Skip to content

Evidence request lists

ISO 45001

Evidence request list. 39 controls, 39 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Context

ISO45001-4.1
Understanding the organization and its context

Determine external and internal issues relevant to OH&S management system purpose and ability to achieve intended outcomes.

Artefacts an auditor will ask for
  • PESTLE/SWOT for OH&S
  • Context register
  • Strategic OH&S issues log
Where this commonly fails
  • No OH&S-specific context
  • Stale issue list
ISO45001-4.2
Needs and expectations of workers and interested parties

Identify workers and other interested parties and determine their relevant needs, expectations and which become compliance obligations.

Artefacts an auditor will ask for
  • Interested party register
  • Worker consultation records
  • Compliance obligations register
Where this commonly fails
  • Contractors omitted
  • No worker rep input
ISO45001-4.3
Determining scope of OH&S management system

Define boundaries and applicability of OH&S MS including activities, products, services and workplaces under organizational control.

Artefacts an auditor will ask for
  • Documented OH&S MS scope
  • Site/activity list
  • Exclusion rationale
Where this commonly fails
  • Mobile workers excluded
  • Contractor scope vague

ISO 45001: OH&S Policy & Planning

ISO45001-01
OH&S policy and commitment

OH&S policy and commitment. Control from ISO 45001 framework, domain: ISO 45001: OH&S Policy & Planning.

Artefacts an auditor will ask for
  • OH&S policy statement
  • Hazard register
  • Legal register
  • Worker consultation records
Where this commonly fails
  • Stale hazard inventory
  • Missing legal updates
  • Token consultation
  • Objectives without measures
ISO45001-02
Hazard identification and risk assessment

Hazard identification and risk assessment. Control from ISO 45001 framework, domain: ISO 45001: OH&S Policy & Planning.

Artefacts an auditor will ask for
  • OH&S policy statement
  • Hazard register
  • Legal register
  • Worker consultation records
Where this commonly fails
  • Stale hazard inventory
  • Missing legal updates
  • Token consultation
  • Objectives without measures
ISO45001-03
Legal and regulatory compliance

Legal and regulatory compliance. Control from ISO 45001 framework, domain: ISO 45001: OH&S Policy & Planning.

Artefacts an auditor will ask for
  • OH&S policy statement
  • Hazard register
  • Legal register
  • Worker consultation records
Where this commonly fails
  • Stale hazard inventory
  • Missing legal updates
  • Token consultation
  • Objectives without measures
ISO45001-04
OH&S objectives and action plans

OH&S objectives and action plans. Control from ISO 45001 framework, domain: ISO 45001: OH&S Policy & Planning.

Artefacts an auditor will ask for
  • OH&S policy statement
  • Hazard register
  • Legal register
  • Worker consultation records
Where this commonly fails
  • Stale hazard inventory
  • Missing legal updates
  • Token consultation
  • Objectives without measures
ISO45001-05
Worker consultation and participation

Worker consultation and participation. Control from ISO 45001 framework, domain: ISO 45001: OH&S Policy & Planning.

Artefacts an auditor will ask for
  • OH&S policy statement
  • Hazard register
  • Legal register
  • Worker consultation records
Where this commonly fails
  • Stale hazard inventory
  • Missing legal updates
  • Token consultation
  • Objectives without measures

ISO 45001: Operational Controls

ISO45001-06
Elimination and substitution of hazards

Elimination and substitution of hazards. Control from ISO 45001 framework, domain: ISO 45001: Operational Controls.

Artefacts an auditor will ask for
  • OH&S policy statement
  • Hazard register
  • Legal register
  • Worker consultation records
Where this commonly fails
  • Stale hazard inventory
  • Missing legal updates
  • Token consultation
  • Objectives without measures
ISO45001-07
Engineering and administrative controls

Engineering and administrative controls. Control from ISO 45001 framework, domain: ISO 45001: Operational Controls.

Artefacts an auditor will ask for
  • Control hierarchy register
  • PPE issue log
  • Emergency response plan
  • Contractor safety pack
Where this commonly fails
  • PPE as first resort
  • Untested emergency drills
  • No contractor onboarding
  • Missing control review cycle
ISO45001-08
Personal protective equipment management

Personal protective equipment management. Control from ISO 45001 framework, domain: ISO 45001: Operational Controls.

Artefacts an auditor will ask for
  • Incident investigation report
  • OH&S audit plan
  • Management review minutes
  • Corrective action register
Where this commonly fails
  • Root cause not identified
  • Audit findings not closed
  • No trend analysis
  • Lessons not shared
ISO45001-09
Emergency preparedness and response

Emergency preparedness and response. Control from ISO 45001 framework, domain: ISO 45001: Operational Controls.

Artefacts an auditor will ask for
  • Control hierarchy register
  • PPE issue log
  • Emergency response plan
  • Contractor safety pack
Where this commonly fails
  • PPE as first resort
  • Untested emergency drills
  • No contractor onboarding
  • Missing control review cycle
ISO45001-10
Contractor and visitor safety management

Contractor and visitor safety management. Control from ISO 45001 framework, domain: ISO 45001: Operational Controls.

Artefacts an auditor will ask for
  • Control hierarchy register
  • PPE issue log
  • Emergency response plan
  • Contractor safety pack
Where this commonly fails
  • PPE as first resort
  • Untested emergency drills
  • No contractor onboarding
  • Missing control review cycle

ISO 45001: Performance & Improvement

ISO45001-11
Incident investigation and reporting

Incident investigation and reporting. Control from ISO 45001 framework, domain: ISO 45001: Performance & Improvement.

Artefacts an auditor will ask for
  • Incident investigation report
  • OH&S audit plan
  • Management review minutes
  • Corrective action register
Where this commonly fails
  • Root cause not identified
  • Audit findings not closed
  • No trend analysis
  • Lessons not shared
ISO45001-12
OH&S monitoring and measurement

OH&S monitoring and measurement. Control from ISO 45001 framework, domain: ISO 45001: Performance & Improvement.

Artefacts an auditor will ask for
  • Incident investigation report
  • OH&S audit plan
  • Management review minutes
  • Corrective action register
Where this commonly fails
  • Root cause not identified
  • Audit findings not closed
  • No trend analysis
  • Lessons not shared
ISO45001-13
Internal OH&S audit program

Internal OH&S audit program. Control from ISO 45001 framework, domain: ISO 45001: Performance & Improvement.

Artefacts an auditor will ask for
  • Incident investigation report
  • OH&S audit plan
  • Management review minutes
  • Corrective action register
Where this commonly fails
  • Root cause not identified
  • Audit findings not closed
  • No trend analysis
  • Lessons not shared
ISO45001-14
Management review and continual improvement

Management review and continual improvement. Control from ISO 45001 framework, domain: ISO 45001: Performance & Improvement.

Artefacts an auditor will ask for
  • Incident investigation report
  • OH&S audit plan
  • Management review minutes
  • Corrective action register
Where this commonly fails
  • Root cause not identified
  • Audit findings not closed
  • No trend analysis
  • Lessons not shared
ISO45001-15
Corrective actions and lessons learned

Corrective actions and lessons learned. Control from ISO 45001 framework, domain: ISO 45001: Performance & Improvement.

Artefacts an auditor will ask for
  • Incident investigation report
  • OH&S audit plan
  • Management review minutes
  • Corrective action register
Where this commonly fails
  • Root cause not identified
  • Audit findings not closed
  • No trend analysis
  • Lessons not shared

Improvement

ISO45001-10.2
Incident, nonconformity and corrective action

Establish processes for reporting, investigating and taking action to control and correct incidents and nonconformities.

Artefacts an auditor will ask for
  • Incident reports
  • Root cause analyses
  • ICAM/TapRooT records
  • CAPA register
Where this commonly fails
  • Blame-focused investigation
  • Near-miss under-reported
ISO45001-10.3
Continual improvement

Continually improve suitability, adequacy and effectiveness of OH&S MS to enhance OH&S performance.

Artefacts an auditor will ask for
  • Improvement initiative register
  • Trend analysis
  • Best practice sharing
Where this commonly fails
  • Status quo bias
  • No benchmarking

Leadership

ISO45001-5.1
Leadership and commitment

Top management demonstrates leadership for OH&S MS including taking accountability for prevention of work-related injury and ill health.

Artefacts an auditor will ask for
  • CEO OH&S statement
  • Management review minutes
  • Visible felt leadership records
Where this commonly fails
  • Delegated to HSE only
  • No site walks
ISO45001-5.2
OH&S policy

Establish, implement and maintain OH&S policy with commitments to safe and healthy working conditions, hazard elimination and worker consultation.

Artefacts an auditor will ask for
  • Signed OH&S policy
  • Communication evidence
  • Policy review log
Where this commonly fails
  • Missing consultation commitment
  • Not communicated to contractors
ISO45001-5.3
Roles, responsibilities and authorities

Assign and communicate responsibilities and authorities for relevant roles in the OH&S MS.

Artefacts an auditor will ask for
  • RACI for OH&S
  • Position descriptions
  • Org chart with OH&S roles
Where this commonly fails
  • No worker-level accountability
  • HSE manager bottleneck
ISO45001-5.4
Consultation and participation of workers

Establish processes for consultation and participation of workers, including non-managerial workers, at all applicable levels.

Artefacts an auditor will ask for
  • HSE committee minutes
  • Toolbox talk records
  • Suggestion system stats
Where this commonly fails
  • Token committee
  • No non-managerial input

Operation

ISO45001-8.1.2
Eliminating hazards and reducing OH&S risks

Establish processes for elimination of hazards and reduction of OH&S risks using hierarchy of controls.

Artefacts an auditor will ask for
  • Hierarchy of controls applied per hazard
  • Engineering control register
  • Design reviews
Where this commonly fails
  • PPE as primary control
  • No design out
ISO45001-8.1.3
Management of change

Establish process for implementation and control of planned temporary or permanent changes that impact OH&S performance.

Artefacts an auditor will ask for
  • MOC procedure
  • Pre-startup safety review
  • Change register
Where this commonly fails
  • Temp changes bypass MOC
  • No HAZOP on changes
ISO45001-8.1.4
Procurement and contractors

Coordinate procurement processes including contractors and outsourced functions to ensure conformity with OH&S MS requirements.

Artefacts an auditor will ask for
  • Contractor prequalification
  • Site induction records
  • Contractor performance reviews
Where this commonly fails
  • No prequalification
  • Lowest cost wins
ISO45001-8.2
Emergency preparedness and response

Establish, implement and maintain processes to prepare for and respond to potential emergency situations.

Artefacts an auditor will ask for
  • Emergency response plan
  • Drill records
  • First aider register
  • Evacuation diagrams
Where this commonly fails
  • Drills not tested
  • No scenario variation

Performance evaluation

ISO45001-9.1
Monitoring, measurement, analysis and evaluation

Determine what, methods, when and analyse OH&S performance and effectiveness of OH&S MS.

Artefacts an auditor will ask for
  • KPI reports
  • Leading indicators
  • Calibration of monitoring equipment
Where this commonly fails
  • Lagging only
  • No statistical analysis
ISO45001-9.1.2
Evaluation of compliance

Plan, establish, implement and maintain processes to evaluate fulfilment of legal and other requirements.

Artefacts an auditor will ask for
  • Compliance evaluation reports
  • Action items log
  • Regulator correspondence
Where this commonly fails
  • Annual only
  • No documented evaluation
ISO45001-9.2
Internal audit

Conduct internal audits at planned intervals to provide information on whether OH&S MS conforms and is effectively implemented.

Artefacts an auditor will ask for
  • Audit programme
  • Audit reports
  • Auditor competence records
Where this commonly fails
  • Auditor independence weak
  • Findings not closed
ISO45001-9.3
Management review

Top management reviews OH&S MS at planned intervals to ensure continuing suitability, adequacy and effectiveness.

Artefacts an auditor will ask for
  • Management review minutes
  • Input/output evidence
  • Action register
Where this commonly fails
  • No worker input
  • Skipped inputs

Planning

ISO45001-6.1.2
Hazard identification and assessment of risks

Establish ongoing proactive process for hazard identification considering routine and non-routine activities, human factors and emergency situations.

Artefacts an auditor will ask for
  • Hazard register
  • Job safety analyses
  • Risk assessment matrix
  • Human factors review
Where this commonly fails
  • Only physical hazards
  • No psychosocial assessment
ISO45001-6.1.3
Determination of legal and other requirements

Determine and have access to up-to-date legal and other requirements applicable to OH&S hazards.

Artefacts an auditor will ask for
  • Legal register
  • Compliance evaluation
  • Subscription to regulatory updates
Where this commonly fails
  • Outdated register
  • No state/jurisdictional split
ISO45001-6.1.4
Planning action

Plan actions to address risks, opportunities, legal requirements and emergency situations and integrate into OH&S MS processes.

Artefacts an auditor will ask for
  • OH&S action plan
  • Hierarchy of controls applied
  • Integration evidence
Where this commonly fails
  • PPE-first thinking
  • No elimination/substitution
ISO45001-6.2
OH&S objectives and planning to achieve them

Establish measurable OH&S objectives at relevant functions and levels consistent with policy.

Artefacts an auditor will ask for
  • SMART OH&S objectives
  • KPI dashboards
  • Owner assignments
Where this commonly fails
  • Lagging only
  • No leading indicators

Support

ISO45001-7.2
Competence

Determine necessary competence of workers affecting OH&S performance and ensure they are competent through education, training or experience.

Artefacts an auditor will ask for
  • Training matrix
  • Licences/tickets register
  • Competency assessments
Where this commonly fails
  • Contractor competence not verified
  • Refreshers overdue
ISO45001-7.3
Awareness

Workers aware of OH&S policy, their contribution to OH&S MS, incidents and outcomes, hazards relevant to them and right to remove themselves from imminent danger.

Artefacts an auditor will ask for
  • Induction records
  • Toolbox talk logs
  • Stop-work authority policy
Where this commonly fails
  • No stop-work rights communicated
ISO45001-7.4
Communication

Determine internal and external communications relevant to OH&S MS including what, when, with whom and how.

Artefacts an auditor will ask for
  • Communication matrix
  • Safety alerts
  • Crisis comms plan
Where this commonly fails
  • No language accommodations
  • Top-down only
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 45001 framework page.