Safety Audit Checklist
One checklist for testing whether your safety system actually works, rather than whether the paperwork exists.
- Three tests per requirement: documented, in use, and works
- Evidence seen recorded against every line
- Auditor independence stated on the form
- Element scores rated conforms, observation, minor or major
Safety Audit Checklist
Documented, in use, and working
| # | Requirement | Doc | Use | Works |
|---|---|---|---|---|
| 1 | Named individual accountable for safety | |||
| 2 | Controls follow the hierarchy rather than defaulting to PPE | |||
| 3 | Incidents investigated to root cause, not just recorded |
The document you will get. Download for the full, editable file.
Who this safety audit checklist is for
Four people read a completed audit, and only one of them was in the room.
Auditor
You are running it. The independence line and the evidence column are what make your score defensible when somebody disputes a major non-conformance.
Safety or HSE manager
You are being audited. The three columns tell you where you actually stand: paperwork that nobody follows scores worse than an honest gap, and it should.
Site or operations leader
You own the result. Element scores tell you which part of the system to invest in, rather than handing you a list of sixty findings with no shape.
Client or insurer
You required the audit. The standard audited against, the auditor's independence and the rating summary are the three things you check first.
Which element matters the most in your sector
The checklist is the same everywhere. What changes is which element you fail on, and that is usually the one your client or your insurer examines first. If you run one of these, the sector page goes further than the template does.
- FM service providers
Contractors and permits. When most of the work is subcontracted, approval, method statements and permit closure are where audits find the gaps.
FM service provider software - Healthcare
Statutory inspections. Pressure, lifting, electrical and gas currency is the element that is checked line by line rather than sampled.
Healthcare maintenance software - Education
Competence and training. High turnover and seasonal staff mean induction records are the element most likely to be documented but not in use.
Campus maintenance software - Commercial real estate
Shared-premises coordination. Multi-occupier buildings fail on the line nobody owns, and it sits in the contractors element.
Portfolio maintenance software - Retail and malls
Emergency preparedness. Evacuation of a public building is where drills at a stated frequency are the difference between a plan and a document.
Retail maintenance software - Corporate facilities
Monitoring and review. Leading indicators as well as lagging ones are what separate a managed system from a reactive one.
Corporate facilities software
What a safety audit should cover
A safety audit checklist tests the safety management system rather than the housekeeping. Every requirement gets three answers: is it documented, is it actually in use, and does it work. Each is backed by the evidence seen, scored by element, and rated as conforming, an observation, or a minor or major non-conformance.
A. Fields specific to a safety audit
| Field | What goes in it | Why it earns its place |
|---|---|---|
| Auditor independence | Whether the auditor is independent of the area being audited | An audit of your own area is a self-assessment, and the form says so. It is not a criticism of the auditor; it is a statement about how much weight the score can carry. |
| Audited against | ISO 45001, an OSHA programme, an insurer standard, an internal standard or a client requirement | Sets what conformance even means. The same evidence passes one standard and fails another, so a score without a standard is a number without units. |
| People interviewed | Names and roles | An audit with no interviews is a document review. The in-use column cannot be answered from a filing cabinet, only from asking the people who do the work. |
| Period covered by the evidence | The window the records must fall inside | Stops a current-looking file of last year's records passing. Evidence has to belong to the period you are auditing. |
| Documented | The procedure exists, is current and is findable | The easiest column to pass and the least informative on its own. A folder full of signed policies tells you almost nothing about risk. |
| In use | People actually follow it, and can describe it | Answered by asking three people at random how they report a near miss. If the answers differ, the system is documented and not in use. |
| Works | It is actually controlling the risk | The column that matters and the one most checklists lack. A risk assessment can exist, be followed, and still name controls that are not the ones in place today. |
| Evidence seen | What you looked at, per line | Turns a score into a finding somebody can challenge or accept. An empty evidence column makes every rating an assertion. |
| Element score and rating | A percentage per element, rated conforms, observation, minor NC or major NC | Gives the result a shape. Sixty scattered findings are unusable; six element scores tell a leadership team where to spend. |
If you cut the checklist down, keep the third column and the evidence column. Documented and in use can be inferred from records and conversations later. Whether a control actually works, and what you saw that convinced you, cannot be reconstructed after you have left the site.
B. What it looks like filled in
Four requirements from one audit. Note the second and fourth: documented, and still failing. That gap is what the three columns exist to expose.
| Requirement | Doc'd | In use | Works | Evidence seen |
|---|---|---|---|---|
| Permit to work for hot work, confined space, electrical and height | Yes | Yes | Yes | Six permits sampled, all issued, signed and closed |
| Incident reporting route known to the workforce | Yes | No | No | Procedure current; three staff asked, three different answers |
| Risk assessments completed for every significant hazard | Yes | Yes | No | Assessments generic, not naming the controls in place today |
| Evacuation drills at the stated frequency, timed and debriefed | Yes | No | No | Last drill nineteen months ago, no debrief record held |
Audit AUD-2026-04, audited against ISO 45001, auditor independent of the area. All four requirements are documented, so a single-tick checklist would have scored this element at one hundred per cent. Three of the four fail in use or works. The third line is the subtle one: the assessments exist and people follow them, but they describe controls that are not the ones fitted today, so the paperwork is being followed and the risk is not being controlled. That is a minor non-conformance a one-column checklist cannot express.
Word to add requirements or swap in your own standard, Excel to score the elements and count the ratings, PDF for the audit file and the client. Free, and yours to rebrand.
How do you run a safety audit?
Run it as an audit, not a document review: the second and third columns can only be answered by walking about and asking people. Six steps.
Set the scope and say whether you are independent
Reference, dates, the site and the area, the standard you are auditing against, the period the evidence must fall in, and whether you are independent of the area. If you are not, the result is a self-assessment and should say so.
Name the people you interviewed
Roles as well as names. The in-use column is answered by asking the people who do the work, and an audit with no interviews cannot honestly complete it.
Work each element and answer all three columns
Documented, in use, and works. Resist collapsing them: a requirement that is documented and followed can still fail the third column if the controls named are not the ones in place.
Write down the evidence for every line
The document you read, the record you sampled, the person you asked, the thing you saw. A rating with an empty evidence cell cannot be defended or accepted.
Score each element and rate it
Requirements met over requirements applicable, as a percentage, then conforms, observation, minor NC or major NC. Spell the ratings exactly that way, because the summary counts them by name.
Close the previous audit's actions before you finish
Check whether the last audit's findings were closed and evidenced. An audit programme that never revisits its own findings produces the same report every year.
Safety audit versus safety inspection
These two are constantly confused and they answer different questions. You need both, at different frequencies, done by different people.
| Aspect | Safety audit | Safety inspection |
|---|---|---|
| What it examines | The management system | The physical workplace |
| The question it answers | Does the system control the risk | Is anything unsafe right now |
| Evidence used | Documents, records and interviews | What you can see on the walk |
| Who should do it | Someone independent of the area | A supervisor or safety rep, often local |
| Typical frequency | Annually, or to a programme | Weekly or monthly |
| What it produces | Element scores and non-conformances | A hazard log with risk ratings |
An audit can pass while the workplace is unsafe, and a workplace can look immaculate while the system is failing. The audit tells you whether the arrangements would catch a problem; the inspection tells you what is wrong today. Running only inspections leaves you fixing the same hazards forever, because nothing tests why they keep appearing.
When the template starts to feel limiting
A checklist handles one audit well. It handles an audit programme badly, and always in the same four ways.
The requirement list drifts
Standards get revised and so does your own. Two audits a year apart end up run against different lists, and the scores stop being comparable, which removes the only thing a score is for.
Non-conformances have no follow-up
A major NC with an owner and a date, on paper, in a folder, does not chase itself. The next audit then opens by discovering the last one's findings are still open.
You cannot see which line always fails
The useful question is which requirement fails across every site and every year. On paper that means reading every past audit, so nobody asks it.
Scores cannot be compared across sites
Element percentages only mean something in aggregate: this site against the estate, this year against last. A folder of PDFs cannot produce that view.
What running this in Facilio looks like
The template is the paper version of this audit. The requirements are the same ones; the difference is that a non-conformance becomes tracked work and the evidence stops living in somebody's folder.
Work Completion Validator
A non-conformance closes on evidence, not a tick
On paper a finding is closed when somebody says so. Work Completion Validator holds each corrective action against evidence that it was done, so the next audit does not open by rediscovering last year's findings still outstanding.
Ops Performance Intelligence
Audit programmes and statutory currency run to a schedule
Audit frequency per site, and the currency of every statutory inspection the audit checks, become dates the system tracks, so an overdue audit or a lapsed certificate surfaces before an auditor finds it.
Audit Report Intelligence
Scores become comparable across the estate
Element scores, ratings and the evidence behind them are held as data, so this site against the estate, and this year against last, is a query rather than a stack of PDFs somebody has to read.
Contractor Work Tracker
Findings about contractors attach to the contractors
Approval, insurance currency, method statements and permit closure sit with the contractor record itself, so the contractors element of the next audit is evidenced from live data rather than reassembled by hand.
Audit-trailed. Every answer Atom AI gives traces back to the record it came from, so a claim in a report can be followed to the visit that produced it.
Frequently asked questions
What is a safety audit checklist?
A safety audit checklist tests whether a safety management system is working. It covers policy and leadership, risk assessment and control, competence and training, contractors and permits, emergency preparedness, and monitoring and review, and gives each requirement three answers: documented, in use, and works.
It is not a walkthrough of the workplace. That is a safety inspection, and the two answer different questions.
What should a safety audit cover?
The audit details first: reference, dates, auditor and whether they are independent of the area, the site and scope, the standard audited against, the period the evidence covers, the people interviewed, and the previous audit's date and score. Then the elements: policy and accountability; hazard identification and control; competence, training and supervision; contractors, visitors and permits; emergency preparedness and incident management; and monitoring, records and review. Then element scores, conformance ratings and a rating summary.
What is the difference between a safety audit and a safety inspection?
An audit examines the management system using documents, records and interviews, is usually done by someone independent, and runs annually or to a programme. An inspection examines the physical workplace, is done locally and often weekly or monthly, and produces a hazard log.
An audit can pass while the workplace is unsafe, and a workplace can look immaculate while the system is failing. Both are needed.
Why three tick columns instead of one?
Because a single tick collapses three different facts. A procedure can exist, be followed, and still fail to control the risk, and that is the most valuable finding an audit can produce.
The practical test for the in-use column is to ask three people at random how they report a near miss. If the answers differ, the system is documented but not in use, however good the paperwork looks.
Does the auditor really have to be independent?
Not always, but the form records the answer either way. An audit of your own area is a self-assessment: still useful, but it cannot carry the same weight with a client, an insurer or a certification body.
Recording it honestly is what protects the score. A good self-assessment labelled as one is worth more than an independent audit that nobody believes was independent.
What do the ratings mean, and why the exact wording?
Conforms, observation, minor NC and major NC, per element. Conforms means the requirements are met; an observation is a drift worth noting; a minor non-conformance is a gap in a working system; a major is an absent or failed arrangement.
Spell them exactly that way. The summary table counts each rating by name, so a rating typed as anything else will not be counted.
Can I edit and rebrand this template?
Yes. It is free to use, edit, rename and put your own logo on, internally or for clients. No attribution required.
The Word version is the one to edit if you want to add requirements, change the elements or swap in your own standard; the Excel version is the one to use if you want the element scores and the rating summary to count themselves.
In one paragraph
A safety audit tests the system rather than the workplace. Set the scope first, say what standard you are auditing against, and record whether you are independent of the area, because that decides how much the score can carry. Name the people you interviewed: the in-use column cannot be answered from a filing cabinet. Then work each requirement three ways, documented, in use and works, and write down what you actually saw for each one. A line that is documented and followed can still fail the third column, and that gap is the most useful thing an audit finds. Score each element, rate it in the exact words the summary counts, and close out the previous audit's findings before you sign.
The template is the floor, not the ceiling
Take the checklist; it will give you a defensible audit with evidence against every line. When one audit a year stops being enough, a connected CMMS runs the programme: statutory currency tracked continuously, findings that become work with owners, and element scores you can compare across the estate.