HSE Incident, Nonconformity, and Corrective Action Procedure Template & Guide (ISO 14001 + ISO 45001)

HSE Incident, Nonconformity, and Corrective Action Procedure Template & Guide (ISO 14001 + ISO 45001)

$249
One integrated procedure satisfying ISO 14001:2026 Clause 10 and ISO 45001:2018 Clause 10 together — for organizations running environment and occupational health and safety through one improvement system. Includes the integration decision record.

ISO 14001:2026 + ISO 45001:2018 · $249 · Editable Word format

A solvent spill in a warehouse is an environmental release and an exposure event at the same time. So is a gas leak, a fire, a failed containment, and most of what an EHS function actually deals with. Running two improvement systems over one set of events produces two records, two causes, two owners, and two effectiveness checks that never reconcile.

This is one procedure covering ISO 14001:2026 Clause 10 and ISO 45001:2018 Clause 10 in full, in editable Word format, written as a filled-in worked example with bracketed placeholders where values are yours to set.

The two standards diverge more here than most integrated systems assume. ISO 45001 covers incidents; ISO 14001 has no incident concept at all. ISO 45001 requires worker participation in the cause evaluation and requires the resulting documented information to be communicated to workers and their representatives; ISO 14001 requires neither. ISO 45001 requires action selection in accordance with the hierarchy of controls and a hazard assessment before implementation; ISO 14001 requires instead that corrective action be appropriate to the significance of the effects including environmental impact. ISO 45001 requires documented information to be retained; ISO 14001:2026 requires it to be available. ISO 45001 Clause 10.3 sets five specific requirements for continual improvement, including promoting a supportive culture and worker participation; ISO 14001 Clause 10.1 is a single paragraph tied to environmental performance.

This procedure takes the stricter of each as the house standard — worker participation on every finding, the hierarchy of controls applied to environmental controls as well as safety controls, the significance test applied to both, and the pre-implementation hazard assessment applied to both. That is a defensible position and it is more work than either standard alone requires. Appendix D records it as a decision, with the alternative stated, so the choice is visible to anyone reviewing the system rather than looking like two standards that collided.

What’s included

Everything in both single-standard templates, integrated into one document — 47 pages, editable Word format — plus:

  • One intake covering incidents, nonconformities, spills and releases, compliance evaluation failures, monitoring results, audit findings, and emergency response reviews
  • Dual severity model — environmental significance from the aspects register alongside OH&S risk, with the higher of the two governing the route
  • Inline scope markers showing which standard drives each requirement, so nothing reads as unexplained
  • Worker participation applied to both scopes, satisfying ISO 45001 and exceeding ISO 14001
  • Hierarchy of controls applied to both scopes at action selection
  • Pre-implementation hazard and impact assessment applied to both scopes
  • Compliance obligation route covering both environmental compliance obligations and OH&S legal and other requirements
  • Emergency preparedness interface — post-emergency evaluation routed into the register under both standards
  • Documented information handled to the stricter of retained and available, with the distribution obligation to workers and their representatives satisfied
  • Continual improvement section covering all five ISO 45001 elements and the ISO 14001 environmental performance link
  • Dual cross-reference — every obligation mapped across ISO 14001:2026, ISO 45001:2018, and where addressed
  • Appendix C with two worked examples — one release event, one exposure event, each showing the other standard's obligations activating on the same record
  • Appendix D — the integration decision record

Who it’s for

EHS managers and consultants at organizations certified or certifying to both ISO 14001 and ISO 45001. Particularly useful for sites where one team owns both systems and maintains two registers, and for organizations transitioning to ISO 14001:2026 who want to rebuild the improvement process once rather than twice.

What it does for you

  • One event, one record. A release that is also an exposure stops generating two investigations that reach two different causes.
  • Take the stricter position deliberately. Worker participation and the hierarchy of controls applied to environmental findings is more than ISO 14001 asks, and it is defensible — Appendix D says so in writing.
  • Transition once. If you are moving to ISO 14001:2026, rebuilding the improvement process across both systems at the same time costs less than doing it twice.
  • Reconcile the documented information requirements. Retained and available are not the same word, and the stricter reading is the one that survives both audits.
  • Bring one trend to management review. Both standards require nonconformity and corrective action trends as a review input. One register produces both.

Clauses addressed

14001: 10.1, 10.2 · 45001: 10.1–10.3

Buy — $249

Other variants of this procedure

VariantPrice
ISO 9001$149
ISO 13485$149
ISO 14001:2026$149
ISO 45001$149
ISO 7101$149
Device (9001 + 13485)$249
Q/EMS (9001 + 14001)$249
Integrated (9001 + 14001 + 45001)$249

Questions

Is this a template or a finished procedure?

Both, and that is deliberate. It is written as a filled-in worked example so you can see what each element looks like when done properly, with bracketed placeholders wherever a value is genuinely yours to set — severity thresholds, roles, systems, intervals, retention periods. You are editing a working document rather than filling in a hollow outline.

What format?

Editable Microsoft Word (.docx), with a PDF copy. Where a process interaction map is included, it ships as an editable SVG alongside the embedded image. Adapt it, rebrand it, adopt it into your document control system. Yours to use.

Will this pass an audit?

A procedure does not pass an audit; an organization does. What this gives you is a procedure that addresses every requirement of the clause with a named owner and a named record, and that describes a process people can actually follow. Conformity is demonstrated by implementation and evidence — a perfect document over an operation that ignores it is still a finding. Unfilled placeholders are unmet requirements, so fill them.

Does it cover the whole standard?

No. Each covers the improvement clause of its standard in full, plus control of nonconforming output where the standard has such a clause. They are one procedure in a management system, and they reference the neighboring processes — document control, internal audit, complaint handling, risk management, management review — rather than replacing them.

What is the difference between correction and corrective action, and why does it matter here?

Correction addresses the thing in front of you: scrap it, rework it, contain it, tell the customer. Corrective action removes the cause so it does not happen again. Every standard in this family requires both, and treats them as separate obligations. The common failure is one form doing both jobs, which lets a disposition record close a finding without any cause ever being examined. These templates keep them as two records with a stated trigger between them, which is usually the single biggest change an organization makes when adopting one.

We already have a corrective action form. Is that not enough?

A form captures what happened. A procedure decides what happens next — which findings get a cause analysis and which do not, who is allowed to decide, how long the organization has, what evidence closes it, and what happens when the check fails. Most systems have a good form sitting on top of an unstated process, which is why closure rates look healthy while the same findings keep coming back.

We use different clause numbering and a different document system.

Every cross-reference is in a table at the back rather than baked into the body text, precisely so you can renumber without unpicking the procedure.

Which one do I need?

Take the template for the standard you are certified to. If you run more than one management system through one improvement process, take the matching combined variant — Device for ISO 9001 with ISO 13485, HSE for ISO 14001 with ISO 45001, Integrated for all three of quality, environment, and safety. If you are unsure, the free Nonconformity and Corrective Action Maturity Check will show you where your current process actually sits before you spend anything.

Can you help us implement it?

Yes. Call Management Systems International at 760-434-9141 to schedule a planning session.

About Management Systems International

MSI is a veteran-owned, woman-owned ISO consulting firm founded in 1998. Diana Lynn has 28 years of experience, has supported more than 80 organizations through successful ISO certification, has attended more than 200 certification and surveillance audits, and has trained more than 600 professionals across manufacturing, technology, medical device, government, healthcare and other regulated industries.

Questions before you buy? Call 760-434-9141.

© 2026 Management Systems International, LLC · All rights reserved