Quick Summary: A gap analysis template is a crucial tool for businesses aiming for ISO 45001 certification. It compares your current Occupational Health and Safety (OH&S) system against the standard's requirements, identifying specific shortfalls. This structured process creates a clear, prioritized roadmap to improve safety, ensure compliance, and prepare for audits.

An ISO 45001 gap analysis is your starting block for getting certified. Think of it as a tool that compares your current Occupational Health and Safety (OH&S) system against the standard's rulebook. It flags exactly where you're falling short, giving you a clear roadmap to certification and helping you land those major tenders.

If you’re in a high-risk industry like construction or manufacturing, the idea of tackling the ISO 45001 standard can feel pretty daunting. This guide is here to cut through the complexity, beginning with a gap analysis template designed for real-world use. We'll show you why this is more than just a box-ticking exercise. It's a strategic move to genuinely improve worker safety, slash incident rates, and give your business a serious competitive edge.

Forget generic checklists. What we'll cover is a structured approach that Australian businesses are using right now to get audit-ready. You’ll learn how to break down a complex standard into a straightforward action plan and lay the foundations for a certification that actually makes a difference on the ground.

Why a Gap Analysis is Your First Step to ISO 45001 Certification

Getting ISO 45001 certified isn't just about paperwork; it's about making safety part of your company's DNA. But before you can build that culture, you have to know where you stand today. That’s why a gap analysis is the most important tool you'll use at the start of this journey.

Men in hard hats review documents on a construction site, referencing ISO 45001 health and safety.

It’s essentially a health check for your OH&S management system. It methodically lines up what you're currently doing—your processes, procedures, and documents—against every single requirement in the ISO 45001 standard.

The Strategic Value Beyond Compliance

The real power of a gap analysis is that it gives you a clear, prioritised roadmap. Instead of guessing where to put your time and money, you get a detailed report showing you exactly where the problems are. This makes the path to certification much faster and more cost-effective.

The process helps you:

  • Pinpoint specific gaps: Know exactly where your system doesn't meet the standard.
  • Avoid audit surprises: Find and fix issues yourself before an external auditor points them out.
  • Focus your resources: Put your budget and team's effort into the areas that need it most.
  • Build a case for change: Use the findings to show management why new safety initiatives are necessary.

The momentum behind ISO 45001 in Australia is impossible to ignore. Certifications have exploded from 6,157 in 2023 to 9,467 in 2024—a massive 53.7% jump that now ranks us 6th in the world. A gap analysis helps you get there by mapping what you do now against the standard's clauses, such as leadership commitment (Clause 5), and finding weaknesses, like not consulting workers properly. You can read more about the benefits of ISO 45001 certification and what it means for Australian businesses.

Turning a Standard into an Action Plan

When it's all said and done, a proper gap analysis turns the dense, formal language of the ISO 45001 standard into a simple, actionable to-do list.

A gap analysis isn't an admission of failure; it's the first step towards building a world-class safety system. It provides the clarity needed to move from uncertainty to a clear, actionable plan for achieving certification.

It shifts your business from reacting to problems to proactively building a strong, compliant OH&S framework. This is the foundation for a lasting safety culture, putting you on the fast track to becoming audit-ready. For a deeper dive into the whole process, have a look at our comprehensive guide on ISO 45001 certification in Australia.

Getting Started With Your Gap Analysis Template

Having a great tool is one thing, but knowing how to wield it is what really counts. Our ISO 45001 gap analysis template isn't just a checklist; when used correctly, it becomes the central hub for your entire compliance project.

Let's walk through how to turn this spreadsheet into a practical, action-oriented plan for your business.

First things first, you'll need to download the template. It's an editable file, built with the realities of Australian Work Health and Safety (WHS) in mind, so it aligns perfectly with what local auditors are looking for.

[Download Your Free ISO 45001 Gap Analysis Template Here]

A detailed gap analysis template document on a wooden desk with a laptop and pen, ready for business planning.

Once you've got it open, you'll see it’s laid out in a series of columns. Each one has a specific job to do, guiding you from understanding the standard to taking decisive action.

Making Sense of the Template Columns

I've structured the template to follow a logical path—from the official requirement to your real-world solution. Here’s a breakdown of each column and what you need to put in it.

  • ISO 45001 Clause: This is your starting point. You'll find the specific clause number and a quick summary of what it covers (e.g., "5.2 OH&S Policy"). These are all pre-filled, so you can focus on the analysis, not the data entry.

  • Current Evidence: Time to put on your detective hat. For every single clause, you need to document what your business is actually doing right now. Be brutally honest and specific. Instead of a vague "We have a safety policy," a much better entry would be: "OH&S Policy signed by the MD (Jan 2024), on the workshop noticeboard and saved in the 'Policies' folder on the shared drive." Think about what you could show an auditor—documents, records, photos, meeting minutes, you name it.

  • Compliance Status: This is your gut-check moment, boiled down to a simple dropdown menu. Based on the evidence you've collected for each clause, you’ll assign one of three statuses:

    • Yes: You’ve got this covered and the evidence to prove it.
    • No: Nothing is in place for this requirement. It's a blank slate.
    • Partial: You're doing something, but it doesn't quite meet the full requirement of the standard.

This quick-glance status gives you an immediate picture of where your biggest challenges and quick wins are.

Moving From Gaps to Actions

The last two columns are where the real magic happens. This is where you shift from just identifying problems to creating a clear plan to fix them.

Identified Gap
If you’ve marked a clause as "No" or "Partial," this column is for explaining why. What’s missing? A good gap description gets straight to the point.

For instance, when looking at Clause 7.3 Awareness, a lazy description might be "Staff don't know the policy." A much more useful one is: "No induction record to prove new field staff have read and understood the OH&S Policy or their specific safety duties before starting on site."

See the difference? The second one gives you something concrete to work with.

Required Action
This is the final, most important step. For every gap you've just described, you need to outline a clear, measurable action to close it. What exactly needs to be done?

Building on our example, the required action would be something like: "Update the New Starter Induction Pack to include a sign-off sheet for the OH&S Policy. Make it mandatory for HR to scan and save the signed sheet to the employee's digital file."

By following this structured approach, your gap analysis template transforms from a static document into a dynamic roadmap. It’s the blueprint that will guide every decision you make on the path to a successful ISO 45001 audit.

Right, let's get into the nitty-gritty. With your gap analysis template fired up, it's time to dive into the core of the assessment. This is where we’ll walk through the guts of the ISO 45001 standard, from Clause 4 right through to Clause 10, and see how your current operations stack up.

Forget theory. This is a practical, sleeves-rolled-up look at what your business actually does every single day. Put on your internal auditor hat for a moment. The mission is to find real, tangible evidence – documents, records, even just observing how people work – that proves you're meeting the spirit of each clause. For every line item, the questions are simple: "How do we do this?" and, more importantly, "Where's the proof?"

Clause 4: Context of the Organisation

Think of this clause as the foundation of your entire OH&S system. It’s all about getting a clear picture of your organisation's unique world. What are the internal and external pressures you face? What do your workers, regulators, and clients actually need and expect from you when it comes to safety?

Here's the kind of evidence you should be looking for:

  • A list of internal and external issues that could impact your OH&S performance. This might include new WHS legislation, high staff turnover, or the introduction of a new piece of heavy machinery.
  • A register of your "interested parties" and what they care about. For example, workers need safe equipment, while major clients demand proof of your safety compliance before signing a contract.
  • A clearly documented scope for your OH&S management system.

The goal here isn't just to tick boxes. It's to show you’ve genuinely thought about why your safety system exists and what factors, both inside and outside your walls, are shaping it.

Clause 5: Leadership and Worker Participation

I’ve seen it a hundred times: without real commitment from the top, an OH&S system is nothing more than a dust-gathering folder on a shelf. This clause is about proving that safety is driven by leadership and that everyone, at every level, has a voice.

Start by hunting for a signed OH&S policy. But don't just stop there. Is it actually communicated? Look for it on noticeboards, in induction packs, and ask a few people on the floor if they know what it says. That tells you if it's a living document or just wallpaper. Next, get your hands on management meeting minutes. Is safety a regular agenda item? Are incident reports discussed? That’s pure gold for an auditor.

A huge part of this is proving worker participation. You're searching for evidence of genuine consultation. This could be minutes from safety committee meetings, toolbox talk records where workers have raised concerns, or a stack of completed hazard report forms submitted by your team.

Clause 6: Planning

Good safety isn't about reacting to incidents; it's about proactively identifying what could go wrong and figuring out how to do things better. That's what Clause 6 is all about. It requires a systematic approach to understanding and managing your risks and opportunities.

Your main piece of evidence here is going to be your risk management process. You'll need to find a comprehensive risk register that clearly identifies OH&S hazards, assesses their risk levels, and details the control measures you have in place. This is also where you show how you stay on top of all your legal and other obligations, making sure you’re always compliant with WHS laws.

Mapping Evidence to Key ISO 45001 Clauses

To help you pinpoint exactly what to look for, I've put together a quick-reference table. This maps some of the key clauses to the kind of documentation and evidence you'll need to gather during your gap analysis.

ISO 45001 ClauseClause FocusExample Evidence to Look For
4.2Understanding the needs of interested partiesStakeholder register, client contracts with safety clauses, worker survey results.
5.2OH&S PolicyA signed, dated, and communicated policy document; evidence of it on noticeboards or intranet.
6.1.2Hazard Identification and Risk AssessmentA comprehensive risk register, Safe Work Method Statements (SWMS), job safety analyses (JSAs).
7.2CompetenceTraining records, skills matrix, licences (e.g., forklift, EWP), induction checklists.
8.1Operational Planning and ControlDocumented procedures, permit-to-work forms, pre-start checklists, maintenance records.
9.1.1Monitoring, Measurement, and AnalysisSite inspection reports, equipment calibration records, incident statistics (LTIFR).
10.2Incident, Nonconformity, and Corrective ActionCompleted incident investigation reports, corrective action register, root cause analysis documents.

Having these types of documents ready will make your analysis—and any future audits—much smoother.

Clause 7: Support

This clause covers all the essential resources you need to make your OH&S system actually function. It’s about having competent people, the right tools and infrastructure, and clear lines of communication.

Dig around for things like:

  • Training records: Can you prove your workers are trained and competent for their jobs, especially for high-risk tasks?
  • Induction checklists: Is there a formal process showing new starters are told about the OH&S policy and their safety duties from day one?
  • Communication methods: How do you get the word out about safety alerts, policy updates, or incident learnings? Find examples of emails, newsletters, or toolbox talk minutes.

Clause 8: Operation

Welcome to the "doing" part of the standard. This covers the day-to-day controls you use to manage risks and stop people from getting hurt. This is often where you'll find the most evidence.

You’ll be digging into your hazard identification logs, Safe Work Method Statements (SWMS), and any permit-to-work systems. An auditor will want to see more than just a plan for emergencies; they'll look for records of drills you've actually run and what you learned from them. Your risk assessment procedures will be under the microscope here.

The push for ISO 45001 in Australia is real, with certifications hitting 9,467 by 2024. A lot of this growth comes from WHS compliance pressures, forcing small and medium businesses to use a gap analysis template to get certified faster. These tools are fantastic for finding holes in your system, especially in areas like performance evaluation or continual improvement, which are critical when you're bidding for those big contracts.

Clause 9: Performance Evaluation

Let's be blunt: you can't improve what you don't measure. This clause is all about checking if your OH&S system is actually working. It requires you to monitor, measure, and evaluate your safety performance.

The evidence you need includes your own internal audit reports—are you actively looking for weaknesses in your own system? You'll also need management review meeting records, where senior leadership discusses the effectiveness of the entire OH&S system. On top of that, show how you're tracking against your safety objectives, like your Lost Time Injury Frequency Rate (LTIFR) targets.

Clause 10: Improvement

Finally, the standard demands a commitment to getting better over time. This clause looks at how you react to incidents and nonconformities and, just as importantly, how you proactively find ways to improve your OH&S performance.

Your incident investigation reports are the key piece of evidence here. Do they just point fingers, or do they perform a proper root cause analysis to find corrective actions that will stop it from happening again? You’ll also need to show a documented process for managing nonconformities and a log of the corrective actions you’ve taken. This is what closes the loop and proves your system can learn and evolve.

A Real-World Example: Gap Analysis for a Construction Business

Theory is one thing, but seeing how it all works in practice is where the real learning happens. So, let’s get our hands dirty and walk through a completed gap analysis template for a hypothetical construction company.

I've based this on a typical small-to-medium business I often see: a 50-person commercial construction company in Western Australia. We'll call them "WA Commercial Builders". This isn't just a generic placeholder; it's a realistic snapshot of the common challenges and compliance gaps a business of this size usually runs into.

Watching how day-to-day operational issues get translated into the structured format of the template is incredibly helpful. It gives you a solid reference point, showing you exactly how to document your own findings in a way that’s actually meaningful and points to clear, practical actions.

Setting the Scene: Our Hypothetical Company

WA Commercial Builders has been around for about a decade. They've got a decent safety record, but like many businesses, they lean heavily on informal processes and the gut-feel experience of their site supervisors.

The motivation for them? They need to land a major government infrastructure project, and ISO 45001 certification is a non-negotiable requirement. The gap analysis is their first big step towards getting there.

Let's zoom in on a few key rows from their completed template to see how different levels of compliance actually look on paper.

Example 1: Partial Compliance in Worker Consultation

This is a classic case I see all the time – a company is doing something, but it doesn't quite tick all the boxes required by the standard.

  • ISO 45001 Clause: 5.4 Consultation and participation of workers
  • Current Evidence: "Site supervisors hold informal 'toolbox talks' when new risks pop up. There’s no set schedule or any record of who was there."
  • Compliance Status: Partial
  • Identified Gap: The whole approach is ad-hoc and completely undocumented. There's zero proof that all workers are regularly consulted on OH&S matters, and their feedback isn't formally captured anywhere.
  • Required Action: "Implement a formal, weekly toolbox talk on every single site. A standardised sign-in sheet must be used to record attendees and topics. Completed sheets must be scanned and saved to the relevant project folder."

You can see how this entry pinpoints the problem. The intent to consult is there, but the lack of a formalised process and record-keeping is a definite gap. The required action is specific, measurable, and directly plugs that hole.

Example 2: A Major Gap in Management of Change

Next, let's look at a scenario where a critical process is completely missing. This is a common and dangerous blind spot for many growing businesses.

  • ISO 45001 Clause: 8.1.3 Management of change
  • Current Evidence: "New machinery or chemicals are brought on-site as needed. The site supervisor just gives everyone a quick verbal rundown on how to use it."
  • Compliance Status: No
  • Identified Gap: There is no documented process at all for assessing OH&S risks before new equipment, materials, or work procedures are introduced.
  • Required Action: "Develop and implement a formal 'Management of Change' procedure and a corresponding request form. The procedure must mandate a risk assessment, which has to be completed and approved by the OH&S Manager before any significant change is made on site."

This is a huge finding. Trust me, an auditor would see this and immediately flag it as a major non-conformance. Lacking a Management of Change process is a critical system failure because it means you're potentially exposing workers to completely unassessed risks every day.

Example 3: Full Compliance in Emergency Preparedness

Finally, it's just as important to document what you're already doing right. This isn’t just about patting yourself on the back; it builds a complete picture of your system and acknowledges your existing strengths.

  • ISO 45001 Clause: 8.2 Emergency preparedness and response
  • Current Evidence: "Emergency Evacuation Plans are posted on each site. We run an annual evac drill at the main office and on all long-term sites. We keep records of the drills, including timings and notes for improvement, in the central OH&S folder."
  • Compliance Status: Yes
  • Identified Gap: None.
  • Required Action: None.

In this case, WA Commercial Builders has a solid, documented process that squarely meets the clause's requirements. By filling out the template even for these areas, they create a comprehensive record of their entire OH&S system, which is pure gold when the auditors come knocking.

Hopefully, this real-world example shows you the true power of the gap analysis. It's not about finding fault; it's about gaining clarity. Each line item you fill in transforms a vague operational reality into a precise data point, giving you the foundation for a targeted and truly effective action plan.

From Gaps to Action: Building Your ISO 45001 Roadmap

Finding the gaps in your safety system is a fantastic start, but it's only half the battle. A list of what’s missing is just that—a list. The real work, and the real value, comes from turning that list into a smart, prioritised action plan that will not only get you through an audit but genuinely make your workplace safer.

This isn't about creating a massive to-do list that gathers dust. It’s about building a strategic roadmap that systematically closes every gap you've found, showing a clear commitment to improving your OH&S performance.

As you can see, the findings from your gap analysis—things like inconsistent safety talks or entire processes that are missing—all feed directly into a structured action plan.

Three-step compliance gap resolution process with Inconsistent Talks, No Process, and Action Plan.

This plan becomes the final, tangible output of all your hard work, transforming observations into a clear strategy for getting things done.

Focus on What Matters Most: Prioritising Your Gaps

Let's be honest: not all gaps carry the same weight. If you try to fix everything at once, you'll burn out your team and likely achieve very little. The secret is to prioritise ruthlessly, focusing on a mix of risk and compliance impact. A simple prioritisation matrix is your best friend here.

For each gap, ask yourself two simple questions:

  • What's the Risk Level? How likely is this to cause an incident or injury? (Think High, Medium, or Low).
  • What's the Compliance Impact? How seriously would an ISO 45001 auditor view this? (Think Major or Minor non-conformance).

For example, discovering you have "no formal process for managing new chemical risks" is a clear High Risk / Major Impact issue. That goes straight to the top of your list. On the other hand, finding an "OH&S policy not displayed on one of five noticeboards" is probably a Low Risk / Minor Impact item you can tackle later.

This approach ensures you're throwing your immediate resources at the problems that pose the biggest threat to your people and your certification hopes.

Laying Out Your Strategic Roadmap

With your priorities straight, it's time to build the action plan. This means taking each gap from your gap analysis template and breaking it down into clear, manageable tasks that people can actually act on.

For every high-priority gap, your action plan needs to spell out:

  • The Specific Actions: What, exactly, needs to be done? Get granular.
  • Who's Responsible: Assign a single person. "The safety team" is not an answer—when everyone is responsible, no one is.
  • The Deadline: When does this need to be finished? Be realistic but firm.
  • The Resources: What do you need to get it done? This could be a budget, new equipment, or outside help.

This level of detail turns a vague idea like "improve chemical safety" into a concrete project. Remember why this is so important: certified Australian organisations have a Total Recordable Injury Frequency Rate (TRIFR) of just 2.29 per million hours worked. Compare that to 10.4 for their non-certified peers—that's a massive 78% difference in safety outcomes.

Once your gap analysis points you in the right direction, sometimes you need specialist help to pick up the pace. Professional process improvement services can be invaluable for turning those insights into reality. A core part of this entire process is risk management, so if you need a refresher, take a look at our guide on what is a risk register. Taking this methodical approach doesn't just get you audit-ready; it builds a stronger, more resilient safety culture from the ground up.

Your Top Gap Analysis Questions, Answered

As you get stuck into your gap analysis, you're bound to have questions. It happens to everyone. Based on my experience helping countless businesses through this process, I've pulled together answers to the most common queries that pop up.

How Much Detail is Too Much (or Too Little)?

You're aiming for the sweet spot: specific enough to be actionable. Think of it this way—could you hand your notes to a colleague, and would they know exactly what the problem is and how to start fixing it?

For instance, a vague note like "fix training records" is pretty useless. It doesn't tell anyone what's actually wrong.

A much better, actionable entry would be: "No evidence of forklift competency refresher training for workshop staff within the last two years. Action: Schedule refresher training for all 8 workshop operators by the end of Q3 and upload certificates to their digital HR files."

The trick is to document your findings with enough detail to be both auditable and actionable.

What if the Standard Asks for a Document We Don't Have?

Don't panic—this is precisely what a gap analysis is for! Finding a missing document isn't a failure; it's a successful finding. It means the process is working.

Let's say ISO 45001 requires a documented "Management of Change" procedure, but you've never created one. That's a clear gap. You'd simply note it down:

  • Compliance Status: No
  • Identified Gap: We don't have a documented procedure to assess OHS risks before we bring in new equipment or change our processes.
  • Required Action: Draft a Management of Change procedure, get it approved, and make sure we train managers on how to use it.

This is a classic example of the gap analysis doing its job. It's a tool to systematically find these omissions so you can get them sorted before an external auditor walks through the door. It’s a finding, not a failure.

Realistically, How Long is This Going to Take?

Honestly, it depends on the size and complexity of your business. There's no single answer.

  • For a smaller business, say 10-20 employees with relatively simple operations, you could probably knock out a thorough analysis in one to two weeks.
  • A larger company with multiple sites, complex risks, and more moving parts might need several weeks or even a month.

The real time-sink isn't the number of clauses in the standard; it's how easily you can get your hands on the evidence. If your records are well-organised and accessible, things will move much faster. The main thing is to be thorough, not just fast. Rushing the gap analysis almost always means missing something critical that an auditor will find later.


Ready to bridge your compliance gaps with expert guidance? The team at ISO45001 Consulting has a 100% certification success rate, helping Australian businesses like yours navigate the entire process. We replace guesswork with a clear, actionable plan. Get in touch to start your journey to ISO 45001 certification.