Skip to main content
    Regulation18 min readPublished April 13, 2026Updated April 16, 2026The QHSE Standard

    How to Pass Your ISO 45001 Audit the First Time: A Step-by-Step Preparation Guide

    Certification audits are stressful — but they don't have to be. With the right preparation, you can walk into your ISO 45001 audit confident that your management system will pass. Here's exactly how.

    Reviewed by The QHSE Standard editorial team

    Fact-checked against ISO 45001, OSHA, EU OSH Framework Directive, and CCPS guidance. Independent of vendor influence — see our review methodology.

    Understanding the ISO 45001 Certification Audit Process

    Before diving into preparation tactics, it's essential to understand what you're preparing for. The ISO 45001 certification process involves two distinct audit stages, each with different objectives and approaches.

    Stage 1 Audit: Documentation Review

    The Stage 1 audit is a readiness assessment. The auditor reviews your documentation and determines whether your management system is sufficiently developed for a full assessment. This is not a "pass/fail" audit — it's a diagnostic.

    What Auditors Evaluate in Stage 1:

    • OH&S policy and objectives
    • Scope of the management system
    • Context of the organization (Clause 4) documentation
    • Risk and opportunity assessment methodology and results
    • Legal register and compliance evaluation process
    • Documented procedures and their alignment with standard requirements
    • Internal audit program and results
    • Management review records
    • Resource allocation for the management system

    Stage 1 Outcomes:

    • Confirmation that you're ready for Stage 2
    • Identification of areas that need attention before Stage 2
    • Agreement on the Stage 2 audit plan (scope, schedule, locations)
    • Flagging of potential non-conformances to address

    Timeline: Stage 1 typically occurs 4-8 weeks before Stage 2, giving you time to address any concerns raised.

    Stage 2 Audit: Implementation Verification

    The Stage 2 audit is the main assessment. Auditors verify that your management system is not just documented but actually implemented and effective. This is where certification is granted or denied.

    What Auditors Evaluate in Stage 2:

    • Evidence that documented processes are followed in practice
    • Worker awareness and participation
    • Operational controls and their effectiveness
    • Incident investigation and corrective action processes
    • Management commitment and engagement
    • Performance monitoring and measurement
    • Continual improvement evidence
    • Emergency preparedness

    Stage 2 Methods:

    • Document review (deeper than Stage 1)
    • Interviews with workers at all levels
    • Observation of work activities
    • Examination of records and evidence
    • Verification of process outputs

    The 12 Most Common Non-Conformances (And How to Avoid Them)

    Based on analysis of thousands of ISO 45001 audits by major certification bodies, these are the most frequently cited non-conformances:

    1. Inadequate Worker Consultation and Participation (Clause 5.4)

    The Problem: ISO 45001 places unprecedented emphasis on worker participation. Many organizations still treat this as a checkbox exercise — a safety committee that meets quarterly and rubber-stamps decisions.

    What Auditors Look For:

    • Evidence that workers at all levels are consulted on OH&S matters
    • Workers can articulate how they participate in the management system
    • Non-managerial workers are involved in hazard identification and risk assessment
    • Mechanisms exist for workers to report concerns without fear of reprisal
    • Workers understand their right to refuse unsafe work

    How to Prepare:

    • Implement safety observation and suggestion programs accessible to all workers
    • Document worker consultation records (meeting minutes, survey results, suggestion logs)
    • Include worker representatives in risk assessment processes
    • Train workers on their participation rights and responsibilities
    • Maintain records of how worker feedback influenced decisions

    2. Incomplete Hazard Identification (Clause 6.1.2.1)

    The Problem: Organizations identify obvious physical hazards but miss psychosocial factors, ergonomic risks, and non-routine activities.

    What Auditors Look For:

    • Systematic hazard identification covering routine and non-routine activities
    • Consideration of all hazard types: physical, chemical, biological, psychosocial, ergonomic
    • Assessment of hazards from changes (new processes, equipment, personnel)
    • Inclusion of hazards created by people working in the vicinity
    • Hazard identification for emergency situations

    How to Prepare:

    • Review your hazard identification process for completeness
    • Ensure psychosocial hazards (stress, bullying, fatigue, violence) are assessed
    • Include non-routine activities (maintenance, shutdowns, emergencies) in assessments
    • Document the methodology used and ensure it's consistently applied
    • Verify that hazard identification is ongoing, not a one-time exercise

    3. Weak Management of Change (Clause 8.1.3)

    The Problem: Organizations make changes to processes, equipment, personnel, or regulations without systematically assessing the OH&S implications.

    What Auditors Look For:

    • A defined MOC process that triggers for relevant changes
    • Impact assessment considering OH&S risks and opportunities
    • Updated risk assessments reflecting changes
    • Communication of changes to affected workers
    • Verification that controls remain effective after changes

    How to Prepare:

    • Define what constitutes a "change" that triggers the MOC process
    • Create a simple MOC form that captures: what changed, impact assessment, required actions, communication plan
    • Review recent changes and ensure they were processed through MOC
    • Interview workers to verify they were informed about changes affecting their safety

    The Problem: Organizations maintain a legal register but don't systematically evaluate their compliance with applicable requirements.

    What Auditors Look For:

    • Complete and current register of legal and other requirements
    • Documented evaluation of compliance status for each requirement
    • Defined frequency of compliance evaluation
    • Actions taken when non-compliance is identified
    • Records of compliance evaluations

    How to Prepare:

    • Update your legal register — ensure it covers all applicable legislation
    • Conduct a formal compliance evaluation with documented evidence
    • Address any non-compliances identified
    • Establish a process for monitoring regulatory changes
    • Keep records of how compliance is evaluated and by whom

    5. Inadequate Internal Audit Program (Clause 9.2)

    The Problem: Internal audits that are too superficial, not independent enough, or don't cover the full scope of the management system.

    What Auditors Look For:

    • Audit program covering all standard clauses and organizational processes
    • Audit frequency based on risk and previous results
    • Auditor competence and independence
    • Audit reports with clear findings
    • Corrective action tracking for audit findings
    • Trend analysis across audit cycles

    How to Prepare:

    • Ensure your internal audit program covers all ISO 45001 clauses
    • Verify auditors are trained and independent from the areas they audit
    • Complete at least one full cycle of internal audits before the certification audit
    • Address all non-conformances identified in internal audits
    • Document how internal audit results are reported to management

    6. Superficial Incident Investigation (Clause 10.2)

    The Problem: Investigation reports that stop at surface-level causes ("worker didn't follow procedure") without exploring systemic factors.

    What Auditors Look For:

    • Root cause analysis methodology applied consistently
    • Investigation scope proportional to incident severity and potential
    • Corrective actions addressing root causes, not just symptoms
    • Evidence of organizational learning from incidents
    • Near-miss investigations

    How to Prepare:

    • Review recent incident investigations for depth of root cause analysis
    • Ensure corrective actions address systemic factors, not just immediate causes
    • Verify that lessons learned are communicated across the organization
    • Check that near-misses are investigated proportional to their potential severity
    • Demonstrate how investigation findings drive improvement

    7. Lack of OH&S Objectives with Plans (Clause 6.2)

    The Problem: Organizations set vague objectives ("improve safety") without measurable targets, timelines, responsible persons, or resource allocation.

    What Auditors Look For:

    • Objectives consistent with the OH&S policy
    • Measurable targets
    • Plans showing what will be done, resources required, responsible persons, timelines
    • Monitoring and measurement of progress
    • Evidence of review and adjustment

    How to Prepare:

    • Set 3-5 SMART objectives for the current period
    • Document action plans for each objective
    • Assign resources and responsibilities
    • Track progress with regular measurement
    • Present objective status in management reviews

    8-12: Additional Common Non-Conformances

    8. Incomplete Context Analysis (Clause 4): Failure to identify all relevant internal/external issues and interested parties. Fix: Conduct and document a thorough PESTLE and stakeholder analysis.

    9. Weak Emergency Preparedness (Clause 8.2): Emergency plans that haven't been tested or updated. Fix: Conduct drills, document results, update plans based on lessons learned.

    10. Inadequate Competence Management (Clause 7.2): No systematic approach to ensuring workers have the competence their roles require. Fix: Define competence requirements for each role, maintain training records, verify effectiveness.

    11. Poor Document Control (Clause 7.5): Outdated documents in circulation, inconsistent version control. Fix: Implement document management with version control, approval workflows, and distribution tracking.

    12. Missing Top Management Commitment Evidence (Clause 5.1): Auditors can't see tangible evidence of leadership engagement beyond signing the policy. Fix: Record management safety walks, meeting participation, resource allocation decisions, and communications.

    Preparation Timeline: 6-Month Countdown

    Month 6: Assessment and Planning

    • Conduct honest gap analysis against all ISO 45001 clauses
    • Identify major gaps and prioritize actions
    • Assign resources and responsibilities
    • Select certification body and agree on audit dates

    Month 5: System Development

    • Address major documentation gaps
    • Implement missing processes (MOC, compliance evaluation, etc.)
    • Configure QHSE software to support standard requirements
    • Begin training workers on new processes

    Month 4: Implementation

    • Roll out new processes across all sites/departments
    • Conduct targeted training on areas of weakness
    • Begin collecting evidence of implementation
    • Start worker consultation and participation activities

    Month 3: Internal Audit

    • Train internal auditors (or engage competent external auditors)
    • Conduct comprehensive internal audit covering all clauses
    • Document findings and initiate corrective actions
    • Track corrective action completion

    Month 2: Management Review and Refinement

    • Conduct management review with complete agenda
    • Address internal audit non-conformances
    • Verify corrective action effectiveness
    • Conduct Stage 1 audit (if scheduled separately)

    Month 1: Final Preparation

    • Address Stage 1 findings (if any)
    • Conduct pre-audit readiness check
    • Brief all staff on audit process and expectations
    • Organize evidence and documentation for easy access
    • Conduct mock audit for high-risk areas

    Audit Week

    • Ensure key personnel are available
    • Prepare meeting rooms with access to systems and documents
    • Brief workers on what to expect during auditor interviews
    • Assign a guide for each auditor
    • Remain calm and professional throughout

    Tips for Audit Day

    Do:

    • Answer questions honestly and directly
    • Say "I don't know, but I can find out" rather than guessing
    • Provide evidence promptly when requested
    • Show genuine enthusiasm for safety management
    • Demonstrate that your system is a living, working tool

    Don't:

    • Volunteer information beyond what's asked
    • Make excuses for gaps or non-conformances
    • Argue with auditors about their findings
    • Panic if a non-conformance is raised — it's normal and manageable
    • Try to hide problems — auditors are experienced at detecting this

    What Happens If You Get Non-Conformances?

    Minor Non-Conformances: You'll have a defined period (typically 90 days) to address them. Provide evidence of corrective action to the certification body. These don't prevent certification.

    Major Non-Conformances: These indicate a significant system failure. You'll need to address them and may require a follow-up audit visit before certification can be granted.

    Observations: Improvement opportunities noted by the auditor. Not formally required to be addressed, but demonstrate commitment by acting on them.

    Conclusion

    Passing your ISO 45001 certification audit on the first attempt is achievable with systematic preparation, genuine implementation, and appropriate use of technology. The key is treating the standard not as a hurdle to clear, but as a framework for building a management system that actually protects your workers.

    Explore QHSE platforms with ISO 45001 support in our comparison guides, or get matched to the right platform for your certification journey with our free tool.

    ISO 45001certification auditpreparationnon-conformancecomplianceaudit tips

    Software covered in this category

    Browse all platforms →
    Not sure which fits? Get matched in 60s

    Looking for the Right QHSE Software?

    Take our 60-second quiz and get personalized recommendations.

    Get Matched — Free
    Back to all articles