Why Hazard Identification Is One of the Hardest Clauses to Audit Well
Hazard identification sits at the heart of ISO 45001. Clause 6.1.2.1 requires organisations to establish, implement, and maintain a process for identifying hazards on an ongoing basis. That word, ongoing, is the one most organisations get wrong. They build a hazard register during implementation, review it annually if they remember, and then treat it as a static document until the next certification audit rolls around.
On this page
When you audit hazard identification, your job is not to confirm that a register exists. Your job is to determine whether the process is genuinely continuous and whether it is picking up hazards before incidents occur. That is a very different audit conversation, and it requires a different set of questions, evidence, and observations.
This article walks through how to audit Clause 6.1.2.1 effectively, what good looks like in practice, and where the most common nonconformities appear. If you are an internal auditor, an HSE manager preparing for a certification audit, or a lead auditor looking to sharpen your approach to safety management systems, this is the practical guidance you need.
What Clause 6.1.2.1 Actually Requires
Before you can audit a clause well, you need to understand what it demands. ISO 45001 Clause 6.1.2.1 sets out a long list of scenarios that the hazard identification process must consider. These include:
- Routine and non-routine activities and situations
- Human factors, including how people interact with work processes, equipment, and each other
- Infrastructure, equipment, and materials
- Changes to the organisation, including planned changes and temporary changes
- Emergency situations
- People, including contractors, visitors, and workers in areas not under the organisation's direct control
- Past incidents, including near misses
- Situations occurring outside the workplace that can affect the health and safety of workers
That is a broad scope. Many organisations focus their hazard identification on routine physical tasks and miss the human factors, the change management triggers, and the non-routine work entirely. As an auditor, you are looking for evidence that the process genuinely covers all of these dimensions, not just the obvious ones.
For a deeper look at what the clause requires before you start planning your audit, the article on Hazard Identification Under Clause 6.1.2.1: What ISO 45001 Requires covers the standard's intent in plain language.
Exemplar Global Recognised Training ProviderRTP No. 310970The Core Audit Question: Is This Ongoing or Was It Done Once?
The single most important distinction you need to make as an auditor is whether hazard identification is a living process or a completed task. This is not always obvious from the documentation alone. A well-formatted hazard register with recent review dates can still represent a reactive, one-off exercise dressed up to look current.
Here is how you test it.
Ask About Triggers, Not Just Reviews
An ongoing hazard identification process is driven by triggers, not just scheduled reviews. Ask the HSE Manager or site supervisor: What would cause you to go back and update the hazard register outside of the annual review?
A mature system will have clear triggers documented and understood by workers. These typically include new equipment or plant, changes to work procedures, incidents and near misses, changes in legislation, new chemicals or materials, changes in the number or type of workers, and feedback from workers or contractors.
If the answer you get is vague, or if the person cannot name a recent example of a trigger prompting a hazard identification review, that is a significant concern. It tells you the process exists on paper but is not embedded in how the organisation actually operates.
Trace a Recent Change Through the System
One of the most effective audit techniques for this clause is to identify a recent change in the workplace and trace it through the hazard identification process. This could be a new piece of equipment, a change in shift patterns, a new contractor on site, or even a change in the layout of a work area.
Ask for evidence that the change triggered a hazard identification review. Look for dated records, updated risk assessments, revised safe work method statements, or toolbox talk records that correspond to the change. If none of these exist, the change management link to hazard identification has broken down.
This is a practical application of the audit trail concept. You are not just checking that a process is documented. You are verifying that it actually ran when it should have.
Interview Workers, Not Just Managers
Managers can describe the process. Workers will tell you whether it actually happens. Ask a few workers on the floor or at the worksite: How do you report a hazard you notice during your work? and When did you last report one?
A proactive hazard identification process depends on worker participation. ISO 45001 places significant emphasis on consultation and participation throughout the standard. If workers cannot describe a functional reporting pathway, or if they tell you that hazard reports “go nowhere,” the process is not working as intended, regardless of what the documented procedure says.
The article on Hazard Identification Methods That Auditors Trust outlines the specific methods you can probe during interviews and observations.
Auditing the Scope of Hazard Identification
Beyond asking whether the process is ongoing, you need to check whether it is comprehensive. Many organisations identify hazards well for their core activities and poorly for everything else. Here are the areas most likely to reveal gaps.
Non-Routine and Emergency Situations
Ask to see evidence that hazards have been identified for non-routine activities. These are tasks that do not happen every day, such as plant shutdowns, maintenance activities, working at heights for infrequent tasks, or emergency response scenarios.
A common finding is that the hazard register covers production activities in detail but has almost nothing for maintenance, cleaning, or emergency procedures. Ask specifically: How are hazards identified when a task is being done for the first time or infrequently? Look for permit-to-work systems, pre-task hazard assessments, or job safety analyses that capture non-routine work.
Human Factors
This is the area most organisations handle least well. Human factors include fatigue, workload, shift patterns, communication failures, and the way people interact with equipment and each other. Clause 6.1.2.1 explicitly requires these to be considered.
Ask whether the organisation has considered human factors in its hazard identification. Look for evidence in the hazard register or risk assessments. A register that lists only physical hazards like “moving machinery” or “chemical exposure” without any reference to human factors is incomplete.
Probing questions here might include: How does the organisation identify hazards related to fatigue or shift work? or Has the hazard identification process considered the risks that arise when workers are under pressure to meet production targets?
Contractors and Visitors
ISO 45001 requires hazard identification to consider people who are not direct employees, including contractors, visitors, and workers in areas the organisation does not directly control. This is a common gap in practice.
Ask how hazards are identified and communicated to contractors before they begin work. Look for site induction records, contractor hazard registers, or pre-work briefing documentation. If contractors are simply handed a generic induction pack without any site-specific hazard information, the process is not meeting the standard's intent.
Past Incidents and Near Misses
One of the clearest signals of a proactive hazard identification process is the use of incident data to update the hazard register. Ask for evidence that near misses, incidents, and dangerous occurrences have fed back into hazard identification.
Pull a sample of recent incident reports and check whether they resulted in a review of the relevant hazard register entry. If incidents are being investigated and corrective actions are being raised but the hazard register is not being updated, the feedback loop is broken.
This connects directly to Clause 10.2 of ISO 45001, which covers incident investigation and corrective action. The two processes should be linked, and your audit should verify that link.
What Good Evidence Looks Like
When you are satisfied that the process is both ongoing and comprehensive, you should be able to point to specific evidence. Here is what a well-functioning hazard identification process looks like in terms of documented information:
- A hazard register with dated entries showing when each hazard was identified or last reviewed
- Records of hazard identification activities tied to specific triggers such as change management records, incident reports, or pre-task assessments
- Toolbox talk records or safety meeting minutes that reference hazard identification discussions
- Worker hazard reports or near miss reports with evidence of follow-up
- Inspection records or workplace observation records that feed into the hazard register
- Risk assessments that are dated and linked to specific hazards in the register
The key is that the evidence should tell a story. You should be able to trace a hazard from its identification through to the risk assessment and the controls applied. If the documentation is fragmented or the trail goes cold, that is your finding.
Common Nonconformities in Hazard Identification Audits
Based on real audit experience across construction, manufacturing, mining services, and healthcare, these are the nonconformities that come up most often when auditing Clause 6.1.2.1.
The Hazard Register Has Not Been Updated Following a Significant Change
This is arguably the most common finding. A new machine is installed, a process is changed, or a new chemical is introduced, and the hazard register is not updated to reflect the new hazard. The change management process and the hazard identification process are not connected.
To write this as a nonconformity, you need to cite the specific change, the date it occurred, and the absence of any corresponding update to the hazard register or risk assessment. Be specific. A vague finding about the register being “not current” will not drive meaningful corrective action.
No Evidence of Worker Participation in Hazard Identification
The hazard register was developed by the HSE Manager with no documented involvement from workers. When workers are interviewed, they are unaware of the hazard identification process or cannot describe how to report a hazard. This is a nonconformity against both Clause 6.1.2.1 and Clause 5.4, which requires worker consultation and participation.
Non-Routine Activities Are Not Covered
The hazard register covers routine production activities only. There is no evidence of hazard identification for maintenance tasks, shutdown activities, or emergency scenarios. This is a clear gap against the explicit requirements of the clause.
Hazard Identification Is Treated as an Annual Event Only
The procedure states that the hazard register will be reviewed annually. There is no provision for interim reviews triggered by changes, incidents, or worker reports. In practice, the register has not been updated between annual reviews despite several incidents and a significant change to work processes. This demonstrates that the process is not ongoing.
Proactive vs Reactive: The Distinction That Matters Most
A truly proactive hazard identification process identifies hazards before they cause harm. A reactive process updates the register after something goes wrong. ISO 45001 is designed to drive proactive safety management, and your audit should assess which mode the organisation is actually operating in.
The clearest signal of proactive hazard identification is the ratio of worker-initiated hazard reports to incident-triggered updates. If most changes to the hazard register follow incidents rather than precede them, the process is reactive. If workers are regularly identifying and reporting hazards that are then assessed and controlled before any harm occurs, the process is proactive.
Ask for data. How many hazard reports were received in the last quarter? How many of those resulted in a change to the hazard register or a control measure? How does that compare to the number of incidents in the same period? This data tells you far more about the health of the hazard identification process than any document review alone.
For context on how auditors assess the full audit trail from hazard identification through to risk control, the article on Understanding the ISO 45001 Hazard Identification Audit Trail provides a useful end-to-end view of how the evidence connects.
Practical Audit Checklist for Clause 6.1.2.1
Use these prompts to structure your audit of hazard identification. They are not a substitute for professional judgement, but they will help you cover the ground systematically.
- Is there a documented procedure or process for hazard identification? Does it define triggers for review beyond the annual cycle?
- Does the hazard register cover routine and non-routine activities, including maintenance, shutdown, and emergency scenarios?
- Is there evidence that human factors have been considered in hazard identification?
- Are contractors and visitors included in the scope of hazard identification?
- Can you trace a recent workplace change through to an update in the hazard register or risk assessment?
- Do incident and near miss records show evidence of feeding back into hazard identification?
- Can workers describe the hazard reporting process and provide a recent example of using it?
- Are hazard reports tracked and closed out with documented outcomes?
- Is the hazard register dated, with evidence of when each entry was last reviewed?
- Does the organisation have data on the volume and nature of hazard reports over time?
Exemplar Global Recognised Training ProviderRTP No. 310970Linking Hazard Identification to the Broader OH&S System
Hazard identification does not exist in isolation. It feeds directly into risk assessment under Clause 6.1.2.2, which determines the level of risk associated with each identified hazard. It also connects to the hierarchy of controls under Clause 8.1.2, which guides how risks are eliminated or reduced. And it links to incident investigation under Clause 10.2, which should generate feedback into the hazard identification process.
When you audit hazard identification, keep these connections in mind. A finding in hazard identification often signals problems elsewhere in the system. Conversely, if you find strong incident investigation practices but a static hazard register, you have identified a broken link that is worth exploring.
Strong auditors audit systems, not just clauses. They look for the connections between processes and ask whether information flows in the right direction at the right time. Hazard identification is one of the best places in an ISO 45001 audit to test whether the system is genuinely integrated or just a collection of separate documents.
Building Auditor Competence in OH&S Management Systems
Auditing safety management systems well requires more than a checklist. It requires an understanding of how hazard identification connects to the rest of the OH&S framework, how to interview workers on the shop floor without making them defensive, and how to distinguish between a process that is working and one that looks good on paper.
If you are looking to build or formalise your competence in auditing ISO 45001, Audit Workshop offers practical ISO 45001 Internal Auditor and Lead Auditor training delivered by a certified lead auditor with hundreds of real external audits behind him. The training covers Clause 6.1.2.1 in depth, including how to plan your audit approach, what evidence to gather, and how to write findings that drive genuine improvement. You can explore the available courses at auditworkshop.com.













