Safety Advice · 10 Jun 2026 · 13 min read

Choosing a WHS Auditor Wisely

admin
admin Safetysure Consultant

Work health and safety auditing has become a crowded market in recent times. Accounting firms, insurance brokers, industry associations and general business consultancies now offer WHS audits alongside their core services, often at attractive prices and sometimes with impressive corporate branding. The results, in our recent experience, has shown that there have been a wave of audit reports that are sometimes inaccurate, poorly grounded in legislation, and indefensible under regulatory scrutiny.

Safetysure has recently reviewed several WHS audit reports prepared for clients by firms whose primary expertise lies in financial assurance. The findings were highly concerning. Legislative citations often referred to repealed provisions. Non-compliances were classified without reference to any legal duty or obligations. Critical risks, including plant guarding deficiencies and confined space hazards visible in the report’s own photographs, went unremarked. In one case, an organisation had paid for an audit that gave its board comfort while leaving it exposed to potential prosecution.

This article explains why WHS auditing is a specialist discipline area, what the different types of audit actually deliver, and how to recognise a competent WHS auditor. It also describes what a properly conducted audit can create for an organisation beyond a compliance scorecard.

WHS auditing is not financial auditing

The audit methodologies used in financial assurance are highly mature and rigorous, and the firms that practise them are typically highly capable within that domain. The problem is not the financial firms, it is largely the problem is the assumption that audit skill transfers across domains (including WHS).

A financial audit tests recorded transactions against accounting standards. The evidence is largely documentary, the standards are typically nationally consistent, and the auditor rarely assess a physical hazard. A WHS audit is fundamentally different in three respects.

  • First, the benchmark is an overarching law, not accounting convention. Every finding in a defensible WHS audit traces to a specific provision. That means a section of the relevant WHS Act, a regulation, a code of practice, or an Australian Standard called up by one of those instruments. Australia’s WHS framework is also jurisdiction-specific. Queensland, New South Wales, and the other harmonised states each maintain their own Acts and Regulations. Victoria operates under a separate OHS regime with different duties, different terminology, and different notification triggers. An auditor who cites the model WHS Regulations to a Victorian employer has potentially produced a finding with no legal foundation.
  • Second, the evidence is physical and behavioural as well as documentary. A documented isolation procedure means little if the auditor cannot recognise that the lockout points on the plant in front of them do not match it. Verifying WHS compliance requires the auditor to walk the site, observe work as it is actually performed on the day of the audit, interview workers, and test whether the paper system reflects practice. The gap between documented systems and real work is one of the most consistent findings in serious incident investigations, and it is precisely the gap a generalist auditor cannot see.
  • Third, the consequences of error are asymmetric. A miscoded ledger entry can be corrected at the next reporting cycle. A missed guarding deficiency can amputate a hand before the report is even issued. The threshold of competence required to declare a workplace compliant is correspondingly higher.

Know what type of audit is being purchased

Much of the disappointment we encounter stems from a mismatch between what an organisation needed and what it bought. WHS audits are typically not interchangeable. The main types include:

Legal compliance audits

These assess the organisation against the specific duties in the applicable WHS or OHS legislation, regulations, and codes of practice. They answer the question every officer should be asking: where would we stand if the regulator walked in tomorrow? It is the most technically demanding audit type. Every finding must be anchored to a verified legislative provision.

Management system audits

These assess conformance with a framework such as AS/NZS ISO 45001:2018, whether for certification, surveillance, or internal assurance. They examine whether the system is established, implemented, and maintained. A system audit can return a clean result while serious legal non-compliances persist, because the benchmark is the standard, not the statute. Both audit types have value. Neither substitutes for the other.

Program or element audits

These take a deep slice through a single risk area: contractor management, electrical safety, confined spaces, hazardous chemicals, or psychosocial risk management. They suit organisations that already understand their broad compliance position and need depth in a known area of exposure.

Due diligence audits

Directed at officers’ obligations under section 27 of the harmonised WHS Acts, these assess whether directors and executives are actually exercising due diligence. That means acquiring current WHS knowledge, understanding operational hazards, verifying that resources and processes are in place, and confirming they are used. Industrial manslaughter prosecutions are expanding in Australia, and March 2026 brought the first conviction of a mining company in Queensland. For boards in high-risk industries, this audit type has moved from prudent to essential.

Post-incident and regulator-prompted audits

Conducted after a notifiable incident or enforcement action, these carry the additional burden that the report may become evidence. Defensibility is not optional here. It is the entire point.

A competent provider will tell a prospective client which of these they actually need, and will sometimes recommend a smaller engagement than the one requested. A provider who quotes for “a WHS audit” without scoping the type, the jurisdiction, and the legislative benchmark is signalling that they do not understand the distinctions.

What makes a good WHS auditor

Auditor competence has two dimensions, and both are highly necessary. ISO 19011:2018, the international guideline for auditing management systems, makes the point directly  “auditors need both generic audit skills and discipline-specific knowledge appropriate to the area being audited.” A certificate in audit technique does not confer WHS expertise, and WHS expertise does not confer audit discipline. Look for both.

In practical terms, a credible WHS auditor demonstrates:

Recognised WHS qualifications and certification.

Qualifications in occupational health and safety or a closely related discipline are the baseline. Look for professional status with the Australian Institute of Health and Safety, or Exemplar Global auditor certification in the OHS management system category. Certification matters because it imposes continuing professional development and a code of conduct, both of which are absent from an unregulated market.

Industry and hazard experience.

An auditor assessing a construction site must understand the inherent risks of the construction activity, a recycling facility auditor should understand mobile plant interaction, fire loading, and silica exposure. An auditor assessing a port should understand stevedoring, suspended loads, and chain of responsibility. Genuine site experience in comparable operations is what allows an auditor to recognise what is absent, which is always harder than recognising what is present.

Legislative currency.

Australian WHS law is changing rapidly. Psychosocial risk regulations, engineered stone prohibitions, the WES to WEL exposure standards transition, expanded incident notification categories, and new industrial manslaughter provisions have all landed within a few years. None of it has arrived uniformly across jurisdictions. Ask a prospective auditor what has changed in the relevant jurisdiction in the past twelve months. The answer will be revealing.

A verifiable citation discipline.

Every non-compliance in the report should cite the specific provision breached, and the citation should survive checking against the current consolidated legislation. In the reports we recently reviewed, citation error rates would have rendered the findings unusable in any enforcement or litigation context. Ask to see a sanitised sample report and check three citations at random. It takes ten minutes and reveals more than any capability statement.

Independence and professional indemnity.

The auditor should be free of conflicts, including the conflict created when the same firm designed the system being audited. They should also carry professional indemnity insurance appropriate to advisory work in a safety-critical field, and be willing to say so.

A defensible methodology.

Findings should be classified against a documented framework, with the classification driven by evidence against the legislative requirement rather than by the commercial relationship. A finding that breaches a legal duty is a non-compliance regardless of how warmly the path forward is written. Softening classifications to protect the relationship is a disservice that eventually becomes a liability.

The real cost of a bad audit

A poor WHS audit is worse than no audit, because it manufactures false assurance for an organisation and its board. The board receives a report, notes the modest findings, and reasonably concludes that the organisation’s risks are controlled. Resources are directed elsewhere. The genuine exposures remain, now wrapped in a document that suggests they were looked for and not found.

The legal dimension compounds this matter significantly. Audit reports are typically discoverable in a legal matter. In a prosecution following a serious incident, an inaccurate audit report can cut both ways. It demonstrates that the organisation turned its mind to compliance, and at the same time that the verification it relied upon was inadequate. Officers seeking to establish due diligence under section 27 will find little comfort in a report whose findings cannot be reconciled with the legislation. Courts and regulators assess the quality of assurance, not merely its existence.

There is also the quieter cost of misdirected effort associated with the audit findings. Corrective action plans built on inaccurate findings consume management attention and budget on the wrong problems. We have seen organisations invest heavily in documentation refinements recommended by a generalist audit. Meanwhile a known plant guarding issue, absent from the report entirely, remained live on the workshop floor unaddressed.

The acquisition blind spot: WHS due diligence in M & A

Nowhere is the generalist audit problem more consequential than in mergers and acquisitions. Venture capital and private equity groups routinely commission exhaustive financial, legal, and tax due diligence before acquiring an asset. WHS, where it is examined at all, is typically folded into the legal workstream as a register check, or handed to an accounting firm conducting the financial review. The acquirer then prices the deal on a safety picture nobody competent has actually verified.

The inherent risks are substantial, and most of them are invisible to a documentary review.

Inherited liability

In a share acquisition, the purchaser acquires the entity together with its history: open regulator investigations, undischarged improvement and prohibition notices, and exposure to prosecutions not yet commenced. WHS prosecutions can be brought well after the conduct in question, and industrial manslaughter charges carry no practical urgency for a regulator building a case. An acquirer can buy a prosecution that has not yet been filed.

Immediate officer exposure

PCBU and officer duties attach at completion. Incoming directors owe due diligence under section 27 from day one, with no grace period for unfamiliarity. A board that completes an acquisition without a credible WHS assessment has, in effect, certified its own ignorance of the operational hazards it now legally must understand.

Latent and long-tail exposures

Occupational disease liabilities crystallise years after the exposure that caused them. Silica, asbestos, and noise claims arising from the target’s historical practices will land on the new owner’s workers’ compensation experience. Dust disease claims are not constrained by ordinary limitation periods. Psychological injury claims, now the fastest-growing and most expensive claim category in several schemes, follow the workforce into the new structure.

Uninsurable penalties

Queensland, New South Wales, and Western Australia all prohibit insurance and indemnity arrangements covering WHS fines, each under section 272A of their respective WHS Acts. Victoria does the same through sections 148A and 148B of the OHS Act 2004 (Vic). Penalty exposure identified after completion sits directly on the acquired entity and cannot be transferred to an insurer.

Capital expenditure hidden in the plant

Unguarded machinery, non-compliant electrical installations, unregistered registrable plant, and degraded racking are remediation costs that belong in the purchase price negotiation. A financial due diligence team will verify that the plant exists and is depreciated correctly. It will not recognise that bringing it to a compliant standard requires two million dollars the model does not contain.

Culture and the paper-practice gap

The most valuable single output of pre-acquisition WHS due diligence is an honest read of whether the target’s documented system reflects how work is actually done. A mature paper system over a degraded operational culture is a liability dressed as an asset. Detecting it takes someone who knows what to look for on the ground.

Handled properly, WHS findings translate directly into deal mechanics: warranties and indemnities, price adjustments, conditions precedent, and a costed 100-day integration plan. Handled by a generalist, they translate into a paragraph confirming that policies exist.

What a good audit creates

The case for a competent audit is not defensive alone. Properly conducted, a WHS audit is one of the highest-leverage diagnostic tools available to an organisation, and its value extends well beyond a findings register.

  • Prioritised system development – A good audit does not simply list gaps. It sequences them. Immediate risk controls come first, then the legislative non-compliances, then the structural improvements that prevent recurrence, and finally the refinements that build maturity. An organisation emerging from a competent audit holds a development roadmap, not a defect list. This sequencing matters because safety resources are finite, and the order in which gaps are closed determines how much risk is carried in the interim.
  • An honest maturity position –  Frameworks such as Hudson’s safety culture ladder allow audit evidence to be translated into a maturity assessment: is the organisation reactive, calculative, or genuinely proactive? Boards find this framing far more useful than a compliance percentage, because it describes the trajectory rather than the snapshot and identifies what the next stage of development requires.
  • Verified assurance for officers – For directors and executives, a rigorous independent audit is direct evidence of the verification element of due diligence. It only serves that purpose if it would withstand examination, which returns us to auditor competence.
  • Organisational learning – The best audits surface the systemic patterns behind individual findings. Think of the procurement process that keeps introducing unassessed plant, the contractor onboarding gap that recurs across sites, or the consultation mechanism that exists on paper only. Addressing patterns prevents categories of failure. Addressing findings prevents single failures.

Choosing a WHS Auditor wisely | Questions worth asking

Before engaging any WHS or OHS auditor, ask: What type of audit is this, and against which legislative benchmark? What are the auditor’s WHS qualifications and certifications, specifically? What comparable industries have they audited? How do they verify legislative citations before issuing a report? Can they provide a sanitised sample report? Who, by name, will conduct the fieldwork? What professional indemnity cover do they hold? For transactions, add one more: how will the findings be expressed as quantified deal risks rather than as a compliance commentary?

A specialist will answer these questions readily and in detail. Evasiveness on any of them is the answer you are most probably looking for.

Work health and safety is multi-discplanary profession  often covering legal implications, technical and engineering, but most of all it remains a deeply practical discipline. The organisations that audit it well are the ones that practice it. Choose an auditor whose expertise matches the consequences of getting it wrong, because in this field, the consequences are measured in lives, livelihoods, and liberty, not in restated accounts.

Safetysure is an ISO 9001, 45001, and 14001 certified WHS and occupational hygiene consultancy operating across Australia in construction, mining, ports, manufacturing, and recycling. We conduct legal compliance audits, management system audits, and officer due diligence reviews grounded in verified, jurisdiction-specific legislation.

You might like to read Why you should conduct safety audits