1. The High-Level Structure: High-Performance Auditing across Clauses 4 to 10
Achieving and maintaining ISO 45001:2018 Certification (Occupational Health and Safety Management Systems) is the hallmark of elite corporate governance in South Africa. Mining corporations, global automotive manufacturers, and tier-one civil engineering groups mandate ISO 45001 certification as a non-negotiable tender pre-requisite.
However, a management system is only as robust as the internal audits that validate it. Under Clause 9.2 (Internal Audit), an organization must conduct formal internal audits at planned intervals to determine whether the OH&S management system conforms to the standard's requirements and is effectively implemented and maintained.
Conducting superficial 'tick-box' audits leaves hidden legal non-compliances that lead to failed Stage 2 external certification audits by SANAS-accredited bodies (e.g. SABS, DNV, BSI, TÜV) and catastrophic workplace incidents.
ISO 45001 Internal Audit Benchmarks
2. Clause-by-Clause Audit Checklists: Sampling Objective Evidence
An ISO 45001 internal auditor must systematically evaluate seven core High-Level Structure (HLS) clauses:
Clause 4 (Context of the Organization): Auditing external and internal issues (PESTLE), stakeholder needs (DEL, unions), and OH&S system scope.
Clause 5 (Leadership & Worker Participation): Auditing executive commitment, policy communication, organizational roles, and active consultation with non-managerial workers.
Clause 6 (Planning): Auditing hazard identification (HIRA), legal registers (Clause 6.1.3), and measurable OH&S objectives.
Clause 7 (Support): Auditing resources, training competence, communication, and documented information control.
Clause 8 (Operation): Auditing operational controls, contractor management (8.1.4), change management (8.1.3), and emergency preparedness (8.2).
Clause 9 (Performance Evaluation): Auditing monitoring, legal evaluation (9.1.2), internal audits (9.2), and management reviews (9.3).
Clause 10 (Improvement): Auditing incident investigations, corrective action root causes (10.2), and continual improvement.
Grading Audit Findings: Major NC vs Minor NC vs Opportunity for Improvement
| Finding Category | Objective Definition & Trigger | Impact on Certification | Mandatory Corrective Action |
|---|---|---|---|
| Major Non-Conformance (Major NC) | Total absence or breakdown of a mandatory clause (e.g. no legal evaluation, unmitigated fatal fall hazard). | Blocks certification immediately; external auditor issues immediate Stage 2 failure. | Root-cause investigation, corrective action, and mandatory re-audit within 90 days. |
| Minor Non-Conformance (Minor NC) | Isolated administrative lapse (e.g. 1 out of 50 training records missing, single delayed calibration log). | Does not block certification, provided a corrective action plan is approved. | CAPA plan submitted within 30 days; verified at next audit cycle. |
| Opportunity for Improvement (OFI) | Conforming process that could be optimized for higher efficiency or digital tracking. | Zero negative impact on certification. | Discretionary review by Management Review Committee. |
3. Scoring & Grading Findings: Major Non-Conformance vs Minor vs OFI
An effective internal audit grading matrix utilizes a quantitative scoring scale (e.g. 0 to 100% conformance per clause):
100% Conformance: Objective evidence proves process is fully implemented, documented, and continually improving.
Minor NC (75% Score): System exists and functions, but minor lapses in documentation or execution were sampled.
Major NC (0% - 50% Score): Significant systemic failure. If a company fails to evaluate legal compliance under Clause 9.1.2, or fails to appoint an impartial internal auditor, a Major NC is automatically registered.
4. The Tri-Fold Verification Methodology: Records, Physical Site & Interviews
A Lead Auditor must never audit solely from a boardroom chair. Auditing requires the Tri-Fold Verification Methodology:
1. Document & Record Sampling: Inspecting policies, risk registers, training matrices, and calibration certificates.
2. Physical Workplace Inspection: Walking the shop floor, checking machine guarding, testing eyewash stations, and verifying chemical bunding.
3. Worker Interviews: Interviewing frontline operators without managers present: *'What are the main hazards of your machine? What do you do if you spot a hydraulic leak? How were you trained?'* If workers cannot explain basic hazards, Clause 7.2 (Competence) fails.
5. 5-Stage ISO 45001 Internal Audit Execution & CAPA Roadmap
Schedule audits covering all 7 standard clauses and all operational shifts across the 12-month calendar.
Review SOPs, previous audit findings, and draft targeted clause checklists for sampling evidence.
Sample records, inspect physical workplace controls, and interview frontline workers across departments.
Classify findings into Major NCs, Minor NCs, and OFIs; present executive summary at formal Closing Meeting.
Ensure process owners execute root-cause analyses, implement corrective actions, and verify effectiveness.
6. Master ISO 45001 Clause Scoring & Conformance Checklist
- Annual Internal Audit Programme (Clause 9.2) is approved and covers all clauses from 4 through 10.
- Internal auditors are trained, certified, and independent of the operational processes being audited.
- Clause 4 (Context) and Clause 6.1.3 (Legal Register) are fully updated within the last 12 months.
- Clause 5.4 (Worker Participation) is proven through active SHE Representative consultation records.
- Clause 8.1.4 (Contractor Management) audits Section 37(2) agreements and subcontractor safety files.
- All Major and Minor Non-Conformances have documented root-cause analyses and signed CAPAs.
- Internal audit summary report is reviewed by executive leadership during Management Review (Clause 9.3).
