Legislation, Audits & Inspections16 min readPublished 18 July 2026

ISO 45001 Clause-by-Clause Internal Audit Scoring Guide & Checklists

The master practitioner guide to ISO 45001:2018 internal audit scoring, auditing Clause 4 through Clause 10, Major vs Minor Non-Conformances, evidence sampling matrices, and SANAS certification readiness.

ISO 45001 Lead Auditor scoring occupational health and safety management system compliance matrices on clipboardExecuting clause-by-clause internal audits and scoring matrices for ISO 45001:2018 certification.

1. The High-Level Structure: High-Performance Auditing across Clauses 4 to 10

Achieving and maintaining ISO 45001:2018 Certification (Occupational Health and Safety Management Systems) is the hallmark of elite corporate governance in South Africa. Mining corporations, global automotive manufacturers, and tier-one civil engineering groups mandate ISO 45001 certification as a non-negotiable tender pre-requisite.

However, a management system is only as robust as the internal audits that validate it. Under Clause 9.2 (Internal Audit), an organization must conduct formal internal audits at planned intervals to determine whether the OH&S management system conforms to the standard's requirements and is effectively implemented and maintained.

Conducting superficial 'tick-box' audits leaves hidden legal non-compliances that lead to failed Stage 2 external certification audits by SANAS-accredited bodies (e.g. SABS, DNV, BSI, TÜV) and catastrophic workplace incidents.

ISO 45001 Internal Audit Benchmarks

Clause 9.2
Audit Standard
Mandatory requirement to maintain an active internal audit programme.
100% Impartial
Auditor Rule
Auditors must not audit their own operational work areas.
Zero Major NCs
Certification Gate
External certification fails if any single Major Non-Conformance remains open.
Tri-Fold Audit
Evidence Matrix
Sampling documented files, physical conditions, and frontline worker interviews.

2. Clause-by-Clause Audit Checklists: Sampling Objective Evidence

An ISO 45001 internal auditor must systematically evaluate seven core High-Level Structure (HLS) clauses:

Clause 4 (Context of the Organization): Auditing external and internal issues (PESTLE), stakeholder needs (DEL, unions), and OH&S system scope.

Clause 5 (Leadership & Worker Participation): Auditing executive commitment, policy communication, organizational roles, and active consultation with non-managerial workers.

Clause 6 (Planning): Auditing hazard identification (HIRA), legal registers (Clause 6.1.3), and measurable OH&S objectives.

Clause 7 (Support): Auditing resources, training competence, communication, and documented information control.

Clause 8 (Operation): Auditing operational controls, contractor management (8.1.4), change management (8.1.3), and emergency preparedness (8.2).

Clause 9 (Performance Evaluation): Auditing monitoring, legal evaluation (9.1.2), internal audits (9.2), and management reviews (9.3).

Clause 10 (Improvement): Auditing incident investigations, corrective action root causes (10.2), and continual improvement.

Grading Audit Findings: Major NC vs Minor NC vs Opportunity for Improvement

Finding CategoryObjective Definition & TriggerImpact on CertificationMandatory Corrective Action
Major Non-Conformance (Major NC)Total absence or breakdown of a mandatory clause (e.g. no legal evaluation, unmitigated fatal fall hazard).Blocks certification immediately; external auditor issues immediate Stage 2 failure.Root-cause investigation, corrective action, and mandatory re-audit within 90 days.
Minor Non-Conformance (Minor NC)Isolated administrative lapse (e.g. 1 out of 50 training records missing, single delayed calibration log).Does not block certification, provided a corrective action plan is approved.CAPA plan submitted within 30 days; verified at next audit cycle.
Opportunity for Improvement (OFI)Conforming process that could be optimized for higher efficiency or digital tracking.Zero negative impact on certification.Discretionary review by Management Review Committee.
Objective criteria for classifying ISO 45001 internal audit findings.

3. Scoring & Grading Findings: Major Non-Conformance vs Minor vs OFI

An effective internal audit grading matrix utilizes a quantitative scoring scale (e.g. 0 to 100% conformance per clause):

100% Conformance: Objective evidence proves process is fully implemented, documented, and continually improving.

Minor NC (75% Score): System exists and functions, but minor lapses in documentation or execution were sampled.

Major NC (0% - 50% Score): Significant systemic failure. If a company fails to evaluate legal compliance under Clause 9.1.2, or fails to appoint an impartial internal auditor, a Major NC is automatically registered.

4. The Tri-Fold Verification Methodology: Records, Physical Site & Interviews

A Lead Auditor must never audit solely from a boardroom chair. Auditing requires the Tri-Fold Verification Methodology:

1. Document & Record Sampling: Inspecting policies, risk registers, training matrices, and calibration certificates.

2. Physical Workplace Inspection: Walking the shop floor, checking machine guarding, testing eyewash stations, and verifying chemical bunding.

3. Worker Interviews: Interviewing frontline operators without managers present: *'What are the main hazards of your machine? What do you do if you spot a hydraulic leak? How were you trained?'* If workers cannot explain basic hazards, Clause 7.2 (Competence) fails.

5. 5-Stage ISO 45001 Internal Audit Execution & CAPA Roadmap

01
Develop Annual Risk-Based Internal Audit Programme (Clause 9.2.2)

Schedule audits covering all 7 standard clauses and all operational shifts across the 12-month calendar.

02
Conduct Pre-Audit Document Review & Compile Audit Checklists

Review SOPs, previous audit findings, and draft targeted clause checklists for sampling evidence.

03
Execute Tri-Fold On-Site Audit (Documents, Walkthrough, Interviews)

Sample records, inspect physical workplace controls, and interview frontline workers across departments.

04
Grade Findings & Issue Formal Internal Audit Report

Classify findings into Major NCs, Minor NCs, and OFIs; present executive summary at formal Closing Meeting.

05
Track Corrective Actions (CAPAs) to Verified Closeout

Ensure process owners execute root-cause analyses, implement corrective actions, and verify effectiveness.

6. Master ISO 45001 Clause Scoring & Conformance Checklist

  • Annual Internal Audit Programme (Clause 9.2) is approved and covers all clauses from 4 through 10.
  • Internal auditors are trained, certified, and independent of the operational processes being audited.
  • Clause 4 (Context) and Clause 6.1.3 (Legal Register) are fully updated within the last 12 months.
  • Clause 5.4 (Worker Participation) is proven through active SHE Representative consultation records.
  • Clause 8.1.4 (Contractor Management) audits Section 37(2) agreements and subcontractor safety files.
  • All Major and Minor Non-Conformances have documented root-cause analyses and signed CAPAs.
  • Internal audit summary report is reviewed by executive leadership during Management Review (Clause 9.3).

Frequently Asked Questions

What is the difference between a Stage 1 and Stage 2 ISO 45001 audit?

A Stage 1 audit evaluates documentation readiness (policies, HIRAs, audit plans). A Stage 2 audit is an extensive on-site audit evaluating full operational implementation, worker interviews, and management system effectiveness.

How often must internal audits be conducted under ISO 45001?

Internal audits must be conducted at planned intervals, typically annually, ensuring that all clauses (4 to 10) and all operational departments are audited at least once during the annual audit cycle.

Can an internal safety officer audit their own safety files?

No. Clause 9.2.2 explicitly requires auditors to be impartial and objective. Safety officers cannot audit their own work; internal audits must be conducted by cross-trained peers or independent external consultants.

What happens if a Major Non-Conformance is found during a certification audit?

A Major Non-Conformance prevents certification from being granted. The company is given a strict deadline (typically 90 days) to rectify the failure and undergo a special follow-up re-audit before certification can be approved.

How does Diba BES assist with ISO 45001 audits and certification?

Diba BES provides certified ISO 45001 Lead Auditors to conduct independent internal audits, perform gap assessments, design scoring matrices, and mentor companies through external SANAS certification. Book an [ISO 45001 Internal Audit](/services/occupational-health-safety-consulting).

DL
Written by Diba OHS Legal Compliance AuditorsVerified by Orlinda Pieterson
Lead Environmental, Health & Safety (EHS) Lead AuditorsISO 45001 Lead Auditor, LLB, Saiosh Chartered Member

Diba BES is a 100% Black Women-Owned, Level 1 B-BBEE provider delivering occupational health & safety consulting, accredited workplace training, and commercial workplace services across South Africa since 2003.