14.2 Inspections, Audits and Legal Compliance Auditing
Key Takeaways
- CR 5(1)(o) requires the client to ensure health and safety audits and document verification at intervals mutually agreed but at least once every 30 days, and CR 5(1)(p) requires the report to reach the principal contractor within seven days.
- CR 7(1)(c)(vii) imposes the identical 30-day audit floor on the principal contractor auditing its contractors, and CR 7(3) cascades that duty down the contracting tiers.
- An inspection tests the physical condition of specific plant or work by the appointed competent person, while an audit tests the system and requires independence from the activity being audited.
- A defensible audit triangulates document, interview and observation evidence for each element, so that a finding is supported on all three legs.
- CR 5(1)(q) and CR 7(1)(c)(viii) create statutory stop-work duties for imminent danger that the client and principal contractor may not decline to exercise.
14.2 Inspections, Audits and Legal Compliance Auditing
[!NOTE] SACPCMP Blueprint Context: This section develops the audit half of Annexure B item 4, "Health and Safety Performance (audit and reviews)". It is one of the highest-yield areas of the CHSO examination because the Construction Regulations 2014 impose audit duties on both the client and the principal contractor, with a hard maximum interval and a hard report turnaround.
1. Four Different Activities That Candidates Confuse
South African construction generates four distinct assurance activities, and a CHSO must be able to place any scenario in the right box.
| Activity | Object | Typical frequency | Statutory anchor |
|---|---|---|---|
| Inspection | Physical condition of a specific item or work area | Daily to weekly | CR 12(3)(f), CR 13(2)(h), CR 16(2) via SANS 10085-1, CR 23(1)(k), CR 24(d)-(e) |
| Audit | The management system that produces safe conditions | At least every 30 days on site | CR 5(1)(o), CR 7(1)(c)(vii) |
| Legal compliance audit | Whether identified legal requirements are met | Typically annual or on legal change | ISO 45001 cl. 9.1.2; supports s 16(1) due diligence |
| Survey / measurement | A quantified exposure | Per the applicable regulation | NIHLR (noise), HCA Regulations (chemical), lighting |
The distinction that most often decides an examination question is inspection versus audit. An inspection asks "is this scaffold safe today?" and is performed by the appointed competent person for that plant. An audit asks "does the process that inspects scaffolds actually work, and can you evidence it?" and must be performed by someone independent of the activity being audited.
2. The Statutory 30-Day Audit Cycle
Two provisions run in parallel, one down from the client and one down from the principal contractor:
- CR 5(1)(o) — the client must ensure that periodic health and safety audits and document verification are conducted at intervals mutually agreed upon between the principal contractor and any contractor, but at least once every 30 days.
- CR 5(1)(p) — a copy of that audit report must be provided to the principal contractor within seven days after the audit.
- CR 7(1)(c)(vii) — the principal contractor must ensure that periodic site audits and document verification are conducted at intervals mutually agreed upon between the principal contractor and any contractor, but at least once every 30 days.
- CR 7(3) — where a contractor appoints another contractor, the duties in CR 7(1)(b) to (g) apply to that contractor as if it were the principal contractor, so the audit cascade continues down the tiers.
[!IMPORTANT] "Mutually agreed upon … but at least once every 30 days" sets a floor that agreement cannot lower. Parties may agree to audit fortnightly; they may not agree to audit quarterly. And the duty in CR 5(1)(o) is not merely to audit — it expressly includes document verification, which is why an audit that walks the site without opening the health and safety file is incomplete.
Note also what the regulation does not say. It does not name the auditor, prescribe a scoring protocol, or require an external auditor. A client discharges CR 5(1)(o) through its agent, its own safety department, or an appointed consultant.
3. Designing an Audit That Finds Something
A protocol that only samples paperwork will find paperwork failures. A defensible construction health and safety audit triangulates three evidence types for each element it tests:
- Document — does the required document exist, is it current, and is it the controlled version?
- Interview — can the person named in the document describe what it requires of them?
- Observation — does the physical site match what the document and the person say?
Applied to fall protection, that means: the CR 10(2) fall protection plan exists and covers the current work fronts (document); the CR 10(1)(a) competent person can explain the rescue plan required by CR 10(2)(e) (interview); and workers at the leading edge are anchored to points the plan actually identifies (observation). A finding raised on all three legs is very hard for a contractor to argue away.
Grading findings
Most South African construction audit protocols grade findings on consequence and immediacy rather than a single score:
| Grade | Definition | Required response |
|---|---|---|
| Imminent danger | A condition likely to cause death or serious injury before the next audit | Stop the activity immediately under CR 5(1)(q) (client) or CR 7(1)(c)(viii) (principal contractor); do not wait for a written notice |
| Major non-conformance | A statutory duty is unmet, or a system element has failed entirely | Corrective action notice with named owner and short due date; verify effectiveness |
| Minor non-conformance | A single lapse in an otherwise functioning process | Corrective action notice; verify at next audit |
| Observation | No breach, but a weakness that will become one | Log and track; no formal close-out required |
The stop-work powers deserve emphasis because they are statutory, not discretionary. CR 5(1)(q) obliges the client to stop any contractor from executing a construction activity which poses a threat to health and safety and which is not in accordance with the client's specification and the principal contractor's plan. CR 7(1)(c)(viii) obliges the principal contractor to stop any contractor executing construction work not in accordance with those documents or which poses a threat. Neither is a right the parties may decline to exercise.
4. Legal Compliance Auditing
A legal compliance audit is a different instrument. Rather than testing whether the system works, it tests whether each identified legal requirement is met, item by item. Its inputs are a legal register — the OHS Act, the Construction Regulations 2014, the General Administrative Regulations 2003, the General Safety Regulations, the Driven Machinery Regulations 2015, the Electrical Installation Regulations 2009, the Electrical Machinery Regulations 1988, the Environmental Regulations for Workplaces 1987, the Facilities Regulations 2004, the Noise-Induced Hearing Loss Regulations 2003, the Hazardous Chemical Agents Regulations, the Ergonomics Regulations 2019, COIDA, and any incorporated SANS standards.
Two practical rules govern its usefulness. First, a legal register that is not maintained is worse than none, because it creates documented evidence that the contractor believed itself compliant with a superseded instrument. Second, the audit must record how compliance was verified for each item, not merely a tick — "CR 8(5): appointment letter dated 14/01/2026, signed by CR 8(1) appointee, SACPCMP registration number verified on the Council register" is evidence; a tick is not.
5. Following the Findings Through
The audit is worthless without the loop. Under GAR 9(4) the employer must ensure that necessary actions arising from incident records are implemented and followed up to prevent recurrence, and ISO 45001 clause 10.2 requires review of the effectiveness of corrective action. Applied to audit findings the discipline is identical:
- Every finding gets a named individual owner — never a department.
- Every finding gets a date, set by consequence, not convenience.
- Every closed finding gets a verification entry by someone other than the person who closed it.
- Repeat findings get escalated to management review rather than re-issued, because a finding appearing twice is a system defect, not a site defect.
During an audit the CHSO finds workers on an unbraced falsework deck immediately before a concrete pour, with visible lateral movement in the props. What is the correct immediate action and its legal basis?
A client and a principal contractor sign a project agreement setting the site health and safety audit interval at 45 days, on the basis that CR 5(1)(o) requires audits 'at intervals mutually agreed upon'. Is this lawful?
Which description correctly distinguishes an inspection from an audit on a construction site?