What this is
What is an ISO 45001 readiness audit?
What is an ISO 45001 readiness audit?
It is a clause-by-clause assessment of an occupational health and safety management system against the requirements of ISO 45001, carried out internally before a certification body audits it. Each requirement is scored on the evidence that exists today, gaps are recorded with the severity they would carry if an external auditor found them, and the record ends in a recommendation on whether to proceed with the external audit or move the date.
How does it differ from an internal audit?
An internal audit under clause 9.2 samples a process against the system as designed: does the permit procedure get followed in the maintenance workshop. A readiness audit tests the system as designed against the standard: does the organisation have the arrangements clause 8.1.4 requires. Neither substitutes for the other, which is why the readiness record asks separately whether the internal audit programme is operating at all.
When should a readiness audit be run?
Far enough ahead that the gaps found can be closed and then evidenced, which for a first certification means roughly ten to sixteen weeks before stage 2. Several clauses depend on elapsed time rather than effort: the internal audit cycle, management review, compliance evaluation and progress against objectives. A gap discovered six weeks out on any of those cannot be closed, only disclosed.
Scope
When is an iso 45001 readiness audit required?
A readiness audit is a gap audit against a standard, run to a deadline. It is not the internal audit programme, not the process audit and not the certification decision, and standing in for any of those leaves a hole the certification body will find.
Use this template when
- A first certification to ISO 45001 has been booked and the organisation needs to know whether stage 2 is survivable
- A recertification or surveillance visit is approaching and the system has changed since the last one
- The management system has been extended to a new site, activity or scope that has never been audited externally
- An external audit produced findings and the whole standard needs testing, not only the clauses cited
- A maintenance check between certification cycles, to stop readiness decaying quietly between visits
Do not use it for
- Auditing a single process against the system, which is the Process Audit Record and samples practice rather than clause coverage
- Planning and tracking audit coverage across the year, which belongs to the Internal Audit Programme and the Audit Plan
- The environmental management system, which needs the ISO 14001 Readiness Audit because the clauses on aspects, impacts and lifecycle have no equivalent here
- A first pass on a standard never held before, where the Certification Gap Analysis is the more honest instrument because it does not pretend to score maturity
- Recording what a certification body or customer actually found, which is the External Audit Record and the Audit Non Conformance Response Record
Compliance mapping
Which ISO 45001:2018 requirements does this satisfy?
No regulator requires certification, and none requires a readiness audit. Regulation requires the underlying duty; ISO 45001 requires that the arrangements be planned, operated, monitored and reviewed. The readiness audit is where both are checked against the same evidence at once.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 45001 cl.4 and cl.5 | Context and interested parties determined, scope documented, policy established and communicated, leadership demonstrated, roles assigned, and worker consultation provided for | Context and leadership |
| ISO 45001 cl.6.1, 6.2 and 8.1.3 | Hazard identification, risk and opportunity assessment, legal and other requirements determined, measurable objectives with plans, and control of change | Planning |
| ISO 45001 cl.7.1 to 7.5 | Resources, competence, awareness, internal and external communication, and documented information controlled and retained | Support |
| ISO 45001 cl.8.1.2, 8.1.4 and 8.2 | Hierarchy of controls applied, procurement, contractor and outsourcing controls in place, and emergency preparedness including periodic testing of the response | Operation |
| ISO 45001 cl.9.1 to 9.3 and cl.10 | Monitoring and measurement, evaluation of compliance, internal audit, management review, incident and nonconformity handling, continual improvement | Performance and improvement |
| ISO 19011 | Audit evidence collected and verified against audit criteria, with findings supported rather than asserted, and workers interviewed as a source of evidence | Evidence quality |
| ISO 45001 cl.10.2 | Nonconformities reacted to, root cause determined, corrective action taken and effectiveness reviewed, with records of the nature of the nonconformity | Gaps |
| ISO/IEC 17021-1 | Initial certification audited in two stages, with stage 2 evaluating implementation and effectiveness on site before a certification decision is taken | Result |
What it does not cover
- The internal audit programme, which under clause 9.2.2 must be planned, established and maintained across the processes and clauses over a cycle, and which a single annual readiness sweep does not constitute.
- Management review, which under clause 9.3 has a prescribed list of inputs and required outputs and must be conducted by top management, not summarised by the auditor.
- Evaluation of compliance, which under clause 9.1.2 requires the organisation to determine whether it actually meets each legal requirement, not to record that a register of requirements exists.
- The certification decision, which only an accredited certification body can take under ISO/IEC 17021-1, and which no internal score influences.
- Corrective action on the gaps found, which belongs in the CAPA record and must reach root cause and effectiveness verification rather than closing on the correction.
Global
ISO 45001 Readiness Audit requirements by country
ISO 45001 is voluntary everywhere. What varies is the legal floor sitting underneath it, and whether a certificate carries any weight with a regulator, a customer or a court.
OSH Act, including the General Duty Clause; ANSI/ASSP Z10 as the domestic analogue
No certification requirement and no regulatory recognition of ISO 45001; enforcement runs on standard-specific compliance.
A certificate is a customer and insurer asset, not a defence, and scoring conformity to the standard is not an evaluation of compliance with 29 CFR.
Health and Safety at Work etc. Act 1974; Management of Health and Safety at Work Regulations 1999; HSE guidance HSG65
Statutory duties are outcome based; certification is not mentioned in law but is routinely demanded in tender.
HSE looks at arrangements and their operation, so a gap scored as documented but not implemented carries regulatory exposure as well as audit risk.
Framework Directive 89/391/EEC and its daughter directives, transposed nationally
National law sets the minimum; ISO 45001 sits above it and does not replace any national documentation duty.
A system conforming to ISO 45001 can still breach a member state requirement, so legal registers belong per country of operation rather than centrally.
Provincial and federal OHS legislation; CSA Z45001 as the national adoption of ISO 45001; provincial COR audit schemes
Joint health and safety committee duties are statutory in most jurisdictions and overlap heavily with clause 5.4.
Worker participation gaps are an audit finding and a statutory breach at once, and existing COR audit evidence can usually be reused against clause 5.4.
Model WHS Act and Regulations; AS/NZS ISO 45001:2018
Duties are framed as so far as is reasonably practicable, with consultation duties in the Act itself.
Reasonably practicable is a legal test no conformity score answers, so control decisions need documented reasoning as well as a clause tick.
ISO 45001:2018, ISO 19011:2018, ISO/IEC 17021-1:2015 and IAF MD 22
Certification bodies audit against the standard under accreditation rules that fix stage structure, audit duration and sampling.
Audit time and multi-site sampling follow accreditation mandatory documents rather than negotiation, so assume the sample reaches the site nobody wants visited.
How to complete it
How to complete an iso 45001 readiness audit, step by step
The form produces a percentage from whatever is entered. Four judgements decide whether it predicts the external outcome or records the mood of the internal team.
For every requirement, the evidence has to be produced during the audit and named. Knowing that a procedure exists somewhere is not evidence located, and a clause whose record could not be found in the session is not partly met, it is not met until it is found. The record asks separately whether evidence was located and whether it would satisfy an external auditor, because those are different answers and the second predicts the outcome.
The line between a minor and a major is not size, it is whether the failure is systemic or the requirement absent. One missing induction record is a minor; an induction process that never ran on nights is a major, and so is any clause with no arrangement at all. Grading everything minor to keep the summary calm degrades the record most, because the recommendation is derived from that grading.
External auditors sample people as well as documents, and they ask the person on the line what happens when they see something unsafe. The consultation procedure tells you nothing about whether the arrangement is live. Speak to workers on every shift pattern the site runs, record the number, and treat a system only the day shift can describe as a gap against awareness and consultation, not a communication opportunity.
The output that matters is the recommendation on proceeding, and it is only worth recording if a no can move the external audit. Where gaps are graded major and are not closable in the time available, the honest options are to defer the visit or to accept a finding deliberately, having priced it. A readiness audit that always recommends proceeding is a formality, and the reaudit date exists so a conditional yes has something behind it.
What auditors find
Most common iso 45001 readiness audit findings
Findings against a readiness audit are rarely that it was not done. They concern who did it, what it looked at, and whether its conclusions matched what the external auditor found.
| Finding | Clause | What fixes it |
|---|---|---|
| Readiness audit conducted by the person who owns and maintains the management system. | ISO 45001 cl.9.2.2 | Use a trained auditor from outside the process, and record the impartiality basis on the audit record. |
| Every clause scored fully or partly met, yet stage 2 raised majors against clauses 9.2 and 10.2. | ISO 19011 | Require a named record for each scored clause and default to not met where none was produced. |
| Records created after the audit date to fill a known gap, with signatures added retrospectively. | ISO 45001 cl.7.5.2 | Record the gap and its date; a missing record is a minor, a manufactured one is a major. |
| Only the day shift interviewed; night and weekend crews could not describe the policy or the reporting route. | ISO 45001 cl.7.3 | Sample every shift pattern the site operates and score awareness on the weakest, not the average. |
| Worker consultation scored met on the existence of a committee that has not met for months. | ISO 45001 cl.5.4 | Test operation, not arrangement: ask for the last three sets of minutes and the actions they produced. |
| Legal requirements scored met, but no evaluation of compliance had been performed in the cycle. | ISO 45001 cl.9.1.2 | Separate having a register of obligations from having evaluated compliance against each one. |
| Management review recorded as conducted, but the minutes lack the required inputs and produce no outputs. | ISO 45001 cl.9.3 | Build the agenda from the clause's input list and record decisions, resources and changes as outputs. |
| Gaps logged without an owner, a severity grading or a closure date before the external visit. | ISO 45001 cl.10.2 | Assign an owner and a date at the point the gap is raised, and grade it as an external auditor would. |
| Gaps closed by correction alone, with no root cause and no effectiveness check. | ISO 45001 cl.10.2 | Route each gap to a CAPA record and verify effectiveness on evidence rather than on the closure note. |
| A high score reported on a form that was only half completed, with whole sections left blank. | ISO 45001 cl.9.2.2 | Report score and completeness together, and treat an incomplete audit as inconclusive rather than passing. |
Case in point
Case in point: ninety-one per cent, two majors
A chilled foods manufacturer preparing for first certification ran its readiness audit eleven weeks out. The health and safety manager, who had written most of the system over the preceding year, scored it at ninety-one per cent. Two clauses came back partly met, both on documented information, and the recommendation was to proceed. The gaps went to the improvement log with owners and dates.
Stage 2 raised two majors. The safety committee that evidenced worker consultation had last met seven months earlier, its terms of reference were never reissued after a restructure, and the operators the auditor spoke to on nights did not know it existed. The register of legal and other requirements was three years old with no evaluation of compliance against it, so that clause had a document behind it and no activity. The certificate was deferred pending corrective action and a follow-up visit.
Neither finding was hidden. Both clauses were scored on the existence of an arrangement rather than on evidence that it was operating, and both were scored by the person who had created the arrangement and therefore knew it was meant to be working. The corrective action that mattered was a rule: no clause may be scored met on a document alone where the clause requires an activity, and the scorer may not be the owner.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
9 sections
- Reference
- CMP-018
- Archetype
- Audit
- Record ID
- AUD-2026-000
- Scoring
- Weighted percent, maturity
- Direction
- High is good
- Singleton
- No
- Basis
- ISO 45001:2018
- Links
- Links Clause Register; feeds Finding
- Tags
- Certification, Safety
- Sections
- 9
- Fields
- 80
- Follow up fields
- 3
- Repeating sections
- 1
- Links out
- 3
Header
13 fieldsAudit ID*
Auto sequence. Format AUD-2026-00000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Standard*
Audit Purpose*
Initial certification readiness, recertification readiness, or maintenance check.
Auditor*
External Audit Date
Weeks Until External Audit*
Certification Body
Score Honestly Now Or Fail Later
Marking yourself green when you are amber wastes the whole exercise. The external auditor will find it anyway, and you will have lost the chance to fix it first.
Context and leadership
6 fieldsContext And Interested Parties Determined*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Scope Defined And Documented*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Policy Established And Communicated*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Top Management Demonstrating Leadership*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Roles And Responsibilities Assigned*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Worker Consultation And Participation*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Planning
6 fieldsHazards Identified Systematically*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Risks And Opportunities Assessed*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Legal Requirements Determined*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Objectives Established And Measurable*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Planning To Achieve Objectives*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Change Management Process*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Support
6 fieldsResources Provided*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Competence Determined And Achieved*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Awareness Across The Workforce*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Communication Internal And External*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Documented Information Controlled*
- Yes3 pts
- Partly1 pt
- No0 pts
Records Retained And Retrievable*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Operation
6 fieldsOperational Planning And Control*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Hierarchy Of Controls Applied*
- Yes3 pts
- Partly1 pt
- PPE focused0 pts
Contractor And Outsourcing Control*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Procurement Controls*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Emergency Preparedness And Response*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Emergency Drills Conducted*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Performance and improvement
9 fieldsMonitoring And Measurement*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Compliance Evaluation Performed*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Internal Audit Programme Operating*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Management Review Conducted*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Incident Investigation Process*
- Documented3 pts
- Informal1 pt
- None0 pts
Nonconformity And Corrective Action*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Continual Improvement Evidenced*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Trend Analysis Performed*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Worker Participation In Improvement*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Evidence quality
6 fieldsEvidence Located For Each Clause*
- Yes3 pts
- Partly1 pt
- No0 pts
Evidence Would Satisfy An External Auditor*
- Yes3 pts
- Marginal1 pt
- No0 pts
Records Contemporaneous*
- Yes3 pts
- Doubtful1 pt
- Clearly not0 pts
People Can Explain Their Part*
External auditors ask front line workers. If they cannot describe the system, documentation will not save you.
- Yes3 pts
- Partly1 pt
- No0 pts
Front Line Workers Spoken To*
All Shifts Checked*
- Yes3 pts
- Partly1 pt
- No0 pts
Gaps
Repeats6 fieldsClause*
Gap Description*
Severity If Found Externally*
- Observation3 pts
- Minor2 pts
- Major1 pt
- Critical0 pts
Owner*
Closable Before External Audit*
- Yes3 pts
- Partly1 pt
- No0 pts
CAPA ID
Links to FDN-014 CAPA ID
Result
22 fieldsItems Assessed*
Excludes anything marked N/A.
Items Failed*
Score Percent*
Calculated on submission. High is good. N/A items leave the denominator.
Result Band*
- Pass3 pts
- Caution1 pt
- Fail0 pts
Completeness Percent*
How much of the template was actually answered. A high score on a half completed form is not a high score.
Clauses Fully Met*
Clauses Partially Met*
Clauses Not Met*
Readiness Percent*
Likely External Outcome*
- Pass cleanly4 pts
- Pass with minors3 pts
- Majors likely1 pt
- Fail likely0 pts
Recommend Proceeding With External Audit*
- Yes3 pts
- With reservations1 pt
- No0 pts
Gap Analysis ID
Links to CMP-020 Analysis ID
Reaudit Before External*
- Not needed3 pts
- Yes1 pt
Reaudit Date
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Auditor*
Signature*
Site Manager*
Second Signature*
CMP-018 · record IDs look like AUD-2026-000 · Links Clause Register; feeds Finding
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The audit is a day's work. What decays is everything around it: the gap closed on a correction, the evidence that lived in someone's inbox, and the twelve months of operating records nobody kept until the certificate was booked.
Holds the clause register against the readiness record, so evidence produced anywhere in the system is already tagged to the clause it answers.

Watches the gap list against the external audit date, flags majors that are not closable in the time remaining, and surfaces the recommendation before the visit is confirmed.
Supplies the operating evidence the time-dependent clauses need: hazard identification, risk assessments, investigations, inspections and drills with their dates intact.
Evidences competence and awareness by shift and role, which is where clauses 7.2 and 7.3 are decided once an auditor starts interviewing the front line.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Meet KnowComply→Glossary
ISO 45001 Readiness Audit definitions and key terms
- Readiness audit
- An internal assessment of a management system against the full text of a standard, run ahead of external audit to find and grade gaps while they can still be closed.
- Stage 1 and stage 2
- The two parts of an initial certification audit: stage 1 examines documentation, scope and preparedness, stage 2 examines implementation on site.
- Major nonconformity
- A failure that indicates a systemic breakdown or the absence of a required arrangement, and which normally prevents or delays certification until corrective action is accepted.
- Minor nonconformity
- An isolated lapse against a requirement whose arrangement otherwise exists and functions, closed on corrective action without a return visit.
- Objective evidence
- Records, statements of fact or other verifiable information relating to the audit criteria, as distinct from opinion, intention or the auditor's own familiarity.
- Impartiality
- The auditor having no responsibility for the activity audited, required by clause 9.2.2 and the first thing a certification body checks in an internal audit record.
- Clause tagging
- Attaching a clause reference to a record created elsewhere, so evidence produced for its own purpose can be found when that clause is audited.
- Surveillance audit
- The periodic external audit between recertifications, sampling part of the system rather than all of it, which is why readiness decays unnoticed.
FAQ
Frequently asked questions about iso 45001 readiness audit
Can a readiness audit count as our internal audit under clause 9.2?+
Sometimes, and only under conditions. It must appear in the audit programme, have defined criteria and scope, be conducted by someone impartial to the processes audited, and be reported to relevant management. Even then it covers clauses rather than processes, so a programme built only from readiness audits reads thin the moment an auditor asks which processes were sampled and why.
How long before the external audit should this be run?+
Ten to sixteen weeks for a first certification, at least six for a surveillance visit. The constraint is not the audit, it is closure and evidence: a corrective action implemented three days before the auditor arrives has no record of operating. Running it early and reauditing the failed clauses beats running it once, late.
What score means we are ready?+
None of them. Certification bodies do not average, they count nonconformities and grade them. The readable answer is in the distribution: how many clauses are not met, whether any are systemic, and whether the majors are closable before the visit. A score in the nineties with one major is a deferral; one in the seventies with only minors usually is not.
Who should carry out the readiness audit?+
A trained internal auditor who does not own the management system, and where nobody fits, an external consultant. The trade-off with a consultant is ownership: they find more, and the organisation is less invested in the findings. Whoever does it, the site manager countersigning matters, because a recommendation to defer only has force if operational leadership signed it.
Do we really need twelve months of records before certification?+
For the cycle-dependent clauses, effectively yes. A certification body will look for a completed internal audit cycle, at least one management review with the required inputs, an evaluation of compliance, incident investigations and objectives with measured progress. Systems younger than that can be audited, but the clauses that depend on elapsed time will be assessed on whatever has actually happened.
Should we show the readiness audit to the certification body?+
You are not obliged to hand over the readiness report, and you must not conceal what it found. The auditor will ask for internal audit records, management review minutes and the nonconformity log, and a gap identified internally and being worked reads better than one discovered cold. What reads badly is everything scored green beside an external finding of systemic failure.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Internal Audit and Certification
Internal Audit Programme
Sets out what will be audited, when, by whom and against which standard, across the year
Internal Audit Report
Records an internal audit against a standard or process, with findings and evidence
Audit Plan
Sets out the scope, criteria, schedule and people involved for a single audit
Audit Finding Record
Records a single audit finding with its evidence, clause reference and classification
Audit Follow Up Record
Checks whether audit findings have actually been closed and the fixes work
Auditor Competency Record
Records an internal auditor's training, experience and audits performed
More in Cert Readiness
ISO 14001 Readiness Audit
Audits the environmental management system against ISO 14001 ahead of certification or surveillance
Certification Gap Analysis
Identifies what is missing before a first certification attempt
External Audit Record
Records a certification body or customer audit, including findings and the response required

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 45001:2018, clauses 4 to 10 and Annex A guidance
- ISO 19011:2018 guidelines for auditing management systems
- ISO/IEC 17021-1:2015 requirements for bodies providing audit and certification of management systems
- IAF MD 22 on the application of ISO/IEC 17021-1 for OH&S management system certification
- IAF MD 5 on the determination of audit time
- HSE HSG65, Managing for health and safety (GB); CSA Z45001 (Canada)
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.