ISO 45001:2018 auditors do not certify manuals. They certify documented information that proves the OH&S management system operates, and they look hardest at clauses 6, 8, 9, and 10, where the documented information is thinnest in most organisations. A folder of scanned PDFs is technically compliant but operationally embarrassing — it forces the auditor to ask the same question five times because the answer is not retrievable. SiteGuard was architected around exactly this problem: every domain object in the platform, from Sites to Daily Plans to Visits to Violations to Corrective Action Programs, is a piece of documented information the auditor will ask to see, and each maps cleanly to a specific ISO 45001 clause. This guide walks HSE managers and compliance officers through the clause-by-clause evidence map, so the next surveillance audit takes a half-day export rather than a week of evidence-gathering.

What your auditor actually wants #

ISO 45001:2018 clause 7.5 requires documented information to be identifiable, retrievable, and protected. The auditor's opening question, in practice, is rarely about whether you have documented information — it is about whether you can retrieve it in a format they can verify in minutes. The fastest way to fail a surveillance audit is to make the auditor wait while you reformat data, search emails, or rebuild a spreadsheet. SiteGuard inverts this dynamic: every Visit History record, every violation, every closed Corrective Action Program is retrievable in seconds through filtered views, with GPS stamps, Photo Evidence, inspector IDs, and timestamps attached. The auditor asks for site 14 in March; you produce a filtered view in 30 seconds that shows every visit, every checklist, every violation, and every closed CAP for that site and that month. That is what a safety management system is supposed to feel like.

Clauses 4 to 5 — Context, leadership, and worker participation #

Clause 4 requires the organisation to determine its context, the needs of interested parties, and the scope of the OH&S system. Clause 5 requires top-management leadership, a safety policy, and clear roles and responsibilities, plus worker participation in the system. SiteGuard satisfies clause 4 through Company Scope (the multi-entity container that defines the OH&S system's operational boundary) and Sites (the master record of every location in scope). Clause 5 is satisfied through Users & Roles, which assigns top-management, HSE-manager, and inspector roles with explicit permissions, and through Worker Compliance, which gives every worker a Safety Profile that records their participation in the system. The SiteGuard Manager dashboard itself is the visible manifestation of top-management leadership — the HSE director and the operations director see the same data, in real time, which is what clause 5.1 (leadership commitment) actually looks like in production.

Clauses 6 to 7 — Planning and support #

Clause 6 covers planning: hazard identification, OH&S risk assessment, legal and other requirements, and OH&S objectives. Clause 7 covers support: resources, competence (typically evidenced through NEBOSH, IOSH, or equivalent safety-officer certifications), awareness, communication, and documented information. SiteGuard satisfies both clauses through the same set of features, because planning and support are operationally inseparable on a real site — the hazard register feeds the checklist template, which feeds the daily plan, which feeds the inspector's competence record. The four-item mapping below shows how each feature produces documented information for both clauses simultaneously.

Clause 8 — Operational control #

Clause 8 is where paper-based systems collapse. It requires operational planning and control of OH&S risks, including management of change, procurement (contractor evaluation), and emergency preparedness. SiteGuard satisfies clause 8.1 through Daily Plan Management (status, reviewer, approval), Plan Approval (second pair of eyes on high-hazard sites), GPS Check-in (proof the inspector was on site), Dynamic Checklists (site-adaptive controls), and Photo Evidence (audit-grade artifacts attached to every checklist item). Plan Actions also feed clause 8 — they capture the supplementary tasks (permit verification, gas test, toolbox talk) that operationalise the risk register on a given site on a given day. For a tier-1 contractor on a NEOM site, clause 8.1 is the clause the auditor will spend the most time on, because it is where the documented information has historically been weakest.

Clause 9 — Performance evaluation #

Clause 9 covers monitoring, measurement, analysis, evaluation, internal audit, and management review. It is the clause most often cited in audit findings, because the documented information here is the most perishable — visit logs disappear, violation trends remain invisible, and corrective action closures lag. SiteGuard satisfies clause 9.1.1 (monitoring) through Visit History (a filterable ledger of every GPS-stamped visit), clause 9.1.2 (evaluation) through Response Review (the manager-side queue that reviews submitted checklist responses per plan with approval), clause 9.2 (internal audit) through Compliance Reporting (which aggregates plans, violations, and certificates into an exportable evidence pack), and clause 9.3 (management review) through Recent Violations and Visit History trend views that surface leading and lagging indicators for the HSE director's quarterly review. The four-item mapping below shows how each sub-clause maps to a specific SiteGuard feature.

Clause 10 — Improvement and CAPA #

Clause 10 is the clause that distinguishes a documented OH&S system from a working one. It requires the organisation to react to incidents and nonconformities, take action to control and correct them, deal with the consequences, and evaluate the need for corrective action to eliminate the root cause. SiteGuard operationalises clause 10.2 through the five-stage closed loop: Violation Reporting creates the record with type, priority, Photo Evidence, and forfeit; Recent Violations surfaces it for review; Violation Closure drives it through statuses (Open, In Review, Corrective Action Assigned, Closed); Corrective Action Programs defines the required correction with types and certificates; Assigned Actions tracks the responsible user until the certificate is issued. The certificate is the auditor's primary evidence that the organisation has not merely logged the issue but has demonstrably corrected it. Without that certificate, the violation is, in auditor terms, still open.