Why the OH&S Policy Is More Than a Framed Document on the Wall
If you have spent any time auditing occupational health and safety management systems, you will have seen the same thing repeatedly. A neatly framed OH&S policy hangs near the reception desk, signed by someone who left the organisation two years ago, stating commitments that bear no resemblance to how the business actually operates. That document is not a policy. It is a compliance prop.
On this page
ISO 45001 Clause 5.2 sets out exactly what the OH&S policy must contain, and more importantly, what top management must do with it. Getting this clause right is not complicated, but it does require genuine engagement from leadership rather than a copy and paste exercise from a template. This article walks through every requirement of Clause 5.2, explains what auditors look for, and gives you practical guidance on how to build or review a policy that actually works.
What ISO 45001 Clause 5.2 Requires
Clause 5.2 sits within Section 5, which covers Leadership and Commitment. This placement is deliberate. The OH&S policy is a leadership document, not an administrative one. Top management must establish, implement, and maintain the policy. It cannot be delegated to the safety team and forgotten.
The standard specifies that the OH&S policy must include commitments to the following areas. Each one matters, and each one is auditable.
A Commitment to Provide Safe and Healthy Working Conditions
The policy must include a commitment to provide safe and healthy working conditions for the prevention of work-related injury and ill health. This goes beyond a generic statement about caring for workers. Auditors will look for evidence that this commitment is reflected in how the organisation allocates resources, responds to incidents, and manages hazards.
In practice, this means the policy should acknowledge the nature of the work environment and the types of hazards present. A construction company and a call centre face very different risks. A policy that could apply to any business in any industry is a warning sign. It suggests the policy has not been tailored to the organisation's context, which is a requirement under Clause 4.1.
A Commitment to Fulfil Legal Requirements and Other Requirements
The policy must include a commitment to fulfil applicable legal requirements and other requirements. In the Australian context, this means the relevant Work Health and Safety legislation, codes of practice, and any other obligations the organisation has taken on, such as contractual requirements or industry standards.
This commitment signals to workers, contractors, and other interested parties that the organisation takes its obligations seriously. When auditing this element, look for evidence that the legal register is current, that compliance evaluations are being conducted, and that the policy commitment is backed up by actual practice. A commitment in a policy that is not reflected in operations is a nonconformity waiting to be written.
A Commitment to Eliminate Hazards and Reduce OH&S Risks
ISO 45001 places significant emphasis on the hierarchy of controls, and this commitment in the policy reflects that emphasis. The policy must state a commitment to eliminate hazards and reduce OH&S risks. This is not just about controlling risks after they have been identified. It is about actively seeking to eliminate them where reasonably practicable, working down the hierarchy from elimination through substitution, engineering controls, administrative controls, and finally personal protective equipment.
This commitment connects directly to the hazard identification and risk assessment requirements in Clause 6.1.2. Auditors will trace this policy commitment through to how hazards are actually managed on the ground. If the policy says the organisation is committed to eliminating hazards but every corrective action involves handing out more PPE, there is a gap worth investigating. For a deeper look at how this plays out in practice, the article on auditing occupational health and safety under ISO 45001 covers the audit trail from policy through to operational controls.
A Commitment to Continual Improvement
The policy must include a commitment to continual improvement of the OH&S management system. This is a standard requirement across all ISO management system standards, but it carries particular weight in the safety context. Workers and other interested parties need to see that the organisation is not just maintaining the status quo but actively working to improve safety performance over time.
When auditing this element, look for evidence of improvement activities, not just statements of intent. Management review outputs, corrective action trends, and objective achievement data all help to demonstrate that continual improvement is real rather than rhetorical.
A Commitment to Worker Consultation and Participation
This is one of the elements that distinguishes ISO 45001 from its predecessor OHSAS 18001. The policy must include a commitment to consultation and participation of workers, and where they exist, workers representatives. This reflects the standard's strong emphasis on worker involvement throughout the management system.
A policy that commits to worker consultation but where no genuine consultation mechanisms exist is a significant gap. Auditors will look for evidence that workers are involved in hazard identification, risk assessment, incident investigation, and the development of controls. This commitment in the policy is the starting point for the detailed requirements in Clause 5.4.
Exemplar Global Recognised Training ProviderRTP No. 310970What the Policy Must Also Do
Beyond the specific commitments listed above, Clause 5.2 also sets out requirements for how the policy must be managed and communicated. These requirements are just as important as the content of the policy itself.
The Policy Must Be Available as Documented Information
The OH&S policy must be available and maintained as documented information. This is straightforward but often poorly executed. The policy needs to be controlled under the organisation's documented information requirements in Clause 7.5. It should have a version number, a review date, and an approval signature from someone in top management.
Auditors will check that the version on the wall, on the intranet, and in the management system documentation are all the same version. Inconsistencies here are a common finding.
The Policy Must Be Communicated Within the Organisation
The policy must be communicated within the organisation. This does not mean emailing it to all staff once and ticking a box. Communication means workers understand the policy, not just that they have received it. Auditors will often ask workers on the shop floor or at the work site what the organisation's safety commitments are. If workers cannot articulate even the broad intent of the policy, communication has not been effective.
Induction training, toolbox talks, posters, and regular team briefings are all valid communication mechanisms. The key is that the method suits the workforce. For a remote workforce or a multilingual team, the approach needs to be adapted accordingly.
The Policy Must Be Available to Interested Parties
The policy must be available to relevant interested parties, as appropriate. This typically means making the policy accessible to contractors, clients, and other stakeholders who have a legitimate interest in the organisation's safety commitments. Many organisations publish their policy on their website or include it in tender documentation. The standard does not prescribe how this is done, only that it happens where appropriate.
The Policy Must Be Relevant and Appropriate
The policy must be appropriate to the purpose, size, and context of the organisation, and to the nature of its OH&S risks and opportunities. This is the requirement that rules out generic template policies. A two person landscaping business and a 500 person manufacturing facility have fundamentally different risk profiles. Their policies should reflect that difference.
Context is set out in Clause 4.1, and the policy must align with what the organisation identified there. Auditors will check this alignment. If the context analysis identified significant psychosocial hazards but the policy makes no reference to worker wellbeing, that is a gap worth noting.
Common Nonconformities Auditors Raise Against Clause 5.2
Having conducted hundreds of external certification audits, the same issues come up repeatedly when auditing the OH&S policy. Knowing what these are helps you address them before the certification auditor arrives.
Policy Signed by Someone Without Current Authority
The policy must be established by top management. If the person who signed the policy is no longer with the organisation, or has been replaced in the relevant role, the policy needs to be reissued with an appropriate signature. This sounds obvious, but it is surprisingly common.
Missing Commitments
Some organisations draft their policy from memory or use a template that predates ISO 45001. The result is a policy that includes some of the required commitments but not all. The commitment to worker consultation and participation is the most frequently missing element, particularly in organisations that transitioned from OHSAS 18001 without fully reviewing their policy content.
Policy Not Reflecting Actual Operations
A policy that commits to eliminating hazards but where the corrective action register shows nothing but PPE solutions is internally inconsistent. Auditors do not just read the policy in isolation. They trace commitments through to evidence of implementation. If the policy says one thing and the records say another, the policy is not being implemented.
Workers Cannot Articulate Policy Commitments
This is a communication failure. If a worker in a high risk role cannot explain, even in general terms, what the organisation's safety commitments are, the policy has not been effectively communicated. This is often raised as an observation or opportunity for improvement rather than a nonconformity, but it can escalate if the gap is significant.
Policy Not Reviewed After Significant Changes
The policy must be maintained, which means it needs to be reviewed when the organisation's context changes significantly. A merger, a major expansion, a new high risk activity, or a significant incident should all trigger a policy review. Organisations that set and forget their policy for five or more years are at risk of having a document that no longer reflects what they do.
How to Write an OH&S Policy That Actually Works
Writing a policy that satisfies Clause 5.2 and actually drives behaviour is not about length. A one page policy that is specific, signed, communicated, and reviewed regularly is far more valuable than a three page document that nobody reads.
Start with the organisation's context. What are the significant hazards? What does the workforce look like? What legal obligations apply? The policy should reflect these realities. Then work through each required commitment and express it in language that is meaningful to the people who will read it.
Involve top management in drafting or reviewing the policy, not just signing it. When top management has been part of the conversation, they are more likely to champion the policy and demonstrate the commitment it describes. This is the intent behind placing the policy requirement in the Leadership section of the standard.
Review the policy at least annually, or whenever there is a significant change to the organisation's context, structure, or risk profile. Document the review, even if no changes are made. The record of review demonstrates that the policy is being maintained, not just filed.
Connecting the Policy to the Rest of the Management System
The OH&S policy does not exist in isolation. It connects to almost every other element of the management system. The commitments in the policy drive the objectives set under Clause 6.2. The commitment to fulfil legal requirements connects to the legal register and compliance evaluation under Clause 6.1.3 and Clause 9.1.2. The commitment to worker consultation connects to the detailed requirements of Clause 5.4.
When auditing the policy, experienced auditors use it as a lens. They look at what the policy commits to and then ask whether the rest of the system delivers on those commitments. This is why a policy that is vague or generic is actually a risk. It makes it harder to demonstrate that the system is working, because the commitments are too broad to be auditable.
For those looking to develop their skills in auditing the OH&S management system end to end, ISO 45001 auditor training levels explained provides a useful overview of the training pathway from foundation through to lead auditor.
The Policy in the Context of Top Management Accountability
One of the most important shifts in ISO 45001 compared to earlier safety standards is the explicit accountability placed on top management. The policy is not something that can be handed to the HSE team to write and maintain without any real involvement from leadership. Clause 5.1 establishes the leadership and commitment requirements, and Clause 5.2 is the first tangible expression of that commitment.
When auditing top management under Clause 5.1, auditors will often ask about the policy. Can top management explain the commitments in the policy? Do they know when it was last reviewed? Can they describe how it has been communicated to the workforce? If top management cannot answer these questions, it raises questions about whether their commitment is genuine or ceremonial.
The article on auditing leadership commitment under Clause 5.1 of ISO 45001 goes into detail on how to approach these conversations with top management during an audit.
Exemplar Global Recognised Training ProviderRTP No. 310970Practical Audit Questions for Clause 5.2
When auditing Clause 5.2, whether as an internal auditor or a certification auditor, the following questions will help you gather the evidence you need.
- Can I see the current OH&S policy? Is it controlled documented information with a version number and approval date?
- Who approved the current version of the policy, and are they still in a position of top management authority?
- Does the policy include all five required commitments: safe working conditions, legal requirements, eliminating hazards and reducing risks, continual improvement, and worker consultation and participation?
- How is the policy communicated to workers? Can you show me evidence of that communication?
- Can you describe how the policy is made available to relevant interested parties?
- When was the policy last reviewed? What prompted the review?
- How does the policy reflect the specific hazards and context of this organisation?
Asking a sample of workers whether they are aware of the policy and what it commits to will also give you a quick read on the effectiveness of communication. Keep the question open and conversational rather than asking workers to recite the policy verbatim.
Building Your Skills in Auditing ISO 45001
Understanding Clause 5.2 in depth is one part of developing competence as an ISO 45001 auditor. The policy connects to leadership, planning, support, operations, and performance evaluation. Auditing it well requires you to understand how the whole system hangs together, not just the words on the page.
At Audit Workshop, the ISO 45001 internal auditor and lead auditor courses are built around exactly this kind of integrated thinking. You learn how to trace commitments from the policy through to evidence on the ground, how to ask the right questions of top management, and how to write findings that are clear, evidence based, and actionable. If you are working in WHS, HSE, or quality management and want to build credible auditing skills in occupational health and safety, the pathway to becoming an ISO 45001 OH&S auditor is more accessible than many people realise.













