Quick Answer: ISO 45001 requires 17 categories of mandatory documented information covering everything from your OH&S policy to internal audit reports. The standard doesn't dictate specific formats — documents can be digital or paper — but every requirement must be demonstrably in place before your certification audit.
Key Takeaways
- ISO 45001 has 17 mandatory documented information requirements spread across Clauses 4 to 10
- The standard uses the term "documented information" — this covers both live documents (policies, procedures) and completed records (audit reports, training logs)
- No specific format is required; paper, spreadsheets, and digital systems all work
- Core mandatory documents include the OHSMS scope, OH&S policy, risk assessment methodology, and emergency preparedness procedures
- Worker consultation and participation procedures must be documented — many organisations underestimate this requirement
- You can (and often should) create additional documents beyond the mandatory list to suit your business
- ISO 45001:2027 is scheduled for release in 2027 and will expand requirements to include psychosocial hazards and mental wellbeing
- A gap analysis before you start will tell you exactly which documents you're missing
What Does "Documented Information" Actually Mean in ISO 45001?
ISO 45001 doesn't ask you to produce a filing cabinet full of paper. "Documented information" simply means any information your organisation needs to control and maintain — whether that's a written procedure, a digital form, a completed checklist, or a database record.
The standard splits this into two types:
- Documents to maintain — things you keep current, like your OH&S policy or risk assessment process
- Records to retain — completed evidence, like audit reports, training attendance logs, and incident investigation outcomes
Here's the thing: the standard deliberately avoids prescribing formats. A Google Doc, a spreadsheet, a purpose-built software system — all valid. What matters is that the information exists, is controlled, and is accessible to the people who need it.
ISO 45001 Documentation Requirements Explained Simply: The Full Mandatory List
There are 17 mandatory documented information requirements in ISO 45001:2018. Here's a plain-English breakdown grouped by clause:
Clause 4 — Organisational Context
- Scope of the OHSMS (4.3)
Clause 5 — Leadership
- OH&S Policy (5.2)
- Worker consultation and participation procedures (5.4)
Clause 6 — Planning
- Methodology and criteria for assessing OH&S risks (6.1.2.2)
- Legal and other requirements register (6.1.3)
- OH&S objectives and plans to achieve them (6.2.2)
Clause 7 — Support
- Competence evidence (7.2)
- Documented information required by the standard and deemed necessary by the organisation (7.5)
Clause 8 — Operation
- Operational planning and control processes (8.1)
- Emergency preparedness and response procedures (8.2)
- Management of change processes (8.1.3)
- Contractor and supplier management records (8.1.4)
Clause 9 — Performance Evaluation
- Monitoring and measurement results (9.1.1)
- Compliance evaluation records (9.1.2)
- Internal audit programme and reports (9.2)
- Management review results (9.3)
Clause 10 — Improvement
- Incident, nonconformity, and corrective action records (10.2)
Common mistake: Many organisations document the OH&S policy but forget the worker consultation procedure. Auditors look for this specifically — it's a standalone requirement, not just a tick under participation.
Which Documents Trip People Up Most?
In practice, three areas catch organisations off guard.
1. Worker consultation procedures
ISO 45001 is more prescriptive about worker involvement than most people expect. You need a documented process showing how workers are consulted and how they participate in OH&S decisions. A suggestion box doesn't cut it.
2. Management of change
Any significant change to operations, personnel, processes, or equipment needs a documented assessment of OH&S risks before the change happens. Many businesses do this informally — the standard wants it formalised.
3. Compliance evaluation records
You need documented evidence that you've assessed your compliance with applicable legal requirements — not just a list of laws, but records showing you've checked against them. This surprises organisations who assumed a legal register alone was sufficient.
ISO 45001 Documentation Requirements Explained Simply: What You Don't Have to Document
Here's what nobody tells you: the standard doesn't require a procedure for everything. Plenty of ISO 45001 requirements are about doing, not documenting.
You don't need a written procedure for every single activity. What you need is evidence that the activity happened when a record is required. For everything else, the question is: "Would a new person be able to do this correctly without a written procedure?" If yes, you might not need one. If no, write it down.
This is where organisations often over-engineer. They create mountains of documentation that nobody reads and nobody maintains. Keep it lean. Document what you genuinely need. Your auditor isn't counting pages — they're checking that your system works.
How Should You Control Your Documents?
Clause 7.5.3 requires that documented information is controlled. In plain English, this means:
- Documents are available to the right people at the right time
- Documents are protected from inappropriate use or loss
- Version control is in place (people aren't working from outdated copies)
- You have a process for reviewing and updating documents
A shared drive with clear folder structure and version numbers works. So does a dedicated quality management system. The format is your call — the control is not optional.
For a broader view of what the certification process looks like from start to finish, the complete ISO certification process guide is worth reading before you commit to a documentation approach.
What Happens to Your Documentation During an Audit?
Your Stage 1 audit is essentially a documentation review. The auditor checks that your mandatory documents exist, are appropriate to your organisation, and are properly controlled. If documents are missing or inadequate, you'll get a finding before Stage 2 even begins.
At Stage 2, auditors verify that your documented processes actually reflect what's happening on the ground. A beautiful procedure that nobody follows is worse than no procedure at all — it's evidence of a gap between your system and your reality.
Understanding what happens during an ISO certification audit will help you prepare your documentation with the right mindset: write for reality, not for the auditor.
What's Changing With ISO 45001:2027?
ISO 45001 is scheduled for an update in 2027. Based on current guidance, the revised standard is expected to expand documentation requirements to include:
- Psychosocial hazards and mental wellbeing — organisations will likely need documented processes for identifying and managing work-related stress and mental health risks
- Inclusivity and diversity considerations in OH&S risk management
- Climate emergency readiness as a contextual factor
If you're implementing ISO 45001 now, it's worth building your documentation framework with these areas in mind. Retrofitting later is always more painful than getting it right the first time. You can read more about the full scope of ISO 45001 and what it covers for your organisation.
FAQ
How many mandatory documents does ISO 45001 require?
ISO 45001:2018 requires 17 categories of mandatory documented information, covering everything from the OHSMS scope through to corrective action records.
Does ISO 45001 require a specific document format?
No. Documents can be paper, digital, or a combination. The standard requires control and accessibility, not a particular format.
What's the difference between a document and a record in ISO 45001?
Documents are maintained and kept current (like policies and procedures). Records are retained as evidence that something happened (like audit reports and training logs).
Do I need a documented procedure for every ISO 45001 requirement?
No. The standard only mandates documented information where it explicitly says so. Over-documenting creates maintenance burden without adding value.
What happens if my documentation is incomplete at the audit?
At Stage 1, missing mandatory documents will result in findings that must be addressed before Stage 2. At Stage 2, inadequate documentation can result in nonconformities that delay certification.
Can I use existing health and safety documents to meet ISO 45001 requirements?
Yes, provided they meet the standard's requirements. A gap analysis will identify which existing documents are sufficient and which need updating.
Is worker consultation documentation really mandatory?
Yes. Clause 5.4 requires documented processes for worker consultation and participation. It's one of the most commonly missed requirements.
How long do I need to retain ISO 45001 records?
The standard doesn't specify retention periods — you need to determine these based on legal requirements, operational needs, and your own risk assessment.
What's the easiest way to manage ISO 45001 documentation?
A shared digital system with clear version control and access permissions works well for most organisations. Dedicated management system software is worth considering if you're managing multiple standards.
Should I integrate ISO 45001 documentation with other management systems?
If you hold or are pursuing other ISO standards, integration makes sense and reduces duplication. ISO 45001 uses the same High Level Structure as ISO 9001 and ISO 14001, making integration straightforward.
Conclusion
Getting your ISO 45001 documentation right isn't about producing the most documents — it's about producing the right documents, controlling them properly, and making sure they reflect how your organisation actually operates.
Start with the 17 mandatory requirements. Build from there based on what your business genuinely needs. Keep it lean, keep it current, and make sure your people know where to find things.
Practical next steps:
- Run a gap analysis to identify which mandatory documents you already have and which are missing
- Prioritise the OH&S policy, OHSMS scope, and risk assessment methodology — these form the foundation everything else sits on
- Build a simple document register so you know what exists, who owns it, and when it was last reviewed
- Don't forget worker consultation procedures — they're mandatory and frequently overlooked
- If you want expert support building your documentation framework from scratch, get in touch with ISO Adviser — we've guided hundreds of organisations through exactly this process
For a broader view of the certification journey, the ISO certification steps guide for first-time applicants is a solid next read.
ISO 45001 Mandatory Documents Checklist
Tick each document as you complete it. Track your readiness before the audit.
