Why the OH&S Policy Deserves More Than a Glance
Most auditors spend about three minutes on the OH&S policy. They pull it up, confirm it is signed, check the date, and move on. That approach misses the point entirely.
On this page
Clause 5.2 of ISO 45001 is not asking you to verify that a document exists. It is asking you to determine whether the organisation has made genuine, specific commitments to worker safety and whether those commitments are actually driving behaviour across the business. That is a much harder question to answer, and it requires a very different audit approach.
This article walks you through exactly how to audit an OH&S policy against Clause 5.2, from the document review through to the floor-level evidence you need to form a credible conclusion.
What Clause 5.2 Actually Requires
Before you can audit it, you need to know what the clause demands. Clause 5.2 of ISO 45001:2018 sets out several specific requirements for the OH&S policy. Top management must establish, implement and maintain it. The policy must:
- Include a commitment to provide safe and healthy working conditions for the prevention of work-related injury and ill health
- Provide a framework for setting OH&S objectives
- Include a commitment to fulfil legal requirements and other requirements
- Include a commitment to eliminate hazards and reduce OH&S risks
- Include a commitment to continual improvement of the OH&S management system
- Include a commitment to consultation and participation of workers
Beyond the content requirements, the standard also requires that the OH&S policy is available as documented information, is communicated within the organisation, is available to interested parties as appropriate, and is relevant to the organisation's purpose, size, and the nature of its OH&S risks.
That last point is critical. A policy that could belong to any organisation in any industry is not meeting the intent of the clause. If you audit a demolition contractor and their policy reads the same as a software firm's, that is a problem worth pursuing.
Exemplar Global Recognised Training ProviderRTP No. 310970Preparing for the Policy Audit
Review the Policy Before You Step on Site
Request the OH&S policy as part of your document review before the audit begins. Read it carefully against each of the six commitment areas listed in Clause 5.2. Create a simple checklist that maps each requirement to the specific policy language that addresses it.
Do not just tick boxes. Ask yourself whether the language is substantive or vague. A commitment to promote a culture of safety is not the same as a commitment to eliminate hazards and reduce risks. Warm language is not a substitute for the specific commitments the standard requires.
Also check the basics: Is the policy signed by top management? Is it dated? Has it been reviewed recently? A policy that has not been touched in five years in a business that has grown, changed scope, or taken on new risk profiles is worth questioning.
Understand the Organisation's Context First
You cannot judge whether the policy is relevant to the organisation's purpose and risks without first understanding what those risks are. Before you audit Clause 5.2, make sure you have a working understanding of the organisation's key hazards, the industries it operates in, and any significant incidents or near misses in recent history.
This context comes from your Clause 4 review. If you are auditing sequentially, you will have already looked at the context of the organisation, the interested parties, and the scope. Use that knowledge when you evaluate the policy.
Auditing the Policy Document Itself
Checking the Six Commitment Areas
Work through each required commitment systematically. Here is what to look for in each:
Commitment to safe and healthy working conditions: The policy should make an explicit commitment to providing conditions that prevent work-related injury and ill health. Generic statements about caring for employees are not sufficient. The language should be unambiguous.
Framework for setting OH&S objectives: The policy itself does not need to list the objectives, but it should make clear that objectives will be set. This is often addressed with a statement about establishing measurable targets or goals aligned with the policy commitments. When you later audit Clause 6.2, you will check whether the actual objectives connect back to this framework.
Commitment to fulfil legal requirements and other requirements: Look for explicit reference to legal compliance. Many policies include this, but some are vague about what other requirements means. In Australia, this includes state and territory WHS legislation, codes of practice, and any industry-specific requirements the organisation has agreed to meet.
Commitment to eliminate hazards and reduce OH&S risks: This is one of the stronger commitments in ISO 45001 compared to its predecessor OHSAS 18001. The policy should reflect the hierarchy of controls approach, or at minimum make clear that the organisation will work to eliminate hazards where practicable and reduce risks where elimination is not possible.
Commitment to continual improvement: This should appear explicitly. A vague reference to always striving to do better is thin. Look for language that ties continual improvement to the OH&S management system specifically.
Commitment to consultation and participation of workers: This is a distinctive feature of ISO 45001 and one that is frequently underdeveloped in policies. The policy should make a clear commitment to involving workers in safety decisions, not just informing them after the fact.
Assessing Relevance to the Organisation
Once you have confirmed the six commitments are present, step back and assess the policy as a whole. Does it reflect what this organisation actually does? A policy for a mining contractor should read differently from one for a healthcare provider. If the policy is entirely generic, that is worth raising, even if all six commitments are technically present.
Ask yourself: if you removed the company name and logo, could this policy belong to any business in any sector? If the answer is yes, the policy is probably not specific enough to be genuinely useful as a framework for the organisation's OH&S management.
Testing Communication and Availability
Is the Policy Communicated Within the Organisation?
The standard requires the policy to be communicated within the organisation. This is where many audits stop at a noticeboard photo or an intranet screenshot. That is not enough.
During your worker interviews, test whether the policy has actually reached people. You do not need to ask workers to recite the policy word for word. That is an unfair and unhelpful test. Instead, ask questions like:
- What does your organisation commit to when it comes to your safety at work?
- Has anyone talked to you about the organisation's safety commitments?
- Do you know where to find the OH&S policy if you needed to look at it?
If workers have never heard of the policy, cannot describe any of its commitments, and do not know where to find it, you have a communication failure. That is a nonconformity against the communication requirement in Clause 5.2, not just an observation.
Is It Available to Interested Parties?
The standard says the policy should be available to interested parties as appropriate. For most organisations, this means it should be accessible to contractors, visitors, and potentially customers or clients who have a legitimate interest in the organisation's safety commitments.
Check whether the policy is published on the organisation's website, included in contractor induction packs, or otherwise made accessible. Ask the relevant person how they would provide the policy to a contractor who requested it. If the answer is a blank stare, that is worth noting.
Tracing the Policy Into Practice
This is where the real audit work happens. A policy on paper means nothing if it does not connect to what the organisation actually does. Your job is to trace the policy commitments into the management system and onto the floor.
Does the Policy Drive the Objectives?
Clause 6.2 requires OH&S objectives to be consistent with the OH&S policy. When you audit the objectives, look for a clear line of sight back to the policy commitments. If the policy commits to eliminating hazards and reducing risks, are there objectives that reflect that commitment? If the policy commits to worker consultation, is there an objective or a programme that makes that real?
If the objectives bear no resemblance to the policy commitments, the policy is decorative. That is a systemic finding, not a minor paperwork issue.
Does Leadership Behaviour Reflect the Policy?
When you interview top management as part of your Clause 5.1 audit, use the policy as a reference point. Ask the CEO, the General Manager, or whoever holds the top management role:
- Can you walk me through what your OH&S policy commits the organisation to?
- How do you personally demonstrate the commitment to worker consultation that your policy describes?
- When did you last review the OH&S policy to make sure it still reflects your organisation's risks?
If top management cannot speak to the policy with any fluency, the commitment is not genuine. That is a leadership finding that connects Clause 5.1 and Clause 5.2.
For practical guidance on auditing leadership commitment more broadly, the article on auditing leadership commitment under Clause 5.1 of ISO 45001 covers the evidence you need to gather from management interviews.
Does the Policy Reflect Current Risks?
Ask when the policy was last reviewed and what triggered the review. A policy that has not been updated since the organisation introduced a new high-risk activity, took on a major contract, or experienced a significant incident is not being maintained as required.
Compare the policy language to the hazard register. If the hazard register identifies psychosocial risks, manual handling, or working at heights as significant risks, and the policy makes no reference to managing those kinds of risks, there is a disconnect worth exploring.
Common Nonconformities Against Clause 5.2
After auditing ISO 45001 across a wide range of industries, the following are the most frequent findings against Clause 5.2:
- Missing commitment to worker consultation and participation: This is the most common gap. Many organisations adapted their policy from OHSAS 18001 and never added the consultation commitment that ISO 45001 introduced.
- Policy not signed or not signed by the right person: The standard requires top management to establish the policy. A policy signed by the Safety Manager, rather than the CEO or equivalent, raises questions about genuine top-level ownership.
- Workers unaware of the policy: Communication is a requirement, not a recommendation. If workers cannot describe any aspect of the policy, the communication requirement has not been met.
- Policy not reviewed when the organisation changed: Significant changes in scope, workforce, or risk profile require the policy to be reviewed and updated as necessary.
- Generic policy with no connection to the organisation's actual risks: A policy that reads like a template and makes no reference to the organisation's specific context is not fulfilling the relevance requirement.
- Objectives not aligned with policy commitments: If the policy commits to eliminating hazards but all the objectives are about incident reporting rates, the framework function of the policy is not being fulfilled.
For more on what auditors commonly find across Clause 5 of ISO 45001, the article on frequent nonconformities in Clause 5 of ISO 45001 provides a useful reference.
Writing the Finding When Something Is Wrong
If you identify a gap against Clause 5.2, be precise about which requirement has not been met. The clause has multiple distinct requirements, and a vague finding like the OH&S policy does not meet Clause 5.2 is not useful to anyone.
A well-written nonconformity might read:
The OH&S policy does not include a commitment to consultation and participation of workers, as required by Clause 5.2(f) of ISO 45001:2018. During interviews with five operational workers across two departments, none could describe any mechanism through which they are consulted on safety matters, and the policy itself contains no reference to worker involvement in safety decisions.
That finding is specific, evidenced, and points directly to the clause requirement. It gives the organisation something concrete to address in their corrective action.
For guidance on structuring nonconformity reports so they actually drive change, the article on what the OH&S policy must contain under ISO 45001 Clause 5.2 is worth reviewing alongside this one.
Exemplar Global Recognised Training ProviderRTP No. 310970Pulling It All Together: A Practical Audit Sequence
Here is a practical sequence for auditing Clause 5.2 during an internal or external audit:
- Obtain the OH&S policy during document review and map it against the six commitment areas.
- Check the policy is signed by top management and has been reviewed within a reasonable period.
- During the management interview, ask top management to describe the policy commitments and how they are demonstrated in practice.
- During worker interviews, test whether the policy has been communicated and whether workers can access it.
- Check that the policy is available to contractors and other relevant interested parties.
- When auditing Clause 6.2, confirm the OH&S objectives are consistent with the policy commitments.
- When auditing Clause 5.4, confirm the consultation and participation commitment in the policy is backed by genuine mechanisms.
- Compare the policy to the hazard register and the organisation's context to assess whether it is relevant to the organisation's actual risks.
This sequence ensures you are not just ticking a box against Clause 5.2 in isolation. You are tracing the policy through the system and testing whether it is doing what it is supposed to do.
Building Your Competence in OH&S Auditing
Auditing an OH&S policy well requires more than knowing what the clause says. It requires the interview skills to test communication, the analytical ability to trace commitments through the system, and the confidence to raise findings when the policy is decorative rather than functional.
If you are developing your skills in auditing occupational health and safety management systems, Audit Workshop's ISO 45001 auditor training courses are built around exactly this kind of practical, clause-by-clause audit work. Whether you are completing your first internal auditor course or working toward lead auditor certification, the training is grounded in real audit scenarios rather than abstract theory. You can explore the available courses at auditworkshop.com.













