ISO 45001 2018 Internal Auditor Migration 01-04-2020 (4)
ISO 45001 2018 Internal Auditor Migration 01-04-2020 (4)
Alcumus Academy
www.alcumusgroup.com
Session One
Auditing experience – Four full management system audits as an auditor-in-training, totaling 20 days,
including a minimum of 15 days on site and three full management system audits as the leader of an
audit team that includes at least one other auditor, totaling 15 days, 10 of which must have been
spent on site.
Course Objectives:
The aim of this course is to provide delegates with the knowledge and skills required to perform first,
second and third-party audits of occupational health and safety management systems against
ISO 45001, in accordance with ISO 19011 and ISO/IEC 17021, as applicable.
Auditors' role:
To assess an organisation’s ability to provide a safe and healthy workplace, to prevent work related
injury and ill health and to proactively improve its occupational health and safety performance
Course Overview
Team exercises
Continuous assessment
Name
Auditing experience
Hobbies/pastimes
Session Two
ISO 45001 Development and Purpose
ISO 45001 Series
The ISO 45001 standard addresses the Health & Safety management needs of all types of organisations
Current standards:
Management systems ISO 45001, which can be audited All areas need to be audited - No exclusions or ‘opt outs’ allowed
Management system guidance ISO 45002, guidance only and it cannot be audited:
BS 45002-0 Occupational health and safety management systems. General guidelines for the application of ISO 45001
BS 45002 Part 3: General guidelines for the application of ISO 45001 – guidance on incident investigation
Continuing Development of Standards
All standards go through a defined drafting, review, consultation, approval and issue process
ISO 45001 is applicable to any organisation that wishes to establish, implement and maintain
an OH&S management system to improve occupational health and safety, eliminate hazards
and minimize OH&S risks (including system deficiencies), take advantage of OH&S
opportunities, and address OH&S management system nonconformities associated with its
activities.
Benefits of ISO 45001
Better working environment - Reduced risks
Worker
Person performing work or work-related activities that are under the control of the organisation
Participation
Involvement in decision-making
Consultation
Seeking views before making a decision
Workplace
Place under the control of the where a person needs to be or to go for work purposes
Structure of ISO 45001
4 Context 7 Support
Interested parties, Scope, Process Competence, Communication
5 Leadership Documentation
Policy, Roles, Consultation
6 Planning 8 Operational planning & control
Hazard identification Management of change
Plan Do Procurement
Legal requirements
Objectives Emergency preparedness
Working Individually:
What external and internal issues / threats, an organisation would need to determine were
in or out of scope of an OHSMS, if they had to manufacture and install a road traffic sign,
for the local council.
Determine which processes might mitigate or control these issues?
5 Leadership and worker participation
Top management shall demonstrate leadership and commitment with respect to the OH&S
management system
Promote a culture that supports the intended outcomes of the OH&S management system
5.2 OH&S policy
Top management shall establish, implement and maintain an OH&S policy that includes a commitment
to provide safe and healthy working conditions for the prevention of work related injury and ill health
and is appropriate to the purpose, size and context of the organisation and to the specific nature of its
OH&S risks and OH&S Opportunities.
Checklist Example:
Check that the policy includes the required elements (Commitments from Top Management)
How would you ensure that interested parties were aware of it?
5.3 Organisational roles, responsibilities and authorities
Top management shall assign, document and communicate the responsibility and authority for:
While responsibility and authority can be assigned, ultimately top management is still accountable for
the functioning
of the OH&S management system.
5.4 Consultation and participation of workers
Exercise 2
The organisation shall establish, implement and maintain a process(es) for consultation and
participation of workers at all applicable levels and functions, and, where they exist, workers’
representatives, in the development, planning, implementation, performance evaluation and actions for
improvement of the OH&S management system.
Working individually, compile a checklist that you could use to confirm that the organisation are meeting
the requirements of this clause of the standard.
OH&S risks and other risks such as peaks in workflow - restructuring and reorganising the works to avoid this
OH&S opportunities and other opportunities - training on, or procurement of, new improved equipment or
supplies
Legal requirements and other requirements - legislation (national, regional or international), including statutes
and regulations
6.1.2 Hazard identification and assessment of risks and opportunities
Exercise 3
The photographs represent a site walk, carried out at the time of audit.
Checklist Example:
Checklist Example:
Have they determined how these requirements apply to the organisation and the applicable
hazard?
Documentation information required. Company will normally have in place, a ‘Legal and Other
Register’ (LOR)
Control of Asbestos Regs Our factory roof is made from Asbestos External survey to be regularly carried out
It needs to be maintained in a safe condition Employee awareness training to be carried out
Regular internal site inspections to be carried out
Roof replacement to be reviewed
Actions for possible disposal to be formulated
Signage to be put in place
6.1.3 Legal Requirements
The auditor needs to be prepared before the audit regarding his / her knowledge of the possible
applicable legislation:
Do some research
The site walk on the day of the audit will also help to identify areas that are subject to legal
requirements – EG: Use of substances, lifting equipment, noisy environment.
Legal Requirements
Exercise 4
Working individually:
The task is to identify any Required Legislation if the works were still operating today
Legal requirements
Be measurable?
What will be done – Resources required – Who will be responsible – When it will be completed – How results
will how evaluated (Indicators) – Integration into the business processes
7 Support
7.1 Resources – Examples of resources include human, natural, infrastructure, technology and
financial.
7.3 Awareness – Contribution - Incidents – Risk assessments - Removal from dangerous work
situations (Refer to the standard)
Emergency preparedness plans can include natural, technical and man-made events that occur inside and
outside normal working hours.
Communicating and providing relevant information to all workers on their duties and Responsibilities
Effective Controls
Calibration/Maintenance
9.1.2 Evaluation of Compliance
The organisation shall establish, implement and maintain a process(es) to:
Determine and have access to up-to-date legal requirements and other requirements that are applicable to
its hazards, OH&S risks and OH&S management system
Determine how these legal requirements and other requirements apply, and what needs to be
communicated
Take these legal requirements and other requirements into account when establishing, implementing,
maintaining and continually improving its OH&S management system
The organisation shall maintain and retain documented information on its legal requirements and other
requirements and shall ensure that it is updated to reflect any changes.
9.2 Internal Audit
The organisation shall ensure that internal audits of the OH&S management system are conducted at
planned intervals
Audit Programme(s) shall be planned, established, implemented and maintained by the organisation, based
on the results of risk assessments of the organisation’s activities, and the results of previous audits.
Selection of auditors and conduct of audits shall ensure objectivity and the impartiality of the audit process.
9.3 Management Review
Top management shall review the organisation's OH&S management system, at planned intervals, to
ensure its continuing suitability, adequacy and effectiveness.
Trends in:
Incidents – Nonconformities – Evaluation of compliance – Audit results – Consultation and participation of
workers – Risks and opportunities
10.2 Incident, nonconformity and corrective action
The organisation shall establish, implement and maintain a process(es), including reporting, investigating
and taking action, to determine and manage incidents and nonconformities.
Checklist Example:
Role Play
Role Play
Step 1
All teams will be shown photographs to represent a site walk of Dicey Engineering company premises. The tutor
will act as company H&S Manager and respond to any arising questions from the teams. (Team members are to
take appropriate notes)
Step 2
Each Delegate will be given a specific photograph showing an issue viewed during the site walk of the company
premises/activities.
Using the photographs supplied by the tutor, select a photo to write up in the next exercise
Example Nonconformity Report
IRCA ISO 45001 AUDIT - NONCONFORMITY REPORT
Description of the nonconformity
During the audit there was evidence that identified any changes to Operational Controls resulting from previous
audit findings & resulting corrective actions (for the sub-contractors carrying out the cleaning activities), were not
effective and did not prevent recurrence
Relevant evidence
The corrective actions for incident reports numbers 57, 58, 59 and 60, for reported near misses
Non-conformances
Each team member is to write out a non-conformance on the hand-out and present it to
the tutor
The tutor, acting as the company representative, has to agree with the findings and
accept the non-conformance
Also, team members can assist one another, by referencing each others notes.
End of course
Course objectives
You now have the knowledge and skills required to perform first and second party
internal audits of
occupational health and safety management systems against ISO 45001 in
accordance with ISO 19011
and ISO/IEC 17021, as applicable.
Thank you
www.alcumusgroup.com