
ISO 45001 Internal Audit Checklist That Works
A certification auditor will not be persuaded by a polished manual if supervisors cannot explain how hazards are controlled on site. An effective ISO 45001 internal audit checklist tests whether your safety management system is being used, understood and improved in the places where work actually occurs.
For Australian businesses, that means looking beyond document control. Your audit needs to examine the connection between ISO 45001 requirements, applicable WHS duties, contractor activity, consultation arrangements and the controls workers rely on every shift. Done properly, internal auditing identifies weaknesses before they become incidents, nonconformities, lost tender opportunities or director-level concerns.
What an ISO 45001 internal audit should achieve
ISO 45001 requires organisations to conduct internal audits at planned intervals. The purpose is to determine whether the WHS management system conforms to the organisation's own requirements and the ISO 45001 standard, and whether it is effectively implemented and maintained.
This is not a document collection exercise. A useful audit gives management a clear view of control effectiveness. It should answer practical questions: Are high-risk activities being planned? Are workers consulted before changes affect them? Are incidents investigated to prevent recurrence? Are corrective actions actually closed and verified?
The audit scope should reflect operational risk. A business with warehouse operations, mobile plant, subcontractors and multiple sites should not apply the same shallow checklist to every area. Higher-risk processes deserve more audit time, more worker interviews and stronger sampling of records.
Independence matters as well. Auditors should be objective and not audit their own work where this can be avoided. In a small business, this may mean cross-auditing between managers or engaging an external auditor for selected areas. The aim is credible findings, not a favourable score.
Before using the ISO 45001 internal audit checklist
Start by defining the audit criteria, scope and plan. Criteria normally include ISO 45001 clauses, your WHS policies and procedures, relevant legislation, client requirements and any controls identified in risk assessments. Scope should state the sites, functions, activities and period being reviewed.
Review previous audit findings, incident trends, consultation records, changes to operations and outstanding corrective actions before entering the field. This directs attention towards known pressure points rather than treating every clause as equally significant.
Notify relevant managers and supervisors, but do not allow preparation to become a staged performance. Walk the work area during normal operations where possible. Speak with workers, observe tasks and compare what is happening with what the system says should happen. A procedure is evidence of intent. Consistent field practice is evidence of implementation.
ISO 45001 internal audit checklist: core questions
The following checklist is designed as a practical audit framework. Each question should be supported by objective evidence, such as observations, interviews, completed forms, training records, maintenance history, meeting minutes or controlled documents. Record both conformities and opportunities for improvement, not only failures.
Context, leadership and worker participation
Begin with clauses 4 and 5. These requirements establish whether the system has a clear purpose, accountable leadership and meaningful worker involvement.
Has the organisation identified relevant internal and external issues, interested parties and applicable WHS obligations?
Is the scope of the WHS management system defined and consistent with the work actually performed?
Do leaders demonstrate accountability through site engagement, resources, reviews and timely action on safety issues?
Is the WHS policy current, communicated and understood by personnel at relevant levels?
Are workers and health and safety representatives consulted on hazards, changes, incidents and controls?
Can workers report hazards or stop unsafe work without fear of reprisal?
Do not accept a signed policy or a toolbox talk register as complete evidence. Ask workers how they raise issues and request examples of concerns that have led to a change. Consultation that produces no visible feedback loop is often consultation in name only.
Planning, hazards and legal requirements
Clause 6 is frequently where systems appear sound on paper but fail under operational pressure. Audit how the business identifies hazards, assesses risks and opportunities, determines controls and keeps legal obligations current.
Are hazard identification methods suitable for routine, non-routine and emergency activities?
Do risk assessments account for workers, contractors, visitors, vulnerable persons and people affected beyond the workplace?
Are controls selected using the hierarchy of control rather than relying mainly on training, signage and PPE?
Are risk assessments reviewed after incidents, changes, new equipment, altered work methods or emerging hazards?
Has the business identified applicable Commonwealth, state or territory WHS laws, codes of practice, licences and client obligations?
Are measurable WHS objectives set, assigned, monitored and reviewed?
For high-risk work, trace the controls through to the field. If a risk assessment identifies exclusion zones, isolation procedures or verification checks, observe whether they are applied by the crew. Where the paperwork and the worksite differ, the worksite is the finding.
Support and operational control
Clauses 7 and 8 test whether the business provides the capability and discipline needed to manage work safely. This includes competence, awareness, communication, documented information, procurement and contractor controls.
Are roles, responsibilities and authorities clear for managers, supervisors, workers and contractors?
Is competence verified for high-risk tasks, licences, plant operation and supervisory duties, rather than assumed from attendance at training?
Are inductions relevant to the site and do they address local hazards, emergency arrangements and reporting expectations?
Are controlled documents current, accessible and protected from unintended changes?
Do purchasing and contractor onboarding processes consider WHS requirements before work or supply begins?
Are contractors monitored for compliance with agreed controls, not merely asked to provide certificates of currency?
Are changes to plant, chemicals, layouts, personnel or work methods assessed before implementation?
Are emergency scenarios identified, tested and reviewed after drills or real events?
Contractor management deserves particular attention in Australian construction, manufacturing, logistics and port-related environments. A prequalification form alone does not control contractor risk. Audit the handover from procurement to site supervision, including scopes of work, SWMS or equivalent task controls, inductions, permits, verification and close-out.
Performance evaluation and improvement
Clauses 9 and 10 show whether the system learns from its performance. Auditors should sample data and follow the organisation's response from issue identification through to verified action.
Are inspections, monitoring activities and legal compliance evaluations planned and completed at suitable intervals?
Are incidents, near misses and hazards reported, investigated and analysed for contributing factors?
Are corrective actions assigned to accountable people with realistic due dates?
Is action effectiveness verified before a finding is closed?
Are internal audit results reported to relevant management and used in management review?
Does management review consider performance trends, resources, risks, opportunities and improvement actions?
A common weakness is closing actions when a form has been updated or a reminder has been issued. That may be appropriate for a minor administrative issue, but it rarely proves that a failed control now works. Verification should be proportionate to the risk. For example, a plant isolation finding may require field observation and worker interviews after the corrective action is introduced.
Recording findings that can be acted on
A finding should be specific enough for management to understand the failure and for the responsible person to act without guessing. Record the audit criterion, factual evidence, location or process, and the consequence or risk created by the gap.
Avoid vague wording such as “safety records were incomplete”. A stronger finding would state that three sampled pre-start inspections for a mobile plant fleet had no recorded defect close-out, contrary to the inspection procedure and planned operational control requirements. This identifies the system requirement, evidence and process affected.
Classify findings consistently. Major nonconformities generally indicate an absent or failed system element, or a pattern that creates doubt about effective implementation. Minor nonconformities are isolated lapses that do not indicate total system failure. Opportunities for improvement are not breaches, but they may prevent future failures or reduce unnecessary administration.
Turn audit results into better operational control
The value of an internal audit is realised after the closing meeting. Prioritise corrective actions according to risk, legal exposure, operational impact and certification implications. Assign one accountable owner, a due date and clear evidence required for closure.
Management should also look for repeat themes. Repeated issues with inductions, contractor monitoring or corrective action closure are rarely isolated staff errors. They usually point to a process that is unclear, under-resourced or not embedded in day-to-day supervision.
For organisations preparing for certification or a major tender, an experienced independent review can test whether the system will stand up to external scrutiny. The Safety Hand supports businesses with practical internal audits that examine both ISO 45001 conformity and how controls operate across real work activities.
A checklist is only as useful as the judgement behind it. Use it to test the evidence, listen to the people doing the work and pursue the gaps that matter most. That is how an internal audit becomes a management tool rather than another compliance task.




Comments