Standardsπ¦πΊπ³πΏ Australia + New ZealandUpdated 2026-05-11
What is an ISO 45001 internal audit programme (clause 9.2)?
Short answer
ISO 45001 clause 9.2 requires the organisation to plan, establish, implement and maintain an internal audit programme to determine whether the OH&S management system conforms to its requirements and is effectively implemented. The programme should be risk-based, periodic, and feed findings into the management review.
ISO 45001:2018 clause 9.2 requires the organisation to:
- Conduct internal audits at planned intervals to determine whether the OH&S management system conforms to ISO 45001 requirements and is effectively implemented and maintained.
- Plan, establish, implement and maintain an audit programme β including the frequency, methods, responsibilities, planning and reporting β that takes into consideration the importance of the processes, the changes affecting the organisation, and the results of previous audits.
- Define audit criteria and scope for each audit.
- Select auditors and conduct audits to ensure objectivity and impartiality.
- Ensure findings are reported to management.
- Take action to address NCs and continually improve.
- Retain documented information as evidence of the programme and audit results.
A practical audit programme typically includes:
- Annual programme β calendar of internal audits across processes and sites, with risk-based frequency.
- Audit checklist per process β questions, evidence to look at, sample selection.
- Lead auditor + audit team assignment.
- Findings register β NC, observation, opportunity for improvement.
- CAPA linkage β every NC becomes a CAPA in the corrective-action register (clause 10.2).
- Audit report PDF with management response.
RAE IQ's Internal Audit Programme module (feature #29, Business tier) covers all of this β AI-generated checklists per process area, finding capture, CAPA linkage and PDF audit reports.
Key terms
ISO 45001clause 9.2internal auditaudit programmelead auditorfindingsCAPA