QUICK ANSWER
ISO 45001 requires a specific set of documented information — policy, risk registers, legal registers, operational controls, training records, audit and incident records — and Australian businesses need to layer their state or territory’s harmonised WHS Regulations on top of that. This is PSMG’s plain-English starting checklist, built from the standard’s own clause structure and Australian WHS law, not a substitute for a gap analysis against your specific operations.
Why this list matters
One of the most common reasons ISO 45001 audits stall isn’t a genuine safety failure — it’s missing or incomplete documentation the standard specifically requires. Below is a practical, plain-English rundown of what an auditor will expect to see, built directly from the standard’s own clause requirements and PSMG’s experience running these audits for Australian businesses. It’s a starting checklist, not a substitute for a proper gap analysis against your specific operations — a business with multiple sites or high-risk activities will typically need more than this baseline.
It’s also not a downloadable template. Every document on this list needs to reflect how your business actually runs its safety system, not a generic form with the right heading — which is exactly the gap a gap analysis and proper system build are for.
The Australian layer: harmonised WHS law
ISO 45001 is an international standard, but it doesn’t operate in a vacuum for Australian businesses. Most states and territories have adopted harmonised Work Health and Safety (WHS) laws based on the model WHS Act, WHS Regulations, and supporting Codes of Practice (Victoria and Western Australia run their own separate but broadly similar OHS frameworks). Your legal and other requirements register — one of the documents below — needs to name the specific WHS Regulator, Regulations, and Codes of Practice that actually apply to your operations and jurisdiction, not a generic reference to “workplace safety law.” This is one of the most common gaps PSMG finds in businesses that have built a system from an overseas or generic template.
Core policy and scope documents
- OH&S Policy — signed by top management, communicated to the workforce, and available to relevant interested parties.
- Scope of the OH&S management system — a clear statement of which sites, activities, and operations the system covers.
- OH&S objectives and plans to achieve them — measurable targets, not vague aspirations, with responsibility assigned.
Risk and legal compliance records
- Hazard identification and risk assessment records — a live, maintained register, not a one-off document from induction.
- Legal and other requirements register — the specific WHS Act, Regulations, and Codes of Practice that apply to your operations in your state or territory, kept current as legislation changes.
- Evaluation of compliance records — evidence you’ve actually checked yourself against that register, not just compiled it.
“A legal register that says ‘comply with workplace safety law’ isn’t a legal register — it’s a placeholder. Auditors expect your actual Regulator, Regulations, and Codes of Practice named.”
Operational control documents
- Procedures for identifying hazards and assessing risk.
- Operational control procedures for high-risk activities specific to your operations (e.g. working at height, confined spaces, plant and equipment, hazardous substances).
- Emergency preparedness and response procedures, including evidence they’ve been tested.
- Management of change procedure — how new equipment, processes, or organisational changes get risk-assessed before rollout, not after an incident.
Competence, training, and communication records
- Training needs analysis and training records demonstrating workers are competent for their role’s specific risks.
- Evidence of worker consultation and participation — genuinely two-way, not a one-way notice board (a specific requirement under Australian harmonised WHS law, not just the standard).
- Induction records for new workers, contractors, and visitors.
Performance and improvement records
- Internal audit programme and audit records — on a defined, regular cycle.
- Incident investigation records, including root-cause analysis, not just an incident log.
- Corrective action records — showing the root cause was addressed, and that the fix was verified as effective.
- Management review meeting minutes — regular, substantive reviews of the system’s performance by leadership, not a formality.
- Monitoring and measurement records relevant to your specific risk profile (e.g. inspection schedules, toolbox talk minutes, plant maintenance logs).
1 register, every jurisdiction
Your legal and other requirements register should name your actual WHS Regulator and applicable Codes of Practice — not a generic reference
A common gap worth flagging specifically
The most frequent shortfall we see isn’t a missing document category — it’s under-specified frequency. A toolbox talk procedure that doesn’t commit to how often talks happen, or an inspection schedule without a defined cadence, tends to read to an auditor (correctly) as a system that exists on paper but isn’t genuinely operating. Every item above needs a real, evidenced rhythm behind it, not just a template with the right heading.
Building this properly, not just ticking boxes
A documentation set that technically satisfies every item above but doesn’t reflect how your business actually operates will struggle at Stage 2 audit, when auditors interview staff and sample records against what’s written down. PSMG builds every document in this list from your actual operations, risk profile, and applicable state or territory WHS law — never from a generic template adapted after the fact — so what’s on paper matches what happens on site.
Want a structured self-assessment before committing to a full build? PSMG’s free ISO Certification Readiness Checklist walks through the same territory as a starting point — ask us for a copy.
View Work Health & Safety Pricing →
info@pspmg.com.au | 1300 810 127 | psmg.com.au