ISO management systems

ISO 45001 Internal Audit vs Certification Audit

ISO 45001 involves two kinds of audit. Internal audits are carried out by or for the organisation itself, to check that its own system works. Certification audits are carried out by an independent certification body, to decide whether the system meets the standard. They use similar techniques but serve different purposes.

Internal audit

ISO 45001 requires organisations to carry out internal audits at planned intervals, to check that the management system conforms to the standard and to the organisation’s own requirements, and that it is effectively implemented and maintained.

  • Who carries it out: competent people who are objective and impartial about what they audit. They can be employees from another part of the organisation or an external auditor.
  • What it is for: finding problems and improvement opportunities before anyone else does.
  • Guidance: ISO 19011 gives guidance on auditing management systems and is widely used for internal audit programmes.
  • Output: findings reported to management, followed by corrective action, and fed into management review.

Certification audit

A certification audit is an independent assessment by a certification body, ideally one accredited for ISO 45001. In the UK, UKAS accredits certification bodies, which work to ISO/IEC 17021-1.

  • Initial certification: a Stage 1 readiness review and a Stage 2 assessment of whether the system is implemented and effective.
  • Ongoing: surveillance audits during the three-year cycle and a recertification audit at the end of it.
  • Output: a certification decision, with any nonconformities that must be addressed.

The main differences

Internal auditCertification audit
Carried out byCompetent, impartial internal or external auditorsAn independent certification body
PurposeCheck and improve your own systemDecide whether to certify against the standard
FrequencyAt intervals you plan, based on risk and resultsStage 1 and 2, then surveillance and recertification
ResultFindings and corrective actionsCertification decision

How internal audit prepares you for certification

A well-run internal audit programme is the best preparation for a certification audit. Before recommending certification, a certification body normally expects to see that internal audits and a management review have been completed, and that findings were acted on.

Can a consultant carry out your internal audits?

Yes, and many organisations use an external auditor for some or all of their programme. The important point is impartiality: someone who designed or wrote part of your system should not be the only person auditing that part of it. We discuss this with every client. See our ISO 45001 consultancy and why consultants and certification bodies are kept separate.

Frequently asked questions

Do internal auditors need a lead auditor qualification?

ISO 45001 does not require a specific qualification. It requires internal auditors to be competent, objective and impartial. Training in management system auditing is a common way to demonstrate competence.

How often should ISO 45001 internal audits happen?

At planned intervals that you set, taking account of the importance of the processes, changes and the results of previous audits. Many organisations cover the whole system over a year.

Can the certification body do our internal audit?

No. An accredited certification body cannot provide internal audits or consultancy to an organisation it certifies, because that would compromise its impartiality.

This guide gives general information about UK health and safety law. It is not legal advice, and duties remain with the employer and other dutyholders.

Planning an ISO 45001 or ISO 14001 project?

Featherstone Safety is an independent consultancy supporting organisations in London and across the UK to implement and maintain ISO management systems. We scope every project before quoting, and we do not issue certificates.

Try the ISO 45001 readiness checklist