ISO 45001:2018 · Clause 9.2 Internal audit
ISO 45001 Clause 9.2 carries three requirements that appear in no other management system standard, and all three are about who is involved.
This is a complete Clause 9.2 procedure built around them. Editable Word format, filled-in worked example, bracketed placeholders wherever the value is yours to set.
Clause 9.2.2 d) requires relevant audit results to be reported to workers, and where they exist, workers' representatives and other relevant interested parties. Reporting to management is the universal habit. Reporting to workers is the requirement MSI most often finds unimplemented in ISO 45001 systems.
It is not difficult — a standing item in a team brief discharges it — but nothing in a general audit procedure points at it, so it is never built in.
What this template does about it: A five-audience reporting table with stated intervals, a worker reporting log in the program register, a field on the audit plan recording the date and route, and a KPI. An obligation nothing measures stops happening within a cycle.
| Requirement | Where it comes from | How the template handles it |
|---|---|---|
| Consultation inside the audit program | Clause 9.2.2 a) | Consultation is part of the program itself, not a courtesy applied to its results. Section 6.3 and a consultation log in Appendix B, with the test an auditor will apply: could the program have changed as a result? |
| The OH&S policy and objectives as audit criteria | Clause 9.2.1 | Named explicitly by the clause, and the criteria most often missing from an OH&S audit plan. The audit plan has separate rows for which commitments and which objectives will be examined. |
| Reporting relevant results to workers | Clause 9.2.2 d) | Five audiences, stated intervals, a reporting log, and a KPI. |
| Action cross-referenced to Clause 10 | Clause 9.2.2 e) | The only standard in the family that cites Clause 10 by name inside the audit clause. Continual improvement of OH&S performance is treated as part of the closure path. |
| A narrower program input list | Clause 9.2.2 a) | ISO 45001 does not name changes affecting the organization as an input, where ISO 9001 and ISO 14001 do. The template includes it as house standard and marks it as such. |
33 pages, editable Microsoft Word format.
Clause 9.2.2 a) requires the audit program to consider the importance of the processes concerned. That is the requirement that makes risk-based prioritization mandatory. The template turns it into a mechanism, with hazard profile, incident history, and the worker view as three of the lenses.
| What varies | Higher risk | Lower risk |
|---|---|---|
| Frequency | Every cycle, re-audited early where findings recur | Longer interval, with the basis recorded |
| Depth | Walked end to end, including handoffs | Key controls sampled |
| Sample size | Large enough to support a conclusion about the system | Sufficient to confirm the control operates |
| Method | On-site, including the shift where supervision is thinnest | Records reviewed remotely |
| Auditor | Most experienced available; second auditor where contested | Any qualified auditor on the register |
Why this matters: Most programs answer the importance-of-processes requirement by adjusting frequency alone. A low-risk and a high-risk process both audited annually, same checklist, same two-hour slot, have not been differentiated in any way that changes what the audit finds.
OH&S managers, safety committee chairs, and management representatives at ISO 45001 certified organizations. Particularly useful where the safety audit is run off a quality audit procedure and the worker-facing obligations were never picked up.
$149
Single-standard variant. ISO 45001:2018 Clause 9.2, in full.
One-time payment. Immediate download. Editable Microsoft Word format.
Because ISO 45001:2018 contains no requirement to determine the sequence and interaction of processes. MSI does not supply a map where the standard does not call for one. The ISO 9001, ISO 13485, ISO 7101, Device, HSE, and IMS variants each carry one.
Seeking views before deciding. Issuing a finished audit schedule to the safety committee for information is communication, and it does not discharge Clause 9.2.2 a). The test an auditor will apply is whether the program could have changed as a result — and the evidence for that is a record showing a view was expressed and either adopted or answered.
Both, and that is deliberate. It is written as a filled-in worked example so you can see what each element looks like when done properly, with bracketed placeholders wherever a value is genuinely yours to set — thresholds, roles, systems, retention periods, audit frequency. You are editing a working document rather than filling in a hollow outline.
Editable Microsoft Word (.docx). Adapt it, rebrand it, adopt it into your document control system.
It is structured to the ISO 19011:2026 clause architecture, and it implements the change ISO names in its own foreword — expanded guidance on remote auditing methods, drawing on ISO/IEC TS 17012. Everything beyond that, including the platform-specific competence prerequisite and the evidence-reliability check, is MSI's house standard drawn from 200+ audits attended, and is labeled as such in the document. ISO 19011 is guidance rather than a requirements standard, so no organization is certified against it and no clause of it can be raised as a nonconformity.
A procedure does not pass an audit; an organization does. What this gives you is a procedure that addresses every requirement of the clause with a named owner and a named record, and that describes a process people can actually follow. Conformity is demonstrated by implementation and evidence — a perfect document over a program that ignores it is still a finding. Unfilled placeholders are unmet requirements, so fill them.
Outside this procedure, deliberately. This one owns the audit program, the audit, the report, finding classification, and the follow-up verification. Root cause analysis, the corrective action record, and effectiveness evaluation belong in your corrective action procedure. The handoff is defined at one named point so nothing falls between them.
Every cross-reference is held in a table at the back rather than baked into the body text, precisely so you can renumber to your own system without unpicking the procedure.
Yes. Call MSI at 760-434-9141 to schedule a planning session.
The free Internal Audit Maturity Check scores eight elements of your audit program in under five minutes and returns an element-by-element breakdown with a priority order. It is the same maturity ladder built into this template, so it will tell you which sections matter most to you before you spend anything.
Take the free Internal Audit Maturity Check
Management Systems International, LLC is a veteran-owned, female-owned ISO consulting firm co-founded in 1998. MSI has 28 years of experience, has supported 80+ certifications, attended 200+ audits, and trained 600+ professionals across manufacturing, technology, medical device, government, healthcare, and other regulated industries.
This template encodes the patterns that recur across that work — not one organization’s approach generalized, but the structural weaknesses that show up again and again.
To discuss your audit program directly, call MSI at 760-434-9141 or 888-914-9141.
© 2026 Management Systems International, LLC · All rights reserved.
Notifications