Training Outcomes Within Your Budget!
We ensure quality, budget-alignment, and timely delivery by our expert instructors.
Table of Content
- ISO 45001 Documentation Made Simple
- Understanding ISO 45001 and Its Documentation Needs
- ISO 45001 Clauses at a Glance
- Clause 6.1: Hazard Identification and Risk Assessment
- Clause 7.5: Documented Information and Control
- Mandatory Documents and Records Under ISO 45001
- Document Control and Practical Checklists
- ISO 45001 Document Control Procedure: Key Elements
- Structuring ISO 45001 Documentation Effectively
- What Auditors Look For
- Implementation Tips: Getting Your ISO 45001 Documentation Right
- Conclusion
Recent Blogs
Best Software Development Projects Guide for All Developers
August 4th, 2026
Communication in Project Management for Modern Workplaces
August 4th, 2026
Master Project Plan in Excel with Templates and Easy Steps
August 4th, 2026
How to Build a Requirement Traceability Matrix Effectively
August 4th, 2026
Complete Guide to Project Failure Causes and Prevention Tips
August 4th, 2026
Project Management Plans: The Complete Resource
August 4th, 2026
Key Project Report Writing Techniques You Should Use Today
August 4th, 2026
What Is the Project Management Life Cycle? 5 Phases Explained
August 4th, 2026
Understanding Project Management Career Path Completely
August 4th, 2026
Effective Agile Risk Management for Better Project Outcomes
August 4th, 2026
ISO 9001 Lead Auditor Interview Guide: Questions Hiring Managers Actually Ask
August 4th, 2026
What Every Project Coordinator Should Know About Their Role
August 4th, 2026
Top Digital Marketing Projects Every Marketer Should Know
August 4th, 2026
Agile vs Traditional Project Management Essential Breakdown
August 4th, 2026
Transform Your PMP Exam Preparation with These Key Insights
August 4th, 2026
Organizations implementing ISO 45001 report up to a 50% reduction in workplace incidents within the first year of certification. This guide explains what is required, how to organize the documentation, and what auditors typically look for, all in plain language.
ISO 45001 Documentation Made Simple
Introduction
ISO 45001 documentation refers to the documented information, including maintained documents and retained records, required to develop, implement, maintain, and continuously improve an OH&S management system, these records support the wider ISO 45001 Safety Standards and include everything from the OH&S policy and risk assessment methodology to training records, audit reports, and incident investigations. Organizations implementing ISO 45001 report up to a 50% reduction in workplace incidents within the first year of certification. This guide explains what is required, how to organize the documentation, and what auditors typically look for, all in plain language.
Understanding ISO 45001 and Its Documentation Needs
ISO 45001 uses one term, “documented information,” for both documents and records. However, it is easier to understand by dividing them into two groups:
The ISO 45001 maintained vs retained documented information distinction helps organizations understand which documents must remain current and which records must be preserved as evidence.
- Maintained documented information (living documents): Documents that need regular updates to stay current. Examples include the OH&S policy, risk assessment methods, plans, procedures, and work instructions.
- Retained documented information (historical records): Evidence that activities were carried out as planned, kept for a defined period. Examples include training records, ISO 45001 internal audit records, incident investigation reports, and ISO 45001 management review records.
Some documents, like your risk register or legal requirements register, are both maintained (updated regularly) and retained (historical versions kept for traceability).
A clear understanding of these two types of information makes it easier to organize and control OH&S documents. ISO 45001 documentation training can also help professionals understand which documents must be updated and which records must be kept as evidence.
Maintained vs. Retained: A Quick Reference
ISO 45001 Clauses at a Glance
ISO 45001 has ten clauses, the first three explain the scope, references, and key terms, while other clauses 4 to 10 cover the main rules for workplace health and safety management.
Clause 4: Context of the Organization
Organizations should understand the internal and external issues that can affect workplace health and safety, they also need to identify important groups, such as workers, regulators, and contractors, and clearly define what the OH&S management system covers. This usually includes a scope statement and records showing how these factors were identified.
Clause 5: Leadership and Worker Participation
Senior management must show commitment to workplace health and safety by creating an OH&S policy, assigning clear roles and responsibilities, and involving workers in safety-related decisions, important documents include the OH&S policy, job roles, and records showing worker participation.
Clause 6: Planning
This clause focuses on identifying hazards, assessing risks, meeting legal requirements, and setting OH&S objectives, key documents include risk assessment methods, risk registers, legal requirements, objectives, and action plans. Clause 6.1 is especially important because it deals with identifying hazards and assessing risks, which will be explained in more detail later.
Clause 7: Support
Organizations must provide the right resources, ensure workers have the required skills and training, manage communication, and control documents, Clause 7.5 focuses on documented information and is an important part of ISO 45001 documentation. Key records include training, worker skills, communication, and document control.
Clause 8: Operation
This clause 8 deals with workplace risks during daily work, it covers routine tasks, contractor work, workplace changes, and emergencies. Common documents include work procedures, risk controls, and emergency response plans.
Clause 9: Performance Evaluation
Organizations need to check workplace health and safety performance, review legal compliance, carry out internal audits, and conduct management reviews, important records include monitoring results, compliance checks, internal audit records, and management review records.
Clause 10: Improvement
This clause focuses on investigating incidents, handling problems, taking corrective action, and improving the system, records of incidents, investigations, and corrective actions show how workplace safety is improved over time.
Clause 6.1: Hazard Identification and Risk Assessment
Clause 6.1 is an important part of ISO 45001 because it explains how workplace risks are identified and controlled, it requires a clear process to identify hazards, assess health and safety risks, find opportunities for improvement, and decide what controls are needed. Hazards may be physical, chemical, biological, ergonomic, or related to mental well-being. The process should identify and address risks before incidents happen.
Key Documentation for Clause 6.1
- A documented risk assessment methodology and criteria (mandatory).
- ISO 45001 risk assessment records, such as hazard registers, risk matrices, and risk treatment plans.
- Evidence that risk assessments are reviewed periodically and updated after changes or incidents.
Why Clause 6.1 Matters
The outputs from Clause 6.1 feed directly into operational controls (Clause 8), performance monitoring (Clause 9), and improvement activities (Clause 10). Without a solid risk assessment process, other parts of the system may be based on incomplete or incorrect assumptions about what poses the greatest risk to workers.
Clause 7.5: Documented Information and Control
This clause explains what documents and records are needed and how they must be handled, and also covers how information is created, updated, stored, and made available when required, keeping these records clear and current makes daily work easier and helps during audits.
7.5.1: General Requirements
The OH&S management system should contain the documents required by the standard and any additional information needed to run the system properly. This allows each organization to create documents that suit its own needs and working conditions.
7.5.2: Creating and Updating
When creating or updating documents, ISO 45001 Clause 7.5.2 requires organizations to make sure that:
- Identification and description: Clear title, document ID, version/revision number, and date.
- Format and media: Documents can be kept on paper, stored digitally, or used in both forms. ISO 45001:2018 allows any format, including cloud-based systems.
- Review and approval: Documents must be checked to make sure they are suitable and complete. Authorized personnel must approve them before they are released.
7.5.3: Control of Documented Information
Documents must be easy to access when and where needed, suitable for use, and properly protected. The organization should control how documents are shared, accessed, stored, updated, kept, and removed. An ISO 45001 document control procedure explains how these activities are handled.
Mandatory Documents and Records Under ISO 45001
One of the most common questions is: What documents are required for ISO 45001 certification? The standard requires organizations to maintain certain key documents and records, while also allowing them to add other documents based on their specific needs and work activities.
An ISO 45001 standard required documents list gives organizations a clear starting point for identifying the policies, procedures, and records that need to be prepared.
What Are the Mandatory Documents for ISO 45001?
ISO 45001 requires 7 mandatory documents (to maintain) and 10+ mandatory records (to retain). The standard does not require an OH&S manual; this is optional.
7 Mandatory Documents
|
Clause |
Document |
|---|---|
|
4.3 |
Scope of the OH&S management system |
|
5.2 |
OH&S policy |
|
5.3 |
Roles, responsibilities, and authorities |
|
6.1.1 |
Process for addressing OH&S risks and opportunities |
|
6.1.2.2 |
Methodology and criteria for OH&S risk assessment |
|
6.2.2 |
OH&S objectives and plans to achieve them |
|
8.2 |
Emergency preparedness and response process |
10+ Mandatory Records
|
Clause |
Record |
Typical Retention Period |
|---|---|---|
|
6.1.1 |
OH&S risks and opportunities and actions taken |
3–5 years |
|
6.1.3 |
ISO 45001 legal requirements register |
3–5 years (or as required by law) |
|
7.2 |
Evidence of competence (training records, qualifications) |
3–5 years or duration of employment + 2 years |
|
7.4.1 |
Evidence of OH&S communications |
2–3 years |
|
8.2 |
Emergency preparedness plans and test results |
3–5 years |
|
9.1.1 |
Monitoring and measurement results; calibration records |
3–5 years (or per legal/manufacturer requirements) |
|
9.1.2 |
Compliance evaluation results |
3–5 years (or as required by law) |
|
9.2.2 |
ISO 45001 internal audit program and records |
3–5 years |
|
9.3 |
ISO 45001 management review records |
3–5 years |
|
10.2 |
Incidents, nonconformities, investigations, and corrective actions |
5–10 years (or as required by law) |
|
10.3 |
Evidence of continual improvement |
3–5 years |
Document Control and Practical Checklists
Effective document control is essential for maintaining a reliable OH&S management system. An ISO 45001 document control checklist can serve as a quick self-assessment tool to verify that controls are in place.
Key Elements of Document Control
- A documented ISO 45001 document control procedure that explains roles, responsibilities, and processes.
- A document register that lists all controlled documents and their latest versions.
- Clear details on each document, including the title, ID, version, date, and owner.
- Processes for reviewing, approving, distributing, and controlling access to documents.
- Methods for removing or marking outdated documents to prevent accidental use.
Digital ISO 45001 Document Management
Many organizations use digital systems to manage documents and records, these systems make it easier to track changes, control access, get reminders for reviews, and keep documents in one place. Whether information is stored digitally or on paper, Clause 7.5 requires it to be available, suitable, and protected.
ISO 45001 Document Control Procedure: Key Elements
ISO 45001 does not specifically require a written document control procedure, auditors usually expect proof that documents are properly managed, document control procedure should cover:
- Document creation and approval: Who can create documents, and who must approve them before use?
- Document identification: How documents are numbered, versioned, and dated.
- Access and distribution: Who can access each document and how access is controlled.
- Review and updates: How often documents are reviewed and who is responsible for updates.
- Obsolete documents: How outdated documents are removed or marked to prevent accidental use.
- External documents: How regulations, safety data sheets, and contractor RAMS are identified, tracked, and updated.
- Record retention and disposal: How long records should be kept and how they should be securely disposed when they are not needed.
Structuring ISO 45001 Documentation Effectively
A clear structure makes ISO 45001 documents easier to manage. Organizing documents in a logical order helps workers find information quickly and makes it easier for auditors to check records and supporting evidence.
When deciding how to structure ISO 45001 documentation, organizations can separate the information into top-level documents, processes, procedures, work instructions, forms, and supporting records.
Suggested Structure
1. Top-Level Documents
These documents provide an overall view of the OH&S management system and explain how it is organized.
- OH&S policy: States the organization's commitment to protecting worker health and safety.
- Scope of the OH&S management system: Explains which parts of the organization, locations, and activities are covered by the system.
- OH&S manual or overview document (optional): Gives a simple overview of how the OH&S management system is organized and managed.
2. Processes and Procedures
- Risk assessment methodology: Shows how hazards at work are found, how each risk is checked, and what can be done to control it.
- Legal requirements management: Covers the process of finding relevant health and safety laws, keeping a record of them, checking for changes, and updating the information when needed.
- ISO 45001 operational control procedures: Explain how health and safety risks are controlled during routine work and other activities.
- Emergency preparedness and response: Explains how the organization prepares for emergencies and responds to them.
- Incident investigation and corrective action: Explains how incidents are investigated, their causes are identified, and steps are taken to prevent them from happening again.
- Internal audit process: Explains how the OH&S management system is checked to make sure it is working as required.
- Management review process: Explains how management reviews the OH&S management system and decides what improvements are needed.
3. Work Instructions and Forms (As Needed)
These documents provide clear instructions and simple tools for carrying out specific health and safety tasks.
- Safe work steps for specific jobs: Give clear instructions for carrying out each task without causing harm.
- Checklists, permits, and inspection forms: Help record safety checks, confirm that the correct steps were followed, and show that equipment and work areas were checked before use.
4. Records
- Keep records with the process they belong to, for example, store training records in the Competence section, internal audit records in the Internal Audit section, and management review records in the Management Review section.
Understanding the difference between maintained and retained documented information helps make the structure clear. Maintained documents explain what needs to be done, while retained records provide evidence that the work was completed.
What Auditors Look For
During an ISO 45001 certification audit, auditors usually start by checking key documents and records. Understanding which information is reviewed first helps an organization keep the right documents ready and make the audit process easier.
Reviewing the ISO 45001 standard required documents list before the audit can help confirm that important documents and supporting evidence are complete and up to date.
Common First Requests
- OH&S policy and scope.
- Risk assessment methodology and key ISO 45001 risk assessment records.
- ISO 45001 legal requirements register.
- OH&S objectives and plans.
- ISO 45001 internal audit records and program.
- ISO 45001 management review records.
- Records of workplace incidents and corrective actions.
- Employee training and competency records.
- Emergency plans and records showing that emergency drills or tests were carried out.
These documents show that management is involved, workplace risks are being addressed, legal requirements are being followed, and improvements are being made. Keeping the documents organized and current makes the audit process easier and helps show that the health and safety system is working properly.
Common Nonconformities Related to Documentation
Based on typical ISO 45001 audit findings, here are the most common documentation-related nonconformities to avoid:
- Outdated risk assessments: Risk assessments not reviewed after incidents, near misses, or significant changes.
- Missing approval signatures: Procedures or work instructions are being used without proof that they were reviewed and approved.
- Outdated external documents: Old regulations, safety data sheets, or contractor RAMS are still being used.
- Incomplete training records: Training records do not include basic details such as the training date, subject, names of people who attended, or the trainer's signature.
- No records of worker consultation: There are no records showing that workers were involved in safety discussions or had a chance to share their feedback.
- Management review without action tracking: ISO 45001 management review records that don't show follow-up on previous action items.
- Incident investigations without root cause analysis: Incident records that only describe what happened, not why it happened or what corrective actions were taken.
Implementation Tips: Getting Your ISO 45001 Documentation Right
Step-by-Step Documentation Development
- Start with the required documents: Put the basic OH&S documents in place first. This includes the safety policy, the scope of the system, the method used to assess workplace risks, and the health and safety goals.
- Create a Master Document Register: Make a list of all controlled documents, including their document IDs, responsible persons, version numbers, and review dates.
- Develop procedures for high-risk work: Prepare clear procedures for activities that have a higher chance of causing harm, such as confined space entry, lockout/tagout, and chemical handling.
- Set up your record-keeping system: Organize retained records by clause or process (e.g., training records under Clause 7.2, ISO 45001 internal audit records under Clause 9.2).
- Define retention periods: Document how long each type of record will be kept and why.
- Explain how to access documents: Make sure workers know where to find the latest procedures and how to report documents that are outdated or incorrect.
- Carry out internal audits: Check documents and records regularly to make sure they are properly controlled and complete.
Small Business vs. Enterprise Documentation
- Smaller organizations: may use a simpler documentation system, this could include one OH&S manual covering the main policies and procedures, along with a basic risk register and training matrix.
- Medium to large organizations: Typically need a more structured hierarchy with separate policies, procedures, work instructions, and forms, plus a digital document management system for multi-site access.
Common Mistakes to Avoid
- Too much documentation: Not every small job needs its own procedure, too many documents can make the system difficult to handle and keep up to date.
- Too little documentation: Missing instructions for risky work or failing to keep important records can leave gaps in safety controls.
- No version control: Using different copies of the same document can create confusion, particularly when someone follows an older version that is no longer valid.
- Ignoring external documents: Laws, safety data sheets, and contractor RAMS may change over time. These updates need to be checked so outdated information is not used.
Related areas such as workplace compliance, risk control, and safety management are also covered through SterlingNext Workplace Safety Learning Programs.
Conclusion
ISO 45001 documentation does not have to be complicated, it should be clear, well-organized, controlled, and useful for managing workplace health and safety. Focusing on required documents and records, using a simple document control process, and organizing information properly can help support both compliance and workplace safety. Clause 6.1 helps with identifying hazards and assessing risks, while Clause 7.5 explains how documented information should be managed and controlled. When these requirements are handled properly, ISO 45001 documentation becomes a useful part of everyday safety management rather than just paperwork. It can help create safer workplaces and improve overall performance.
Get Certified With Industry Level Projects & Fast Track Your Career
Checkout Top 10 Highest Paying Jobs
Frequently Asked Questions
ISO 45001 documentation covers the information used to manage workplace health and safety, this includes documents that explain how safety activities are handled and records that show what was done and when it was completed.
ISO 45001 does not require a safety manual, organization may choose to create an OH&S manual as a top-level document to explain the management system, but having one is optional and not a certification requirement.
Mandatory documents include the OH&S policy, system scope, risk assessment methods, safety objectives and plans, emergency preparedness procedures, and clearly defined roles and responsibilities. These documents help explain how the OH&S management system is organized and managed.
Records may include risk assessments, legal requirements, training and competence records, audit findings, management review minutes, incident reports, and corrective action records, these records show that important health and safety activities have been carried out and reviewed.
ISO 45001 does not set fixed retention periods for records, each organization decides how long records should be kept based on legal requirements, contractual obligations, and its own operational needs.
Maintained documented information includes policies and procedures that are kept up to date. Retained documented information includes records that serve as evidence of past activities.
Yes. Digital ISO 45001 document management is allowed as long as Clause 7.5 requirements for availability, control, and protection are met.
It is a documented list of applicable legal and other requirements related to OH&S, along with evidence of how compliance is monitored and evaluated.
Risk assessments need to be checked regularly and updated when major changes occur, after an incident, or when new information becomes available, this helps ensure that workplace hazards and risks are still properly identified and controlled.
Good ISO 45001 documentation helps keep safety practices consistent, supports employee training and communication, shows that requirements are being followed, and helps identify areas where workplace health and safety can be improved.
Sachin Kumar