ISO 45001 Occupational Health & Safety Checklist Template

An OH&S management system can pass its audit while the risk assessment predates the last near miss, the safety committee meets without anyone from the shop floor, and contractors work to rules nobody showed them.

ISO 45001 does not set a calendar, but most organisations run it as a yearly cycle. This free ISO 45001 checklist gives health and safety managers, EHS leads and management system coordinators that cycle, built on ISO 45001:2018 and its 2024 climate change amendment. It covers context and policy, worker consultation and participation under clause 5.4, hazards and risk, the legal register, objectives, contractors and management of change, emergencies, incident investigation, internal audit and management review. It produces a dated, clause-by-clause record that the system runs, and that the people doing the work helped run it.

Use This Template Free See Live Example
No Credit Card Required

Last reviewed: September 2026

A Safety Inspection Checks the Workplace. ISO 45001 Checks the System Behind It

ISO 45001 is the international standard for occupational health and safety management systems, now maintained by ISO/TC 283. It replaced the British standard OHSAS 18001 and shares its clause structure with ISO 9001 and ISO 14001. It is voluntary: your health and safety law applies either way, and certification is a choice.

What sets it apart is who it involves. Clause 5.4 requires consultation of non-managerial workers before decisions are made, and their participation in hazard identification, the choice of controls and incident investigation. Clause 8.1.2 makes the hierarchy of controls a requirement rather than a textbook diagram. Clause 6.1.2.1 counts workload, harassment and culture as hazards.

A safety inspection finds the blocked fire exit. The management system asks why it was blocked, whether anyone had reported it and whether the risk assessment changed.

Site safety inspection

Run by a supervisor or EHS officer on the floor

Asks: are guards fitted, exits clear, PPE worn and chemicals labelled today?

Cadence: daily, weekly or monthly, area by area.

Output: a list of defects and quick fixes.

ISO 45001 management system (this checklist)

Owned by top management, run by the OH&S lead

Asks: are hazards found early, are workers involved, and does the organisation learn?

Cadence: an annual cycle, with meetings, drills and audits inside it.

Output: evidence for each clause, a management review and an improvement plan.

What the ISO 45001 Checklist Covers

Six phases take the management system through one year, from context to management review. A seventh switches on for organisations holding an accredited certificate.

Phase 1

Phase 1: Context, Scope & Policy

The first task asks the scope questions. Its answers switch on the contractor tasks in Phase 4 and the certification phase.

  • Open the year’s OH&S management system record — record the sites in scope, the certificate held and the certification body’s audit dates
  • Review internal and external issues — including whether climate change is a relevant issue, as Amd 1:2024 requires (clause 4.1)
  • Update the needs and expectations of workers and other interested parties — and record which of them the system will address (clause 4.2)
  • Confirm the scope still matches the work — new sites, activities, shift patterns or remote workers since last year (clause 4.3)
  • Review the OH&S policy with top management — the commitments to eliminate hazards, meet legal requirements and consult workers still stand (clause 5.2)
  • Confirm OH&S roles, responsibilities and authorities are assigned — and understood by the people holding them, not only drawn on a chart (clause 5.3)
Phase 2

Phase 2: Worker Consultation & Participation

Clause 5.4 names non-managerial workers in both consultation and participation. Keep evidence of each.

  • Confirm the consultation and participation mechanisms — committee, representatives, briefings, with the time, training and resources to use them (clause 5.4)
  • Identify barriers to participation and remove them — language, literacy, shift patterns, agency status or fear of reprisal
  • Consult non-managerial workers on this year’s decisions — policy, objectives, contractor controls, what is monitored and the audit programme
  • Record worker participation in hazard, control and incident decisions — names and dates, not a general statement
  • Test the hazard and incident reporting route — reports are acknowledged and acted on, and nobody who reports faces reprisal (clause 5.1)
  • Hold and minute health and safety committee meetings where one exists — attendance, decisions and actions with owners
Phase 3

Phase 3: Hazards, Risks & Legal Requirements

  • Review hazard identification across routine and non-routine work — maintenance, start-up, breakdowns, emergencies and people on site who are not employees (clause 6.1.2.1)
  • Include psychosocial hazards — workload, work hours, harassment, bullying, leadership and culture are named in the standard
  • Reassess OH&S risks and risks to the management system — record every rating that changed, and why (clause 6.1.2.2)
  • Record OH&S opportunities — changes to work, equipment or organisation that would improve OH&S performance (clause 6.1.2.3)
  • Update the register of legal and other requirements — new legislation, regulator guidance, client and contract requirements (clause 6.1.3)
  • Plan action on significant risks, legal requirements and emergencies — as objectives, operational controls or training (clause 6.1.4)
Phase 4

Phase 4: Objectives & Operational Control

The contractor and outsourcing tasks appear only when Phase 1 records that contractors or outsourced processes operate within scope.

  • Set measurable OH&S objectives — each with an owner, resources, a deadline and the indicator that tracks it (clause 6.2)
  • Check each new or revised control against the hierarchy — elimination and substitution before engineering, administrative controls and PPE (clause 8.1.2)
  • Run changes through management of change — new equipment, processes, sites, staffing or legal requirements assessed before they happen (clause 8.1.3)
  • Verify contractor controls — OH&S selection criteria, site induction, reviewed risk assessments and method statements, and monitoring (clause 8.1.4.2)
  • Confirm outsourced functions and processes are controlled — and that the arrangements meet legal requirements (clause 8.1.4.3)
  • Check competence for safety-critical roles — every gap has a named person and a training date (clause 7.2)
Phase 5

Phase 5: Emergencies & Incidents

The first task asks whether any incident this year had to be reported to a regulator. If Yes, the notification check appears.

  • Review the year’s incidents and near misses — each was reported, recorded and investigated in proportion to its severity (clause 10.2)
  • Check investigations found causes, not culprits — and asked whether similar incidents have occurred or could occur
  • Confirm corrective actions followed the hierarchy of controls — risks from new or changed hazards assessed before acting, and effectiveness reviewed
  • Confirm regulator notifications were made on time — for example to OSHA within 8 hours of a work-related death in the US, or under RIDDOR in Great Britain
  • Communicate incident findings to workers and their representatives — the standard requires it, and it is what keeps people reporting
  • Exercise the emergency plan — run a drill or test, record what failed and revise the plan (clause 8.2)
Phase 6

Phase 6: Performance Evaluation & Management Review

The OH&S lead prepares the inputs. Top management holds and signs off the review.

  • Analyse monitoring results — leading and lagging indicators against the objectives set in Phase 4 (clause 9.1)
  • Evaluate compliance with each legal and other requirement — at the frequency you set, with action where one is not met (clause 9.1.2)
  • Complete the internal audit programme — every clause and site covered at the planned intervals, with workers consulted on the programme (clause 9.2)
  • Report relevant audit results to workers and their representatives — not only to management
  • Hold the management review — inputs include incidents, audit results, compliance evaluation, worker consultation, resources and objectives (clause 9.3)
  • Communicate the relevant review outputs to workers — decisions, resources and changes to the system
  • Log every nonconformity and improvement action — with an owner, due date and effectiveness check (clauses 10.2 and 10.3)
Phase 7 — Certified Organisations Only

Phase 7: Certification Audit & Revision Readiness

Shown only when Phase 1 records an accredited ISO 45001 certificate.

  • Confirm the certification body’s surveillance or recertification audit — dates, sites, shifts and scope to be sampled
  • Close the last visit’s nonconformities — with evidence of the root cause and of the action working
  • Tell the certification body about significant changes — new sites, scope changes or serious incidents, as your certification agreement requires
  • Record the audit outcome and any new findings — and add them to the Phase 6 action log
  • Track the ISO 45001 revision — when the new edition is published, run a gap analysis and agree a transition date with the certification body

The ISO 45001 Clauses Each Phase Evidences

The table maps the main requirements of ISO 45001:2018, as amended in 2024, to the phase that produces the evidence. ISO 45001 sits on top of your health and safety law rather than replacing it, and your certification body applies its own audit rules, so treat the table as a starting point, not legal advice.

Requirement ISO 45001:2018 Evidenced in
Context, interested parties and climate change4.1, 4.2 (Amd 1:2024)Phase 1
Scope4.3Phase 1
Leadership, policy and roles5.1–5.3Phases 1 and 2
Consultation and participation of workers5.4Phase 2
Hazard identification and risk assessment6.1.2Phase 3
Legal and other requirements6.1.3Phase 3
OH&S objectives6.2Phase 4
Competence7.2Phase 4
Hierarchy of controls8.1.2Phases 4 and 5
Management of change8.1.3Phase 4
Contractors and outsourcing8.1.4Phase 4
Emergency preparedness and response8.2Phase 5
Evaluation of compliance9.1.2Phase 6
Internal audit9.2Phases 6 and 7
Management review9.3Phase 6
Incidents, nonconformity and corrective action10.2Phases 5 and 6

ISO 45001:2018 with Amendment 1:2024 is the current edition, and this checklist uses its clause numbers. The amendment, published in February 2024, added one sentence to clause 4.1 requiring you to determine whether climate change is a relevant issue, and a note to clause 4.2. Unlike ISO 9001 and ISO 14001, ISO 45001 has not yet moved to a new edition. The revision is at draft stage: ISO/DIS 45001 went to ballot among ISO members in June 2026, and voting closed on 9 September 2026. At the time of review the result had not been published, and ISO expects the new edition to replace the 2018 edition in the first half of 2027. Certification bodies such as LRQA and NQA expect more weight on psychosocial health and wellbeing, but a draft can still change, so keep auditing against 2018. Global Accreditation Cooperation Incorporated (Global ACI) will set transition rules after publication. It gave ISO 9001:2026 and ISO 14001:2026 three years, and certification bodies expect similar here. Certificates to ISO 45001:2018 remain valid in the meantime.

Why Run Your ISO 45001 Management System in CheckFlow?

1

The year opens on schedule

An annual recurring schedule opens the cycle and assigns each phase to its owner, with dynamic due dates across the year. A data set of sites and safety representatives fills Phase 1, so each site runs its own copy of one template.

2

Worker participation leaves a record

Assign consultation and investigation tasks to safety representatives or a committee group, not only to managers. Minutes and risk assessments attach to their task, and the activity trail shows who did each step and when.

3

Only the tasks that apply

Conditional logic hides contractor tasks and the certification phase where they do not apply. Enforced step order holds the management review until the audits are done, and an approval records top management’s sign-off. Template versioning keeps each finished year on the edition it was run against.

CheckFlow is not a certification body and cannot certify you to ISO 45001. It runs the management system work and keeps the evidence. Day-to-day checks belong in their own checklists: the Safety Audit Checklist for a workplace walk-round and the Manufacturing Safety Inspection Checklist for plant, guarding and lockout. For implementing any ISO standard from gap analysis to certification, use the ISO Compliance Checklist.

CheckFlow’s compliance checklist software shows how recurring reviews and evidence fit across your compliance calendar, and CheckFlow for manufacturing covers the shift and inspection checklists that run alongside it on the factory floor.

Frequently Asked Questions

Is ISO 45001 a legal requirement?

+

No. ISO 45001 is a voluntary standard, and certification to it is optional. Your legal duties come from health and safety law in each country where you operate. The standard makes you identify those duties (clause 6.1.3) and check you meet them (clause 9.1.2), but holding a certificate does not show legal compliance on its own. Many adopt it because customers or tenders ask for it.

What does ISO 45001 mean by worker consultation and participation?

+

Consultation means asking workers for their views before a decision is made. Participation means involving them in making it. Clause 5.4 lists topics for each: non-managerial workers are consulted on matters such as the policy, objectives, contractor controls and the audit programme, and take part in identifying hazards, choosing controls and investigating incidents. Time, training and resources must be provided, and barriers such as language or fear of reprisal removed.

What is the hierarchy of controls in ISO 45001?

+

Clause 8.1.2 sets five levels, in order: eliminate the hazard; substitute less hazardous processes, operations, materials or equipment; use engineering controls and reorganise work; use administrative controls, including training; and use adequate personal protective equipment. Controls are often combined, but an auditor will expect higher levels to have been considered before procedures and PPE.

Does ISO 45001 cover mental health and stress?

+

Yes. The hazard identification clause, 6.1.2.1, includes how work is organised and social factors such as workload, work hours, victimisation, harassment and bullying, along with leadership and culture. ISO 45003, published in 2021, gives guidance on managing psychosocial risk within an ISO 45001 system. Phase 3 asks for psychosocial hazards explicitly, because a walk-round never finds them.

Is ISO 45001 being revised, and what happens to our certificate?

+

Yes. A draft revision, ISO/DIS 45001, was balloted from June to September 2026, and ISO expects the new edition to replace ISO 45001:2018 in the first half of 2027. Once the new edition is published, the accreditation bodies will set a transition period, and you will move to it at a surveillance, recertification or separate transition audit agreed with your certification body.

Can ISO 45001 be combined with ISO 9001 and ISO 14001?

+

Yes. All three share the same high-level clause structure, from context in clause 4 to improvement in clause 10, so many organisations run one management review and audit programme. Keep worker participation, the hierarchy of controls and incident investigation visible: ISO 9001 has no equivalent.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

A Safety System Your Workers Helped Run, With the Records to Show It

Free trial — no credit card required.