Written by David Rodgers

Quality and Operations Perspective

Written by David Rodgers, Lean Six Sigma Black Belt and ASQ-certified quality leader. This guide applies quality and process-improvement methods to workplace safety management from a quality and operations perspective. The author is not a certified safety professional, industrial hygienist, occupational physician, or lawyer.

Last editorial review: September 24, 2026. Educational content only: not medical, legal, or regulatory advice. Follow your organization's policies and the requirements that apply to you, and have subject-matter experts review any change to a live process.

  • Lean Six Sigma Black Belt
  • ASQ CQE
  • ASQ CMQ/OE
  • Quality systems and process improvement

Inspections and audits are how a safety system checks itself. Inspections look at the conditions and equipment in the workplace. Audits test whether the system that is meant to control the risks works and can be shown to work. Both find problems before injuries do.

This guide explains the differences, how to plan a risk-based program, how to collect evidence, how to score with weights and a critical-failure rule, how to grade findings and set time limits, and how to close actions and look for system causes. A worked audit at an illustrative plant shows a respectable score that still fails because of one critical finding.

Weights, grades, bands, and time limits are examples. Set your own and apply them consistently.

Open the Audit Scorecard Get the Audit Pack

Before You Start

Educational content. This guide applies quality and process-improvement methods to workplace safety. It is not legal, regulatory, or professional safety advice, and it does not replace your organization's safety program, the laws and standards that apply to you, or qualified safety professionals. Requirements differ by country, region, and industry: OSHA and ISO 45001 are used as common references. The worked example is illustrative.

Inspections, Audits, and Observations

The words overlap in everyday talk, but the activities do different jobs, and a mature program uses all of them.

ActivityQuestion it answersWho and how oftenOutput
Workplace inspectionAre the physical conditions and equipment safe today?Supervisors and champions; daily, weekly, or monthlyHazards to fix now
Behavior or task observationIs the work being done as planned, and what makes it hard?Supervisors and peers; frequent short visitsCoaching and system fixes
Management system auditDoes the system work as designed and meet the standard, and can it be shown?Trained auditors independent of the area; yearly or by riskScored findings and corrective actions
Compliance auditDo we meet the legal requirements?Specialists; periodicList of gaps against the law
Third-party or certification auditDoes an outsider confirm conformity, for example with ISO 45001?External body; set cycleCertificate or non-conformities
Inspection looks at things; audit looks at the system. An inspection finds the missing guard. An audit asks why there was no check that would have found it, and whether the same problem exists elsewhere.

What a Good Program Does

Finds Problems Before Injuries Do

Hazards found by a planned check cost far less than hazards found by an incident.

Verifies That Controls Work

A control on paper is not a control. Audits check that the guard, the procedure, and the training are real.

Gives a Fair Score

A weighted scorecard shows the system’s strengths and weak spots, and a trend over time.

Feeds Improvement

Findings become actions with owners and dates, and the pattern of findings shows system causes.

Planning the Program

  1. Set the scope and the criteria. Decide what the audit covers and what it is measured against: your own procedures, the law, and ISO 45001 clauses.
  2. Risk-base the schedule. Audit high-risk areas and areas with a history of problems more often and more deeply.
  3. Choose and train the auditors. They should know the standard and the process, be independent of the area, and know how to observe, interview, and sample. Mix them, for example a safety professional with a worker from another area.
  4. Build the checklist. Keep it to the questions that matter, group them by category, and weight them by importance.
  5. Tell the area in advance, and agree access and times, except where an unannounced check is part of the plan.
  6. Carry out the audit. Opening meeting, evidence collection, closing meeting.
  7. Report and agree actions. Give the report quickly, with graded findings and agreed owners and dates.
  8. Follow up and verify. Check that actions were done and that they worked.

ISO 19011 gives guidance on managing audit programs, selecting auditors, and conducting audits, and applies to management system audits of any kind.

Collecting Evidence

MethodHowExample
ObserveWatch the work and the conditionsAn operator reaches into a machine with the guard open
InterviewAsk open questions of the people who do the work“What do you do when the machine jams?”
Review recordsSample documents and dataInspection records, training files, action logs, maintenance records
TestCheck that a control worksPress the emergency stop; test an interlock; time an evacuation

Sample, do not just check one example, and trace a finding back to its record. Findings need evidence: write what you saw, where, and when, and not just a conclusion.

Scoring and Grading

A weighted scorecard gives each question a weight by importance, scores the answer, and combines them. The method below is the one used by the Safety Audit Scorecard on this site.

ElementRule
Weight3 = critical control (a failure could kill or seriously injure); 2 = important; 1 = standard
AnswerYes = 1; Partial = 0.5; No = 0; Not applicable = left out of the score
Category scoreSum of (weight × answer) ÷ sum of weights, for the items in the category
Overall scoreThe same calculation over all applicable items. Do not average the category scores
Critical failureA “No” on a weight-3 item fails the audit whatever the overall score
GradeMeaningTypical time to close
CriticalA failure of a critical control. Imminent danger of serious harmImmediately: within 1 day, with interim protection
MajorA significant gap in an important control, or a system failureWithin 7 days, or an agreed plan
MinorA partial failure or a small gap in a standard itemWithin 30 days
ObservationAn opportunity to improve, not a failureOptional; consider at review

Typical interpretations: 90% or more is strong, 75 to 89% needs focused attention in the weaker categories, and under 75% needs a corrective plan. These bands and the time limits are examples. Set your own, and apply them in the same way each time.

Why the critical-failure rule matters. A weighted average can hide a dangerous gap: an area can score well overall while missing a lockout device that could kill someone. The rule makes sure a critical control failure is always treated as a failure, however good the rest looks.

Worked Example: An Annual Audit at Riverside Plant

Riverside Plant, an illustrative 140-employee metal fabrication and assembly plant, audited itself against 32 questions in 8 categories. A team of a safety coordinator, an engineer, and an operator from another area spent two days on it. All figures are illustrative.

0% 25% 50% 75% 100% Leadership and participation 93% Hazard identification and risk assessment 55% Machine guarding and energy control 64% Housekeeping and walkways 90% Chemicals and hazard communication 83% Personal protective equipment 86% Emergency preparedness 71% Training and competence 94%
Category scores. The dashed lines mark 75% (gold) and 90% (green).

Overall score 77.3%. Three categories are below 75%: hazard identification and risk assessment (55%), machine guarding and energy control (64%), emergency preparedness (71%). There were 11 findings: 1 critical, 2 major, and 8 minor.

#CategoryFindingAnswerGrade
1Leadership and participationLeaders completed their safety walks as plannedPartialMinor
2Hazard identification and risk assessmentRisk assessments exist for all high-risk tasksPartialMinor
3Hazard identification and risk assessmentJob hazard analyses are current for tasks changed in the last yearNoMajor
4Hazard identification and risk assessmentHazard reports are closed within the agreed timePartialMinor
5Machine guarding and energy controlLockout devices and procedures are available at each machine that needs themNoCritical
6Machine guarding and energy controlLockout procedures were audited in the last yearPartialMinor
7Housekeeping and walkwaysFloors are free from oil, debris, and trip hazardsPartialMinor
8Chemicals and hazard communicationEyewash and shower stations are unobstructed and tested at the required intervalPartialMinor
9Personal protective equipmentRequired PPE is available, in good condition, and in usePartialMinor
10Emergency preparednessFirst aid supplies and trained first aiders are available on every shiftNoMajor
11Training and competenceTraining records are complete for all employeesPartialMinor
The audit result is a fail. The overall score of 77% looks respectable, but the critical finding stands: lockout devices and procedures were missing at machines that need them. The rule overrides the score. The plant fixed the critical item within a day by issuing devices, put the major findings on a 7-day plan, and added the minor findings to the committee’s action log.

Looking past the list. Four of the findings, in different categories, trace to one cause: the plant had updated its machines without updating its job hazard analyses and lockout procedures. The audit team reported this pattern as a system finding on management of change, which a list of separate fixes would not have solved.

Run your own audit with the Safety Audit Scorecard or the Safety Inspection and Audit Pack workbook, which includes an inspection checklist, an audit scorecard, and a findings tracker.

Writing Findings and Closing Them

DoDo notExample
State the requirement, the evidence, and the gapWrite opinions or blame“Lockout devices were not at the saws and the press (requirement: procedure LO-1); three operators said they use the main switch”
Look for the system causeFix only the symptomWhy did nobody notice? What check was missing?
Agree an owner and a date with the areaLeave findings unassignedOwner, due date from the grade, and how it will be verified
Verify the fix workedClose on the owner’s wordRe-inspect, test, or sample records
Look for patterns across findingsTreat each finding on its ownMany findings in one category point to a system gap
  • Escalate overdue findings. Critical and major findings that miss their date go to the sponsor.
  • Track closure. Report the on-time closure rate and the age of open findings in the safety committee.
  • Share the learning, including the good practices that auditors saw.

Running Good Inspections

  • Use a short checklist tailored to the area, and add a question after each incident or new hazard.
  • Walk with a worker from the area, and ask what worries them.
  • Fix what you can on the spot, and record the rest with an owner and a date.
  • Rotate the inspectors so that new eyes see old habits.
  • Look at the work, not just the place. Watch tasks as they are done, and ask about non-routine jobs.
  • Close the loop quickly, and tell people what was fixed.

A layered process audit applies the same idea to process discipline, with frequent short checks at different levels. See Layered Process Audits and the Gemba Walk.

Common Mistakes

A Checklist Exercise

Ticking boxes by looking at paper, and never watching the work.

Announced and Staged

The area cleans up for the audit, and the audit sees the best day.

Findings With No Owner

A report with no owners or dates is a document and not a plan.

Fixing Symptoms

Each finding is closed, and the system cause remains.

Average Hides the Critical

A good overall score masks a failed critical control.

Auditing Your Own Work

No independence, so no one challenges the answers.

Self-Assessment Questions

  • Do we have a risk-based schedule of inspections and audits, with trained and independent auditors?
  • Do we collect evidence by observation, interviews, records, and tests, and not by checklist alone?
  • Do we grade findings, set time limits, and let a critical failure fail the audit?
  • Do we verify that actions worked, and do we look for system causes across findings?
  • Do we report closure rates to the safety committee?

Safety Audits and Inspections: Frequently Asked Questions

What is the difference between a safety inspection and a safety audit?

An inspection looks at the physical conditions and equipment in an area, to find hazards to fix now. An audit examines the management system: does it work as designed, meet the standard, and can it be shown with evidence? Inspections are frequent and local, and audits are periodic and independent.

How often should we audit?

Base it on risk. High-risk areas, and areas with a history of problems, warrant more frequent and deeper audits. Many sites audit the whole system yearly, with inspections weekly or monthly, and short observation walks more often. Check any legal or certification requirements that apply.

What is a critical failure in an audit?

A failure of a control whose absence could cause death or serious injury. In a weighted scorecard it is a “No” on a top-weight item, and it fails the audit whatever the overall score, because an average can hide a dangerous gap.

How should audit findings be graded?

A common scheme is Critical (act at once), Major (a significant gap, closed in about a week or by a plan), and Minor (a small gap, closed in about a month), with Observations for improvement ideas. The time limits are examples. What matters is that grades and time limits are set in advance and used consistently.

Who should do the audit?

Trained auditors who are independent of the area being audited, for example a safety professional with a worker or manager from another area. ISO 19011 gives guidance on choosing and managing auditors. Independence matters because people do not see problems in their own work.

Sources and Further Reading

  • ISO 19011:2018, Guidelines for auditing management systems.
  • ISO 45001:2018, clause 9.2 on internal audit, and clause 10 on improvement and corrective action (check current edition).
  • US Occupational Safety and Health Administration, Recommended Practices for Safety and Health Programs (2016), on evaluating performance and program review.
  • UK Health and Safety Executive, Managing for Health and Safety (HSG65), on monitoring and review.
  • ANSI/ASSP Z10.0, Occupational Health and Safety Management Systems, on evaluation and corrective action.