HSE Internal Audit Procedure Template and Guide (ISO 14001:2026 + ISO 45001:2018)

HSE Internal Audit Procedure Template and Guide (ISO 14001:2026 + ISO 45001:2018)

$249
One internal audit procedure serving ISO 14001:2026 and ISO 45001:2018 together, built to the 2026 environmental changes and the worker-facing safety obligations, with every divergence resolved and recorded.

ISO 14001:2026 + ISO 45001:2018 · Clause 9.2 in both standards

The environmental and safety audit clauses look alike and are not.

Where the standards differ, this procedure takes the stricter as the house standard and says so. The result is a program carrying objectives, control, consultation, and worker reporting across both scopes, with scope markers showing which obligation comes from where.

Ten divergences, running in both directions

ISO 14001:2026 now requires per-audit objectives and requires the audit program itself to be available as documented information. ISO 45001 requires neither.

ISO 45001 requires consultation inside the program, measures conformity against the OH&S policy and objectives, and requires relevant results reported to workers and their representatives. ISO 14001 requires none of those. ISO 45001 requires action on nonconformities with an explicit cross-reference to Clause 10; ISO 14001 Clause 9.2 carries no action requirement at all.

Neither standard is the stricter one throughout, which is exactly why a merged procedure written from whichever came first loses something.

Appendix D is why this variant costs more: Every divergence, the house standard adopted, the alternative that was rejected, and where in the procedure it applies. Row 8 is the one most often missed: a blended importance score hides the process that is high risk in one discipline and low in the other.

What this variant carries that the others do not

RequirementWhere it comes fromHow the template handles it
Both 2026 environmental changesISO 14001:2026 Clause 9.2.2Objectives and the program as available documented information, carried across the combined program.
Consultation extended to both scopesISO 45001 Clause 9.2.2 a)Consultation covers the whole program, environmental audits included, with a log in Appendix B.
Worker reporting extended to both scopesISO 45001 Clause 9.2.2 d)One combined audit produces one brief. Extending it to environmental results costs nothing and makes the environmental system visible to the people who operate it.
Two importance lenses, recorded separatelyMSI house standardEnvironmental significance and OH&S risk profile scored separately, never averaged.
The compliance evaluation boundary, twiceClause 9.1.2 in bothA distinct requirement in both standards, satisfied by neither audit. In a combined system that means up to four determinations, not two.
Process interaction mapMSI house standardEditable SVG plus embedded image, with the scope of each interface marked.

What you get

40 pages, editable Microsoft Word format. The process interaction map ships alongside as an editable SVG.

  • Complete internal audit procedure in editable Microsoft Word format
  • Audit program built as a controlled document, with defined re-planning triggers rather than a rolling annual calendar
  • Risk-based audit planning section, with the five levers risk actually changes
  • Per-audit objectives field, with worked examples of well-formed and poorly-formed objectives
  • Method-selection step — on-site, remote, or hybrid, chosen against the evidence the objective demands, with the rationale recorded
  • Platform-specific auditor competence prerequisite (MSI house standard)
  • Evidence-reliability check for remote and digital evidence (MSI house standard)
  • Auditor independence rules written as a decision test, not an intention
  • Finding classification scheme with stated criteria, so a finding means the same thing whoever raised it
  • Follow-up and closure path, with the handoff to corrective action defined at one named point
  • Records table with a location, an owning role, and a retention basis for every record
  • Maturity ladder — eight elements, four levels, scoreable as a self-assessment, with Level 3 named as a legitimate place to stop
  • Full clause cross-reference table mapping every obligation to where it is addressed
  • Section mapping to the ISO 19011:2026 published clause structure
  • Process interaction map — editable SVG plus the embedded image, so you can redraw it to your own process names
  • Appendix A — audit plan, built to function as the gate that opens an audit
  • Appendix B — audit program register with the re-planning log
  • Appendix C — desk-level auditor work instruction with a worked example
  • Appendix D — integration decision record: every divergence between the standards, what this procedure does, and what the alternative was

Risk-based audit planning, written as a mechanism

Both clauses require the program to take account of process importance, each through its own lens. The template turns it into a mechanism, with environmental significance and hazard profile recorded separately and the audit set against the higher of them.

What variesHigher riskLower risk
FrequencyEvery cycle, re-audited early where findings recurLonger interval, with the basis recorded
DepthWalked end to end, including handoffsKey controls sampled
Sample sizeLarge enough to support a conclusion about the systemSufficient to confirm the control operates
MethodOn-site, including the shift where supervision is thinnestRecords reviewed remotely
AuditorMost experienced available; second auditor where contestedAny qualified auditor on the register

Why this matters: Most programs answer the importance-of-processes requirement by adjusting frequency alone. A low-risk and a high-risk process both audited annually, same checklist, same two-hour slot, have not been differentiated in any way that changes what the audit finds.

Who this is for

HSE managers and management representatives at organizations holding both ISO 14001 and ISO 45001, and consultants supporting integrated environmental and safety systems. Particularly useful during the ISO 14001:2026 transition, when the environmental clause changes and the safety clause does not.

What it does for you

  • Transition the environmental side without disturbing the safety side. The 2026 changes are marked, so what changed is visible.
  • Keep the worker obligations from being lost in the merge. Consultation and worker reporting are ISO 45001 requirements with no environmental counterpart.
  • Bring the program under control once. ISO 14001:2026 requires it; extending it across both scopes costs nothing extra.
  • Score the two lenses separately. A blended importance number gives a middling audit to a process that is critical in one discipline.
  • See the design decisions. Appendix D records every divergence and the alternative that was rejected.

$249

Combined variant. Both clauses in full, with the divergences resolved and recorded.

One-time payment. Immediate download. Editable Microsoft Word format.

Questions

We are mid-transition to ISO 14001:2026. Is this the right time?

It is arguably the best time. The environmental audit clause changed and the safety clause did not, so a combined procedure written before the transition is now partly out of date on one side only. This variant marks the 2026 changes explicitly, which makes the transition work visible rather than buried.

Why extend worker reporting to environmental audits when ISO 14001 does not require it?

Because the audit is combined and the brief is one brief. Splitting the reporting so that safety findings reach workers and environmental findings do not is arbitrary, costs more to administer than doing both, and leaves the environmental system invisible to the people who operate it. The decision is recorded at Appendix D row 5, so you can reverse it deliberately if you disagree.

Is this a template or a finished procedure?

Both, and that is deliberate. It is written as a filled-in worked example so you can see what each element looks like when done properly, with bracketed placeholders wherever a value is genuinely yours to set — thresholds, roles, systems, retention periods, audit frequency. You are editing a working document rather than filling in a hollow outline.

What format does it arrive in?

Editable Microsoft Word (.docx). Adapt it, rebrand it, adopt it into your document control system.

Is this built to ISO 19011:2026?

It is structured to the ISO 19011:2026 clause architecture, and it implements the change ISO names in its own foreword — expanded guidance on remote auditing methods, drawing on ISO/IEC TS 17012. Everything beyond that, including the platform-specific competence prerequisite and the evidence-reliability check, is MSI's house standard drawn from 200+ audits attended, and is labeled as such in the document. ISO 19011 is guidance rather than a requirements standard, so no organization is certified against it and no clause of it can be raised as a nonconformity.

Will this pass an audit?

A procedure does not pass an audit; an organization does. What this gives you is a procedure that addresses every requirement of the clause with a named owner and a named record, and that describes a process people can actually follow. Conformity is demonstrated by implementation and evidence — a perfect document over a program that ignores it is still a finding. Unfilled placeholders are unmet requirements, so fill them.

Where does corrective action sit?

Outside this procedure, deliberately. This one owns the audit program, the audit, the report, finding classification, and the follow-up verification. Root cause analysis, the corrective action record, and effectiveness evaluation belong in your corrective action procedure. The handoff is defined at one named point so nothing falls between them.

We use different clause numbering or a different document system.

Every cross-reference is held in a table at the back rather than baked into the body text, precisely so you can renumber to your own system without unpicking the procedure.

Can you help us implement it?

Yes. Call MSI at 760-434-9141 to schedule a planning session.

Not sure where your program stands?

The free Internal Audit Maturity Check scores eight elements of your audit program in under five minutes and returns an element-by-element breakdown with a priority order. It is the same maturity ladder built into this template, so it will tell you which sections matter most to you before you spend anything.

Take the free Internal Audit Maturity Check

Related training

If your organization is already certified to ISO 14001:2015, MSI's transition course covers the changes across the whole standard: ISO 14001:2026 Transition

About Management Systems International

Management Systems International, LLC is a veteran-owned, female-owned ISO consulting firm co-founded in 1998. MSI has 28 years of experience, has supported 80+ certifications, attended 200+ audits, and trained 600+ professionals across manufacturing, technology, medical device, government, healthcare, and other regulated industries.

This template encodes the patterns that recur across that work — not one organization’s approach generalized, but the structural weaknesses that show up again and again.

To discuss your audit program directly, call MSI at 760-434-9141 or 888-914-9141.

© 2026 Management Systems International, LLC · All rights reserved.