Skip to main content
    Guide14 min readPublished May 29, 2026Elena Papadakis

    ISO 45001 Internal Audit Checklist 2026: 80-Point Clause-by-Clause Template

    A full ISO 45001 internal audit checklist for 2026 — clause-by-clause questions, evidence to collect, common nonconformities certification bodies actually raise, scoring rubric and post-audit CAPA workflow.

    Guide illustration for the article “ISO 45001 Internal Audit Checklist 2026: 80-Point Clause-by-Clause Template” — The QHSE Standard

    Written by Elena Papadakis · Reviewed by The QHSE Standard editorial team

    Fact-checked against ISO 45001, OSHA, EU OSH Framework Directive, and CCPS guidance. Independent of vendor influence — see our review methodology.

    ISO 45001 Internal Audit Checklist 2026: 80-Point Clause-by-Clause Template

    A useful ISO 45001 internal audit is not a 200-question PDF that nobody reads. It is a focused, clause-by-clause walk-through that surfaces real risk and produces actions your business will actually close. This 2026 template gives you exactly that: 80 audit questions across clauses 4 to 10, the evidence to look for, the nonconformities certification bodies are raising right now, and the scoring rubric that keeps results comparable across sites.

    Use it as a working document for your next internal audit cycle, or as a self-assessment before booking your stage 2 / surveillance audit.

    How to use this checklist

    • Pace. Plan 1.5 to 2 days for a single site of 50–200 FTE. Half a day for sites under 50 FTE. Multi-site programmes should run one audit per site per year, plus a central audit on clauses 4, 5, 9.3 and 10.
    • Auditors. Two-person team minimum. One leads, one notes. Both must be ISO 45001 lead-auditor trained or equivalent.
    • Scoring rubric. Per question: 2 = Conforms, 1 = Observation (opportunity for improvement), 0 = Minor NC, –1 = Major NC. Roll up by clause and overall.
    • Evidence rule. Every "Conforms" needs at least one piece of objective evidence cited in the audit note — a document, an interview, a system screenshot or a site observation.

    Clause 4 — Context of the organization (8 questions)

    1. Is there a documented context analysis covering internal and external issues, including climate change (per the 2024 amendment)?
    2. Are interested parties identified with their needs and expectations documented?
    3. Is the scope of the OH&S management system documented and available to interested parties?
    4. Does the scope reference physical boundaries (sites, units), activities and exclusions with justification?
    5. Are workers and worker representatives identified as a primary interested party?
    6. Are PESTLE-style external factors (regulatory, technology, economic) reviewed at least annually?
    7. Is the scope aligned with the organization's strategic direction and current operations?
    8. Are subcontractors, visitors and remote workers explicitly addressed in the scope?

    Evidence to collect: Context register, scope statement, interested-parties register, last review minutes.

    Common nonconformities: Context register not updated in >12 months. Climate change not considered. Scope excludes contractors without justification.


    Clause 5 — Leadership & worker participation (12 questions)

    1. Is there a current, signed and dated OH&S policy?
    2. Does the policy include commitments to provide safe working conditions, eliminate hazards and reduce risks?
    3. Does it commit to consultation and participation of workers?
    4. Does it commit to continual improvement and to legal/other compliance?
    5. Is the policy communicated, understood and applied within the organization?
    6. Are top management's OH&S responsibilities documented (e.g. in role descriptions)?
    7. Have OH&S roles, responsibilities and authorities been assigned and communicated at all levels?
    8. Is there evidence of top management driving OH&S performance, not just signing the policy?
    9. Are workers consulted on hazard identification, risk assessment and corrective actions?
    10. Are non-managerial workers consulted on policy, objectives, audit programme and management review?
    11. Is the worker consultation evidence specific (names, dates, decisions) rather than generic?
    12. Is there a documented mechanism for workers to raise OH&S concerns without reprisal?

    Evidence to collect: Policy, org chart with OH&S accountabilities, consultation minutes, worker interviews.

    Common nonconformities: Generic policy with no measurable commitments. Worker consultation evidence missing for risk-assessment work. No mechanism for non-managerial worker input to management review.


    Clause 6 — Planning (14 questions)

    1. Is there a documented hazard identification process covering routine, non-routine and emergency activities?
    2. Does it cover physical, chemical, biological, ergonomic and psychosocial hazards?
    3. Are human factors (fatigue, error, behaviour) addressed?
    4. Is there a current risk assessment for each significant activity?
    5. Are risk assessments reviewed after incidents, changes or at defined intervals?
    6. Is the hierarchy of controls applied (eliminate → substitute → engineering → admin → PPE)?
    7. Is there a legal register listing applicable OH&S legislation?
    8. Is the legal register updated when regulations change?
    9. Are OH&S objectives SMART, measurable and assigned to owners?
    10. Are OH&S objectives consistent with the policy and risk-assessment outputs?
    11. Are objectives reviewed for progress at least quarterly?
    12. Is there a planning process for changes (organizational, process, technology, regulatory)?
    13. Are temporary changes (one-off jobs, trials) included in change planning?
    14. Are emergency situations identified and emergency-response plans tested?

    Evidence to collect: Risk register, legal register, objectives tracker, change records, emergency drill reports.

    Common nonconformities: Risk assessments not reviewed after incidents. Legal register missing recent regulations (e.g. 2024 climate amendments). Objectives written but never tracked.


    Clause 7 — Support (10 questions)

    1. Are OH&S resources (people, time, budget) documented and provided?
    2. Is there a competence matrix linking roles to required training and qualifications?
    3. Are training records current and accessible?
    4. Are workers aware of the OH&S policy and the risks of their work?
    5. Are workers aware of the consequences of not following the OH&S management system?
    6. Is internal communication documented (toolbox talks, alerts, briefings)?
    7. Is external communication (regulators, neighbours, contractors) handled?
    8. Are documented OH&S procedures version-controlled and accessible at the point of use?
    9. Are records (training, audits, incidents) retained per defined retention rules?
    10. Is documented information protected from unauthorized changes and loss?

    Evidence to collect: Training matrix, training records, communication log, document control system, retention policy.

    Common nonconformities: Training matrix incomplete for contractors. Procedures available in head office but not on site. No documented retention rules.


    Clause 8 — Operation (14 questions)

    1. Are operational controls established for identified risks?
    2. Are work permits used for high-risk work (hot work, confined space, working at height, excavation)?
    3. Is the management-of-change process applied before changes go live?
    4. Are contractors selected on OH&S criteria, not just commercial?
    5. Are contractor OH&S performance and incidents monitored?
    6. Is there a procurement process that considers OH&S (PPE, plant, chemicals)?
    7. Are subcontractors integrated into the OH&S system (induction, RAMS, incident reporting)?
    8. Are workplace inspections conducted and findings closed within target dates?
    9. Is plant and equipment subject to scheduled inspection and maintenance?
    10. Are SDS (Safety Data Sheets) current and accessible for all hazardous substances?
    11. Is PPE issue tracked and replacement scheduled?
    12. Is emergency-response capability tested (drills, equipment, training) at least annually?
    13. Are first-aid resources sufficient and first-aiders trained and current?
    14. Is occupational health (audiometry, lung function, etc.) provided where risk requires?

    Evidence to collect: Permits issued, change records, contractor evaluations, inspection reports, drill reports, SDS register.

    Common nonconformities: Subcontractors not inducted. Permits issued but isolation not verified. Drills run but no learning captured. SDS register missing recent substances.


    Clause 9 — Performance evaluation (12 questions)

    1. Are OH&S KPIs defined (TRIR, LTIFR, near-miss rate, audit closure rate)?
    2. Are KPIs reported to top management at defined intervals?
    3. Are leading indicators (training completion, inspection rate, close-out time) tracked, not just lagging?
    4. Is compliance with the legal register evaluated at least annually?
    5. Is the result of the compliance evaluation documented?
    6. Is there an internal audit programme covering all clauses over a defined cycle?
    7. Are internal auditors competent and independent of the area being audited?
    8. Are audit findings documented, assigned and tracked to closure?
    9. Is the management review held at planned intervals (at least annually)?
    10. Does the management review cover all required inputs (audit results, incidents, KPIs, worker consultation, changes, etc.)?
    11. Are management review outputs documented as decisions and actions with owners?
    12. Are management review outputs implemented and followed up?

    Evidence to collect: KPI dashboard, compliance evaluation, audit programme, audit reports, management review minutes.

    Common nonconformities: Only lagging indicators tracked. Compliance evaluation undated. Management review missing worker consultation input. Outputs documented but not actioned.


    Clause 10 — Improvement (10 questions)

    1. Are all incidents (work-related, near-miss, ill-health) reported via a defined process?
    2. Are incidents investigated proportionate to potential severity?
    3. Is root-cause analysis applied (5-Why, Ishikawa, equivalent)?
    4. Are corrective actions defined and tracked to closure?
    5. Is the effectiveness of corrective actions verified?
    6. Are nonconformities raised by audits, observations and worker reports also routed through the same process?
    7. Is learning from incidents shared across sites and teams?
    8. Is there evidence of continual improvement (year-on-year KPI trend, fewer recurring incidents)?
    9. Is the OH&S management system itself reviewed for improvement opportunities?
    10. Are improvement opportunities captured outside formal audits (e.g. worker suggestions, supplier feedback)?

    Evidence to collect: Incident register, RCA records, CAPA tracker, lessons-learned bulletins, year-on-year KPI trends.

    Common nonconformities: RCA is "human error" with no underlying cause identified. CAPAs closed without effectiveness check. No mechanism for cross-site learning.


    Post-audit workflow

    1. Closing meeting. Within 24 hours of fieldwork. Walk top management through findings.
    2. Audit report. Within 5 working days. Include scope, methodology, findings by clause, scoring, evidence references.
    3. CAPA log. Every minor and major NC gets a corrective action with owner and target date. Major NCs need a containment action first, then a permanent fix.
    4. Effectiveness review. 30–60 days after CAPA closure, sample the area again and confirm the issue has not reappeared.
    5. Management review input. Roll all audit results into the next management review with year-on-year trends.

    Software that runs this audit for you

    A spreadsheet-based audit is fine the first year but becomes a bottleneck by the second cycle. Modern audit platforms ship ISO 45001 templates aligned to this clause structure, mobile evidence capture, automated CAPA workflows and one-click certification-body audit packs. See our top picks in Best Audit Management Software and the broader ISO 45001 Software guide.

    For SMEs running ISO 45001 alongside 9001 and 14001, the higher-leverage move is to consolidate all three on one platform — see ISO 45001 vs ISO 14001 vs ISO 9001: Building One Integrated QHSE Management System.

    Frequently asked questions

    How often should ISO 45001 internal audits run? At least annually, covering every clause within the cycle. High-risk sites should run quarterly themed audits (e.g. permits one quarter, contractors the next) plus the annual full-scope audit.

    Who can perform an ISO 45001 internal audit? Anyone competent and independent of the area audited. "Competent" typically means ISO 45001 lead-auditor trained (40-hour CQI/IRCA course) or equivalent industry experience.

    What is the difference between a minor and a major nonconformity? A major NC is a systemic failure of a clause (e.g. no risk assessments at all) or repeated minor NCs in the same area. A minor NC is a single instance of nonconformance. Certification bodies will not certify with open major NCs.

    Can the same checklist work for ISO 45001 and OHSAS 18001 transition? OHSAS 18001 was withdrawn in March 2021. If you are still operating on it, this checklist is your transition plan — every question maps to an ISO 45001 clause.

    How long do audit records need to be retained? Define a retention rule in your documented information (clause 7.5). Typical practice is 3 years for routine inspection records and 7 years for major-incident investigations and management reviews.

    Should contractors be audited under our ISO 45001 system? You audit your control of contractors (selection, induction, monitoring). You do not audit the contractor's own management system unless your contract requires it.

    What if our internal audit finds something the certification audit missed? That is the system working as intended. Document the NC, close it via CAPA, and have the evidence ready for the next surveillance audit.

    Does AI change how internal audits are run in 2026? Yes — leading platforms now suggest questions based on incident history, auto-tag evidence to clauses and pre-draft findings from interview transcripts. Treat AI as a productivity layer, not a substitute for auditor judgement.

    ISO 45001Internal AuditChecklistOH&S
    EP

    Elena Papadakis

    Editor-in-Chief, The QHSE Standard

    15+ years in occupational health & safety software analysis. Lead reviewer for incident management, audit and permit-to-work platforms.

    More from this authorLinkedInLast reviewed May 29, 2026

    Software covered in this category

    Browse all platforms →
    Not sure which fits? Get matched in 60s

    Looking for the Right QHSE Software?

    Take our 60-second quiz and get personalized recommendations.

    Get Matched — Free
    Back to all articles