ISO 45001 audit prep: the 7 evidence gaps most programs share
We walk through the seven gaps the external auditor will find if you do not fix them first. Every gap has a Composer template that closes it.
QEHS safety desk
Safety practitioners on staff
Practising QEHS professionals who write how-to guides, regulatory breakdowns, and field-tested program playbooks.
12 min read
- Worker consultation and participation (clause 5.4) — consultation log missing timestamps and attendance.
- Legal and other requirements (6.1.3) — compliance register exists as a spreadsheet, not a live evaluation.
- Operational planning and control (8.1) — procedures referenced in documents but not executable as workflows.
- Emergency preparedness (8.2) — drill records present, but corrective actions from drills are not tracked.
- Monitoring, measurement, analysis (9.1) — leading indicators defined but not reported at management review.
- Internal audit (9.2) — audit plan exists, but scope coverage is not traceable across clauses.
- Management review (9.3) — minutes exist, but inputs/outputs are not mapped to the clause-required items.
Each of the seven above is a module-plus-report pattern. The fastest path is the Audits module paired with the clause-mapped lookup list we ship with the ISO 45001 template pack.
An ISO 45001:2018 external audit is a sample, not an exhaustive read; the auditor pulls evidence for a representative set of requirements and reads the management system through that sample. A gap in a sampled area is a finding; a gap in an unsampled area is a finding at the next audit. The seven gaps below are the seven the auditor reaches for first because they are the ones that show whether the system runs or performs, and they are the ones a platform closes with a module and a report rather than a memo.
Gap one, worker consultation and participation (clause 5.4). The standard asks for evidence that workers were consulted on hazard identification, risk assessment, and the definition of controls, and that participation is structured rather than symbolic. The finding is a consultation log without timestamps, without attendance, or without a link to the decision the consultation informed. The fix is a consultation record tied to the risk assessment it fed, with the attendees, the date, and the change that resulted — participation that produced a change is the participation the standard rewards.
Gap two, legal and other requirements (clause 6.1.3). The compliance register is the artifact, and the finding is a register that is a spreadsheet of citations rather than a live evaluation of status. The standard asks the organization to determine which requirements apply, to track changes, and to communicate them — a register that lists the regulation without recording the status and the owner is a list, not an evaluation. The fix is a compliance-obligations register that carries the requirement, the applicability decision, the owner, the status, and the next review date, evaluated on a schedule.
Gap three, operational planning and control (clause 8.1). The finding is a procedure referenced in the management-system documentation but not executable as a workflow — the procedure exists on paper and the work is done a different way on the floor. The standard asks for operational controls that are implemented and maintained, which means the control has to be the work, not a description of the work. The fix is a workflow the procedure lives inside: the procedure is the workflow, the workflow is the system of record, and the auditor reads the workflow executions instead of a procedure document.
Gap four, emergency preparedness and response (clause 8.2). The finding is drill records present but the corrective actions from drills untracked — the drill happened, the gaps were noted, and the gaps are still there at the next drill. The standard asks the organization to test the emergency response, to review the test, and to act on the review. The fix is a drill record that spawns CAPAs, with the CAPAs closed before the next drill is scheduled; a drill that produces no CAPAs is a drill that found nothing, which is the finding the auditor writes.
Gap five, monitoring, measurement, analysis, and performance evaluation (clause 9.1). The finding is leading indicators defined but not reported at the management review — the indicators exist in a side report and leadership never sees them. The standard asks the organization to determine what is monitored and to report the results, and the management review (9.3) is where the results land. The fix is a leading-indicator dashboard that is a standing input to the management review, not a separate artifact; the indicators that do not reach the review are the indicators that do not move the system.
Gap six, internal audit (clause 9.2). The finding is an audit plan that exists but whose scope coverage is not traceable across the clauses — the plan says everything is audited and the record shows the same easy areas every cycle. The standard asks for an audit programme that covers the whole system, with auditors independent of the area, and with results reported to leadership. The fix is an audit programme that maps every clause to an audit on a cycle, that rotates auditors across areas, and that reports the systemic findings rather than the individual nonconformities to the management review.
Gap seven, management review (clause 9.3). The finding is minutes that exist but whose inputs and outputs are not mapped to the items the standard requires — the meeting happened, the minutes are a narrative, and the required inputs (audit results, objective achievement, incident trends, corrective-action status, changes in context) are not all present. The standard asks the management review to take specific inputs and to produce specific outputs (decisions and actions), and the review that does not is the review that closes no loop. The fix is a management-review record structured against the 9.3.2 inputs and the 9.3.3 outputs, so the meeting is read against the standard, not against a template.
- Map the compliance-obligations register to the clause 6.1.3 requirements, with status and owner per obligation, evaluated on a schedule that the system enforces.
- Convert the high-risk procedures into workflows, so the clause 8.1 operational control is the workflow the work runs in, not a document the work ignores.
- Wire the emergency drill record to spawn CAPAs, and block the next drill scheduling until the prior drill CAPAs are closed — the clause 8.2 loop that closes itself.
- Stand up the leading-indicator dashboard as a standing management-review input, so the clause 9.1 indicators reach the 9.3 review by default, not by request.
- Schedule the internal audit programme against the clause map, rotate auditors across areas, and report the systemic findings to the management review.
- Structure the management-review record against the 9.3.2 inputs and 9.3.3 outputs, so the review is read against the standard, and every output is a decision with an owner and a due date.
The audit itself runs in two stages under the ISO 45001 certification scheme: a stage-one document review that reads the management system, and a stage-two on-site audit that reads the implementation. The seven gaps above are the gaps stage two finds, because stage one reads the documents and stage two reads whether the documents describe the work. A program that closes the seven before stage one gives the stage-two auditor a system that runs, and the audit becomes a confirmation rather than a discovery. For the standards background, see the ISO 45001 glossary entry and the ISO 45001 certification guide; for the audit-readiness pass, the audit management use case.
The certification cycle is the frame the seven gaps sit in, and a program that closes the seven once is a program that has to keep them closed. ISO 45001 certification runs on a three-year cycle: a stage-one and stage-two initial audit, then annual surveillance audits, then a recertification audit at the end of the cycle. The surveillance audit samples a subset of clauses each year; the recertification samples the whole. A gap that closes for the initial audit and reopens by the first surveillance is the gap that was closed by effort and not by system, and the auditor reads the reopening as a regression. The discipline is to close the seven as standing controls — workflows that run, registers that evaluate, reviews that take their inputs by default — so the surveillance auditor finds them closed because they are the work, not because someone prepared.
The certification body is the other decision, and it is the one the market reads. A body accredited by a recognized national accreditation body (ANAB in the United States, UKAS in the United Kingdom, and the equivalent elsewhere under the IAF Multilateral Recognition Arrangement) is a body whose certificates are accepted across borders; a body without that accreditation is a body whose certificate is a document, not a credential. The scope statement on the certificate is the part to read before issuing it: a scope that names the sites and activities the system covers is a scope a customer can rely on, and a scope that reads "all activities of the organization" is a scope that covers whatever the auditor did not exclude. The platform that holds the management-system evidence is the same platform that produces the scope statement at recertification, and the alignment between the two is the alignment the accreditation body checks.