A new safety manager finds an unguarded penetration during a Tuesday walk across a commercial construction slab. The immediate response is obvious, isolate the area, install a physical control, and notify the supervisor. The harder question is whether that walk was an inspection or a work health and safety audit. The answer matters because each activity produces different evidence and supports a different management decision.
A useful audit doesn't ask whether a site looked safe for an hour. It tests whether the PCBU has designed, implemented and reviewed arrangements that meet its primary duty under the WHS Act. It also tests whether those arrangements work under normal operating pressure, across workers, supervisors, contractors and sites.
Table of Contents
- What a Work Health and Safety Audit Actually Is
- Setting Scope, Type and Cadence for Your Audit Program
- Building the Audit Checklist and Scoring Criteria
- Collecting Evidence and Scoring Findings on Site
- Writing the Audit Report and Logging Corrective Actions
- Tracking Remediation and Closing Out Actions
- Tips, Common Pitfalls and Using Safety Space
What a Work Health and Safety Audit Actually Is
A work health and safety audit is a systematic, documented and evidence-based review of a PCBU's safety arrangements against defined criteria. The central test is whether the organisation has ensured, so far as is reasonably practicable, the health and safety of workers and other persons, as required by the primary duty in section 19 of the model WHS Act. The same framework requires the PCBU to eliminate risks where reasonably practicable, or minimise them where elimination isn't reasonably practicable. The model WHS Act provides the legal foundation for that test.
An inspection is narrower. It checks conditions and controls at a point in time. A toolbox talk communicates a hazard, task control or change in work method. A compliance spot check tests a selected requirement. An audit follows the chain from obligation to control, implementation, evidence and management review.

Three audit relationships
The person commissioning and receiving the audit changes its purpose.
- Internal audits support management review. The auditor can be an employee, but shouldn't audit an area where they control the work or own the outcome.
- Second-party audits assess a supplier, subcontractor or project partner for a client, principal contractor or head contractor. Contractual requirements often sit alongside legal duties.
- Regulator-led audits are conducted by the relevant WHS authority. The regulator may inspect conditions, interview people, review records and require responses to non-conformances.
Safe Work Australia describes an audit as a systematic examination against defined criteria. It also notes that audits and reviews generally aren't mandated under the model WHS Act, although properly conducted audits provide important assurance over WHS systems. Safe Work Australia's assurance and verification guidance also identifies limited schemes where formal certification evidence applies, such as Class A asbestos removal.
A defensible audit doesn't guarantee that an incident won't occur. It does create a traceable record of what the organisation checked, what evidence it considered, what gaps it identified and how it responded. That record is far stronger than a completed checklist with no supporting evidence. For a broader explanation of structured audit practice, the IT Cloud Global audit guide is useful because it reinforces the need to examine systems rather than only collect documents.
The practical model is a cycle: set the scope, test the controls, record findings, assign actions, verify closure and adjust the next audit. Treating the audit as a living risk process is what ties it back to the PCBU's primary duty.
Setting Scope, Type and Cadence for Your Audit Program
A serious incident has exposed a control failure on a manufacturing line. The site manager wants a full-system audit immediately, while the safety team knows the urgent question is narrower: whether the failed control exists, is understood, and works in practice. Scope determines whether the audit answers that question or produces a long report that nobody can close.
Start with the PCBU's operations, hazards on the risk register, recent incidents and near misses, changes to plant or process, and contractual requirements from a principal contractor or client. Define the sites, work groups, subcontractors, shifts and activities included. Tie each boundary to the PCBU's primary duty under the model WHS Act, then identify the correct local Act, regulations and regulator. Australia uses harmonised model laws, but Commonwealth, state and territory governments administer and enforce WHS legislation themselves. The Australian Government's WHS framework overview explains that distinction.
Choose the audit type for the decision required
A compliance audit tests whether applicable legal and regulatory duties are addressed. A program audit examines one process, such as contractor management, incident investigation or working at heights. A management system audit tests how leadership, planning, implementation, review and improvement fit together. An ISO 45001-style audit suits an organisation that maintains or pursues a formal occupational health and safety management system.
A site-specific task audit has a tighter purpose. It can test the SWMS and actual work for crane lifts, scaffolding, confined space entry or live electrical work. Use this format when the risk is concentrated in a task rather than distributed across the whole WHS system. It gives a faster answer, but it will not show whether wider governance or resourcing problems are affecting the control.
Write the scope before booking interviews or requesting records. The document should identify:
- Purpose: What decision will the audit support?
- Criteria: Which legislation, regulations, codes, standards, procedures and contractual clauses apply?
- Boundaries: Which sites, teams, shifts, tasks and contractors are included?
- Evidence: Which records, observations, interviews and samples will be tested?
- Outputs: What must management receive, own and act on?
Record exclusions as well. An audit that starts with scaffolding, absorbs contractor onboarding, then expands into training, procurement and every site document will miss its closure date. A narrow audit with a clear escalation rule is more useful than a broad review that cannot test controls properly.
Set cadence from changing risk
Use risk and change to set the interval, rather than treating an annual audit as proof that the system is under control. High-risk activities such as working at heights, confined space entry or live electrical work may warrant quarterly review. Lower-critical-risk activities may suit six-monthly review, alongside an annual full-system audit. These are planning intervals, not legal rules.
Increase the frequency after a notifiable incident, regulator visit, major process change, repeated finding or material change in contractor arrangements. Keep two measures separate: whether scheduled audits occurred, and whether the controls passed testing. The Federal Safety Commissioner auditing guidance supports using both cadence and control quality when reviewing an audit program.
| Audit type | Typical scope | Best cadence | Example trigger |
|---|---|---|---|
| Compliance | Applicable WHS duties, regulations and codes | Risk-based, with a full-system review annually | Regulatory change or tender requirement |
| Program | One management process, such as contractor control | Quarterly or six-monthly for material risks | Repeated actions or poor incident trends |
| Management system | Leadership, planning, implementation, review and improvement | Annual, plus significant-change reviews | Certification maintenance or restructure |
| Site-specific task | SWMS, plant, supervision and work as done | Before high-risk work and at planned intervals | New task, incident or changed conditions |
Before formal fieldwork, a WHS gap analysis template can help compare the selected requirements with existing evidence. The output should refine the audit, not replace interviews, observations or testing of work as performed. That distinction keeps the program tied to current risk and gives the PCBU a defensible basis for changing the next audit.
Building the Audit Checklist and Scoring Criteria
A checklist should reflect the work people perform, the controls the PCBU has selected, and the duties imposed by the model WHS Act. Start with the legal duties, regulations, codes of practice, risk register, SWMS, plant controls and current site conditions. Each question should identify a requirement and produce evidence that another competent person can review.
Build the checklist as a living risk tool, not a fixed form. Review it after an incident, a material process change, a regulator concern or a repeated finding. That keeps the audit connected to the PCBU's primary duty to ensure health and safety so far as is reasonably practicable. Confirm the relevant state or territory regulator before relying on a legal citation.
For the model WHS Act, map applicable questions to sections 19 and 35 to 39, then map operational controls to regulations 36 to 44 where those provisions apply. The provisions do not apply uniformly to every business, task or jurisdiction, so the checklist should show the basis for each question.
Build questions around control decisions
Group questions by how the business manages risk, while allowing the auditor to follow a process from planning through verification:
- Governance: PCBU responsibilities, consultation, officer due diligence and document control.
- Hazard management: Risk identification, hierarchy of control, SWMS, change management and control verification.
- Competence: Induction, training, supervision, licences and contractor capability.
- Incident management: Notification, investigation, corrective actions and trend review.
- Emergency readiness: Plans, equipment, communication, drills and site-specific response.
- Plant and equipment: Guarding, isolation, inspections, maintenance and operator controls.
Use four outcomes: compliant, partially compliant, non-compliant and not applicable. Require a reason for every “not applicable” result. Otherwise, difficult questions can disappear from the score without a defensible basis.
Break high-risk controls into subcriteria. A lockout procedure should test energy-source identification, isolation points, personal locks, zero-energy verification, shift handover and restoration. A working-at-height control should test edge protection, penetration covers, access, rescue arrangements and inspection records. One tick cannot show whether all of those elements work.
Practical rule: A checklist item should be short enough to answer, specific enough to evidence and important enough to change a decision.
Weight the controls that affect exposure
An illustrative working-at-heights model can help set priorities. These percentages are planning values, not an industry benchmark. Adjust them to the site's hazards and control design.
| Checklist item | Legal reference | Weight (%) | Conformance criteria |
|---|---|---|---|
| Edge protection or approved fall-prevention system | WHS Act section 19 and applicable regulations | 30 | Compliant only where the system is installed, suitable and in use |
| Penetration protection and covers | WHS Act section 19 and applicable regulations | 25 | Compliant where covers are secured, marked and load-suitable |
| SWMS, supervision and worker understanding | WHS Act section 19 and relevant high-risk work duties | 20 | Compliant where the SWMS reflects the task and workers can explain controls |
| Rescue and emergency response | WHS Act section 19 and site emergency arrangements | 15 | Compliant where equipment, roles and response arrangements are available |
| Housekeeping and access routes | WHS Act section 19 and site controls | 10 | Compliant where access is clear and conditions are maintained |
Weight controls that prevent serious harm more heavily than low-consequence housekeeping issues. A final score should show exposure to uncontrolled risk, rather than reward an auditor for completing many easy questions. The facility compliance audit guide for 2026 offers a useful external comparison, provided its generic structure is adapted to Australian WHS law, the correct regulator and the site's actual risks.
Collecting Evidence and Scoring Findings on Site
An auditor's credibility depends on the evidence trail. A statement such as “workers appear compliant” doesn't tell management what was seen, who was interviewed or which requirement was tested. Record the condition, the source, the location, the relevant criterion and the reason for the rating.
The four evidence methods below don't carry equal weight for every question.
| Evidence method | Reliability | What it reveals |
|---|---|---|
| Physical inspection | High for visible controls | Whether guarding, access, signage, barriers and equipment conditions exist |
| Document review | High for system design and records | Whether procedures, registers, training and review mechanisms are documented |
| Interview | Moderate, strengthened by corroboration | Whether workers and supervisors understand duties and can describe normal practice |
| Observation of work as done | High for implementation | Whether people follow the documented method under real operating conditions |
Physical inspection is usually the strongest evidence for a missing guard. Documents are stronger for testing whether the PCBU has defined a process, reviewed it and assigned responsibility. Interviews expose the gap between a SWMS and the way the task is performed. Observation is essential where workers can bypass a control without the paperwork changing.
Choose a scoring model that matches the decision
A binary conform or non-conform model is simple and can work for tightly defined checks. A three-level traffic-light model gives management more context, but auditors can apply amber inconsistently. A weighted risk-based model takes more discipline and produces a more useful result where controls differ greatly in consequence.
Consider an unguarded press. It should be treated as a major finding because the physical control is absent and the exposure may be immediate. A missing signature on an otherwise completed SOP review may be minor, unless the missing record prevents the organisation from proving competence or document approval. The rating comes from the risk and system impact, not the visual neatness of the record.
Federal construction audit data demonstrates why findings need structure. The Office of the Federal Safety Commissioner completed 657 safety audits in 2024 across 918 on-site compliance-testing days, covering 17,367 audit subcriteria. Those audits produced 3,319 Corrective Action Reports, with an 80.9% compliance rate, and 18% of CARs classified as major compared with 82% classified as minor. The OFSC 2024-25 Annual Data Report supports a practical lesson: use a defined subcriterion matrix, log actions immediately and separate major from minor findings.
Record positive observations as well. A well-maintained isolation board, a supervisor correcting a control without prompting or workers stopping a task to resolve uncertainty are evidence of effective arrangements. Positive evidence doesn't dilute a finding. It helps distinguish a local lapse from a system that is working and builds more constructive conversations with crews. For mobile evidence capture, a tool such as mobile safety inspection software can keep photos, notes and actions connected to the relevant checklist item.
Writing the Audit Report and Logging Corrective Actions
A report should allow a senior leader to understand the exposure quickly and allow an operational manager to fix it without guessing. Start with a cover page stating the PCBU, site, audit dates, scope, auditor, participants and criteria. Follow it with an executive summary that separates effective controls, major findings, minor findings and overdue matters.
The methodology note should identify how evidence was collected. State whether the auditor reviewed documents, inspected the site, observed work and interviewed workers or supervisors. A report that hides its limitations invites challenge.
Write findings as evidence, not opinion
Use a consistent structure:
- Statement of fact: What did the auditor see, review or hear?
- Requirement: Which legal, regulatory, procedural or contractual criterion applies?
- Evidence: What document, photograph, record or interview supports the finding?
- Risk and rating: Why does the gap matter, and is it major or minor?
- Required action: What must the owner change, not merely investigate?
For example:
Finding: Two temporary slab penetrations were open beside an active access route, with no secured covers or edge protection observed during the site walk. The site control required penetrations to be covered or barricaded before work continued. The condition creates a fall exposure and requires immediate isolation, followed by verification of the permanent control.
That wording is stronger than “fall protection needs improvement”. It identifies the condition, the criterion, the evidence and the action. If a SafeWork inspector later reviews the report, the reasoning is visible.
Make corrective action reports operational
Each corrective action report should contain:
- Owner: A named person with authority to implement the action.
- Due date: Set according to risk, not convenience.
- Action: A specific control change, document revision, training activity or engineering solution.
- Closure evidence: The photo, revised procedure, inspection record, competency evidence or reinspection result required.
- Escalation: The manager who receives notice if the action passes its due date.
Don't assign “review WHS” to a department. Assign “install and secure covers to all identified slab penetrations, photograph each location and arrange independent verification” to a person who can make it happen. High-risk immediate exposures need containment first. The permanent action can follow, but the report must show both stages.
A report also needs a clear distinction between correction and corrective action. Replacing one missing guard corrects the immediate condition. Reviewing why the guard was absent, checking other similar machines and changing the inspection process addresses the system weakness. Senior management needs both views.
Tracking Remediation and Closing Out Actions
An audit remains open after the report is issued. The PCBU must be able to show that each action was implemented, tested and considered across comparable work areas. A live remediation register keeps that evidence together instead of scattering it across PDFs and email threads.
Give every finding a unique reference, site, owner, risk rating, due date, status and evidence requirement. Set the response according to exposure. A serious finding may need immediate containment and a reinspection, while a minor document-control issue can wait for the next management cycle. The due date should reflect risk and operational reality, never convenience alone. The register should also identify the state or territory regulator whose requirements apply, so the PCBU can demonstrate how its primary duty under the model WHS Act is being managed.

Define acceptable closure evidence
Evidence must show that the risk control changed and is working. Set the requirement when the action is created:
- Physical controls: Photographs showing the completed guard, barrier, access arrangement or plant modification.
- Document changes: The approved procedure, revised SWMS, updated risk assessment or controlled register.
- Competence evidence: Attendance, assessment or supervisor verification, rather than a calendar invitation.
- Implementation evidence: Inspection records, observations or worker interviews showing the control is being used.
- Independent verification: A reinspection where the finding involved serious exposure, a systemic failure or an uncertain outcome.
A photograph of a repaired machine proves that work occurred. It does not prove the repair is suitable or that operators can use the machine safely. The verifier must test both points before changing the status to closed.
Overdue actions require a recorded escalation path. The owner explains the delay, the responsible manager sets an interim control, and the risk reaches the PCBU or relevant senior leader. Record every due-date change. Otherwise, the organisation loses the history needed to identify resourcing and accountability problems.
Data quality also affects remediation. The Federal Safety Commissioner annual data report describes compliance information accumulated over about 20 years, alongside inadequate IT and data-governance systems and processes. The Federal Safety Commissioner annual data report shows how weak data structures can limit trend analysis, repeat-offender tracking and confidence in evidence.
A digital case-management system can keep actions visible across sites and subcontractors, even when personnel or project assignments change. Compliance case management software can support the register, evidence workflow and verification record required for defensible closeout.
Tips, Common Pitfalls and Using Safety Space
The failures are predictable. Teams review paperwork but don't watch the task. They run one large annual audit, then spend months closing findings. They calculate a score without weighting risk. They mark actions complete because someone uploaded a document, without checking whether the control changed in the field.
A practical pre-audit review should examine incident records, hazard registers, previous findings, overdue actions, SWMS changes and contractor performance. Keep the checklist below 80 well-worded questions where that is enough to test the defined scope. A short, relevant checklist produces better evidence than a long catalogue of weak questions.
Field habits that improve the result
- Walk the floor: Spend time where the work happens, including less convenient areas and different shifts.
- Sample evidence: Test records against actual workers, plant and tasks instead of counting documents.
- Use one rubric: Apply the same conformance and severity definitions across comparable sites.
- Review actions proportionately: Check high-risk actions more often and escalate slippage early.
- Report patterns: Tell management about recurring contractor, training, plant or supervision weaknesses, not just isolated defects.
- Keep workers involved: Discuss findings with the crew while the evidence is fresh and ask what makes the control difficult to follow.
Recent regulatory activity reinforces the need for follow-up, particularly for psychosocial risks. Safe Work Australia's NSW case study records 649 inspector audits from 1 July 2025 to 30 April 2026, with 376 notices and 5 prohibition notices connected to deficiencies in psychosocial WHS risk management. The Safe Work Australia case studies show why a program can't stop at identifying a gap. It must demonstrate action and verification.
Paper, spreadsheets and generic audit apps can work for a small, stable operation. They become difficult to control when evidence, corrective actions and subcontractor responsibilities sit in separate places. A purpose-built platform can connect digital checklists, photos, scoring, action ownership and verification across sites. Use the technology to enforce the method, not to replace competent judgement.
Safety Space provides digital audit forms, evidence capture, scoring templates and corrective-action tracking for multi-site and subcontractor environments. Visit Safety Space to arrange a demonstration and discuss how to build a risk-based audit cycle around your construction, manufacturing or industrial operations.
Ready to Transform Your Safety Management?
Discover how Safety Space can help you implement the strategies discussed in this article.
Explore Safety Space FeaturesRelated Topics
Safety Space Features
Explore all the AI-powered features that make Safety Space the complete workplace safety solution.
Articles & Resources
Explore our complete collection of workplace safety articles, tools, and resources.