In 2024, 188 workers were fatally injured in Australia, with vehicle incidents accounting for 42% of those deaths. A workplace safety audit is a systematic, independent process that gathers evidence to test whether WHS controls work in the field, not just whether the required documents exist.
That distinction matters when a construction supervisor signs off a SWMS that no longer matches the lift, or when a manufacturing procedure says a guard is checked but nobody can show the last effective verification. A routine inspection may identify an exposed edge, damaged plant or blocked access route. An audit asks why the issue existed, whether the control was implemented, who verified it, and whether the system prevents recurrence.
Table of Contents
- Defining the Workplace Safety Audit
- Legal Obligations and Compliance Frameworks
- Executing a Risk-Based Audit Program
- Auditing Subcontractors and Multi-Site Operations
- Tracking Corrective Actions and System Maturity
- Building a Culture of Field Verification
Defining the Workplace Safety Audit
A crew may have an approved SWMS, current training records and signed pre-start forms, yet still expose workers to uncontrolled risk when the job changes. A workplace safety audit tests that gap between the documented system and the work being performed.
WorkSafe WA defines an audit as a “systematic, independent and documented process for obtaining evidence and evaluating it objectively against audit criteria”. An inspection usually checks hazards or unsafe practices at a particular time. An audit compares evidence with defined criteria and reaches a defensible conclusion about whether the system performs as intended. (WorkSafe WA's audit guidance)

An auditor reviews procedures, interviews workers and supervisors, observes tasks, checks records, samples sites or teams, and traces corrective actions to their source. The audit should test whether controls remain effective when production pressures, weather, access conditions or subcontractor arrangements change.
A useful question is: “Can the business show that workers understand the procedure, supervisors verify it, and the control works at the point of risk?” A signature proves attendance. It does not prove understanding or safe execution.
Audit evidence must reach the workface
For construction and industrial operations, collect evidence from four sources:
- Documents and records: Review risk assessments, SWMS, training records, plant inspections, permits, incident investigations and previous findings.
- Worker interviews: Ask workers to explain critical controls in their own words. Compare their answers with the documented method.
- Field observation: Watch the task while it is performed. Check the sequence, equipment, exclusion zones and conditions against the approved control.
- Action verification: Confirm that corrective actions removed or controlled the hazard. A photograph or uploaded form is not proof that the risk was addressed.
A sound audit records positive conformance as well as gaps. It can show reliable supervisor checks, effective consultation and a system that adapts when work changes. WorkSafe WA's WorkSafe Plan assesses health and safety management systems against achievement levels, supporting this broader view of audit performance. (WorkSafe Plan audit and assessment process)
Practical rule: If the audit never observes the work, it has tested paperwork, not the control.
Regulators assess PCBU performance through interventions, workplace visits, audits, meetings, correspondence and notices. Safe Work Australia recorded 229,236 workplace interventions in 2018–19, 1,187 field active inspectors and 55,568 notices issued by Australian jurisdictions during that year. (Safe Work Australia's comparative performance reporting)
For business owners, the implication is direct. An audit is a control-verification activity that tests whether the PCBU's arrangements operate beyond the office, including where subcontractors perform high-risk work.
Legal Obligations and Compliance Frameworks
A workplace safety audit doesn't create the PCBU's duties. It tests whether the organisation has identified and managed them under the applicable WHS legislation, regulations and codes. The model WHS Act forms the basis of WHS Acts implemented in most Australian jurisdictions, while each regulator administers its own legislation and enforcement arrangements. SafeWork NSW, for example, administers and enforces the WHS Act 2011 and WHS Regulation 2025 in NSW. (SafeWork NSW legislation)
That jurisdictional detail affects the audit criteria. An auditor should identify the state or territory, the nature of the work, the PCBU's role, licensing conditions, principal contractor arrangements and any self-insurer or client requirements before selecting a checklist. A generic form can help organise evidence, but it can't replace a legal and operational scope.
SWMS verification is a field test
For high-risk construction work, the audit must test more than whether a SWMS is stored in a document system. A PCBU carrying out high-risk construction work must prepare, keep, comply with and review a SWMS, and must give a copy to the principal contractor before work starts. (Safe Work Australia's SWMS requirements)
On site, verify that:
- the SWMS describes the high-risk construction work underway;
- workers can access and explain the relevant controls;
- the control measures are implemented in the sequence described;
- supervisors monitor the work and respond when conditions change;
- the SWMS is reviewed when the task, plant, environment or risk changes;
- the principal contractor has received the current version.
A signed acknowledgment doesn't prove compliance. If the SWMS requires exclusion zones, isolation or a defined lifting method, the auditor needs to observe those controls and speak with the people doing the work.
Periodic audits support governance
Comcare's national self-insurer WHS audit tool is designed to test legislative compliance and the effectiveness of a licensee's WHS policy, procedures and management systems. Its user guide states that scheduled audits should verify workplace activities against procedures, while periodic audits test whether the system has been implemented, maintained and aligned with the performance objectives in the WHS policy. (Comcare's self-insurer WHS audit tool user guide)
This provides a useful governance argument when audit resources compete with operational priorities. Directors don't need another document archive. They need evidence that the organisation's controls operate, that failures are escalated, and that management reviews whether actions solved the underlying problem.
Businesses also need a controlled approach to legal registers, standards and evidence ownership. Teams managing compliance through Microsoft technology may find this overview of manage compliance with Microsoft technology useful when deciding how document control and accountability fit into broader business systems. For Australian-specific audit criteria and standards context, review auditing standards in Australia before finalising the audit protocol.
Executing a Risk-Based Audit Program
A calendar that gives every department the same audit treatment is easy to administer, but it can leave the highest-consequence work under-tested. A risk-based program directs audit effort towards tasks where a control failure could seriously harm people, disrupt operations or expose the PCBU to enforcement action.
In 2024, 188 workers were fatally injured in Australia, and vehicle incidents accounted for 42% of those deaths. Mental health conditions represented 12% of all serious claims. (Safe Work Australia's workplace safety data) Those figures support a practical audit decision: test vehicle-pedestrian separation, traffic management and mobile plant controls, while also examining how the organisation identifies and manages psychosocial risks.

Build the program around failure modes
Start with the work, not the form. Identify activities where controls depend on timing, worker judgement, changing interfaces or equipment condition. In construction, that may include crane lifts, excavation, temporary works, traffic movements and subcontractor interfaces. In manufacturing, it may include isolation, guarding, chemical handling, maintenance access and line changeovers.
Then use a five-part planning sequence:
- Define the scope. Name the site, activity, contractor group, shift, plant or legal requirement being tested. “Whole-site WHS” is usually too broad to produce useful evidence.
- Set audit criteria. Use legislation, SWMS requirements, internal procedures, client conditions and approved risk controls. State what conformance looks like before the auditor arrives.
- Choose the method and sample. Combine document review, interviews, observation and action verification. Sample different shifts, crews, work fronts and contractors where the risk changes.
- Set frequency by risk. Revisit controls after incidents, changes in plant, new contractors, altered production, enforcement activity or evidence of weak supervision. A low-risk administrative process doesn't need the same attention as an active vehicle interface.
- Report decisions, not just defects. Separate immediate hazards, non-conformances, observations and effective practices. Assign owners, due dates and verification requirements.
A good auditor tests whether the control works under pressure. Ask the operator to demonstrate the isolation process. Follow a vehicle route during a busy period. Check whether dust controls remain in place during production, not only during a planned walk-through. Interview a worker who joined the task recently and one who performs it routinely.
A risk-based audit asks where the system is most likely to fail, then gathers evidence there.
Use a readiness process to confirm that scope, records, people and site access are available without turning preparation into a paper exercise. Guidance on audit readiness for Australian operations can help operations teams organise that evidence before the auditor starts, but readiness must never become document staging. The final judgement still depends on what workers do and what supervisors verify.
Auditing Subcontractors and Multi-Site Operations
An internal audit can show that the principal contractor's system is well written while subcontractors use different controls at the workface. That's the blind spot created when the audit follows organisational boundaries instead of physical risk.
The principal contractor and other PCBUs may have overlapping duties. The audit therefore needs to test the interfaces between businesses, including who provides plant, who controls the work area, who manages traffic, who reviews the SWMS, who responds to changed conditions and who closes findings.
Audit the interface, not just the contractor file
A contractor prequalification file can contain insurance, licences, competencies and policies. Those records matter, but they don't prove that a subcontractor's controls are working on the current site.
Check the connection points:
- Mobilisation: Confirm the contractor received current site rules, emergency arrangements, traffic controls and relevant risk information.
- Task control: Compare the subcontractor's SWMS with the actual plant, work sequence and location. Check that the principal contractor has the required copy before work starts.
- Induction and supervision: Ask workers who they report to, who can stop the job and what happens when the agreed method no longer fits.
- Shared hazards: Test how multiple contractors manage simultaneous work, mobile plant, exclusion zones, overhead risks, services and access.
- Corrective actions: Trace a finding from the original observation to the assigned owner, evidence of completion and a later effectiveness check.
Transient worksites need a different sampling approach from a stable factory. The audit should visit active work fronts, not only the site office. It should sample crews that arrived recently, tasks that occur intermittently and areas where the principal contractor's controls depend on subcontractor behaviour.
The Federal Safety Commissioner conducted 698 safety audits in 2024-25 across 963 on-site testing days and issued 3,474 Corrective Action Reports. (Office of the Federal Safety Commissioner annual data report) The scale of field testing reinforces the operational point: audit evidence needs to come from the place and time where work happens.
Make multi-site findings comparable
Each site can use local procedures, but the audit program needs common criteria for critical controls. Otherwise, one site may report “traffic management in place” while another tests separation distances, spotter arrangements, access gates and supervisor verification under the same heading.
Use a shared finding structure across sites:
- the requirement or control being tested;
- the evidence observed;
- the specific gap;
- the responsible PCBU or manager;
- the interim control;
- the due date and effectiveness test.
A central register helps, but accountability remains with the people controlling the work. Subcontractor safety management should connect contractor selection, site induction, field verification and action closure rather than treating each process as a separate administrative task.
Tracking Corrective Actions and System Maturity
An audit finding matters only when the business changes the condition or system that created it. Reissuing a procedure does not demonstrate control if workers continue the same behaviour. Each action needs a clear cause, an accountable owner, an interim safeguard where required, and a defined test for effectiveness.

Separate correction from effectiveness
A correction resolves the immediate defect. Corrective action addresses why the defect occurred and tests whether the risk remains controlled.
Replacing a missing machine guard restores the immediate physical control. A stronger review asks why the guard was missing, whether inspections should have detected the defect, whether replacement parts were available, and whether the equipment remains safe after repair. That investigation takes more time, but it shows whether the management system can detect and prevent similar failures.
A useful action record includes:
| Action field | What it should show |
|---|---|
| Finding | The requirement and evidence that failed |
| Risk and interim control | How people are protected while the action remains open |
| Owner | The person with authority and resources to act |
| Due date | The agreed completion point |
| Evidence | Records, photographs, interviews, observations or test results |
| Effectiveness review | How an independent person will confirm that the risk is controlled |
The closure test should match the failure. A document change may require worker interviews and field observation. A plant defect may require inspection records, functional testing and observation under operating conditions. For subcontractor findings, verify the control at the workface rather than accepting a signed response from the contractor's office.
Paper registers often remove the context needed for sound escalation. A spreadsheet may show an overdue action while hiding the original evidence, affected site, responsible contractor, interim control or verification result. Use audit management software when a business needs findings, evidence, owners, due dates and effectiveness checks in one traceable workflow across sites.
Use maturity as a management measure
Maturity should describe whether the system learns from failures, not whether the business has completed a set number of audits. Track overdue actions, repeat findings by site or contractor, time from finding to verified closure, and the proportion of closures rejected during effectiveness review. These measures reveal whether managers resource corrective work and whether controls hold after the report is issued.
Review trends by hazard, work group, contractor and control type. A falling overdue total can still conceal poor performance if teams close actions administratively or remove old findings from the register. A recurring lifting, isolation or traffic-control finding should trigger a review of the underlying planning, supervision and subcontractor assurance arrangements.
Digital tools can help preserve photographs, interview notes, field observations, notifications and approval history. They cannot decide whether evidence is adequate. Managers must set acceptance criteria, challenge vague descriptions, and keep an action open until the control has been tested in the conditions where the work occurs.
Building a Culture of Field Verification
A mature audit culture changes what managers ask during site visits. Instead of asking whether the form is complete, they ask whether the control is present, understood, maintained and effective for the conditions in front of them.
That requires independence without isolation. Auditors need enough distance from the task to challenge decisions, but they also need operational knowledge to recognise when a control is impractical. An external auditor can provide fresh scrutiny. An internal auditor can understand production constraints and follow issues through the business. The choice depends on competence, conflict of interest and the purpose of the audit.
Worker participation provides another test of quality. Workers see workarounds, production pressure and control failures before those issues appear in a report. Ask open questions, observe the task without disrupting it, and compare answers across roles. If workers describe different controls for the same hazard, the system has an implementation problem even when the procedure is correct.
The strongest audit finding is specific enough for an operations manager to act on and clear enough for a worker to recognise.
Field verification should also evolve when the risk changes. Review the program after an incident, equipment change, new process, new contractor, regulator focus or recurring action. Include psychosocial hazards where work design, workload, conflict, poor support or exposure to traumatic events may create risk. A checklist that never changes can become evidence that the audit program is static, not that the workplace is controlled.
Industrial inspection resources, such as the MA Hydraulics Ltd inspection tag archive, can provide useful examples of how inspection records and equipment checks are presented. They still need to sit inside a wider WHS audit process that examines ownership, follow-up, worker behaviour and control effectiveness.
For Australian construction, manufacturing and industrial services businesses, the operating standard is clear. Audit the highest-risk work, test subcontractor interfaces, verify SWMS implementation, involve workers, protect auditor independence and track each finding until the control proves effective. A complete file is not the same as a controlled risk.
Safety Space provides digital audit forms, mobile field evidence capture, audit scheduling, reporting and corrective-action tracking for multi-site and subcontractor operations. Visit Safety Space to see how the platform can support a risk-based WHS audit program that follows findings from the workface through to verified closure.
Ready to Transform Your Safety Management?
Discover how Safety Space can help you implement the strategies discussed in this article.
Explore Safety Space FeaturesRelated Topics
Safety Space Features
Explore all the AI-powered features that make Safety Space the complete workplace safety solution.
Articles & Resources
Explore our complete collection of workplace safety articles, tools, and resources.