ISO 45001 Documentation Requirements Explained Simply

Quick Answer: ISO 45001 requires 17 categories of mandatory documented information covering everything from your OH&S policy to internal audit reports. The standard doesn't dictate specific formats — documents can be digital or paper — but every requirement must be demonstrably in place before your certification audit.


Key Takeaways

  • ISO 45001 has 17 mandatory documented information requirements spread across Clauses 4 to 10
  • The standard uses the term "documented information" — this covers both live documents (policies, procedures) and completed records (audit reports, training logs)
  • No specific format is required; paper, spreadsheets, and digital systems all work
  • Core mandatory documents include the OHSMS scope, OH&S policy, risk assessment methodology, and emergency preparedness procedures
  • Worker consultation and participation procedures must be documented — many organisations underestimate this requirement
  • You can (and often should) create additional documents beyond the mandatory list to suit your business
  • ISO 45001:2027 is scheduled for release in 2027 and will expand requirements to include psychosocial hazards and mental wellbeing
  • A gap analysis before you start will tell you exactly which documents you're missing

What Does "Documented Information" Actually Mean in ISO 45001?

ISO 45001 doesn't ask you to produce a filing cabinet full of paper. "Documented information" simply means any information your organisation needs to control and maintain — whether that's a written procedure, a digital form, a completed checklist, or a database record.

The standard splits this into two types:

  • Documents to maintain — things you keep current, like your OH&S policy or risk assessment process
  • Records to retain — completed evidence, like audit reports, training attendance logs, and incident investigation outcomes

Here's the thing: the standard deliberately avoids prescribing formats. A Google Doc, a spreadsheet, a purpose-built software system — all valid. What matters is that the information exists, is controlled, and is accessible to the people who need it.


ISO 45001 Documentation Requirements Explained Simply: The Full Mandatory List

There are 17 mandatory documented information requirements in ISO 45001:2018. Here's a plain-English breakdown grouped by clause:

Clause 4 — Organisational Context

  • Scope of the OHSMS (4.3)

Clause 5 — Leadership

  • OH&S Policy (5.2)
  • Worker consultation and participation procedures (5.4)

Clause 6 — Planning

  • Methodology and criteria for assessing OH&S risks (6.1.2.2)
  • Legal and other requirements register (6.1.3)
  • OH&S objectives and plans to achieve them (6.2.2)

Clause 7 — Support

  • Competence evidence (7.2)
  • Documented information required by the standard and deemed necessary by the organisation (7.5)

Clause 8 — Operation

  • Operational planning and control processes (8.1)
  • Emergency preparedness and response procedures (8.2)
  • Management of change processes (8.1.3)
  • Contractor and supplier management records (8.1.4)

Clause 9 — Performance Evaluation

  • Monitoring and measurement results (9.1.1)
  • Compliance evaluation records (9.1.2)
  • Internal audit programme and reports (9.2)
  • Management review results (9.3)

Clause 10 — Improvement

  • Incident, nonconformity, and corrective action records (10.2)

Common mistake: Many organisations document the OH&S policy but forget the worker consultation procedure. Auditors look for this specifically — it's a standalone requirement, not just a tick under participation.


Which Documents Trip People Up Most?

In practice, three areas catch organisations off guard.

1. Worker consultation procedures
ISO 45001 is more prescriptive about worker involvement than most people expect. You need a documented process showing how workers are consulted and how they participate in OH&S decisions. A suggestion box doesn't cut it.

2. Management of change
Any significant change to operations, personnel, processes, or equipment needs a documented assessment of OH&S risks before the change happens. Many businesses do this informally — the standard wants it formalised.

3. Compliance evaluation records
You need documented evidence that you've assessed your compliance with applicable legal requirements — not just a list of laws, but records showing you've checked against them. This surprises organisations who assumed a legal register alone was sufficient.


ISO 45001 Documentation Requirements Explained Simply: What You Don't Have to Document

Here's what nobody tells you: the standard doesn't require a procedure for everything. Plenty of ISO 45001 requirements are about doing, not documenting.

You don't need a written procedure for every single activity. What you need is evidence that the activity happened when a record is required. For everything else, the question is: "Would a new person be able to do this correctly without a written procedure?" If yes, you might not need one. If no, write it down.

This is where organisations often over-engineer. They create mountains of documentation that nobody reads and nobody maintains. Keep it lean. Document what you genuinely need. Your auditor isn't counting pages — they're checking that your system works.


How Should You Control Your Documents?

Clause 7.5.3 requires that documented information is controlled. In plain English, this means:

  • Documents are available to the right people at the right time
  • Documents are protected from inappropriate use or loss
  • Version control is in place (people aren't working from outdated copies)
  • You have a process for reviewing and updating documents

A shared drive with clear folder structure and version numbers works. So does a dedicated quality management system. The format is your call — the control is not optional.

For a broader view of what the certification process looks like from start to finish, the complete ISO certification process guide is worth reading before you commit to a documentation approach.


What Happens to Your Documentation During an Audit?

Your Stage 1 audit is essentially a documentation review. The auditor checks that your mandatory documents exist, are appropriate to your organisation, and are properly controlled. If documents are missing or inadequate, you'll get a finding before Stage 2 even begins.

At Stage 2, auditors verify that your documented processes actually reflect what's happening on the ground. A beautiful procedure that nobody follows is worse than no procedure at all — it's evidence of a gap between your system and your reality.

Understanding what happens during an ISO certification audit will help you prepare your documentation with the right mindset: write for reality, not for the auditor.


What's Changing With ISO 45001:2027?

ISO 45001 is scheduled for an update in 2027. Based on current guidance, the revised standard is expected to expand documentation requirements to include:

  • Psychosocial hazards and mental wellbeing — organisations will likely need documented processes for identifying and managing work-related stress and mental health risks
  • Inclusivity and diversity considerations in OH&S risk management
  • Climate emergency readiness as a contextual factor

If you're implementing ISO 45001 now, it's worth building your documentation framework with these areas in mind. Retrofitting later is always more painful than getting it right the first time. You can read more about the full scope of ISO 45001 and what it covers for your organisation.


FAQ

How many mandatory documents does ISO 45001 require?
ISO 45001:2018 requires 17 categories of mandatory documented information, covering everything from the OHSMS scope through to corrective action records.

Does ISO 45001 require a specific document format?
No. Documents can be paper, digital, or a combination. The standard requires control and accessibility, not a particular format.

What's the difference between a document and a record in ISO 45001?
Documents are maintained and kept current (like policies and procedures). Records are retained as evidence that something happened (like audit reports and training logs).

Do I need a documented procedure for every ISO 45001 requirement?
No. The standard only mandates documented information where it explicitly says so. Over-documenting creates maintenance burden without adding value.

What happens if my documentation is incomplete at the audit?
At Stage 1, missing mandatory documents will result in findings that must be addressed before Stage 2. At Stage 2, inadequate documentation can result in nonconformities that delay certification.

Can I use existing health and safety documents to meet ISO 45001 requirements?
Yes, provided they meet the standard's requirements. A gap analysis will identify which existing documents are sufficient and which need updating.

Is worker consultation documentation really mandatory?
Yes. Clause 5.4 requires documented processes for worker consultation and participation. It's one of the most commonly missed requirements.

How long do I need to retain ISO 45001 records?
The standard doesn't specify retention periods — you need to determine these based on legal requirements, operational needs, and your own risk assessment.

What's the easiest way to manage ISO 45001 documentation?
A shared digital system with clear version control and access permissions works well for most organisations. Dedicated management system software is worth considering if you're managing multiple standards.

Should I integrate ISO 45001 documentation with other management systems?
If you hold or are pursuing other ISO standards, integration makes sense and reduces duplication. ISO 45001 uses the same High Level Structure as ISO 9001 and ISO 14001, making integration straightforward.


Conclusion

Getting your ISO 45001 documentation right isn't about producing the most documents — it's about producing the right documents, controlling them properly, and making sure they reflect how your organisation actually operates.

Start with the 17 mandatory requirements. Build from there based on what your business genuinely needs. Keep it lean, keep it current, and make sure your people know where to find things.

Practical next steps:

  1. Run a gap analysis to identify which mandatory documents you already have and which are missing
  2. Prioritise the OH&S policy, OHSMS scope, and risk assessment methodology — these form the foundation everything else sits on
  3. Build a simple document register so you know what exists, who owns it, and when it was last reviewed
  4. Don't forget worker consultation procedures — they're mandatory and frequently overlooked
  5. If you want expert support building your documentation framework from scratch, get in touch with ISO Adviser — we've guided hundreds of organisations through exactly this process

For a broader view of the certification journey, the ISO certification steps guide for first-time applicants is a solid next read.


ISO 45001 Mandatory Documents Checklist

Tick each document as you complete it. Track your readiness before the audit.

0 of 17 documents completed
Clause 4 — Organisational Context
Scope of the OHSMS
Clause 4.3 — defines boundaries and applicability of your system
Critical
Clause 5 — Leadership
OH&S Policy
Clause 5.2 — signed, communicated, and available to workers
Critical
Worker Consultation & Participation Procedures
Clause 5.4 — frequently missed; must be a standalone documented process
Often Missed
Clause 6 — Planning
OH&S Risk Assessment Methodology & Criteria
Clause 6.1.2.2 — how you identify and evaluate hazards and risks
Critical
Legal & Other Requirements Register
Clause 6.1.3 — applicable health and safety legislation and obligations
Critical
OH&S Objectives & Plans to Achieve Them
Clause 6.2.2 — measurable targets with assigned responsibilities and timelines
Critical
Clause 7 — Support
Competence Evidence
Clause 7.2 — training records, qualifications, and competency assessments
Records
Clause 8 — Operation
Operational Planning & Control Processes
Clause 8.1 — day-to-day OH&S risk management procedures
Critical
Management of Change Processes
Clause 8.1.3 — risk assessment before operational changes are implemented
Often Missed
Contractor & Supplier Management Records
Clause 8.1.4 — procurement controls and contractor OH&S requirements
Records
Emergency Preparedness & Response Procedures
Clause 8.2 — documented plans for potential emergency situations
Critical
Clause 9 — Performance Evaluation
Monitoring & Measurement Results
Clause 9.1.1 — records of OH&S performance data and KPI tracking
Records
Compliance Evaluation Records
Clause 9.1.2 — evidence you've checked compliance against legal requirements
Often Missed
Internal Audit Programme & Reports
Clause 9.2 — planned audit schedule plus completed audit findings
Critical
Management Review Results
Clause 9.3 — formal records of top management review meetings and decisions
Critical
Clause 10 — Improvement
Incident & Nonconformity Records
Clause 10.2 — incident investigations and near-miss reports
Records
Corrective Action Records
Clause 10.2 — documented actions taken to address nonconformities and prevent recurrence
Records