What is the ISO 45001 readiness checklist?

ISO 45001 is an international standard that aims to help organisations establish the effectiveness of their Occupational Health and Safety management systems. Adopting the latest ISO 45001 version minimises occupational health and safety risks and reduces workplace accidents.
What is the ISO 45001 readiness checklist?

If you’re preparing for ISO 45001 certification, the process only works when you’re genuinely ready before your external auditor arrives. For any Australian business with responsibility for worker health and safety, ISO 45001 is one of the clearest ways to demonstrate that your occupational health and safety management system (OHSMS) is built on solid ground – not just on paper.

This guide covers the full ISO 45001 checklist, from gap analysis through to certification, including what to check at each clause, what documentation you need in place, and what auditors focus on.

What is an ISO 45001 checklist?

An ISO 45001 checklist is a structured tool that maps the requirements of the standard to a series of checkpoint questions. Internal teams use it to check whether their OHSMS is designed correctly and actually working, and businesses use it to verify readiness before their external auditor arrives.

ISO 45001:2018 is built around a risk-based approach to managing occupational health and safety. It goes deeper than a tick-box exercise. Instead, it’s checking whether your safety processes are genuinely working, properly documented, and driving real improvement over time.

Used well, it helps your organisation:

  • Identify ISO 45001 compliance gaps before an external auditor surfaces them.
  • Build a clear evidence base that your safety controls are doing what they’re supposed to.
  • Verify alignment with legal and other requirements.
  • Document corrective actions and track them to resolution.
  • Demonstrate continual improvement in your safety management system.

ISO 45001 prerequisites: what you need before you start

Before working through the ISO 45001 checklist, the foundational elements of your OHSMS should be in place. These aren’t a formal part of the audit itself, but without them your ISO 45001 audit will surface significant gaps quickly.

  • Top management commitment: leadership must demonstrate active commitment to safety. Auditors check for this early.
  • A defined OHSMS scope: determines which operations, sites, and activities are covered.
  • A completed context analysis: identifies internal and external issues affecting your ability to achieve OHS objectives.
  • Hazard identification completed: all significant safety risks must be identified, assessed, and documented.
  • Legal and other requirements documented: your organisation must determine its compliance obligations and keep them current.
  • Measurable OH&S objectives: set and connected to identified hazards, risks, and legal requirements.
  • Worker participation processes established: ISO 45001 requires formal processes for worker consultation and participation in safety decisions. This must be in place before certification.
  • Training and awareness program: personnel must be trained and aware of their safety responsibilities.
  • A documented internal audit plan: audits must be planned and conducted at regular intervals, not carried out on an ad hoc basis.

If any of these aren’t in place, an ISO 45001 gap analysis is the most efficient starting point. It gives you an honest picture of where your organisation stands – including the cost of ISO 45001 certification – before committing to the full certification process.

Gap analysis vs ISO 45001 audit checklist: what you need and when

These two tools serve different purposes at different stages of your ISO 45001 journey.

A gap analysis is conducted before your OHSMS is fully built. It compares your current system against the requirements of the standard, identifying where existing processes need revision. It’s your roadmap for ISO 45001 implementation – the first step in a structured approach to ISO 45001 certification.

An ISO 45001 audit checklist is used once your OHSMS is operational. It checks whether the system is working as required, generates the objective evidence your external auditor will review, and supports the Plan-Do-Check-Act (PDCA) cycle that underpins ISO 45001 continual improvement. Conducting regular internal audits is a requirement of the standard, not optional.

The ISO 45001 audit checklist below aligns with the PDCA methodology and covers the seven key clauses that form the core of every ISO 45001 certification audit.

ISO 45001 audit checklist: clause by clause

Clause 4: Context of the organisation

Before you can manage safety risks effectively, you need a clear picture of your operating environment. Check:

  • Have you identified internal and external issues relevant to your OHSMS?
  • Have interested parties been identified, along with their requirements and expectations?
  • Is the OHSMS scope clearly defined and documented?
  • Does the scope account for non-routine activities, contractor work, and activities that could affect worker health and safety beyond the immediate workplace?

Clause 5: Leadership

Top management must demonstrate genuine leadership and commitment to safety – not just sign a policy. Roles and responsibilities for safety must be documented and owned. This is one of the first areas an auditor checks. Verify:

  • Has top management established a documented OHS policy committing to a safe and healthy workplace, eliminating hazards, and continual improvement?
  • Is the OHS policy communicated to all workers and available to interested parties?
  • Are roles, responsibilities, and authorities for safety management clearly assigned and documented?
  • Is leadership actively driving worker participation in health and safety decisions, rather than delegating it entirely?
  • Does top management participate in the management review process?

Clause 6: Planning

This is where hazard identification, risk assessment, and legal compliance requirements are established. Planning is among the most closely scrutinised areas in any ISO 45001 audit. Check:

  • Have safety risks and opportunities been systematically identified and assessed?
  • Is there a documented process for hazard identification, including non-routine activities?
  • Have legal and other requirements been identified, documented, and kept current? In Australia, this includes the Work Health and Safety Act at federal level and equivalent WHS legislation across relevant states and territories.
  • Have measurable OHS objectives been set, with plans that define who is responsible, what resources are required, and how progress will be measured?
  • Are processes in place to implement corrective actions and achieve risk reduction when hazards are identified?

Clause 7: Support

Necessary resources must be allocated for your safety management system to function effectively. Verify:

  • Are the necessary resources identified and provided for the OHSMS?
  • Do workers have the competence required for their safety responsibilities, and is evidence of competence retained?
  • Are training programs in place to build safety awareness, particularly for workers in higher-risk roles?
  • Have clear communication processes been established for internal and external communication on safety matters?
  • Is documented information maintained, controlled, and accessible?

Clause 8: Operation

This is where planning becomes action. Operational controls must be implemented for identified hazards and risks. Check:

  • Are operational controls in place to eliminate hazards and reduce safety risks to acceptable levels?
  • Is there a documented hierarchy of controls, from elimination through to PPE?
  • Are emergency preparedness and response procedures in place, tested, and communicated to all relevant workers?
  • Are supplier and contractor relationships managed with appropriate safety requirements built in?
  • Are processes in place to manage change before they’re introduced?

Clause 9: Performance evaluation

ISO 45001 requires that performance evaluation includes monitoring, measuring, analysing, and conducting internal audits. Check:

  • Are monitoring and measurement processes in place for significant safety risks, legal compliance, and progress toward OHS objectives?
  • Are regular evaluations of compliance with legal requirements conducted and documented?
  • Is there a documented internal audit program covering all OHSMS processes at planned intervals?
  • Are audit results recorded, including non-conformances and corrective actions, and reported to management?
  • Does the management review evaluate OHSMS effectiveness against safety performance data, with decisions and actions documented?

Clause 10: Improvement

Continual improvement is both a requirement of the standard and the foundation of a genuine safety culture. Check:

  • Are incidents, non-conformances, and near misses investigated for root cause?
  • Are corrective actions implemented promptly, tracked to resolution, and verified as effective?
  • Is there evidence of continual improvement in safety performance, not just the absence of incidents?
  • Are improvement outcomes feeding back into the planning cycle to continually improve the OHSMS?

ISO 45001 checklist: documentation you need in place

Before your certification audit, the following documented information must be in place and accessible. Your auditor will expect to review these as evidence that your OHSMS is operating as required.

Clause Required documented information
4.3 OHSMS scope statement
5.2 OHS policy
6.1.2 Hazard identification and risk assessment results
6.1.3 Legal and other requirements register
6.2 OH&S objectives and plans to achieve them
7.2 Evidence of worker competence for relevant roles
8.1 Operational control procedures
9.1 Monitoring, measurement, and evaluation results
9.2 Internal audit program, audit plans, and audit reports
9.3 Management review records
10.2 Non-conformances, corrective actions, and evidence of effectiveness

How to conduct an ISO 45001 internal audit

Running regular internal audits is a requirement under ISO 45001. Here’s how to do it properly.

  1. Plan the audit program: define scope, frequency, and methods. Areas with higher safety risks or previous non-conformities should be audited more frequently.
  2. Assign trained, independent auditors: auditors must not audit their own work. Use internal staff from other areas or engage an external auditor.
  3. Conduct the audit: use the ISO 45001 checklist above to assess conformity, gather objective evidence, and identify gaps.
  4. Document findings: categorise results as conformities, observations, or non-conformities. Be specific; vague findings are hard to act on.
  5. Implement corrective actions: for every non-conformity, identify the root cause and define what is needed to resolve it. Implement corrective actions promptly.
  6. Report to management: audit results are a mandatory input to your management review. Act on findings promptly.
  7. Track to resolution: follow up on corrective actions and verify they have been effective before closing them out.

What your auditor will look for

When your external auditor assesses your OHSMS, they’re looking for objective evidence – not just that procedures exist, but that they’re working. Here’s what they focus on:

Focus area What auditors check Common issues
Hazard identification Systematic, current, and covering non-routine activities. Outdated assessments, gaps for contractors or visitors.
Legal compliance Obligations identified, current, and being met. Missing state/territory WHS legislation.
Leadership commitment Genuine management engagement, not nominal sign-off. No documented leadership activity beyond policy sign-off.
Worker participation Formal consultation processes in place and active. No structured consultation mechanisms.
Internal audits Independent, planned, and findings acted on. Ad hoc audits, corrective actions not closed out.
Management review Performance data reviewed, decisions documented. Superficial reviews, no actions recorded.
Continual improvement Systematic and evidenced, not aspirational. Corrective actions not closed; no proactive improvement.

Ready for your audit? Get certified with Citation

Citation Group is an accredited ISO 45001 certification body helping Australian businesses achieve and maintain ISO 45001 certification. From your initial gap analysis through to your certificate and annual surveillance audits, our team supports you at every stage.

Do you want to establish a robust OHSMS? Contact us to discover more about our ISO 45001 certification services.

 

FAQs

What is the ISO 45001 readiness checklist?

The ISO 45001 readiness checklist is a structured tool that helps organisations assess whether their occupational health and safety management system (OHSMS) meets the requirements of ISO 45001:2018. It covers seven key clauses aligned to the Plan-Do-Check-Act cycle: context, leadership, planning, support, operation, performance evaluation, and improvement. It’s used to identify gaps before certification, run internal audits, and verify readiness before an external auditor arrives.

What does an ISO 45001 audit checklist cover?

An ISO 45001 audit checklist covers the seven key requirement clauses of the standard: context of the organisation, leadership, planning (including hazard identification and legal compliance), support (resources, training, and communication), operational controls, performance evaluation, and improvement. It aligns with the Plan-Do-Check-Act methodology and generates objective evidence that your OHSMS is working as designed and genuinely improving safety performance over time.

How often do you need to conduct internal audits under ISO 45001?

ISO 45001 requires organisations to conduct internal audits at planned intervals but does not specify a fixed frequency. Most organisations conduct regular internal audits at least annually. Higher-risk processes or areas with previous non-conformities should be audited more frequently. Your audit program must be documented, and all OHSMS processes must be covered across the certification cycle.

What is the ISO 45001 implementation process?

The ISO 45001 implementation process typically spans several phases over a year. It begins with a gap analysis to identify compliance needs, followed by developing an implementation plan using the PDCA cycle. From there, organisations document OHS policies and procedures, complete hazard identification, establish legal compliance processes, build worker participation mechanisms, conduct internal audits to assess OHSMS effectiveness, and engage an accredited certification body for the external audit. Citation Group supports businesses through every phase of this process.

Does ISO 45001 certification need to be renewed?

Yes. ISO 45001 certification operates on a three-year cycle. Once certified, your organisation must participate in annual surveillance audits to demonstrate that your OHSMS remains effective and compliant. A full recertification audit is required at the end of the three-year period. Ongoing compliance requires regular internal audits, current hazard identification and risk assessments, and documented evidence of continual improvement.

What are the business benefits of ISO 45001 certification?

ISO 45001 certification delivers both safety and commercial benefits. It reduces workplace incidents and improves safety outcomes for workers, leading to significant cost savings from fewer incidents, lower workers’ compensation claims, and reduced insurance premiums. Certification enhances your organisation’s reputation with clients, suppliers, and regulators, and provides globally recognised evidence of your commitment to worker health and safety. It also promotes a culture of continuous improvement that strengthens the business well beyond compliance.

Is worker participation required under ISO 45001?

Yes. Worker participation is a central and specific requirement of ISO 45001, not an optional extra. The standard requires organisations to establish documented processes for worker consultation and participation in health and safety decisions. This includes hazard identification, risk assessment, and the development of safety policies and procedures. This is a key difference between ISO 45001 and its predecessor OHSAS 18001, and it’s an area auditors assess closely.

Hard hat icon

How Citation Certification can help

Do you want to establish a robust Occupational Health and Safety management system? Citation Certification can help you identify your organisation’s OHS risks and adopt the best standards. Contact us to discover more about our ISO 45001 training and certification services.

Take your business to the next level

This field is for validation purposes and should be left unchanged.
What are you interested in?
HR
Your data will be processed inline with our Privacy Policy.