Guide · ISO 45001 · 3 September 2026
The ISO 45001 Audit: Stage 1, Stage 2, and the Surveillance
The ISO 45001 audit is the stage 1 and the stage 2 — the document review and the on-site check. The stage 1 is the readiness; the stage 2 is the certification. The surveillance is the year one and the year two, and the recertification is the year three. This guide is the audit in working form: the stage 1, the stage 2, the surveillance, the recertification, and the evidence that passes.

The audit: the stage 1 and the stage 2
The ISO 45001 audit is the two stages. The stage 1 is the document review — the auditor reads the system: the manual, the policy, the risk register, the legal register, the procedure — and checks the readiness. The stage 1 is the question: is the system there? The document is the clause, and the clause is the evidence.
The stage 2 is the on-site — the auditor walks the site, interviews the worker, and checks the evidence the document claims. The stage 2 is the question: is the system working? The two stages are the initial certification — the year zero, before the surveillance and the recertification.
The stage 1: the document review
The stage 1 is the readiness. The auditor reads the manual (the scope, the system, the clause map), the policy (the commitment, the statement, the signed), the risk register (the hazard, the likelihood, the consequence, the control, the clause 6.1), the legal register (the compliance obligation, the clause 6.1.3), and the procedure (the process, the who, the when).
The auditor checks the objective (the clause 6.2, the measurable), the training matrix (the clause 7.2), the emergency plan (the clause 8.2), and the previous internal audit (the clause 9.2). The stage 1 finding is the gap — the document that is missing, out of date, or not the clause. The gap has to be closed before the stage 2 is confirmed.
The stage 2: the on-site, the evidence
The stage 2 is the evidence. The auditor walks the site — the risk assessment on the floor (the clause 6.1), the permit to work (the clause 8.2, the signed), the training record (the clause 7.2), the near-miss log (the clause 10.2, the leading indicator). The auditor interviews the worker — the awareness (the clause 7.3) and the consultation (the clause 5.4).
The evidence is the practice, not the document: the risk assessment that matches the walkover, the permit that is the signed one, the worker who can say the policy. The finding of the stage 2 is the conformance, the minor, or the major — and the major has to be closed before the certificate is issued.
The surveillance: the year one, the year two
The surveillance is the year one and the year two — the check that the system is still working. The surveillance audit is shorter than the stage 2: the spot-check, the clause that has moved, not the full system. The surveillance checks the management review (the clause 9.3, the annual), the internal audit (the clause 9.2, the programme), the objective (the progress), the nonconformity (the closed), and the change (the re-assessment).
The site that keeps the evidence current between the audit passes the surveillance without the pain. The site that lets the system sleep is the site that finds the gap at the surveillance — and the gap at the surveillance is the gap at the recertification.
The recertification: the year three
The recertification is the year three — the full audit again: the stage 1 and the stage 2, and the new certificate. The certificate is three years: the surveillance in the year one and the year two, and the recertification in the year three. The cycle repeats every three years.
The recertification checks the system is still the system: the clause that is updated, the evidence that is current, the objective that is met, the nonconformity that is closed. The site that keeps the system alive passes the recertification — and the certificate continues.

ISO 45001 Internal Audit: Who Does It, and How Often
The internal audit runs on the audit programme, at least annually, and the auditor is the competent and the independent one — independent of the area audited, and competent on the ISO 19011 principles (the impartiality, the evidence-based conclusion, the audit programme). The internal audit is the best friend of the stage 2: the finding that is closed before the certification body arrives is the finding that is not a nonconformity. The internal auditor who runs the audit holds the ISO 45001 internal auditor certificate (or the IAS 19011), and the lead auditor who runs it for the certification body holds the lead auditor certificate — the difference is on the Lead Auditor guide on this page.
Need the sign-off, not just the guide?
The guide is the preparation; the sign-off is the professional. For the ISO 45001 implementation and audits, the RIDDOR and CDM work, the statutory assessments and the training that comes with them, ask Muhammad Umer — 8+ years across Iraq, KSA and Pakistan, and the programme runs through umer-hse.pro. One message gets the written scope.
Common questions
The ISO 45001 Audit — answered
What is an ISO 45001 audit?
The external audit by the certification body: the stage 1 (the document review, the readiness) and the stage 2 (the on-site, the evidence), then the surveillance (the year one, the year two) and the recertification (the year three). The internal audit (the clause 9.2) runs inside the system; the external audit is the certification.
What is the difference between stage 1 and stage 2 in ISO 45001?
The stage 1 is the document review — the auditor reads the system (the manual, the policy, the risk register, the legal register, the procedure) and checks the readiness. The stage 2 is the on-site — the auditor walks the site, interviews the worker, and checks the evidence (the risk assessment, the permit, the training, the near-miss log). The stage 1 asks: is the system there? The stage 2 asks: is the system working?
How often is the ISO 45001 audit?
The stage 1 and the stage 2 are the initial certification (the year zero). The surveillance is the year one and the year two (the shorter, the spot-check). The recertification is the year three (the full audit again, the new certificate). The certificate is three years, and the cycle repeats.
What evidence does the ISO 45001 auditor check?
The practice, not the document: the risk assessment that matches the walkover, the permit that is the signed one, the training that is the record, the near-miss that is the log, the management review that is the minute, the worker who is consulted. The evidence runs the clause by the clause — the clause 6.1, the clause 8.2, the clause 7.2, the clause 10.2, the clause 9.3.
What is the ISO 45001 surveillance audit?
The year one and the year two check that the system is still working: the management review (the annual), the internal audit (the programme), the objective (the progress), the nonconformity (the closed), the change (the re-assessment). The surveillance is the shorter, the spot-check — the clause that has moved, not the full system.
What happens if you fail the ISO 45001 audit?
The nonconformity: the major (the system that is not working, the clause that is missing) and the minor (the gap, the isolated). The site has the corrective action — the root cause, the action, and the verification before the re-audit. The site that closes the nonconformity is certified; the site that does not is not. The re-audit checks that the corrective action is effective.
What is the ISO 45001 management review?
The clause 9.3: the top management reviews the system — the objective, the risk, the nonconformity, the internal audit, the change, and the resource. The management review is the annual, and the minute is the evidence. The review is where the top management is visible — the auditor checks it first.
Keep reading
Related guides
ISO 45001 Audit Preparation: the 90-Day Plan That Passes
ISO 45001 audit preparation: the 90-day plan
ISO 45001 · 7 September 2026ISO 45001 Certification: the Process, Step by Step
The ISO 45001 certification process, step by step: the gap analysis, the system, the internal audit, the stage
ISO 45001 · 1 September 2026ISO 45001 Explained: the Clauses, the Logic, the System
ISO 45001 explained: the occupational health and safety management system
THE HEALTH AND SAFETY is an education and knowledge network. The guides are free and open; the professional assessments and the training run through umer-hse.pro.
Safety disclaimer
The guides on this site are practical guidance, built to the UK baseline with the US equivalents named in the text. They do not replace a competent person assessment for high-risk work, a statutory assessment, or the advice of your insurer. Where a duty has legal force — the RIDDOR report, the CDM plan, the ISO 45001 system — the responsible person or the responsible owner carries it. Read the guide as the preparation, and take the sign-off from the competent person.
