The 7 findings that fail ISO 45001 audits most often
Certification and surveillance audits fail on a remarkably consistent set of issues. None of them are obscure, all of them are fixable in advance, and almost all of them are visible before the auditor arrives if you know where to look.

Auditors are not looking for creative failures. They work through the standard systematically, and the same weak points surface again and again, because they are the parts of ISO 45001 that require genuine organisational behaviour rather than a document. Here are the seven we see most, what the finding actually says, and how to close each one properly.
1. Worker consultation exists in theory, not in evidence
The clause: 5.4, consultation and participation of workers.
What the finding says: the organisation cannot demonstrate that non-managerial workers were consulted on hazard identification, control selection, incident investigation or procedure development.
This is the most distinctive requirement ISO 45001 introduced over OHSAS 18001, and it is where systems built by consultants in isolation fail most reliably. A safety committee that exists on an organisation chart, or a suggestion box nobody empties, is not consultation. Auditors will ask a worker directly: “Were you asked about the risks in this task?”
Minuted safety committee meetings with named non-managerial worker representatives present and contributing. Risk assessments signed by the people who actually perform the task. Incident investigations that include a worker on the team. Records showing worker input changed something. That last one carries the most weight.
2. PPE presented as the primary control
The clause: 8.1.2, eliminating hazards and reducing OH&S risks.
What the finding says: the hierarchy of controls has not been applied in the required order; controls default to PPE and administrative measures without documented consideration of elimination, substitution or engineering controls.
The standard is explicit about the order: eliminate, substitute, engineering controls, administrative controls, PPE. Risk assessments listing “wear gloves and safety glasses, toolbox talk” as the whole control set for every hazard tell an auditor the hierarchy was never genuinely applied.
Restructure your risk assessment form so each level of the hierarchy is a separate field the assessor must address, with a justification when a higher control is rejected as impracticable. This single form change closes the finding and improves the assessments materially.
3. Root cause recorded as “human error”
The clause: 10.2, incident, nonconformity and corrective action.
What the finding says: corrective actions address symptoms rather than causes; the effectiveness of actions taken has not been reviewed; similar incidents have recurred.
“Operator was careless: retrained” is the single most common entry in UAE incident records, and it is almost never the root cause. If an operator could take a dangerous shortcut, the questions are why the shortcut was available, whether the safe method was practicable under time pressure, whether supervision was present, and whether others do the same thing.
Adopt a structured method (five whys is sufficient for most incidents) and require the investigation form to record each step. Add a mandatory effectiveness review field with a date, typically three months out. Then actually complete it, because auditors check whether the review happened.
4. A legal register with no local law in it
The clause: 6.1.3, determination of legal requirements and other requirements.
What the finding says: the register of legal and other requirements is generic and does not reflect requirements applicable in the jurisdiction of operation, or has not been evaluated for compliance.
Registers imported from an international template, listing legislation from other countries and no UAE federal law, no Abu Dhabi framework requirements and no permit conditions, are common. The related failure is having a good register and never evaluating compliance against it.
Rebuild the register around UAE federal law, your Sector Regulatory Authority's requirements, the applicable ADOSH Codes of Practice and your own permit and licence conditions. Then run a documented compliance evaluation and retain the result. See ADOSH-SF v4.0 compliance.
5. Subcontractors operating outside the system
The clause: 8.1.4, procurement, contractors and outsourcing.
What the finding says: the organisation has not adequately coordinated OH&S arrangements with contractors, or cannot demonstrate that contractor competence and controls were verified.
This finding is near-universal in construction and facilities management. The main contractor's own system is sound; the subcontractor working under its control has never been assessed, its personnel competence is unverified, and its risk assessments are unseen. Auditors sample subcontractor records precisely because they know this.
Document OH&S pre-qualification criteria for contractors, verify competence records before mobilisation, require and review their risk assessments and method statements, include them in inductions and toolbox talks, and monitor their performance with records. Their incidents must enter your incident data.
6. Management review missing mandatory inputs
The clause: 9.3, management review.
What the finding says: the management review did not consider all required inputs, or outputs and decisions were not recorded.
Clause 9.3 lists its required inputs explicitly: status of previous actions, changes in internal and external issues, extent to which objectives were met, incident and nonconformity data, audit results, consultation outcomes, risks and opportunities, and adequacy of resources among them. Minutes that record “safety discussed, no issues raised” are an immediate finding, and this one is entirely self-inflicted.
Build your management review agenda directly from the clause, with one heading per required input. Minute each heading, even where the answer is that nothing changed. Record decisions, actions, owners and dates as outputs. This converts the most avoidable finding in the standard into a fifteen-minute administrative task.
7. Emergency plans that have never been tested
The clause: 8.2, emergency preparedness and response.
What the finding says: emergency response arrangements have not been periodically tested, or the results of testing have not been used to review and improve the plans.
Almost every organisation has an emergency plan. Far fewer can produce drill records for the current year, and fewer still can show that the drill revealed anything and that the plan changed as a result. A drill in which everything went perfectly is treated by experienced auditors as a drill that was not taken seriously.
Schedule drills across the year covering your actual credible scenarios, not only fire. Record the date, participants, timings, what went wrong and what was changed afterwards. Cover scenarios specific to your operations: chemical spill, confined space rescue, heat illness, power failure, medical emergency on a remote site.
What to check the week before your audit
A short list you can work through yourself. Each item corresponds to a finding above.
Open findings carried over from your previous audit. A single unclosed action suggests an isolated lapse; several suggest the corrective action process itself does not work, and that is a systemic finding against clause 10.2, regardless of how minor the original items were. Close last year's findings before this year's audit, without exception.
A pre-certification readiness audit simulates the Stage 2 assessment so nothing is a surprise on the day. Two to three days, findings you can still fix, and no consequences for failing. See internal auditing or book a consultation.

Let’s make your next audit a non-event.
Book a free 30-minute consultation. We will tell you honestly whether you need a consultant, and if you do, exactly what it will take.