Most ISO 45001 nonconformities I see during stage 2 audits and internal reviews aren't hazard problems. They're paperwork problems: a legal register that hasn't been touched since it was created, a training record that doesn't match who's actually on the floor, an emergency plan that describes a building the company moved out of two years ago. The system was working. The documentation didn't prove it.
That gap exists because ISO 45001:2018 doesn't hand you a template. It tells you, clause by clause, what documented information you must have and whether you must maintain it or retain it, and leaves the format entirely up to you. That flexibility is the point of the standard, and it's also why so many organizations either over-document (binders nobody opens) or under-document (nothing an auditor can actually verify). This checklist walks through what clause 7.5 and its surrounding clauses actually require, in the order you'll build it.
What "Documented Information" Actually Means
ISO 45001 dropped the old OHSAS 18001 language of "documents" and "procedures" in favor of a single term: documented information. Clause 7.5.1 then splits that term into two distinct obligations, and the verb the standard uses tells you which one applies.
Maintain means the organization has to keep a current version of something — a policy, a process description, a plan — updated as conditions change. Retain means the organization has to keep evidence that something happened in the past and leave it alone. A policy is maintained. A training record is retained. Confusing the two is one of the most common documentation failures I see: an organization treats its legal register (which must be maintained, i.e., kept current) like a record, files it away, and doesn't touch it again until the next surveillance audit finds it three regulatory changes out of date.
Clause 7.5.1 note (b) also does something worth underlining: it explicitly states that the extent of documented information can differ from one organization to the next because of the size of the organization, its activities, processes, products and services, the complexity of its processes and their interactions, and the competence of persons. That single sentence is the standard's own permission slip for scaling documentation to the size of the business — a 12-person electrical contractor and a 400-person manufacturer are both certifiable under the same clause numbers, with very different volumes of paper behind them.
The Complete List of Required Documented Information
Here is every clause in ISO 45001:2018 that names a specific documented information requirement, what it covers, and whether the standard requires you to maintain it (keep current) or retain it (keep as evidence).
| Clause | Documented Information Required | Maintain or Retain |
|---|---|---|
| 4.3 | Scope of the OH&S management system | Maintain |
| 5.2 | OH&S policy | Maintain |
| 5.3 | Roles, responsibilities and authorities (to the extent necessary) | Maintain |
| 6.1.1 | Risks and opportunities needing action, and the processes needed to address them | Maintain |
| 6.1.2.2 | Methodology and criteria for hazard identification and risk assessment | Maintain |
| 6.1.3 | Legal requirements and other requirements | Maintain |
| 6.2.2 | OH&S objectives and plans to achieve them | Maintain |
| 7.2 | Evidence of worker competence | Retain |
| 7.4.1 | Internal and external communication process(es) | Maintain and Retain |
| 8.1.1 | Operational planning and control processes | Maintain and Retain |
| 8.2 | Emergency preparedness and response process and plans | Maintain and Retain |
| 9.1.1 | Results of monitoring, measurement, analysis and performance evaluation | Retain |
| 9.1.2 | Results of the evaluation of compliance with legal requirements | Retain |
| 9.2.2 | Internal audit programme and audit results | Retain |
| 9.3 | Results of management reviews | Retain |
| 10.2 | Nature of incidents/nonconformities, actions taken, and results of those actions | Retain |
That's roughly sixteen distinct sub-clauses spanning clauses 4 through 10, which is a smaller mandatory list than most people expect walking into their first ISO 45001 project. Everything else — job hazard analyses, permit-to-work forms, contractor qualification files, near-miss logs — is documentation your OH&S system needs to function, but it isn't named line-by-line in the standard. It falls under the "to the extent necessary" language in clauses like 6.1.1 and 8.1.1, which means you decide the format and auditors judge whether it's adequate for your risk profile.
Context, Leadership and Planning (Clauses 4–6)
This cluster is where the system's foundation gets written down: the scope statement (4.3) that defines which sites, activities, and workers the system covers; the policy (5.2) signed by top management; and the risk assessment methodology (6.1.2.2) that every hazard identification exercise downstream will follow. Get the scope wrong here and every audit finding traces back to it — I've seen certification bodies flag entire sites as "out of scope but performing OH&S-covered work" because the 4.3 statement was copied from a template and never adjusted to the actual operation.
Clause 6.1.3 deserves particular attention because it's the one most often left stale. It requires organizations to maintain documented information on their legal requirements and other requirements, not merely identify them once during initial registration. A legal register that was accurate in 2023 and hasn't been reviewed since is a maintained document that stopped being maintained — the exact failure mode clause 7.5.1's verb choice is trying to prevent. For a deeper walkthrough of building the hazard identification methodology this clause depends on, see our hazard identification resources.
Support and Competence (Clause 7)
Clause 7.2 requires retained evidence of competence — training certificates, qualification records, verified experience — for anyone whose work affects OH&S performance. Clause 7.4.1 requires both a maintained communication process describing what gets communicated, when, to whom, and how, and retained documented information as evidence that the communication took place. Clause 7.5 itself, covering creation, updating, and control of documented information, is procedural rather than a document you create once; it governs how every other document on this list gets approved, reviewed, and protected.
Operational Control (Clause 8)
Clause 8.1.1 is the broadest and vaguest-sounding requirement on the list, and it's also the one that generates the most paperwork in practice: maintain documented information "to the extent necessary to have confidence that the processes have been carried out as planned," and retain documented information to the extent necessary to have that same confidence after the fact. In plain terms, if a process is important enough to control, write down how it's supposed to work and keep evidence that it worked that way. Clause 8.2 narrows that down to one specific requirement: a maintained and retained emergency preparedness and response process, including the plans for responding to the emergencies your risk assessment actually identified.
Performance Evaluation (Clause 9)
This is the retention-heavy section of the standard. Clause 9.1.1 requires retained evidence of monitoring, measurement, analysis, and performance evaluation results. Clause 9.1.2 requires retained evidence of compliance evaluation results, tied directly back to the legal register from 6.1.3. Clause 9.2.2 requires a retained audit programme and retained audit results. Clause 9.3 requires retained evidence of management review outcomes. An auditor working through clause 9 is essentially checking whether the organization is watching itself, and these five records are how it proves the watching happened.
Improvement (Clause 10)
Clause 10.2 requires organizations to retain documented information as evidence of the nature of each incident or nonconformity, the action taken in response, and the results of that action including its effectiveness. This is usually the record set an auditor pulls first during a stage 2 audit, because it's the fastest way to see whether the whole system — hazard identification, risk assessment, corrective action — actually closes the loop or just generates paperwork that describes problems without resolving them.
Documents vs. Records: Why the Distinction Matters to Auditors
An auditor who understands clause 7.5.1's maintain/retain split will ask two different questions depending on which type of documented information is in front of them. For a maintained document, the question is "is this current?" For a retained record, the question is "did this actually happen, and can you prove it wasn't altered after the fact?"
That's why version control matters more for policies and procedures, while integrity and retrievability matter more for records. A policy with no revision date is a red flag. A training record that was edited after the training date, with no audit trail showing why, is a bigger one. Clause 7.5.3 requires documented information to be protected from loss of confidentiality, improper use, and loss of integrity — language written specifically to cover both failure modes.
How Much Documentation Does Your Organization Actually Need?
I get some version of this question from nearly every small business client before an implementation kicks off: does a 15-person roofing company need the same paperwork as a 500-person manufacturing plant? No — and clause 7.5.1's own scalability language backs that up. What changes is depth, not the list of clause requirements above. A small contractor's legal register might be four pages covering OSHA 1926 subparts and state licensing; a multi-site manufacturer's might run to sixty pages across federal, state, and local requirements at each location. Both satisfy clause 6.1.3. Neither is wrong.
Where organizations get into trouble is treating "small" as an excuse to skip a requirement rather than an excuse to right-size it. Clause 8.1.1's operational controls still have to exist for a five-person crew doing confined space entry — they just don't need a 40-page procedures manual to do it. A one-page checklist that's actually followed beats a comprehensive procedure that sits in a binder nobody has opened since the audit that required it.
Where Documentation Audits Usually Break Down
A few patterns show up repeatedly enough to be worth naming directly:
- The legal register stops being a living document. It gets built once for certification and never revisited, which violates the "maintain" obligation in clause 6.1.3 even if every entry was accurate on the day it was written.
- Competence records don't match the current workforce. Clause 7.2 evidence gets created for the people on staff during implementation and never updated as people are hired, promoted, or leave.
- Emergency plans describe a facility that no longer exists. A layout change, a new hazardous material, or a relocated muster point that never made it back into the clause 8.2 documentation.
- Corrective action records show the action but not the effectiveness check. Clause 10.2 requires evidence of results, including whether the action worked — not just that something was done.
- Objectives (6.2.2) exist on paper but aren't tracked against a plan. The standard requires plans to achieve the objectives, not just a list of aspirational targets.
None of these are hazard failures. They're documentation discipline failures, and they're also the fastest nonconformities to fix once you know exactly which clause governs them.
Controlling Documented Information: The Clause 7.5 Basics
Clause 7.5.2 covers creating and updating documented information: appropriate identification (title, date, author, reference number), an appropriate format, and review and approval for suitability and adequacy before use. Clause 7.5.3 covers control: documented information has to be available and suitable for use where and when it's needed, adequately protected, and controlled for distribution, storage, retrieval, retention, and disposition — including documents of external origin that the organization has determined are necessary for planning and operating the OH&S management system, such as a supplier's safety data sheet or a manufacturer's equipment manual.
None of this requires a specific software platform or a specific numbering scheme. It requires that when someone needs the current version of the emergency response plan, they can find it, and when someone needs to prove what the corrective action record said six months ago, that record hasn't quietly changed underneath them.
Building the Documentation Set in the Right Order
Organizations that build documentation in sequence spend far less time revising it than organizations that build everything simultaneously. A workable order looks like this:
- Scope (4.3) and policy (5.2) first, because everything else references them.
- Risk assessment methodology (6.1.2.2) and legal register (6.1.3) next, because operational controls can't be written until you know what you're controlling for.
- Objectives and plans (6.2.2) once the risk picture is clear.
- Competence evidence (7.2) and communication process (7.4.1) as the support layer.
- Operational controls and the emergency plan (8.1.1, 8.2) as the operational core.
- Performance evaluation and improvement records (clauses 9 and 10) last, since they document the system in motion rather than the system on paper. For the full document-by-document build sequence with templates, our required documents checklist walks through each item in more detail.
Frequently Asked Questions
Does ISO 45001 require a formal OH&S manual? No. Unlike some older management system standards, ISO 45001:2018 does not require a single consolidated manual. It requires the specific documented information listed in clauses 4 through 10, in whatever format the organization chooses.
How many mandatory documents does ISO 45001 actually require? There's a difference between "mandatory documents" and "named requirements," and that's usually where the confusion starts. ISO 45001:2018 names a specific documented information requirement at sixteen points in the standard, but a single one of those — clause 8.1.1's operational controls, for example — commonly turns into several separate documents once an organization runs more than one operational process.
What's the difference between a maintained document and a retained record under clause 7.5.1? Ask which mistake would be worse: the document being out of date, or the record having been altered after the fact. If it's the first, you're looking at something to maintain, like the OH&S policy or the legal register — it has to track current conditions. If it's the second, you're looking at something to retain, like a training certificate or a corrective action file — its entire value is proving, unchanged, that something happened at a specific point in time.
Can a small business use less documentation than a large manufacturer? Yes. Clause 7.5.1 explicitly states that the extent of documented information can vary based on organization size, activities, process complexity, and worker competence. Small businesses still need every clause requirement covered, just at a scale appropriate to their operation.
What documented information do auditors usually check first? In my experience, auditors reach for clause 10.2 records first because one corrective action file lets them trace a single problem end to end — how it was identified, how the risk was assessed, what was done, and whether it worked. It's a faster read on the whole system than starting anywhere else, and if that one file holds up, it's a good sign the rest will too.
If you want a structured walkthrough of how these clauses fit into a full certification project, our implementation guide covers the build sequence end to end.
Last updated: 2026-09-24
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.