ISO 45001 Internal Audit Malaysia: Practical Workplace Checklist

Engineer with safety gear reviewing a clipboard at a construction site, illustrative ISO 45001 auditing image

An ISO 45001 internal audit should test whether the occupational health and safety management system works where the job happens—not just whether a procedure exists in a folder. In Malaysia, effective auditing also checks how statutory duties, site hazards, workers and contractors are managed.

Plan the audit around risk

ISO 45001:2018 Clause 9.2 addresses internal audits. Set criteria, scope, methods and an audit programme that considers the importance of processes, changes and previous audit results. Keep objectivity and impartiality. High-risk work deserves proportionate attention rather than simply equal audit hours for every department.

Five evidence streams worth reviewing

  1. Leadership: How does management allocate resources, address critical risks and remove barriers?
  2. Risk assessment: Do HIRARC and task assessments reflect the actual equipment, conditions and controls?
  3. Competence: Can workers and contractors explain and demonstrate task-critical controls?
  4. Operational control: Are permit-to-work, isolation, lifting and emergency arrangements applied on site?
  5. Improvement: Are incident actions completed and checked for effectiveness?

Follow one real work activity

For example, sample a conveyor maintenance job. Trace the process from risk assessment to the isolation plan, instructions, worker authorisation and work completion. Interview the people doing the job, review evidence and observe safe practice. Never create an unsafe situation merely to gather audit evidence.

Write findings that people can act on

A strong nonconformity identifies the specific requirement, objective evidence and the difference between them. “Three maintenance records had no evidence of isolation verification required by procedure X” is much more actionable than “poor safety culture”. Separate verified findings from assumptions, opportunities and positive practices.

Check corrective action effectiveness

Training alone will not fix a missing isolation point or a permit system that is impossible to follow. Identify the cause of the finding, assign an owner, implement suitable controls and verify them after implementation. ISO 45001 Clause 10.2 addresses incidents, nonconformity and corrective action.

Practical checklist

  • Confirm scope, criteria, sampling approach and auditor independence.
  • Review incidents, objectives, previous findings and changes.
  • Sample both documents and actual worksite practice.
  • Agree accountable owners and realistic closure dates.
  • Report themes to management and test lasting effectiveness.

Explore ISO 45001 / ISO 14001 Awareness and Internal Audit programmes, or request a practical audit workshop.

References

ISO 45001:2018 Clauses 9.2 and 10.2 (consult licensed standard text); DOSH Malaysia. Certification and statutory legal compliance are distinct requirements.

Comments

One response to “ISO 45001 Internal Audit Malaysia: Practical Workplace Checklist”

  1. A WordPress Commenter Avatar

    Hi, this is a comment.
    To get started with moderating, editing, and deleting comments, please visit the Comments screen in the dashboard.
    Commenter avatars come from Gravatar.

Leave a Reply

Your email address will not be published. Required fields are marked *