← Back to all posts
October 3, 2026TechRevati

ISO 45001 and the video record: what a camera can give an auditor, and what it cannot

An ISO 45001 auditor does not ask for video. They ask for documented information that shows your management system works. Here is where a camera-backed record fits the standard, and where it does not.

  • workplace-safety
  • iso-45001
  • documented-information
  • audit

Does an ISO 45001 auditor want to see camera footage?

No. An auditor checks whether your occupational health and safety management system works, and asks for documented information that shows it. Footage is not documented information on its own: nobody can audit three weeks of video, and a clip says nothing about how often something happens or what you did about it.

A camera can still help, in a narrow and specific way. It can turn what happens in a few defined places on site into a record with a time, a place and a source. That record can then be counted, reviewed and kept under control. The rest of this article goes clause by clause: where such a record fits ISO 45001:2018, and where it does not.

Where does a camera record fit in hazard identification (§6.1.2)?

It shows where a hazard you have already identified actually occurs, and how often. §6.1.2 asks you to identify hazards on an ongoing basis and to assess the risks. A risk assessment usually rests on walk-throughs, incident reports and the experience of the people who work there. All of these are valuable, and all of them miss what nobody reported.

If you have defined a hazard, for example a pedestrian in a forklift lane, a camera can record each time that situation occurs in the zone you drew. That does not identify new hazards for you, and it does not assess risk. It gives the people who do the assessment an observed frequency where they used to have an estimate.

Can a camera record count as documented information (§7.5.2 and §7.5.3)?

Only if it is created and controlled the way the standard asks; a folder of exported clips is not. §7.5.2 asks for identification and description (a title, a date, an author, a reference number), the right format, and review and approval. §7.5.3 asks for control: access, storage, protection against unintended alteration, change control, retention and disposition.

The question an auditor can ask of any digital record is: how do I know this has not been changed since it was made? A record built for audit answers that without you in the room. It carries a cryptographic signature made on the camera when the event was detected. It sits in a registry where any later change is detectable. And the report that summarises it carries its issue, its author and a block for the approval a person gives it.

None of that makes the record true. It makes it verifiable: the auditor can check that what they are reading is what was recorded, and when.

Does a camera help with monitoring and measurement (§9.1.1)?

Yes, in two ways, and the second is the one auditors rarely see.

The first is the obvious one. §9.1.1 asks you to determine what is monitored and measured, how, and when, and to evaluate the results. Event counts per zone, per type and per period are a measurement you can repeat, taken continuously rather than reconstructed from injury reports. They are a leading indicator: they show how often a hazardous situation occurs, not how often someone got hurt.

The second matters more for the audit. §9.1.1 also asks for documented evidence of the maintenance, calibration or verification of measuring equipment. If a camera produces a safety figure, the camera is a measuring instrument. An auditor is entitled to ask whether it was working. Was its view blocked? Was it pointed where the zones were drawn? Was its clock right? Did anyone change its configuration?

A record that cannot answer those questions is a number without provenance. A record that states them per camera and per period is evidence for the instrument as well as for the events.

How does it support incident investigation and corrective action (§10.2)?

It gives the investigation a fixed starting point, and it lets you check afterwards whether the corrective action worked. §10.2 asks you to react to incidents, investigate their causes, take action, and review whether the action was effective.

A record with a time, a place, a duration and an integrity check tells the investigation exactly when and where to look. The cause, the action and the decision remain your HSE process. What the record adds comes later. If you change a traffic route, move a barrier or retrain a shift, you can compare the same zone before and after, measured the same way. "Did it work?" then has a number for an answer instead of an impression.

What does a camera not do?

It does not replace your risk assessment, it does not decide anything for people, and it does not make your management system compliant by itself. Say this to your auditor before they say it to you.

  • It does not assess risk. It records occurrences of situations you defined. Which hazards matter, how serious they are and what to do about them stays with competent people.
  • It does not decide. A record is a prompt for review. People decide what an event means and whether to act on it.
  • It does not prevent anything. It records what happened. Whatever changes on site because of it is a change you made.
  • It is not compliance. ISO 45001 is a management system: leadership, worker participation, planning, competence, operational control, evaluation, improvement. A record supports some of those clauses. It does not stand in for any of them.
  • It is personal data before it is anything else. A camera on a workplace processes data about the people in view. Before it records anything, you need a lawful basis, information for workers and visitors, and, in most cases, a data protection impact assessment. Where it applies, worker representatives must be consulted too. A record meant for safety must not become a tool for monitoring or rating individual workers.

What should you ask a supplier before relying on a camera record in an audit?

Ask the questions the auditor will ask you:

  1. Can someone other than you verify the record? Ask how anyone can check that it was not altered after it was made, and whether a third party can do that without the supplier.
  2. Does the record state its own reliability? Ask whether you can show, per camera and per period, that the camera was seeing, was aimed correctly and kept the right time.
  3. Is the report controlled documented information? Look for a reference, an issue, an author, an approval block, a retention period and a change history.
  4. What is kept, for how long, and who can see it? The shorter and narrower, the easier it is to defend to workers and to a data protection authority.
  5. What does the supplier say it does not do? A supplier who promises compliance, prevention or proof is selling something an auditor will not accept.

A camera gives you a verifiable record of what happened in a few places you chose. Your management system decides what that record is worth.


Check whether your cameras can produce such a record: camera check See what an auditor receives: sample audit pack (PDF)