Skip to main content
Industry Analysis
14 min read

Malaysian manufacturer's guide to ISO 45001 evidence: what AI monitoring can and cannot substitute

ISO 45001:2018 requires objective evidence for occupational health and safety records, and AI monitoring systems can produce documented, timestamped data that satisfies several evidence requirements but cannot discharge others that require human judgment and legal interpretation. This guide maps which ISO 45001 clauses AI monitoring directly supports, which clauses require AI data as supporting inputs only, and which clauses AI monitoring cannot address.

Malaysian manufacturer's guide to ISO 45001 evidence: what AI monitoring can and cannot substitute

ISO 45001:2018 replaced OHSAS 18001 as the primary international standard for occupational health and safety management systems, with a 3-year transition period that closed in 2021. For Malaysian manufacturers seeking DOSH recognition of their safety management system, ISO 45001 now provides the baseline framework — and clause 9.1.1, covering monitoring and measurement records, is where surveillance audits most consistently surface corrective action requests.

The question that surfaces consistently ahead of those audits is not whether AI monitoring systems generate data. They generate substantial data. The question is whether the data they generate qualifies as objective evidence under the standard — and if so, for which clauses. The answer is specific: AI monitoring can produce structured, timestamped records that satisfy several evidence requirements directly and support others as documented inputs. Several requirements cannot be delegated to any monitoring system regardless of its capabilities. This guide maps both.

What ISO 45001 means by objective evidence

ISO 45001:2018 adopts the definition of objective evidence from ISO 9000:2015: information that can be proved true based on facts obtained through observation, measurement, or testing. For a DOSH-recognised surveillance auditor, "objective evidence" means records available for examination — not a verbal explanation and not a live system demonstration that cannot be reproduced after the audit.

The documented information requirements most directly affected by AI monitoring fall across three clauses:

  • Clause 9.1.1 (Monitoring and measurement): Records of monitoring activities, measurement results, and OH&S performance evaluation. This is the clause where continuous AI monitoring has the most direct application.
  • Clause 9.1.2 (Evaluation of compliance): Records showing the organisation has evaluated its compliance status against applicable legal requirements. This clause requires human judgement applied to specific legal texts — AI monitoring records can provide supporting data, but they do not discharge the evaluation requirement.
  • Clause 10.2 (Incident, nonconformity, and corrective action): Records of incidents, near-miss events, investigation findings, corrective actions taken, and effectiveness reviews. AI monitoring alert logs serve as near-miss records for events within camera coverage.

A dashboard that shows today's compliance status is not documentary evidence unless the underlying event records are exportable, timestamped, and tied to specific incidents. The distinction matters in audit: a dashboard screenshot is an assertion; a timestamped event log is evidence.

What AI monitoring generates as documentary evidence

HyperQ AI Safety produces structured event logs for every detection, alert, and response within its monitoring configuration. The record types, and the clauses they support, are as follows.

Zone-presence and access records: Timestamped log of zone entry, dwell time, and exit for each monitored area, with the detection classification and confidence level. For restricted-access areas, permit zones, and confined space entrances, these records provide continuous monitoring documentation that supports clause 9.1.1 monitoring activities without sampling gaps.

PPE compliance records: Per-shift detection log of required PPE presence — hard hats, high-visibility vests, safety footwear, fall-arrest harness detection in height-work zones — with timestamps and non-compliance event flags. These records support the clause 8.1.1 operational control requirement to verify that PPE requirements are being followed, providing evidence that monitoring occurred rather than relying on supervisor attestation.

Alert and escalation logs: Timestamped record of every alert generated, the alert classification, the escalation path, and the response confirmation. Alert logs for proximity events, zone violations, stopped work in permit areas, and PPE non-compliance serve as near-miss records under clause 10.2, provided the alert classification and response are documented together.

Trend reports: Aggregated compliance data by shift, zone, work category, and time period. These support clause 9.3 management review inputs for OH&S performance trending — auditors can see whether compliance rates are improving, stable, or degrading across audit periods.

System availability logs: Records of camera uptime, monitoring coverage gaps, and system health events. When an auditor asks whether the monitoring system was operational during a specific period — particularly following an incident — availability logs answer the question with a timestamp rather than a verbal account.

None of these record types require manual data entry. They are system-generated, timestamped at the event level, and exportable in structured formats compatible with document management systems and eQMS platforms.

ISO 45001 clause mapping: what AI monitoring can and cannot provide

The following table maps each primary ISO 45001 clause requiring documented evidence to what AI monitoring contributes and what must remain human-generated.

Clause Requirement AI monitoring can contribute Must remain human-owned
4.1 Context of the organisation Context analysis, stakeholder consultation and documentation
5.2 OH&S policy Management-authored, signed policy document
5.4 Worker participation and consultation Consultation meeting records, worker input documentation
6.1.1 Hazard identification records Alert history as inputs to hazard register Initial hazard identification walkthroughs, worker knowledge capture
6.1.2 Risk assessment records Zone event frequency and severity data as risk inputs Risk evaluation, prioritisation, and treatment decisions
6.1.3 Legal compliance identification Identification of applicable OSHA 1994 requirements and DOSH codes of practice
7.2 Competence evidence Training completion records, competence verification and sign-off
7.4 Communication records Alert dispatch and acknowledgement logs Safety briefing records, toolbox talk documentation
8.1.1 Operational control records PPE compliance logs, zone violation logs Work procedure documentation, permit authorisations
8.2 Emergency preparedness records Alert initiation timestamps for emergency-category events Emergency plan documentation, drill records and evaluation
9.1.1 Monitoring and measurement records Zone-presence, PPE, alert, and availability records Measurement calibration records, environmental monitoring
9.1.2 Compliance evaluation records Monitoring data as supporting input Legal compliance checklist, evaluator signature and date
9.2 Internal audit records Audit programme, auditor competence records, audit findings
9.3 Management review inputs and outputs Performance trend data as review input Review attendance records, decisions, resource allocations
10.2 Incident and near-miss records Alert logs, zone event records for in-scope events Incident investigation, root cause analysis, corrective action

What AI monitoring cannot substitute

Several ISO 45001 requirements have human ownership embedded in the standard's intent. A monitoring system contributing data to these areas provides supporting inputs, not discharge of the requirement. This is the honest positioning: knowing which requirements AI covers directly and which it does not is what allows a manufacturer to close genuine gaps rather than assume coverage.

Hazard identification (clause 6.1.1). The standard calls for a proactive, participative approach to identifying hazards, including physical walkthroughs, worker knowledge, and review of past incidents. AI monitoring detects events within configured zones in real time. It does not identify hazards in areas outside its field of view, in new work processes where no alert baseline has been established, or from tacit worker knowledge that has not expressed itself as a reportable event. Alert history from AI monitoring is a valid and useful input to the hazard identification process — it is not a substitute for it.

Legal compliance evaluation (clause 9.1.2). The Occupational Safety and Health Act 1994 (OSHA 1994), its subsidiary regulations, DOSH Codes of Practice, and sector-specific requirements require a named responsible person to evaluate the organisation's compliance status against each applicable legal provision and record the evaluation results with a date and signature. A monitoring system that tracks PPE usage does not evaluate whether the organisation's PPE programme meets the specific requirements of applicable DOSH Codes of Practice. Legal compliance evaluation requires human judgement applied to legal text.

Worker consultation (clause 5.4). ISO 45001 is explicit: workers and worker representatives must be consulted on hazard identification, risk assessment, determination of controls, and OH&S objectives. The consultation records showing worker participation in these decisions are mandatory documented information. No monitoring system generates them.

Internal audit (clause 9.2). An internal audit must be conducted by a competent person who is independent of the area being audited, applying defined audit criteria and producing documented findings. AI monitoring data may be one evidence source that an internal auditor reviews during the audit. The audit itself — including the planning, execution, findings, and conclusions — remains a human function.

Management review (clause 9.3). Management review requires documented records of the review, including attendance, agenda items, decisions, and actions assigned. AI monitoring trend data is an input to the review. The review conversation and the decisions that follow must be documented separately and cannot be generated from system logs.

The pattern across these requirements is consistent: wherever the standard requires judgement — legal interpretation, prioritisation, root cause analysis, decisions about resource allocation — the record must come from a person who exercised that judgement. AI monitoring generates evidence of what the system observed. It does not generate evidence of human decision-making.

DOSH Malaysia context

Under OSHA 1994, Malaysian employers must provide a safe working environment, safe systems of work, and adequate information, instruction, supervision, and training. For industries covered by the Factories and Machinery Act 1967 — including scheduled machinery operations, pressure vessels, and lifting equipment — DOSH inspection officers may request monitoring records during site visits.

AI monitoring records that are timestamped, traceable to specific events, and linked to specific work areas provide more defensible evidence than handwritten check-sheets for continuous monitoring activities. The key DOSH expectation for any monitoring record is traceability: can the record be linked to a specific event, location, and response? Aggregated summary reports without underlying event-level records may be questioned. The same applies to records that exist only within a vendor's platform without an export path — records that cannot be produced in a format the auditor can examine are not records for audit purposes.

For industries that have implemented or are pursuing ISO 45001 certification through an accredited certification body recognised by DOSH, the mapping in this guide applies to both certification audits and surveillance audits. The clause-by-clause approach is the same; only the audit scope and sample selection method differs between the two.

Leading indicator trends generated from AI monitoring — PPE compliance rates by shift, zone dwell-time patterns, near-miss frequency — are useful inputs to management review and to the safety metrics programme covered in safety metrics that survive an audit: leading indicators AI cameras actually measure. The current post focuses on evidence requirements; the leading indicators post addresses the metric design question separately.

Preparing for a surveillance audit using AI monitoring records

Four steps to prepare AI monitoring records for a surveillance audit:

1. Export structured event logs before the audit window. AI monitoring records must be accessible in a format the auditor can examine offline — structured CSV, signed PDF summaries, or records within your eQMS. Records accessible only through the monitoring platform's user interface are not available to an auditor without a platform account and are not auditable in the standard sense.

2. Map exported records to specific clause requirements in your document master list. Your document controller should know which AI-generated record types serve as evidence for which clauses. A verbal claim that "AI monitoring handles clause 9.1.1" is not an audit position. A document master list entry that says "Zone-presence event logs (exported quarterly) — supporting evidence for clause 9.1.1 monitoring activities" is.

3. Verify clause coverage against the mapping table. For each clause in the "must remain human-owned" column, check that a separate human-generated record exists and is current. The AI monitoring records do not substitute for those requirements. The gap between what AI covers and what requires human documentation is the audit preparation checklist.

4. Confirm that AI records reflect the monitoring scope in your OH&S management plan. If your safety plan identifies five work zones as requiring continuous monitoring and your AI system covers three, the records speak to three zones. The auditor will ask about the other two. Either expand monitoring coverage or document the alternative control for the uncovered zones.

Three questions to ask before deploying AI monitoring for ISO 45001

Can the system export structured, timestamped event logs in a format compatible with your document management system or eQMS? If the answer is dashboard-only, the system will not produce records suitable for audit without manual transcription, which defeats the purpose.

Does the system maintain an audit log of changes to monitoring configurations? If the coverage zones, detection thresholds, or alert rules change during an audit period, an auditor may ask whether the records from before and after the change are comparable. A configuration change log answers that question.

What happens to historical records if the system is upgraded or replaced? Records must remain accessible for the duration of your document retention period. A system migration that does not preserve exportable historical records creates a gap in the evidence trail for past audit periods.

Frequently asked questions

Does ISO 45001 require AI monitoring systems?

No. ISO 45001 requires that monitoring and measurement be appropriate to the organisation's needs and that the results are retained as documented information. AI monitoring is one approach that generates continuous, structured, timestamped records. Manual observation, environmental monitoring instruments, and paper check-sheets can all satisfy the same requirements. The advantage of AI monitoring for continuous activities — like zone access control and PPE compliance — is the absence of sampling gaps and the structured, exportable format of the records it generates.

Will a DOSH auditor accept AI-generated records as objective evidence?

Generally yes, provided the records are timestamped, traceable to specific events, and the monitoring system itself is described in the OH&S management plan. An auditor may ask about the validation of the monitoring system's accuracy — specifically, how the organisation verifies that the cameras and detection models are operating within a stated accuracy range. Camera calibration records and system availability logs address this question.

How does AI monitoring handle incidents that occur outside camera coverage?

It does not. Events outside the configured monitoring scope are not captured. Your incident reporting procedure for out-of-coverage areas, mobile work, and off-site activities remains unchanged. The monitoring system's records speak only to what it was configured to cover during the period it was operational.

What if an incident occurs and the AI monitoring record conflicts with a worker's account of events?

Handle the conflict as you would any conflict between two evidence sources. Both the AI-generated record (timestamped, with event classification) and the worker's account are inputs to the incident investigation. The investigation — root cause analysis, corrective action determination, effectiveness review — remains a human function under clause 10.2. AI records are one input to the investigation, not the investigation itself.

How should AI monitoring records be retained to satisfy ISO 45001's documentation requirements?

ISO 45001 does not specify retention periods for most records — it requires records to be retained for a period sufficient to demonstrate conformance and compliance with legal requirements. Malaysian OSHA 1994 and subsidiary regulations specify retention periods for certain record types (accident records are typically 5 years minimum). AI monitoring records that serve as supporting evidence for OSHA-specified records should be retained for at least the same period. Confirm the applicable retention requirement for each record type with your legal compliance reviewer.


Share your ISO 45001 scope document and a description of your current monitoring configuration and we will produce a clause-by-clause gap assessment — identifying which 45001 requirements your AI monitoring currently addresses and which require additional human-generated documentation — within two weeks. No advisory contract is required until you decide the findings are worth acting on.

Share your ISO 45001 scope and monitoring setup to receive a clause-by-clause evidence gap assessment within two weeks, no contract until you decide the findings are useful.

Written by

Hypernology Team

September 20, 2026

Share

Continue Reading

Translate Insight
to Infrastructure.

Interested in deploying these solutions to your facility? Let's discuss the technical requirements.

Initiate Briefing