What Documented Information Does ISO 45001 Require?

ISO 45001 requires a defined set of documented information, including your OH&S policy, scope, risk and opportunity methodology, legal requirements, objectives, competence and communication records, operational controls, emergency procedures, incident and audit records and management review outputs. The standard is less prescriptive than people expect, but auditors will ask for all of it.
The confusion usually comes from the wording. ISO 45001 talks about "documented information" rather than documents and records and it distinguishes between information you must maintain (documents that stay current) and information you must retain (records that evidence something happened).
The documents you must maintain
These are living documents that should be current and controlled.
- Scope of the management system (clause 4.3)
- OH&S policy (clause 5.2)
- Roles, responsibilities and authorities (clause 5.3)
- Risks and opportunities, and the processes and actions to address them (clause 6.1.1)
- The methodology and criteria for assessing risks (clause 6.1.2)
- Legal and other requirements (clause 6.1.3)
- OH&S objectives and plans to achieve them (clause 6.2.2)
- Operational controls, to the extent needed for confidence the processes are carried out as planned (clause 8.1.1)
- Emergency preparedness and response processes and plans (clause 8.2)
The records you must retain
These evidence that something was done and are the ones auditors spend most of their time on.
- Evidence of competence (clause 7.2)
- Evidence of communications (clause 7.4.1)
- Monitoring, measurement, analysis and performance evaluation results (clause 9.1.1)
- Maintenance and calibration of monitoring equipment (clause 9.1.1)
- Evaluation of compliance results (clause 9.1.2)
- Internal audit programme and results (clause 9.2.2)
- Management review results (clause 9.3)
- Incidents and nonconformities, actions taken and results (clause 10.2)
- Evidence of continual improvement (clause 10.3)
Some items sit in both categories. Your legal register, risk assessment methodology, objectives, operational controls, emergency plans and continual improvement evidence must be kept current and also retained as a record. In practice that means version control: the live document is current and earlier versions are kept so you can show what applied at the time.
What people assume is required but is not
ISO 45001 does not require a manual. It does not require a documented procedure for every clause and it does not dictate a numbering system or a template. The old habit of writing a procedure per clause comes from earlier standards and mostly produces documents nobody reads.
What the standard actually says is that you keep the documented information necessary for the effectiveness of the system, plus the specific items listed above. A small business can meet this with a modest set of documents that people actually use.
What auditors ask for in practice
Beyond the list, expect to be asked for:
- Risk assessments covering the activities in scope, with evidence they are current
- Your legal register and, crucially, evidence you have evaluated compliance against it
- Consultation and participation records
- Training records and how you decided what competence was needed
- Incident investigations with root cause and closed out actions
- Evidence the last management review actually happened and produced decisions
Document control is the other half
Having the documents is not enough. Clause 7.5.3 requires that they are available where needed, protected, controlled for distribution and change and that superseded versions are not used by mistake.
This is where most findings are raised. Not the absence of a document, but three versions of it in different folders and no way to tell which one is current.
How TalkHSE helps
TalkHSE's Document Management module gives each document an owner, a revision history, an approval step and a review date, so the maintained documents stay current and the retained records stay findable. Risk assessments, incidents, actions and toolbox talks generate their records in the same system, which means the evidence side of the list builds itself as you work rather than being assembled the month before an audit.
Frequently asked questions
Does ISO 45001 require a manual?
No. A manual is optional. The standard requires specific documented information, not a single overarching document.
How many procedures does ISO 45001 require?
None by name. The standard requires documented processes in certain areas, but it does not mandate a procedure document for each clause.
Can documents be electronic?
Yes. ISO 45001 is neutral on format. Electronic documents are generally easier to control, because version history and access are handled by the system rather than by people.
How long do ISO 45001 records need to be kept?
The standard does not set retention periods. You decide them, based on legal requirements, contractual obligations and how long the information is useful, then apply them consistently.
What is the difference between maintain and retain?
Maintained information is a live document you keep up to date, such as your policy. Retained information is a record of something that happened and is not edited afterwards, such as an audit result.
More Articles


