Policies can be approved, risk assessments completed and training records filed without providing a clear answer to the most important question:
Are the organisation’s health and safety arrangements actually working?
That is what a health and safety audit should help establish.
A health and safety audit is a structured, evidence-based review of how an organisation manages health and safety. It compares the expected standard with what has been planned, documented, implemented and achieved in practice.
An audit should therefore do more than confirm that documents exist. It should test whether responsibilities are understood, controls are being used, information is reaching the right people and weaknesses are being corrected.
HSE describes auditing as a process through which an organisation can review and continually evaluate the effectiveness of its health and safety management system. HSE’s broader guidance also treats health and safety management as an ongoing process in which organisations must check that risks remain controlled and act when arrangements are not working.
What is the purpose of a health and safety audit?
The purpose of an audit is to provide a reliable picture of how well health and safety is being managed.
It can help an organisation establish:
- whether responsibilities are clear;
- whether risk assessments remain suitable;
- whether agreed controls have been implemented;
- whether employees understand the arrangements;
- whether training has produced the required competence;
- whether inspections and maintenance are taking place;
- whether incidents and near misses lead to learning;
- whether actions are completed and verified;
- whether weaknesses are isolated or appear across the organisation;
- whether the overall management system remains suitable and effective.
This sits within the “Check” and “Act” parts of HSE’s Plan, Do, Check, Act approach. HSE advises organisations to monitor performance, periodically audit the effectiveness of management structures and risk controls, and review whether their arrangements remain effective.
A good audit does not exist simply to produce a report. It should help leaders understand where the organisation is well controlled, where assurance is weak and what needs to change.
Is a health and safety audit a legal requirement?
UK health and safety legislation does not prescribe one universal audit format that every organisation must follow.
However, regulation 5 of the Management of Health and Safety at Work Regulations 1999 requires employers to establish appropriate arrangements for the effective planning, organisation, control, monitoring and review of preventive and protective measures. A structured audit is one way of supporting that monitoring and review.
HSE advises larger public and private sector organisations to have formal procedures for auditing and reporting health and safety performance. It also recommends periodic audits of the effectiveness of management structures and risk controls.
This means the appropriate approach will depend on factors such as:
- the organisation’s size;
- the nature of its work;
- the level of risk;
- the complexity of its operations;
- the number of sites;
- previous incidents and findings;
- customer or contractual requirements;
- whether it follows a recognised management standard.
A smaller, lower-risk organisation may use a proportionate internal review rather than a large formal audit programme. What matters is that the organisation can show how it monitors and reviews whether its arrangements remain effective.
Is an audit the same as an inspection?
Audits and inspections are related, but they are not the same.
An inspection usually looks at a particular workplace, activity or piece of equipment to check its current condition and identify visible problems. An audit takes a broader view by examining the system used to manage those risks, including responsibilities, procedures, records, monitoring and corrective action.
For example, an inspection may find a damaged machine guard. An audit would also ask why it was damaged, whether routine checks should have identified it earlier, how the defect was reported, and whether similar equipment could be affected.
A health and safety inspection
An inspection normally examines a workplace, activity, item of equipment or particular set of controls.
It may look at:
- machinery guarding;
- workplace condition;
- vehicle and pedestrian routes;
- storage;
- work at height;
- hazardous substances;
- fire precautions;
- employee behaviour;
- visible deterioration or damage.
For example, HSE explains that work-equipment inspections are used to identify whether equipment can be operated and maintained safely, and to detect deterioration before it creates a health and safety risk.
A health and safety audit
An audit looks more widely at the system used to manage those risks.
It may examine:
- how inspection requirements are decided;
- whether inspections take place when required;
- whether inspectors are competent;
- whether failures are recorded consistently;
- whether corrective actions are assigned;
- whether completed work is verified;
- whether recurring findings are reviewed by management.
An inspection might identify a damaged machine guard.
An audit would ask how the guard became damaged, whether routine checks should have found it earlier, how the defect was reported, who owned the response, and whether similar equipment could have the same problem.
A risk assessment
A risk assessment identifies hazards, considers who could be harmed and determines the controls needed to reduce the risk.
An inspection examines the workplace at a particular point in time to check whether conditions are safe and whether those controls are present, suitable and being followed in practice.
An audit takes a wider view. It tests whether the organisation’s overall risk-assessment and inspection processes are suitable, consistently applied and capable of managing risk effectively.
The three activities support one another. Risk assessments define what should be controlled, inspections check what is happening in practice, and audits examine whether the wider management system is working as intended.
What types of health and safety audit are there?
Not every audit needs to examine the organisation’s entire health and safety management system. The scope should reflect the purpose of the audit, the level of risk and the areas where assurance is needed.
Full management-system audit
A full management-system audit examines the organisation’s overall approach to managing health and safety rather than focusing on one activity, department or location.
It may review leadership, policy, responsibilities, risk management, competence, worker consultation, operational controls, performance monitoring, incident management and management review.
The aim is to determine whether these arrangements work together as a coherent system, are applied consistently and support continual improvement.
Topic-specific audit
A topic-specific audit examines one particular risk or management process in greater detail, rather than reviewing the whole health and safety system at once.
For example, a contractor-management audit might look at selection, competence checks, induction, supervision and performance monitoring. A work-at-height audit may examine planning, equipment selection, inspections, training and rescue arrangements.
This focused approach allows the auditor to follow evidence more thoroughly, identify gaps between policy and practice, and understand whether weaknesses are isolated or part of a wider problem. It can be especially useful after an incident, recurring finding, operational change or concern about a safety-critical control.
Site audit
A site audit evaluates how organisational health and safety arrangements have been applied at a particular location.
It may examine local responsibilities, workplace conditions, significant hazards, employee understanding, contractor controls, inspection records and corrective actions. This is especially useful in multi-site organisations where common policies exist, but layouts, equipment, staffing and working practices vary.
Process audit
A process audit follows one health and safety activity from beginning to end to test whether each stage works and connects properly.
For example, an accident-management audit may examine how incidents are reported, immediate risks are controlled, investigations identify causes, actions are assigned, completion is verified, and learning is shared. This helps reveal gaps between individual stages that may not be obvious when each record is reviewed separately.
Compliance audit
This tests arrangements against relevant legislation, approved codes of practice, internal standards, customer requirements or another defined set of criteria.
A compliance audit can establish whether specified requirements are being met, but it should not be mistaken for a complete assessment of management effectiveness.
Certification audit
An organisation seeking certification to ISO 45001 will be audited against that standard by a certification body.
HSE explains that ISO 45001 is an international occupational health and safety management system standard. It may help demonstrate good management, but it can go beyond minimum legal requirements, and certification alone does not prove legal compliance. HSE inspectors continue to consider a wider range of evidence and observations.
What is the difference between an internal and external audit?
Internal health and safety audit
An internal audit is carried out by someone from within the organisation.
This could be:
a health and safety professional;
a manager from another department;
a member of a central assurance team;
an auditor from another company site.
Internal auditors may understand the organisation, its terminology and its operational pressures well. They can also complete more frequent reviews and follow actions over time.
However, familiarity can make it harder to challenge arrangements that have become normal. Internal auditors therefore need enough independence from the activity being examined to make an objective judgement.
External health and safety audit
An external audit is completed by someone outside the organisation.
This may provide:
greater independence;
specialist knowledge;
experience from other organisations;
additional credibility for customers or senior leaders;
certification against a recognised standard where applicable.
External auditors still need a clear scope and suitable competence. HSE advises organisations using ISO 45001 auditors or certifiers to check their competence and ensure that the approach is proportionate to the organisation’s size, complexity and risks.
The strongest assurance programmes often combine internal visibility with periodic external challenge.
What should a health and safety audit include?
The exact content should reflect the organisation, its activities, significant risks and the purpose of the audit. A small office, for example, will require a different level of scrutiny from a multi-site manufacturing or logistics operation.
A general management-system audit should examine both the arrangements documented by the organisation and the way those arrangements work in practice. This means reviewing policies and records, speaking to employees and managers, observing relevant work and following findings through to corrective action.
The audit should provide a balanced view of leadership, risk control, competence, consultation, monitoring, incident management and continual improvement, rather than focusing only on whether paperwork is present.
Leadership and accountability
The auditor should establish whether leaders understand their responsibilities and receive useful information about health and safety performance.
This might include:
how responsibilities are allocated;
who owns significant risks;
how overdue or serious issues are escalated;
whether leaders act when standards are not met;
how health and safety affects operational decisions.
Policy and objectives
The audit should test whether the policy reflects the current organisation and whether objectives are clear, owned and monitored.
A signed policy is not enough if employees do not understand what it means for their work.
Risk assessment and control
The auditor should examine whether the organisation has identified the significant hazards associated with its activities. This should include both routine work and less frequent tasks, such as maintenance, cleaning, breakdowns, deliveries or temporary changes to normal operations.
They should also consider whether all relevant groups of people have been included. Employees may be the most obvious group, but contractors, visitors, members of the public, young workers, new starters, pregnant workers and people with disabilities may face different or additional risks.
The controls selected should follow a sensible hierarchy rather than relying too heavily on instructions, training or personal protective equipment. Where possible, the organisation should first consider eliminating the hazard, replacing it with something safer or using engineering controls to prevent exposure.
Risk assessments should reflect the work that is actually taking place. A well-written assessment has limited value if the equipment, substances, environment, staffing arrangements or working methods described within it no longer match workplace reality.
The auditor should therefore look at whether changes trigger a review. New machinery, altered layouts, different materials, staffing changes, incidents, near misses and emerging guidance may all indicate that an existing assessment needs to be revisited.
Finally, findings must be communicated and implemented. Workers should understand the controls that affect their roles, and the auditor should be able to see evidence that those controls are being applied consistently in practice.
Employers must make suitable and sufficient assessments of workplace risks and take appropriate action to eliminate those risks or control them so far as is reasonably practicable.
Roles, competence and training
Training records provide useful evidence, but they do not automatically prove competence.
An audit may need to establish whether people:
understand their responsibilities;
received relevant instruction;
can apply what they learned;
receive appropriate supervision;
know what to do when controls fail;
are reassessed when work changes.
Worker consultation
Employees often understand where formal procedures become difficult to follow.
The auditor should consider whether consultation is genuinely two-way and whether concerns, suggestions and reported problems influence decisions. HSE advises organisations to consult workers throughout the management process because involvement supports sensible risk control and a positive health and safety culture.
Operational control
The audit should examine how written arrangements translate into everyday work and whether the controls described in procedures are actually being used.
This may include reviewing:
safe systems of work and whether employees understand them;
permit-to-work arrangements for higher-risk activities;
machinery guards, isolation procedures and other equipment controls;
planned maintenance and the response to reported defects;
contractor selection, induction, supervision and coordination;
emergency arrangements and whether people know how to respond;
the suitability, availability and correct use of PPE;
the quality of day-to-day supervision;
purchasing decisions and how health and safety is considered when equipment, substances or processes change.
The auditor should look for any gap between the documented process and what happens during normal work, busy periods, maintenance or unusual conditions.
Monitoring and inspection
The auditor may test whether inspections, checks and maintenance activities provide reliable assurance that important controls remain effective.
This includes considering whether they:
focus on the organisation’s significant risks;
take place often enough for the activity and level of risk;
use clear and consistent pass-and-fail standards;
are completed by people with suitable knowledge and competence;
produce useful evidence rather than simple ticks;
identify trends, deterioration and repeat problems;
lead to corrective action with clear owners and deadlines;
verify that completed improvements have worked.
The aim is to establish whether monitoring helps the organisation find and correct weaknesses before they contribute to an incident.
Incident and near-miss management
Incident records should show more than what happened.
The audit should consider whether investigations identify why controls failed, whether lessons are shared and whether improvements are made elsewhere. HSE describes incident investigation as part of effective monitoring and a way to improve future risk control.
Corrective actions
The auditor should examine whether findings are being managed through to an effective conclusion, rather than simply being recorded and marked as complete.
Each action should include a clear description of the issue, an appropriate priority and a named owner who is responsible for progressing it. Deadlines should be realistic but proportionate to the level of risk, with escalation arrangements in place where actions become overdue or where immediate control is required.
The auditor should also look for suitable evidence that the action has been completed. This might include photographs, revised documents, maintenance records, training evidence or confirmation that a physical change has been made.
Completion evidence alone is not always enough. The final step is to verify that the action has addressed the original finding and that the intended improvement is working in practice. Without this check, an organisation may close actions administratively while the underlying risk remains.
Management review and continual improvement
Health and safety management should not stop when the audit report is issued.
Leaders should review findings, decide what needs to change and use the results to inform the next cycle of planning. HSE’s guidance describes health and safety management as an ongoing Plan, Do, Check, Act process rather than a one-off exercise.
Use Evalu-8’s Audit Evidence Chain
A useful audit should do more than confirm that a policy, procedure or control exists. It should follow the evidence from what is expected, through what the organisation has put in place, to what actually happens in practice and whether the intended result is being achieved.
The Evalu-8 Audit Evidence Chain was developed to address a common weakness in auditing: conclusions being reached from a single layer of evidence. A written procedure may look suitable but may not be followed. A control may be present but may not be effective. An improvement may have been recorded as complete without any evidence that it has reduced the risk.
The model therefore provides auditors with a structured way to test the full journey from requirement to outcome. It helps prevent audits from becoming document checks and encourages a more balanced assessment of arrangements, workplace practice, effectiveness and improvement.
Evalu-8’s Audit Evidence Chain uses five connected layers.
1. Requirement
What should happen?
The auditor first identifies the standard the organisation is expected to meet. This may come from legislation, internal policy, a procedure, risk assessment, recognised standard, manufacturer guidance or an agreed control.
The requirement should be specific enough to support a clear judgement. Without it, different auditors may apply different expectations or rely too heavily on personal opinion.
2. Arrangement
How has the organisation planned to meet the requirement?
The auditor then examines the systems put in place to achieve the required standard.
This may include named responsibilities, procedures, training, inspection schedules, maintenance programmes, reporting routes and escalation arrangements. The aim is to establish whether the organisation has created a practical and workable method for controlling the risk.
3. Practice
What actually happens?
The auditor tests whether the planned arrangements are being applied during normal work.
This involves observing activities, speaking to employees and managers, reviewing records and following real examples through the process. It often reveals where procedures are misunderstood, difficult to follow or replaced by informal workarounds.
4. Effectiveness
Is the arrangement controlling the risk?
A process can be documented and consistently followed without delivering the intended result.
The auditor should therefore test whether the controls genuinely reduce risk, identify deterioration and trigger an appropriate response when standards are not met. This may involve reviewing incidents, repeat findings, overdue actions and evidence that completed improvements have worked.
5. Improvement
Does the organisation learn and act?
The auditor examines whether weaknesses lead to proportionate action, whether completed improvements are verified and whether learning is transferred to other relevant areas. A good audit does not stop at whether an arrangement exists. It follows the evidence through to whether the arrangement works and improves.
How is a health and safety audit carried out?
1. Define the scope
The audit should begin with a clear statement of what is being examined.
The scope might cover:
the whole organisation;
one site;
a department;
a process;
a specific risk;
a defined management standard;
actions from a previous audit.
An unclear scope can lead auditors towards whatever information is easiest to find while important areas remain outside the review.
2. Set the audit criteria
The criteria define the standard against which evidence will be evaluated.
These may include:
legislation;
HSE guidance;
company policies;
risk assessments;
procedures;
customer requirements;
ISO 45001;
industry standards.
3. Prepare an audit plan
The plan should identify:
the activities to be sampled;
documents to be reviewed;
people to be interviewed;
workplaces to be visited;
the timetable;
the audit team;
reporting and escalation arrangements.
The plan should remain flexible enough to follow important evidence when it emerges.
4. Gather evidence
Audit evidence normally comes from three main sources: documents and records, conversations with relevant people, and direct observation of work.
Using more than one source helps the auditor test whether written arrangements match what employees understand and what actually happens in practice. Evidence should be relevant, reliable and sufficient to support the finding, rather than relying on one document, a single answer or a brief visual check.
Documents and records
These can show what has been planned and recorded.
Examples include risk assessments, inspection results, training records, maintenance histories, meeting minutes and corrective-action logs.
Conversations
Interviews help establish whether people understand the arrangements and how work is completed in practice.
The purpose is not to test employees or catch them out. It is to understand how the system works from their position.
Observation
The auditor should see relevant work, conditions and controls wherever possible.
A procedure may look convincing on paper but prove difficult to apply during a busy shift, breakdown, delivery or maintenance task.
No single evidence source should automatically be treated as conclusive.
5. Evaluate the evidence
The auditor compares the evidence with the audit criteria and considers whether the arrangement is:
present;
understood;
implemented;
effective;
consistently applied;
monitored;
improved when necessary.
6. Record findings clearly
Findings should explain:
what was expected;
what evidence was examined;
what was found;
why it matters;
which requirement or standard applies;
what response is needed.
Vague statements such as “training could be improved” do not provide enough information to support meaningful action.
7. Report the results
The report should provide senior leaders and operational owners with a clear picture of:
strengths;
significant weaknesses;
recurring themes;
immediate risks;
improvement priorities;
limitations in the evidence or scope.
8. Assign and verify actions
Each action should have an owner, deadline and suitable verification method.
The audit is not complete merely because the report has been issued. Its value depends on what happens afterwards.
What should a health and safety audit report contain?
A useful audit report should clearly identify the audit title, date, scope, objectives and criteria. It should explain which sites, processes and activities were examined, who completed the audit and how evidence was gathered or sampled.
The report should record positive findings as well as non-conformities, control failures and opportunities for improvement. It should also explain the level of risk, any immediate action taken and the corrective actions that have been agreed.
Each action should have a clear owner, deadline and verification requirement. Any limitations, exclusions or wider themes requiring management review should also be recorded.
The report should contain enough detail to support meaningful action without becoming so long that the most important risks and priorities are difficult to identify.
How often should health and safety audits take place?
There is no single audit interval that will suit every organisation. Audit frequency should reflect the seriousness of the risks, the size and complexity of the organisation, the pace of operational change and the maturity of the health and safety management system.
Previous audit results, incidents, near misses, repeated inspection findings and evidence of ineffective controls should also influence how often audits are completed. Contractor, supply-chain or certification requirements may create additional expectations.
A stable, lower-risk area may require less frequent formal auditing than a high-risk operation undergoing significant change. Focused audits may also be needed after a serious incident, the introduction of new equipment or processes, a major organisational change, a business acquisition or a significant change to legal or technical requirements.
The audit programme should direct the greatest attention towards areas where control is weakest and where failure could have the most serious consequences.
Who should carry out a health and safety audit?
A health and safety auditor should have enough competence to understand the activity being examined, the hazards involved and the criteria against which performance is being assessed. They must also know how to gather, test and evaluate evidence rather than relying on assumptions, impressions or incomplete records.
Good auditors recognise the limits of their own knowledge. They should be able to identify when an issue falls outside their competence and when specialist input is needed, particularly where complex machinery, occupational hygiene, hazardous substances or technical legal requirements are involved.
Communication skills matter as well. Findings should be explained clearly and constructively so that managers and employees understand both the weakness identified and why it matters. The purpose of an audit is not simply to criticise existing arrangements, but to provide an objective assessment that supports meaningful improvement.
The auditor should also have enough independence to reach an impartial conclusion. This does not always require an external consultant. An internal auditor from another site, department or business function may provide suitable separation, provided they are competent and are not reviewing decisions, systems or controls for which they are directly responsible.
Common health and safety audit weaknesses
Auditing documents rather than work
The auditor confirms that policies, procedures and records exist but does not test whether they influence everyday behaviour or risk control.
A procedure may look suitable on paper while employees use a different method because the official process is unclear, impractical or poorly supervised. Documents should therefore be supported by observation and conversation.
Using the checklist as the objective
The audit becomes focused on completing every question rather than understanding whether important controls are effective.
A checklist should guide the auditor, not restrict them. Where significant evidence appears, the auditor should be able to follow it, ask further questions and examine related areas.
Accepting training records as proof of competence
Attendance may be recorded without confirming that people understood the training or can apply the required standard.
The auditor may need to speak to employees, observe the task and review supervision or assessment records before concluding that someone is competent.
Sampling only convenient areas
Day shifts, tidy departments and available managers receive attention while difficult activities, remote sites or unusual operating conditions are missed.
This can produce an overly positive result. Sampling should reflect the organisation’s risk profile and include different shifts, locations, activities and working conditions where relevant.
Recording vague findings
Findings do not identify the expected standard, supporting evidence or operational consequence.
A useful finding should explain what should have happened, what the auditor found, why it matters and what needs to change. This gives action owners enough information to respond effectively.
Treating all findings equally
Minor document issues receive the same attention as failures involving safety-critical controls.
Findings should be prioritised according to risk, urgency and potential consequence so that the most serious weaknesses receive immediate attention and appropriate escalation.
Closing actions without verification
A document, email or photograph is accepted as proof even though nobody has checked whether the improvement works.
Verification may require a follow-up visit, observation, equipment test, employee conversation or review of updated evidence. Completion and effectiveness are not always the same thing.
Repeating the same findings
Problems return because actions address the immediate symptom rather than the underlying cause.
Recurring findings may indicate weak ownership, ineffective corrective action or a wider organisational issue. The audit should examine why the problem returned and whether the same weakness exists elsewhere.
What does a good health and safety audit look like?
A strong audit is:
Risk-led: It concentrates on the organisation’s significant hazards and vulnerable controls.
Evidence-based: Conclusions are supported by documents, conversations and observations.
Proportionate: The depth and formality reflect the organisation and its risks.
Independent: The auditor can reach an objective judgement.
Practical: It considers how work happens under normal and difficult conditions.
Constructive: It identifies strengths as well as weaknesses and supports improvement rather than blame.
Traceable: Findings show what was expected, what was examined and how the conclusion was reached.
Action-focused: Significant weaknesses lead to owned and prioritised improvements.
Verified: Actions are not closed until the organisation has checked that the intended result was achieved.
Conclusion
A health and safety audit is not simply a search for missing documents.
It is a structured examination of whether the organisation understands its risks, has suitable arrangements and makes those arrangements work in practice.
The most useful audits follow the evidence from requirement to arrangement, from arrangement to everyday practice and from practice to the result being achieved.
They also continue beyond the report.
An audit creates value when its findings lead to verified improvements, stronger management decisions and better control of workplace risk.
A health and safety audit is a structured review of how an organisation manages workplace health and safety. It compares expected standards with documents, records, conversations and workplace evidence to establish whether arrangements are suitable and effective.
Its main purpose is to establish whether health and safety arrangements are working as intended. It identifies strengths, weaknesses and priorities for improvement.
UK law does not prescribe one standard audit format for every employer. However, employers must have arrangements for monitoring and reviewing measures used to protect people. Formal auditing is a common way to support this duty, particularly in larger or more complex organisations.
An inspection usually examines workplace conditions, activities or equipment. An audit examines the wider system used to manage those conditions, including responsibilities, processes, records, monitoring and corrective action.
Yes. Internal audits can be effective where the auditor is competent and sufficiently independent from the activity being examined. Some organisations also use external auditors to provide specialist expertise or additional objectivity.