Diba-branded safety consultants at a commercial building site

OHS compliance audits

Know where your OHS compliance stands.

Review current OHS arrangements and plan focused corrective action.

Who this service is for

Support for your team and your projects.

This service is for organisations that need a documented view of their current position, not a generic inspection or a promise of certification. An audit is most useful when its findings support a real decision, such as setting improvement priorities, checking earlier actions or understanding variation between sites. State who will use the results and what that person or team needs to decide.

Conceptual illustration of a magnifying lens examining an audit file

Your project

Do you need a structured review of current OHS arrangements against defined requirements?

The final scope is defined for the organisation, workplace or project involved.

01

Business and facility leaders

For leaders who need an organised view of current arrangements and priorities across a workplace or site.

02

SHEQ and compliance teams

For teams preparing an internal improvement programme, management review or follow-up process.

03

Multi-site organisations

For organisations considering a defined review across several locations with a consistent scope.

Choose the correct review

Audit and risk assessment answer different questions.

The two services can inform one another, but they should not be treated as duplicate names for the same engagement. For example, an audit may identify that an assessment record is missing or outdated, while the assessment itself examines the work and the controls it needs. Linking the two can support improvement without merging their distinct purposes.

OHS compliance audit and risk assessment comparison
Decision pointCompliance auditRisk assessment
Primary questionHow does the current position compare with defined requirements?What hazards are present, what could happen and which controls are appropriate?
Typical starting pointAn agreed audit basis and current evidence.The work, workplace, task or project context.
Decision supportedPrioritising gaps and corrective action.Selecting and reviewing risk controls.
What it does not proveGuaranteed compliance or certification.That every hazard has been eliminated.

Service scope

What the work can include.

The audit basis and expected output are agreed before review work begins. The engagement may use document, workplace and stakeholder inputs that are relevant to that basis.

01

Audit basis

Define the requirements, internal standards or agreed criteria against which the current position will be reviewed. Confirm the operations, locations and time period being considered, together with the criteria relevant to the review. Different departments may use different internal requirements, so clarify which versions apply. This prevents findings from being judged against an unclear or changing reference point.

02

Evidence review

Identify the records, workplace observations and stakeholder inputs needed for the agreed audit scope. A record can show what was planned, while conversations and workplace observations can help explain how an activity operates. Agree the mix of inputs needed for the review. Where information is unavailable or access is limited, that gap should remain visible in the audit context.

03

Findings and priorities

Present evidence-based findings in a form that helps the organisation understand gaps, strengths and relative priorities. A useful finding links the issue raised to the relevant criterion and the evidence considered. It should help the organisation distinguish a specific gap from a broader improvement opportunity. Clear descriptions also make it easier for action owners to ask questions before deciding on a response.

04

Corrective-action support

Where included, help organise actions, ownership and follow-up without guaranteeing the organisation’s final compliance position. Discuss whether support ends with the findings or includes a later review of agreed actions. The organisation can identify an owner, target date and evidence of completion for each action. A planned action should remain distinguishable from one that has been implemented and checked.

Engagement process

How we get started.

  1. 01

    Set the audit purpose

    Confirm why the audit is needed, which sites or operations are included and what will be reviewed. Explain whether the review is a first assessment of current arrangements, a planned internal exercise or follow-up to earlier findings. This influences what information is useful and how much attention should be given to changes since the previous review.

  2. 02

    Agree the evidence

    Identify the documents, people and workplace access necessary for a useful review. Identify people who understand the activities being reviewed and arrange access to current records. Let the team know about shift patterns, restricted areas or unavailable personnel so the review plan reflects the evidence that can realistically be examined.

  3. 03

    Conduct the review

    Assess the agreed evidence and operating context against the defined audit basis. Clarify factual questions during the review where possible. Distinguish what was directly observed from what was reported or documented, and keep the limits of any sample clear. This gives later discussions of the findings a traceable foundation.

  4. 04

    Use the findings

    Discuss priorities and any agreed corrective-action or follow-up support. Share the findings with the people who can make decisions and implement changes. Discuss ownership and the evidence needed to demonstrate progress. If a later verification exercise is needed, agree its scope instead of assuming it is included in the initial audit.

Scope and limitations

Scope and responsibilities.

  • An audit reflects the agreed scope, evidence available and position observed during the engagement.
  • The service does not guarantee compliance, certification or the elimination of workplace risk.
  • A compliance audit is not a substitute for a risk assessment where the organisation needs to identify hazards and evaluate risk.

Common questions

Before we get started.

Start an OHS enquiry
What is the purpose of an OHS compliance audit?

It provides a structured view of the current position against defined requirements so an organisation can understand findings and plan appropriate action.

How is an audit different from a risk assessment?

An audit considers conformance against agreed requirements. A risk assessment identifies hazards, evaluates risk and supports control decisions.

Can one audit cover several sites?

A multi-site audit can be scoped for review. The organisation should provide the number, type and location of sites so the audit basis and sampling approach can be defined.

Does an audit guarantee compliance?

No. The audit records findings within its agreed scope. The organisation remains responsible for decisions, corrective actions and its ongoing compliance position.

How should our team prepare for an audit?

Start by confirming the review purpose and the activities or sites included. Identify current procedures, relevant records, earlier findings and action updates, then nominate people who can explain how the work operates. There is little value in creating a separate presentation that hides the normal working process. Tell the reviewer about missing records, access restrictions and recent changes. Accurate preparation helps the review reflect the current position and makes it easier to interpret any limitations in the findings.

What makes an audit finding useful for corrective action?

The organisation should be able to understand the issue, the basis for raising it and the evidence considered. An action owner then needs to decide what change is appropriate, who will carry it out and how completion will be demonstrated. Recording only that an issue is closed can leave uncertainty about what changed. Where follow-up is agreed, discuss whether it reviews submitted evidence, checks implementation at the workplace or addresses another defined question.

Talk to Diba BES

Plan your next step with Diba BES.

Tell us about your project, location and timing. We will help you identify the right service and agree the scope.

Start an OHS enquiry

Planning guidance

Compliance Auditing & Reports are in the approved consulting catalogue. Agree what is being compared, the evidence sample and how findings will inform decisions.

Scope the discussion

Provide the sites, activities, relevant requirements, current document index and existing action records. Ask what document review, interviews, observation and reporting are included. A general “compliance audit” label does not establish exhaustive coverage or a guaranteed outcome.

Illustrative output to discuss

Illustrative report entry: a sampled action is marked complete but the supplied evidence does not demonstrate verification. The report identifies the criterion, sample and gap, then records management’s response. The example is fictional and does not claim a Diba client result.

Information to prepare

Scope and agreed audit criteria; Evidence index with versions; Responsible people and access; Response and verification expectations. Confirm the proposed deliverables, exclusions, programme and commercial terms before an appointment is agreed.

Related guidance and resources

Source context

Source context checked 6 October 2026. Examples are illustrative.