ISO 45001 Internal Audit: How to Plan, Conduct and Report Effectively
Internal audit is the heartbeat of ISO 45001. It’s not a compliance checkbox. It’s your system’s early warning mechanism—the place where gaps are found before they become incidents, before they become audit findings, before they become regulatory issues.
Clause 9.2 requires you to conduct internal audits at planned intervals. How you interpret and execute this requirement separates organisations that merely hold certificates from those that genuinely manage health and safety.
Understanding ISO 45001 Clause 9.2: The Requirements
Clause 9.2 isn’t lengthy, but it’s comprehensive. It requires that you:
- Conduct internal audits at planned intervals to determine whether your system conforms to ISO 45001
- Determine audit criteria, scope, frequency, and methods
- Ensure internal auditors are competent and impartial
- Evaluate and report findings
- Ensure management acts on audit findings
Each requirement has teeth. “Planned intervals” doesn’t mean “whenever we remember.” “Competent and impartial” doesn’t mean “someone who knows the business.” “Evaluate and report findings” doesn’t mean “send an email with a list of issues.”
Let’s break down what each requirement actually means in practice.
Building Your Annual Audit Programme: Risk-Based Planning
Your audit programme is your annual schedule. It determines which areas you’ll audit, when, how deeply, and why. A good programme is risk-based—you audit areas with higher safety risk more frequently or deeply than lower-risk areas.
How to Develop a Risk-Based Programme
Start with your HIRA. Which areas have the highest hazards and risks? Your construction site’s site management has higher risk than your office reception. Your chemical storage has higher risk than your stationery supplies. Your audit programme should reflect this.
Next, consider regulatory compliance. If your industry is heavily regulated, audit compliance areas annually. If you’ve had incidents in a particular area, audit it more frequently until you’ve verified the fix works.
Third, consider your system maturity. New processes need more scrutiny than embedded ones. If you’ve just implemented a new competence system, audit it twice in year one. If it’s been running well for two years, annual audit is adequate.
Frequency Guidelines
There’s no mandated frequency in ISO 45001. Common practice varies:
- High-risk areas: Quarterly or biannual audits
- Medium-risk areas: Biannual or annual audits
- Low-risk areas: Annual or 18-month audits
- Core processes (HIRA, competence, incident investigation, management review): Annual minimum
Your certification body will review your programme at Stage 1 and Stage 2. If your risk-based frequency is unreasonably low (e.g., auditing your highest-risk area once every two years), they’ll flag it. Conversely, if your frequency is excessive but your programme doesn’t demonstrate clear risk-based logic, they’ll question whether it’s truly planned.
The sweet spot: Annual audit of high-risk areas and core processes, biannual or triennial audit of lower-risk areas, with a documented justification for your chosen frequency.
Designing Your Audit Scope
Your annual programme should cover your entire system over a defined period (typically 1-3 years). If you have 20 operational areas, don’t audit only 5. Your external auditor will sample across all areas during certification audits. If they find major gaps in unaudited areas, that’s a credibility issue.
Your scope should cover:
- All operational areas (if multi-site, sample representative sites)
- All significant hazards and risk controls
- All core processes (HIRA, competence, incident investigation, consultation)
- Management system elements (documentation, records, communication)
Document your programme in writing. Show your risk-based logic. This becomes part of your system documentation that certification auditors review.
Internal Auditor Competence and Impartiality
An internal auditor must be competent and impartial. These are often in tension. Someone who knows your business intimately is competent but may lack impartiality. Someone impartial may lack technical knowledge. Your job is to navigate this tension.
What Competence Means
Your internal auditor needs:
- ISO 45001 Knowledge: Understanding of the standard’s requirements and how they apply to your organisation
- Audit Skills: Ability to plan audits, gather evidence, interview effectively, and write clear reports
- Technical Knowledge: Understanding of your operation, key hazards, and risk controls
- Communication Skills: Ability to explain findings clearly and respectfully without being dismissive or alarmist
Competence is demonstrated and documented. Have your internal auditors complete training (internal or external). Have them shadow an experienced auditor on one or two audits. Then assess whether they can conduct audits independently. Document this assessment.
Many organisations invest in external auditor training for internal staff—typically a 2-3 day course covering audit methodology, ISO 45001 requirements, and practical audit techniques. This is worth the investment.
What Impartiality Means
Impartiality means freedom from conflict of interest. Auditing your own work is not impartial. An operation supervisor auditing their own operation is not impartial. A maintenance manager auditing maintenance is not impartial.
This doesn’t mean you need external auditors. It means internal auditors should audit areas they’re not directly responsible for. A maintenance supervisor can audit health and safety administration. An administration officer can audit maintenance procedures. A site manager can audit a different site.
Document who conducts each audit and verify no conflicts of interest exist.
Building Your Auditor Pool
Small organisations often struggle here. If you have five people total, finding impartial internal auditors is impossible. In this case, consider:
- Rotating roles: different people audit different areas each year
- Using external auditors: contracting a third party to conduct some internal audits
- Including management: supervisors and managers can audit core processes if properly trained
- Multi-organisation consortia: if you’re in an industry group, members can audit each other’s systems
Even if you’re small, strive for impartiality. If you must audit your own area, at least have someone else review your audit findings before finalising them.
Conducting an Internal Audit: The Complete Process
A well-conducted audit follows a consistent methodology. This builds credibility and ensures you don’t miss issues.
Stage 1: Audit Planning
Before you walk into the audit, you’ve already done significant work. You’ve determined:
- Audit Objectives: What are you assessing? Compliance with ISO 45001? Specific risk control effectiveness? Recent incident investigation closure? Be clear.
- Audit Criteria: What standard are you measuring against? ISO 45001 clauses? Your own procedures? Regulatory requirements? List them.
- Audit Scope: Which areas, processes, or people are you auditing? What’s excluded?
- Audit Methods: Will you interview, observe, review documents, or all three?
- Audit Team: Who’s the lead auditor? Are there supporting auditors?
- Timeline: How many days? Who needs to participate?
You’ll communicate this to the area being audited. Yes, communicate it. Surprise audits aren’t best practice (though they’re sometimes useful for verifying authenticity). Usually, you’ll notify the area 1-2 weeks ahead, allowing them to prepare evidence.
Stage 2: Opening Meeting
Start with a brief opening meeting with the area manager. Explain the audit’s purpose, scope, timeline, and methodology. Answer questions. This sets the tone—you’re auditing the system, not the people.
Stage 3: Evidence Gathering
Now you collect evidence. Three primary methods:
Document Review: You examine procedures, records, and evidence. Is the competence procedure documented? Are training records complete? Is the HIRA current? Are incident investigation files complete?
Interviews: You ask people open-ended questions. “How do you identify hazards in your job?” “What happens when you find a hazard?” “Can you show me how you report it?” Good interview technique avoids leading questions and allows people to explain their understanding.
Observation: You observe work being performed. Do people follow documented procedures? Are controls actually used? Do people understand why controls exist?
The best audits combine all three. You review the hazard identification procedure, interview workers about how they identify hazards, and observe them actually identifying hazards during work.
Stage 4: Finding Determination
As you gather evidence, you assess whether the area conforms to your audit criteria. Where it does, you note conformance. Where it doesn’t, you identify findings.
A finding isn’t a guess. It’s based on evidence. You’ve reviewed the procedure, compared actual practice to the procedure, and found a gap. Document what the requirement is, what you actually found, and why it’s a gap.
Stage 5: Closing Meeting
Before you leave, meet with the area manager and discuss findings. Don’t surprise them at the report stage. Walk through what you found, why it’s a finding, and what they might do about it. Get their perspective. Sometimes they’ll have context you’re missing.
Stage 6: Report and Follow-Up
Document your audit findings in a clear report. Include audit scope, criteria, methodology, findings (classified as nonconformity or observation), and any positive areas where you found good practice. Share the report with relevant management.
Crucially, follow up on findings. If you identified a nonconformity, set a timeline for corrective action. If it’s an observation, agree on a response. Track closure. An internal audit with no follow-up is just documentation—it drives no improvement.
Classifying Internal Audit Findings
Internal audit findings differ from external audit findings, but the classification logic is similar.
Nonconformity: A failure to meet your documented procedure or ISO 45001 requirement. Example: Your procedure requires annual competence assessment, but three employees have no recent assessment record.
Observation: An advisory finding. The system’s working, but there’s room for improvement. Example: Your hazard identification process exists, but it hasn’t been updated in 18 months. Recommend reviewing for emerging hazards.
Opportunity for Improvement (OFI): A constructive suggestion for enhancement. Not a finding, just an idea. Example: “Consider implementing digital hazard reporting to speed up response time.”
Don’t overload reports with observations and OFIs. Focus on nonconformities and significant observations. Too many findings creates audit fatigue and reduces the signal-to-noise ratio.
Using Audit Findings to Drive Improvement
An audit is only valuable if findings lead to action. This is where many organisations fail. They conduct audits, identify issues, then do nothing.
The Corrective Action Process
For each nonconformity, the responsible area manager should document a corrective action. This should include:
- Root cause analysis (why the nonconformity exists)
- Corrective action plan (what you’ll do to fix it)
- Responsibility and timeline (who owns it, when it’s complete)
- Evidence that the fix worked (how you’ll verify closure)
The auditor or audit coordinator should track closure. Set a review date. Get evidence that the corrective action was implemented. Verify it addressed the root cause. Only then mark the finding closed.
This process—audit finding → corrective action → verification of closure—is central to ISO 45001. It’s how you turn potential problems into demonstrated improvements.
Common Internal Audit Mistakes and How to Avoid Them
After thousands of internal audits, patterns emerge. Here are the most frequent mistakes:
Mistake 1: Auditors Lack Competence
Appointing someone to audit internal controls without training them first is setting them up for failure. They won’t know what to look for. They’ll miss issues. Their findings won’t be credible.
Solution: Invest in training. Have auditors complete formal audit training or shadow an experienced auditor before conducting independent audits.
Mistake 2: Audits Aren’t Risk-Based
Auditing every area equally every year is inefficient. You’re auditing low-risk areas while potentially missing high-risk ones.
Solution: Develop an explicit risk-based programme. Document why you’ve chosen your frequency. Audit high-risk areas more frequently.
Mistake 3: No Corrective Action Follow-Up
You conduct the audit, issue the report, then lose track. Six months later, nobody’s addressed the findings.
Solution: Assign someone to track corrective actions. Set review dates. Follow up until closure is verified. This is non-negotiable.
Mistake 4: Audits Focus on Documentation, Not Reality
The auditor reviews procedures and documents but never observes actual work. They don’t interview workers. They don’t see whether controls actually work in practice.
Solution: Require observation and interviews as part of every audit. Don’t audit only on paper.
Mistake 5: Audit Reports Are Unclear
The report lists findings but doesn’t explain why they’re findings. It doesn’t quote the requirement or describe the actual situation.
Solution: Write audit findings clearly. State the requirement, state what you found, explain why they don’t match. Make the report a learning document, not a bureaucratic exercise.
Mistake 6: Auditor Conflicts of Interest Are Ignored
The operations manager audits their own operations. The maintenance supervisor audits maintenance. They miss obvious issues because they’re invested in those areas appearing functional.
Solution: Ensure auditor impartiality. If you can’t achieve it, document why and compensate (e.g., by reviewing their findings with someone impartial).
Preparing for External Audit: Using Internal Audit as Your Early Warning System
Your certification body will examine your internal audit programme at Stage 1. They’ll review your scope, frequency, audit reports, and corrective action tracking. This is your opportunity to show them that your system self-regulates.
A robust internal audit programme (well-planned, competently executed, thoroughly followed up) tells the certification auditor: “We don’t wait for you to find our problems. We find them ourselves and fix them.”
This is the impression you want to create. It speeds the certification process and demonstrates genuine commitment to continual improvement.
Conversely, if your internal audits are sporadic, superficial, and not acted upon, certification auditors will assume your system is reactive at best, non-functional at worst. They’ll audit more deeply. They may find more findings. Your timeline extends.
For more on preparing for external audits, see our article on ISO 45001 Stage 1 and Stage 2 audits: what to expect and how to prepare.
Connecting Internal Audit to Management Review
Your internal audit findings should feed into your management review process. Clause 9.3 requires that management review your system’s performance, including audit results. This isn’t separate—it’s integrated.
At your quarterly or semi-annual management review, you should review:
- Audit findings from the period
- Corrective action closure status
- Trends (are you seeing the same type of finding repeatedly?)
- Improvements resulting from audits
Management should make decisions based on this. Do we need more training? Should we revise a procedure? Do we need to reallocate resources? Internal audit data should drive these conversations.
Key Takeaways
Internal audit is your system’s quality control. It’s where you catch problems before they become incidents, before they become audit findings. A well-executed internal audit programme is the single best predictor of certification audit success.
Build a risk-based programme. Ensure auditors are competent and impartial. Conduct audits thoroughly, combining document review, interviews, and observation. Report findings clearly. Track corrective actions to closure. Use audit results to drive management decisions.
This isn’t bureaucracy. It’s how you genuinely improve your safety management system and demonstrate that improvement to certification auditors.
Frequently Asked Questions
There’s no fixed frequency in ISO 45001. Best practice is risk-based: audit high-risk areas annually or more frequently, medium-risk areas biannually, low-risk areas 18-24 months. Core processes (HIRA, competence, internal audit, management review) should be audited at least annually.
Yes, if they’re competent and impartial. However, rotating auditors (same person audits different areas each year, or different people audit the same area in different years) is often better for catching fresh issues.
Document the constraint. Have the person audit their own area, but have their findings reviewed and approved by someone else (e.g., the manager above them). This provides some independence, even if not perfect.
Not necessarily. Internal auditors are typically internal staff trained in audit methodology. External auditors are your certification body’s auditors during Stage 1, Stage 2, and surveillance audits. Some organisations contract external auditors to conduct some internal audits, but trained internal auditors are usually sufficient.
Treat it as a nonconformity. Don’t hide it. Document the finding, conduct a root cause analysis, implement a corrective action, and track closure. This demonstrates integrity and proactive management.
Depends on scope and size. A small office might take 1 day. A large manufacturing site might take 3-5 days. Plan enough time to observe actual work, interview people, and review documents thoroughly. Rushing an audit produces shallow findings.
Yes, absolutely. Conduct at least one internal audit before Stage 2. Ideally, conduct two or more. This shows your programme is operational and gives you a chance to find and fix issues before the certification body does.
Conclusion: Internal Audit as a Management Tool
Internal audit isn’t a compliance requirement you tolerate—it’s a management tool you leverage. When executed well, it identifies problems early, drives improvement, and demonstrates to certification auditors that your system is self-regulating.
Start with a risk-based audit programme. Develop competent, impartial auditors. Conduct audits thoroughly. Report findings clearly. Track corrective actions to closure. Let audit results inform your management review and drive decisions.
This investment in internal audit—in people, process, and discipline—returns dividends in certification audit success and genuine safety improvement.
Need Help Building Your Internal Audit Programme?
We provide audit training, help design risk-based programmes, and can conduct initial audits to establish your baseline. Contact us to discuss your audit needs.
Recent Comments