Fast ISO certification isn’t a win – it’s a warning sign
Certification was never designed to reward speed. It exists to provide independent assurance that a...
If you’re preparing for ISO 45001 certification, the process only works when you’re genuinely ready before your external auditor arrives. For any Australian business with responsibility for worker health and safety, ISO 45001 is one of the clearest ways to demonstrate that your occupational health and safety management system (OHSMS) is built on solid ground – not just on paper.
This guide covers the full ISO 45001 checklist, from gap analysis through to certification, including what to check at each clause, what documentation you need in place, and what auditors focus on.
An ISO 45001 checklist is a structured tool that maps the requirements of the standard to a series of checkpoint questions. Internal teams use it to check whether their OHSMS is designed correctly and actually working, and businesses use it to verify readiness before their external auditor arrives.
ISO 45001:2018 is built around a risk-based approach to managing occupational health and safety. It goes deeper than a tick-box exercise. Instead, it’s checking whether your safety processes are genuinely working, properly documented, and driving real improvement over time.
Used well, it helps your organisation:
Before working through the ISO 45001 checklist, the foundational elements of your OHSMS should be in place. These aren’t a formal part of the audit itself, but without them your ISO 45001 audit will surface significant gaps quickly.
If any of these aren’t in place, an ISO 45001 gap analysis is the most efficient starting point. It gives you an honest picture of where your organisation stands – including the cost of ISO 45001 certification – before committing to the full certification process.
These two tools serve different purposes at different stages of your ISO 45001 journey.
A gap analysis is conducted before your OHSMS is fully built. It compares your current system against the requirements of the standard, identifying where existing processes need revision. It’s your roadmap for ISO 45001 implementation – the first step in a structured approach to ISO 45001 certification.
An ISO 45001 audit checklist is used once your OHSMS is operational. It checks whether the system is working as required, generates the objective evidence your external auditor will review, and supports the Plan-Do-Check-Act (PDCA) cycle that underpins ISO 45001 continual improvement. Conducting regular internal audits is a requirement of the standard, not optional.
The ISO 45001 audit checklist below aligns with the PDCA methodology and covers the seven key clauses that form the core of every ISO 45001 certification audit.
Before you can manage safety risks effectively, you need a clear picture of your operating environment. Check:
Top management must demonstrate genuine leadership and commitment to safety – not just sign a policy. Roles and responsibilities for safety must be documented and owned. This is one of the first areas an auditor checks. Verify:
This is where hazard identification, risk assessment, and legal compliance requirements are established. Planning is among the most closely scrutinised areas in any ISO 45001 audit. Check:
Necessary resources must be allocated for your safety management system to function effectively. Verify:
This is where planning becomes action. Operational controls must be implemented for identified hazards and risks. Check:
ISO 45001 requires that performance evaluation includes monitoring, measuring, analysing, and conducting internal audits. Check:
Continual improvement is both a requirement of the standard and the foundation of a genuine safety culture. Check:
Before your certification audit, the following documented information must be in place and accessible. Your auditor will expect to review these as evidence that your OHSMS is operating as required.
| Clause | Required documented information |
|---|---|
| 4.3 | OHSMS scope statement |
| 5.2 | OHS policy |
| 6.1.2 | Hazard identification and risk assessment results |
| 6.1.3 | Legal and other requirements register |
| 6.2 | OH&S objectives and plans to achieve them |
| 7.2 | Evidence of worker competence for relevant roles |
| 8.1 | Operational control procedures |
| 9.1 | Monitoring, measurement, and evaluation results |
| 9.2 | Internal audit program, audit plans, and audit reports |
| 9.3 | Management review records |
| 10.2 | Non-conformances, corrective actions, and evidence of effectiveness |
Running regular internal audits is a requirement under ISO 45001. Here’s how to do it properly.
When your external auditor assesses your OHSMS, they’re looking for objective evidence – not just that procedures exist, but that they’re working. Here’s what they focus on:
| Focus area | What auditors check | Common issues |
|---|---|---|
| Hazard identification | Systematic, current, and covering non-routine activities. | Outdated assessments, gaps for contractors or visitors. |
| Legal compliance | Obligations identified, current, and being met. | Missing state/territory WHS legislation. |
| Leadership commitment | Genuine management engagement, not nominal sign-off. | No documented leadership activity beyond policy sign-off. |
| Worker participation | Formal consultation processes in place and active. | No structured consultation mechanisms. |
| Internal audits | Independent, planned, and findings acted on. | Ad hoc audits, corrective actions not closed out. |
| Management review | Performance data reviewed, decisions documented. | Superficial reviews, no actions recorded. |
| Continual improvement | Systematic and evidenced, not aspirational. | Corrective actions not closed; no proactive improvement. |
Citation Group is an accredited ISO 45001 certification body helping Australian businesses achieve and maintain ISO 45001 certification. From your initial gap analysis through to your certificate and annual surveillance audits, our team supports you at every stage.
Do you want to establish a robust OHSMS? Contact us to discover more about our ISO 45001 certification services.
The ISO 45001 readiness checklist is a structured tool that helps organisations assess whether their occupational health and safety management system (OHSMS) meets the requirements of ISO 45001:2018. It covers seven key clauses aligned to the Plan-Do-Check-Act cycle: context, leadership, planning, support, operation, performance evaluation, and improvement. It’s used to identify gaps before certification, run internal audits, and verify readiness before an external auditor arrives.
An ISO 45001 audit checklist covers the seven key requirement clauses of the standard: context of the organisation, leadership, planning (including hazard identification and legal compliance), support (resources, training, and communication), operational controls, performance evaluation, and improvement. It aligns with the Plan-Do-Check-Act methodology and generates objective evidence that your OHSMS is working as designed and genuinely improving safety performance over time.
ISO 45001 requires organisations to conduct internal audits at planned intervals but does not specify a fixed frequency. Most organisations conduct regular internal audits at least annually. Higher-risk processes or areas with previous non-conformities should be audited more frequently. Your audit program must be documented, and all OHSMS processes must be covered across the certification cycle.
The ISO 45001 implementation process typically spans several phases over a year. It begins with a gap analysis to identify compliance needs, followed by developing an implementation plan using the PDCA cycle. From there, organisations document OHS policies and procedures, complete hazard identification, establish legal compliance processes, build worker participation mechanisms, conduct internal audits to assess OHSMS effectiveness, and engage an accredited certification body for the external audit. Citation Group supports businesses through every phase of this process.
Yes. ISO 45001 certification operates on a three-year cycle. Once certified, your organisation must participate in annual surveillance audits to demonstrate that your OHSMS remains effective and compliant. A full recertification audit is required at the end of the three-year period. Ongoing compliance requires regular internal audits, current hazard identification and risk assessments, and documented evidence of continual improvement.
ISO 45001 certification delivers both safety and commercial benefits. It reduces workplace incidents and improves safety outcomes for workers, leading to significant cost savings from fewer incidents, lower workers’ compensation claims, and reduced insurance premiums. Certification enhances your organisation’s reputation with clients, suppliers, and regulators, and provides globally recognised evidence of your commitment to worker health and safety. It also promotes a culture of continuous improvement that strengthens the business well beyond compliance.
Yes. Worker participation is a central and specific requirement of ISO 45001, not an optional extra. The standard requires organisations to establish documented processes for worker consultation and participation in health and safety decisions. This includes hazard identification, risk assessment, and the development of safety policies and procedures. This is a key difference between ISO 45001 and its predecessor OHSAS 18001, and it’s an area auditors assess closely.