How to Pass Your ISO 45001 Audit the First Time: A Step-by-Step Preparation Guide
Certification audits are stressful — but they don't have to be. With the right preparation, you can walk into your ISO 45001 audit confident that your management system will pass. Here's exactly how.
Reviewed by The QHSE Standard editorial team
Fact-checked against ISO 45001, OSHA, EU OSH Framework Directive, and CCPS guidance. Independent of vendor influence — see our review methodology.
Understanding the ISO 45001 Certification Audit Process
Before diving into preparation tactics, it's essential to understand what you're preparing for. The ISO 45001 certification process involves two distinct audit stages, each with different objectives and approaches.
Stage 1 Audit: Documentation Review
The Stage 1 audit is a readiness assessment. The auditor reviews your documentation and determines whether your management system is sufficiently developed for a full assessment. This is not a "pass/fail" audit — it's a diagnostic.
What Auditors Evaluate in Stage 1:
- OH&S policy and objectives
- Scope of the management system
- Context of the organization (Clause 4) documentation
- Risk and opportunity assessment methodology and results
- Legal register and compliance evaluation process
- Documented procedures and their alignment with standard requirements
- Internal audit program and results
- Management review records
- Resource allocation for the management system
Stage 1 Outcomes:
- Confirmation that you're ready for Stage 2
- Identification of areas that need attention before Stage 2
- Agreement on the Stage 2 audit plan (scope, schedule, locations)
- Flagging of potential non-conformances to address
Timeline: Stage 1 typically occurs 4-8 weeks before Stage 2, giving you time to address any concerns raised.
Stage 2 Audit: Implementation Verification
The Stage 2 audit is the main assessment. Auditors verify that your management system is not just documented but actually implemented and effective. This is where certification is granted or denied.
What Auditors Evaluate in Stage 2:
- Evidence that documented processes are followed in practice
- Worker awareness and participation
- Operational controls and their effectiveness
- Incident investigation and corrective action processes
- Management commitment and engagement
- Performance monitoring and measurement
- Continual improvement evidence
- Emergency preparedness
Stage 2 Methods:
- Document review (deeper than Stage 1)
- Interviews with workers at all levels
- Observation of work activities
- Examination of records and evidence
- Verification of process outputs
The 12 Most Common Non-Conformances (And How to Avoid Them)
Based on analysis of thousands of ISO 45001 audits by major certification bodies, these are the most frequently cited non-conformances:
1. Inadequate Worker Consultation and Participation (Clause 5.4)
The Problem: ISO 45001 places unprecedented emphasis on worker participation. Many organizations still treat this as a checkbox exercise — a safety committee that meets quarterly and rubber-stamps decisions.
What Auditors Look For:
- Evidence that workers at all levels are consulted on OH&S matters
- Workers can articulate how they participate in the management system
- Non-managerial workers are involved in hazard identification and risk assessment
- Mechanisms exist for workers to report concerns without fear of reprisal
- Workers understand their right to refuse unsafe work
How to Prepare:
- Implement safety observation and suggestion programs accessible to all workers
- Document worker consultation records (meeting minutes, survey results, suggestion logs)
- Include worker representatives in risk assessment processes
- Train workers on their participation rights and responsibilities
- Maintain records of how worker feedback influenced decisions
2. Incomplete Hazard Identification (Clause 6.1.2.1)
The Problem: Organizations identify obvious physical hazards but miss psychosocial factors, ergonomic risks, and non-routine activities.
What Auditors Look For:
- Systematic hazard identification covering routine and non-routine activities
- Consideration of all hazard types: physical, chemical, biological, psychosocial, ergonomic
- Assessment of hazards from changes (new processes, equipment, personnel)
- Inclusion of hazards created by people working in the vicinity
- Hazard identification for emergency situations
How to Prepare:
- Review your hazard identification process for completeness
- Ensure psychosocial hazards (stress, bullying, fatigue, violence) are assessed
- Include non-routine activities (maintenance, shutdowns, emergencies) in assessments
- Document the methodology used and ensure it's consistently applied
- Verify that hazard identification is ongoing, not a one-time exercise
3. Weak Management of Change (Clause 8.1.3)
The Problem: Organizations make changes to processes, equipment, personnel, or regulations without systematically assessing the OH&S implications.
What Auditors Look For:
- A defined MOC process that triggers for relevant changes
- Impact assessment considering OH&S risks and opportunities
- Updated risk assessments reflecting changes
- Communication of changes to affected workers
- Verification that controls remain effective after changes
How to Prepare:
- Define what constitutes a "change" that triggers the MOC process
- Create a simple MOC form that captures: what changed, impact assessment, required actions, communication plan
- Review recent changes and ensure they were processed through MOC
- Interview workers to verify they were informed about changes affecting their safety
4. Insufficient Legal Compliance Evaluation (Clause 6.1.3 / 9.1.2)
The Problem: Organizations maintain a legal register but don't systematically evaluate their compliance with applicable requirements.
What Auditors Look For:
- Complete and current register of legal and other requirements
- Documented evaluation of compliance status for each requirement
- Defined frequency of compliance evaluation
- Actions taken when non-compliance is identified
- Records of compliance evaluations
How to Prepare:
- Update your legal register — ensure it covers all applicable legislation
- Conduct a formal compliance evaluation with documented evidence
- Address any non-compliances identified
- Establish a process for monitoring regulatory changes
- Keep records of how compliance is evaluated and by whom
5. Inadequate Internal Audit Program (Clause 9.2)
The Problem: Internal audits that are too superficial, not independent enough, or don't cover the full scope of the management system.
What Auditors Look For:
- Audit program covering all standard clauses and organizational processes
- Audit frequency based on risk and previous results
- Auditor competence and independence
- Audit reports with clear findings
- Corrective action tracking for audit findings
- Trend analysis across audit cycles
How to Prepare:
- Ensure your internal audit program covers all ISO 45001 clauses
- Verify auditors are trained and independent from the areas they audit
- Complete at least one full cycle of internal audits before the certification audit
- Address all non-conformances identified in internal audits
- Document how internal audit results are reported to management
6. Superficial Incident Investigation (Clause 10.2)
The Problem: Investigation reports that stop at surface-level causes ("worker didn't follow procedure") without exploring systemic factors.
What Auditors Look For:
- Root cause analysis methodology applied consistently
- Investigation scope proportional to incident severity and potential
- Corrective actions addressing root causes, not just symptoms
- Evidence of organizational learning from incidents
- Near-miss investigations
How to Prepare:
- Review recent incident investigations for depth of root cause analysis
- Ensure corrective actions address systemic factors, not just immediate causes
- Verify that lessons learned are communicated across the organization
- Check that near-misses are investigated proportional to their potential severity
- Demonstrate how investigation findings drive improvement
7. Lack of OH&S Objectives with Plans (Clause 6.2)
The Problem: Organizations set vague objectives ("improve safety") without measurable targets, timelines, responsible persons, or resource allocation.
What Auditors Look For:
- Objectives consistent with the OH&S policy
- Measurable targets
- Plans showing what will be done, resources required, responsible persons, timelines
- Monitoring and measurement of progress
- Evidence of review and adjustment
How to Prepare:
- Set 3-5 SMART objectives for the current period
- Document action plans for each objective
- Assign resources and responsibilities
- Track progress with regular measurement
- Present objective status in management reviews
8-12: Additional Common Non-Conformances
8. Incomplete Context Analysis (Clause 4): Failure to identify all relevant internal/external issues and interested parties. Fix: Conduct and document a thorough PESTLE and stakeholder analysis.
9. Weak Emergency Preparedness (Clause 8.2): Emergency plans that haven't been tested or updated. Fix: Conduct drills, document results, update plans based on lessons learned.
10. Inadequate Competence Management (Clause 7.2): No systematic approach to ensuring workers have the competence their roles require. Fix: Define competence requirements for each role, maintain training records, verify effectiveness.
11. Poor Document Control (Clause 7.5): Outdated documents in circulation, inconsistent version control. Fix: Implement document management with version control, approval workflows, and distribution tracking.
12. Missing Top Management Commitment Evidence (Clause 5.1): Auditors can't see tangible evidence of leadership engagement beyond signing the policy. Fix: Record management safety walks, meeting participation, resource allocation decisions, and communications.
Preparation Timeline: 6-Month Countdown
Month 6: Assessment and Planning
- Conduct honest gap analysis against all ISO 45001 clauses
- Identify major gaps and prioritize actions
- Assign resources and responsibilities
- Select certification body and agree on audit dates
Month 5: System Development
- Address major documentation gaps
- Implement missing processes (MOC, compliance evaluation, etc.)
- Configure QHSE software to support standard requirements
- Begin training workers on new processes
Month 4: Implementation
- Roll out new processes across all sites/departments
- Conduct targeted training on areas of weakness
- Begin collecting evidence of implementation
- Start worker consultation and participation activities
Month 3: Internal Audit
- Train internal auditors (or engage competent external auditors)
- Conduct comprehensive internal audit covering all clauses
- Document findings and initiate corrective actions
- Track corrective action completion
Month 2: Management Review and Refinement
- Conduct management review with complete agenda
- Address internal audit non-conformances
- Verify corrective action effectiveness
- Conduct Stage 1 audit (if scheduled separately)
Month 1: Final Preparation
- Address Stage 1 findings (if any)
- Conduct pre-audit readiness check
- Brief all staff on audit process and expectations
- Organize evidence and documentation for easy access
- Conduct mock audit for high-risk areas
Audit Week
- Ensure key personnel are available
- Prepare meeting rooms with access to systems and documents
- Brief workers on what to expect during auditor interviews
- Assign a guide for each auditor
- Remain calm and professional throughout
Tips for Audit Day
Do:
- Answer questions honestly and directly
- Say "I don't know, but I can find out" rather than guessing
- Provide evidence promptly when requested
- Show genuine enthusiasm for safety management
- Demonstrate that your system is a living, working tool
Don't:
- Volunteer information beyond what's asked
- Make excuses for gaps or non-conformances
- Argue with auditors about their findings
- Panic if a non-conformance is raised — it's normal and manageable
- Try to hide problems — auditors are experienced at detecting this
What Happens If You Get Non-Conformances?
Minor Non-Conformances: You'll have a defined period (typically 90 days) to address them. Provide evidence of corrective action to the certification body. These don't prevent certification.
Major Non-Conformances: These indicate a significant system failure. You'll need to address them and may require a follow-up audit visit before certification can be granted.
Observations: Improvement opportunities noted by the auditor. Not formally required to be addressed, but demonstrate commitment by acting on them.
Conclusion
Passing your ISO 45001 certification audit on the first attempt is achievable with systematic preparation, genuine implementation, and appropriate use of technology. The key is treating the standard not as a hurdle to clear, but as a framework for building a management system that actually protects your workers.
Explore QHSE platforms with ISO 45001 support in our comparison guides, or get matched to the right platform for your certification journey with our free tool.
Software covered in this category
Browse all platforms →- Risk & Compliance4.4
Origami Risk
Integrated risk, safety, and insurance management platform
Read review - Risk & Compliance4.4
Onspring
No-code GRC & business operations
Read review - Risk & Compliance4.3
Enhesa
Global EHS & product regulatory intelligence
Read review
Looking for the Right QHSE Software?
Take our 60-second quiz and get personalized recommendations.
Get Matched — Free