ISO 45001 Mandatory Documents and Records: The Complete List
Documentation is where many organisations stumble. They interpret “documented information” as “create a massive manual.” Six months later, they have a 200-page document no one reads, procedures disconnected from actual practice, and a system that feels bureaucratic rather than useful.
Here’s the truth: ISO 45001 doesn’t mandate an OH&S manual. It mandates documented information—policy, procedures, records—that support your system. How you organise that is your choice.
This guide clarifies what you absolutely must document, what’s optional, and how to structure documentation so people actually use it.
What ISO 45001 Actually Requires: The No-Manual Surprise
OHSAS 18001 (the old standard) typically required an OH&S manual. ISO 45001 is silent on this. It requires documented information to support the system, but doesn’t dictate format or structure.
This is liberating if understood correctly. You could document everything as a single manual. Or you could have modular procedures for hazard management, incident response, competence, operational controls, audit, and management review—each owned by a different department.
The standard is results-focused: Does your documented information support system operation? Do people know where to find guidance when they need it? Are procedures accurate and kept current? You can achieve this through a manual or modular structure.
The weak organisations I audit typically have beautiful manuals that operators never consult because they’re locked in a cabinet. The strong organisations have slim procedure booklets or digital access points that are actually used.
Mandatory Documented Information: The Complete List
Here’s what ISO 45001 explicitly requires you to document:
Clause 4.3: Scope of the Management System
What: A documented statement of which legal entities, locations, processes, and workforce categories are included in your management system. If anything is excluded, justify the exclusion.
Why: Auditors need to verify your system boundaries match your intended scope. Exclusions must be logical (e.g., “We scope in manufacturing operations and exclude sales, which have no OH&S hazards”). Vague scoping invites audit findings.
Example: “This management system covers all manufacturing and warehouse operations at our Portland facility. The system includes all permanent employees, contractors, and temporary workers on-site. Sales and administrative functions at off-site locations are excluded because they have no occupational health and safety hazards beyond standard office ergonomics, which are managed through generic office safety procedures.”
Clause 5.2: OH&S Policy
What: A documented statement of your organisation’s OH&S commitment, approved by top management, addressing all ISO 45001 requirements (legal compliance, OH&S commitment, prevention focus, management accountability, worker participation).
Why: Your policy sets the tone for your entire system. It’s public—it tells your workforce what you stand for on OH&S.
Length: Typically 1-2 pages. If your policy runs 10 pages, it’s not a policy; it’s a procedure disguised as policy.
Requirement: Must be signed by top management personally, not delegated. The policy signature must be recent (within 2-3 years) and come from someone with actual authority (CEO, MD, site director). Not the OH&S manager.
Clause 6.1: HIRA Results
What: Documented evidence of your hazard identification and risk assessment process. This includes your risk register showing identified hazards, affected parties, current risk, controls, and residual risk.
Why: This is foundational. Your HIRA determines your risk profile. Everything else (objectives, controls, monitoring) flows from HIRA findings.
Format: Can be a spreadsheet (risk register), a risk assessment report, or a comprehensive document with narrative plus register. The format doesn’t matter; completeness and accuracy do.
Update requirement: HIRA must be reviewed and updated annually, or when major process changes occur. Document when the HIRA was last reviewed.
Clause 6.2: OH&S Objectives and Targets
What: Documented OH&S objectives (strategic goals) and targets (measurable intermediate goals) that cascade from your HIRA and support your policy. Objectives should include how they’ll be monitored, who’s responsible, and timeline.
Why: Objectives show how you translate risk findings into improvement actions. They focus your resources on what matters.
Example: Objective: “Reduce manual handling injuries by 30% within 12 months.” Supporting targets: “Implement ergonomic workstation assessments (all stations by Q2 2026),” “Train all operators in safe lifting techniques (100% by Q3 2026),” “Monitor manual handling incidents monthly and track trend.”
Clause 7.2: Competence Requirements and Evidence
What: Documented competence requirements for each role (what knowledge, skills, experience is needed), evidence that competence has been verified (training records, certificates, assessments), and records of competence maintenance (refresher training, skill checks).
Why: You need to prove that people are competent before they perform roles with OH&S significance. A person operating machinery must be trained. Someone investigating incidents must understand investigation methodology.
Common gap: Many organisations have training records but no clear link between role requirements and training provided. You need both.
Evidence: Training certificates, competency assessments, signed competency declaration forms, or supervisor sign-off confirming competence.
Clause 7.4: Communication
What: Documented information about your communication processes—how OH&S information flows up, down, and across the organisation. Specifically, how do workers report hazards? How does management communicate decisions? Is feedback provided?
Why: Communication is essential for system effectiveness. If workers report hazards and never hear back, they stop reporting.
Format: Can be a communication procedure, a description of communication mechanisms (safety meetings, toolbox talks, email updates), or a communication matrix showing who communicates what to whom.
Evidence: Meeting minutes, hazard report tracking sheets, feedback logs showing responses to worker submissions.
Clause 7.5: Documented Information Requirements
What: Your document and record control procedure. You must document how you ensure:
—Documented information is approved before release (who must sign off?)
—Documented information has version control (date, author, revision number)
—Documented information is accessible (who can access? where is it stored?)
—Documented information is protected from unintended changes (is it read-only once approved? can it be edited without approval?)
—Records are retained for an appropriate period (what’s your retention schedule?)
Why: You need discipline around documentation. Otherwise, people work from outdated procedures, or procedures are changed without approval.
Format: A document control procedure (typically 2-3 pages) plus a document register (list of all controlled documents with version, date, owner). Can be embedded in a broader information management policy.
Clause 8.1: Operational Controls
What: Documented procedures for how you control risks in your operations. For each high-risk hazard identified in your HIRA, you need documented control procedures that ensure it’s managed consistently.
Examples: Safe machinery operation procedure, hazardous chemical handling procedure, safe manual handling procedure, lone worker procedure, hot work permit procedure.
Why: Procedures ensure consistency. Without documented procedures, you rely on worker knowledge and memory—both unreliable.
Level of detail: Depends on risk level. High-risk operations need detailed procedures. Lower-risk operations might only need a brief work instruction or poster.
Common gap: Organisations create procedures but don’t verify they’re followed operationally. A procedure in a manual isn’t effective if workers aren’t using it. Embed follow-up checks into your procedure (e.g., “Supervisor to observe procedure compliance weekly and document in observation log”).
Clause 8.1.3: Management of Change
What: A documented process for how you handle operational changes (new equipment, process redesign, layout change, staffing change) while maintaining OH&S. Before changes are implemented, you must assess OH&S implications and ensure necessary controls are in place.
Why: Many incidents occur during change periods when hazards are disrupted and people aren’t yet clear on new procedures.
Format: A change management procedure with a change impact assessment template. When someone proposes a change, they complete the template: What’s changing? Why? What OH&S implications? What controls will be in place? Who approves?
Clause 8.2: Emergency Preparedness and Response
What: Documented emergency procedures for credible emergency scenarios (fire, chemical spill, medical emergency, natural disaster, etc.). Procedures should include notification systems, evacuation routes, roles and responsibilities, and recovery procedures.
Why: In emergencies, people need clear procedures. Ambiguity or confusion costs lives.
Evidence: Emergency procedure documents, emergency contact lists, evacuation diagrams, first aid trained personnel lists, emergency drill records (showing drills are conducted and evaluated).
Clause 9.1: Monitoring and Measurement
What: Documented description of what OH&S metrics you track, how you track them, and how frequently. Metrics might include: incidents and near-misses (monthly), absenteeism (monthly), training completion (quarterly), hazard close-outs (monthly), management observations (monthly), internal audit schedule (annually).
Why: You need to measure what matters so you can manage it. If you don’t track it, you can’t improve it.
Format: A monitoring and measurement procedure or a metrics dashboard that shows what’s tracked, target levels, actual performance, and trends.
Clause 9.2: Internal Audit
What: Documented internal audit programme showing: audit scope (which clauses, which departments), frequency (annual? quarterly?), auditor qualifications, audit timeline, and audit procedure. You must also document internal audit results (audit reports showing what was assessed, findings, recommendations).
Why: Internal audit is your self-check mechanism. It reveals non-conformities before external auditors find them.
Frequency: Audits should cover all clauses and key processes at least annually. For complex organisations, you might audit different departments on different cycles, but collectively you audit everything annually.
Evidence: Audit schedule, auditor training records, audit checklists, audit reports with findings and recommendations, audit action tracking.
Clause 9.3: Management Review
What: Documented records of management review meetings where leadership reviews system performance, makes decisions, and approves improvements. Reviews should include: performance data (metrics, incidents, audit findings), external/internal changes (regulatory, process, workforce), and decisions (resource allocation, improvement actions, policy updates).
Why: Management review is where leadership engages. It’s where data informs decisions. It’s where system improvements are prioritised.
Frequency: At minimum annually. Larger organisations might do quarterly reviews.
Evidence: Management review meeting agenda, performance data reviewed, attendee list, documented decisions, action items with ownership and deadline.
Clause 10.2: Incident Investigation
What: Documented incident investigation procedure and records of investigations performed. When incidents occur, you must investigate, identify root causes, and determine corrective actions to prevent recurrence.
Why: Incident investigation is how you learn from things that went wrong. It prevents similar incidents in future.
Procedure content: What defines an incident worthy of investigation? Who investigates? What’s the investigation timeline? What information is gathered (interviews, photos, documentation)? How are root causes identified? How are corrective actions tracked to completion?
Evidence: Incident reports, investigation records (who was interviewed, what evidence was reviewed), root cause analysis, corrective action plans, follow-up to verify corrective action effectiveness.
Clause 10.1: Non-Conformity and Corrective Action
What: Documented records of non-conformities (instances where the system didn’t work as intended—someone didn’t follow procedure, control failed, etc.), root cause analysis, and corrective actions to prevent recurrence.
Why: Non-conformities are learning opportunities. If you identify them and address them systematically, you improve continuously.
Difference from incidents: Incidents are harmful events (someone was injured, property was damaged). Non-conformities are system failures that might not have caused immediate harm. “Found machinery operating without guarding” is a non-conformity. “Worker caught in unguarded machinery and lost arm” is an incident (which might trigger investigation into the non-conformity of missing guarding).
Evidence: Non-conformity reports, root cause analysis, corrective action plans, follow-up verification that corrective actions were effective.
Mandatory Records: What Evidence Must You Keep?
Beyond documented procedures, you must maintain records proving you did what you documented:
Training and Competence Records: Evidence that employees received training and demonstrated competence. Training certificates, attendance records, competency assessments, supervisor sign-offs.
Incident and Investigation Records: Incident reports, investigation documentation, corrective action records, follow-up verification.
Monitoring and Measurement Records: Monthly/quarterly metrics reports, near-miss logs, hazard reports, management observation records.
Audit Records: Internal audit reports, management review meeting minutes, corrective action tracking.
Operational Control Records: Permit-to-work records, machinery maintenance logs, chemical inventory and disposal records, emergency drill records.
Communication Records: Safety meeting minutes, toolbox talk topics, hazard reporting logs with management responses.
How Long to Retain Records?
ISO 45001 doesn’t specify retention periods. You must determine appropriate periods based on:
Legal/Regulatory Requirements: Labour law, health regulations, and industry-specific rules often specify minimum retention. Incident records are typically required for 5-7 years. Training records should be retained for employee tenure plus 1-2 years.
Statute of Limitations: If someone is injured and later claims compensation, they might have several years to lodge a claim. Retain incident records for the full statute period so you can defend if challenged.
Audit Trail Needs: You should be able to show your system evolution over time. Retain enough historical data to demonstrate continuous improvement.
Reasonable Schedule: Policy and HIRA records: indefinite (or at least 10 years). Incident and training records: 5-7 years. Meeting minutes and routine monitoring data: 3-5 years. Operational records (permits, inspections): 2-3 years or per regulatory requirement.
Document your retention schedule explicitly in your document control procedure.
Paper vs. Digital: Which Format?
Digital is increasingly preferred because:
—Version control and audit trail are built in
—Documents are easily searchable and accessible
—Revision is simpler than maintaining multiple paper versions
—Access control can be granular (who can view? who can edit?)
However, if your workforce works in the field without laptop access, you might need to print key procedures for on-site reference. This is fine—just ensure printed copies are marked with version number and date so people don’t work from outdated versions.
Digital-only storage is acceptable provided:
—Documents are backed up (so they’re not lost if the server crashes)
—Access control is secure (unauthorised people can’t change approved documents)
—Search functionality is available (people can find what they need)
—Archive/retrieval processes are defined (so old records remain accessible)
A shared folder is not sufficient. Use a document management system (SharePoint, ISO management software, etc.) that provides version control and audit trail.
What Goes Beyond Mandatory: Optional Documentation
Beyond the mandatory items above, many organisations create additional documentation that, while not required by the standard, supports operations:
Work Instructions: Detailed step-by-step guidance for specific tasks. Example: “Chemical Handling Work Instruction” or “Machinery Lockout Work Instruction.” Not mandatory but useful for ensuring consistency.
Templates and Forms: Incident report forms, hazard report forms, near-miss logs. These standardise how information is captured.
Guidance Documents: Explanatory material on why certain practices matter or how to comply. Example: “Ergonomic Assessment Guidelines.” These support understanding but aren’t auditable requirements.
Audit Checklists: Questions used in internal audits to verify compliance. Helpful for consistency but not mandatory.
Competence Matrix: Role-by-role summary of competence requirements. Useful for identifying training needs.
The danger with optional documentation is that it proliferates. Soon you have 300 pages of guidance, and people don’t know what’s mandatory versus nice-to-have. Be selective: document what clarifies understanding or ensures consistency. Don’t document for documentation’s sake.
Structuring Your Documentation System: Manual vs. Modular
You have two main approaches:
Single Manual Approach
Format: One comprehensive document covering scope, policy, procedures, requirements, templates.
Advantages: Single source of truth. Easy for new employees to understand the whole system. Good for smaller organisations.
Disadvantages: Updates are labour-intensive (change one section, re-release whole manual). Makes ownership unclear (who maintains which section?). Can be overwhelming if comprehensive.
Modular Approach
Format: Separate documents for each functional area: Hazard Management Procedure, Incident Response Procedure, Competence Management Procedure, Operational Controls Work Instructions, etc.
Advantages: Each document owned by a specific person (Operations Manager owns operational controls; HR owns competence). Updates are simple (change one procedure without affecting others). Easier for different departments to find relevant guidance.
Disadvantages: Requires a master index or document register so people can find relevant documents. Risk of inconsistency if different authors use different styles or terminology. Requires robust document control so you know which versions are current.
Which approach? For organisations under 100 employees with centralised operations, a manual works. For larger organisations or those with distributed teams, modular is better. Many organisations use a hybrid: a slim “OH&S System Overview” manual (5-10 pages) plus modular procedures for each functional area.
Frequently Asked Questions
Does ISO 45001 require an OH&S manual?
No. ISO 45001 does not mandate a formal ‘OH&S manual.’ Instead, it requires documented information to support the management system (policy, scope, HIRA results, objectives, procedures, records). You can organise this as a manual, or as modular documents/procedures—the standard is flexible on format.
What is the difference between ‘documented information’ and ‘records’ in ISO 45001?
‘Documented information’ is procedural guidance—what you’re supposed to do (procedures, work instructions, policies). ‘Records’ are evidence that you did it (training certificates, incident reports, audit minutes). Procedures tell you how to manage incidents; incident records prove you managed incidents. Both must be controlled and retained.
What documented information is absolutely mandatory?
Policy, scope, HIRA results, objectives/targets, competence requirements, emergency procedures, operational controls, internal audit programme and results, management review outputs, incident investigation records, and non-conformity/corrective action records. Beyond these, what else you document depends on your operations and complexity.
How long must we retain records?
ISO 45001 doesn’t specify retention periods—it requires you to determine appropriate periods. Consider: regulatory requirements (labour law, health regulations), incident statute of limitations (typically 3-6 years), and business needs. Training records should be retained for employee tenure plus 1 year. Incident records should be retained for at least 5 years.
Can we store documents digitally or do we need paper copies?
Digital storage is acceptable and increasingly preferred. You must ensure digital documents have version control (date, author, approval), are accessible when needed, are protected from unauthorised change, and are retrievable if systems fail. Paper copies are only necessary if your operations require them (e.g., on-site access for field workers without laptops).
What document control requirements does ISO 45001 impose?
Clause 7.5.2-7.5.3 requires: documented information is approved before release (who approved?), version control applied (date, revision number), accessible to those who need it, protected from unintended changes, and retained for a defined period. You need to determine when documents are reviewed and updated. This can be embedded in your document management system.
Should we create an ISO 45001 manual or modular procedures?
There’s no ‘must.’ Some organisations prefer a single manual (easy reference, comprehensive). Others prefer modular procedures (easier to update, clearer ownership). The standard works with either approach. Choose based on your size and culture: small organisations often do better with a concise manual; larger organisations with distributed teams often prefer modular procedures with clear role-specific work instructions.
Conclusion: Document Smartly, Not Bureaucratically
Documentation is a means, not an end. The purpose of documented information is to ensure consistency and support effective OH&S management. If your documentation becomes so voluminous or disconnected from reality that people avoid it, you’ve failed the purpose.
Document what you need to ensure consistency, guide people, and comply with the standard. Don’t document to impress auditors. Auditors respect clean, practical documentation more than comprehensive, unused documentation.
If you’re unclear on what to document or how to structure your system, contact Anitech Group. We help organisations build documentation systems that are both compliant and useful—that actually guide people’s work rather than gathering dust.
Contact Anitech Group to structure your documentation system.
Recent Comments