What evidence do auditors ask for in an ISO 45001 audit?

Updated 5 August 2026

Short answer

ISO 45001 auditors ask for evidence that the system runs, not that it was written: the HSE policy and objectives with measured progress, hazard identification and risk assessments that match current site activity, legal and other requirements with compliance evaluation, competence and training records, consultation and participation records, operational controls including permits, emergency drill records, incident and CAPA records, internal audit results and the management review minutes. Each item must be current, signed and traceable to a named owner.

Key points

  • The most common non-conformities are stale risk assessments, missing verification of corrective action effectiveness, and management reviews with no measurable inputs.
  • Evidence must be retrievable during the audit — 'it exists somewhere' is a finding.
  • Contractor and subcontractor control (clause 8.1.4) is tested on live sites, not just in the procedure.

Clause 5–6: leadership, policy, objectives

Signed and dated HSE policy, evidence of communication, HSE objectives with targets, timescales, owners and current measured performance against them.

Clause 6.1: risk and legal requirements

Hazard identification and risk assessments covering current activities, the register of legal and other requirements applicable in the UAE, and a documented compliance evaluation with dates.

Clause 7: competence, awareness, communication

Training matrix, third-party certificates with expiry tracking, induction records, toolbox talk attendance, and evidence of worker consultation and participation.

Clause 8: operational control and emergency preparedness

Permit-to-work records, method statements, contractor pre-qualification and control records, plant and lifting equipment third-party inspection certificates, and emergency drill reports with lessons learned.

Clause 9–10: monitoring, audit, review, improvement

Monitoring and measurement records, internal audit programme and reports, management review minutes with the required inputs and outputs, and incident/CAPA records including effectiveness verification.

Frequently asked questions

How current do risk assessments need to be?

They need to reflect the work actually happening on site on the day of the audit, and to have been reviewed after any incident, change of method, or change of plant. An assessment dated at tender stage and never revised is a standard finding.

Does ISO 45001 require digital records?

No. It requires documented information that is controlled, current, retrievable and protected from unintended alteration. Digital systems make those four properties easier to demonstrate, which is why most certified contractors move away from shared drives.

Put this into practice

Site Safety UAE runs these workflows for UAE and GCC contractors. Start free on one site, or ask the founding team for a walkthrough on your own permit types.

Related

More answers