Skip to main content
Free tool · Excel

ISO 14001 and ISO 45001 internal audit checklist

38 audit questions, clause by clause, each with the evidence to look for. Every question is shown below. The Excel version adds a rating drop-down, the same questions grouped by department, a findings log and an audit plan.

The checklist

Audit questions by clause

Written against ISO 14001:2015 and ISO 45001:2018. Questions marked Both apply to either standard, so an integrated audit asks them once.

Clause 4 Context of the organisation

  1. 4.1 Both Context

    Has the organisation identified the internal and external issues that affect its environmental and OH&S management system, and are they reviewed when circumstances change?

    Evidence: Context analysis (for example SWOT or PESTLE) with a review date; minutes showing it was revisited

  2. 4.2 Both Interested parties

    Are the relevant interested parties and their needs identified, including workers, and is it clear which of those needs have become compliance obligations?

    Evidence: Interested parties register linked to the legal register

  3. 4.3 Both Scope

    Is the scope documented, covering every site, activity and function within the boundary, and does it match the scope on the certificate?

    Evidence: Scope statement; certificate; site list

  4. 4.4 Both System and processes

    Are the processes of the system and how they interact defined, and do they run as described rather than only on paper?

    Evidence: Process map or manual; sample of records from each process

Clause 5 Leadership and worker participation

  1. 5.1 Both Leadership

    Can top management show how they take accountability for the system, provide resources and integrate it into business decisions?

    Evidence: Interview with top management; budget and resourcing decisions; business plans that reference the system

  2. 5.1 ISO 45001 Leadership

    Does top management actively promote a culture where workers report incidents, hazards and risks without fear of reprisal?

    Evidence: Reporting statistics; staff interviews; communications from leadership

  3. 5.2 Both Policy

    Does the policy contain the required commitments (pollution prevention or safe and healthy working conditions, compliance, continual improvement, and for OH&S, consultation of workers) and is it communicated and available?

    Evidence: Signed policy; notice boards; intranet; induction material

  4. 5.3 Both Roles

    Are responsibilities and authorities for the system assigned and communicated, including who reports system performance to top management?

    Evidence: Organisation chart; job descriptions; appointment letters

  5. 5.4 ISO 45001 Worker consultation

    Is there a working process for consulting non-managerial workers and involving them in hazard identification, incident investigation and setting controls, with barriers to participation removed?

    Evidence: Safety committee minutes; worker representatives; suggestion and response records; interviews with workers

Clause 6 Planning

  1. 6.1.1 Both Risks and opportunities

    Are the risks and opportunities to the system identified, with actions planned, and are planned changes assessed before they happen?

    Evidence: Risks and opportunities register; action plan

  2. 6.1.2 ISO 14001 Environmental aspects

    Are environmental aspects and impacts identified for normal, abnormal and emergency conditions, with a life cycle perspective, and are significant aspects decided using defined criteria?

    Evidence: Aspects and impacts register; significance criteria; review date

  3. 6.1.2.1 ISO 45001 Hazard identification

    Is hazard identification ongoing and proactive, covering routine and non-routine work, contractors and visitors, human factors, and psychosocial factors such as workload, hours and harassment?

    Evidence: Hazard identification and risk assessment register; psychosocial risk assessment; recent updates

  4. 6.1.2.2 ISO 45001 Risk assessment

    Are OH&S risks assessed with a defined method, and are assessments reviewed after incidents and changes?

    Evidence: Risk assessment methodology; sample assessments; revision history

  5. 6.1.3 Both Legal requirements

    Is there a current register of legal and other requirements for every jurisdiction in scope, with how each applies to the organisation?

    Evidence: Legal register with last update date; source references

  6. 6.1.4 Both Planning action

    Are actions planned for significant aspects, hazards, legal requirements and risks, and is their effectiveness evaluated?

    Evidence: Action plans with owners and dates; effectiveness reviews

  7. 6.2 Both Objectives

    Are objectives set at relevant functions, measurable where practicable, monitored and supported by plans saying what, who, when, resources and how results are evaluated?

    Evidence: Objectives and targets register; KPI tracking; progress reports

Clause 7 Support

  1. 7.1 Both Resources

    Are the resources the system needs (people, budget, equipment, time) determined and provided?

    Evidence: Budget; staffing; management review decisions on resources

  2. 7.2 Both Competence

    Is the competence required for roles that affect environmental and OH&S performance defined, and is there evidence that people meet it, including training effectiveness?

    Evidence: Competence matrix; training records; certificates; effectiveness evaluation

  3. 7.3 Both Awareness

    Are workers aware of the policy, the significant aspects and hazards of their own work, their contribution, the consequences of not conforming, and (for OH&S) their right to remove themselves from imminent danger?

    Evidence: Induction records; toolbox talks; worker interviews

  4. 7.4 Both Communication

    Is it defined what is communicated internally and externally, when, to whom and how, and are communications from interested parties answered and recorded?

    Evidence: Communication plan; external correspondence log; complaints log

  5. 7.5 Both Documented information

    Are documents and records identified, approved, version controlled, available where needed, protected and retained for defined periods, including documents of external origin?

    Evidence: Document master list; sample of controlled documents; retention schedule

Clause 8 Operation

  1. 8.1 Both Operational control

    Are operating criteria and controls in place for significant aspects and OH&S risks, and are they followed in practice on site?

    Evidence: Procedures and work instructions; site observation; permits; inspection records

  2. 8.1 ISO 14001 Waste and pollution

    Are waste streams segregated, stored, transported and disposed of through licensed contractors, with records kept?

    Evidence: Waste manifests; contractor licences; storage area inspection

  3. 8.1 ISO 14001 Life cycle

    Are environmental requirements considered in design, procurement and communication to external providers, consistent with a life cycle perspective?

    Evidence: Procurement criteria; supplier communications; design review records

  4. 8.1.2 ISO 45001 Hierarchy of controls

    Are controls chosen in the order of the hierarchy (eliminate, substitute, engineering, administrative, PPE), and is PPE the last resort rather than the first?

    Evidence: Risk assessments showing control selection; PPE register

  5. 8.1.3 Both Management of change

    Are planned changes (new sites, layouts, equipment, processes, staffing, legal changes) assessed for environmental and OH&S impact before they are made, and are unintended changes reviewed?

    Evidence: Management of change register; sample change assessments

  6. 8.1.4 ISO 45001 Procurement

    Does the procurement process make sure purchased products and services meet OH&S requirements?

    Evidence: Procurement procedure; purchase specifications; supplier evaluation

  7. 8.1.4.2 ISO 45001 Contractors

    Are contractors selected using OH&S criteria, inducted, and controlled on site so their work and yours do not harm each other or others?

    Evidence: Contractor prequalification; contracts with HSE clauses; contractor inductions; permits

  8. 8.1.4.3 Both Outsourcing

    Are outsourced processes (for example facilities management, cleaning, security, waste) controlled, with the type and extent of control defined?

    Evidence: Service contracts; KPIs; supplier audits or reviews

  9. 8.2 Both Emergency preparedness

    Are emergency situations identified, response plans in place including first aid, people trained, and the response tested by drills and revised afterwards?

    Evidence: Emergency response plan; drill reports; fire warden and first aider lists; spill kits

  10. 8.2 Both Emergency equipment

    Are fire extinguishers, alarms, emergency lighting, first aid kits and spill kits inspected and in date, and are escape routes clear and signed?

    Evidence: Inspection tags and registers; site walk

Clause 9 Performance evaluation

  1. 9.1.1 Both Monitoring and measurement

    Is it defined what is monitored and measured, how, when and against what criteria, and is measuring equipment calibrated or verified?

    Evidence: Monitoring plan; KPI results; calibration records

  2. 9.1.2 Both Evaluation of compliance

    Is compliance with every legal and other requirement evaluated at a defined frequency, with results recorded and gaps acted on?

    Evidence: Compliance evaluation report; actions for gaps

  3. 9.2 Both Internal audit

    Is there an internal audit programme covering the whole scope, with impartial auditors, defined criteria and scope for each audit, and results reported to management (and for OH&S, to workers)?

    Evidence: Audit programme; audit plans and reports; auditor competence records

  4. 9.3 Both Management review

    Has top management reviewed the system at planned intervals, covering every required input, and recorded decisions and actions as outputs?

    Evidence: Management review minutes with each input addressed; action log

  5. 9.3 ISO 45001 Management review

    Did the review consider trends in worker consultation and participation, and were the relevant outputs communicated to workers?

    Evidence: Minutes; communication to workers after the review

Clause 10 Improvement

  1. 10.2 Both Incidents and nonconformity

    Are incidents and nonconformities reported, investigated to root cause with worker participation where relevant, corrected, and checked for effectiveness?

    Evidence: Incident log; investigation reports; corrective action register with closure evidence

  2. 10.3 Both Continual improvement

    Is there evidence that environmental and OH&S performance is improving over time, not only that the system is maintained?

    Evidence: Trend data; improvement projects; year-on-year KPIs

Written against ISO 14001:2015 and ISO 45001:2018 (with its 2024 climate amendment). ISO 14001:2026 was published in April 2026 and certificates move to it during a three-year transition, and ISO 45001 is under revision. If your system has moved to a newer edition, check each clause reference against it.

The questions paraphrase the requirements of each clause. They are a working aid, not a substitute for the standards, which are published by ISO and national standards bodies. Add questions for your own legal requirements, procedures and sites.

Free download

Get the Excel version

Enter your work email. We'll send the workbook to your inbox and unlock the direct download here.

Work or organisation email required. No spam.

  • Five sheets: start here, checklist, by department, findings log, audit plan
  • Filter to ISO 14001 or ISO 45001 if you hold one standard only
  • Editable, in Calibri, works in Excel and Google Sheets
Questions

Using an internal audit checklist

What is an ISO internal audit checklist?

A list of audit questions, each tied to a clause of the standard, with the evidence an auditor should look for. It keeps an internal audit complete and consistent from one auditor to the next, and gives a record of what was checked. It does not replace the standard; it is a working aid for auditing against it.

Can one checklist cover ISO 14001 and ISO 45001 together?

Yes. Both standards share the same clause structure, so most requirements (context, leadership, planning, documented information, internal audit, management review, corrective action) are audited once for both. This checklist marks 27 of its 38 questions as common to both, and the rest as specific to one standard, so an integrated audit avoids asking the same question twice.

How often should an ISO internal audit be done?

At planned intervals, covering the whole scope within the certification cycle. Most organisations run a rolling programme so every process and site is audited at least once a year, with higher-risk areas more often. Certification bodies hold surveillance audits every calendar year, so an internal audit that finishes well before each surveillance visit is the practical target.

Who can use this checklist?

Anyone running an internal audit who is not auditing their own work, which is the impartiality requirement in clause 9.2. That can be a trained member of staff from another department or an external auditor. Add questions for your own legal requirements, procedures and sites before you use it.

Related: ISO internal audit services, managed ISO systems for keeping certification across several sites, and ISO internal auditor training.