The Mandatory Records, Policies, and Procedures Your OH&S Management System Must Have
Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.
You Don’t Fail an ISO 45001 Audit Because of Your Safety Program. You Fail It Because You Can’t Prove It.
Most manufacturers with a real safety culture assume that’s enough. It isn’t. Auditors evaluate your ISO 45001 documentation requirements just as closely as your actual safety performance, and a strong program with weak documentation behind it still produces findings.
An auditor doesn’t walk your floor and take your word for it. They ask for documented information — the specific policies, records, and evidence ISO 45001 requires you to maintain and retain. If the required documented information isn’t available, controlled, or retrievable when the auditor needs objective evidence, you’re creating a potential nonconformity. It doesn’t matter how few incidents you’ve had.
This is where documentation-ready operations separate from everyone else. Not because their safety performance is better on paper, but because their paper actually matches what happens on the floor. The goal isn’t a five-minute retrieval requirement from ISO — that’s not written anywhere in the standard. It’s an operational test: if someone asks for evidence, can your team find the right record quickly, without reconstructing history on the spot?
From the Floor: I’ve sat across the table from an auditor who asked for evidence that a hazard identification process had actually been followed on a specific line — not the procedure, the record that it happened. We had the procedure. We didn’t have three months of the records behind it, because the paperwork existed as a form nobody was consistently filling out. That gap turned a strong safety program into a documented nonconformity, and it took us most of a quarter to close the loop on retraining and evidence.
If you’re not sure your OH&S management system would survive that same request, run the Manufacturing Compliance Checklist against your current files before your next audit — it takes less than an hour and tells you exactly where the gaps are. If you haven’t mapped out your certification timeline yet, our ISO 45001 Implementation Timeline breaks down when documentation work should start relative to your target audit date.
In This Guide
- What “documented information” means under ISO 45001 and why the term matters
- The specific documents you’re required to maintain (policies, procedures, plans)
- The specific records you’re required to retain (evidence of what actually happened)
- A quick-reference maintain vs. retain matrix you can hand to your team
- Where manufacturers commonly fall short — and the finding it produces
- Whether you need a full OH&S manual (you don’t)
- What to do about the ISO 45001 revision while you finalize documentation
Table of Contents
Quick Answer: ISO 45001 Documentation at a Glance
| Category | What ISO 45001 Requires | Clause |
|---|---|---|
| Scope statement | Documented boundaries and applicability of the OH&S system | 4.3 |
| OH&S Policy | Documented, communicated, and available policy statement | 5.2 |
| Roles & responsibilities | Documented assignment of OH&S roles, responsibilities, authorities | 5.3 |
| Risks, opportunities & related actions | Documented information on OH&S risks, opportunities, and the processes/actions needed to address them | 6.1.1 |
| OH&S risk assessment methodology & criteria | Methodology and criteria for assessing OH&S risks, maintained and retained | 6.1.2.2 |
| Objectives & plans | OH&S objectives and plans to achieve them — maintained and retained | 6.2.1–6.2.2 |
| Worker consultation & participation | Documented, maintained process for consultation and participation (records recommended as evidence) | 5.4 |
| Competence evidence | Records proving workers are competent for their OH&S-related duties | 7.2 |
| Operational controls | Documented information maintained and retained to the extent needed to show processes were carried out as planned | 8.1.1 |
| Emergency preparedness | Documented process for preparing for and responding to potential emergencies | 8.2 |
| Emergency response testing | Evidence that emergency response processes are periodically tested and evaluated | 8.2 |
| Legal & other requirements | Applicable OH&S legal and other requirements identified and kept current | 6.1.3 |
| Compliance evaluation | Results showing applicable requirements were periodically evaluated | 9.1.2 |
| Internal audit & management review | Audit program, audit results, and management review records | 9.2, 9.3 |
| Incidents & corrective action | Records of nonconformities, incidents, and actions taken | 10.2 |
(This is the practical short list. The detailed breakdown of the core requirements follows below.)
👉 Start Here (Top Resources)
- ISO 45001:2018 — Official Standard, ANSI Webstore — the source document that defines every documentation requirement below. Use code CC2026 for 5% off through December 31, 2026.
- ISO 45001 Training — BSI Group — for teams building documentation for the first time and wanting structured guidance on what “conforming” actually looks like.
- ISO 45001 Training — ISOQAR — a second training and certification body option worth comparing against BSI on cost and course format.
What “Documented Information” Actually Means
ISO 45001 doesn’t use the words “documents” and “records” the way most operations managers use them. It uses one term — documented information — and requires it throughout nearly every clause in the standard, from the scope statement in Clause 4.3 through corrective action in Clause 10.2. The standard groups that documented information into two functions rather than two separate document types.
Maintained documented information generally supports keeping information current as part of the management system. Your OH&S policy, your scope statement, your risk assessment methodology — these are maintained, meaning they’re kept up to date as your operation changes.
Retained documented information provides evidence that an activity, process, or result actually occurred. Your training records, your incident reports, your internal audit results — these are retained as proof something happened, not as a living reference document.
The distinction matters because auditors ask for both, and they’re looking for different things. A maintained document shows your system is designed correctly. A retained record shows your system is actually being followed. A gap between the two — a well-designed procedure with no consistent evidence behind it — is exactly what happened in the anecdote above.
The tables below organize the core ISO 45001 documentation requirements into practical categories for implementation. ISO 45001 doesn’t present these as a fixed numbered checklist — the requirement is distributed across the clauses — but the items below represent the core documentation auditors most commonly request during certification audits.
One of the more common documentation gaps: a documented procedure exists, but there’s no retained evidence that it’s been executed consistently over time. The procedure isn’t the problem. The missing paper trail behind it is.
Not sure your current documentation would hold up? Before you invest in a documentation overhaul, run the Manufacturing Compliance Checklist — most operations managers find the gap is narrower, and more fixable, than they expected.
The Documents You’re Required to Maintain
These are the “maintained” items — the documents ISO 45001 requires you to keep current and available, mapped to the clause that requires them.
| Document | Clause | What It Must Cover |
|---|---|---|
| Scope of the OH&S management system | 4.3 | Boundaries, applicability, sites and activities covered |
| OH&S Policy | 5.2 | Commitment to safe conditions, hazard elimination, legal compliance, worker consultation |
| Roles, responsibilities, and authorities | 5.3 | Who owns which OH&S function, documented and communicated |
| Risks, opportunities, and related actions | 6.1.1 | OH&S risks, opportunities, and the processes/actions needed to address them |
| OH&S risk assessment methodology and criteria | 6.1.2.2 | The methodology and criteria used to assess OH&S risk — maintained and retained as documented information |
| OH&S objectives and plans to achieve them | 6.2.1, 6.2.2 | Measurable objectives tied to the policy, with a plan, resources, and timeline — maintained and retained as documented information |
| Operational planning and control criteria | 8.1.1 | The criteria established for processes needed to meet OH&S requirements — also both maintained and retained |
| Emergency preparedness and response process | 8.2 | How the organization identifies and prepares to respond to potential emergency situations |
If you are building this system from scratch, this table is your starting checklist. Each category corresponds to documented-information requirements in ISO 45001:2018, though the exact number and format of documents you create will depend on your organization’s size, complexity, risks, and processes.
If you plan to certify through a specific registrar, ANAB and IAF both maintain public accreditation records you can check before selecting a certification body — it’s a quick way to confirm a registrar’s accreditation is current before you invest documentation time around their specific audit expectations.
If you are already ISO 9001 or ISO 14001 certified → most of this structure already exists in your management system. ISO 45001 shares the same high-level structure, so your scope statement, policy format, and objectives-planning process can largely be adapted rather than built new. Our Integrated Management Systems guide walks through exactly how to combine them.

The Records You’re Required to Retain
These are the “retained” items — the evidence that proves your system actually operated the way the maintained documents say it should.
| Record | Clause | What It Proves |
|---|---|---|
| Legal and other requirements register | 6.1.3 | Applicable OH&S legal and other requirements have been identified and kept current |
| Compliance evaluation results | 9.1.2 | The organization periodically evaluated whether those requirements are actually being met |
| Risk assessment methodology and criteria | 6.1.2.2 | The methodology and criteria used to assess OH&S risk are maintained and retained as documented information |
| OH&S objectives and plans to achieve them | 6.2.2 | The organization’s OH&S objectives and plans are maintained and retained as documented information |
| Worker consultation and participation records (recommended) | 5.4, 7.4.1 | Clause 5.4 requires a maintained process for consultation and participation; it doesn’t itself mandate a specific retained record. Retaining evidence — meeting notes, consultation logs — is standard practice and often overlaps with the communication records already required under 7.4.1 |
| Evidence of competence | 7.2 | Workers performing OH&S-related tasks are qualified for them |
| Communication records | 7.4.1 | Internal and external OH&S communications actually occurred |
| Operational control evidence | 8.1.1 | Documented and retained to the extent necessary to have confidence that processes were carried out as planned |
| Emergency response testing | 8.2 | Evidence that the planned emergency response capability was periodically tested and evaluated |
| Monitoring, measurement, and calibration | 9.1.1 | Performance data is accurate and equipment is verified |
| Internal audit program and results | 9.2.2 | The management system is being checked against itself, on a planned interval |
| Management review records | 9.3 | Leadership is actually reviewing OH&S performance, not delegating it entirely |
| Nonconformity and corrective action records | 10.2 | Evidence that nonconformities and incidents were addressed, corrective actions were taken, and their effectiveness was evaluated |
| Continual improvement evidence | 10.3 | Evidence that the OH&S management system is continually improved |
If you’re three to six months from your planned Stage 1 audit → this is a useful table to work backward from. An auditor sampling your system will ask for evidence across these categories, and gaps here tend to be more damaging than gaps in the maintained documents above, because a missing record can’t be written retroactively without it looking exactly like what it is.
Quick-Reference: Maintain vs. Retain by Requirement Area
| Requirement Area | Maintain | Retain |
|---|---|---|
| Scope | ✓ | |
| OH&S Policy | ✓ | |
| Risk & Opportunity Methodology | ✓ | ✓ |
| Objectives | ✓ | ✓ |
| Legal & Other Requirements | ✓ | ✓ |
| Worker Consultation & Participation | ✓ | |
| Competence | ✓ | |
| Emergency Preparedness | ✓ | ✓ |
| Operational Controls | ✓ | ✓ |
| Internal Audit | ✓ | |
| Management Review | ✓ | |
| Corrective Action | ✓ |
Note: This matrix is a practical implementation guide, not a substitute for reviewing the specific documented-information requirements in each clause. Whether you maintain or retain information, and in what form, depends on the applicable requirement and your organization’s processes. One nuance worth flagging: Worker Consultation & Participation is checked under Maintain because Clause 5.4 requires a maintained process — the clause itself doesn’t mandate a specific retained record, though retaining evidence of consultation is standard practice and strongly recommended.
According to ISO.org, ISO 45001 was developed to give organizations a framework for managing occupational health and safety risk in a way that’s auditable and comparable across industries, not just a policy statement of intent — which is why the standard leans so heavily on retained evidence rather than stated commitment.

Do You Need a Formal OH&S Manual?
No. This is a common misconception carried over from older safety standards. ISO 45001 does not require a standalone OH&S manual as a mandatory document. The standard cares about whether the required documented information exists and is controlled — not whether it’s bound into a single manual.
That said, many organizations still choose to build one, because it’s a practical way to organize the required documents and make them easy to locate during an audit. If your team already thinks in terms of a manual from ISO 9001 or ISO 14001 work, keeping the format is often faster than fighting it. The manual itself just isn’t the requirement — the underlying documented information is.
Common Documentation Mistakes That Trigger Findings
Writing procedures nobody follows. A documented process that doesn’t match actual floor practice is worse than no document at all — it hands the auditor a direct comparison between what you say you do and what you actually do.
Treating documentation as a one-time project. Documented information under Clause 7.5.3 has to be controlled — reviewed, updated, and version-controlled over time. A policy written for certification and never touched again is a stale document waiting to be flagged.
No traceable link between the risk assessment and the objectives. Auditors increasingly check whether your OH&S objectives actually connect back to the hazards your risk assessment identified. If your objectives read like generic safety goals with no tie to your specific risk profile, that disconnect gets noticed.
Missing evidence of worker consultation. Clause 5.4 requires a maintained process for consulting and involving workers — it doesn’t itself spell out a specific retained record. In practice, though, auditors expect to see evidence that consultation actually happened: meeting notes, sign-off sheets, toolbox-talk logs. This is frequently missed in fast-moving fabrication and production environments, where consultation happens informally on the floor and never makes it into any retained record at all.
⚠️ If any of these sound familiar, address them before your audit window closes, not after a finding forces the issue. Most of them are a documentation fix, not an operational overhaul — but only if you catch them early enough to build the evidence trail.
If you’re running ISO 45001 alongside ISO 9001 or ISO 14001, our ISO 14001 Documentation Requirements guide covers the same maintain-versus-retain distinction from the environmental side, and the two documentation sets typically share more structure than teams expect.
Should You Wait for the ISO 45001 Revision Before Finalizing Your Documentation?
No. The revision of ISO 45001, expected to become the 2027 edition, is now at the Draft International Standard (DIS) stage, with the DIS ballot underway as of mid-2026. ISO 45001:2018 remains the current published, certifiable standard while that ballot runs. No final publication date is confirmed, and no transition timeline for existing 2018 certificate holders has been formally published.
Organizations pursuing certification today should continue building documentation to ISO 45001:2018. Even if the eventual revision introduces new requirements, a well-documented OH&S management system gets updated when a standard revises — it doesn’t get rebuilt from zero. Waiting on documentation you need for certification now, based on a revision that hasn’t reached final publication, puts your current certification timeline at risk for no protective benefit.
A team can understand ISO 45001 perfectly and still stumble at audit time because it assumed a document existed somewhere that nobody had actually built. Run the readiness checklist below before that assumption costs you an audit cycle →

ISO 45001 Documentation Readiness Checklist
✅ Scope statement is documented, dated, and matches your actual sites and activities
✅ OH&S policy is signed, communicated, and available to workers — not just filed
✅ Risk assessment methodology is documented and consistently applied, not ad hoc
✅ OH&S objectives trace back to specific identified risks
✅ Evidence of worker consultation and participation exists and is retained
✅ Legal and other requirements register is current, not built once and forgotten
✅ Internal audit program has actually run — not just been scheduled
✅ Management review meetings are documented, with dated minutes and action items
✅ Corrective action records show root cause analysis, not just “issue resolved”
Emergency response process has been tested, and the test is documented
If you checked fewer than eight of these, download the Manufacturing Compliance Checklist and work through the gaps before you schedule a certification audit — closing them after a finding costs far more time than closing them before one.
Frequently Asked Questions
Does ISO 45001 require a documented OH&S manual?
No. ISO 45001 requires specific documented information listed throughout the standard, but it does not mandate a single bound manual. Many organizations build one anyway for organizational convenience, but it is not a certification requirement.
Can I use my existing ISO 9001 or ISO 14001 documentation system for ISO 45001?
Largely, yes. ISO 45001 shares the same high-level structure as ISO 9001 and ISO 14001, which means your document control process, management review format, and internal audit program can typically be extended to cover OH&S rather than rebuilt separately. The content — your risk assessment methodology, your OH&S-specific objectives — still has to be built specifically for occupational health and safety.
How many documented procedures does ISO 45001 actually require by name?
ISO 45001 doesn’t specify a fixed number of documents by name. It requires documented information throughout multiple clauses — the tables above organize those requirements into the categories auditors most commonly request during certification. The exact number of individual procedures you write depends on your operation’s size and complexity — a 30-person fabrication shop and a 500-employee facility will document the same clauses very differently in scope and detail.
Is 3 months enough time to build ISO 45001 documentation from scratch?
For a small operation with an existing safety program to formalize, it’s tight but possible if documentation work starts immediately and runs in parallel with any remaining implementation gaps. For an organization building both the OH&S program and its documentation from zero, 3 months is an aggressive timeline that typically compresses the record-retention evidence auditors look for most closely.
What happens if I’m missing a required record during my audit?
If a requirement calls for retained documented information and the organization can’t provide the required evidence, the auditor may raise a nonconformity. The significance depends on the nature and extent of the gap and the certification body’s audit determination — missing evidence of an ongoing process, like consistent hazard identification records, tends to raise more concern than a single administrative gap, because it questions whether the process is actually operating.
Do digital record-keeping systems satisfy ISO 45001 documentation requirements?
Yes. ISO 45001 is explicit that documented information can exist in any format or medium, including electronic systems, as long as it’s controlled — meaning it’s identifiable, retrievable, protected from unauthorized changes, and available where it’s needed.
How long do I need to retain OH&S records?
ISO 45001 does not specify one universal retention period for every OH&S record. Retention periods can depend on applicable legal and other requirements, the organization’s own needs, and the type of documented information involved. Check applicable requirements directly through OSHA.gov and other relevant authorities rather than assuming a single retention period applies across all record types.
Does documentation quality affect certification cost?
Indirectly, yes. Weak documentation extends audit time, increases the likelihood of findings that require a follow-up audit, and can push out your certification timeline. Our ISO 45001 cost breakdown covers how audit findings translate into real cost.
📥 Free Resources
- ISO 9001 Roadmap — a step-by-step implementation guide for manufacturers building or improving a quality management system, useful if you’re documenting an integrated system alongside ISO 45001.
- Manufacturing Compliance Checklist — a practical compliance reference covering key ISO, OSHA, and quality documentation requirements for production environments.
- Supplier Quality Checklist — an evaluation tool for assessing supplier quality controls and flow-down compliance, useful when your OH&S documentation extends to contractor and supplier requirements.
Not Sure What to Do Next?
🔹 Still researching what ISO 45001 actually requires? Start with our ISO 45001 Certification Guide for the full picture before you commit to a documentation project.
🔹 Ready to start building your documentation? Download the Manufacturing Compliance Checklist and map your current files against it before you write a single new procedure.
🔹 Need to buy the standard itself? Get ISO 45001:2018 from ANSI Webstore — code CC2026 takes 5% off through December 31, 2026, and ANSI Webstore serves international buyers in multiple languages if you’re documenting across sites outside the US.
🔹 Want structured help closing documentation gaps? Compare ISO 45001 training through BSI Group against ISOQAR’s ISO 45001 course to see which fits your team’s timeline and budget.
Documentation is where most ISO 45001 certification timelines quietly slip. The Standards Navigator exists to make sure yours doesn’t — clear breakdowns of exactly what the standard requires, without the guesswork.
Struggling to Keep Your OH&S Records Audit-Ready?
Some operations build a safety program first and scramble to document it later. Others build the documentation structure alongside the program from day one — and walk into their Stage 1 audit without a single scramble.
The Standards Navigator covers ISO 45001 documentation, implementation timelines, and certification costs specifically for manufacturers who need the practical answer, not the theoretical one.
👉 Get updates on ISO 45001 documentation and audit-readiness content
👉 Be first to access new OH&S checklists and gap-assessment tools
Industrial Compliance. Clearly Explained.
