新闻中心
होम पेज > समाचार केंद्र > Industry News

ISO 45001 Audit: What I Check, What Companies Get Wrong, and How to Prepare With Confidence
2026-08-23 18:14:34

Introduction: Are You Really Ready for an ISO 45001 Audit?

What would happen if an auditor walked into your factory tomorrow and asked a production worker, “What do you do if you find a serious safety hazard?”

Would the worker know the answer?

Now imagine the auditor walks to a machine and asks the supervisor, “How do you know this machine is safe to operate?”

Could the supervisor show practical evidence, or would someone immediately start searching through folders?

These questions explain why I see an ISO 45001 audit as much more than a document-checking exercise.

A company can have a beautifully written occupational health and safety manual and still have weak controls on the factory floor. On the other hand, a company with simple documents can have a strong safety culture because managers and workers actually understand and use the system.

When I prepare organizations for an audit, I focus on one basic connection:

What does the company say it does, what does it actually do, and what evidence shows that it works?

That connection is the heart of a successful audit.

In this practical guide, I will walk through what I look for during an ISO 45001 audit, how companies should prepare, which findings appear most often, how to choose an audit partner, and how to turn the audit into something useful rather than stressful.


1. What an ISO 45001 Audit Really Looks Like

Let me start with a common misunderstanding.

An ISO 45001 audit is not simply an inspection of whether a company has enough safety documents.

The purpose is to determine whether the organization's occupational health and safety management system meets the applicable requirements and is being implemented effectively.

In plain language, I want to understand whether the company has a reliable way to prevent work-related injury and ill health.

That means I look at both the management system and the real workplace.

The three questions I keep coming back to

During an audit, I naturally move between three questions:

  1. What risks does this company have?

  2. What has the company done to control those risks?

  3. How does the company know those controls are working?

Take a factory using industrial presses.

The company may identify crushing injuries as a significant hazard.

It may establish machine guarding, operating procedures, emergency stops, maintenance requirements, and employee training.

That sounds good.

But I still need to see what happens in real life.

Is the guard actually installed?

Can an operator easily bypass it?

Does the emergency stop work?

Are maintenance workers protected from unexpected machine movement?

Does the training reflect the machine employees actually use?

If an employee removes a guard because it makes production slower, does the supervisor know?

That is where an audit becomes practical.

An audit usually follows a logical path

Although the exact audit program varies according to the organization, I normally think about the process in several stages:

Audit stage

What I focus on

Typical evidence




Planning

Scope, locations, processes, risks

Organization information, audit plan

Leadership review

Responsibility and direction

Policies, objectives, management decisions

Risk review

Hazards and controls

Risk assessments, workplace observations

Operational review

Actual implementation

Procedures, inspections, machine controls

Worker involvement

Participation and communication

Meetings, reports, interviews

Performance review

Whether controls work

KPIs, inspections, incidents, audits

Corrective action

Response to problems

Root-cause analysis, action records

Closing assessment

Overall conformity

Audit findings and conclusions

Source basis: ISO 45001:2018 management-system requirements and ISO/IEC 17021-1 conformity-assessment principles.

The important point is that these areas are connected.

If the risk assessment identifies a serious hazard but the workplace has no effective control, there is a gap.

If a procedure requires monthly inspections but nobody performs them, there is a gap.

If workers report hazards but management never follows up, there is a gap.

The audit is about finding those connections.


2. How I Prepare for an ISO 45001 Audit: Start With the Factory, Not the Files

One of the worst preparation methods is to begin by printing documents.

I prefer to begin with a walk.

Walk through production.

Walk through the warehouse.

Visit maintenance areas.

Look at chemical storage.

Watch material movement.

Talk to operators.

Check emergency exits.

Observe contractors.

Ask supervisors what problems they deal with every week.

This approach often tells me more in one hour than a large document folder does.

Step 1: Define your actual audit scope

Before anything else, make sure the organization understands what is included in the management system.

For example, a manufacturing company may have:

  • Production buildings

  • Warehouses

  • Offices

  • Laboratories

  • Maintenance workshops

  • Loading areas

  • Company vehicles

  • Temporary work areas

  • Contractors working on site

The scope should reflect the organization's real activities.

If an important activity is quietly ignored because it is difficult to manage, the company is creating a weakness before the audit even begins.

Step 2: Review your hazards

I recommend reviewing hazards by activity rather than creating a generic list.

For a textile factory, I might expect risks related to:

  • Moving machinery

  • Needles and sharp tools

  • Noise

  • Dust

  • Electrical equipment

  • Fire

  • Manual handling

  • Ergonomics

  • Chemicals

  • Forklifts

For a metal factory, the list may look very different.

There may be welding fumes, hot surfaces, cutting equipment, heavy loads, cranes, compressed gases, grinding operations, and high-energy machinery.

The risk assessment should tell the story of the actual workplace.

Step 3: Check whether controls match the risks

This is where I often find the biggest gap.

A company may identify a serious risk correctly but use a weak control.

For example:

Hazard: Employees may be struck by moving forklifts.

Weak response: Put up a warning sign.

Stronger response: Separate pedestrian and forklift routes, improve visibility, establish speed controls, train operators, maintain vehicles, and monitor traffic behavior.

A warning sign may help.

But a physical separation between people and vehicles is usually a much stronger form of control.

Step 4: Talk to employees

I never recommend preparing only managers for an audit.

Auditors may interview employees.

More importantly, employees are the people who live with the risks every day.

A worker should be able to explain basic safety expectations in normal language.

They do not need to memorize the standard.

If I ask an operator, “What would you do if this machine became unsafe?” I am not looking for a perfect sentence.

I want to know whether the person understands how to stop, report, isolate, or escalate the problem according to the company's process.


3. What Auditors Usually Examine During an ISO 45001 Audit

ISO 45001 covers a management system, so an audit looks at several connected areas.

I find it useful to divide them into eight practical questions.

1. Does management take safety seriously?

A policy alone is not enough.

Leadership should demonstrate that occupational health and safety is part of business decision-making.

I may look at:

  • Safety objectives

  • Resources

  • Management review

  • Responsibilities

  • Safety performance

  • Decisions following serious incidents

  • Evidence of leadership involvement

If production targets are always prioritized while known safety problems remain unresolved, the organization has a management issue, not simply a worker issue.

2. Does the company understand its risks?

The organization should understand the hazards connected with its activities.

This includes routine and non-routine work.

For example, production may be safe during normal operation, but maintenance could create much greater risks.

Shutdown periods can also introduce unusual hazards.

Cleaning, equipment installation, construction, contractor work, and emergency situations deserve attention.

3. Are legal and other requirements controlled?

A company needs to understand the occupational health and safety requirements that apply to its activities and locations.

The important point is not simply having a large legal register.

Someone should know what the requirements mean and how the company checks compliance.

A spreadsheet containing hundreds of legal entries is not useful if nobody knows which requirements affect the factory.

4. Are workers involved?

Worker participation is an important part of a practical safety system.

Workers often know about problems before managers do.

They may know that:

  • A machine guard is difficult to use

  • A walkway becomes slippery during rain

  • A chemical container is awkward to move

  • A forklift route is too crowded

  • A safety procedure does not match the actual process

If employees have no safe and practical way to report these problems, management loses valuable information.

5. Are operational controls working?

This is where paperwork meets reality.

I may compare the written procedure with actual work.

For example, if the procedure says workers must inspect lifting equipment before use, I want to understand:

  • Who performs the inspection?

  • What do they check?

  • How often?

  • What happens when a defect is found?

  • Who decides whether equipment can return to service?

A control should have a clear owner and a clear response.

6. Is emergency preparedness realistic?

An emergency plan should not live inside a document cabinet.

Consider a fire drill.

Can employees find the correct exit?

Do they know where to assemble?

Are visitors and contractors included?

Can people with special needs evacuate safely?

Who contacts emergency services?

Who accounts for employees?

After the drill, does anyone review what went wrong?

An emergency exercise should be a learning opportunity, not a performance staged for an auditor.

7. Does the company learn from incidents?

When something goes wrong, I want to see more than a statement saying:

“Employee did not follow the procedure.”

That may be part of the story, but it is rarely the whole story.

A better investigation asks:

  • Was the procedure clear?

  • Was the worker trained?

  • Was supervision adequate?

  • Was the equipment suitable?

  • Was production pressure involved?

  • Had similar near misses occurred?

  • Were previous corrective actions effective?

This helps the company fix the system instead of simply blaming one person.

8. Does the organization improve?

An effective system should become better over time.

Internal audits, inspections, incidents, worker feedback, performance data, and management reviews should lead to decisions.

If the same problem appears year after year, the organization is not learning effectively.


4. Common ISO 45001 Audit Findings and How I Would Fix Them

Let me share several situations that I regularly consider important.

Finding 1: The risk assessment is too general

A company may have one large risk assessment covering an entire production department.

The problem is that "production" is not one activity.

Different machines, tasks, materials, and workers may face very different hazards.

Better approach: Break significant activities into manageable tasks and assess the hazards where they actually occur.

Finding 2: Training records exist, but competence is unclear

A training attendance sheet proves that someone attended a session.

It does not necessarily prove that the person can perform the task safely.

For high-risk work, the company should consider whether competence needs to be demonstrated.

For example, a forklift operator may need practical evaluation rather than only classroom attendance.

Finding 3: Emergency drills are performed but not evaluated

Some companies complete the drill and immediately mark it as "done."

I prefer to ask:

What happened?

Did everyone hear the alarm?

Did people use the correct exits?

Was the assembly point crowded?

Did visitors know what to do?

Were emergency contacts available?

The value is in the learning.

Finding 4: Corrective actions address symptoms

Suppose workers repeatedly trip over materials left in a walkway.

The company cleans the area.

A week later, the same problem happens.

The cleaning action did not solve the reason materials were being left there.

Maybe the storage area is too small.

Maybe production planning creates temporary overflow.

Maybe material routes are poorly designed.

The corrective action should address the underlying cause.

Finding 5: Contractor control is weak

A contractor may enter a factory with different training, tools, and working methods.

If contractors perform hot work, electrical work, maintenance, construction, or work at height, the organization needs a clear process for controlling the associated risks.

Simply asking a contractor to sign a safety declaration is rarely enough.

Finding 6: Workers are afraid to report problems

This is harder to see in documents.

If employees believe reporting a hazard will lead to punishment, they may stay silent.

A strong reporting culture makes it easier for workers to raise concerns before someone gets hurt.


5. ISO 45001 Audit vs. Internal Audit vs. Certification Audit

Companies sometimes use these terms as if they mean the same thing.

They do not.

Understanding the difference helps management prepare properly.

Audit type

Main purpose

Who normally performs it?

Typical result





Internal audit

Check the organization's own system and find improvement areas

Organization's trained auditors or qualified internal resources

Internal findings and corrective actions

Certification audit

Determine whether the system meets certification requirements

Independent certification body

Certification decision and audit findings

Follow-up audit

Check whether specific issues have been adequately addressed

Certification body or assigned audit team

Confirmation of corrective action

Surveillance audit

Periodically assess the certified system

Certification body

Continued certification, subject to applicable conditions

Source basis: ISO 45001:2018 and ISO/IEC 17021-1 conformity-assessment framework.

I strongly recommend completing internal audits before the external certification audit.

But there is one condition:

Do not use the internal audit as a rehearsal designed only to make the company look perfect.

Use it to discover weaknesses.

If your internal auditor finds that employees cannot explain emergency procedures, that is good news.

You found the problem before an external auditor did.

Internal audits should be independent enough to be useful

If a department manager audits only his or her own work and has no ability to question problems, the audit may become too comfortable.

Internal auditors should have appropriate competence and enough independence to report what they actually find.

They also need to understand the operations.

A checklist alone does not make someone a good auditor.


6. How to Choose the Right Certification Partner for an ISO 45001 Audit

Choosing a certification partner is an important business decision.

I would not choose one simply because the quotation is the cheapest.

Instead, I recommend comparing capability, recognition, industry experience, audit quality, and communication.

First: Check accreditation and recognition

The first question should be:

Is the certification activity properly accredited and recognized for the relevant scope?

Ask to see the accreditation information and verify that the relevant certification activity is covered.

This is particularly important if the certificate will be presented to international customers.

Second: Look at industry experience

An auditor who understands your industry can ask better questions.

A warehouse has different risks from a chemical manufacturer.

A garment factory has different operational challenges from a metal-processing plant.

A construction contractor has a different risk profile again.

Industry experience does not replace knowledge of the standard, but it makes the audit more practical.

Third: Ask how auditors are selected

I recommend asking about auditor competence in areas relevant to your business.

For example:

  • Machinery safety

  • Chemical risks

  • Electrical safety

  • Construction

  • Logistics

  • Manufacturing processes

  • Emergency management

  • Occupational health

Fourth: Compare the audit process

Before signing a contract, make sure you understand:

  • Audit stages

  • Audit duration

  • Scope

  • Locations covered

  • Reporting process

  • Handling of findings

  • Corrective-action expectations

  • Certification decision process

  • Surveillance arrangements

Clear expectations reduce unpleasant surprises.

Fifth: Evaluate communication

A professional certification organization should communicate clearly before, during, and after the audit.

If your questions are answered vaguely before the contract, the same communication problems may become worse during the audit.

A practical selection scorecard

I use a weighted comparison when helping companies evaluate service providers.

Selection factor

Suggested weight

Why it matters




Accreditation and recognition

25%

Supports acceptance of certification

Relevant industry competence

20%

Helps auditors understand real operational risks

Auditor competence

20%

Directly affects audit quality

Audit methodology

15%

Creates a clear and consistent assessment

Communication and service

10%

Reduces preparation problems

Commercial terms

10%

Important, but should not dominate the decision

Source basis: Practical certification-provider evaluation methodology; weighting should be adapted to the organization's needs.

My advice is simple: compare the total value, not just the quotation.

A small saving at the beginning is not worth much if the audit process creates confusion or fails to provide useful feedback.


7. Practical Tips to Pass an ISO 45001 Audit Without Creating Fake “Audit Documents”

Here are the techniques I find most useful.

Tip 1: Follow the worker's journey

Pick a real job and follow it from beginning to end.

For example:

Receive material → move material → operate machine → inspect product → clean equipment → dispose of waste

At each stage, ask:

  • What can hurt someone?

  • What control is in place?

  • Who is responsible?

  • What evidence shows the control works?

This is much more useful than reviewing documents randomly.

Tip 2: Interview employees before the audit

Ask workers simple questions:

  • What are the biggest safety risks in your job?

  • What PPE do you need?

  • What do you do if equipment becomes unsafe?

  • How do you report a hazard?

  • What happens during an emergency?

  • Who do you contact if you need help?

Do not tell workers to memorize answers.

If they understand the workplace, natural answers are better.

Tip 3: Check the top risks first

Do not spend 80% of your preparation time fixing small administrative issues while a serious machine hazard remains.

Prioritize risks according to their potential consequences and likelihood.

Tip 4: Match records to reality

Choose several records and trace them backward.

For example, select a maintenance record.

Then visit the machine.

Does the machine match the record?

Select a training record.

Then talk to the employee.

Does the employee understand the task?

Select a corrective action.

Then inspect the original problem.

Has it actually been fixed?

This type of traceability is extremely powerful.

Tip 5: Do a realistic mock audit

A useful mock audit should not simply ask:

"Do you have a procedure?"

Instead, ask:

"Show me how this procedure works."

If the company says employees inspect machines every morning, go to the machine.

If it says workers report near misses, ask to see a recent example.

If it says emergency drills are evaluated, find the evaluation.

This exposes gaps quickly.

Tip 6: Keep documents controlled and understandable

A document is useful when the right person can find it and understand it.

Avoid creating 50-page procedures for a task that workers can understand from a two-page instruction with clear pictures.

The goal is control, not paperwork.

Tip 7: Never coach employees to hide problems

This is one of my strongest recommendations.

If employees discover a problem during an audit, report it honestly.

A mature organization does not need to pretend that nothing ever goes wrong.

What matters is whether the organization recognizes the issue, controls the immediate risk, investigates the cause, and improves the system.


8. Frequently Asked Questions About an ISO 45001 Audit

How often does an ISO 45001 audit happen?

The exact audit schedule depends on the certification arrangement and applicable certification rules.

A certification cycle normally includes an initial certification process followed by periodic surveillance activities and subsequent recertification.

The important point is that certification is not normally a one-time event.

The organization needs to maintain its management system over time.

What documents should I prepare for an ISO 45001 audit?

The exact evidence depends on the organization's activities and system.

Common areas include:

  • OH&S policy

  • Scope of the management system

  • Hazard identification and risk assessment

  • Applicable legal and other requirements

  • Objectives and plans

  • Roles and responsibilities

  • Training and competence records

  • Operational controls

  • Emergency preparedness

  • Incident investigations

  • Internal audits

  • Management reviews

  • Corrective actions

  • Monitoring and measurement records

However, I would not recommend creating documents simply because you think an auditor wants to see them.

Start with the actual process.

Then create the information needed to control and demonstrate that process.

What happens if an auditor finds a nonconformity?

A nonconformity means the audit has identified a failure to meet a relevant requirement.

The organization generally needs to understand the problem, take appropriate action, determine the cause where required, and provide evidence of correction and corrective action according to the certification body's process.

The important thing is not to panic.

A finding is useful information.

The wrong response is to fix the document while leaving the real problem untouched.

Can a small company pass an ISO 45001 audit?

Yes.

Company size does not automatically determine whether the management system can work.

A small factory may actually have an advantage because communication can be faster and responsibilities can be clearer.

The system should be appropriate to the organization's size, activities, risks, and complexity.

What is the biggest mistake companies make before an ISO 45001 audit?

In my experience, one of the biggest mistakes is treating the audit as a document competition.

Companies sometimes spend enormous effort making procedures look perfect while paying less attention to what happens on the factory floor.

I would reverse that order.

Fix the real risk first. Then make sure the system and records accurately describe what you do.


Conclusion: The Best ISO 45001 Audit Is the One That Helps You Find Problems Early

When I conduct or prepare for an ISO 45001 audit, I do not think the real goal is simply to get through the audit with no findings.

The bigger goal is to understand whether the organization can consistently identify risks, control them, listen to workers, respond to incidents, and improve its way of working.

A certificate can demonstrate that a management system has been assessed.

But the real test happens every day.

It happens when a machine breaks down.

It happens when a worker notices an unsafe condition.

It happens when a contractor arrives unexpectedly.

It happens during a night shift.

It happens when production is under pressure.

It happens during an emergency.

That is why I encourage companies to prepare for an ISO 45001 audit by asking a simple question:

“If an auditor followed our employees through a normal working day, would our actual behavior match our documented system?”

If the answer is yes, you are probably starting from a strong position.

If the answer is no, that is not a reason to panic.

It is a reason to improve.

At GAIA Standard Technical Service Co., Ltd., we approach auditing and certification from that practical perspective. Established in 2021, GAIA provides third-party auditing, certification, and verification services with a focus on international ISO systems, occupational health and safety, social responsibility, environmental protection, green and low-carbon development, sustainability, and supply-chain requirements.

Our organization has been approved by China's Certification and Accreditation Administration for relevant third-party certification activities, and our qualifications and service capabilities also cover international certification and verification needs. We bring together professionals with management, auditing, certification, and industry experience so that assessments can connect management-system requirements with actual business operations.

For companies preparing for an ISO 45001 audit, my final advice is straightforward:

Do not prepare to impress the auditor. Prepare to protect your people.

When the safety system genuinely works for employees, the audit becomes much easier to understand.

The paperwork becomes evidence of what the company actually does.

The interview questions become conversations rather than rehearsed answers.

And the audit becomes what it should have been from the beginning: a practical opportunity to identify weaknesses before those weaknesses become injuries, disruptions, or costly business problems.

संबंधित टैग: ISO45001 price ISO 45001 audit ISO 45001 fees
Follow the GAIA

Scan QR code

GAIA

Business consultation

Contact Information
  • +86 510-85218007
  • service@gaiasts.com
  • 2-2-716, 717 Xiangjiang Road, Xinwu District, Wuxi City, Jiangsu Province
Follow Us
  • Facebook
    Facebook
  • LinkedIn
    LinkedIn
  •  Youtube
    Youtube
  • Twitter
    Twitter
  •  Google+
    Google+
साइट मानचित्र

Copyright @ GAIA Standard Technical Service Co., Ltd.  All rights reserved 

Technical Support: Wuxi website construction 

यह वेबसाइट यह सुनिश्चित करने के लिए कुकीज़ का उपयोग करती है कि आपको हमारी वेबसाइट पर सर्वोत्तम अनुभव मिले।

स्वीकार करना अस्वीकार करना