4.1 Safety Auditing Procedures

Key Takeaways

  • A safety audit is a systematic, independent, and documented evaluation of whether the HSE management system conforms to planned arrangements and is effectively implemented
  • ISO 45001 Clause 9.2 requires planned internal audits against defined scope, criteria, and auditor competence rules
  • Findings are classified as major nonconformities, minor nonconformities, observations, or opportunities for improvement — each drives different corrective action urgency
  • First-party audits are internal; second-party audits are customer/contractor; third-party audits are independent certification or regulatory assessments
  • Supervisors must support evidence collection, close corrective actions, and never coach workers to hide nonconformities during audits
Last updated: July 2026

On the ISPON HSE Level 3 exam, auditing sits inside the HSE Management Systems, Leadership, and Auditing domain (about 20% of the paper). Supervisors are not expected to be full-time lead auditors, but they must understand how audits verify the Health, Safety, and Environment Management System (HSE-MS), how findings are classified, and how corrective actions are tracked to closure.

A safety audit is a systematic, independent, and documented process for obtaining objective evidence and evaluating it objectively to determine the extent to which audit criteria are fulfilled. In plain language: auditors compare what the organisation says it does against what it actually does, using records, interviews, and workplace observation.

Why Auditing Matters for Supervisors

Audits protect workers and the business when they reveal gaps before incidents do. Under frameworks such as ISO 45001 (Occupational Health and Safety Management System) and HSG65 Plan-Do-Check-Act thinking, internal audit is part of the Check stage. Nigerian employers in oil and gas, construction, manufacturing, and logistics also face client audits, contractor bridging reviews, and regulatory inspections — all of which test whether local work packs, permits, and training records match reality.

As a supervisor you typically:

  • Keep area procedures, permits, training matrices, and inspection records ready for sampling
  • Escort auditors safely and answer questions honestly with evidence
  • Own or chase corrective actions for findings raised in your area
  • Brief crews so audits are treated as learning opportunities, not blame sessions

Types of Safety Audits

Audit typeWho performs itTypical purpose
First-party (internal)Organisation’s own trained auditorsVerify HSE-MS conformity and effectiveness before external scrutiny
Second-partyCustomer, client, or contractor partnerAssure supplier/contractor HSE competence and bridging documents
Third-partyIndependent certification body or regulatorCertification (e.g., ISO 45001), surveillance, or statutory compliance
Compliance auditInternal or externalCheck legal and other requirements (Factories Act duties, permit conditions, NESREA/NUPRC expectations)
System / management-system auditUsually trained auditorsEvaluate policy, planning, support, operation, performance evaluation, and improvement as a whole
Process / operational auditInternal specialists or supervisors with audit trainingDeep-dive one process (PTW, confined space, journey management)

First-party audits are mandatory in ISO 45001 Clause 9.2. They must be planned, take account of risk and previous results, and be conducted by people who are independent of the work being audited as far as practicable — you should not audit your own crew’s permit system alone without objectivity safeguards.

Second-party audits are common on Nigerian project sites when operators audit contractors or when a principal contractor audits subcontractors. Bridging documents, method statements, and competence matrices are frequent evidence samples.

Third-party audits include certification and surveillance visits. Regulators may also conduct compliance-focused assessments that feel like audits even when labelled “inspections.”

Audit Criteria, Scope, and Evidence

Every audit needs three clear definitions before fieldwork starts:

  1. Scope — boundaries (site, department, processes, time period)
  2. Criteria — the “should” against which performance is judged (ISO 45001 clauses, company procedures, legal requirements, client standards)
  3. Methods — document review, interviews, observation, sampling

Objective evidence includes signed permits, toolbox-talk attendance sheets, calibration certificates, incident logs, training records, risk assessments, and observed behaviours. Opinions without evidence are not audit findings.

Typical Audit Process (PDCA Aligned)

StageActivities
PlanSet programme, select scope/criteria, assign competent auditors, issue plan and checklist
ConductOpening meeting → evidence gathering → daily/closing debriefs
ReportDocument findings with evidence references; classify severity
Follow-upCorrective action, verification of effectiveness, programme update

Opening meetings confirm scope, logistics, HSE rules for the audit team, and confidentiality. Closing meetings present draft findings so auditees can correct factual errors before the report is finalised.

Findings and Nonconformities

A nonconformity (NC) is the non-fulfilishment of a requirement. Auditors also raise observations (potential weaknesses without clear requirement breach) and opportunities for improvement (OFI) (better practice suggestions).

ClassificationMeaningTypical supervisory response
Major NCSystemic failure or complete absence of a required control; significant risk or legal breachImmediate containment; formal corrective action; escalate to management
Minor NCIsolated lapse or partial implementation with limited riskRoot-cause action within agreed deadline; verify fix
ObservationWeakness or inconsistency not proven as NCTrend and strengthen controls before it becomes an NC
OFIImprovement suggestionConsider in continual improvement plans

Example — Major NC: No Permit-to-Work system exists for hot work in a live process area, despite procedure and legal expectations.

Example — Minor NC: Three of twenty sampled toolbox talks lack attendee signatures for one week, while the process otherwise functions.

Corrective action must address root cause, not only the symptom. Re-training alone is weak if the real cause was an unworkable procedure or missing tools. Effectiveness verification (did the fix stick?) closes the loop — reopening the same finding at the next audit is a classic Level 3 exam trap.

Auditor Competence and Ethics

Competent auditors understand HSE criteria, sampling methods, and interview technique. They remain impartial, protect confidential information, and never accept gifts that compromise independence. Supervisors must not coach workers to give false answers or hide defective equipment; that behaviour creates bigger legal and certification risk than an honest nonconformity.

Linking Audits to Continual Improvement

Audit results feed management review, HSE objectives, and training needs analysis. High-performing sites track open NCs by age, recurrence rate, and area ownership. For ISPON Level 3, remember the distinction: audits test the system; inspections (next section) check workplace conditions day to day. Both generate findings, but audits are broader, criteria-driven, and usually less frequent.

Test Your Knowledge

According to common HSE-MS practice aligned with ISO 45001, which statement best describes a first-party safety audit?

A
B
C
D
Test Your Knowledge

During an internal audit, auditors find that confined-space entry is routinely performed with no atmospheric testing, no rescue plan, and no entry permit, despite a written company procedure requiring all three. How should this finding typically be classified?

A
B
C
D
Test Your Knowledge

What are audit criteria in a safety audit?

A
B
C
D
Test Your Knowledge

A supervisor’s most appropriate role when a third-party certification audit visits their area is to:

A
B
C
D