Most ISO 45001 certification projects slow down for one reason: nobody is sure which documents are actually required. You may already have risk assessments, toolbox talks, incident reports and training records, but they are scattered across spreadsheets, emails and site folders. The ISO 45001 documentation requirements are not about creating paperwork for its own sake; they are about proving that your OH&S management system is planned, controlled, measured and improved.
This checklist separates what ISO 45001:2018 expects you to document, what is strongly recommended in practice, and what audit evidence you should prepare before Stage 1 and Stage 2 certification audits.
Quick Answer
ISO 45001 documentation requirements include documented information for the OH&S management system scope, OH&S policy, responsibilities and authorities, risks and opportunities, hazard identification and risk assessment methods, legal and other requirements, OH&S objectives, operational controls, emergency preparedness, competence, monitoring, internal audits, management review, incidents and corrective actions.
ISO 45001:2018 does not require a formal OH&S manual, but auditors will expect controlled, current and usable documents that show how your organization manages health and safety risks. A practical pack usually includes 15–30 templates plus live records such as training logs, inspections, risk assessments and management review minutes.
In This Guide
- ISO 45001 Required Documents: What Certification Auditors Expect
- ISO 45001 Documentation Checklist by Clause
- ISO 45001 Mandatory Records for OH&S Audits
- ISO 45001 Policies and Procedures Every Company Needs
- ISO 45001 Templates by Industry: Construction, Manufacturing, Oil & Gas, Logistics and Facilities
- How Long ISO 45001 Documentation Takes to Prepare
- ISO 45001 Documentation Mistakes That Cause Audit Findings
- Frequently Asked Questions
- Next Steps
ISO 45001 Required Documents: What Certification Auditors Expect
ISO 45001:2018 is the international standard for occupational health and safety management systems. The official ISO 45001:2018 standard page describes it as a requirements standard with guidance for use, which means certification bodies audit your organization against defined requirements, not against a generic safety programme.
The standard uses the term documented information. That includes documents you maintain, such as policies and registers, and records you retain, such as inspections, training evidence and management review minutes.
For certification preparation, split your OH&S documentation into three groups:
- Mandatory documented information: Documents and records explicitly required by ISO 45001:2018 clauses.
- Recommended templates: Procedures, forms and registers that make the system easier to run and easier to audit.
- Audit evidence records: Completed examples proving the system is active, not just written.
Does ISO 45001 require an OH&S manual?
No. ISO 45001 does not require a formal OH&S manual. Some companies still use one because it gives auditors, managers and workers a single navigation document for the management system. If you use a manual, keep it short: scope, process map, clause references, key responsibilities and links to live procedures.
Quick check: Can you show your OH&S scope, policy, risk methodology, objectives and emergency preparedness process within five minutes? If not, your documentation may be technically present but not audit-ready.
ISO 45001 Documentation Checklist by Clause
The table below gives a practical ISO 45001 documentation checklist by clause. It focuses on what most certification auditors expect to see during Stage 1 document review and Stage 2 implementation audit.
| ISO 45001 clause | Documented information to prepare | Mandatory or recommended? | What auditors check |
|---|---|---|---|
| 4.3 | Scope of the OH&S management system | Mandatory | Boundaries, locations, activities, workers and contractors. |
| 5.2 | OH&S policy | Mandatory | Commitment to safe work, legal compliance, consultation and improvement. |
| 5.3 | Roles, responsibilities and authorities | Mandatory | Named responsibilities for managers, supervisors, workers and emergency roles. |
| 6.1.1 | Process for addressing risks and opportunities | Mandatory | How risks, opportunities and actions are assessed and reviewed. |
| 6.1.2.1 and 6.1.2.2 | Hazard identification process and OH&S risk assessment methodology | Mandatory | Criteria, hierarchy of controls, consultation inputs and review triggers. |
| 6.1.3 | Legal and other requirements register | Mandatory documented information | Applicable laws, permits, client requirements and owners. |
| 6.2.2 | OH&S objectives and plans to achieve them | Mandatory | Measurable targets, owners, resources, deadlines and review. |
| 7.2 | Competence evidence | Mandatory record | Training matrix, licences, induction and competence reviews. |
| 8.1 | Operational controls, safe work procedures and management of change records | Recommended, often necessary | Controls for high-risk work, contractors and changes. |
| 8.2 | Emergency preparedness and response process | Mandatory | Emergency scenarios, roles, drills, first aid and review. |
| 9.1.1 and 9.1.2 | Monitoring, measurement and compliance evaluation records | Mandatory record | Inspections, KPIs, compliance checks and actions. |
| 9.2 | Internal audit programme and audit results | Mandatory record | Schedule, criteria, independence, findings and actions. |
| 9.3 | Management review results | Mandatory record | Inputs, decisions, actions and responsibilities. |
| 10.2 | Incident, nonconformity and corrective action records | Mandatory record | Root cause, actions, effectiveness review and lessons learned. |
What is an ISO 45001 risk and opportunity register?
An ISO 45001 risk and opportunity register is a working record that connects hazards, OH&S risks, legal obligations, business risks, opportunities and actions. It should not be a static spreadsheet created just before the audit. It should show risk owners, control measures, residual risk, action deadlines and review dates.
What records prove ISO 45001 hazard identification?
Auditors usually look for completed risk assessments, job safety analyses, inspection reports, near-miss reports, consultation records, incident investigations and change assessments.
ISO 45001 Mandatory Records for OH&S Audits
ISO 45001 mandatory documents show what your system is supposed to do. Mandatory records prove it is happening. Before your certification audit, prepare records covering at least one management system cycle. For a small company, that usually means 3–6 months of evidence.
What evidence do ISO 45001 auditors ask for?
Auditors commonly ask for evidence in six areas:
- Planning evidence: OH&S risk assessments, legal register, objectives and action plans.
- Operational evidence: inspections, permits, maintenance records, contractor controls and safe work procedures.
- Competence evidence: induction, role-specific training, licences, toolbox talks and competence reviews.
- Consultation evidence: safety committee minutes, worker feedback, issue logs and risk assessment input.
- Performance evidence: OH&S KPIs, incident trends, compliance evaluations and emergency drill results.
- Improvement evidence: corrective actions, root cause analysis, internal audit results and management review outputs.
Pro tip: Do not wait until the certification audit to complete your first internal audit and management review. Auditors expect Clause 9.2 and Clause 9.3 to be operating before certification, not planned for after certification.
How do you document worker consultation for ISO 45001?
Worker consultation is stronger when it leaves a clear trail. Use safety meeting minutes, toolbox talk attendance, hazard reporting logs, risk assessment sign-offs, suggestion records, investigation participation notes and evidence that workers were consulted before major operational changes.
What emergency preparedness documents does ISO 45001 require?
Clause 8.2 requires an emergency preparedness and response process. Prepare an emergency procedure, scenario register, evacuation plan, contact list, first aid arrangements, drill reports and action tracker.
ISO 45001 Policies and Procedures Every Company Needs
Not every procedure is explicitly mandatory, but a certification-ready OH&S management system needs enough structure to run consistently. The right ISO 45001 policies and procedures make responsibilities clear and reduce the chance that safety controls depend on memory or individual habits.
As a practical baseline, most organizations should prepare these templates:
- OH&S policy
- OH&S scope statement
- Hazard identification and risk assessment procedure
- Legal and other requirements register
- Worker consultation and participation procedure
- Operational control procedure
- Contractor and procurement safety procedure
- Management of change procedure
- Emergency preparedness and response procedure
- Incident investigation and corrective action procedure
- Management review agenda and minutes template
If you are building from scratch, browse the broader ISO documentation toolkits collection to compare how different management system standards structure policies, procedures and records.
Can ISO 45001 documentation be combined with ISO 9001 and ISO 14001?
Yes. ISO 45001 follows the same high-level structure as ISO 9001:2015 and ISO 14001:2015, so document control, internal audit, management review, competence, corrective action and objectives can often be shared. Keep hazard identification, worker consultation, emergency preparedness and incident investigation detailed enough for OH&S risks.
ISO 45001 Templates by Industry: Construction, Manufacturing, Oil & Gas, Logistics and Facilities
A generic ISO 45001 checklist is useful, but industry risk determines which documents matter most. A low-risk office and a fabrication workshop may both need Clause 6.1 documentation, but the evidence will look very different.
| Industry | ISO 45001 templates to prioritise | Audit evidence auditors may sample | Common weak point |
|---|---|---|---|
| Construction | RAMS, permits, site inspections, contractor control, lifting plans | Risk assessments, toolbox talks, subcontractor checks, incident reports | Controls not updated when site conditions change |
| Manufacturing | Machine safety, lockout-tagout, maintenance, PPE, chemicals | Guarding checks, maintenance logs, training, exposure assessments | Risk assessments missing maintenance and cleaning tasks |
| Oil & gas | Permits, emergency response, competence, contractor HSE plan | PTW records, drills, competence evidence, contractor reviews | Contractor controls not linked to operational risk |
| Logistics | Vehicle safety, loading, driver competence, fatigue, traffic plans | Vehicle inspections, driver checks, route risk assessments | Informal controls for temporary drivers and peak-season work |
| Facility management | Contractor induction, maintenance safety, work at height, evacuation | Permits, inspection logs, fire drills, maintenance records | Outsourced work controlled informally |
For a broader view of how ISO 45001 supports risk reduction, the article on reducing risks and improving productivity with ISO 45001 is a useful supporting read.
Can small businesses use ISO 45001 templates?
Yes, and small businesses often benefit most because they rarely have time to write every procedure from a blank page. The template still needs customization: your site activities, hazards, legal obligations, responsibilities, emergency arrangements and worker consultation process must reflect how your business actually operates.
How Long ISO 45001 Documentation Takes to Prepare
For a small business with one site and existing safety records, ISO 45001 documentation often takes 2–4 weeks to prepare. A mid-sized organization with multiple departments usually needs 4–8 weeks. A high-risk or multi-site organization can take 8–12 weeks or more, especially if legal registers, contractor controls and operational procedures need to be built properly.
- Define the OH&S scope: Confirm locations, activities, workers, contractors and boundaries before writing procedures.
- Map legal and other requirements: Build a register covering laws, permits, client rules, insurance requirements and contract obligations.
- Complete hazard identification: Review routine and non-routine work, emergency situations, contractor activities and changes.
- Create the risk methodology: Define risk criteria, hierarchy of controls, review frequency and escalation rules.
- Write operational procedures: Prioritise high-risk work, contractor controls, emergency response and management of change.
- Start using the records: Run inspections, toolbox talks, training, consultation meetings and corrective actions before the audit.
- Complete internal audit and management review: Use Clause 9.2 and Clause 9.3 outputs to prove the system has been checked and improved.
Pro tip: Create a document matrix with document owner, version, approval date, review date and retention period. This prevents audit findings under document control and makes ownership visible to department heads.
ISO 45001 Documentation Mistakes That Cause Audit Findings
Most ISO 45001 documentation mistakes are not caused by missing templates. They are caused by documents that do not match real work. Certification auditors interview workers, walk through sites and sample records, so inconsistencies are easy to find.
What ISO 45001 documentation mistakes cause nonconformity?
- Skipping worker consultation: Risk assessments are written by managers with no evidence of worker participation.
- Ignoring contractors: Contractor activities are inside the OH&S scope but not controlled through induction, permits or performance review.
- Weak legal registers: Legal requirements are listed but not evaluated for compliance under Clause 9.1.2.
- No management of change trail: New equipment, processes, chemicals or layouts are introduced without reviewing OH&S risk.
- Incomplete corrective actions: Incidents are recorded, but root cause, action owner and effectiveness review are missing.
If you are evaluating templates, this guide to the top features to look for in an ISO 45001 documentation toolkit explains what separates useful documentation from a folder of generic forms.
How do you avoid ISO 45001 audit findings?
Start by matching every document to a real process owner. Then test each procedure against actual work: ask supervisors how they use it, ask workers how hazards are reported, and sample completed records before the certification body does. If a document cannot be explained by the people expected to use it, rewrite it.
Frequently Asked Questions
What documents are required for ISO 45001 certification?
ISO 45001 certification requires documented information for the OH&S management system scope, OH&S policy, responsibilities and authorities, risks and opportunities, risk assessment methodology, legal and other requirements, OH&S objectives, emergency preparedness, competence, monitoring, internal audits, management review, incidents, nonconformities and corrective actions. Additional procedures are often needed to control high-risk work consistently.
Does ISO 45001 require a health and safety manual?
No, ISO 45001:2018 does not require a formal health and safety manual. You can use one if it helps explain your OH&S management system, but auditors will focus on whether your controlled documented information meets the standard, reflects real work and is supported by evidence such as risk assessments, training records and management review outputs.
What records are required for an ISO 45001 audit?
ISO 45001 audit records usually include competence evidence, consultation records, risk assessments, legal compliance evaluations, monitoring and measurement results, workplace inspections, emergency drill reports, internal audit results, management review minutes, incident investigations, nonconformity records and corrective action evidence. The records should show that the OH&S system is operating across relevant activities, shifts and sites.
How long does ISO 45001 documentation take for a small business?
For a small business with one site and some existing safety controls, ISO 45001 documentation often takes 2–4 weeks to prepare. The timeline increases if the company needs to build risk assessments, legal registers, contractor controls or emergency procedures from scratch. You should also allow time to generate live records before the certification audit.
Can ISO 45001 documents be integrated with ISO 9001 and ISO 14001?
Yes. ISO 45001 documents can be integrated with ISO 9001 and ISO 14001 because these standards share a common management system structure. Many organizations combine document control, internal audit, management review, corrective action, objectives and competence processes. Keep OH&S-specific risk assessment, worker consultation, emergency preparedness and incident investigation content detailed enough for health and safety audit requirements.
Can I get ISO 45001 certified using a documentation toolkit?
Yes, many organizations use an ISO 45001 documentation toolkit to accelerate certification preparation, especially when they have limited internal time. The toolkit must be customized to your actual hazards, legal requirements, workers, sites and operational controls. Certification depends on implementation evidence, not just owning templates, so completed records and worker awareness still matter.
Next Steps
The ISO 45001 documentation requirements are manageable when you separate mandatory documented information, recommended templates and audit evidence records. Start with scope, policy, risk methodology, legal requirements, objectives, emergency preparedness and competence evidence. Then build enough live records to prove your OH&S system is working before the certification audit.
Ready to prepare your certification documents faster? Our ISO 45001:2018 Occupational Health and Safety Management System Documentation Toolkit gives you ready-made policies, procedures, forms and records you can customize instead of writing everything from scratch.


