What would happen if an auditor walked into your factory tomorrow and asked a production worker, “What do you do if you find a serious safety hazard?”
Would the worker know the answer?
Now imagine the auditor walks to a machine and asks the supervisor, “How do you know this machine is safe to operate?”
Could the supervisor show practical evidence, or would someone immediately start searching through folders?
These questions explain why I see an ISO 45001 audit as much more than a document-checking exercise.
A company can have a beautifully written occupational health and safety manual and still have weak controls on the factory floor. On the other hand, a company with simple documents can have a strong safety culture because managers and workers actually understand and use the system.
When I prepare organizations for an audit, I focus on one basic connection:
What does the company say it does, what does it actually do, and what evidence shows that it works?
That connection is the heart of a successful audit.
In this practical guide, I will walk through what I look for during an ISO 45001 audit, how companies should prepare, which findings appear most often, how to choose an audit partner, and how to turn the audit into something useful rather than stressful.
Let me start with a common misunderstanding.
An ISO 45001 audit is not simply an inspection of whether a company has enough safety documents.
The purpose is to determine whether the organization's occupational health and safety management system meets the applicable requirements and is being implemented effectively.
In plain language, I want to understand whether the company has a reliable way to prevent work-related injury and ill health.
That means I look at both the management system and the real workplace.
During an audit, I naturally move between three questions:
What risks does this company have?
What has the company done to control those risks?
How does the company know those controls are working?
Take a factory using industrial presses.
The company may identify crushing injuries as a significant hazard.
It may establish machine guarding, operating procedures, emergency stops, maintenance requirements, and employee training.
That sounds good.
But I still need to see what happens in real life.
Is the guard actually installed?
Can an operator easily bypass it?
Does the emergency stop work?
Are maintenance workers protected from unexpected machine movement?
Does the training reflect the machine employees actually use?
If an employee removes a guard because it makes production slower, does the supervisor know?
That is where an audit becomes practical.
Although the exact audit program varies according to the organization, I normally think about the process in several stages:
Audit stage
What I focus on
Typical evidence
Planning | Scope, locations, processes, risks | Organization information, audit plan |
Leadership review | Responsibility and direction | Policies, objectives, management decisions |
Risk review | Hazards and controls | Risk assessments, workplace observations |
Operational review | Actual implementation | Procedures, inspections, machine controls |
Worker involvement | Participation and communication | Meetings, reports, interviews |
Performance review | Whether controls work | KPIs, inspections, incidents, audits |
Corrective action | Response to problems | Root-cause analysis, action records |
Closing assessment | Overall conformity | Audit findings and conclusions |
Source basis: ISO 45001:2018 management-system requirements and ISO/IEC 17021-1 conformity-assessment principles.
The important point is that these areas are connected.
If the risk assessment identifies a serious hazard but the workplace has no effective control, there is a gap.
If a procedure requires monthly inspections but nobody performs them, there is a gap.
If workers report hazards but management never follows up, there is a gap.
The audit is about finding those connections.
One of the worst preparation methods is to begin by printing documents.
I prefer to begin with a walk.
Walk through production.
Walk through the warehouse.
Visit maintenance areas.
Look at chemical storage.
Watch material movement.
Talk to operators.
Check emergency exits.
Observe contractors.
Ask supervisors what problems they deal with every week.
This approach often tells me more in one hour than a large document folder does.
Before anything else, make sure the organization understands what is included in the management system.
For example, a manufacturing company may have:
Production buildings
Warehouses
Offices
Laboratories
Maintenance workshops
Loading areas
Company vehicles
Temporary work areas
Contractors working on site
The scope should reflect the organization's real activities.
If an important activity is quietly ignored because it is difficult to manage, the company is creating a weakness before the audit even begins.
I recommend reviewing hazards by activity rather than creating a generic list.
For a textile factory, I might expect risks related to:
Moving machinery
Needles and sharp tools
Noise
Dust
Electrical equipment
Fire
Manual handling
Ergonomics
Chemicals
Forklifts
For a metal factory, the list may look very different.
There may be welding fumes, hot surfaces, cutting equipment, heavy loads, cranes, compressed gases, grinding operations, and high-energy machinery.
The risk assessment should tell the story of the actual workplace.
This is where I often find the biggest gap.
A company may identify a serious risk correctly but use a weak control.
For example:
Hazard: Employees may be struck by moving forklifts.
Weak response: Put up a warning sign.
Stronger response: Separate pedestrian and forklift routes, improve visibility, establish speed controls, train operators, maintain vehicles, and monitor traffic behavior.
A warning sign may help.
But a physical separation between people and vehicles is usually a much stronger form of control.
I never recommend preparing only managers for an audit.
Auditors may interview employees.
More importantly, employees are the people who live with the risks every day.
A worker should be able to explain basic safety expectations in normal language.
They do not need to memorize the standard.
If I ask an operator, “What would you do if this machine became unsafe?” I am not looking for a perfect sentence.
I want to know whether the person understands how to stop, report, isolate, or escalate the problem according to the company's process.
ISO 45001 covers a management system, so an audit looks at several connected areas.
I find it useful to divide them into eight practical questions.
A policy alone is not enough.
Leadership should demonstrate that occupational health and safety is part of business decision-making.
I may look at:
Safety objectives
Resources
Management review
Responsibilities
Safety performance
Decisions following serious incidents
Evidence of leadership involvement
If production targets are always prioritized while known safety problems remain unresolved, the organization has a management issue, not simply a worker issue.
The organization should understand the hazards connected with its activities.
This includes routine and non-routine work.
For example, production may be safe during normal operation, but maintenance could create much greater risks.
Shutdown periods can also introduce unusual hazards.
Cleaning, equipment installation, construction, contractor work, and emergency situations deserve attention.
A company needs to understand the occupational health and safety requirements that apply to its activities and locations.
The important point is not simply having a large legal register.
Someone should know what the requirements mean and how the company checks compliance.
A spreadsheet containing hundreds of legal entries is not useful if nobody knows which requirements affect the factory.
Worker participation is an important part of a practical safety system.
Workers often know about problems before managers do.
They may know that:
A machine guard is difficult to use
A walkway becomes slippery during rain
A chemical container is awkward to move
A forklift route is too crowded
A safety procedure does not match the actual process
If employees have no safe and practical way to report these problems, management loses valuable information.
This is where paperwork meets reality.
I may compare the written procedure with actual work.
For example, if the procedure says workers must inspect lifting equipment before use, I want to understand:
Who performs the inspection?
What do they check?
How often?
What happens when a defect is found?
Who decides whether equipment can return to service?
A control should have a clear owner and a clear response.
An emergency plan should not live inside a document cabinet.
Consider a fire drill.
Can employees find the correct exit?
Do they know where to assemble?
Are visitors and contractors included?
Can people with special needs evacuate safely?
Who contacts emergency services?
Who accounts for employees?
After the drill, does anyone review what went wrong?
An emergency exercise should be a learning opportunity, not a performance staged for an auditor.
When something goes wrong, I want to see more than a statement saying:
“Employee did not follow the procedure.”
That may be part of the story, but it is rarely the whole story.
A better investigation asks:
Was the procedure clear?
Was the worker trained?
Was supervision adequate?
Was the equipment suitable?
Was production pressure involved?
Had similar near misses occurred?
Were previous corrective actions effective?
This helps the company fix the system instead of simply blaming one person.
An effective system should become better over time.
Internal audits, inspections, incidents, worker feedback, performance data, and management reviews should lead to decisions.
If the same problem appears year after year, the organization is not learning effectively.
Let me share several situations that I regularly consider important.
A company may have one large risk assessment covering an entire production department.
The problem is that "production" is not one activity.
Different machines, tasks, materials, and workers may face very different hazards.
Better approach: Break significant activities into manageable tasks and assess the hazards where they actually occur.
A training attendance sheet proves that someone attended a session.
It does not necessarily prove that the person can perform the task safely.
For high-risk work, the company should consider whether competence needs to be demonstrated.
For example, a forklift operator may need practical evaluation rather than only classroom attendance.
Some companies complete the drill and immediately mark it as "done."
I prefer to ask:
What happened?
Did everyone hear the alarm?
Did people use the correct exits?
Was the assembly point crowded?
Did visitors know what to do?
Were emergency contacts available?
The value is in the learning.
Suppose workers repeatedly trip over materials left in a walkway.
The company cleans the area.
A week later, the same problem happens.
The cleaning action did not solve the reason materials were being left there.
Maybe the storage area is too small.
Maybe production planning creates temporary overflow.
Maybe material routes are poorly designed.
The corrective action should address the underlying cause.
A contractor may enter a factory with different training, tools, and working methods.
If contractors perform hot work, electrical work, maintenance, construction, or work at height, the organization needs a clear process for controlling the associated risks.
Simply asking a contractor to sign a safety declaration is rarely enough.
This is harder to see in documents.
If employees believe reporting a hazard will lead to punishment, they may stay silent.
A strong reporting culture makes it easier for workers to raise concerns before someone gets hurt.
Companies sometimes use these terms as if they mean the same thing.
They do not.
Understanding the difference helps management prepare properly.
Audit type
Main purpose
Who normally performs it?
Typical result
Internal audit | Check the organization's own system and find improvement areas | Organization's trained auditors or qualified internal resources | Internal findings and corrective actions |
Certification audit | Determine whether the system meets certification requirements | Independent certification body | Certification decision and audit findings |
Follow-up audit | Check whether specific issues have been adequately addressed | Certification body or assigned audit team | Confirmation of corrective action |
Surveillance audit | Periodically assess the certified system | Certification body | Continued certification, subject to applicable conditions |
Source basis: ISO 45001:2018 and ISO/IEC 17021-1 conformity-assessment framework.
I strongly recommend completing internal audits before the external certification audit.
But there is one condition:
Do not use the internal audit as a rehearsal designed only to make the company look perfect.
Use it to discover weaknesses.
If your internal auditor finds that employees cannot explain emergency procedures, that is good news.
You found the problem before an external auditor did.
If a department manager audits only his or her own work and has no ability to question problems, the audit may become too comfortable.
Internal auditors should have appropriate competence and enough independence to report what they actually find.
They also need to understand the operations.
A checklist alone does not make someone a good auditor.
Choosing a certification partner is an important business decision.
I would not choose one simply because the quotation is the cheapest.
Instead, I recommend comparing capability, recognition, industry experience, audit quality, and communication.
The first question should be:
Is the certification activity properly accredited and recognized for the relevant scope?
Ask to see the accreditation information and verify that the relevant certification activity is covered.
This is particularly important if the certificate will be presented to international customers.
An auditor who understands your industry can ask better questions.
A warehouse has different risks from a chemical manufacturer.
A garment factory has different operational challenges from a metal-processing plant.
A construction contractor has a different risk profile again.
Industry experience does not replace knowledge of the standard, but it makes the audit more practical.
I recommend asking about auditor competence in areas relevant to your business.
For example:
Machinery safety
Chemical risks
Electrical safety
Construction
Logistics
Manufacturing processes
Emergency management
Occupational health
Before signing a contract, make sure you understand:
Audit stages
Audit duration
Scope
Locations covered
Reporting process
Handling of findings
Corrective-action expectations
Certification decision process
Surveillance arrangements
Clear expectations reduce unpleasant surprises.
A professional certification organization should communicate clearly before, during, and after the audit.
If your questions are answered vaguely before the contract, the same communication problems may become worse during the audit.
I use a weighted comparison when helping companies evaluate service providers.
Selection factor
Suggested weight
Why it matters
Accreditation and recognition | 25% | Supports acceptance of certification |
Relevant industry competence | 20% | Helps auditors understand real operational risks |
Auditor competence | 20% | Directly affects audit quality |
Audit methodology | 15% | Creates a clear and consistent assessment |
Communication and service | 10% | Reduces preparation problems |
Commercial terms | 10% | Important, but should not dominate the decision |
Source basis: Practical certification-provider evaluation methodology; weighting should be adapted to the organization's needs.
My advice is simple: compare the total value, not just the quotation.
A small saving at the beginning is not worth much if the audit process creates confusion or fails to provide useful feedback.
Here are the techniques I find most useful.
Pick a real job and follow it from beginning to end.
For example:
Receive material → move material → operate machine → inspect product → clean equipment → dispose of waste
At each stage, ask:
What can hurt someone?
What control is in place?
Who is responsible?
What evidence shows the control works?
This is much more useful than reviewing documents randomly.
Ask workers simple questions:
What are the biggest safety risks in your job?
What PPE do you need?
What do you do if equipment becomes unsafe?
How do you report a hazard?
What happens during an emergency?
Who do you contact if you need help?
Do not tell workers to memorize answers.
If they understand the workplace, natural answers are better.
Do not spend 80% of your preparation time fixing small administrative issues while a serious machine hazard remains.
Prioritize risks according to their potential consequences and likelihood.
Choose several records and trace them backward.
For example, select a maintenance record.
Then visit the machine.
Does the machine match the record?
Select a training record.
Then talk to the employee.
Does the employee understand the task?
Select a corrective action.
Then inspect the original problem.
Has it actually been fixed?
This type of traceability is extremely powerful.
A useful mock audit should not simply ask:
"Do you have a procedure?"
Instead, ask:
"Show me how this procedure works."
If the company says employees inspect machines every morning, go to the machine.
If it says workers report near misses, ask to see a recent example.
If it says emergency drills are evaluated, find the evaluation.
This exposes gaps quickly.
A document is useful when the right person can find it and understand it.
Avoid creating 50-page procedures for a task that workers can understand from a two-page instruction with clear pictures.
The goal is control, not paperwork.
This is one of my strongest recommendations.
If employees discover a problem during an audit, report it honestly.
A mature organization does not need to pretend that nothing ever goes wrong.
What matters is whether the organization recognizes the issue, controls the immediate risk, investigates the cause, and improves the system.
The exact audit schedule depends on the certification arrangement and applicable certification rules.
A certification cycle normally includes an initial certification process followed by periodic surveillance activities and subsequent recertification.
The important point is that certification is not normally a one-time event.
The organization needs to maintain its management system over time.
The exact evidence depends on the organization's activities and system.
Common areas include:
OH&S policy
Scope of the management system
Hazard identification and risk assessment
Applicable legal and other requirements
Objectives and plans
Roles and responsibilities
Training and competence records
Operational controls
Emergency preparedness
Incident investigations
Internal audits
Management reviews
Corrective actions
Monitoring and measurement records
However, I would not recommend creating documents simply because you think an auditor wants to see them.
Start with the actual process.
Then create the information needed to control and demonstrate that process.
A nonconformity means the audit has identified a failure to meet a relevant requirement.
The organization generally needs to understand the problem, take appropriate action, determine the cause where required, and provide evidence of correction and corrective action according to the certification body's process.
The important thing is not to panic.
A finding is useful information.
The wrong response is to fix the document while leaving the real problem untouched.
Yes.
Company size does not automatically determine whether the management system can work.
A small factory may actually have an advantage because communication can be faster and responsibilities can be clearer.
The system should be appropriate to the organization's size, activities, risks, and complexity.
In my experience, one of the biggest mistakes is treating the audit as a document competition.
Companies sometimes spend enormous effort making procedures look perfect while paying less attention to what happens on the factory floor.
I would reverse that order.
Fix the real risk first. Then make sure the system and records accurately describe what you do.
When I conduct or prepare for an ISO 45001 audit, I do not think the real goal is simply to get through the audit with no findings.
The bigger goal is to understand whether the organization can consistently identify risks, control them, listen to workers, respond to incidents, and improve its way of working.
A certificate can demonstrate that a management system has been assessed.
But the real test happens every day.
It happens when a machine breaks down.
It happens when a worker notices an unsafe condition.
It happens when a contractor arrives unexpectedly.
It happens during a night shift.
It happens when production is under pressure.
It happens during an emergency.
That is why I encourage companies to prepare for an ISO 45001 audit by asking a simple question:
“If an auditor followed our employees through a normal working day, would our actual behavior match our documented system?”
If the answer is yes, you are probably starting from a strong position.
If the answer is no, that is not a reason to panic.
It is a reason to improve.
At GAIA Standard Technical Service Co., Ltd., we approach auditing and certification from that practical perspective. Established in 2021, GAIA provides third-party auditing, certification, and verification services with a focus on international ISO systems, occupational health and safety, social responsibility, environmental protection, green and low-carbon development, sustainability, and supply-chain requirements.
Our organization has been approved by China's Certification and Accreditation Administration for relevant third-party certification activities, and our qualifications and service capabilities also cover international certification and verification needs. We bring together professionals with management, auditing, certification, and industry experience so that assessments can connect management-system requirements with actual business operations.
For companies preparing for an ISO 45001 audit, my final advice is straightforward:
Do not prepare to impress the auditor. Prepare to protect your people.
When the safety system genuinely works for employees, the audit becomes much easier to understand.
The paperwork becomes evidence of what the company actually does.
The interview questions become conversations rather than rehearsed answers.
And the audit becomes what it should have been from the beginning: a practical opportunity to identify weaknesses before those weaknesses become injuries, disruptions, or costly business problems.
The management team of GAIA possesses both solid
professional skills and extensive organizational management
abilities. In terms of ideological quality, professionalism, and
management capabilities, they are a trustworthy partner who
understands business, excels in management, adheres to
discipline, dares to take responsibility, and is reliable.

Scan QR code
GAIA
Business consultation








Copyright @ GAIA Standard Technical Service Co., Ltd. All rights reserved
Technical Support: Wuxi website construction
This website uses cookies to ensure you get the best experience on our website.
Comment
(0)