Set the boundary before choosing a label
An audit request needs to identify the requirements being checked and the sites, activities and period included. A risk-assessment request needs to identify the activity and people exposed, including changes and interfaces. Neither title establishes the depth of evidence collection or the competence needed.
Illustrative comparison: a changed work procedure
A manager wants to know whether the approved procedure is being followed and whether it still addresses the changed task. The first question can be part of an audit against agreed criteria. The second requires examination of the current activity and its hazards. A record showing that a procedure was signed does not settle whether its controls remain suitable.
Read the output in relation to the question
An audit finding should connect the criterion, evidence and observed gap. An assessment should explain the activity, identified hazard, potential consequence and controls considered. Where evidence is incomplete, the output should say so. Avoid converting an absence of evidence into a blanket assurance statement.
Decide what follow-up is needed
A finding may lead to an assessment review; an assessment may lead to checks on implementation. Assign the follow-up and decide how the outcome will be verified. Keep the original evidence and the later verification distinct so management can see what changed.
Compare the evidence
| Aspect | Audit | Risk assessment |
|---|---|---|
| Primary question | How does evidence compare with criteria? | What could cause harm and how is it controlled? |
| Starting information | Agreed criteria and evidence sources | Activity details and change context |
| Useful follow-up | Address and verify findings | Implement and review controls |

