Exemplar Global Certified Courses from USD 99. Ending Soon!

Common Nonconformities Against Clause 4 of ISO 45001

AW

Team @ Audit Workshop

14 min read
Common Nonconformities Against Clause 4 of ISO 45001

Clause 4 of ISO 45001 is the foundation of the entire occupational health and safety management system. It covers organisational context, interested parties, scope, and the OH&S management system itself. Despite being foundational, it consistently produces nonconformities during both internal audits and certification audits. Understanding the common nonconformities against Clause 4 of ISO 45001 is essential for any quality or safety professional responsible for maintaining certification or preparing for an audit.

This article walks through the most frequently raised nonconformities under each subclause, explains why they occur, and gives you practical guidance on how to avoid them. The examples come from real audit experience across Australian workplaces, construction sites, manufacturing facilities, and service organisations.

Why Clause 4 Nonconformities Are More Common Than You Might Expect

Many organisations treat Clause 4 as a one-time setup exercise. They complete a context analysis during implementation, document it somewhere, and then move on. The problem is that ISO 45001 does not treat context as a static document. It expects the organisation to maintain and update its understanding as internal and external factors change.

Auditors who approach Clause 4 with the right questions quickly discover that context documents are often outdated, interested parties lists are incomplete, scope statements are vague, and the processes that make up the OH&S management system have not been adequately defined. These are not minor paperwork issues. They are systemic gaps that affect how the entire system functions.

For a deeper look at how auditors approach this clause in practice, see How to Audit Organisational Context Under ISO 45001 Clause 4.1.

Clause 4.1: Understanding the Organisation and Its Context

Clause 4.1 requires the organisation to determine external and internal issues that are relevant to its purpose and that affect its ability to achieve the intended outcomes of the OH&S management system.

Nonconformity 1: Context Analysis Completed Once and Never Reviewed

This is the most common finding under Clause 4.1. An organisation completes a SWOT analysis or a context register during initial certification and never revisits it. The document might reference a business structure that no longer exists, a regulatory environment that has since changed, or risks that have already been addressed.

ISO 45001 does not specify a review frequency, but it does require the organisation to monitor and review information about these external and internal issues. Auditors will ask when the context was last reviewed and what triggered that review. If the answer is “we set it up three years ago and haven't looked at it since,” that is a nonconformity waiting to happen.

What to do: Link your context review to the management review cycle. At minimum, review the context register annually and document the outcome, even if nothing has changed. If something significant has changed, such as a new site, a change in legislation, or a major workforce restructure, update the register and record who made the decision and when.

Nonconformity 2: External Issues Are Superficial or Generic

Many context registers list generic external issues such as “economic conditions” or “regulatory requirements” without any specificity. When an auditor asks how these issues affect the OH&S management system, the auditee cannot explain the connection.

ISO 45001 is an OH&S standard. The external issues need to be relevant to occupational health and safety. That means identifying things like changes to the Work Health and Safety Act, emerging psychosocial risks, industry-specific hazard trends, or climate-related impacts on outdoor workers. Generic lists that could apply to any organisation in any industry do not demonstrate genuine understanding.

What to do: For each external issue listed, document how it relates to the OH&S management system and what the organisation is doing in response. If you cannot explain the link, the issue probably should not be on the list, or you need to think harder about what it means for your workers.

Nonconformity 3: Internal Issues Ignore Worker-Related Factors

Internal issues under ISO 45001 should include factors like workforce demographics, worker health and wellbeing trends, organisational culture, leadership capability in safety, and the organisation's history of incidents. Organisations often focus only on structural issues like governance, resources, and processes, and miss the human factors that are central to an OH&S system.

What to do: Review your internal issues register and ask whether it reflects the realities of your workforce. If you have an ageing workforce, high contractor turnover, or a history of manual handling injuries, those should be captured as internal issues influencing the system.

Clause 4.2: Understanding the Needs and Expectations of Workers and Other Interested Parties

Clause 4.2 is where ISO 45001 diverges most clearly from ISO 9001 and ISO 14001. Workers are explicitly identified as the primary interested party, and the standard requires the organisation to understand their needs and expectations in a way that goes beyond simply consulting them occasionally.

Nonconformity 4: Workers Not Identified as the Primary Interested Party

Some organisations produce an interested parties register that lists customers, regulators, shareholders, and community groups, but buries workers somewhere in the middle or treats them the same as any other stakeholder. ISO 45001 Clause 4.2 specifically calls out workers and their representatives as the central interested party. Auditors expect to see this reflected in both the register and in how the organisation actually operates.

For more on how auditors assess this specific issue, see Auditing Clause 4.2: Are Workers Treated as the Primary Interested Party?.

What to do: Structure your interested parties register so that workers are clearly identified as the primary group. Document their needs and expectations in specific terms. This includes things like the right to a safe workplace, the right to refuse unsafe work, access to information about hazards, and the right to participate in safety decisions.

Nonconformity 5: Needs and Expectations Not Linked to Legal Obligations

Clause 4.2 requires the organisation to determine which of the needs and expectations of interested parties are, or could become, legal requirements or other requirements. Many organisations list the needs and expectations of interested parties without identifying which ones are legally binding.

For example, a worker's expectation to be consulted on hazard identification is not just a preference. Under Australian WHS legislation, it is a legal obligation. Failing to make this connection means the organisation is not properly integrating its legal compliance obligations into its understanding of interested parties.

What to do: For each interested party and each identified need or expectation, add a column to your register that flags whether this is a legal requirement, a contractual obligation, or a voluntary commitment. This directly supports your compliance obligations register under Clause 6.1.3.

Nonconformity 6: Interested Parties Register Is Not Reviewed or Updated

Like the context register, interested parties registers are often created during implementation and left unchanged. Organisations change. Contractors come and go. Regulatory requirements evolve. Community expectations shift. If the register has not been reviewed in two or more years, an auditor will question whether it still reflects reality.

What to do: Review the interested parties register at least annually, and record the review. If a significant change occurs, such as a new major contractor or a change in legislation affecting workers, update the register and note what triggered the change.

Clause 4.3: Determining the Scope of the OH&S Management System

The scope defines what the OH&S management system covers. It sounds straightforward, but auditors consistently find scope statements that are either too vague to be meaningful or that do not align with the organisation's actual operations.

Nonconformity 7: Scope Statement Is Too Vague

A scope statement that says something like “all activities of the organisation” without specifying locations, activities, or workers covered is not sufficient. ISO 45001 Clause 4.3 requires the scope to be determined considering the external and internal issues from Clause 4.1 and the requirements of interested parties from Clause 4.2. The scope should also consider what work activities are performed, where, and by whom.

What to do: Write a scope statement that specifies the physical locations covered, the types of work activities included, the categories of workers covered (including contractors and visitors where relevant), and any exclusions with justification. The scope should be documented as documented information.

Nonconformity 8: Scope Excludes Activities That Should Be Included

Some organisations attempt to exclude high-risk activities from the scope, either to simplify the system or to avoid scrutiny. Common examples include excluding remote workers, excluding contractor activities, or excluding certain worksites from the scope without adequate justification.

ISO 45001 Clause 4.3 is clear that the organisation cannot exclude activities, products, or services that could affect the organisation's OH&S performance or its ability to fulfil its compliance obligations. If the exclusion cannot be justified, it is a nonconformity.

What to do: Review your scope against all of your actual work activities. If there are workers performing tasks that carry OH&S risks, those activities need to be within scope. Excluding them to make the system simpler is not a valid justification.

Nonconformity 9: Scope Has Not Been Reviewed Since Certification

Organisations grow. They open new sites, take on new types of work, or restructure. If the scope was defined during initial certification and has not been updated to reflect these changes, there is a gap between what the certificate covers and what the organisation actually does.

Auditors check this by comparing the scope statement against the actual operations they observe during the audit. If they find activities or locations that are clearly outside the documented scope, they will raise a nonconformity.

What to do: Include scope review as a standing agenda item in your management review. Whenever the organisation takes on new work, opens a new location, or changes its structure, assess whether the scope needs to be updated and document the decision.

Clause 4.4: OH&S Management System and Its Processes

Clause 4.4 requires the organisation to establish, implement, maintain, and continually improve its OH&S management system, including the processes needed and their interactions. This is where many organisations confuse having a set of procedures with having a functioning system.

Nonconformity 10: Processes Not Defined or Their Interactions Not Understood

ISO 45001 Clause 4.4 requires the organisation to determine the processes needed for the OH&S management system and understand how they interact. Many organisations have individual procedures but have never mapped how these processes connect. For example, the hazard identification process feeds into the risk assessment process, which feeds into the operational controls process, which feeds into the monitoring and measurement process. If these connections are not understood and documented, the system lacks coherence.

Auditors assess this by asking people at different levels of the organisation to explain how the processes connect. If a safety manager cannot explain how a new hazard identified on the floor flows through the system to a control measure and then to monitoring, that is a sign the process approach has not been properly implemented.

What to do: Develop a process map or system diagram that shows the key processes of the OH&S management system and how they interact. This does not need to be complex. A simple flowchart or table that shows inputs, outputs, and connections between processes is sufficient. The important thing is that people who run the system understand it.

Nonconformity 11: The System Exists on Paper but Not in Practice

This is perhaps the most serious finding under Clause 4.4. An organisation has a documented OH&S management system, but the people who are supposed to be operating it are unaware of its requirements, do not follow its procedures, or cannot explain what the system is meant to achieve.

Auditors test this by interviewing workers at various levels, from senior managers to frontline workers. If a supervisor cannot explain what the OH&S policy commits to, or if a worker does not know how to report a hazard, the system is not functioning as intended.

What to do: Invest in awareness and communication. The system needs to be embedded in daily operations, not just documented in a folder. Regular toolbox talks, visible safety information, and genuine consultation with workers are all part of making the system real rather than theoretical.

Nonconformity 12: Outsourced Processes Not Adequately Controlled

Clause 4.4 also requires the organisation to determine and control outsourced processes that affect OH&S performance. This is a common gap, particularly in organisations that rely heavily on contractors or labour hire workers. If the organisation has outsourced a safety-critical activity but has not defined how it will control that activity or verify that the provider meets OH&S requirements, this is a nonconformity.

What to do: Identify all outsourced processes that have an OH&S impact. For each one, document how the organisation controls and monitors the process. This might include pre-qualification requirements, site inductions, regular inspections, or contractual OH&S obligations.

Patterns Auditors Look For Across All of Clause 4

Experienced auditors do not audit Clause 4 in isolation. They look for consistency between the four subclauses. The context should inform the scope. The interested parties should influence what is included in the system. The scope should be reflected in the processes that make up the system. When these elements are not aligned, it signals that Clause 4 was treated as a compliance exercise rather than a genuine foundation for the system.

Another pattern auditors look for is whether Clause 4 outputs are actually used to drive the rest of the system. The context and interested parties analysis should inform the planning process under Clause 6. If there is no visible connection between what was identified in Clause 4 and what appears in the risk and opportunity register, the system is not integrated.

For a broader view of what auditors look for when assessing the OH&S management system, see Auditing Occupational Health and Safety Under ISO 45001.

How to Prepare for a Clause 4 Audit

Whether you are preparing for an internal audit or a certification audit, the following steps will help you identify and address Clause 4 gaps before the auditor does.

  • Pull out your context register and check the review date. If it has not been reviewed in the past twelve months, schedule a review before the audit.
  • Check that your interested parties register identifies workers specifically and documents their needs and expectations in concrete terms, not generic statements.
  • Read your scope statement and compare it to your actual operations. If you have opened new sites or taken on new types of work since the scope was last updated, revise it.
  • Map your OH&S processes and check that the interactions are understood. Ask a supervisor or safety officer to walk you through how a new hazard would be managed from identification to control. If they cannot do it, you have a training and awareness gap.
  • Check that outsourced and contracted activities are identified and that there are documented controls in place.

You can also use a structured checklist to work through each subclause systematically. The ISO 45001 Internal Audit Checklist published on this site covers all clauses including Clause 4 and gives you a practical starting point.

Building Auditor Competence to Assess Clause 4 Effectively

Many of the nonconformities described in this article go undetected during internal audits because the internal auditor does not know what to look for, or lacks the confidence to challenge vague or incomplete documentation. Auditing Clause 4 well requires understanding what the standard actually requires, knowing how to ask the right questions, and being able to distinguish between a system that genuinely works and one that only looks good on paper.

If you want to build that competence, Audit Workshop offers ISO 45001 internal auditor and lead auditor training that covers Clause 4 in depth. The training is designed by Dilawar Laghari, a certified lead auditor with over 14 years of compliance experience and more than 500 external ISO certification audits. The courses combine clause-by-clause analysis with practical audit scenarios, so you leave knowing not just what the standard says, but how to audit against it in the real world. Courses are available in live and self-paced formats to suit your schedule.

Frequently Asked Questions

The most common finding is that the context analysis was completed during initial certification and has never been reviewed or updated. ISO 45001 requires the organisation to monitor and review information about external and internal issues, which means the context register must be a living document, not a one-time exercise. Auditors check when it was last reviewed and whether it still reflects the organisation's current situation.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2015 Lead Auditor Training Course
  • Lead Auditor
  • Self-Paced Online
  • Exemplar Global
  • USD 199USD 789
ISO 45001:2018 Lead Auditor Training Course
  • Lead Auditor
  • Self-Paced Online
  • Exemplar Global
  • USD 199USD 789
ISO 14001:2026 Lead Auditor Training Course
  • Lead Auditor
  • Self-Paced Online
  • Exemplar Global
  • USD 199USD 789
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Access to self-coaching assessment
  • Access to webinars, events, and online resources
Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Instant Certificate

Download your digital certificate the moment you complete the course.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.