ISO 45001 Compliance Checklist — 7 Powerful Steps to Pass Your Occupational Health and Safety Audit

The ISO 45001 compliance checklist is the starting point every organisation needs — whether you are preparing for your first certification audit, your annual surveillance audit, or the ISO 45001:2027 transition that is coming.
ISO 45001:2018 is the international standard for Occupational Health and Safety Management Systems. It applies to any organisation that wants to systematically identify, control, and reduce workplace health and safety risks — and demonstrate that capability to clients, regulators, and workers.
With over 45,000 people dying from work-related accidents and diseases every day globally according to the International Labour Organization, occupational health and safety is not a compliance exercise. It is a moral obligation. ISO 45001 provides the management system framework that makes it systematic.
This ISO 45001 compliance checklist covers the 7 steps that determine whether your OH&S management system will pass a certification or surveillance audit — and what auditors actually check when they arrive on site.

WHY ISO 45001 COMPLIANCE CHECKLIST MATTERS FOR YOUR NEXT AUDIT

Most organisations that fail ISO 45001 audits do not fail because of a fundamental safety problem. They fail because their management system documentation, evidence, and operational processes are out of alignment.
An auditor is not just checking whether your workplace is safe. They are checking whether you have a functioning, documented, monitored, and continually improving OH&S management system. Those are two different things — and organisations that confuse them consistently get surprised at audit.
Note that ISO 45001:2027 is in active revision — mental health, remote work, and climate-related OH&S risks are all expected in the updated standard. The compliance foundation in this ISO 45001 compliance checklist remains the basis for 45001:2027 as well.

ISO 45001 COMPLIANCE CHECKLIST — 7 POWERFUL STEPS

Step 1 — Hazard Identification and Risk Assessment (Clause 6.1.2)
The hazard identification and risk assessment process is the operational core of ISO 45001 — and the starting point for every audit conversation.
Your ISO 45001 compliance checklist for this clause must confirm:
→ All workplace hazards are identified — physical, chemical, biological, ergonomic, and psychosocial
→ Hazard identification covers all activities: routine, non-routine, maintenance, emergency, and contractor activities
→ Risk assessment evaluates likelihood and severity for each identified hazard
→ Controls are selected following the hierarchy of controls: Eliminate → Substitute → Engineer → Administer → PPE
→ Residual risk is formally accepted by an appropriate authority
→ Risk assessment is reviewed when changes occur — not just annually
What auditors specifically check: They will ask workers directly — “what hazards exist in your work area?” If workers cannot name hazards, the hazard identification process is not reaching operational level. That is a finding.
For GCC organisations, heat stress must be formally included in the hazard register — particularly for outdoor work between June and September. Auditors are increasingly checking this specifically.

Step 2 — Legal Compliance Register and Compliance Evaluation (Clauses 6.1.3 and 9.1.2)
ISO 45001 requires organisations to identify, access, and evaluate compliance with applicable OH&S legislation. This is one of the most common sources of nonconformities in ISO 45001 audits.
Your legal compliance register must:
→ List all applicable national, emirate-level, and sector-specific OH&S legislation
→ Document how the organisation complies with each specific requirement
→ Be reviewed and updated when legislation changes
→ Include compliance evaluation records — not just the list of laws
The compliance evaluation trap: Many organisations maintain a legal register but never formally evaluate whether they are actually compliant with each requirement. ISO 45001 Clause 9.1.2 requires documented compliance evaluation — not just registration of the law. Auditors will ask: “When did you last evaluate compliance with [specific regulation] and what did you find?”

Step 3 — Worker Participation and Consultation (Clause 5.4)
Worker participation is one of the most distinctive requirements in ISO 45001 — and one of the most commonly implemented superficially.
ISO 45001 Clause 5.4 requires organisations to actively consult workers on OH&S matters — not just inform them. The difference is significant:
→ Consultation means workers have input into decisions before they are made — hazard identification, risk assessment, incident investigation, return to work, development of OH&S policies
→ Information means telling workers what has been decided — which is what most organisations actually do
Your ISO 45001 compliance checklist for worker participation must confirm:
→ A documented process for worker consultation and participation
→ Workers involved in hazard identification and risk assessment — with records
→ Workers consulted on proposed changes that could affect OH&S
→ Non-management workers represented in OH&S decision-making (safety committee or equivalent)
→ Workers can raise OH&S concerns without fear of retaliation
→ Contractor and visitor participation considered

Step 4 — Operational Controls and Work Permits (Clause 8.1)
Operational controls are the practical implementation of your risk assessment — the specific measures that prevent hazards from causing harm. ISO 45001 Clause 8.1 requires controls to be planned, implemented, and maintained.
Your ISO 45001 compliance checklist for operational controls must cover:
→ Written Safe Work Procedures (SWPs) or Safe Operating Procedures (SOPs) for high-risk tasks
→ Permit-to-Work system for hazardous activities: hot work, confined space entry, working at height, electrical isolation, excavation
→ Contractor management — how contractor OH&S is assessed, managed, and monitored on site
→ Management of change — OH&S impact assessed before operational changes are implemented
→ Emergency response procedures documented, communicated, and tested at planned intervals
The permit-to-work audit check: Auditors will request permit records from the past 30–60 days. Missing permits, incomplete permits, or permits signed off after work commenced are common findings. Review your permit records before any audit.

Step 5 — OH&S Objectives and Performance Monitoring (Clauses 6.2 and 9.1)
ISO 45001 requires OH&S objectives to be established at relevant functions and levels — and monitored with documented performance data.
Your ISO 45001 compliance checklist for objectives and monitoring must confirm:
→ OH&S objectives are documented, measurable, and tracked
→ Objectives are linked to significant hazards and legal compliance obligations
→ Plans to achieve objectives are in place — with responsible owners and target dates
→ OH&S performance indicators are monitored: incident rates, near-miss rates, unsafe condition reports, training completion, permit compliance
→ Leading indicators are tracked — not just lagging indicators (incidents that have already happened)
The lagging indicator trap: Many organisations only track incidents and injuries. ISO 45001 expects a balanced performance monitoring approach — leading indicators (hazard reports, training completed, inspections conducted) that predict future performance alongside lagging indicators.

Step 6 — Incident Investigation and Corrective Action (Clauses 9.1.1 and 10.2)
Every incident, near-miss, and unsafe condition report in your system is an opportunity — and an audit evidence trail. ISO 45001 requires incidents to be investigated, root causes to be identified, and corrective actions to be implemented and verified.
Your ISO 45001 compliance checklist for incident management must confirm:
→ All incidents and near-misses reported, recorded, and investigated — not just lost-time injuries
→ Root cause analysis conducted for significant incidents — not just immediate cause identification
→ Corrective actions assigned, tracked, and closed with verified effectiveness Corrective action records must show the action was implemented AND that it was effective — not just closed on the target date.
→ Near-miss reporting is actively encouraged — near-miss rates are a leading indicator of future incidents
→ Regulatory reporting obligations met for notifiable incidents (MOHRE in UAE, Saudi OSHA, etc.)
What auditors check in incident records: They look at closed corrective actions and ask: “How did you verify this was effective?” If the answer is “we just ticked the box,” that is a finding.

Step 7 — Internal Audit and Management Review (Clauses 9.2 and 9.3)
The internal audit and management review processes are how ISO 45001 ensures the management system is working as intended. They are also where organisations most commonly present weak evidence at certification audits.
Internal audit ISO 45001 compliance checklist:
→ Internal audit programme covers all clauses and all significant hazard areas
→ Auditors are competent in OH&S and independent of the areas they audit
→ Audit findings are formally recorded and processed through the CAPA system
→ Previous audit CAPA actions are closed before the next cycle
Read our internal audit guide to understand the most common reasons internal audits fail to find what external auditors find — and how to close that gap.
Management review ISO 45001 compliance checklist:
→ Management review conducted at planned intervals — typically annually or more frequently
→ All required inputs reviewed: context changes, OH&S objectives progress, incident rates, audit findings, compliance evaluation, worker participation feedback
→ Outputs documented: decisions on improvements, resources, changes to the OH&S management system
→ Top management attendance evidenced — not delegated entirely to the safety team
The management review authenticity test: Auditors will read management review minutes and ask top management directly about OH&S performance. If senior management cannot discuss OH&S KPIs fluently, that signals the management review is a paperwork exercise.

WHAT AUDITORS CHECK FIRST — THE ISO 45001 COMPLIANCE CHECKLIST PRIORITIES
Based on common certification and surveillance audit findings, these are the highest-risk areas in any ISO 45001 audit:
→ Hazard register completeness — all significant hazards identified, including psychosocial and GCC-specific risks
→ Worker participation records — documented evidence of consultation — not just information sharing
→ Permit-to-Work records — complete, correctly authorised, and demonstrating compliance
→ Legal compliance evaluation — formal documented evaluation, not just a list of laws
→ Near-miss reporting culture — low near-miss rates often indicate under-reporting, not good safety
→ CAPA effectiveness verification — closed actions with evidence of verification
→ Top management engagement — genuine, evidenced engagement beyond a signed OH&S policy
For organisations running an Integrated Management System alongside ISO 9001 and ISO 14001, our QHSE integration guide shows how a single audit programme can cover all three standards simultaneously — reducing audit burden significantly.

THE BOTTOM LINE
The ISO 45001 compliance checklist above is not a documentation exercise. It is a map of the management system behaviours that prevent injuries, protect workers, and demonstrate to clients and regulators that your organisation takes occupational health and safety seriously.
The organisations that pass ISO 45001 audits consistently are not those with the most impressive documentation — they are those where the management system is genuinely operational at every level of the organisation. Workers report near-misses. Permits are completed correctly. Corrective actions are verified. Management reviews are substantive.
Build the system. Train your people. Monitor performance. The audit follows from the system — not the other way around.
👉 Download your free ISO 45001 Compliance Checklist — 50 gap assessment items mapped to all 7 steps. Use it to prepare for your next certification or surveillance audit.
👉 Visit the Standards Unlimited shop for ISO 45001 compliance tools including risk assessment templates, legal compliance registers, and internal audit checklists built for GCC organisations.

#ISO45001 #ISO45001ComplianceChecklist #OccupationalHealth #WorkplaceSafety #HSE #ISO45001Audit #OHSManagement #SafetyCompliance #ISO45001Certification #WorkplaceSafetyGCC #HSECompliance #OccupationalSafety

Leave a Comment