What this is
What is a policy statement record?
What is a policy statement record?
It is the controlled record of the organisation's signed OH&S policy: the statement itself, the commitments it makes, its version and issue date, and where and how it is made available. It exists so the policy is treated as a governed document rather than a framed poster nobody owns.
Why does it need its own record if the policy is already a PDF?
A PDF has no review trail. This record forces a decision at a fixed interval on whether the document still reflects who signed it, what the organisation does, and which standards it claims to meet, and it captures that decision as evidence rather than assumption.
Who is expected to complete it?
Top management signs the policy itself, but a compliance or HSE lead typically owns the record: tracking the review date, confirming the signatory is still in post, and raising an action when the content or the person behind it has moved on.
Scope
When is a policy statement record required?
This record governs the policy document itself — its wording, its signatory, its currency and where it is made available. It does not cover whether people actually received or understood it; that is a separate, evidenced step.
Use this template when
- A new or revised policy statement has just been signed and needs to enter document control
- The annual (or trigger-based) review of the existing policy statement is due
- A change of top management, site scope or applicable standard has occurred and the policy needs re-validation
- An audit or management review has flagged the policy as out of date or unsigned
- The workspace is being set up and a baseline policy statement record needs to exist before anything else in the programme runs
Do not use it for
- Policy Communication Record, which records how a policy already judged current was communicated and to whom, including contractors and agency workers.
- Document Control Record, which tracks the document lifecycle of every controlled document, not the policy's content or currency specifically.
- Management Review Record, which is where the policy's continuing suitability is discussed as one input among many, not where it is drafted or re-signed.
- Context and Interested Parties Review, which supplies the organisational facts this record checks the policy against, but does not itself judge the policy.
- Anything outside KnowComply, which belongs to the workspace that owns that operational process
Compliance mapping
Which ISO 45001 cl.5.2 requirements does this satisfy?
The clause map below ties the record's four content and currency checks back to specific requirements in ISO 45001 cl.5.2, rather than treating the policy as a single pass/fail block.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 45001:2018 cl.5.2(a) | Policy is appropriate to the purpose, size and context of the organisation and the nature of its OH&S risks | Content |
| ISO 45001:2018 cl.5.2(b) | Policy provides a framework for setting OH&S objectives | Content |
| ISO 45001:2018 cl.5.2(c) | Policy includes a commitment to satisfy applicable legal requirements and other requirements | Content |
| ISO 45001:2018 cl.5.2(f) | Policy includes a commitment to consultation and participation of workers, and worker representatives | Content |
| ISO 45001:2018 cl.5.1 | Top management demonstrates leadership by establishing, implementing and personally approving the policy | Currency |
| ISO 45001:2018 cl.7.5.3 | Documented information is controlled: identifiable, version-controlled, and superseded copies withdrawn from use | Currency |
| ISO 45001:2018 cl.5.2 (chapeau) | Policy is available as documented information and available to interested parties, as appropriate | Availability |
What it does not cover
- A policy signed by a managing director who left the business two years ago, which tells an auditor that nobody has revisited the document since a change of that magnitude.
- A policy carrying generic commitments to "compliance" and "continual improvement" with no reference to what the site actually makes, handles or does, which reads as boilerplate copied from a template rather than a genuine commitment.
- A policy version-stamped correctly but with an older copy still pinned in the canteen, which fails document control even though the current record looks clean.
- A review date moved forward with no evidence the content, structure or standard checks were actually reconsidered, which is a date change, not a review.
- A policy available only in English at a site with a workforce that does not primarily read English, which fails the availability requirement regardless of how current the content is.
Global
Policy Statement Record requirements by country
ISO 45001 is not tied to a single legal jurisdiction, but how the policy statement is treated varies by where and how the certification is used.
ISO 45001:2018 cl.5.2, verified via accredited third-party audit
Certification bodies treat an outdated or unsigned policy as a routine minor nonconformity, and a repeated one as evidence the management review process itself is not functioning.
The record needs to survive a surveillance audit, not just look correct internally — the signatory and review trail are the first things checked.
Health and Safety at Work etc. Act 1974, s.2(3) (written statement of general policy, for employers with five or more employees)
UK law imposes a separate statutory duty to have a written health and safety policy, independent of any ISO certification decision.
A UK site cannot treat this record as optional even if it drops ISO 45001 certification — the underlying legal duty to maintain and revise the statement persists.
OSH Act 1970, General Duty Clause (29 U.S.C. §654), with ISO 45001 adopted voluntarily
OSHA does not mandate a written OH&S policy statement or ISO 45001 certification; the record's value is largely contractual, driven by customer or insurer requirements.
In the US the currency of this record is judged against whoever is relying on the certificate, not a regulator, so lapses surface as commercial risk rather than statutory exposure.
How to complete it
How to complete a policy statement record, step by step
Filling in the fields is mechanical. The judgement calls below are what actually determine whether the record defends the policy or just documents that a form was opened.
A policy that could describe almost any company in the sector is not appropriate to this one. The reviewer has to be willing to mark Appropriate To The Organisation as Partly or No even when the wording sounds professional, if it does not reference this organisation's actual risk profile.
Reviewed Within The Interval, Reflects Current Activities, Reflects Current Structure and Reflects Current Standards are four separate fields for a reason. Treating them as one judgement defeats the design and hides exactly the drift the record is built to catch.
Signatory Currently In Post scores zero the moment the answer is No, with no grace period built in. The judgement call is how fast the organisation moves from noticing to reissuing — leaving it recorded as a known gap for a full review cycle is itself the finding auditors cite most.
Displayed On Site and Available Digitally can both be Yes while the workforce that needs the policy in another language still cannot read it. The record only closes that gap if the reviewer treats Available In Needed Languages as load-bearing, not a formality.
What auditors find
Most common policy statement record findings
These are the failure patterns that recur across sites running this record, mapped to the clause they break and the fix that actually clears them.
| Finding | Clause | What fixes it |
|---|---|---|
| Policy signature belongs to a person no longer employed by the organisation | ISO 45001:2018 cl.5.1 / cl.5.2 | Reissue the statement for signature by the current top management role holder, increment the Version field, and log the new Issue Date |
| No evidence the policy was actually approved at top management level rather than drafted by HSE and signed off in passing | ISO 45001:2018 cl.5.1 | Route the draft through a documented approval step before publication, and hold that evidence against the Document Control ID |
| Superseded versions of the policy still visible on noticeboards or shared drives | ISO 45001:2018 cl.7.5.3 | Physically and digitally withdraw prior versions, and only then mark Superseded Versions Withdrawn as Yes |
| Policy commitments describe activities the site no longer carries out, or omit ones it has since taken on | ISO 45001:2018 cl.5.2(a) | Rewrite the commitments against the current Context and Interested Parties Review before the next Issue Date |
| No record that workers or their representatives were consulted before the policy was finalised | ISO 45001:2018 cl.5.2(f) | Capture and reference the consultation evidence before setting Commitment To Consultation to Yes, or mark it N/A only where consultation genuinely does not apply |
| Policy not available in the language spoken by a material part of the workforce | ISO 45001:2018 cl.5.2 (chapeau) | Commission translation, reissue, and raise an action record referencing the CAPA ID until distribution is confirmed |
Case in point
Case in point: the framed policy nobody had touched since a takeover
A distribution site had one policy statement, framed, dated four years prior, signed by a managing director who had left when the business was acquired eighteen months earlier. Nobody had a role called "policy owner" in the interim, so the review date simply lapsed without anyone noticing it lapse.
Reissuing it took an afternoon once someone owned it: new signatory, updated commitments reflecting the acquired entity's actual product range, and a translated second copy for a warehouse team that was majority non-English-speaking. The finding wasn't that the content was wrong — it was that no record had ever forced the question to be asked.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
5 sections
- Reference
- CMP-048
- Archetype
- Record
- Record ID
- POL-2026-000
- Scoring
- Policies current
- Direction
- High is good
- Singleton
- Yes
- Basis
- ISO 45001 cl.5.2
- Links
- Links Document control, Management review
- Tags
- Policy
- Sections
- 5
- Fields
- 45
- Follow up fields
- 3
- Repeating sections
- 0
- Links out
- 4
Header
13 fieldsRecord ID*
Auto sequence. Format POL-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Policy Type*
Version*
Issue Date*
Signed By*
Signatory Currently In Post*
- Yes3 pts
- No0 pts
Next Review Due*
Signed By Somebody Who Left Two Years Ago
The most common opening finding of any audit. It signals that nothing in the management system is genuinely reviewed.
Content
6 fieldsCommitment To Legal Compliance*
- Yes3 pts
- Partly1 pt
- No0 pts
Commitment To Continual Improvement*
- Yes3 pts
- Partly1 pt
- No0 pts
Commitment To Consultation Where Required*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Appropriate To The Organisation*
- Yes3 pts
- Partly1 pt
- No0 pts
Framework For Objectives*
- Yes3 pts
- Partly1 pt
- No0 pts
Standard Specific Commitments Included*
- Yes3 pts
- Partly1 pt
- No0 pts
Currency
6 fieldsReviewed Within The Interval*
- Yes3 pts
- Partly1 pt
- No0 pts
Reflects Current Activities*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Reflects Current Structure*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Reflects Current Standards*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Approved At Top Management Level*
- Yes3 pts
- Partly1 pt
- No0 pts
Version Controlled*
- Yes3 pts
- Partly1 pt
- No0 pts
Availability
6 fieldsDisplayed On Site*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Available To Interested Parties*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Available In Needed Languages*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Included In Induction*
- Yes3 pts
- Partly1 pt
- No0 pts
Available Digitally*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Superseded Versions Withdrawn*
- Yes3 pts
- Partly1 pt
- No0 pts
Outcome
14 fieldsPolicy Current*
- Yes3 pts
- Overdue0 pts
Would Pass An Audit*
- Yes3 pts
- Marginal1 pt
- No0 pts
Revision Required*
- No3 pts
- Yes1 pt
Document Control ID
Links to CMP-022 Record ID
Communication Record ID
Links to CMP-049 Record ID
Next Review Due*
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Compliance Lead*
Signature*
Site Manager*
Second Signature*
CMP-048 · record IDs look like POL-2026-000 · Links Document control, Management review
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The signature and the wording are the visible part. Catching the drift between review cycles — a departed signatory, a structure change nobody flagged — is the part that depends on something actually watching the calendar.
Holds the policy statement against the review interval, flags a departed signatory automatically once role changes are logged, and keeps the version history intact when a revision is issued.
Feeds the OH&S-specific commitments and risk context this policy needs to stay appropriate, so the content check isn't done from memory.
Keeps the equivalent quality-policy commitments aligned where a site runs an integrated management system, avoiding two policies that quietly drift apart.

Surfaces the review as it comes due, drafts the reissue for a human to approve, and never signs or publishes a policy on your behalf without that sign-off.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Meet KnowComply→Glossary
Policy Statement Record definitions and key terms
- Top management
- The person or group who directs and controls the organisation at the highest level. In ISO 45001 they must personally take accountability for the OH&S policy, not merely delegate its drafting.
- Documented information
- ISO's term for any controlled record or document a management system requires — replacing the older split between "documents" and "records". The policy statement is documented information that must be maintained and controlled.
- Interested party
- Any person or organisation that can affect, be affected by, or perceive itself to be affected by the OH&S management system — workers, regulators, contractors, neighbours and customers among them.
- Version control
- The discipline of uniquely identifying each issue of a document and withdrawing prior issues from active use, so only one current version can ever be referenced or displayed.
- Management review
- The scheduled, top-management-led evaluation of the whole OH&S system, one input to which is whether the policy remains suitable. It is where systemic policy drift should surface if this record's own review has been skipped.
FAQ
Frequently asked questions about policy statement record
Does the policy statement have to be re-signed every year even if nothing has changed?+
The review has to happen every year; re-signature is only required if the review finds the content, signatory or context has changed. A confirmed unchanged review is still evidence and should be logged, not skipped because nothing moved.
Can a deputy sign the policy if the top management role is vacant?+
Only if that deputy genuinely holds accountability for the OH&S system in the interim and that authority is documented. Signing purely to keep the record current, without real accountability behind it, recreates the exact defect the record exists to catch.
Is one policy statement enough for a multi-site organisation?+
It depends on how uniform operations are across sites. Where risk profiles differ materially, a single generic statement usually fails the "appropriate to context" test at the site level, even if it is technically current and signed.
What happens if the review finds the policy is no longer appropriate?+
Mark Revision Required as Yes, raise the linked action with a CAPA ID, and hold Policy Current at its true status rather than rounding up to Yes while the rewrite is pending.
Does updating the policy automatically trigger a new communication cycle?+
It should, but this record does not do that automatically — it only judges the statement itself. A new Communication Record ID needs to be raised separately once a revised policy is signed.
Why is this a singleton record rather than one per year?+
It represents the current, live policy statement at any point in time. Prior versions are retained as controlled document history rather than as separate live records, so the register always shows a single current status.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Management System Governance
Legal and Other Requirements Register
Lists every law, regulation, permit and commitment that applies to your operation
Compliance Obligation Assessment
Assesses how each legal requirement applies to you and what you do to meet it
Compliance Evaluation Record
Records the periodic evaluation of whether you actually comply with each obligation
Regulatory Change Record
Records a change in law or regulation and what it means for you
Regulatory Inspection Record
Records a visit by a regulator, including what was inspected, what was said and any orders issued
Management Review Record
Records the periodic review of the management system by senior leadership, covering performance, risks, resources and improvement

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 45001:2018 cl.5.2 — Policy
- ISO 45001:2018 cl.5.1 — Leadership and commitment
- ISO 45001:2018 cl.7.5.3 — Control of documented information
- Health and Safety at Work etc. Act 1974, s.2(3) — Written statement of policy
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.