4.3 Clause 7.5: Documented Information Control & Retention

Key Takeaways

  • ISO 45001 replaces the legacy terms 'documents' and 'records' with the unified Annex SL term 'documented information', divided functionally into maintenance and retention.
  • The standard strictly distinguishes between 'maintaining documented information' (living documents like policies, procedures, and hazard registers) and 'retaining documented information' (immutable evidence such as audit logs, calibration certificates, and training records).
  • Clause 7.5.2 requires structured identification, appropriate formatting/media, and formal review and approval for suitability and adequacy prior to release.
  • Clause 7.5.3 mandates rigorous controls for distribution, retrieval, storage, change tracking, external origin documents, and confidentiality, particularly for sensitive occupational medical records.
Last updated: September 2026

4.3 Clause 7.5: Documented Information Control & Retention

Under the High-Level Structure (Annex SL) governing modern management system standards, the legacy terminology of 'documents' (procedures, specifications, and policies) and 'records' (completed forms, logs, and historical evidence) has been integrated under the unified term documented information. However, this linguistic consolidation does not eliminate their distinct operational and legal functions. Within ISO 45001:2018, Clause 7.5 establishes rigorous requirements for creating, updating, controlling, and preserving the information necessary to validate that the OH&S management system is operating effectively. For a lead auditor, examining documented information is the primary gateway to obtaining objective evidence, reconstructing past events, and verifying continuous control.


1. Annex SL Evolution: The Unified Concept of Documented Information (Clause 7.5.1)

Clause 7.5.1 establishes that the organization's OH&S MS must include two distinct tiers of documented information:

  1. Documented information required by ISO 45001: Mandatory items explicitly dictated by the standard's requirements (e.g., OH&S policy under 5.2, hazard identification methodology under 6.1.2.1, compliance evaluations under 9.1.2, internal audit programs under 9.2.2).
  2. Documented information determined by the organization as necessary for effectiveness: Additional standard operating procedures (SOPs), technical work instructions, batch cards, equipment operating manuals, and engineering drawings deemed necessary to ensure operational reliability.

The Proportionality Principle

Clause 7.5.1 acknowledges that the extent of documented information can differ significantly based on:

  • The size of the organization and its activities, processes, products, and services;
  • The complexity of processes and their interactions;
  • Applicable legal and other compliance obligations;
  • The competence of workers.

ISO 45001 is not a bureaucratic paper-generation standard. An enterprise with highly competent, stable workers and automated interlocks may require fewer written procedures than a multi-tier facility employing rapid-turnover contract labor handling volatile petrochemicals.


2. The Critical Audit Distinction: 'Maintain' vs. 'Retain'

One of the most frequent examination subjects for ISO 45001 Lead Auditors is the technical distinction between the verbal directives 'maintain documented information' and 'retain documented information':

Technical DimensionMaintain Documented InformationRetain Documented Information
Annex SL / ISO 45001 Syntax'The organization shall maintain documented information of...''The organization shall retain documented information as evidence of...'
Legacy EquivalentDocuments (Policies, procedures, manuals, work instructions, plans, registers)Records (Completed forms, inspection logs, test reports, audit evidence, minutes)
Operational NatureLiving, dynamic, and revisable. Subject to continuous review, updating, change tracking, and obsolescence control.Historical, immutable, and fixed. Represents objective evidence of past activities or results achieved; must never be altered retroactively.
Primary Lifecycle PurposeDirects how activities are to be planned, executed, controlled, and governed today and in the future.Proves what actually took place, who executed the task, what data was measured, and whether controls functioned.
Lead Auditor Examination FocusVerifying current revision status, authorization/approval, point-of-use availability, and removal of obsolete versions.Sampling records across time, verifying completeness, sign-offs, chronological integrity, and retention periods.
Key ISO 45001 Clause Examples- Scope of the OH&S MS (4.3)<br/>- OH&S Policy (5.2)<br/>- Hazard ID methodologies (6.1.2.1)<br/>- OH&S Objectives & plans (6.2.1/6.2.2)<br/>- Emergency response procedures (8.2)- Evidence of competence (7.2.d)<br/>- Calibration records (9.1.1)<br/>- Compliance evaluations (9.1.2.f)<br/>- Internal audit results (9.2.2.f)<br/>- Management review minutes (9.3)<br/>- Incident investigations & corrective actions (10.2.f)

An organization that retroactively alters chemical exposure logs or training sign-offs to pass an audit commits serious document falsification, triggering an immediate Major Nonconformity.


3. Clause 7.5.2: Rigorous Controls for Creating and Updating

When creating and updating documented information, Clause 7.5.2 mandates that the organization ensure three operational controls:

  • a) Identification and Description: Every document must possess clear identifiers, such as a unique document title, reference code, publication date, author, revision number, and scope.
  • b) Format and Media: The format must be appropriate for users, encompassing language, software version, graphics, photographic instructions, and delivery medium (paper hardcopy, mobile tablets, intranet portal).
  • c) Review and Approval for Suitability and Adequacy: Before release, documented information must undergo formal review and authorization by designated, competent authorities. Draft procedures circulating without formal approval violate Clause 7.5.2(c).

4. Clause 7.5.3: Controlling, Protecting, and Preserving Documented Information

Clause 7.5.3 establishes operational rules governing the lifecycle of documented information, both electronic and paper-based:

  1. Availability and Suitability for Use: Documents must be readily accessible at the exact locations and times needed (e.g., maintenance shop floor, control rooms).
  2. Adequate Protection: The organization must protect documented information from loss of confidentiality, improper use, or loss of integrity (unauthorized editing, file corruption, physical degradation).
  3. Distribution, Access, Retrieval, and Use: Defined permissions must govern who can view, download, or edit files in Electronic Document Management Systems (EDMS). Read-only permissions should apply to operational users, reserving edit rights for document owners.
  4. Storage and Preservation: Physical archives must be protected from environmental degradation (fire, water, humidity). Digital archives require automated, off-site backup systems and disaster recovery protocols.
  5. Control of Changes: Organizations must track version history, change rationales, and revision markers, ensuring workers can immediately identify amendments.
  6. Retention and Disposition: Defined retention schedules based on statutory mandates and business needs, followed by secure destruction (cross-cut shredding or certified digital data sanitization).

5. Controlled External Origin Documents and Medical Confidentiality

Clause 7.5.3 contains two specialized areas requiring intense lead auditor scrutiny:

Documents of External Origin

Clause 7.5.3 mandates that documented information of external origin determined necessary for the OH&S MS must be identified, indexed, and controlled. Typical external documents include:

  • Statutory safety acts, national occupational exposure standards, and municipal fire codes;
  • Safety Data Sheets (SDS) provided by chemical manufacturers;
  • Original Equipment Manufacturer (OEM) installation, maintenance, and operating manuals;
  • Customer-mandated contractor safety requirements.

An auditor samples active machinery and chemicals on the shop floor to verify that current OEM manuals and SDS are readily available and integrated into document control registers.

Confidentiality of Medical Surveillance Records

ISO 45001 places extraordinary emphasis on protecting sensitive personal health data. Under Clause 7.5.3, access to personal medical surveillance records (audiometric tests, respiratory fit tests, biological blood lead monitoring) must be strictly restricted to licensed occupational medical practitioners. Management and supervisors must not have unauthorized access to confidential medical diagnoses. However, the organization must ensure that individual workers have guaranteed access to their own personal health surveillance records.


6. Real-World Audit Scenario: The Overwritten Hot-Work Log and Compromised Medical Privacy

Context: During an audit of a naval shipyard, the lead auditor examines hot-work permits and occupational health files.

Audit Trail & Findings:

  1. Reviewing hot-work permits in the welding fabrication shop, the auditor discovers hot-work fire-watch records are maintained on a shared spreadsheet on a public network drive. All 140 shop workers have full editing rights.
  2. In several cases, historical fire-watch temperature verification logs from prior shifts were overwritten or erased by incoming welders to record new data, destroying objective evidence of compliance.
  3. In the administration building, annual audiometric hearing loss examination results for all grinders—including private medical diagnoses and clinical physician evaluations—are stored in an unencrypted folder on the general company intranet accessible to all staff.

Auditor Ruling: The lead auditor issues two separate nonconformities:

  1. A Major Nonconformity under Clause 7.5.3 for failure to protect the integrity of retained documented information, allowing historical compliance records to be overwritten.
  2. A Major Nonconformity under Clause 7.5.3 for gross failure to maintain the confidentiality of sensitive worker health surveillance data.

7. Common Exam Traps & Candidate Errors

  • Trap 1: Confusing 'Maintain' with 'Retain'. Audit results and training records are always retained (immutable records of past events), never maintained (living operational procedures).
  • Trap 2: Assuming ISO 45001 Requires a Formal 'Safety Manual'. ISO 45001:2018 contains no requirement for an OH&S Manual. It requires documented information, granting organizations full flexibility in media and format.
  • Trap 3: Overlooking External Documents. Failing to control external Safety Data Sheets (SDS) or OEM operating manuals is a direct nonconformity under Clause 7.5.3.
Loading diagram...
ISO 45001 Clause 7.5 Documented Information Lifecycle and Control Architecture
Test Your Knowledge

In ISO 45001:2018, what is the precise standard convention regarding the distinction between 'maintaining' and 'retaining' documented information?

A
B
C
D
Test Your Knowledge

During an audit of an industrial manufacturing facility, the lead auditor reviews how worker health surveillance data is controlled under Clause 7.5.3. Which of the following arrangements constitutes an auditable nonconformity?

A
B
C
D
Test Your Knowledge

Under ISO 45001:2018 Clause 7.5.2, what three controls must an organization ensure whenever creating or updating documented information?

A
B
C
D