8 October 2026 by ASC Team
To become an ISO 45001 internal auditor you need three things: knowledge of ISO 45001:2018 and of the OH&S law your site works under; auditing skill as ISO 19011:2026 describes it, from planning and interviewing to sampling and writing findings; and audit experience, ideally first under the supervision of a competent auditor. ISO 45001 itself sets no qualification. Clause 7.2 asks for competence, and clause 9.2.2 c) asks for auditors selected so that audits are objective and impartial. An OH&S auditor also needs what a quality auditor can do without: the ability to see a hazard on the floor, to know the law behind it, and to act at once when someone is in danger.
What does an ISO 45001 internal auditor actually do?
Clause 9.2.1 of ISO 45001:2018 requires internal audits at planned intervals to provide information on whether the OH&S management system conforms to the organisation’s own requirements, including its policy and objectives, and to the standard, and whether it is effectively implemented and maintained. Clause 9.2.2 then sets out the programme:
- a) a programme including the frequency, methods, responsibilities, consultation, planning requirements and reporting, taking into consideration the importance of the processes concerned and the results of previous audits;
- b) audit criteria and scope defined for each audit;
- c) auditors selected and audits conducted to ensure objectivity and impartiality;
- d) results reported to relevant managers, and relevant results reported to workers, their representatives where they exist, and other relevant interested parties;
- e) action to address nonconformities and continually improve;
- f) documented information retained as evidence of the programme and the results.
Two of those are particular to ISO 45001. Consultation is part of the programme, and clause 5.4 d) 8) emphasises consulting non-managerial workers on it. And relevant results go back to the workers. An internal auditor who writes a report for the SHEQ manager alone has done half the job.
How is an internal audit different from an inspection?
People mix these up all the time, and the difference matters to how you behave on the day.
| Activity | Who does it | What it tests |
|---|---|---|
| Internal audit | Trained auditors selected for objectivity | Whether the system conforms and is effective, against defined criteria |
| Workplace inspection | Supervisors, area owners | Conditions on the floor against a checklist |
| Representative’s inspection | A health and safety representative, under section 18(1) of the OHS Act, at intervals agreed with the employer | The workplace, from the workers’ side |
| Evaluation of compliance | The owner of each legal register line, under clause 9.1.2 | Whether each legal requirement is met |
| Inspection by the Department of Employment and Labour | An inspector acting under sections 29 to 31 of the OHS Act | Compliance with the Act; can end in notices or a prohibition |
The internal audit sits beside the inspector, never in place of the inspector. The OHS Act applies whatever the audit concludes.
What competence does an OH&S internal auditor need?
The note to ISO 45001 clause 9.2.2 points to ISO 19011 for more information on auditing and the competence of auditors. The current edition is ISO 19011:2026, the fourth, published in May 2026. It is guidance, so it says “should” throughout. Its foreword lists two changes from 2018: expanded guidance on remote auditing methods, drawing on ISO/IEC TS 17012, and an expanded Annex A on remote auditing methods and virtual locations.
Clause 7.2.2 of ISO 19011:2026 lists the personal behaviours auditors should show: ethical, open-minded, diplomatic, observant, perceptive, versatile, determined, decisive, self-reliant, open to improvement, culturally sensitive and collaborative. Clause 7.2.3 covers knowledge and skills: audit principles, processes and methods, including planning, interviewing, observing, reviewing records and understanding sampling; the management system standards; the organisation and its context; and the applicable legal requirements. Auditors should have generic competence and a level of discipline-specific and sector-specific knowledge.
For OH&S, the discipline-specific part is heavy. I would expect an internal auditor on a food site to:
- recognise the main hazards on the floor: nip points, forklifts, confined spaces, chemicals, ammonia, noise, heat and cold, manual handling;
- know the hierarchy of controls in clause 8.1.2 and tell a guard from a sign;
- know the core of the OHS Act and the regulations on the legal register well enough to follow a legal trail, without playing inspector;
- interview a cleaner on the night shift in a way that produces evidence, in the worker’s language or through an interpreter who is not the worker’s supervisor;
- know what to do when they see someone in imminent danger.
What principles does an auditor work by?
ISO 19011:2026 clause 4 sets out seven principles: integrity, fair presentation, due professional care, confidentiality, independence, an evidence-based approach and a risk-based approach. In an OH&S audit the evidence-based approach is where most new auditors slip. ISO 19011:2026 clause 6.4.7 says: “Only information that can be subject to some degree of verification should be accepted as audit evidence.” A supervisor telling you the night shift drill happened is not evidence. The drill record, the names on it and a night shift worker who remembers it are.
Who can be an internal auditor on your site?
Anyone competent who is not auditing their own work. Clause 9.2.2 c) requires objectivity and impartiality. Annex A.9.2 of ISO 45001, which is informative and adds no requirements, says objectivity can be established by separating auditors’ roles from their normal assigned duties, or by using external people.
In practice that means a hygiene supervisor can audit the warehouse but not the hygiene team, and the SHEQ officer should not audit a legal register he maintains himself. Health and safety representatives can make good auditors of areas outside their own; they know the floor and the workers trust them. A section 16(2) assignee should not audit the area assigned to them.
What makes an OH&S audit different from a quality audit?
The walk, the law, the worker and the danger.
- The walk. You audit with the HIRA in your hand and look for the hazard the register missed, the control that is on paper and not on the floor, and the control that sits too low on the hierarchy.
- The shift. If the hygiene team works from 22h00 to 05h00, an audit between 08h00 and 16h00 audits their paperwork. ISO 19011:2026 Annex A.17 b) advises that interviews should normally be conducted during the interviewees’ defined working hours and, where practical, at their normal workplace.
- The law. A legal finding is written against the clause of ISO 45001 that should have caught it, usually 6.1.3 or 9.1.2, with the legal provision cited correctly.
- The danger. If you see an imminent danger, you act and report it at once, not at the closing meeting.
On the Kempton Park ready meals plant we use as the case in our courses, the first internal audit programme starts in July 2027 and the simulated audits in the workshop are of the night hygiene team and of contractor management. The case is a training scenario built from real audit, inspection and incident patterns; no real company is named.
What does a new auditor usually get wrong?
Three things, in my experience. First, auditing the documents and not the work: the procedure is fine, the permit file is tidy, and nobody went to the isolator. Second, accepting what people say. “We drill every shift” is a claim until you see the night shift drill record and talk to someone who was there. Third, findings that cannot be closed: three issues bundled into one, or a statement that repeats the requirement without saying what was wrong. A nonconformity needs the requirement, the evidence with the record and its date, and a statement of the gap that a stranger could use to find it again. Write it so the process owner can act on it the same week.
How do you get there?
ISO 19011:2026 clause 7.2.4 says auditor competence can be acquired through a combination of training programmes covering generic auditor knowledge and skills, relevant work experience, education and experience in the specific discipline and sector, and audit experience under the supervision of a competent auditor. A sensible route on a South African site:
- Learn the standard. If ISO 45001 is new to you, start with the requirements and the law.
- Take an internal auditor course built on ISO 45001 clause 9.2 and ISO 19011:2026.
- Audit two or three times alongside an experienced auditor, then lead an audit with them watching.
- Have the programme manager evaluate you, as ISO 19011:2026 clause 7 suggests, and record the result.
- Keep auditing. Clause 7.6 says auditors should maintain competence through regular participation in audits and continual professional development.
Frequently asked questions
Is an internal auditor course the same as a lead auditor course?
No. An internal auditor audits their own organisation’s system under clause 9.2. Certification body auditors work under their body’s own competence requirements; that is a different route.
Do I need to be a safety officer to audit OH&S?
No. You need competence in auditing and enough OH&S knowledge to recognise hazards, controls and legal requirements. Many good OH&S auditors come from production, engineering or quality.
Can a quality auditor audit ISO 45001 too?
Yes, with the OH&S knowledge added. The shared clauses audit the same way. Worker participation, hazard identification, the hierarchy of controls, emergencies and the law need their own preparation.
Does ISO 19011:2026 change how we audit?
The main changes from 2018 expand the guidance on remote auditing methods and virtual locations. In OH&S, the floor walk and the worker interview rarely work remotely; decide in the plan what can and cannot.
How many internal auditors does a site need?
Enough that nobody audits their own work and every area, including the night shift, is covered at the planned frequency.
What if I find something illegal during an audit?
Write the finding against the clause that should have caught it, cite the provision correctly, and where people are in danger act at once. Do not issue instructions as if you were an inspector.
Which ASC course trains ISO 45001 internal auditors?
This guide is drawn from ISO 45001:2018 Internal Auditor, FS63, built on ISO 45001:2018 clause 9.2 and ISO 19011:2026 by clause.
R3 850, a limited period special (normally R4 670), prices in rand with no VAT added. About 14 hours, self paced, lifetime access.
- The principles, the auditor’s competence and what makes an OH&S audit different.
- Auditing every clause from 4 to 10 with the HIRA, legal, training, permit and incident trails.
- A risk based programme with consultation and reporting to workers, and two simulated audits on a case site.
- Two practice exercises and a three part assessment, all at 70 percent. It is not a lead auditor course.
New to the standard? Start with Introduction to ISO 45001:2018, R1 195.
Enrol now and learn to audit it. See all eight courses at ISO 45001 training, or ask about training your audit team on WhatsApp ASC.
Related guides: ISO 45001 internal audit checklist: questions and evidence clause by clause and What is ISO 45001?
Sources
- ISO 45001:2018, Occupational health and safety management systems: Requirements with guidance for use (ISO)
- ISO 19011:2026, Guidelines for auditing management systems (ISO)
- Occupational Health and Safety Act 85 of 1993, and the regulations made under it
ISO 45001 and ISO 19011 are copyright and are not reproduced here. ASC is not affiliated with ISO. Last updated 8 October 2026.