4.1 Safety Auditing Procedures
Key Takeaways
- A safety audit is a systematic, independent, and documented evaluation of whether the HSE management system conforms to planned arrangements and is effectively implemented
- ISO 45001 Clause 9.2 requires planned internal audits against defined scope, criteria, and auditor competence rules
- Findings are classified as major nonconformities, minor nonconformities, observations, or opportunities for improvement — each drives different corrective action urgency
- First-party audits are internal; second-party audits are customer/contractor; third-party audits are independent certification or regulatory assessments
- Supervisors must support evidence collection, close corrective actions, and never coach workers to hide nonconformities during audits
On the ISPON HSE Level 3 exam, auditing sits inside the HSE Management Systems, Leadership, and Auditing domain (about 20% of the paper). Supervisors are not expected to be full-time lead auditors, but they must understand how audits verify the Health, Safety, and Environment Management System (HSE-MS), how findings are classified, and how corrective actions are tracked to closure.
A safety audit is a systematic, independent, and documented process for obtaining objective evidence and evaluating it objectively to determine the extent to which audit criteria are fulfilled. In plain language: auditors compare what the organisation says it does against what it actually does, using records, interviews, and workplace observation.
Why Auditing Matters for Supervisors
Audits protect workers and the business when they reveal gaps before incidents do. Under frameworks such as ISO 45001 (Occupational Health and Safety Management System) and HSG65 Plan-Do-Check-Act thinking, internal audit is part of the Check stage. Nigerian employers in oil and gas, construction, manufacturing, and logistics also face client audits, contractor bridging reviews, and regulatory inspections — all of which test whether local work packs, permits, and training records match reality.
As a supervisor you typically:
- Keep area procedures, permits, training matrices, and inspection records ready for sampling
- Escort auditors safely and answer questions honestly with evidence
- Own or chase corrective actions for findings raised in your area
- Brief crews so audits are treated as learning opportunities, not blame sessions
Types of Safety Audits
| Audit type | Who performs it | Typical purpose |
|---|---|---|
| First-party (internal) | Organisation’s own trained auditors | Verify HSE-MS conformity and effectiveness before external scrutiny |
| Second-party | Customer, client, or contractor partner | Assure supplier/contractor HSE competence and bridging documents |
| Third-party | Independent certification body or regulator | Certification (e.g., ISO 45001), surveillance, or statutory compliance |
| Compliance audit | Internal or external | Check legal and other requirements (Factories Act duties, permit conditions, NESREA/NUPRC expectations) |
| System / management-system audit | Usually trained auditors | Evaluate policy, planning, support, operation, performance evaluation, and improvement as a whole |
| Process / operational audit | Internal specialists or supervisors with audit training | Deep-dive one process (PTW, confined space, journey management) |
First-party audits are mandatory in ISO 45001 Clause 9.2. They must be planned, take account of risk and previous results, and be conducted by people who are independent of the work being audited as far as practicable — you should not audit your own crew’s permit system alone without objectivity safeguards.
Second-party audits are common on Nigerian project sites when operators audit contractors or when a principal contractor audits subcontractors. Bridging documents, method statements, and competence matrices are frequent evidence samples.
Third-party audits include certification and surveillance visits. Regulators may also conduct compliance-focused assessments that feel like audits even when labelled “inspections.”
Audit Criteria, Scope, and Evidence
Every audit needs three clear definitions before fieldwork starts:
- Scope — boundaries (site, department, processes, time period)
- Criteria — the “should” against which performance is judged (ISO 45001 clauses, company procedures, legal requirements, client standards)
- Methods — document review, interviews, observation, sampling
Objective evidence includes signed permits, toolbox-talk attendance sheets, calibration certificates, incident logs, training records, risk assessments, and observed behaviours. Opinions without evidence are not audit findings.
Typical Audit Process (PDCA Aligned)
| Stage | Activities |
|---|---|
| Plan | Set programme, select scope/criteria, assign competent auditors, issue plan and checklist |
| Conduct | Opening meeting → evidence gathering → daily/closing debriefs |
| Report | Document findings with evidence references; classify severity |
| Follow-up | Corrective action, verification of effectiveness, programme update |
Opening meetings confirm scope, logistics, HSE rules for the audit team, and confidentiality. Closing meetings present draft findings so auditees can correct factual errors before the report is finalised.
Findings and Nonconformities
A nonconformity (NC) is the non-fulfilishment of a requirement. Auditors also raise observations (potential weaknesses without clear requirement breach) and opportunities for improvement (OFI) (better practice suggestions).
| Classification | Meaning | Typical supervisory response |
|---|---|---|
| Major NC | Systemic failure or complete absence of a required control; significant risk or legal breach | Immediate containment; formal corrective action; escalate to management |
| Minor NC | Isolated lapse or partial implementation with limited risk | Root-cause action within agreed deadline; verify fix |
| Observation | Weakness or inconsistency not proven as NC | Trend and strengthen controls before it becomes an NC |
| OFI | Improvement suggestion | Consider in continual improvement plans |
Example — Major NC: No Permit-to-Work system exists for hot work in a live process area, despite procedure and legal expectations.
Example — Minor NC: Three of twenty sampled toolbox talks lack attendee signatures for one week, while the process otherwise functions.
Corrective action must address root cause, not only the symptom. Re-training alone is weak if the real cause was an unworkable procedure or missing tools. Effectiveness verification (did the fix stick?) closes the loop — reopening the same finding at the next audit is a classic Level 3 exam trap.
Auditor Competence and Ethics
Competent auditors understand HSE criteria, sampling methods, and interview technique. They remain impartial, protect confidential information, and never accept gifts that compromise independence. Supervisors must not coach workers to give false answers or hide defective equipment; that behaviour creates bigger legal and certification risk than an honest nonconformity.
Linking Audits to Continual Improvement
Audit results feed management review, HSE objectives, and training needs analysis. High-performing sites track open NCs by age, recurrence rate, and area ownership. For ISPON Level 3, remember the distinction: audits test the system; inspections (next section) check workplace conditions day to day. Both generate findings, but audits are broader, criteria-driven, and usually less frequent.
According to common HSE-MS practice aligned with ISO 45001, which statement best describes a first-party safety audit?
During an internal audit, auditors find that confined-space entry is routinely performed with no atmospheric testing, no rescue plan, and no entry permit, despite a written company procedure requiring all three. How should this finding typically be classified?
What are audit criteria in a safety audit?
A supervisor’s most appropriate role when a third-party certification audit visits their area is to: