- March 21, 2026
- Posted by: Sage Shield Safety Consultants
- Category: Blog
ISO 45001 Audit Checklist Singapore — Free Download (2026)
Last updated: April 2026. This checklist has been reviewed and expanded to reflect current Ministry of Manpower enforcement priorities and the latest ISO 45001:2018 audit expectations for Singapore businesses.
An ISO 45001 audit checklist is an essential tool for any Singapore business pursuing or maintaining ISO 45001:2018 certification. Whether you are preparing for an initial certification audit, a surveillance audit, or an internal review, having a structured checklist ensures that every requirement of the Occupational Health and Safety Management System (OHSMS) standard is addressed. In Singapore, where the Workplace Safety and Health Act imposes strict obligations on employers, an ISO 45001 audit checklist helps organisations demonstrate compliance, protect workers, and build a culture of continuous improvement.
This guide provides a complete, clause-by-clause ISO 45001 audit checklist tailored for Singapore companies, along with practical tips for each clause, the most common audit findings, a comparison with bizSAFE requirements, and how Sage Shield Safety Consultants can support your certification journey.
What Is ISO 45001:2018?
ISO 45001:2018 is the international standard for occupational health and safety management systems (OHSMS). It replaced OHSAS 18001 and provides a framework for organisations to proactively improve worker safety, reduce workplace risks, and create safer working conditions.
The standard follows the High-Level Structure (HLS) shared by other ISO management system standards such as ISO 9001 and ISO 14001, making it easier for companies to integrate multiple management systems. In Singapore, ISO 45001 certification is increasingly recognised as a benchmark for workplace safety excellence and aligns closely with requirements under the Workplace Safety and Health Act and the bizSAFE programme.
Key principles of ISO 45001 include:
- Leadership commitment and worker participation in OH&S decisions
- Systematic identification and control of workplace hazards
- Legal compliance with national and international safety regulations
- Continual improvement of OH&S performance through the Plan-Do-Check-Act (PDCA) cycle
Why You Need an ISO 45001 Audit Checklist
For Singapore businesses, having a comprehensive ISO 45001 audit checklist is not just good practice — it is a strategic necessity. Here is why:
Ministry of Manpower Compliance
The Ministry of Manpower enforces the Workplace Safety and Health Act and its subsidiary regulations. An ISO 45001 audit checklist helps you systematically verify that your OHSMS meets or exceeds these legal requirements, reducing the risk of enforcement action, Stop Work Orders, or penalties.
bizSAFE Alignment
Many Singapore companies pursue bizSAFE certification alongside ISO 45001. The two frameworks share common elements — risk assessment, management commitment, and safety implementation. Using an ISO 45001 audit checklist ensures your OHSMS covers the broader international standard while remaining aligned with bizSAFE Level 3 and above requirements.
Workplace Safety and Health Act Requirements
The Workplace Safety and Health Act places a duty of care on employers to take reasonably practicable measures to ensure the safety and health of workers. An ISO 45001 Singapore audit checklist translates these legal duties into specific, auditable actions that your organisation can track and verify.
Additional Benefits
- Reduces workplace injuries and incidents, lowering insurance premiums and lost-time costs
- Improves tender competitiveness — many government and MNC contracts require ISO 45001
- Demonstrates due diligence to regulators, clients, and stakeholders
- Provides a structured framework for internal audits and management reviews
- Supports integration with ISO 9001, ISO 14001, and other management systems
Complete ISO 45001 Audit Checklist — Clause by Clause
The following workplace safety audit checklist is organised by ISO 45001 clause. Use it as a guide during internal audits, gap analyses, or certification preparation. Each item should be verified with documented evidence.
Clause 4: Context of the Organisation
- ☐ Internal and external issues affecting the OHSMS have been identified and documented
- ☐ Needs and expectations of workers and other interested parties have been determined
- ☐ The scope of the OHSMS is defined, documented, and available to interested parties
- ☐ The scope addresses all activities, products, and services under the organisation’s control
- ☐ The OHSMS is established, implemented, maintained, and continually improved per ISO 45001
- ☐ Applicable legal and regulatory requirements (including the Workplace Safety and Health Act) are identified
Practical tip for Clause 4: Conduct a SWOT or PESTLE analysis to capture internal and external context. In Singapore, external issues commonly include Ministry of Manpower enforcement priorities, industry-specific WSH regulations (e.g., Factories Act subsidiary legislation), and contractor safety culture. Keep a living register of legal requirements — the WSH Act and its regulations are amended periodically, and your register must stay current. Auditors will test whether your scope boundaries are logical and whether any exclusions are justified.
Clause 5: Leadership & Worker Participation
- ☐ Top management demonstrates leadership and commitment to the OHSMS
- ☐ An OH&S policy is established, communicated, and available as documented information
- ☐ The OH&S policy includes commitments to eliminate hazards, reduce risks, and comply with legal requirements
- ☐ Roles, responsibilities, and authorities are assigned and communicated at all levels
- ☐ Workers and their representatives are consulted on OHSMS decisions that affect them
- ☐ Mechanisms for worker participation and consultation are established and documented
- ☐ Workers have access to relevant OH&S information without fear of reprisal
- ☐ Safety committees or worker representatives are in place as required by Singapore regulations
Practical tip for Clause 5: Auditors frequently look for evidence of genuine top-management engagement — not just a signed policy statement. Prepare minutes of management meetings that include OH&S agenda items, records of management walking the shop floor, and documented decisions made at the senior level. For worker participation, maintain a log of safety committee meetings with attendance sheets and action items. Under the Workplace Safety and Health Act, companies with 50 or more employees in certain industries are required to establish a Workplace Safety and Health Committee. Ensure your committee charter and meeting records are audit-ready.
Clause 6: Planning
- ☐ Hazard identification is systematic, proactive, and covers all routine and non-routine activities
- ☐ Risk assessment methodology is documented and consistently applied
- ☐ Opportunities to improve OH&S performance and the OHSMS are identified
- ☐ Legal and other requirements are identified, accessed, and kept up to date
- ☐ OH&S objectives are established at relevant functions and levels, and are measurable
- ☐ Plans to achieve OH&S objectives include what, who, when, and how progress is evaluated
- ☐ Actions to address risks and opportunities are planned and integrated into OHSMS processes
Practical tip for Clause 6: Your risk assessment methodology must be documented and consistently applied across all work activities — not just high-risk ones. Common gaps include failing to assess psychosocial risks (excessive workload, harassment, fatigue), ergonomic hazards, and risks from temporary or visiting workers. For objectives, use SMART criteria: specific, measurable, achievable, relevant, and time-bound. Examples include: reduce lost-time injury rate by 20% within 12 months, achieve 100% completion of toolbox meetings, or complete all planned internal audits by Q3.
Clause 7: Support
- ☐ Adequate resources (financial, human, technological) are provided for the OHSMS
- ☐ Competence requirements for roles affecting OH&S performance are determined
- ☐ Workers receive appropriate training, education, or experience to fulfil their OH&S roles
- ☐ Workers are aware of the OH&S policy, their contributions to OHSMS effectiveness, and implications of non-conformance
- ☐ Internal and external communication processes are established and documented
- ☐ Documented information required by ISO 45001 is created, updated, and controlled
- ☐ Document control ensures current versions are available and obsolete documents are prevented from unintended use
- ☐ Training records are maintained and competence is periodically re-evaluated
Practical tip for Clause 7: Prepare a competency matrix that maps each role to required OH&S competencies and the evidence of those competencies (certificates, records of on-the-job training, test results). In Singapore, certain roles require specific qualifications — for example, a registered Workplace Safety and Health Officer (WSHO) for higher-risk workplaces. Ensure all mandatory appointments are valid and that appointment letters are on file. For document control, implement a simple version-control system: each document should have a version number, revision date, and approval signature.
Clause 8: Operation
- ☐ Operational controls are implemented using the hierarchy of controls (eliminate, substitute, engineering, administrative, PPE)
- ☐ Management of change processes address new or modified processes, products, services, and work locations
- ☐ Procurement processes ensure outsourced activities and contractor operations conform to OH&S requirements
- ☐ Contractor OH&S performance is monitored and coordinated with the organisation’s OHSMS
- ☐ Emergency preparedness and response plans are established, tested, and reviewed
- ☐ Emergency drills are conducted at planned intervals and results are documented
- ☐ Permit-to-work systems are in place for high-risk activities (confined spaces, hot work, working at height)
- ☐ Risk assessments are reviewed and updated when changes occur or after incidents
Practical tip for Clause 8: The hierarchy of controls is a key audit focus. When controls are only at the PPE or administrative level, auditors will question why higher-order controls (engineering or elimination) were not feasible. Document your justification. For management of change, use a formal MOC form that triggers a risk assessment review before any significant change is implemented — this is a frequently cited gap. For contractors, go beyond just issuing a safety handbook: obtain their risk assessments, conduct safety inductions, and maintain records of contractor safety briefings and site assessments.
Clause 9: Performance Evaluation
- ☐ Monitoring, measurement, analysis, and evaluation processes are established for OH&S performance
- ☐ Compliance with legal and other requirements is periodically evaluated
- ☐ An internal audit programme is established with defined scope, frequency, and methods
- ☐ Internal auditors are competent, objective, and impartial
- ☐ Audit results are reported to relevant management and communicated to workers
- ☐ Management reviews are conducted at planned intervals covering all required inputs
- ☐ Management review outputs include decisions on continual improvement opportunities and resource needs
Practical tip for Clause 9: Your compliance evaluation must be a separate, documented exercise — not assumed from the absence of enforcement action. Review your legal register against actual practices at least annually, and document the results. For internal audits, ensure auditors do not audit their own work (impartiality requirement). If your team is small, consider cross-departmental auditing or bringing in an external consultant for the internal audit. Management review minutes must cover all ISO 45001 required inputs — prepare a standard agenda template to ensure nothing is missed.
Clause 10: Improvement
- ☐ Incidents and non-conformities are investigated to determine root causes
- ☐ Corrective actions are implemented in a timely manner and their effectiveness is verified
- ☐ Changes to the OHSMS are made as needed based on investigation findings
- ☐ Opportunities for continual improvement are identified and acted upon
- ☐ Worker feedback and participation data are used to drive improvements
- ☐ Trends in incident data, audit findings, and performance metrics are analysed and acted upon
Practical tip for Clause 10: Root cause analysis is a persistent weak point in Singapore audits. Train your team to use structured methods — the 5 Whys, fishbone (Ishikawa) diagrams, or Fault Tree Analysis — rather than defaulting to “worker carelessness” as the root cause. Corrective actions that address only behaviours without fixing systemic issues will result in recurring non-conformities. Maintain a corrective action register that tracks each finding from identification through root cause, action taken, target completion date, and effectiveness verification.
How to Use This ISO 45001 Audit Checklist
Follow these steps to get the most value from this OHSMS audit checklist:
- Conduct a gap analysis first. Before your certification audit, use this checklist to identify gaps between your current OHSMS and ISO 45001 requirements. Document each gap with the clause reference, current status, and required action.
- Assign responsibilities. For each checklist item, assign a responsible person or department. In Singapore, this typically involves the WSH Officer, HR, operations managers, and top management.
- Gather objective evidence. Auditors will ask for documented evidence — policies, procedures, records, minutes of meetings, training certificates, risk assessments, and incident reports. Prepare these in advance.
- Conduct internal audits. Use this checklist during internal safety audits to simulate the certification audit experience. Record findings as conformities, observations, or non-conformities.
- Hold a management review. Present audit findings to top management. Ensure decisions and actions are documented, resourced, and tracked to completion.
- Close gaps before the certification audit. Address all non-conformities and major observations. Verify that corrective actions are effective before inviting the certification body.
- Maintain and update. The ISO 45001 audit checklist is not a one-time exercise. Update it as regulations change, your operations evolve, or new hazards are identified.
Common ISO 45001 Audit Findings in Singapore
Based on our experience supporting over 500 Singapore companies through ISO certification, these are the five most common non-conformities found during ISO 45001 Singapore audits:
1. Incomplete Hazard Identification
Many organisations focus on obvious physical hazards but overlook psychosocial risks, ergonomic issues, or hazards associated with non-routine activities. Under the Workplace Safety and Health Act, employers must identify all reasonably foreseeable hazards — not just the obvious ones.
2. Lack of Worker Consultation Evidence
ISO 45001 places strong emphasis on worker participation. A common finding is that while companies claim to consult workers, they lack documented evidence — meeting minutes, feedback forms, safety committee records, or records of worker input into risk assessments.
3. Inadequate Management of Change
When processes, equipment, or work locations change, the OHSMS must be updated accordingly. Many Singapore companies fail to formally assess OH&S implications before implementing changes, leading to uncontrolled risks.
4. Weak Emergency Preparedness
While most companies have emergency plans, common gaps include infrequent drill testing, failure to review plans after drills or actual emergencies, and lack of coordination with external emergency services such as the Singapore Civil Defence Force.
5. Superficial Root Cause Analysis
When incidents or non-conformities occur, many organisations identify only the immediate cause rather than the underlying root cause. This leads to corrective actions that address symptoms rather than preventing recurrence. Robust methods such as the 5 Whys or fishbone diagrams are recommended.
ISO 45001 Audit Checklist vs bizSAFE Requirements
Many Singapore companies ask how ISO 45001 relates to the bizSAFE programme administered by the Workplace Safety and Health Council. While both frameworks aim to improve workplace safety, there are key differences in scope, depth, and recognition.
| Dimension | ISO 45001:2018 | bizSAFE (Levels 1–4) |
|---|---|---|
| Issuing body | International Organisation for Standardisation (ISO) — internationally recognised | Workplace Safety and Health Council (WSHC) — Singapore-specific |
| Scope | Full OHSMS covering all clauses 4–10; requires systematic management across entire organisation | Progressive framework from risk management (Level 3) through implementation (Level 4) to certification (Star) |
| Risk assessment | Clause 6: systematic hazard identification and risk assessment required for all activities | Level 3 requires Risk Management Programme (RMP) and WSH risk assessment |
| Management commitment | Clause 5: mandatory documented evidence of top management leadership and commitment | Level 1 requires CEO/top management to attend WSH workshop |
| Internal audit | Clause 9: mandatory internal audit programme with competent, impartial auditors | Required at Level 4 (WSHMS implementation); not mandated at Levels 1–3 |
| Third-party certification | Certification by accredited ISO certification body (e.g., Bureau Veritas, SGS, TUV) | bizSAFE Star requires third-party audit; Levels 1–4 are self-declared with WSHC validation |
| International recognition | Globally recognised — required by MNCs, international tenders, and supply chain partners | Primarily recognised in Singapore — preferred by local government and statutory boards |
| Worker participation | Clause 5: explicit requirement for worker consultation and participation with documented evidence | Encouraged but not as explicitly defined as in ISO 45001 |
| Best for | Companies tendering for MNC/international contracts, or integrating with ISO 9001/14001 | Companies starting their WSH journey or required to meet local government procurement requirements |
Can you achieve both? Yes — and many Singapore companies do. bizSAFE Level 4 and Star share significant overlap with ISO 45001 Clauses 4–10. A company that has achieved bizSAFE Level 3 has typically completed a risk assessment programme that satisfies ISO 45001 Clause 6 planning requirements. Building on this foundation with a full OHSMS documentation set and internal audit programme can lead to ISO 45001 certification with relatively modest additional effort. Sage Shield consultants specialise in this dual-pathway approach. Learn more about our ISO 45001 certification services.
How Sage Shield Can Help
Sage Shield Safety Consultants has helped over 500 companies in Singapore achieve and maintain ISO 45001 certification. Our experienced consultants provide end-to-end support tailored to your industry and organisational size.
Our ISO 45001 certification consultancy services include:
- Gap analysis and readiness assessment — identify exactly what your organisation needs to achieve certification
- OHSMS development and documentation — policies, procedures, risk assessments, and operational controls tailored to your operations
- Internal audit support — our certified auditors conduct thorough internal safety audits using comprehensive checklists like the one above
- Training and competency development — equip your team with the knowledge to maintain the OHSMS independently
- Certification audit preparation — mock audits and coaching to ensure you pass with confidence
- Ongoing maintenance and surveillance audit support — keep your certification current with annual reviews and updates
We also support integrated management system certification for companies pursuing ISO 9001, ISO 14001, and ISO 45001 together — reducing duplication and audit costs.
Get Expert Help With Your ISO 45001 Certification
Ready to prepare for your ISO 45001 audit? Our consultants will guide you through every step — from gap analysis to successful certification.
WhatsApp us: wa.me/6593859592
Call us: +65 8332 8220
Email: info@sageshield.com
Frequently Asked Questions About ISO 45001 Audits in Singapore
How long does an ISO 45001 certification audit take in Singapore?
For most small to medium-sized Singapore companies, the certification audit consists of two stages. Stage 1 (document review) typically takes one to two days and can be conducted remotely. Stage 2 (on-site audit) takes one to three days depending on the size of your organisation, the number of sites, and the complexity of your operations. Prior to the certification audit, you should allow three to six months for OHSMS implementation and at least one full cycle of internal audit and management review.
What is the difference between an internal audit and a certification audit under ISO 45001?
An internal audit is conducted by your own staff (or an external consultant acting on your behalf) to verify that your OHSMS conforms to ISO 45001 requirements and is effectively implemented. It is a mandatory element under Clause 9.2 of the standard. A certification audit is conducted by an independent, accredited certification body — such as Bureau Veritas, SGS, or TUV — whose auditors assess your OHSMS against the standard and determine whether to award or maintain your ISO 45001 certificate. Internal audits should be completed and corrective actions closed before you invite the certification body.
Does ISO 45001 replace the need for bizSAFE certification in Singapore?
No — ISO 45001 and bizSAFE serve different purposes and are not interchangeable for procurement requirements. Many government agencies and statutory boards in Singapore require bizSAFE Level 3 or above as a pre-qualification condition for contracts. ISO 45001 certification does not automatically satisfy this requirement. However, a company with ISO 45001 certification has typically met or exceeded the technical safety management requirements for bizSAFE Level 4 and Star. Sage Shield can help you pursue both certifications simultaneously to maximise market access.
How often do I need to conduct internal audits for ISO 45001?
ISO 45001 requires that internal audits be conducted at planned intervals — but the standard does not specify a minimum frequency. Best practice and the expectation of most certification bodies is at least one complete internal audit cycle per year, covering all clauses of the standard. Higher-risk operations or organisations with a history of non-conformities should conduct audits more frequently, or focus additional attention on high-risk areas between full audit cycles. Surveillance audits by the certification body occur annually, and a recertification audit is required every three years.
What are the most common reasons companies fail their ISO 45001 certification audit in Singapore?
The most frequent causes of certification audit failure in Singapore are: (1) incomplete or poorly documented hazard identification and risk assessment — particularly for non-routine activities and contractor work; (2) lack of documented evidence for worker consultation and participation; (3) no formal management of change process, leading to undocumented changes to operations or equipment; (4) internal audit records showing that auditors assessed their own work, violating the impartiality requirement; and (5) corrective actions that address symptoms rather than root causes, with no effectiveness verification. Companies that work with an experienced ISO 45001 consultant before their certification audit consistently achieve first-time certification.
