Why Clause 4.4 Is More Than a Tick Box
Clause 4.4 sits at the heart of every ISO management system. Whether you are auditing ISO 9001, ISO 14001, or ISO 45001, this clause requires the organisation to establish, implement, maintain, and continually improve its management system, including the processes needed and their interactions. On paper, that sounds straightforward. In practice, it is one of the clauses where auditors most commonly find either a superficial paper exercise or a genuinely embedded system.
On this page
The auditing clause 4.4 OHS system processes question is not simply whether a process map exists. It is whether the organisation actually understands how its processes connect, what inputs and outputs flow between them, who owns each process, and whether the system as a whole is functioning as intended. This article walks through exactly how to assess that, with practical guidance drawn from real audit scenarios.
What Clause 4.4 Actually Requires
Across ISO 9001, ISO 14001, and ISO 45001, Clause 4.4 uses consistent language rooted in the harmonised structure. The organisation must determine the processes needed for the management system and their application throughout the organisation. It must also determine the inputs required and outputs expected from each process, the sequence and interaction of those processes, the criteria and methods needed to ensure effective operation and control, the resources required, the responsibilities and accountabilities, the risks and opportunities, and how the processes will be evaluated and improved.
ISO 9001 goes slightly further with Clause 4.4.2, which requires the organisation to maintain documented information to support the operation of its processes and retain documented information to have confidence that processes are being carried out as planned. ISO 45001 places particular emphasis on worker participation in how processes are defined and managed, which shapes how you audit the OH&S system specifically.
The practical implication for auditors is that you are not just checking whether a list of processes exists. You are verifying that the organisation has genuinely thought through how its system operates as a connected whole, rather than a collection of isolated procedures.
Exemplar Global Recognised Training ProviderRTP No. 310970Starting the Assessment: Process Identification
What to ask before you arrive on site
Before the audit begins, request the organisation's process framework or process map. This might be a turtle diagram, a process interaction matrix, a flowchart, or a simple list. The format is less important than the content. You are looking for evidence that the organisation has identified the processes that make up its management system and understands how they relate to each other.
Common processes you would expect to see in an ISO 45001 system include hazard identification and risk assessment, legal and other requirements management, operational controls, emergency preparedness, incident investigation, internal audit, management review, and corrective action. The list will vary by industry and organisational size, but there should be a clear rationale for what is included and what is not.
If the organisation cannot produce a coherent process framework during document review, that is your first signal that Clause 4.4 may be more form than substance.
Checking the scope connection
Process identification must align with the scope defined under Clause 4.3. If the scope covers a specific site or set of activities, the processes identified should reflect that. An organisation that has defined a narrow scope but lists processes that extend well beyond it, or one that has a broad scope but has identified only a handful of processes, warrants closer examination. Defining the scope of your OH&S management system is covered in detail separately, but the audit of Clause 4.4 must always be read in the context of what the scope actually says.
Auditing Process Inputs and Outputs
One of the most revealing lines of questioning in a Clause 4.4 audit is around process inputs and outputs. This is where you find out whether the organisation understands its processes as a system or simply as a list of activities.
Take the hazard identification process as an example. A useful audit question might be: what triggers a hazard identification review, and what does it produce? The answer should describe something like a planned review cycle triggered by operational changes, new equipment, or incident data, producing an updated hazard register and risk assessment that feeds into the operational controls process and the objectives and targets process.
If the person you are interviewing describes hazard identification as something that happens when someone notices a problem, with no defined trigger, no structured output, and no connection to how controls are selected or reviewed, you are looking at a process that exists on paper but not in practice.
The same logic applies to every process in the system. Ask what comes in, what goes out, and where the output goes. If the answers are vague or inconsistent across different people in the organisation, that tells you something important about how well the system is actually understood.
Assessing Process Interactions
The interaction question is the hardest one to fake
Process interactions are where auditors separate genuine systems thinkers from organisations that have assembled a management system from templates. The standard requires that the organisation determine the sequence and interaction of processes. In an OH&S context, this means understanding how, for example, the legal register feeds into the hazard identification process, how risk assessment outputs drive operational controls, how incident data informs the corrective action process and feeds back into hazard identification, and how all of this is reviewed at management review.
A practical audit technique here is to follow a thread. Pick a recent incident or near miss and trace it through the system. Where was it reported? How was it investigated? What corrective actions were raised? Were those actions verified as effective? Did the incident trigger a review of the relevant hazard identification record? Did it result in any change to operational controls? Was it reported at management review?
If you can follow that thread coherently through the system, the process interactions are working. If the thread breaks at any point, you have found a gap in how the processes connect, which is exactly what Clause 4.4 is designed to prevent.
Using turtle diagrams in the audit
Turtle diagrams are a practical tool for auditing individual processes within the Clause 4.4 framework. They prompt you to examine the inputs, outputs, resources, competencies, methods, and performance measures for each process. If the organisation has prepared turtle diagrams for its key processes, review them for completeness and then verify them against what you observe on the ground. A turtle diagram that lists “trained personnel” as a resource but where the training records are incomplete, or where the person responsible for the process cannot describe the performance measures, is a document that does not reflect reality. Turtle diagrams in process audits are worth understanding in depth if this is a regular part of your audit work.
Criteria, Methods and Performance Measurement
Clause 4.4 requires the organisation to determine the criteria and methods needed to ensure effective operation and control of its processes. In plain terms, this means each process should have defined success criteria and a way of measuring whether those criteria are being met.
For an OH&S system, this might mean that the hazard identification process has a criterion that all new tasks are assessed before work begins, measured through a completion rate tracked by the safety team. The incident investigation process might have a criterion that all incidents are investigated within five working days, measured through the dates recorded in the corrective action register.
When auditing this, ask the process owner: how do you know this process is working? If the answer is a confident description of a specific measure and a recent result, you are in good shape. If the answer is a pause followed by a general statement about things running smoothly, you have found something worth recording as an observation or potential nonconformity.
The absence of performance measures for key processes is a common finding under Clause 4.4 and is often linked to broader weaknesses in the monitoring and measurement requirements of Clause 9.1. The two clauses reinforce each other, and a gap in one usually points to a gap in the other.
Resources, Responsibilities and Accountabilities
Each process must have defined resources and clear ownership. This is not just a documentation requirement. It is a practical test of whether the organisation has actually thought through what each process needs to function.
A common scenario in ISO 45001 audits is finding that the hazard identification process is nominally owned by the safety manager, but that the safety manager has no authority to stop work or mandate corrective actions, and that operational managers have no defined role in the process at all. The process exists, but it lacks the resources and authority structure to function effectively. That is a Clause 4.4 finding, but it also connects to Clause 5.1 leadership and commitment and Clause 5.3 roles and responsibilities.
When you find this kind of structural gap, document it carefully. Note the specific evidence: who you spoke to, what they said, what the documented process says, and where the gap lies. A well-written finding here will reference Clause 4.4 and note the specific process and the specific gap in resources or accountability, rather than making a general statement about unclear responsibilities.
Risks and Opportunities Within Processes
Clause 4.4 requires the organisation to address the risks and opportunities as determined in accordance with Clause 6.1 and to plan and implement appropriate actions to address them. This means that the risk and opportunity assessment process must be connected to how individual processes are designed and controlled.
In practice, this means asking whether the organisation has considered what could go wrong within each process, and what opportunities exist to improve process performance. For an OH&S system, this might mean that the emergency preparedness process has been assessed for the risk that drills are not conducted as planned, with a control in place to schedule and record drills, and an opportunity identified to use drill outcomes to improve the emergency response plan.
Many organisations treat Clause 6.1 as a separate exercise that produces a risk register, without connecting those risks back to how processes are designed. When you audit Clause 4.4, always ask whether the risks identified in the Clause 6.1 assessment have influenced how the relevant processes are structured and controlled. If the answer is no, or if the process owner is not aware of the relevant risks, that connection is missing.
Common Nonconformities Under Clause 4.4
After hundreds of audits across multiple standards and industries, the most common findings against Clause 4.4 fall into a predictable pattern. Understanding these patterns helps you focus your audit time where the real gaps are likely to be.
- Process maps that are not kept current. The organisation produced a process interaction diagram when it first implemented the system but has not updated it since. New processes have been added, old ones changed, and the map no longer reflects how the system actually works.
- Process owners who cannot describe their process. The documented process owner is a senior manager who delegates the work entirely to a team member. Neither person has a clear understanding of the process inputs, outputs, or performance measures.
- Missing performance criteria. Processes are described in terms of activities but without any defined measure of whether those activities are producing the intended outputs.
- Disconnected processes. The audit trail from one process to the next breaks down. Incident investigation outputs, for example, do not feed back into hazard identification records in any systematic way.
- Outsourced processes not included. The organisation has outsourced a significant process, such as contractor management or environmental monitoring, but has not included it in the process framework or defined how it is controlled and monitored.
That last point is particularly relevant under ISO 45001, where Clause 8.1.4 specifically addresses procurement and contractor management. If those processes are outsourced, they must still appear in the Clause 4.4 process framework with defined controls and monitoring arrangements.
Audit Techniques That Work Well for Clause 4.4
Process tracing
As described above, selecting a specific output, such as a corrective action, an incident report, or a training record, and tracing it through the system is one of the most effective techniques for assessing process interactions. It is concrete, evidence-based, and difficult for an auditee to deflect.
Cross-interviewing
Ask the same question about a process to different people in different roles. Ask the safety manager how the hazard identification process connects to operational controls. Then ask an operational supervisor the same question. If the answers are consistent, the process is understood. If they differ significantly, there is a gap in how the process is communicated and embedded.
Observation
Where possible, observe the process in action. Watch a toolbox talk, sit in on a hazard identification review, or observe how a near miss is reported and recorded. What you see will often differ from what is documented, and those differences are where your most valuable findings will come from. Observation skills for auditors on the floor are a discipline worth developing deliberately.
Document sampling
Pull a sample of process outputs and check them for completeness and consistency. If the hazard identification process is supposed to produce a reviewed and approved hazard register, check whether the records show evidence of review and approval. If the corrective action process is supposed to produce a root cause analysis, check whether the records contain one. The absence of expected outputs is direct evidence of process gaps.
Exemplar Global Recognised Training ProviderRTP No. 310970Writing the Finding
When you find a gap under Clause 4.4, write it with precision. State the requirement, describe the evidence of the gap, and reference the specific process involved. Avoid vague language like “the process approach is not fully implemented.” Instead, write something like: the organisation has not defined performance criteria or measurement methods for the incident investigation process, as required by Clause 4.4. Review of ten incident records from the past twelve months showed that seven contained no documented root cause analysis and no evidence that corrective actions were verified as effective.
That kind of finding is specific, evidence-based, and actionable. The organisation knows exactly what needs to be addressed and can demonstrate closure through concrete evidence. How to write nonconformities that hold up is worth reviewing if you want to sharpen this skill further.
Building Your Competence in Process-Based Auditing
Auditing Clause 4.4 well requires a genuine understanding of the process approach, not just familiarity with the clause text. It requires the ability to think in systems, to follow threads of evidence across multiple processes, and to ask questions that reveal how things actually work rather than how they are documented to work.
These skills develop with practice, but they also develop faster with structured training that is grounded in real audit scenarios rather than theory. At Audit Workshop, the ISO 45001 Internal Auditor and Lead Auditor courses cover process-based auditing in depth, including how to assess Clause 4.4 in practice, how to use tools like turtle diagrams and process tracing, and how to write findings that reflect genuine system gaps rather than documentation shortcomings. If you are building your auditing skills or preparing to conduct your first ISO 45001 audit, the training is designed to give you practical techniques you can use immediately.













