ISO 45001 Internal Audits: What Industrial Facilities Should Expect from a Competent Auditor
Facilities certified to ISO 45001 already understand the basic audit process. There will be an audit plan, document review, employee interviews, findings, corrective actions, and a closing meeting.
A properly conducted internal audit should provide clear evidence of conformity with ISO 45001 and the organization’s own requirements. It should also determine whether the occupational health and safety management system is implemented, maintained, and effective.
These objectives are not in conflict. A strong audit can be conducted by the book while still examining whether the system works inside an operating industrial facility.
Establishing Conformity Comes First
ISO 45001 establishes the audit criteria. The auditor should evaluate each applicable requirement and maintain clear traceability between the standard, the evidence reviewed, and the audit conclusion.
A clause based checklist can be useful for confirming that the audit covers the entire management system. It helps ensure that requirements are not overlooked and provides an organized record of the evaluation.
However, confirming that a policy, procedure, or record exists is only part of the audit. The auditor must also determine whether the requirement has been implemented and whether it is producing the intended result.
A complete audit evaluates both conformity and effectiveness.
Audit Depth Should Reflect Risk
Although the audit should address all applicable requirements, the time spent evaluating each process should reflect its importance and risk.
Audit planning should consider:
Significant hazards and serious injury potential.
Recent incidents and near misses.
Previous audit findings.
Operational and organizational changes.
Adverse performance trends.
High risk contractor activities.
Recurring corrective actions.
At an industrial facility, this may require greater attention to hazardous energy, machine safety, confined spaces, chemical exposure, contractors, emergency response, industrial hygiene, maintenance, and process safety.
The goal is not to skip requirements considered less significant. The goal is to provide complete coverage while spending enough time on the areas where failure could have the most serious consequences.
Documents Are Only the Beginning
Procedures, risk assessments, training records, inspections, incident investigations, and management reviews provide important evidence. They do not prove by themselves that the system works.
The auditor should compare written requirements with actual practices.
Consider a lockout/tagout program. Confirming that the facility has a written program and completed training records is necessary. The auditor may also need to examine equipment specific procedures, periodic inspections, group lockout, shift changes, contractor coordination, and energy isolation in the field.
The same approach applies throughout the management system. The audit should answer three basic questions:
What does the organization require?
Is that requirement being followed?
Is the process effectively controlling the risk?
The plant floor provides much of the evidence needed to answer those questions.
Industrial Experience Matters
Understanding ISO 45001 is necessary, but an industrial auditor also needs to understand the work being evaluated.
An auditor working in a manufacturing or chemical facility should recognize the practical significance of machine guarding, energy isolation, respiratory protection, confined space entry, chemical handling, emergency response, contractor safety, management of change, and Process Safety Management.
The auditor does not need to be the facility’s technical expert on every subject. The auditor does need enough experience to determine whether controls are credible, whether the evidence is meaningful, and when a condition requires deeper technical or regulatory evaluation.
A general auditor may confirm that a confined space procedure exists. An industrial auditor should also recognize whether classifications, isolation practices, atmospheric testing, rescue arrangements, and permits are reflected in actual work.
Employee Interviews Should Evaluate the System
Employee interviews are an important source of objective evidence. They help determine whether workers understand the hazards, controls, responsibilities, and reporting processes that apply to their work.
The purpose is not to catch an employee giving the wrong answer.
When several employees provide inconsistent answers to the same question, the auditor should examine the training, communication, supervision, and procedures behind those answers. The inconsistency may point to a broader management system issue.
The focus should remain on the effectiveness of the system rather than the performance of one employee during an interview.
Findings Should Be Clear and Defensible
An audit report should provide findings that management can understand and act upon.
Each nonconformity should identify:
The applicable requirement.
The evidence reviewed.
What failed to meet the requirement.
Whether the condition appears isolated or systemic.
The auditor should also distinguish between a nonconformity and an opportunity for improvement. A preferred practice is not automatically a requirement.
Management should be able to read the finding and understand what was expected, what the evidence demonstrated, and which part of the management system needs attention.
Recurring Findings Require More Attention
One of the most important questions an auditor can ask is whether the organization has identified the same problem before.
Recurring findings often indicate that the facility is correcting examples without addressing causes.
The damaged guard gets repaired, but nobody determines why inspections failed to identify it. One procedure gets updated, but the document control process remains unchanged. One employee gets retrained, but nobody evaluates why the training process failed.
Closing an action does not prove that the action was effective.
The internal audit should evaluate whether previous corrective actions addressed the cause, were applied to similar conditions, and were checked for effectiveness.
Independence Can Expose Blind Spots
Internal teams often audit programs they designed, manage, or administer. Even experienced auditors may have difficulty evaluating their own work objectively.
Familiarity can also create blind spots. Workarounds become normal, and longstanding weaknesses are accepted because the facility has operated that way for years.
Using an outside auditor can provide independence while still meeting the organization’s internal audit requirements. This can be valuable when:
The EHS manager owns most of the management system.
The facility lacks qualified internal auditors.
Corporate audit resources are limited.
Previous audits have become repetitive.
Management wants an objective assessment before a certification or surveillance audit.
An outside auditor should not impose a personal auditing style on the organization. The auditor should work within the agreed scope, criteria, reporting format, and audit objectives.
What the Facility Should Receive
A competent ISO 45001 internal audit should provide:
Complete coverage of the agreed audit criteria.
Clear traceability to ISO 45001 requirements.
Audit depth based on risk and previous performance.
Meaningful sampling of documents and records.
Adequate time in operating areas.
Interviews with workers, supervisors, and leadership.
Findings supported by objective evidence.
Evaluation of recurring problems and corrective action effectiveness.
A practical report that helps management decide what needs attention.
Industrial facilities should expect an auditor who can evaluate clause by clause conformity, maintain clear traceability to the standard, and understand how those requirements apply inside an operating facility.
Appalachian EHS & Process Safety Consulting provides ISO 45001 internal audits, gap assessments, corrective action reviews, and management system alignment support for industrial facilities.
Our approach combines structured ISO auditing with practical experience in industrial safety, occupational health, chemical manufacturing, high hazard operations, and Process Safety Management.
We do not issue ISO certification. We help organizations determine whether their systems conform to requirements, operate as intended, and effectively control the risks they were created to manage.