AuditCore · Health & Safety · HSG65 audit checklist
Guide

HSG65 Audit Checklist: Plan, Do, Check, Act

By Anthony Oakes, Founder · Updated September 2026 · 7 min read

HSG65 is the Health and Safety Executive’s guidance on managing health and safety, structured as Plan, Do, Check, Act. It is not a certifiable standard and there is no HSG65 certificate. It is a framework for organising a safety management system, and it is the one most UK employers are implicitly measured against, because it reflects how the regulator itself thinks about competent management.

HSG65 gets recommended constantly and explained rarely. This is what auditing against it actually looks like at a manufacturing site — the twelve areas worth examining, and what evidence each one calls for.

Why audit against HSG65 rather than ISO 45001

HSG65ISO 45001:2018
Published byHSE (Great Britain)ISO (international)
Certifiable No such thing as HSG65 certification Yes, via an accredited body
Cost to referenceFree to download from HSEPurchased licence
StructurePlan, Do, Check, ActAnnex SL clauses 4–10
Best forA single site putting a system in placeCertification, or a customer that requires it
Aligns with other standards~ Conceptually Shares structure with ISO 9001, 14001

For most UK food manufacturers with no certification requirement, HSG65 is the more honest starting point: free, plainly written, and aimed at whether the system works rather than whether the paperwork conforms. Move to ISO 45001 when a customer asks for it, or when you genuinely intend to certify.

The twelve areas to audit

This is the structure AuditCore uses for its HSG65 audit standard — 12 sections, 56 questions.

Plan — Policy and Direction

P1. A written policy signed by the most senior person, setting out the organisation and arrangements — not just a statement of intent. Directors visibly leading, and safety weighed when business decisions are made.

Plan — Planning and Objectives

P2. A plan with objectives, owners and target dates; the resources to deliver it; legal requirements identified and kept current; statutory inspection dates (LOLER, PSSR, LEV, PAT, fire) scheduled and tracked.

Do — Risk Profiling

D1. Understanding which risks could cause serious harm. Suitable and sufficient assessments, covering non-routine work, the assessments the law specifically requires, vulnerable workers, and work-related stress as a health risk.

Do — Organising: Competence

D2. A competent person appointed to assist; training needs mapped to roles; induction and job-specific training before the task, recorded; refresher training before certificates expire; managers trained in their own duties.

Do — Organising: Control

D3. Responsibilities allocated and understood at every level, safety performance part of how managers are assessed, and arrangements that ensure rules are actually followed rather than merely published.

Do — Cooperation and Consultation

D4. Workers consulted before decisions that affect them, a forum that meets and is minuted, concerns raised without fear of blame, and coordination where more than one employer shares the workplace.

Do — Communication

D5. Information in a form workers can understand, significant assessment findings communicated to the people they affect, the law poster displayed, and visitors, contractors and drivers briefed on arrival.

Do — Implementing the Plan

D6. The hierarchy of control applied properly; equipment suitable, maintained and guarded; permits for high-risk work; the workplace itself safe; COSHH controlled; work at height avoided where possible; emergency arrangements tested; PPE provided free and worn.

Check — Active Monitoring

C1. Planned inspections and tours to a schedule, findings assigned and tracked to closure, leading indicators monitored rather than only injury figures, health surveillance where assessed as needed.

Check — Reactive Monitoring

C2. Accidents, near misses and work-related ill health reported and recorded; investigation proportionate to potential severity; underlying causes found rather than individual error; RIDDOR reports made in time; corrective actions verified effective.

Act — Reviewing Performance

A1. Formal senior management review at least annually, considering leading and lagging indicators and progress against the plan, and resulting in real changes where performance falls short.

Act — Learning Lessons

A2. Lessons from incidents, audits and inspections shared and acted on; learning taken from enforcement notices and industry alerts; recurring findings addressed at root cause rather than repeatedly corrected.

What auditors actually find

Four failures come up far more than the rest, and none of them is about paperwork being absent:

Auditing this in AuditCore

HSG65 ships as a complete audit standard — 12 sections, 56 questions with guidance notes on each. Build an annual programme against it, run the audits, and failed questions raise non-conformances that close through root cause and independent verification. ISO 45001 (21 sections, 81 questions) is included too, so you can move between them without rebuilding anything.

Frequently asked questions

What is HSG65?
HSG65 is the Health and Safety Executive’s guidance on managing health and safety at work, structured around Plan, Do, Check, Act. It sets out how an organisation should set direction, assess and control risk, monitor performance and learn from what it finds. It is guidance rather than law, but it reflects how the regulator assesses whether an employer is managing safety competently.
Can you be certified to HSG65?
No. There is no HSG65 certification, and any body offering one is not offering what it appears to. HSG65 is free HSE guidance, not a certifiable management system standard. If you need a certificate — usually because a customer asks — ISO 45001:2018 is the standard to certify against. You can audit internally against HSG65 without certifying against anything.
What is the difference between HSG65 and ISO 45001?
HSG65 is free HSE guidance structured as Plan, Do, Check, Act and aimed at Great Britain; ISO 45001 is an international, certifiable standard structured on the Annex SL clause framework shared with ISO 9001 and 14001. The underlying expectations overlap heavily — leadership, risk assessment, competence, consultation, monitoring, review. HSG65 suits a single site building a system; ISO 45001 suits an organisation that needs a certificate or already runs other ISO standards.
How often should an HSG65 audit be carried out?
A full audit of the management system annually is the common pattern, supported by more frequent active monitoring: weekly or monthly safety tours and quarterly themed inspections. The annual audit examines whether the system works; the tours check whether its controls are holding day to day. Sites with higher risk or recent incidents should audit the affected areas more often.
Does HSG65 apply outside Great Britain?
HSG65 is written for Great Britain and references British legislation such as the Health and Safety at Work etc. Act 1974 and its regulations. The Plan, Do, Check, Act structure is portable and the management principles are sound anywhere, but the legal references will not match. Northern Ireland has parallel legislation administered by HSENI; outside the UK, ISO 45001 is the more appropriate framework.

Audit against HSG65 without building it first

12 sections, 56 questions, with guidance notes. Included in every subscription. 14-day free trial.

Start Free Trial

Anthony Oakes — Founder, AuditCore 30 years in UK food manufacturing. Six Sigma Black Belt, Advanced HACCP Level 4, IRCA Lead Assessor. AuditCore is built from the audits he has run and sat.