Knowella

Policy Statement Record

The policy statement is the shortest document in the system and the one nobody re-reads. It gets signed once, framed, and left. Two years and a management change later it still carries a name nobody recognises, a review date long past, and commitments that were true when it was written but no longer describe what the site actually does. It is the single most common opening finding auditors raise, because it is the first document they ask for.

KnowComplyRecordCMP-04845 fields across 5 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 45001 cl.5.2
Workspace
KnowComply
Form type
Record
Review trigger
Yearly, or immediately on a change of top management or standard
Completed by
Signed by top management

The short version

  • This record exists because policy documents drift silently: the content stays static while the organisation, its leadership and its standards change underneath it.
  • The single most common defect is a signature from someone who has left the organisation — ISO 45001 cl.5.2 requires top management ownership, and an absent signatory breaks that at the root.
  • Currency is checked on four axes independently — activities, structure, standards and interval — because a policy can pass one and fail the others silently.
  • Availability is scored separately from content: a correct, current policy that sits in one language on one noticeboard has not met the standard's intent.

What this is

What is a policy statement record?

What is a policy statement record?

It is the controlled record of the organisation's signed OH&S policy: the statement itself, the commitments it makes, its version and issue date, and where and how it is made available. It exists so the policy is treated as a governed document rather than a framed poster nobody owns.

Why does it need its own record if the policy is already a PDF?

A PDF has no review trail. This record forces a decision at a fixed interval on whether the document still reflects who signed it, what the organisation does, and which standards it claims to meet, and it captures that decision as evidence rather than assumption.

Who is expected to complete it?

Top management signs the policy itself, but a compliance or HSE lead typically owns the record: tracking the review date, confirming the signatory is still in post, and raising an action when the content or the person behind it has moved on.

Scope

When is a policy statement record required?

This record governs the policy document itself — its wording, its signatory, its currency and where it is made available. It does not cover whether people actually received or understood it; that is a separate, evidenced step.

Use this template when

  • A new or revised policy statement has just been signed and needs to enter document control
  • The annual (or trigger-based) review of the existing policy statement is due
  • A change of top management, site scope or applicable standard has occurred and the policy needs re-validation
  • An audit or management review has flagged the policy as out of date or unsigned
  • The workspace is being set up and a baseline policy statement record needs to exist before anything else in the programme runs

Do not use it for

  • Policy Communication Record, which records how a policy already judged current was communicated and to whom, including contractors and agency workers.
  • Document Control Record, which tracks the document lifecycle of every controlled document, not the policy's content or currency specifically.
  • Management Review Record, which is where the policy's continuing suitability is discussed as one input among many, not where it is drafted or re-signed.
  • Context and Interested Parties Review, which supplies the organisational facts this record checks the policy against, but does not itself judge the policy.
  • Anything outside KnowComply, which belongs to the workspace that owns that operational process

Compliance mapping

Which ISO 45001 cl.5.2 requirements does this satisfy?

The clause map below ties the record's four content and currency checks back to specific requirements in ISO 45001 cl.5.2, rather than treating the policy as a single pass/fail block.

ClauseRequirementWhere it lands
ISO 45001:2018 cl.5.2(a)Policy is appropriate to the purpose, size and context of the organisation and the nature of its OH&S risksContent
ISO 45001:2018 cl.5.2(b)Policy provides a framework for setting OH&S objectivesContent
ISO 45001:2018 cl.5.2(c)Policy includes a commitment to satisfy applicable legal requirements and other requirementsContent
ISO 45001:2018 cl.5.2(f)Policy includes a commitment to consultation and participation of workers, and worker representativesContent
ISO 45001:2018 cl.5.1Top management demonstrates leadership by establishing, implementing and personally approving the policyCurrency
ISO 45001:2018 cl.7.5.3Documented information is controlled: identifiable, version-controlled, and superseded copies withdrawn from useCurrency
ISO 45001:2018 cl.5.2 (chapeau)Policy is available as documented information and available to interested parties, as appropriateAvailability

What it does not cover

  • A policy signed by a managing director who left the business two years ago, which tells an auditor that nobody has revisited the document since a change of that magnitude.
  • A policy carrying generic commitments to "compliance" and "continual improvement" with no reference to what the site actually makes, handles or does, which reads as boilerplate copied from a template rather than a genuine commitment.
  • A policy version-stamped correctly but with an older copy still pinned in the canteen, which fails document control even though the current record looks clean.
  • A review date moved forward with no evidence the content, structure or standard checks were actually reconsidered, which is a date change, not a review.
  • A policy available only in English at a site with a workforce that does not primarily read English, which fails the availability requirement regardless of how current the content is.

Global

Policy Statement Record requirements by country

ISO 45001 is not tied to a single legal jurisdiction, but how the policy statement is treated varies by where and how the certification is used.

International (IAF-accredited certification)

ISO 45001:2018 cl.5.2, verified via accredited third-party audit

Certification bodies treat an outdated or unsigned policy as a routine minor nonconformity, and a repeated one as evidence the management review process itself is not functioning.

The record needs to survive a surveillance audit, not just look correct internally — the signatory and review trail are the first things checked.

United Kingdom

Health and Safety at Work etc. Act 1974, s.2(3) (written statement of general policy, for employers with five or more employees)

UK law imposes a separate statutory duty to have a written health and safety policy, independent of any ISO certification decision.

A UK site cannot treat this record as optional even if it drops ISO 45001 certification — the underlying legal duty to maintain and revise the statement persists.

United States

OSH Act 1970, General Duty Clause (29 U.S.C. §654), with ISO 45001 adopted voluntarily

OSHA does not mandate a written OH&S policy statement or ISO 45001 certification; the record's value is largely contractual, driven by customer or insurer requirements.

In the US the currency of this record is judged against whoever is relying on the certificate, not a regulator, so lapses surface as commercial risk rather than statutory exposure.

How to complete it

How to complete a policy statement record, step by step

Filling in the fields is mechanical. The judgement calls below are what actually determine whether the record defends the policy or just documents that a form was opened.

Whether "appropriate" means specific or merely plausible

A policy that could describe almost any company in the sector is not appropriate to this one. The reviewer has to be willing to mark Appropriate To The Organisation as Partly or No even when the wording sounds professional, if it does not reference this organisation's actual risk profile.

What a genuine review looks like versus a date change

Reviewed Within The Interval, Reflects Current Activities, Reflects Current Structure and Reflects Current Standards are four separate fields for a reason. Treating them as one judgement defeats the design and hides exactly the drift the record is built to catch.

How long a departed signatory is tolerated before it is a finding

Signatory Currently In Post scores zero the moment the answer is No, with no grace period built in. The judgement call is how fast the organisation moves from noticing to reissuing — leaving it recorded as a known gap for a full review cycle is itself the finding auditors cite most.

Whether availability without reach counts as availability

Displayed On Site and Available Digitally can both be Yes while the workforce that needs the policy in another language still cannot read it. The record only closes that gap if the reviewer treats Available In Needed Languages as load-bearing, not a formality.

What auditors find

Most common policy statement record findings

These are the failure patterns that recur across sites running this record, mapped to the clause they break and the fix that actually clears them.

FindingClauseWhat fixes it
Policy signature belongs to a person no longer employed by the organisationISO 45001:2018 cl.5.1 / cl.5.2Reissue the statement for signature by the current top management role holder, increment the Version field, and log the new Issue Date
No evidence the policy was actually approved at top management level rather than drafted by HSE and signed off in passingISO 45001:2018 cl.5.1Route the draft through a documented approval step before publication, and hold that evidence against the Document Control ID
Superseded versions of the policy still visible on noticeboards or shared drivesISO 45001:2018 cl.7.5.3Physically and digitally withdraw prior versions, and only then mark Superseded Versions Withdrawn as Yes
Policy commitments describe activities the site no longer carries out, or omit ones it has since taken onISO 45001:2018 cl.5.2(a)Rewrite the commitments against the current Context and Interested Parties Review before the next Issue Date
No record that workers or their representatives were consulted before the policy was finalisedISO 45001:2018 cl.5.2(f)Capture and reference the consultation evidence before setting Commitment To Consultation to Yes, or mark it N/A only where consultation genuinely does not apply
Policy not available in the language spoken by a material part of the workforceISO 45001:2018 cl.5.2 (chapeau)Commission translation, reissue, and raise an action record referencing the CAPA ID until distribution is confirmed

Case in point

Case in point: the framed policy nobody had touched since a takeover

A distribution site had one policy statement, framed, dated four years prior, signed by a managing director who had left when the business was acquired eighteen months earlier. Nobody had a role called "policy owner" in the interim, so the review date simply lapsed without anyone noticing it lapse.

Reissuing it took an afternoon once someone owned it: new signatory, updated commitments reflecting the acquired entity's actual product range, and a translated second copy for a warehouse team that was majority non-English-speaking. The finding wasn't that the content was wrong — it was that no record had ever forced the question to be asked.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

45fields
5 sections
Reference
CMP-048
Archetype
Record
Record ID
POL-2026-000
Scoring
Policies current
Direction
High is good
Singleton
Yes
Basis
ISO 45001 cl.5.2
Links
Links Document control, Management review
Tags
Policy
Sections
5
Fields
45
Follow up fields
3
Repeating sections
0
Links out
4
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

13 fields
Text

Record ID*

Generated on save

Auto sequence. Format POL-2026-000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Date & Time

Date and Time*

Users

Completed By*

Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Single Choice

Policy Type*

Health and safetyEnvironmentalQualityFood safetyEnergyEthicalPrivacy
Text

Version*

Date & Time

Issue Date*

Users

Signed By*

Single Choice

Signatory Currently In Post*

Scored
  • Yes3 pts
  • No0 pts
Date & Time

Next Review Due*

Info

Signed By Somebody Who Left Two Years Ago

The most common opening finding of any audit. It signals that nothing in the management system is genuinely reviewed.

Content

6 fields
Single Choice

Commitment To Legal Compliance*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Commitment To Continual Improvement*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Commitment To Consultation Where Required*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Appropriate To The Organisation*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Framework For Objectives*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Standard Specific Commitments Included*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Currency

6 fields
Single Choice

Reviewed Within The Interval*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Reflects Current Activities*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Reflects Current Structure*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Reflects Current Standards*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Approved At Top Management Level*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Version Controlled*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Availability

6 fields
Single Choice

Displayed On Site*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Available To Interested Parties*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Available In Needed Languages*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Included In Induction*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Available Digitally*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Superseded Versions Withdrawn*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Outcome

14 fields
Single Choice

Policy Current*

Scored
  • Yes3 pts
  • Overdue0 pts
Single Choice

Would Pass An Audit*

Scored
  • Yes3 pts
  • Marginal1 pt
  • No0 pts
Single Choice

Revision Required*

Scored
  • No3 pts
  • Yes1 pt
Text

Document Control ID

OptionalLinked

Links to CMP-022 Record ID

Text

Communication Record ID

OptionalLinked

Links to CMP-049 Record ID

Date & Time

Next Review Due*

Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Users

Compliance Lead*

Signature

Signature*

Users

Site Manager*

Signature

Second Signature*

CMP-048 · record IDs look like POL-2026-000 · Links Document control, Management review

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The signature and the wording are the visible part. Catching the drift between review cycles — a departed signatory, a structure change nobody flagged — is the part that depends on something actually watching the calendar.

KnowComply

Holds the policy statement against the review interval, flags a departed signatory automatically once role changes are logged, and keeps the version history intact when a revision is issued.

KnowSafe

Feeds the OH&S-specific commitments and risk context this policy needs to stay appropriate, so the content check isn't done from memory.

KnowQuality

Keeps the equivalent quality-policy commitments aligned where a site runs an integrated management system, avoiding two policies that quietly drift apart.

Ella
Ella

Surfaces the review as it comes due, drafts the reissue for a human to approve, and never signs or publishes a policy on your behalf without that sign-off.

This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.

Meet KnowComply→

Glossary

Policy Statement Record definitions and key terms

Top management
The person or group who directs and controls the organisation at the highest level. In ISO 45001 they must personally take accountability for the OH&S policy, not merely delegate its drafting.
Documented information
ISO's term for any controlled record or document a management system requires — replacing the older split between "documents" and "records". The policy statement is documented information that must be maintained and controlled.
Interested party
Any person or organisation that can affect, be affected by, or perceive itself to be affected by the OH&S management system — workers, regulators, contractors, neighbours and customers among them.
Version control
The discipline of uniquely identifying each issue of a document and withdrawing prior issues from active use, so only one current version can ever be referenced or displayed.
Management review
The scheduled, top-management-led evaluation of the whole OH&S system, one input to which is whether the policy remains suitable. It is where systemic policy drift should surface if this record's own review has been skipped.

FAQ

Frequently asked questions about policy statement record

Does the policy statement have to be re-signed every year even if nothing has changed?+

The review has to happen every year; re-signature is only required if the review finds the content, signatory or context has changed. A confirmed unchanged review is still evidence and should be logged, not skipped because nothing moved.

Can a deputy sign the policy if the top management role is vacant?+

Only if that deputy genuinely holds accountability for the OH&S system in the interim and that authority is documented. Signing purely to keep the record current, without real accountability behind it, recreates the exact defect the record exists to catch.

Is one policy statement enough for a multi-site organisation?+

It depends on how uniform operations are across sites. Where risk profiles differ materially, a single generic statement usually fails the "appropriate to context" test at the site level, even if it is technically current and signed.

What happens if the review finds the policy is no longer appropriate?+

Mark Revision Required as Yes, raise the linked action with a CAPA ID, and hold Policy Current at its true status rather than rounding up to Yes while the rewrite is pending.

Does updating the policy automatically trigger a new communication cycle?+

It should, but this record does not do that automatically — it only judges the statement itself. A new Communication Record ID needs to be raised separately once a revised policy is signed.

Why is this a singleton record rather than one per year?+

It represents the current, live policy statement at any point in time. Prior versions are retained as controlled document history rather than as separate live records, so the register always shows a single current status.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO 45001:2018 cl.5.2 — Policy
  • ISO 45001:2018 cl.5.1 — Leadership and commitment
  • ISO 45001:2018 cl.7.5.3 — Control of documented information
  • Health and Safety at Work etc. Act 1974, s.2(3) — Written statement of policy

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.