ISO 45001 Audit: A Practical Guide to Occupational Health and Safety Management

When I talk with manufacturers about an ISO 45001 audit, I often notice the same concern: people think the audit is mainly about documents, checklists, and finding mistakes. In reality, a good ISO 45001 audit should tell me something much more useful: Can this organization actually control the health and safety risks that come with its work?
That question matters whether I am looking at a factory, warehouse, construction company, logistics operation, service provider, or another organization with workers exposed to occupational health and safety risks.
ISO 45001 provides a structured management system for identifying hazards, assessing risks, meeting applicable requirements, involving workers, preparing for emergencies, checking performance, and continually improving occupational health and safety. The current published standard remains ISO 45001:2018, with a climate-action amendment published in 2024.
At GAIA Standard Technical Service Co., Ltd. (GAIA), I approach an ISO 45001 audit as a practical assessment of how a management system works in the real world. GAIA was established in 2021 and is a third-party auditing organization approved by the Certification and Accreditation Administration of the People's Republic of China (CNCA), approval number CNCA-R-2022-1132.
Our work covers international ISO systems, supply chain quality, social responsibility, occupational safety, environmental protection, green and low-carbon development, ESG, sustainability, certification, auditing, and verification. We also hold the credentials and qualifications described by our organization, including International Accreditation Service (IAS) accreditation under MSCB-3712, HIGG/FEM verification qualification under ID186793, and membership in the Social & Labor Convergence Program (SLCP).
In this guide, I will explain what an ISO 45001 audit looks like, what auditors actually check, how companies can prepare, where common problems appear, how the audit can support better risk control, and how we approach ISO 45001 audit and certification services at GAIA.
1. What Is an ISO 45001 Audit and Why Does It Matter?
An ISO 45001 audit is a systematic assessment of an organization's occupational health and safety management system against the applicable requirements of ISO 45001.
In plain English, I am checking whether the organization has a sensible way to manage workplace safety and whether that system is actually being used.
That second part is important.
A company may have a beautifully written safety manual. It may have hundreds of forms. It may even have a large folder named “ISO 45001.” None of that automatically means the system is effective.
When I audit, I want to connect the paperwork with what is happening on the production floor.
If the risk assessment says a machine has a serious entanglement hazard, I want to see how that hazard is controlled in practice. If the procedure says workers receive training, I want to understand whether the people doing the job are competent. If the emergency plan says workers can evacuate safely, I want to know whether the evacuation arrangements are realistic.
The three situations where an ISO 45001 audit is commonly used
First, certification. An organization may want to obtain ISO 45001 certification for the first time. The certification audit assesses whether the management system meets the standard and is implemented effectively within the proposed scope.
Second, surveillance. After certification, periodic surveillance activities are used to assess continued conformity and implementation of the management system.
Third, recertification. At the end of the certification cycle, the organization undergoes a more complete reassessment before another certification cycle can begin.
There can also be internal audits, supplier audits, gap assessments, customer audits, and other forms of assessment. These are not necessarily the same as third-party certification audits, even though they may examine similar parts of the management system.
What makes ISO 45001 different from a simple safety inspection?
A safety inspection usually focuses on conditions or specific activities. For example, are fire extinguishers available? Are machine guards installed? Are electrical panels safe?
An ISO 45001 audit goes further. I also ask how the organization manages these issues systematically.
Who identifies hazards?
How are risks assessed?
Who is responsible for controlling them?
How does management provide resources?
How are workers consulted?
How are legal requirements identified and evaluated?
How are incidents and near misses investigated?
How are corrective actions tracked?
How does management know whether the system is working?
How is the system improved when something does not work?
This is why I see ISO 45001 auditing as a management-system assessment, not simply a factory walk-through.
| Area | Routine Safety Inspection | ISO 45001 Audit |
|---|---|---|
| Main focus | Workplace conditions and specific hazards | OH&S management system and its implementation |
| Risk assessment | May check selected risks | Reviews the organization's systematic approach to identifying and managing risks |
| Leadership | Usually limited | Examines leadership responsibility, policy, objectives, resources, and accountability |
| Worker participation | May involve worker interviews | Considers consultation and participation within the management system |
| Legal requirements | May check selected compliance points | Examines the organization's process for identifying and evaluating applicable requirements |
| Continual improvement | Usually not the main focus | Reviews corrective action, performance evaluation, audits, management review, and improvement |
| Source basis: ISO 45001:2018 management-system requirements and common conformity-assessment practice. The comparison is a practical explanation and does not replace the standard or audit rules. | ||
2. What I Check During an ISO 45001 Audit
When preparing for an ISO 45001 certification audit, I recommend that companies stop thinking only about individual clauses. Instead, think about how the whole business manages safety.
ISO 45001 follows a management-system structure. I normally look at the organization from several connected angles.
Understanding the organization
Before looking at individual hazards, I need to understand what the organization actually does.
What products are manufactured? What processes are used? How many workers are involved? Which contractors work on site? Are there multiple shifts? What equipment and chemicals are used? What external conditions can affect occupational health and safety?
This gives context to everything that follows.
Leadership and management responsibility
Safety should not sit only on the desk of an EHS manager.
During an audit, I may want to understand how senior management sets OH&S direction, provides resources, assigns responsibilities, reviews performance, and responds to important risks.
A useful question is very simple: What happens when production pressure and safety requirements conflict?
If management always chooses output first, the written policy does not tell the whole story.
Worker consultation and participation
Workers are often the people closest to the actual hazards.
A machine operator may know that a particular adjustment is difficult. A warehouse worker may know that two forklift routes cross at a dangerous point. A maintenance worker may know that an isolation procedure is difficult to follow.
ISO 45001 puts strong attention on consultation and participation of workers. During an audit, I therefore look beyond training attendance sheets. I want to see whether workers have meaningful ways to report problems and contribute to safer work.
Hazard identification
This is one of the most important parts of the audit.
The organization should identify hazards connected with its activities, products, services, workplaces, equipment, people, and changes to operations.
For a manufacturing company, this may include machinery, electricity, chemicals, noise, heat, lifting, material handling, vehicles, work at height, confined spaces, maintenance, contractors, and emergency situations.
Risk assessment and controls
Listing hazards is not enough.
I need to understand how the organization determines which risks matter most and what controls are used.
For example, if a cutting machine presents a serious injury risk, putting up a warning sign may not be enough. I would expect the organization to consider stronger controls such as machine guarding, safe operating arrangements, maintenance controls, training, and appropriate personal protective equipment.
Legal and other requirements
Every organization needs to understand which occupational health and safety laws and other requirements apply to its activities.
This becomes more complicated for companies operating across countries or regions. A manufacturer exporting internationally may have to manage requirements from several jurisdictions while also meeting customer and corporate requirements.
An effective ISO 45001 audit checklist should therefore not be limited to internal documents. It should connect legal requirements with actual operations.
Operational control
Next, I look at how the organization controls important activities.
This can include machine operation, maintenance, procurement, contractor management, change management, chemical handling, emergency preparedness, and other activities related to significant risks.
Performance evaluation
Management needs information to know whether its system is working.
That information can come from inspections, incident records, near-miss reports, monitoring, compliance evaluations, internal audits, worker feedback, corrective actions, and other suitable indicators.
I do not expect every company to use the same performance indicators. A good system uses information that makes sense for the organization's risks and operations.
Improvement
Finally, I look at what happens when something goes wrong.
Does the company investigate the cause? Does it take corrective action? Does it check whether the action worked? Does it look for similar problems elsewhere?
This is where an ISO 45001 management system can become a real improvement tool rather than just a compliance exercise.
3. How to Prepare for an ISO 45001 Audit Without Creating a Paper Mountain
One of the most common mistakes I see is preparing for an audit by creating documents at the last minute.
That approach usually creates two problems.
First, employees do not know the new procedures. Second, the documents may describe a system that does not match what actually happens.
I prefer a different approach: build the system around the real operation first, then organize the evidence.
Start with a gap assessment
Before the formal audit, the organization should understand where it stands.
A gap assessment can compare current practices with ISO 45001 requirements. It can identify missing processes, weak controls, incomplete records, unclear responsibilities, and areas where actual practice differs from written procedures.
This gives management a practical action list.
Review your hazard and risk assessments
I would make this one of the first preparation steps.
Do not simply check whether a risk assessment document exists. Ask whether it reflects the current workplace.
Have new machines been added? Has production changed? Are temporary workers involved? Has the layout changed? Are contractors performing new activities? Have previous incidents revealed new hazards?
A risk assessment that has not changed for years may be a warning sign.
Check worker awareness
Auditors may speak with workers.
Workers do not need to memorize ISO clauses. In fact, I do not recommend turning them into walking standards manuals.
They should simply understand the safety rules relevant to their jobs, know the major hazards, know what to do in an emergency, and know how to report a concern.
Check actual workplace conditions
Before an ISO 45001 audit for manufacturing companies, walk through the facility.
Look at the basics:
Machine guards
Emergency exits
Fire protection equipment
Electrical installations
Material storage
Chemical labels and storage
Forklift and pedestrian routes
Personal protective equipment
Housekeeping
Warning signs
Maintenance activities
Emergency equipment
These physical conditions should match the organization's documented risk controls.
Review incidents and near misses
Do not hide problems from the management system.
If an incident happened, the important question is not simply whether the report has been filed. I want to know whether the organization understood the cause and took effective action.
Near misses are equally useful. They can reveal weaknesses before somebody gets seriously injured.
Prepare your internal audit
The internal audit should not be treated as a rehearsal where the goal is to make every finding disappear.
Its purpose is to test whether the management system works.
A useful internal audit can find weaknesses while there is still time to fix them.
| Preparation Area | What I Recommend Checking | Common Weakness |
|---|---|---|
| Organization context | Scope, activities, sites, relevant internal and external issues | Scope does not match actual operations |
| Hazard identification | Routine, non-routine, emergency, contractor, and change-related hazards | Risk assessment is outdated |
| Legal compliance | Applicable requirements and evaluation process | Legal register exists but is not maintained |
| Worker participation | Consultation, reporting, communication, involvement | Workers know rules but cannot explain how to raise concerns |
| Operational control | High-risk activities and procedures | Procedure does not match actual work |
| Emergency preparedness | Plans, equipment, drills, lessons learned | Drills are completed only as paperwork |
| Internal audit | Coverage, competence, findings, corrective action | Internal audit is too superficial |
| Management review | Performance, risks, resources, opportunities, actions | Meeting occurs but produces little action |
| Source basis: practical preparation aligned with ISO 45001:2018 requirements. Checklist items are implementation guidance rather than a substitute for the standard. | ||
4. What Happens During an ISO 45001 Certification Audit?
Many clients feel nervous before their first certification audit. That is understandable. But I usually tell them not to think of the audit as an interrogation.
A well-planned audit is a structured professional assessment.
Stage 1: Understanding readiness
For an initial certification arrangement, the audit process commonly includes an initial stage that focuses on the organization's readiness, documented management system, scope, site information, and understanding of key requirements.
The exact audit arrangement depends on the certification program and applicable conformity-assessment rules.
This stage can be especially useful because it allows the organization and audit team to identify significant readiness issues before the main implementation assessment.
Stage 2: Assessing implementation
The main certification audit examines whether the OH&S management system is implemented and effective within the certification scope.
This is where the auditor may review records, interview employees and managers, observe activities, inspect workplaces, and follow evidence through different parts of the organization.
For example, I might start with a risk assessment, move to the related operating procedure, speak with the worker performing the task, observe the activity, and then check training or inspection records.
This is called following the audit trail. It helps me see whether different pieces of the system actually connect.
What happens if a nonconformity is found?
A nonconformity means that a requirement has not been met in the way required by the applicable criteria.
The response should not be “How do I make this finding disappear?”
The better question is “Why did this happen, and how do I prevent it from happening again?”
The organization may need to correct the immediate problem, investigate the cause, determine whether similar issues exist elsewhere, implement corrective action, and provide appropriate evidence.
Not every audit finding has the same significance
Audit findings are classified according to the applicable certification and audit rules. The terminology and decision process should be understood in the context of the certification scheme being used.
From a management point of view, however, I encourage companies to take every credible finding seriously. A small paperwork problem may sometimes point to a bigger system weakness.
The audit should follow evidence
An auditor should not simply ask employees to recite standard clauses.
The strongest evidence normally comes from several sources that support the same conclusion:
Documents and records
Interviews
Workplace observation
Performance data
Incident and corrective-action records
Management decisions
When these sources tell the same story, confidence in the management system becomes much stronger.
How long does an ISO 45001 audit take?
There is no single answer.
Audit duration depends on factors such as the number of employees, organization complexity, risk level, number of sites, shift arrangements, activities, degree of outsourcing, and other factors defined by applicable audit-time and certification rules.
That is why I do not recommend choosing an auditor simply because someone promises the shortest possible audit. A certification audit needs enough time to obtain meaningful evidence.
5. Using the ISO 45001 Audit to Reduce Risk, Waste, and Business Disruption
I often tell manufacturers that occupational safety is not separate from operational efficiency.
When a serious incident happens, production may stop. Equipment may be damaged. Workers may be absent. Management may spend days investigating the event. Customers may face shipment delays. Contractors may need to be replaced.
None of these costs necessarily appears in the company's safety budget.
That is why a good ISO 45001 audit can provide value beyond certification.
Risk control can protect production continuity
Consider machine maintenance.
If maintenance workers face uncontrolled energy during servicing, the risk is obvious. But an incident could also lead to machine downtime, investigation, repair, retraining, and delayed production.
A well-designed maintenance control process can address the safety risk while also supporting predictable production.
Good corrective action prevents repeated work
Suppose a warehouse has repeated problems with blocked emergency routes.
A weak corrective action might tell workers to “keep the area clear.”
A stronger approach asks why the route becomes blocked. Is storage space insufficient? Is the layout poorly designed? Are delivery times creating congestion? Is responsibility unclear?
Fixing the cause is often more effective than repeatedly reminding people about the same problem.
Better data supports better decisions
An ISO 45001 system encourages organizations to collect and evaluate useful OH&S information.
Management can then identify trends.
For example, several minor hand injuries may point toward one common process weakness. Several near misses around a loading area may show that traffic control needs improvement.
The goal is to move from “something happened” to “we understand why it happened and know what to do next.”
| Finding or Signal | Short-Term Response | Better Long-Term Action | Potential Business Benefit |
|---|---|---|---|
| Repeated machine safety issue | Repair the immediate problem | Review machine design, guarding, maintenance, and training | Fewer repeat failures and interruptions |
| Repeated near misses | Issue a warning | Identify root causes and redesign the control | Lower risk of serious incidents |
| Incomplete contractor controls | Remind contractor of rules | Improve contractor selection, induction, supervision, and monitoring | More predictable high-risk work |
| Emergency drill weakness | Repeat the drill | Analyze the failure and improve emergency arrangements | Better response capability |
| Repeated audit findings | Close each finding separately | Analyze common system causes | Less repeated corrective work |
| Source basis: practical application of ISO 45001 continual-improvement and corrective-action principles. Business benefits are potential outcomes and depend on organization-specific conditions. | |||
I deliberately use the word potential here. ISO 45001 certification does not guarantee a particular percentage reduction in accidents or operating costs. Every organization is different.
What the system can provide is a disciplined way to identify problems, prioritize risks, assign responsibility, measure results, and improve controls.
6. ISO 45001, ISO 9001, and ISO 14001: Can I Build One Integrated System?
For companies that already have several management systems, this is one of the questions I hear most often.
The good news is that organizations do not necessarily need three completely separate systems.
ISO 45001 can be integrated with standards such as ISO 9001:2015 and ISO 14001:2015. The standards use compatible high-level structures and share many management-system concepts.
For example, an organization may be able to combine:
Organization context analysis
Leadership processes
Management-system objectives
Documented information controls
Internal audit programs
Corrective-action processes
Management review
Competence and awareness processes
Continual improvement
The technical focus remains different.
ISO 9001 focuses on quality management and the ability to consistently provide products and services that meet customer and applicable requirements.
ISO 14001 focuses on environmental management and environmental performance.
ISO 45001 focuses on occupational health and safety and the prevention of work-related injury and ill health.
So I would not combine everything into one giant document and call it an integrated system. Instead, I would integrate the common management processes while keeping the technical controls appropriate to each subject.
Why integrated certification can make sense for manufacturers
Imagine a factory already operating ISO 9001 and ISO 14001.
The company probably already has internal auditors, management review meetings, corrective-action procedures, document controls, training systems, objectives, and operational processes.
Adding ISO 45001 does not mean starting from zero.
The company can examine what already exists, identify gaps in occupational health and safety, strengthen the relevant processes, and integrate the systems where appropriate.
This can make the management framework easier for employees to understand and easier for management to review.
The climate-change amendment
Another point companies should not overlook is the 2024 amendment to ISO 45001:2018.
The amendment introduces climate-action considerations into the management-system context. Organizations need to determine whether climate change is a relevant issue and consider relevant interested-party requirements connected with climate change.
For example, some workplaces may face increased heat exposure, extreme weather, flooding, or other conditions that can affect occupational health and safety. The exact relevance depends on the organization's location, activities, and circumstances.
I recommend treating this as a real business question rather than adding a generic sentence about climate change to a procedure.
7. Why Choose GAIA for ISO 45001 Audit and Certification Services?
Choosing an ISO 45001 audit provider is not only about obtaining a certificate. The organization should understand who will perform the assessment, what competence is available, what accreditation or approval applies, how the scope is determined, and how communication will be handled.
At GAIA, our approach is built around fairness, impartiality, value transmission, efficient service, and integrity.
Third-party auditing experience
GAIA was established in 2021 and is a third-party auditing organization approved by the Certification and Accreditation Administration of the People's Republic of China (CNCA), with approval number CNCA-R-2022-1132.
Our organization has developed services around certification, auditing, verification, and innovative technical services across Asia and beyond.
Broader management-system knowledge
Our service areas include international ISO systems, corporate social responsibility, environmental management, green and low-carbon development, supply chain quality, safety, sustainability, and ESG.
This broader view is useful because an occupational health and safety system rarely operates in isolation.
A manufacturer may need to manage quality, environmental performance, worker safety, social responsibility, supplier requirements, and customer audits at the same time.
We aim to understand that business environment rather than treating ISO 45001 as a standalone checklist.
Relevant qualifications and credentials
According to our company credentials, GAIA holds International Accreditation Service (IAS) accreditation under MSCB-3712 and HIGG/FEM verification qualification under ID186793. We are also a member of the Social & Labor Convergence Program (SLCP).
Our stated management-system credentials include ISO 9001, ISO 14001, ISO 45001, HSE, GB/T 27922, GB/T 31950, and GB/T 39604.
Experienced professionals
GAIA has brought together professionals with experience in auditing, certification, verification, management, and different industry environments.
For us, technical knowledge is only one part of the job. An auditor also needs to communicate clearly, understand evidence, remain objective, and know how to distinguish a genuine system weakness from a misunderstanding.
A practical service style
Our service philosophy is professionalism, standardization, thoughtfulness, and flexibility.
I believe that is particularly important when working with manufacturing companies.
Factory managers do not need complicated language for the sake of complicated language. They need to know what the requirement means, what evidence is needed, what the actual risk is, and what should happen next.
That is how we try to communicate during ISO 45001 audit and certification projects.
8. ISO 45001 Audit FAQ
What is the purpose of an ISO 45001 audit?
The purpose is to assess whether an organization's occupational health and safety management system conforms to applicable ISO 45001 requirements and is effectively implemented within the relevant scope. The audit also provides useful information about system strengths, weaknesses, and opportunities for improvement.
Is an ISO 45001 audit the same as a safety inspection?
No. A safety inspection normally focuses on workplace conditions and specific hazards. An ISO 45001 audit examines the wider management system, including leadership, worker participation, risk assessment, legal requirements, operational controls, performance evaluation, internal auditing, and improvement.
What documents are checked during an ISO 45001 audit?
Depending on the organization and audit scope, an auditor may review the OH&S policy, objectives, risk assessments, legal requirements, operational controls, training and competence records, emergency plans, monitoring information, incident investigations, internal audits, corrective actions, management reviews, and other relevant documented information.
However, an auditor should not judge the system only by the number of documents. Evidence from interviews and workplace observation is also important.
Will an auditor interview workers?
Workers may be interviewed because they are important sources of evidence about how the management system works in practice. They should understand the safety risks and controls relevant to their work and know how to report problems. They do not need to memorize ISO 45001 clauses.
What happens if the auditor finds a nonconformity?
The organization needs to respond according to the applicable certification and audit requirements. Depending on the finding, this can involve correction, cause analysis, corrective action, and submission or verification of appropriate evidence. The most useful response is to solve the underlying system problem rather than simply prepare paperwork to close the finding.
Can a company fail an ISO 45001 audit?
Certification decisions are made according to applicable conformity-assessment rules and the evidence obtained during the audit. Significant unresolved nonconformities can prevent certification or affect continuation of certification. This is why preparation should focus on actual system implementation rather than last-minute document creation.
How long does ISO 45001 certification take?
The total project time varies. Factors include company size, workforce, risk level, number of sites, operational complexity, existing management systems, readiness, and the time needed to implement corrective actions. A realistic schedule should be established after understanding the organization's actual situation.
How often is an ISO 45001 audit performed after certification?
Certification normally operates within a certification cycle with surveillance activities and a recertification assessment. The exact schedule depends on the certification arrangement and applicable certification rules. Organizations should maintain the system continuously rather than preparing only when the next audit date approaches.
Can ISO 45001 replace occupational safety laws?
No. ISO 45001 is a management-system standard. It does not replace applicable laws, regulations, permits, licenses, or mandatory safety requirements. An organization must continue to identify and meet the legal and other requirements that apply to its activities.
Can ISO 45001 certification help with supplier qualification?
It can. Some customers and supply chains use ISO 45001 certification as one part of supplier evaluation. However, customer requirements differ, and certification does not automatically satisfy every customer's social responsibility, safety, or supplier-audit requirement.
Is ISO 45001 suitable for small and medium-sized companies?
Yes. ISO 45001 can be applied to organizations of different sizes and sectors. The management system should be proportionate to the organization's activities, risks, workforce, and operating environment. A small business does not need to copy the paperwork of a multinational company.
What is the difference between ISO 45001 audit and ISO 45001 certification?
An audit is the assessment activity. Certification is the formal conformity decision and certification outcome made under the applicable certification process. An organization may also conduct internal or gap audits that are not certification audits.
Can GAIA help a company prepare for an ISO 45001 audit?
GAIA provides certification, auditing, verification, and related technical services within applicable scopes and arrangements. Depending on the service requested and applicable impartiality requirements, organizations can discuss their current system, certification scope, sites, industry, major risks, and readiness before deciding on the appropriate service.









