ISO 45001

ISO 45001 Internal Audit Checklist: What Auditors Look For

An ISO 45001 internal audit checklist covers the requirements of Clauses 4 through 10 — from context of the organization and hazard identification through to worker participation, incident investigation, and management review. A well-structured checklist maps each clause to the evidence an auditor expects to find, ensuring full OHSMS coverage and consistent findings across every audit.

An ISO 45001 internal audit checklist is one of the most widely searched topics in occupational health and safety management — and one of the most misunderstood. Most organizations approach a checklist as a list of questions to tick through. The auditors who produce the most consistent, credible findings treat it differently: as a structured framework for evidence gathering, not a substitute for judgment. This article explains what a well-structured ISO 45001 internal audit checklist covers, how it maps to the standard's clauses, and what auditors are actually looking for in each area — drawing on the approach developed by Maria Falbo, a Lead Auditor with decades of ISO 45001 experience.

Maria Falbo|Lead Trainer, Logix ISO|July 2026|11 min read

What an ISO 45001 Internal Audit Checklist Is — and What It Isn't

An ISO 45001 internal audit checklist is a structured tool that guides an auditor through the requirements of the standard — clause by clause — ensuring that every area of the OHSMS is examined with consistency across audits and auditors. It is not a script. It is not a pass/fail form. And it is not a substitute for auditor judgment.

The most common mistake organizations make with checklists is treating them as the audit itself — working through questions in order, recording yes or no answers, and declaring the audit complete. A checklist used this way produces a false sense of coverage. Auditors miss the gaps that don't fit neatly into a predefined question, ignore the evidence that doesn't align with what they expected to find, and fail to follow trails that the checklist didn't anticipate.

A well-structured checklist covers all clauses of ISO 45001 from Clause 4 through to Clause 10, maps each clause to the type of evidence the auditor should expect to find, and builds in enough flexibility to prompt follow-up rather than closing off inquiry. It is the framework the auditor uses before and during the audit — not the output they produce at the end of it. Checklists are also not static documents — a checklist appropriate for a warehouse operation with forklift traffic and racking hazards looks very different from one built for an office-based professional services firm, even though both organizations are certified to the same standard. For a complete guide to the full ISO 45001 internal audit lifecycle, see our ISO 45001 Internal Audit: The Complete Guide.

In Practice

A checklist built from a template downloaded off the internet asks whether hazard identification has taken place. A checklist built by someone who understands the operation asks whether the hazard register reflects the new palletizing equipment installed last quarter, whether the risk assessment for that equipment considered the operators who'll actually run it on the night shift, and whether those operators were involved in developing the control before it was finalized. The specificity is what separates a checklist that produces real findings from one that produces a completed form.

Clause 4 — Context of the Organization

Clause 4 covers the foundational analysis that the entire OHSMS is built on — the organization's internal and external issues, its interested parties and their requirements, and the scope of the OHSMS.

The checklist for Clause 4 examines whether the context analysis is documented and current. Auditors look for evidence that the organization has identified both internal factors (operational changes, workforce composition, resource constraints) and external factors (regulatory environment, industry safety standards, contractor and supply chain arrangements).

The scope of the OHSMS is another key checkpoint. Auditors verify that the documented scope accurately reflects what the organization does and where it does it — and that it hasn't been drawn so narrowly as to exclude activities or locations where workers face significant hazards, including contractor-managed areas and locations where the organization's activities could affect people outside its own workforce.

Clause 5 — Leadership and Worker Participation

Clause 5 covers top management commitment, the OHS policy, and — distinctively for ISO 45001 — the consultation and participation of workers. This clause carries a lot of weight in ISO 45001, because of the worker participation requirement it introduces.

The checklist for Clause 5 examines whether the OHS policy is documented, communicated, and actually understood by the people it applies to. Auditors look for evidence that management is actively involved in setting OHS objectives, allocating resources, and reviewing OHSMS performance — not just signing off on a policy document.

Consultation and participation of workers deserves its own dedicated checklist attention. Auditors examine whether mechanisms exist — safety committees, worker representatives, direct engagement processes — for consulting and involving workers, including non-managerial workers, in hazard identification, incident investigation, and OHSMS development. Staff interviews are essential here: if frontline workers cannot describe a specific instance where their input shaped a decision, the audit has found a gap regardless of what the documentation says. For structured training on how to audit worker consultation and participation credibly, see our ISO 45001 Internal Auditor course.

A professionally structured checklist, ready to use

The Logix ISO documentation package includes an ISO 45001 internal audit checklist built to the current standard — fully editable for your organization.

View Documentation

Clause 6 — Planning

Clause 6 is where the most critical and most frequently cited nonconformities in ISO 45001 audits are found. It covers hazard identification, risk assessment, legal and other requirements, and OHS objectives.

Hazard identification and risk assessment (Clause 6.1.2) — The checklist examines whether hazards have been identified across all operations including routine, non-routine, and emergency conditions, and whether social factors — workload, work hours, and workplace culture — have been considered alongside physical hazards. Auditors look for whether the risk assessment is credible and current, and whether the register reflects recent process changes.

Legal and other requirements (Clause 6.1.3) — The checklist verifies that the legal register is complete and current, capturing all applicable occupational health and safety legislation, industry-specific regulations, and licensing conditions. Critically, auditors look for evidence that compliance is being actively evaluated (Clause 9.1.2), not just listed.

OHS objectives (Clause 6.2) — The checklist examines whether objectives are measurable, consistent with the OHS policy, and supported by documented action plans. Auditors look for evidence of progress monitoring — not just targets set and forgotten.

In Practice

The hazard identification gap I see most often isn't a missing register — it's a register that only captures what's obvious. A facility's register might list "chemical storage" as a hazard, but when you ask what specifically about chemical storage — incompatible chemicals stored together, no secondary containment, no one trained on the safety data sheet for the newest product added last month — the specificity falls apart. A hazard register that names categories instead of actual conditions gives auditors nothing concrete to verify, and gives workers no real protection either.

Clause 7 — Support

Clause 7 covers the resources, competence, awareness, communication, and documented information that support OHSMS implementation.

Competence (Clause 7.2) — The checklist examines whether personnel whose work has a significant effect on OHS performance have the necessary competence — through education, training, or experience — and whether that competence is documented. Auditors look for training and other supporting records that are current, relevant, and specific to the hazards of the roles in question.

Awareness (Clause 7.3) — The checklist verifies that workers are aware of the OHS policy, the hazards relevant to their own work, and their right to remove themselves from a work situation they believe presents an imminent and serious risk. Auditors ask workers directly whether they understand this right — a distinctly ISO 45001 requirement with no parallel in quality or environmental management.

Communication (Clause 7.4) — The checklist examines whether the organization has an established process for internal and external OHS communication, and whether it is being followed. This includes communication to contractors, visitors, and other relevant interested parties about hazards and requirements affecting them.

Documented information (Clause 7.5) — The checklist verifies that required documented information exists, is controlled, and is in use. Auditors look for evidence that the documents in use are the current approved versions.

Clause 8 — Operation

Clause 8 is the implementation clause — where the OHSMS either works in practice or doesn't. It covers operational planning and control and emergency preparedness and response.

Operational control (Clause 8.1) — The checklist examines whether operational controls exist for every significant hazard, whether those controls are documented where necessary, and whether they are being followed in practice. This is where physical site observation is most critical. Controls that exist on paper but are not followed in the operation are one of the most common audit findings. For a practical breakdown of how hazards are identified and controls are determined, see our guide to ISO 45001 hazard identification.

Emergency preparedness and response (Clause 8.2) — The checklist examines whether potential emergency scenarios related to significant hazards have been identified, whether response procedures are documented and current, and whether drills or exercises have been conducted within the required timeframe, with worker involvement.

Clause 9 — Performance Evaluation

Clause 9 covers monitoring and measurement, compliance evaluation, internal audit, and management review — the mechanisms through which the organization assesses how well the OHSMS is performing.

Monitoring and measurement (Clause 9.1.1) — The checklist examines whether key OHS performance indicators are being monitored at the required frequency, and whether both leading indicators (near-miss reporting, safety inspections) and lagging indicators (incident rates) are being tracked and used to drive improvement.

Evaluation of compliance (Clause 9.1.2) — The checklist verifies that the organization has a documented process for regularly evaluating compliance with its legal and other requirements, and that this evaluation is being conducted and recorded. Organizations that maintain a legal register but never formally evaluate whether they are meeting those obligations are failing this clause.

Management review (Clause 9.3) — The checklist examines whether management reviews are being conducted at planned intervals, whether the required inputs are being presented, and whether the review is producing documented outputs — decisions and actions, not just minutes of a meeting.

Clause 10 — Improvement

Clause 10 covers incident investigation, nonconformity and corrective action, and the continual improvement obligation that runs through the entire standard.

Incident investigation — The checklist examines whether incidents and near-misses are being reported, investigated to identify root cause, and used to drive corrective action — not just logged and filed. A high volume of near-miss reports with no evidence of investigation is itself a nonconformity signal, not a sign of a healthy reporting culture.

Corrective action (Clause 10.2) — The checklist examines whether nonconformities and incidents are being addressed through root cause analysis, whether corrective actions address the root cause rather than just the symptom, and whether the effectiveness of those actions is being verified before they are closed. A corrective action log full of entries marked "closed" without evidence of verification is a Clause 10.2 finding.

Continual improvement (Clause 10.3) — The checklist looks for evidence that the organization is actively seeking to improve OHS performance — not just maintaining compliance. This might be reflected in OHS objectives becoming more ambitious over time, in the reduction of incident rates, or in proactive identification of improvement opportunities through the audit program itself.

For a step-by-step walkthrough of how to use a checklist during an actual audit, see our guide on how to conduct an ISO 45001 internal audit. For a full explanation of how ISO 45001 requires organizations to address risks and opportunities during planning, see our risks and opportunities guide.

FAQ

Frequently asked questions

Does an ISO 45001 internal audit checklist need to cover every clause?

The audit program must cover all clauses of ISO 45001 over the audit cycle — but not every clause needs to be audited in every individual audit. Higher-risk areas should be audited more frequently. The checklist for a given audit should cover the clauses within the defined scope of that audit, with full clause coverage achieved across the overall program.

Should the checklist be the same for every audit?

No — a well-designed checklist is tailored to the specific scope, objectives, and risk profile of each individual audit. A generic checklist applied to every audit regardless of context will miss the organization-specific hazards that matter most. The clause structure of ISO 45001 provides the framework, but the checklist questions should reflect the actual operations being audited.

What is the difference between an audit checklist and a legal register?

A legal register (required under Clause 6.1.3) lists the occupational health and safety legislation and other requirements that apply to the organization. An audit checklist is the tool the auditor uses to assess whether the OHSMS conforms to ISO 45001 requirements — including, but not limited to, whether legal requirements have been identified and evaluated. They serve different purposes and neither substitutes for the other.

Does the checklist need to include questions about worker participation?

Yes — and this is one of the areas most generic checklists handle poorly. Worker consultation and participation under Clause 5.4 is one of the most distinctive requirements in ISO 45001, and a checklist that treats it as a single yes/no item ("does a safety committee exist?") misses the substance of the requirement. The checklist should prompt the auditor to verify genuine engagement, not just the presence of a mechanism.

Is a downloadable checklist sufficient for ISO 45001 certification?

A checklist is a tool, not a management system. Organizations that approach ISO 45001 by downloading a checklist and working through it are likely to pass the checklist but fail the audit — because conformity requires a functioning OHSMS, not a completed form. A professionally developed checklist is a useful starting point, but it needs to be applied by a competent auditor who understands both the standard and the organization's operations.

About the Author
Maria Falbo — Lead Trainer, Logix ISO
Maria Falbo
Founder & Lead Trainer, Logix ISO · 25+ Years Global Experience

Maria Falbo has over 25 years of experience working as a Lead Auditor for certification bodies worldwide. She founded Logix ISO with the mission of making expert-level ISO training accessible to organizations of all sizes. Her work spans Quality, Environmental, Occupational Health and Safety, Food Safety, Automotive, and Energy management systems.

Learn more about Maria →
ISO 45001 Documentation
Looking for a professionally structured ISO 45001 internal audit checklist?

Available individually or as a complete package with the manual, procedures, and forms — fully editable and built to the current standard.

View ISO 45001 Documentation