How to Audit ISO 45001 Documented Information Before Certification in 14 Days
An ISO 45001 documented-information audit should test whether records support real risk control, not whether folders look complete. This 14-day method helps EHS managers connect documented information to operational decisions before certification.
Key takeaways
- 01ISO 45001 documented information is useful only when it proves that risk controls are defined, understood, applied, and reviewed.
- 02A 14-day audit should begin with high-consequence work and decision records, not with a folder-by-folder formatting review.
- 03The most important test is whether a supervisor can find the current control, understand its owner, and show evidence that it works in the field.
- 04Andreza Araujo distinguishes a complete document set from an effective management system.
- 05The final output should be a prioritized correction plan with owners, evidence requirements, and a verification date before the certification audit.
Many organizations approach ISO 45001 certification by asking whether every required document exists. The stronger question is whether each record proves that a real risk decision was made, communicated, applied, and checked.
ISO 45001:2018 requires controlled documented information, but a perfectly indexed repository can still hide weak permits, outdated procedures, unverified competence, and emergency plans that nobody can execute. This 14-day method gives an EHS manager a practical route from document inventory to field confidence.
Before you start, define what the audit must prove
Before reviewing a file, define the operational claim it should support. A procedure should show how a significant hazard is controlled. A training record should show that the person is competent for the assigned task. A corrective-action record should show that the organization changed a condition, not only closed a workflow.
ISO explains that ISO 45001:2018 provides a structured system for managing occupational health and safety risks and improving performance. Read that system logic alongside the comparison of ISO 45001, ANSI Z10, and ILO-OSH before fixing local terminology. Write one audit question: can a competent person use this information to control the stated risk under normal and abnormal conditions?
Step 1: Freeze the audit scope and evidence owners
A 14-day audit needs a fixed boundary. Select the site, shifts, departments, contractor interfaces, and processes that certification will cover, then name one evidence owner for each process. ISO 45001 assigns responsibilities through the management system, so an unowned record is already a control weakness.
Do not assign ownership only to EHS. Operations should own operational procedures, maintenance should own isolation and inspection evidence, learning should own competence records, and site leadership should own management review and resources. Across more than 250 cultural transformation projects, Andreza Araujo has seen that ownership becomes credible when the line organization can explain the decision without waiting for EHS to translate it.
Publish a one-page scope note with the audit boundary, evidence owner, backup owner, review date, and escalation route. Classify any unowned record as an open gap by the end of day one.
Step 2: Map documents to significant hazards
Build the review list from the hazard register and legal requirements, not from folder names. For each significant hazard, identify the risk assessment, operational control, competence requirement, inspection or monitoring record, emergency response, incident learning, and management review link.
This mapping exposes a common failure. A site may have a confined-space procedure, a rescue plan, and training certificates, yet no evidence that the rescue method was checked against actual access, equipment, staffing, and response time. The files exist, but the control chain is incomplete.
Use a matrix with one row per significant hazard and columns for requirement, current document, field owner, evidence date, and unresolved question. The matrix should make missing links visible before an auditor does.
Step 3: Verify version control where work changes
Version control is not a file-name convention. It is the ability to prove that the person doing the work received the current instruction and that obsolete information cannot quietly guide a decision.
Check revision history, approval, effective date, distribution method, withdrawal of obsolete copies, and the point at which the change reached the field. HSE guidance on leadership emphasizes arrangements that are understood, implemented, and reviewed, so the audit must test the path from approval to use.
Select three changed documents from the previous six months and trace each one to a briefing, electronic acknowledgment, or observed work practice. If the document changed but the work did not, record an implementation gap.
Step 4: Test operational controls against real work
Choose five high-risk activities and compare the approved instruction with what the shift actually does. Check permits, isolation points, pre-job planning, equipment condition, supervision, and recovery when the plan no longer matches the field.
The central thesis is that a document is not an operational control until it changes a decision at the point of exposure. In Safety Culture: From Theory to Practice, Andreza Araujo treats the distance between declared rules and operated rules as a diagnostic signal.
Interview the worker and supervisor separately. Ask what could go wrong, which control matters most, what happens when production pressure changes the plan, and where the current instruction can be found. Record differences in understanding as system evidence.
Step 5: Check competence evidence, not attendance alone
Attendance proves that someone was present for a learning event. It does not prove that the person can recognize the hazard, select the control, or respond when conditions change. Competence evidence should connect role requirements, training, experience, evaluation, and authorization.
Review workers in critical roles, including contractors and supervisors. Confirm the required competence, current authorization, practical evaluation where relevant, refresher trigger, and evidence that limitations were communicated.
Ask how competence is checked after a procedure changes or a person moves between tasks. If the answer is only a spreadsheet status, add a field verification action with a named assessor and due date.
Step 6: Reconcile legal and external requirements
Legal registers and external requirements should lead to decisions, owners, and review evidence. A list of regulations without applicability reasoning does not show that the organization understands what applies to its site, process, equipment, or workforce.
Check the source, jurisdiction, applicability decision, responsible owner, last evaluation, and resulting operational change. Use official sources such as ISO information on ISO 45001:2018 and HSE guidance on leadership, rather than an undated secondary summary.
Sample three recent legal or standards updates and trace them to a revised procedure, risk assessment, communication, or documented decision. If no operational consequence was considered, the register is functioning as a library instead of a control mechanism.
Step 7: Examine incidents, corrective actions, and change
Incident and corrective-action records should show how the organization learned, assigned control ownership, and verified effectiveness. Closure dates alone are weak evidence because an action can be completed administratively while the exposure remains unchanged.
Review five closed actions and ask whether each one changed the hazard, the barrier, the work design, the competence requirement, or the supervisory routine. Compare each action with repeat events, near misses, inspection findings, and management-review decisions. James Reason helps investigators look for latent conditions that make weak control more likely.
Mark an action ineffective when the evidence shows only a memo, a retraining event, or a revised form without field verification. A readiness audit should leave leadership with fewer open questions about control effectiveness.
Step 8: Run the final evidence review and correction plan
On days thirteen and fourteen, run a cross-functional review using the hazard matrix, sample results, legal checks, competence findings, and corrective-action tests. Sort gaps by potential consequence, control weakness, evidence quality, owner, and time to verification.
Separate missing information, obsolete information, and information that is correct but not followed. Each requires a different correction. Recreating a document cannot solve an ownership or implementation problem.
Agree on no more than ten priority corrections before certification. Each correction needs an accountable owner, a completion date, the evidence required, and a verification method. A senior leader should sign the decision when a gap remains open because the business has accepted temporary risk.
Comparison: document completeness versus operational control
The table below distinguishes a repository that looks ready from a management system that can defend its decisions. Certification evidence should represent work as it is controlled, not only work as it is described.
| Audit question | Document completeness | Operational control |
|---|---|---|
| Procedure | Approved file with revision date | Current instruction changes the work at the hazard |
| Competence | Attendance or training status | Role competence is evaluated and authorized |
| Legal requirements | Register entry | Applicability leads to an owned operational decision |
| Corrective action | Action marked closed | Effectiveness is verified where the exposure occurs |
| Management review | Minutes stored | Leadership allocates resources and follows unresolved risk |
For a broader explanation of why paperwork can look complete while control remains weak, see Compliance Is Not Control and the four evidence layers that connect stated values to shift decisions.
Conclusion: certify the control system, not the filing system
An ISO 45001 readiness audit is credible when every important document can be connected to a hazard, an owner, a decision, and evidence of use. The 14-day sequence begins with scope and hazards, moves through version control and field verification, and ends with prioritized corrections that leadership can verify.
If your team needs to turn certification preparation into a working safety management system, explore the resources from Andreza Araujo. The current information must reach the person making the next risk decision.
Frequently asked questions
What is documented information in ISO 45001?
How long does an ISO 45001 documentation audit take?
What should be checked first before ISO 45001 certification?
Can an organization pass certification with missing documents?
What is the difference between document compliance and operational control?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.