Checklist · ISO 45001:2018
The ISO 45001 checklist clause by clause, for a small business.
ISO 45001:2018 is written in ten clauses. Clauses 4 to 10 are the ones an auditor tests. This checklist takes each one, says what it asks in plain English, and names the document or register in a small Australian business that answers it. Use it to build the system, to run your own internal audit, or to understand what the certification body will look for. PolicySystem generates every item on the right-hand column. We are not a certification body.
How to use this checklist
Work down the table. For each clause ask three questions: do we have the document or register, is it controlled, and is there evidence it is used. A yes to all three is a pass. A yes to the first only is the most common finding at Stage 1: the paperwork exists but the registers behind it are empty. Record each gap as a corrective action with an owner and a date, and you have also met clause 10.2.
Clauses 4 to 10
| Clause | What it asks | What answers it |
|---|---|---|
| 4.1 to 4.4 Context | Who are your workers and interested parties, what affects your WHS performance, what is the scope of the system? | Scope statement in the policy pack: legal name, sites, states, activities, high-risk work. |
| 5.1 Leadership | Does top management own WHS, provide resources and hold people accountable? | Signed policy, named owner on each document, management review record. |
| 5.2 WHS policy | A policy committed to safe conditions, legal compliance, hazard elimination, consultation and improvement. | WHS policy (OHS in Victoria) under document control. |
| 5.3 Roles and responsibilities | Who is responsible for what, and do they know it? | Responsibilities section in the policy and procedures; induction record. |
| 5.4 Consultation and participation | Are workers consulted on hazards, controls, incidents and changes, and can they raise issues? | Evidence register: toolbox talks, meetings, HSR records. |
| 6.1 Hazards, risks and opportunities | Do you identify hazards proactively, assess risk and plan controls? | Hazard register with risk rating, controls and review date; risk management procedure. |
| 6.1.3 Legal and other requirements | Do you know which laws, codes and client requirements apply and keep them current? | Legal register in the policy pack naming the state acts and regulations you work under. |
| 6.2 Objectives | Measurable WHS objectives with plans to achieve them. | Objectives recorded and reviewed at management review. |
| 7.1 Resources | Enough people, equipment and time to run the system. | Management review input on resource adequacy. |
| 7.2 Competence | Are people competent for the work, and can you prove it? | Induction and training register with tickets and expiry. |
| 7.3 Awareness | Do workers know the policy, hazards, incidents and their right to stop unsafe work? | Induction content and signed record; toolbox talk evidence. |
| 7.4 Communication | What is communicated, when, to whom, and how. | Communication section in the consultation procedure; evidence register. |
| 7.5 Documented information | Documents are identified, approved, current, available and protected. | Document control on every policy and record: number, version, owner, status. |
| 8.1 Operational planning and control | Hierarchy of controls applied, change managed, procurement and contractors controlled. | Procedures for each high-risk activity; chemicals and SDS register; contractor procedure. |
| 8.2 Emergency preparedness | Planned response to emergencies, tested, with roles and training. | Emergency procedure; drill records on the evidence register. |
| 9.1 Monitoring and evaluation | What do you measure, how, and what did it show, including legal compliance. | Register counts and trends at management review; inspection evidence. |
| 9.2 Internal audit | Planned audits by competent people, findings reported, actions taken. | AI internal auditor scored against these clauses; CAPA raised for gaps. |
| 9.3 Management review | Top management reviews the system at planned intervals against the listed inputs. | Management review record built from live registers. |
| 10.2 Incident, nonconformity and corrective action | Incidents reported, investigated, root cause found, corrective action taken and checked. | Incident and near miss register linked to the CAPA register. |
| 10.3 Continual improvement | Does the system get better over time, and can you show it? | Closed CAPA, improved audit score, actions from management review. |
The clauses small businesses most often fail
- 5.4 Consultation. Consultation happens every day on a small crew, but nobody writes it down. A dated toolbox talk record with what was raised fixes it.
- 6.1.3 Legal requirements. The policy says "all applicable legislation" and names nothing. Name the acts, regulations and codes for the states you work in.
- 7.2 Competence. Tickets exist but expiry is not tracked and one has lapsed. The training register with expiry dates fixes it.
- 9.2 Internal audit. Skipped because nobody knew how. The internal audit checklist and the AI auditor are for exactly this.
- 10.2 Corrective action. Incidents are recorded but no root cause or follow-up is written. Link each incident to a corrective action and close it.
ISO 45001 and Australian law
The standard is voluntary. Work health and safety law is not. The good news is that the two line up: the duties in the model WHS Act and the Victorian OHS Act (manage risk, consult, train, report, keep records) are clauses 6, 5.4, 7.2, 10.2 and 7.5 in the table above. A business that meets the standard meets the law, and a business that meets the law with records is most of the way to the standard. See WHS requirements for small business for the legal side.
Where to next
ISO 45001 · Internal audit checklist · Incident register · Training register · How to get certified · WHS management system
Common questions.
No. ISO publishes the standard, not a checklist. Certification bodies and consultants each write their own from the clauses. This one is written for a small Australian business and names the document or register that answers each clause, which is what an auditor is really looking for.
Every clause from 4 to 10 applies to every organisation. What changes is the depth. A twelve-person cleaning company does not need a corporate risk committee to meet clause 6.1; a hazard register with controls and a review date does the job. The standard asks for outcomes, not paperwork volume.
AS/NZS 4801 was the Australian and New Zealand OHS management system standard. It was withdrawn after ISO 45001 was published in 2018, and certifications transitioned by 2021. Tenders that still mention 4801 mean 45001. Some also accept the National Self-Insurer OHS Audit Tool for larger employers.
Clause 8.1.4 asks you to coordinate with contractors, make sure they meet your WHS requirements, and control outsourced work. In practice that is a contractor induction, checking their licences and insurance, and including them in consultation and incident reporting. They count as workers under the standard and under Australian law.
No. It scores your system against these clauses so you know your gaps before the certification body does, and it tells you which form to file to close each one. Certification still requires a JAS-ANZ accredited body to audit and issue the certificate.