observation tells the auditor what is actually being done. Worker interviews reveal whether people understand what is expected of them, whether they've been genuinely consulted, and why the controls that affect them exist.
What to Audit: The Key Clauses — An OHSMS internal audit program must cover all clauses of ISO 45001 over the audit cycle. The following areas carry the highest risk of nonconformity and warrant the most rigorous attention.
Clause 4.1 — Context of the organization. Auditors verify that the organization has identified internal and external issues relevant to worker health and safety and that its scope reflects the full range of activities where workers could be exposed to hazards, including contractors and visitors.
Clause 5.4 — Consultation and participation of workers. This is the requirement most distinctive to ISO 45001 and most frequently under-audited. Auditors examine whether mechanisms exist — safety committees, worker representatives, direct engagement processes — and, critically, whether workers can describe how they've actually been consulted on hazard identification, incident investigation, or changes affecting their work. A documented consultation process that workers can't describe in their own words is a signal the process exists on paper only.
Clause 6.1.2 — Hazard identification and risk assessment. This is the single most frequently cited nonconformity in ISO 45001 audits. The auditor examines whether hazards have been identified proactively across routine and non-routine activities — including maintenance, startup, shutdown, and emergency scenarios — whether the risk assessment is credible and current, and whether controls follow the hierarchy of controls rather than defaulting to PPE. For a full breakdown of what this clause requires and how organizations identify hazards systematically, see our guide to ISO 45001 hazard identification.
Clause 6.1.3 — Legal requirements and other requirements. The auditor reviews the compliance obligations register for completeness — does it capture all applicable occupational health and safety legislation, industry-specific regulations, and licensing conditions? The auditor also looks for evidence that compliance is being actively evaluated, not just listed and assumed.
Clause 7.3 — Awareness. Auditors verify that workers are aware of the OHS policy, the hazards and risks relevant to their own work, the OHSMS's contribution to their safety, the implications of not conforming to OHSMS requirements, and their right to remove themselves from work situations they believe present an imminent and serious risk. This last element is unique to ISO 45001 — no equivalent exists in ISO 9001 or ISO 14001. Auditors should ask workers directly whether they understand this right and would feel able to exercise it without fear of reprisal.
Clause 8.1 — Operational planning and control. This is the implementation clause — where the OHSMS either works or doesn't. Auditors verify that operational controls exist for every significant hazard, that those controls are documented where necessary, that workers have been trained on them, and — critically — that they are being followed in practice. If your organization is preparing for certification or wants expert support strengthening operational controls, our ISO 45001 consulting services can help identify gaps before an external auditor does.
Clause 8.2 — Emergency preparedness and response. The auditor checks that emergency scenarios related to significant hazards have been identified, that response procedures exist and are current, and that drills or exercises have been conducted with worker involvement.
Clause 9.1.2 — Evaluation of compliance. One of the most important and most neglected clauses. The auditor verifies that the organization has a process for regularly evaluating compliance with its legal and other requirements — and that this evaluation is documented. Many organizations assume they are compliant without actually checking.
Clause 9.3 — Management review. Auditors verify that top management is reviewing OHSMS performance at planned intervals, and that the review genuinely addresses the required inputs — audit results, incident trends, worker consultation outcomes, progress against OHS objectives — rather than functioning as a formality. The audit should check whether management review has produced any documented decisions or actions, not just minutes recording that a meeting occurred.
When auditing worker consultation and participation, the question isn't "do you have a safety committee?" — almost every organization does. The question is "when this hazard was identified, who from the workforce was actually consulted, and how did their input change the outcome?" I've audited organizations with an active, well-attended safety committee that meets monthly — but when I ask workers whether their concerns are being addressed there is no clear answer. A safety committee that meets and produces minutes is not the same as workers being genuinely heard. That distinction is exactly what Clause 5.4 is designed to test.
Audit findings must be reported accurately, objectively, and in sufficient detail for management to understand what was found, where it was found, and what evidence supports the finding. A nonconformity report that says "hazard identification is incomplete" is not useful. A report that says "the hazard assessment has not been updated to reflect the introduction of a new forklift route through the warehouse, commissioned in March 2026, as confirmed during a floor walk and verified against the equipment installation log" gives management everything they need to act.
Classifying Findings — ISO 45001 does not prescribe a finding classification system, but most organizations and certification bodies use a three-tier structure: major nonconformities, minor nonconformities, and observations or opportunities for improvement.
A major nonconformity is a failure that represents either the complete absence of a required OHSMS element or a systemic breakdown in implementation — for example, a significant hazard with no operational control in place, or no evidence that worker consultation has occurred on any topic in the past year. A major nonconformity at a certification audit puts certification at risk until it is resolved.
A minor nonconformity is an isolated departure from a requirement — a few training records missing, an inspection not conducted on schedule with no systemic pattern. Multiple minor nonconformities in the same area can indicate a systemic issue and may be escalated to major.
Observations or opportunities for improvement are not nonconformities — they are areas where the OHSMS could be strengthened even though it is not currently failing. A well-written audit report includes both findings and opportunities for improvement, giving management a complete picture of current state and improvement potential.
Reporting findings back to the workforce is a step some organizations overlook. Because worker consultation and participation is central to ISO 45001, communicating relevant audit outcomes — particularly findings that affect worker safety directly — back to the people who raised concerns or were interviewed reinforces the credibility of the consultation process itself. An organization that consults workers during the audit but never tells them what came of it undermines the very engagement Clause 5.4 requires.
If your organization needs professionally structured OHSMS documentation to support certification or strengthen its audit trail, our ISO 45001 documentation package covers the manual, procedures, forms, and internal audit checklist your organization needs. If you need to assess how far your current safety management arrangements are from full ISO 45001 conformity before pursuing certification, our ISO 45001 gap analysis guide explains what that process involves.
Identifying a nonconformity is the beginning of the process, not the end. Clause 10.2 requires that when a nonconformity occurs, the organization reacts to control and correct it, investigates the root cause, determines whether similar nonconformities exist or could occur, implements corrective actions to eliminate the root cause, and reviews the effectiveness of those actions.
This root cause requirement is where many organizations fall short. A corrective action for "hazard register not updated to reflect new forklift route" might be to update the register — which addresses the symptom. The root cause analysis should go further: why wasn't the register updated? Was the safety manager not notified of the operational change? Is there no process connecting operational changes to a hazard review? The corrective action must address the root cause, or the same nonconformity might reappear at the next audit.
Internal auditors play a critical role beyond the initial finding. The audit program should include verification activities — a follow-up check at a defined interval to confirm that corrective actions have been implemented and are effective. A corrective action that was "closed" without verification has not actually been closed. The next external audit might find the same nonconformity and will question why the internal audit program failed to catch it.
The results of internal audits, including corrective actions and their status, must be presented as inputs to management review under Clause 9.3. This is the feedback loop that connects internal audit findings to management decision-making and resource allocation — the mechanism through which internal auditing genuinely drives OHSMS improvement rather than just fulfilling a compliance obligation. For a full step-by-step walkthrough of how to plan, conduct, and follow up on an ISO 45001 internal audit — including how to write findings and verify corrective actions — see our guide on how to conduct an ISO 45001 internal audit. For expert support strengthening your corrective action process or preparing for a certification audit, our ISO 45001 consulting services cover the full scope from gap analysis through to certification preparation.
The corrective actions I see fail most often in ISO 45001 audits are the ones written by someone who never spoke to the worker involved. A near-miss report gets closed with "reminded employee of proper procedure" — but nobody asked the employee why they deviated from the procedure in the first place. Often the answer is that the procedure, as written, doesn't match how the task is actually performed, or that following it correctly would have taken twice as long under production pressure. A corrective action that doesn't account for that reality will not prevent a recurrence. It will just produce a paper trail that looks resolved until the next audit finds the same gap.
ISO 45001 requires internal audits at planned intervals but does not prescribe a specific frequency. The audit program must be risk-based — processes with significant hazards, recent incidents, or demanding legal requirements should be audited more frequently than lower-risk areas. Most certified organizations audit their full OHSMS at least once per 12-month cycle, with higher-risk processes covered more often.
Yes, provided they are competent and impartial — meaning they do not audit their own work. ISO 45001 does not require auditor rotation. The key requirement is that the auditor is not auditing areas they are personally responsible for managing.
An internal audit is a first-party audit conducted by or on behalf of the organization to assess its own OHSMS — it is a management tool for finding and fixing issues before the certification body arrives. An external audit is conducted by an accredited certification body to verify conformity and grant or maintain certification. Certification bodies expect to see evidence of a functioning internal audit program and closed corrective actions before they issue a certificate.
Yes — worker consultation and participation is one of the areas ISO 45001 internal audits must specifically verify, and involving workers directly in the audit process, through interviews and floor observations, is also good auditing practice. Some organizations go further and involve trained worker representatives as part of the internal audit team itself, which strengthens both the credibility of findings and worker trust in the process.
ISO 45001 requires auditors to be competent — meaning they have the relevant knowledge and skills to conduct an effective OHSMS audit. While the standard does not mandate a specific training certificate, most certification bodies normally prefer to see evidence of formal auditor training in competence records. A recognized internal auditor training course provides that documented evidence and ensures auditors have the methodology to conduct credible, evidence-based audits.

Maria Falbo has over 25 years of experience working as a Lead Auditor for certification bodies worldwide. She founded Logix ISO with the mission of making expert-level ISO training accessible to organizations of all sizes. Her work spans Quality, Environmental, Occupational Health and Safety, Food Safety, Automotive, and Energy management systems.
Learn more about Maria →Self-paced · 365-day access · Training certificate included