New: ISO 42001 and NIS2 Supply Chain are available in the Compliance Tool.Explore standards and requirements →Careers
ISO 45001 · Occupational health and safety

ISO 45001: Compliance Tool and internal audits

For organisations that want a systematic approach to occupational health and safety. DCA supports you with the Compliance Tool and internal audits: from oversight of arrangements and evidence to following up improvement actions.

ISO 45001 for occupational health and safety

ISO 45001 is the international standard for an occupational health and safety management system. It helps organisations systematically manage workplace hazards and risks and improve their approach. Topics include leadership, employee involvement, working conditions and learning from incidents. These are topics within the standard; the support you need depends on your organisation.

DCA supports organisations that want to implement ISO 45001 or maintain their existing approach through the Compliance Tool and internal audits. We help organise agreed activities, responsibilities and follow-up. Your day-to-day operations are the starting point.

The current published edition is ISO 45001:2018, with amendment 1:2024 on climate change. This requires attention to the relevance of climate change in the organisational context. SCCM explains that the Dutch and European designation NEN-EN-ISO 45001:2023 has the same content as ISO 45001:2018. A future draft version does not replace the current edition.

Common questions within your organisation

  • Where are the current occupational health and safety arrangements and evidence of implementation?
  • Who is responsible for a control and when must it be implemented?
  • What should we prepare for the internal audit, and which employees should be involved?
  • What have we done with previous findings, and how can we see which improvement actions remain open?
  • Can we align the organisation of ISO 45001 with our existing quality and environmental management?

The Compliance Tool supports oversight. An internal audit examines whether arrangements within the selected scope are demonstrably implemented and effective. Together, we clarify what DCA handles and which actions remain with you.

How does the Compliance Tool help?

With the Compliance Tool you manage requirements, activities and supporting evidence in one environment. For ISO 45001, we use the Tool’s existing capabilities:

  • Connect risks and controls: record the risks you have identified and the associated controls, and track follow-up.
  • Allocate tasks: assign owners and deadlines so it is clear who carries out each action.
  • Store documents and evidence: keep policies, procedures and supporting evidence easy to find alongside the relevant requirement or control.
  • Organise audits and findings: record audit findings and connect them to concrete improvement actions.
  • Track progress: see what has been completed, where evidence is missing and which actions still need attention.

We align the setup with your existing practices and available information. The Tool supports the organisation of work; you assess the content, implement controls and keep information current.

Request a demo →

What does our internal audit involve?

An internal audit provides insight into the effectiveness of your occupational health and safety management system. We assess the agreed components against ISO 45001 and your own arrangements. We review documents and evidence, speak to those involved and examine how arrangements are implemented in practice.

  1. Preparation and scope. We discuss the audit objective, activities, locations, organisational units and topics you want assessed. We also agree audit criteria, employees involved, previous findings and planning in advance.
  2. Gather information. You make the agreed documents and records available. We agree who can explain the approach and how we will examine implementation.
  3. Carry out the audit. We examine whether the agreed approach is demonstrably applied. We distinguish what is documented, what happens in practice and where supporting evidence is missing.
  4. Discuss the report. You receive findings with supporting evidence, areas requiring attention and improvement priorities. We agree in advance whether the report is delivered in the Compliance Tool or as a standalone audit report.
  5. Follow up improvements. We discuss the next steps. You assign actions, implement improvements and record evidence. We agree any support or further assessment separately.

For an objective assessment, we agree roles and reporting arrangements. An auditor does not approve their own work. The specific audit assignment determines its extent and execution; a statutory RI&E review is not automatically included.

Discuss your ISO 45001 internal audit →

How should you prepare for the audit?

Gather information relevant to the agreed scope. Consider your occupational health and safety policy and objectives, responsibilities, relevant procedures, risk information and the status of improvement measures. An existing Dutch occupational risk inventory and evaluation (RI&E) and action plan may provide relevant input.

Also include previous audit findings and available records. Information about incidents, instructions and employee involvement, for example, can show how you implement your approach. We agree in advance which documents are relevant and who will explain their way of working. This does not mean every topic is automatically included in the audit assignment.

Make open issues visible. Missing documentation or a control that still needs implementing is useful information for preparation. The team does not need to present work as complete when it is not yet complete in practice.

What does DCA do and what remains your responsibility?

  • DCA: provides the Compliance Tool, agrees the setup and audit assignment, carries out the agreed internal audit and discusses findings and next steps.
  • Your management: sets objectives and priorities, allocates time and resources and decides on improvements.
  • Your team: provides accurate information, applies arrangements, implements controls and involves the employees who know the work.
  • A certification body: conducts the certification audit if required and decides independently on the certificate.

Our internal audit does not provide an ISO certificate. Using software or having an audit also does not guarantee full legal compliance or an accident-free workplace. The organisation remains responsible for occupational health and safety in day-to-day practice.

How does ISO 45001 relate to the RI&E?

A Dutch occupational risk inventory and evaluation (RI&E) identifies workplace risks; the associated action plan describes the measures. ISO 45001 helps organise ongoing occupational health and safety management, with responsibilities, implementation, assessment and improvement. The RI&E and action plan can form an important foundation.

The Dutch obligations concerning the RI&E and its review continue to apply separately. An ISO 45001 certificate or internal audit does not automatically replace the RI&E or a required review by a qualified expert. Whether such a review is mandatory and what expertise is required depends on the applicable rules and your situation. Our internal audit assignment does not automatically include that statutory review.

Organise ISO 45001, ISO 9001 and ISO 14001 together

Occupational health and safety, quality and the environment often concern the same activities. Consider responsibilities, document management, audit planning and following up improvements. Aligning these organisational arrangements allows the team to work with a coherent approach.

According to SCCM the shared structure of these management system standards makes it possible to combine them. Where appropriate, you can organise policies, meetings and recurring tasks together. The Compliance Tool enables requirements, tasks and evidence to be managed under the relevant frameworks.

Keep clear which topic belongs to which standard. Shared documents or a combined schedule do not remove the individual requirements. For an audit, we agree which standards and components will be assessed.

Working with SPOTTEN

DCA supports SPOTTEN with ISO 45001 through the Compliance Tool and internal audits.

Discuss the resources required and schedule

The extent of the audit depends on the agreed scope, locations and processes involved, available documents and previous findings. The availability of employees and the auditor, and your preferred deadline, also play a part.

Use the audit form to specify ISO 45001, your preferred scope and date. We review the request and discuss resources, reporting and planning. We make appropriate arrangements for software use and any additional support; also view the general cost breakdown.

Frequently asked questions about ISO 45001

How does DCA support ISO 45001?+

With the Compliance Tool for requirements, tasks, responsibilities, documents and improvement actions, and with internal audits. We agree which support and audit topics fit your organisation.

What does an internal audit involve?+

We assess the agreed components of your management system against ISO 45001 and your own arrangements. We review evidence, speak to those involved and examine implementation. You receive findings and discuss priorities and next steps with us.

How should we prepare for the audit?+

First agree the scope and objective. Then gather the relevant policies, roles, procedures, risk information, previous findings and evidence of implementation. Ensure the employees involved can explain how they work.

How does the Compliance Tool help?+

The Tool connects requirements, risks, controls, tasks and evidence. You assign owners, store documents, record audit findings and follow up improvements. Content and day-to-day implementation remain with your organisation.

How does ISO 45001 relate to the RI&E?+

The RI&E and action plan can provide input for the management system. ISO 45001 helps organise the approach on an ongoing basis. Statutory RI&E obligations continue to apply; our internal audit does not automatically include a legally required RI&E review.

What is the difference between an internal audit and a certification audit?+

Our internal audit shows how the agreed components are established and work, with findings for improvement. A certification body carries out the certification audit and decides on the certificate. DCA does not guarantee a certification outcome.

How can ISO 45001, ISO 9001 and ISO 14001 be organised together?+

Align shared elements such as document management, responsibilities, audit planning and improvement actions. The standards share a common structure but retain their own requirements. We agree the scope of any combined audit in advance.

Sources and current edition of the standard

Sources checked: 19 September 2026. This explanation uses the published edition of the standard and official guidance:

Define your ISO 45001 requirements

Discuss which components you want audited, or explore how the Compliance Tool can support your work.

Prefer to discuss things first? Contact us.