QUESTION 42 An auditor has just completed an interview with a member of top management (TM), a highly experienced professional, but who has never worked within an ISO management system environment before. They want to take the opportunity to ask the auditor about a number of management system requirements. As the interview has finished a little early, the auditor agrees. Which three of the following auditor responses are correct?
The three correct responses are A, B, and G . A is correct because ISO 45001 Clause 5.3 requires top management to ensure that the responsibilities and authorities for relevant roles are assigned, communicated and understood at all levels within the organization , and that they are maintained as documented information . So if top management asks whether responsibilities and authorities for relevant roles have to be documented, the correct answer is yes . B is correct because Clause 5.1 Leadership and commitment requires top management to ensure that the resources needed to establish, implement, maintain and improve the OH and S management system are available . Therefore, the auditor’s “Yes, you do” is correct. G is correct because Clause 5.1 also requires top management to promote continual improvement . This is stated directly as part of top management leadership and commitment responsibilities under ISO 45001. Why the others are not correct: * C is incorrect because top management does have to ensure that processes are established for consultation and participation of workers . Clause 5.4 makes this a requirement, so “No, you do not” is wrong. * D is incorrect as written. Top management must establish, implement and maintain the OH and S policy, but ISO 45001 does not state that top management personally has to “write” it. The wording in the option is too specific and not how the standard states the requirement. * E is incorrect because top management does have to ensure that the OH and S management system achieves its intended results. Clause 5.1 says this directly. * F is incorrect because top management must ensure OH and S objectives are established and compatible with the strategic direction, but ISO 45001 does not require top management personally to “write” the objectives. * H is incorrect because the organization must determine the scope under Clause 4.3 , and top management remains accountable for the OH and S management system. Saying “No, you do not” is not correct in this context.
QUESTION 43 XYZ Corporation is an organisation that employs 100 people. As an audit team leader, you are conducting a certification audit at Stage1. When reviewing the OH and S management system (OHSMS), you find that the objectives have been defined by an external consultant using those of a competitor, but nothing is documented. The Health and Safety Manager complains that this has created a lot of resistance to the OHSMS, and the Chief Executive Is asking questions about how much It will cost. Select two erf the options which describe the circumstances h which you could raise a nonconformity against clause 0.2 of ISO 45001.
Clause 0.2 of ISO 45001 emphasizes the involvement of top management and alignment of OH and S objectives with the organization’s OH and S policy. * Nonconformities Identified: * The objectives were developed by an external consultant without involving top management, which undermines leadership accountability and commitment. * The objectives were based on a competitor’s framework, not aligned with the organization’s unique OH and S policy or context. * Analysis of Options: * A. Establishing OH and S objectives did not include top management. True. Clause 5.1 (Leadership) and Clause 6.2 (Objectives) emphasize that top management must be involved in defining and supporting OH and S objectives. * B. OH and S objectives are not being implemented by personnel. Implementation relates to operationalization, not the development phase, and is not relevant to Clause 0.2. * C. OH and S objectives are not maintained as documented information. While documentation is required, the absence of documented information is a separate issue under Clause 7.5, not Clause 0.2. * D. OH and S objectives were not established in alignment with the organization’s OH and S policy. True. Clause 6.2.1 requires objectives to align with the OH and S policy, which reflects the organization’s commitment to safety and health. * E. The consultant has not interpreted ISO 45001 correctly. While possibly true, the issue here is the organization’s failure to involve top management, not the consultant’s interpretation. * F. The organization cannot afford to undertake OH and S objectives all at once. Financial constraints are not relevant to Clause 0.2; objectives can be prioritized for phased implementation. ISO References: * Clause 0.2: Leadership commitment and alignment with organizational policy. * Clause 5.1: Top management’s role in leadership and participation. * Clause 6.2.1: Establishing OH and S objectives aligned with the policy.
QUESTION 48 You are conducting a Stage 2 certification audit to ISO 45001 at an adventure park in the Scottish Highlands. The park offers treetop walks, zip-line rides, walking trails, and horse-riding trips. The park is open to adults and children of any age. You are particularly interested in compliance with legal requirements and interview the Park Manager. You: How do you evaluate the risks to participants that the various activities present? Park Manager: Our risks are covered by insurance, and we operate under health and safety legislation that requires frequent checks of all our facilities. For example, we trust staff to check all our harnesses every morning. You: Are you required to have an independent inspection carried out of zip lines, for example? Park Manager: Yes, our insurance company employs a reputable body to do that sort of thing. You: Can you show me a copy of the latest inspection report? Park Manager: I’d need to get that from the insurance organisation. I have the initial one when we opened eight years ago. You examine the inspection report, which takes the form of a checklist that does not identify individual zip lines, treetop platforms, harnesses, or rope ladders. It is dated eight years previously and has a scribbled signature with no other identification of the inspection engineer. Select the two statements for which there is evidence of a nonconformity to ISO 45001. Select two statements.
ISO 45001 requires organizations to identify and maintain documentation to demonstrate compliance with legal and other requirements (Clause 7.5 and Clause 9.1.2). It also requires the evaluation and control of outsourced processes (Clause 8.1.4.3). Analysis of Options: * A. The park did not have the required documentation to demonstrate compliance with legal requirements:Correct. The outdated and incomplete inspection report (8 years old, lacking detailed identification) fails to demonstrate compliance with health and safety legislation. * B. The organization did not monitor the safety checks by staff of equipment:Incorrect. While there is a potential gap in monitoring, the evidence provided does not directly indicate a lack of monitoring of staff checks. * C. The inspection organization employed by the insurance organization was not evaluated: Correct. ISO 45001 requires the organization to evaluate outsourced services, including those provided by the inspection body, to ensure their adequacy. * D. The park relied on the insurance organization to evaluate its OHS risks:Incorrect. Reliance on external evaluations may not constitute a nonconformity if risks are properly managed, but there is no evidence provided for noncompliance here. * E. Testing to determine the safe loading of equipment was not carried out:Incorrect. While load testing is crucial, there is no evidence presented to confirm this specific issue as a nonconformity. ISO References: * Clause 7.5: Control of documented information. * Clause 8.1.4.3: Control of outsourced processes. * Clause 9.1.2: Evaluation of compliance.
QUESTION 50 According to ISO 45001, who should participate in the continuous improvement of the health and safety management system?
ISO 45001 emphasizes worker participation and engagement at all levels of the organization to support continuous improvement (Clause 5.4 and Clause 10.3). Continuous improvement requires input from everyone, including workers who identify hazards, report incidents, and contribute to safety enhancements. Analysis of Options: A . Everyone, at all levels of the company: Correct. Clause 5.4 explicitly includes all levels of the organization in consultation and participation, fostering continuous improvement. B . Top management and senior officers only: Incorrect. While top management plays a crucial role in leadership, ISO 45001 extends the responsibility for participation to all levels. C . Top management, senior officers, and designated safety representatives only: Incorrect. Limiting participation to designated representatives excludes a significant portion of the workforce from the improvement process. D . Top management only: Incorrect. While top management must lead and commit to continuous improvement, their involvement alone is insufficient under ISO 45001. ISO Reference: Clause 5.4: Worker consultation and participation. Clause 10.3: Continual improvement.
QUESTION 52 As a third-party auditor, you must audit company ABC, which has agreed with the Certification Body that the scope will be ” manufacture of food for domestic animals ” . They have recently bought the company XYZ across the road, which can manufacture the packaging materials for their food products. They have implemented a single OHS management system (ISO 45001) for both plants. However, for marketing purposes, they want to certify the management system for the food manufacturing only. They argue that XYZ has the role of a supplier. What would be your response? Select one
The correct answer is D . ABC states that it has implemented one single OH and S management system for both plants . Once a single management system covers both sites, the certification body has to determine and audit the scope of the management system being operated , not an artificially narrowed commercial scope. IAF MD 1 says a multi-site organization has a single management system , and the certification body must confirm that a single management system is deployed and determine the scope of the management system being operated . It also says the certification document must reflect the scope of certification and the sites/legal entities covered by that multi-site certification. ( IAF ) The argument that XYZ is “just a supplier” does not solve the problem. IAF MD 5 makes an important distinction: where an external provider is only a supplier, the certification body audits the organization’s control of the supplied activity, not the performance of the activity itself . But here, XYZ is not outside the management system; ABC has already said both plants are inside one single OHSMS . So XYZ cannot simply be treated as an external supplier for certification-scoping purposes. ( IAF ) This is also consistent with the multi-site certification rules that do not allow an organization to exclude covered sites just to avoid certification consequences. IAF MD 1 explicitly says it is not admissible to exclude a problematic site from scope during certification, and the certification documents must show the sites covered by the certified system. While this example is about a “problematic” site, the principle is the same: once the site is part of the single management system, it cannot be carved out simply for convenience or marketing. ( IAF ) Therefore, as a third-party auditor, you should not agree to audit only the food plant while ignoring the packaging plant if both are included in the same ISO 45001 management system.