7.1 Clause 9.2: Internal Audit Programme & Auditor Impartiality

Key Takeaways

  • Clause 9.2.1 establishes that internal audits must determine whether the OH&S management system conforms to both the organization's own requirements and ISO 45001:2018, while verifying effective implementation and maintenance.
  • Under Clause 9.2.2, the internal audit programme must be risk-based, dynamically scheduled according to process importance, operational changes, and prior audit results rather than a flat annual calendar.
  • Auditor impartiality and objectivity are non-negotiable normative mandates; internal auditors are strictly prohibited from auditing their own work, departmental processes, or direct subordinates.
  • Clause 5.4(e)(11) mandates the consultation of non-managerial workers in establishing, implementing, and maintaining the internal audit programme, with audit results communicated to workers under Clause 9.2.2(f).
Last updated: September 2026

7.1 Clause 9.2: Internal Audit Programme & Auditor Impartiality

Lead Auditor Core Concept: Internal audits (first-party audits) serve as an organization's primary self-diagnostic mechanism and internal assurance engine. Clause 9.2 does not exist merely to check boxes in anticipation of an external certification registrar. A Lead Auditor must critically evaluate whether an internal audit programme functions as a dynamic, risk-driven inquiry governed by impartial, competent personnel, or whether it has degraded into a superficial paper exercise designed to validate administrative comfort.


1. The Normative Mandate of Clause 9.2.1

ISO 45001:2018 Clause 9.2.1 mandates that the organization conduct internal audits at planned intervals. These internal audits provide vital assurance to top management, workers, and interested parties regarding two foundational criteria (Clause 9.2.1 a–b):

  1. Conformance (Clause 9.2.1a): Whether the occupational health and safety (OH&S) management system conforms to:
    • The organization's own requirements for its OH&S management system, including the OH&S policy, organizational objectives, and operational procedures;
    • The international standard requirements of ISO 45001:2018.
  2. Effectiveness (Clause 9.2.1b): Whether the OH&S management system is effectively implemented and maintained in day-to-day operational reality.

The Dual Conformance Standard

Lead auditors must recognize the duality inherent in Clause 9.2.1(a). Conforming to ISO 45001 alone is insufficient if the organization ignores its own documented requirements. For example, if an enterprise's internal standard operating procedure (SOP) requires daily pre-operational inspections of overhead cranes, but workers perform only monthly inspections, the organization is nonconforming under Clause 9.2.1(a)(1)—even though ISO 45001 itself does not specify daily crane checks.

Conformance vs. Effective Implementation

A management system can achieve textbook textual alignment on paper while failing completely on the shop floor. Clause 9.2.1(b) charges the internal audit process with verifying effective implementation and maintenance. Internal auditors must not restrict their inquiries to reviewing written policies in an office; they must conduct field verifications, observe operational practices, interview frontline operators, inspect equipment, and test physical safeguards.


2. Clause 9.2.2: The Internal Audit Programme Framework

Clause 9.2.2 establishes the operational architecture for managing internal audits. It requires the organization to plan, establish, implement, and maintain an internal audit programme.

                    ISO 19011 / ISO 45001 AUDIT TAXONOMY
┌────────────────────────────────────────────────────────────────────────┐
│ Audit Programme (Clause 9.2.2)                                         │
│ • The overarching governance framework covering 1 to 3 years           │
│ • Defines total scope, frequencies, methodologies, and resources       │
├────────────────────────────────────────────────────────────────────────┤
│ Audit Plan (ISO 19011 Clause 3.6)                                      │
│ • The specific, tactical schedule for a single discrete audit event    │
│ • Defines hour-by-hour agendas, attendees, and operational units       │
└────────────────────────────────────────────────────────────────────────┘

Under Clause 9.2.2(a), the audit programme must define:

  • Frequency: How often discrete audits occur across different operational areas;
  • Methods: The auditing techniques deployed (e.g., visual inspections, worker interviews, sampling records, tracer audits);
  • Responsibilities: Who coordinates the programme, who selects audit teams, and who verifies corrective action closure;
  • Consultation: Mechanisms for consulting non-managerial workers on the programme (Clause 5.4);
  • Planning Requirements: Protocols for creating tactical audit plans, defining checklists, and allocating time;
  • Reporting: How audit findings, conformities, and nonconformities are synthesized and delivered to leadership.

3. Risk-Based Audit Scheduling vs. Static Calendars

One of the most frequent nonconformities identified by Lead Auditors during certification assessments is the deployment of an inflexible, static internal audit schedule. Organizations often construct a generic grid that schedules "Department A in January, Department B in February, Department C in March" regardless of hazard profiles or operational turmoil.

Clause 9.2.2(a) explicitly forbids arbitrary scheduling by mandating that the audit programme shall take into consideration:

  1. The importance of the processes concerned: High-hazard operations (e.g., confined space entries, molten metal casting, pressurized gas handling) require significantly higher audit frequency, deeper sampling, and more specialized audit competence than low-risk administrative archiving.
  2. Changes affecting the organization: Introduction of new chemical substances, installation of automated robotic lines, structural corporate reorganizations, or major facility expansions (Clause 8.1.3 Management of Change) mandate prompt targeted internal audits.
  3. The results of previous audits: Operational areas that exhibited recurring nonconformities, poor incident reporting, or delayed corrective actions must be audited more frequently to evaluate stabilization.

4. Defining Audit Criteria, Scope, and Evidence Collection

Under Clause 9.2.2(b), the organization must define the audit criteria and scope for each individual audit:

  • Audit Criteria (ISO 19011 Clause 3.7): The reference standards, statutory regulations, internal procedures, and contractual specifications used as the benchmark against which objective evidence is compared.
  • Audit Scope (ISO 19011 Clause 3.5): The boundaries and extent of the audit, including physical locations, operational departments, organizational activities, processes, and time frames examined.

Objective Evidence under ISO 19011:2018

Auditors collect objective evidence through three primary techniques:

  1. Document and Record Review: Examining risk assessments, training matrices, calibration logs, and safety committee minutes.
  2. Direct Observation: Watching workers execute high-hazard tasks, verifying lock-out/tag-out (LOTO) isolations, inspecting personal protective equipment (PPE) compliance, and evaluating housekeeping.
  3. Worker and Supervisor Interviews: Engaging personnel at all organizational levels. In accordance with ISO 45001's participatory focus, auditors must interview non-managerial workers out of earshot of supervisors to gauge reporting culture and awareness of hazards.

5. Auditor Selection, Objectivity, and Impartiality

Clause 9.2.2(c) articulates a strict normative requirement:

"The organization shall select auditors and conduct audits to ensure objectivity and the impartiality of the audit process."

The Fundamental Rule of Impartiality

Internal auditors are strictly prohibited from auditing their own work. An auditor cannot evaluate an operational process they manage, a risk assessment they authored, or standard operating procedures they approved. Auditing one's own work creates an inherent conflict of interest that destroys objectivity and conceals vulnerabilities.

Strategies for Maintaining Impartiality Across Organizations

  • Large Enterprises: Utilize cross-departmental auditing pools (e.g., the Logistics Manager audits the Chemical Processing Area, while the Engineering Supervisor audits Warehouse Logistics).
  • Small and Medium-Sized Enterprises (SMEs): Where management personnel wear multiple hats, organizations can utilize reciprocal auditing arrangements with qualified peer companies, or contract qualified independent external third-party auditors to execute the internal audit programme.
  • Competency Requirements: Impartiality is meaningless without auditor competence. Under ISO 19011:2018, internal auditors must demonstrate knowledge of ISO 45001 principles, hazard identification techniques, legal compliance frameworks, and professional interview methodologies.

6. Worker Consultation, Reporting, and Documented Information

Internal audits do not function in a managerial silo. ISO 45001 integrates worker engagement directly into the audit lifecycle:

  • Worker Consultation (Clause 5.4e.11): The organization must consult non-managerial workers when establishing, implementing, and maintaining the internal audit programme. Workers provide vital input into which processes require audit scrutiny based on shop-floor hazards.
  • Reporting to Relevant Managers (Clause 9.2.2e): Audit findings, nonconformity notices, and opportunities for improvement must be formally communicated to the managers responsible for the audited areas.
  • Reporting to Workers (Clause 9.2.2f): Relevant audit results must be communicated to workers, and where they exist, workers' representatives. Full transparency ensures that safety concerns are shared openly.
  • Timely Corrective Action (Clause 9.2.2d / 10.2): Managers must initiate prompt root cause analyses and corrective actions to eliminate detected nonconformities without undue delay.
  • Documented Information Retention (Clause 9.2.2g): The organization must retain documented evidence of the audit programme's implementation and the formal results of all audits.

7. Comparative Analysis: Static Calendar vs. Risk-Based Audit Programme

Audit DimensionTraditional Static CalendarRisk-Based Programme (Clause 9.2.2)
Core PhilosophyAdministrative box-ticking; treat all units identicallyProactive resource allocation; prioritize severe hazards
Frequency DeterminationFixed schedule (e.g., every department audited annually)Dynamic frequency driven by risk, changes, and prior findings
Auditor AssignmentOften convenience-driven, risking self-auditing conflictsStrictly vetted for technical competence and total impartiality
Scope & DepthStandardized, generic checklist applied uniformlyTailored audit criteria and targeted high-risk process scopes
Worker EngagementZero worker involvement; treated as confidential management reportWorkers consulted on programme (5.4); results shared with workers (9.2.2f)
Lead Auditor EvaluationVulnerable to Major Nonconformity under Clause 9.2.2(a)Full compliance; demonstrates mature governance assurance

8. Real-World Audit Scenario: The Safety Director Who Audited His Own System

Audit Context: During a Stage 2 certification audit of a commercial plastics manufacturing facility, the Lead Auditor examines documented information for the internal audit completed four months prior.

Audit Investigation:

  1. The internal audit report indicates that the entire OH&S management system was audited over three days by a single individual: the Corporate EHS Director.
  2. The audit files confirm that the EHS Director personally audited Clause 6.1 (Hazard Identification & Risk Assessment), Clause 8.1.2 (Hierarchy of Controls), and Clause 9.1.2 (Evaluation of Compliance).
  3. In an interview, the EHS Director explains: "I designed this management system, authored every procedure, and chair the safety steering committee. No one else in this company understands the ISO 45001 requirements well enough to audit them, so I handle the internal audits myself to guarantee technical accuracy."
  4. The auditor confirms that while the EHS Director holds lead auditor credentials, none of the internal audit reports identified any nonconformities in risk assessment or compliance evaluation, despite two unaddressed machine guarding violations currently active on the factory floor.

Lead Auditor Evaluation: The Lead Auditor issues a Major Nonconformity citing ISO 45001:2018 Clause 9.2.2(c). The organization failed to ensure objectivity and the impartiality of the internal audit process. Appointing the primary architect and manager of the OH&S system to audit their own processes creates an insurmountable conflict of interest, invalidating the assurance function of the internal audit programme.


9. Common Exam Traps and Candidate Errors

  • Trap 1: Confusing an Audit Programme with an Individual Audit Plan. An audit programme is the strategic, multi-year organizational framework governing all audits (Clause 9.2.2). An audit plan is the operational agenda for a specific 1- or 2-day audit event. Candidates frequently conflate the two terms.
  • Trap 2: Prioritizing Technical Competence Over Auditor Impartiality. Auditees often argue that having process owners audit their own departments ensures deeper technical insight. For exam scenarios, technical competence never excuses a lack of impartiality. Auditors must never audit their own work.
  • Trap 3: Omitting Worker Consultation in Programme Development. Candidates often assume that internal audit programmes are exclusively developed by executive safety directors. ISO 45001 Clause 5.4(e)(11) explicitly mandates the consultation of non-managerial workers in establishing and maintaining the audit programme.
Loading diagram...
ISO 45001 Clause 9.2 Risk-Based Internal Audit Programme Architecture
Test Your Knowledge

An organization operating high-voltage electrical substations and low-risk administrative offices schedules internal audits once every twelve months for every department equally across the site. The internal audit procedure specifies that every department shall be audited on the same standardized 2-hour checklist annually regardless of past audit findings or operational hazards. How should a Lead Auditor evaluate this internal audit programme under Clause 9.2.2?

A
B
C
D
Test Your Knowledge

During a Stage 2 certification audit, the Lead Auditor examines the internal audit records for the chemical blending plant. The audit records reveal that the Quality and EHS Manager—who authored the site's chemical handling standard operating procedures (SOPs) and hazard assessment registers—personally conducted the internal audit of Clause 6.1 (Actions to address risks and opportunities) and Clause 8.1.2 (Hierarchy of controls) for the chemical blending plant. How must the Lead Auditor assess this audit practice?

A
B
C
D
Test Your Knowledge

An organization completes its annual internal audit cycle and submits the comprehensive audit report containing six minor nonconformities directly to the Plant Operations Director. The Lead Auditor discovers that neither the internal audit programme nor the resulting audit reports were shared with or made available to the Joint Health and Safety Committee or non-managerial worker representatives. What is the auditor's required finding?

A
B
C
D