Clause 10.2 — Incident, nonconformity, and CAPA
Of every ISO 45001 clause, 10.2 generates the most audit findings — usually because organisations can show the incident, but not the chain of evidence that connects root cause to CAPA to effectiveness-check.
| What the auditor asks | What to show from QEHS |
|---|---|
| Every incident recorded? | Incident module — "All" filter, date range = audit period |
| Root-cause analysis on every recordable? | RCA capability — linked to incident, 5-whys / fishbone / bowtie chain |
| Corrective actions assigned + closed? | Actions module — filter by source-incident-id, view open vs. closed |
| Effectiveness verified? | Action "effectiveness-check" step — signed-off by a second approver |
| Lessons shared? | Announcement / lessons-learned capability post-closure |