ISO 14001 and ISO 45001 internal audit checklist
38 audit questions, clause by clause, each with the evidence to look for. Every question is shown below. The Excel version adds a rating drop-down, the same questions grouped by department, a findings log and an audit plan.
Audit questions by clause
Written against ISO 14001:2015 and ISO 45001:2018. Questions marked Both apply to either standard, so an integrated audit asks them once.
Clause 4 Context of the organisation
- 4.1 Both Context
Has the organisation identified the internal and external issues that affect its environmental and OH&S management system, and are they reviewed when circumstances change?
Evidence: Context analysis (for example SWOT or PESTLE) with a review date; minutes showing it was revisited
- 4.2 Both Interested parties
Are the relevant interested parties and their needs identified, including workers, and is it clear which of those needs have become compliance obligations?
Evidence: Interested parties register linked to the legal register
- 4.3 Both Scope
Is the scope documented, covering every site, activity and function within the boundary, and does it match the scope on the certificate?
Evidence: Scope statement; certificate; site list
- 4.4 Both System and processes
Are the processes of the system and how they interact defined, and do they run as described rather than only on paper?
Evidence: Process map or manual; sample of records from each process
Clause 5 Leadership and worker participation
- 5.1 Both Leadership
Can top management show how they take accountability for the system, provide resources and integrate it into business decisions?
Evidence: Interview with top management; budget and resourcing decisions; business plans that reference the system
- 5.1 ISO 45001 Leadership
Does top management actively promote a culture where workers report incidents, hazards and risks without fear of reprisal?
Evidence: Reporting statistics; staff interviews; communications from leadership
- 5.2 Both Policy
Does the policy contain the required commitments (pollution prevention or safe and healthy working conditions, compliance, continual improvement, and for OH&S, consultation of workers) and is it communicated and available?
Evidence: Signed policy; notice boards; intranet; induction material
- 5.3 Both Roles
Are responsibilities and authorities for the system assigned and communicated, including who reports system performance to top management?
Evidence: Organisation chart; job descriptions; appointment letters
- 5.4 ISO 45001 Worker consultation
Is there a working process for consulting non-managerial workers and involving them in hazard identification, incident investigation and setting controls, with barriers to participation removed?
Evidence: Safety committee minutes; worker representatives; suggestion and response records; interviews with workers
Clause 6 Planning
- 6.1.1 Both Risks and opportunities
Are the risks and opportunities to the system identified, with actions planned, and are planned changes assessed before they happen?
Evidence: Risks and opportunities register; action plan
- 6.1.2 ISO 14001 Environmental aspects
Are environmental aspects and impacts identified for normal, abnormal and emergency conditions, with a life cycle perspective, and are significant aspects decided using defined criteria?
Evidence: Aspects and impacts register; significance criteria; review date
- 6.1.2.1 ISO 45001 Hazard identification
Is hazard identification ongoing and proactive, covering routine and non-routine work, contractors and visitors, human factors, and psychosocial factors such as workload, hours and harassment?
Evidence: Hazard identification and risk assessment register; psychosocial risk assessment; recent updates
- 6.1.2.2 ISO 45001 Risk assessment
Are OH&S risks assessed with a defined method, and are assessments reviewed after incidents and changes?
Evidence: Risk assessment methodology; sample assessments; revision history
- 6.1.3 Both Legal requirements
Is there a current register of legal and other requirements for every jurisdiction in scope, with how each applies to the organisation?
Evidence: Legal register with last update date; source references
- 6.1.4 Both Planning action
Are actions planned for significant aspects, hazards, legal requirements and risks, and is their effectiveness evaluated?
Evidence: Action plans with owners and dates; effectiveness reviews
- 6.2 Both Objectives
Are objectives set at relevant functions, measurable where practicable, monitored and supported by plans saying what, who, when, resources and how results are evaluated?
Evidence: Objectives and targets register; KPI tracking; progress reports
Clause 7 Support
- 7.1 Both Resources
Are the resources the system needs (people, budget, equipment, time) determined and provided?
Evidence: Budget; staffing; management review decisions on resources
- 7.2 Both Competence
Is the competence required for roles that affect environmental and OH&S performance defined, and is there evidence that people meet it, including training effectiveness?
Evidence: Competence matrix; training records; certificates; effectiveness evaluation
- 7.3 Both Awareness
Are workers aware of the policy, the significant aspects and hazards of their own work, their contribution, the consequences of not conforming, and (for OH&S) their right to remove themselves from imminent danger?
Evidence: Induction records; toolbox talks; worker interviews
- 7.4 Both Communication
Is it defined what is communicated internally and externally, when, to whom and how, and are communications from interested parties answered and recorded?
Evidence: Communication plan; external correspondence log; complaints log
- 7.5 Both Documented information
Are documents and records identified, approved, version controlled, available where needed, protected and retained for defined periods, including documents of external origin?
Evidence: Document master list; sample of controlled documents; retention schedule
Clause 8 Operation
- 8.1 Both Operational control
Are operating criteria and controls in place for significant aspects and OH&S risks, and are they followed in practice on site?
Evidence: Procedures and work instructions; site observation; permits; inspection records
- 8.1 ISO 14001 Waste and pollution
Are waste streams segregated, stored, transported and disposed of through licensed contractors, with records kept?
Evidence: Waste manifests; contractor licences; storage area inspection
- 8.1 ISO 14001 Life cycle
Are environmental requirements considered in design, procurement and communication to external providers, consistent with a life cycle perspective?
Evidence: Procurement criteria; supplier communications; design review records
- 8.1.2 ISO 45001 Hierarchy of controls
Are controls chosen in the order of the hierarchy (eliminate, substitute, engineering, administrative, PPE), and is PPE the last resort rather than the first?
Evidence: Risk assessments showing control selection; PPE register
- 8.1.3 Both Management of change
Are planned changes (new sites, layouts, equipment, processes, staffing, legal changes) assessed for environmental and OH&S impact before they are made, and are unintended changes reviewed?
Evidence: Management of change register; sample change assessments
- 8.1.4 ISO 45001 Procurement
Does the procurement process make sure purchased products and services meet OH&S requirements?
Evidence: Procurement procedure; purchase specifications; supplier evaluation
- 8.1.4.2 ISO 45001 Contractors
Are contractors selected using OH&S criteria, inducted, and controlled on site so their work and yours do not harm each other or others?
Evidence: Contractor prequalification; contracts with HSE clauses; contractor inductions; permits
- 8.1.4.3 Both Outsourcing
Are outsourced processes (for example facilities management, cleaning, security, waste) controlled, with the type and extent of control defined?
Evidence: Service contracts; KPIs; supplier audits or reviews
- 8.2 Both Emergency preparedness
Are emergency situations identified, response plans in place including first aid, people trained, and the response tested by drills and revised afterwards?
Evidence: Emergency response plan; drill reports; fire warden and first aider lists; spill kits
- 8.2 Both Emergency equipment
Are fire extinguishers, alarms, emergency lighting, first aid kits and spill kits inspected and in date, and are escape routes clear and signed?
Evidence: Inspection tags and registers; site walk
Clause 9 Performance evaluation
- 9.1.1 Both Monitoring and measurement
Is it defined what is monitored and measured, how, when and against what criteria, and is measuring equipment calibrated or verified?
Evidence: Monitoring plan; KPI results; calibration records
- 9.1.2 Both Evaluation of compliance
Is compliance with every legal and other requirement evaluated at a defined frequency, with results recorded and gaps acted on?
Evidence: Compliance evaluation report; actions for gaps
- 9.2 Both Internal audit
Is there an internal audit programme covering the whole scope, with impartial auditors, defined criteria and scope for each audit, and results reported to management (and for OH&S, to workers)?
Evidence: Audit programme; audit plans and reports; auditor competence records
- 9.3 Both Management review
Has top management reviewed the system at planned intervals, covering every required input, and recorded decisions and actions as outputs?
Evidence: Management review minutes with each input addressed; action log
- 9.3 ISO 45001 Management review
Did the review consider trends in worker consultation and participation, and were the relevant outputs communicated to workers?
Evidence: Minutes; communication to workers after the review
Clause 10 Improvement
- 10.2 Both Incidents and nonconformity
Are incidents and nonconformities reported, investigated to root cause with worker participation where relevant, corrected, and checked for effectiveness?
Evidence: Incident log; investigation reports; corrective action register with closure evidence
- 10.3 Both Continual improvement
Is there evidence that environmental and OH&S performance is improving over time, not only that the system is maintained?
Evidence: Trend data; improvement projects; year-on-year KPIs
Written against ISO 14001:2015 and ISO 45001:2018 (with its 2024 climate amendment). ISO 14001:2026 was published in April 2026 and certificates move to it during a three-year transition, and ISO 45001 is under revision. If your system has moved to a newer edition, check each clause reference against it.
The questions paraphrase the requirements of each clause. They are a working aid, not a substitute for the standards, which are published by ISO and national standards bodies. Add questions for your own legal requirements, procedures and sites.
Get the Excel version
Enter your work email. We'll send the workbook to your inbox and unlock the direct download here.
Your checklist is on its way.
We've emailed the workbook. You can also download it now.
Download the Excel fileWant an independent auditor instead? ISO internal audit
- Five sheets: start here, checklist, by department, findings log, audit plan
- Filter to ISO 14001 or ISO 45001 if you hold one standard only
- Editable, in Calibri, works in Excel and Google Sheets
Using an internal audit checklist
What is an ISO internal audit checklist?
A list of audit questions, each tied to a clause of the standard, with the evidence an auditor should look for. It keeps an internal audit complete and consistent from one auditor to the next, and gives a record of what was checked. It does not replace the standard; it is a working aid for auditing against it.
Can one checklist cover ISO 14001 and ISO 45001 together?
Yes. Both standards share the same clause structure, so most requirements (context, leadership, planning, documented information, internal audit, management review, corrective action) are audited once for both. This checklist marks 27 of its 38 questions as common to both, and the rest as specific to one standard, so an integrated audit avoids asking the same question twice.
How often should an ISO internal audit be done?
At planned intervals, covering the whole scope within the certification cycle. Most organisations run a rolling programme so every process and site is audited at least once a year, with higher-risk areas more often. Certification bodies hold surveillance audits every calendar year, so an internal audit that finishes well before each surveillance visit is the practical target.
Who can use this checklist?
Anyone running an internal audit who is not auditing their own work, which is the impartiality requirement in clause 9.2. That can be a trained member of staff from another department or an external auditor. Add questions for your own legal requirements, procedures and sites before you use it.
Related: ISO internal audit services, managed ISO systems for keeping certification across several sites, and ISO internal auditor training.