Skip to Content

Safety Audits

An audit verifies that the tools meant to manage safety are present and functioning. It is not the same thing as looking for hazards, and treating a clean audit as proof that you have none is a dangerous mistake. I audit safety programs and management systems against whichever standard applies to you, and report what is actually working rather than what is merely documented.

What an audit is for, and what it is not

Auditing and hazard identification are often mistaken for the same activity. They serve two different purposes.

Audits are for verification. A system audit checks that the organizational framework, the policies and the accountabilities, is in place and meets the required standard. A process audit confirms that the work is being carried out and documented according to the rules. Together they verify that the machinery meant to manage safety exists and runs.

Hazard identification is for detection. It is the continuous, real-time search for threats inside the daily operation. An audit can tell you that your reporting process works. It is not designed to find the hazards sitting in the work today.

You need both, and confusing them leaves a gap. This is set out at more length in The Three-Tiered Engine of Hazard Identification.

What gets audited

  • The framework. Policy, defined accountabilities, resourcing, and whether leadership commitment shows up as decisions rather than statements.
  • The documented system. Whether procedures exist, are current, reference the right regulations and standards, and reflect how the work is really performed.
  • Competence and training. Whether the people doing the work have been trained and, more importantly, whether their competence has been verified.
  • Risk management. Whether hazards are identified, assessed consistently, and controlled to a defensible standard.
  • Assurance and reporting. Whether deviations get reported, whether reports get closed, and whether anyone acts on the resulting data.

Which standards you can be audited against

  • ISO 45001, as a gap audit against the standard's requirements.
  • The Canadian Aviation Regulations, for operators with a regulated SMS obligation.
  • Applicable Occupational Health and Safety legislation, federal or provincial.
  • Your own internal standard, a client requirement, or a contractual obligation you need to demonstrate you are meeting.

On the quality of what gets audited

An audit is only as good as the criteria behind it. This is particularly true of risk assessment, where scores are often produced by blending exposure frequency with a guess about how effective the controls are. Where risk assessments cannot be repeated or defended, they fail the people they are meant to protect. My approach to assessing control effectiveness as an audit rather than an opinion is set out in The Illusion of Likelihood.

What you receive

  • Findings against the standard, evidenced rather than asserted.
  • A clear separation between what is missing, what exists but is not working, and what is working.
  • Prioritised corrective actions, so you can address exposure in a sensible order rather than treating a long list as equally urgent.

Frequently asked questions

What standards can you audit against?

ISO 45001, the Canadian Aviation Regulations, applicable federal or provincial Occupational Health and Safety legislation, or a client-specified internal standard. Which applies is settled before the audit begins.

Is an audit the same as a hazard inspection?

No, and the difference matters. An audit verifies that the system meant to manage safety is present and functioning. Hazard identification is the continuous search for threats in the daily operation. A clean audit does not mean you have no hazards; it means your machinery for finding and controlling them is in place.

Will an audit tell us we are compliant?

It will tell you where you meet the standard, where you do not, and what the gap consists of. Compliance is a determination a regulator makes. What an audit gives you is the evidence and the corrective actions to stand behind.

What happens after the audit?

You get prioritised corrective actions. Where it makes sense, the audit findings become the scope for the remediation work, whether that is procedure development, competence verification or building out the parts of the management system that are missing.

Start with a conversation

Every engagement begins with a needs assessment, and that starts with a conversation about what your operation actually does and what you already have in place. Get in touch and we can work out whether this is the right fit.