Internal audit of occupational health and safety

An internal occupational health and safety (OSH) audit is a planned review that compares the effectiveness of prevention measures against defined criteria. It uses evidence to identify non-compliance, assess the system’s implementation, and guide improvements before problems result in harm.

In short

An internal audit needs scope, criteria, competent personnel, and sufficient independence. Its outcome should explain what was verified, what evidence supports the findings, and how the agreed-upon actions will be followed.

Content
  1. What is an internal OSH audit
  2. Differences between an inspection and a legal audit
  3. How to prepare the program and its scope
  4. Team competence and independence
  5. Obtaining evidence and writing up findings
  6. Practical example
  7. Follow-up and closure
  8. Records and limits of the conclusion
  9. Related concepts
  10. On the blog
  11. References

AZ Dictionary →

What is an internal OSH audit

It is an organized process to determine whether preventive management meets the criteria the organization has decided to verify and whether it is being applied effectively. These criteria may derive from applicable legislation, internal procedures, or system commitments. The review requires gathering and verifying sufficient information; it is not limited to asking if documents exist or checking boxes on a generic list.

The term “internal” describes who the audit is for: it serves the organization itself. It can be performed by company personnel or professionals hired specifically for that purpose. The crucial issue is their competence and ability to evaluate independently of those responsible for justifying the reviewed process. A report prepared by an external party does not automatically become a legal or certification audit.

An inspection typically focuses on observable conditions of equipment, facilities, or tasks. An audit connects those conditions with decisions, procedures, and records: why equipment was authorized, how its maintenance was scheduled, or what was done after a deviation. Both tools can complement each other, but they don’t necessarily have the same scope or pursue the same conclusion.

Occupational health and safety (OSH) audits can also fulfill regulatory or certification requirements. In Spain, the Regulation of Prevention Services establishes the assumptions and conditions for audits of the prevention system. An internal review does not replace legally required audits nor does it allow for presentation as certified. The program must clearly define the purpose of each review to avoid using a report outside the scope for which it was prepared.

How to prepare the program and its scope

The program distributes audits over time, taking into account risks, changes, past results, and the relevance of the processes. Not all facilities require the same level of effort in each review. A new activity, a significant incident, or a recurrence of failures may warrant greater attention than a stable process with verified controls.

For each audit, the scope is defined: centers, activities, periods, and groups included. The criteria and resources are also specified. Less visible shifts, maintenance work, concurrent companies, and non-routine operations should be considered when relevant. Systematically excluding these situations can create a false sense of security that does not reflect the actual work. The limitations of the sampling must be clearly stated in the report.

Team competence and independence

The team needs to understand the risks of the activities being reviewed, the criteria used, and the techniques for obtaining evidence. Knowing how to interpret a standard is not enough to assess a complex operation without technical knowledge. When necessary, specialized support is brought in, while preserving the responsibility of the person leading the audit.

Independence is ensured by preventing any one person from exclusively evaluating their own work. In small companies, it may be necessary to involve other departments or seek external support. How the results are received is also important: if the findings lead to retaliation or pressure to soften conclusions, the process’s usefulness diminishes. Interviews should provide information without turning the audit into a blame game.

Obtaining evidence and writing up findings

Evidence can come from direct observation, interviews, and documents, all of which should be compared and contrasted. A signed procedure outlines what is planned; observing a task reveals how it is carried out; records show some of the monitoring. Contradictions between these sources are relevant and should be investigated before drawing a conclusion.

A non-conformity in occupational health and safety (OSH) requires an identifiable requirement and evidence of non-compliance. The report must differentiate it from a suggestion for improvement or a question pending confirmation. Expressions such as “lack of a preventive culture” are too broad if they do not explain the facts, scope, and criteria. Sufficient references must be retained to understand and review the conclusion without disclosing unnecessary personal data.

Practical example

An audit is reviewing how maintenance on a production line is prepared. The procedure requires verifying energy isolation before any work begins. While authorization appears in the records, interviews and observation reveal that a secondary energy source is not listed in the inventory used by the team. The presence of signatures does not demonstrate complete control.

The finding identifies the task, the requirement, and the evidence. The organization takes immediate action, reviews the inventory of energy sources, and checks whether other production lines share the problem. Subsequent verification observes the actual intervention and reviews staff preparedness. Closing the finding simply because a document has been updated would leave the effectiveness of the solution unverified.

Follow-up and closure

Each finding must receive a response commensurate with its relevance, including assigned responsibilities, deadlines, and criteria for verifying the outcome. The audit provides information; the management of the actions falls to those with the authority and resources to implement them. Significant delays and difficulties that cannot be resolved within the area must be escalated to the appropriate level.

Closure requires verifying the commitments made and, where applicable, their effectiveness. It is helpful to distinguish between implemented measures and verified results. The recurrence of a finding may indicate unresolved issues, an overly narrow scope, or insufficient verification. The aggregated results feed into the PDCA cycle and help refine the priorities of the next program.

Records and limits of the conclusion

The plan, criteria, relevant evidence, report, and follow-up must be preserved through appropriate document control. The documentation should allow for the reconstruction of what was reviewed and what was omitted. A very long report is not necessarily better if it makes it difficult to identify the problems that require a decision.

All audits use limited information and time. Their conclusions pertain to the scope and evidence obtained; they do not guarantee the complete absence of risk or permanent compliance. This limitation does not diminish the tool’s value: it simply requires combining it with daily monitoring, staff participation, and inspections tailored to specific activities.

Related concepts

On the blog

References

  1. Official State Gazette. Royal Decree 39/1997, Regulations for Prevention Services. Consolidated text. Official source
  2. Official State Gazette. Law 31/1995, on Occupational Risk Prevention. Consolidated text. Official source
  3. Occupational Safety and Health Administration. Recommended Practices for Safety and Health Programs: Program Evaluation and Improvement. Official source

Editorial information

Publication date: October 10, 2026.

Editorial Manager: Sabentis Editorial Team.

Author: Pablo Rodríguez LinkedIn

Executive Vice President of the ORP International Foundation and Chief Financial Officer of Sabentis.

Request a Demo

Discover all that Sabentis can do for your organization.

Try Sabentis

request a demo
stars 5
GetApp Software Advice Capterra