How to Prepare for a Compliance Audit: Evidence, Not Intentions
Prepare for a compliance audit by assembling evidence, not intentions. An auditor works from your documented system outwards: the scope and the standard, then the register of what you say you do, then a sample of records against it, then the people who do the work. Almost every adverse finding is a control that exists and cannot be shown. Fix the evidence trail in the months before, because the week before is too late for anything but tidying.

Looking to improve your compliance processes?
Create a Free AccountI have sat on both sides of enough compliance audits to know that the businesses that dread them are usually the ones doing the work properly. They just cannot prove it, and they know they cannot, and that is what the dread is.
So let us start by dropping the framing. An auditor is not an opponent, there is nothing to beat, and a business that treats the day as a contest tends to argue about findings instead of fixing them. The auditor’s job is to form a view on whether what you say you do is what you actually do. Everything below is about making that easy to check.
An Auditor Is Not an Opponent.
Two different things get called an audit, and knowing which one is coming changes what you prepare.
Safe Work Australia’s report on measuring and reporting draws the line clearly. A compliance audit gives feedback on the extent to which your safety management system and activities are legally compliant, conform to planned arrangements, and are operating as intended. A performance audit asks a harder question: whether the systems you have are actually effective and suitable to achieve your own policy and objectives, and what the weaknesses are.1
The first is a matching exercise between your documents and your records; the second is an opinion about whether any of it works. Most contractor and WHS audits are the first kind with a few questions from the second.
What an Auditor Asks For, in the Order They Ask.
The order is almost always the same, and understanding it removes most of the surprise.
- The scope and the standard. What is being audited, against which standard or client requirement set, over which period, at which sites.
- Your documented system. The policy, the procedures, the risk register, the requirement sets, and the org chart that says who owns what. This is the step where you tell them what you do.
- A sample of records. They pick, not you. Names and dates: this worker, that site, that week. Everything from here is measured against what you told them in step 2.
- The people. They ask a leading hand the same question they asked you, and listen for whether the two answers describe the same workplace.
- The loop. What did the last audit find, what did you do about it, and can you show that too.
Safe Work Australia names five things a compliance audit gives assurance on, and they are a useful pre-read of the sample: whether notifiable incidents are reported, whether workers have been consulted, whether notices issued under the WHS Act have been complied with, whether workers have been provided with WHS training and instruction, and whether health and safety representatives have received their training entitlements.1
Notification is the one people underestimate. An auditor will open the incident register, pick one, and ask when the regulator was told. SafeWork NSW requires that call immediately, on 13 10 50, and states the maximum penalty for failing to notify as AU$50,000 for a body corporate and AU$10,000 for an individual.4 Our post on which incidents must actually be notified works through where that line sits.
Having a Control and Being Able to Show It Are Different Things.
This is the whole post, and it is why “we do that” is not an answer.
An auditor cannot see a control. They can only see its trace: a record with a name, a date, and somebody’s sign-off on it. A pre-start check that happens every morning and is recorded nowhere is, to an auditor, indistinguishable from one that never happens.
Australian WHS law already treats verification as separate from doing. Section 27 of the model WHS Act sets out what an officer’s due diligence includes, and it lists two different obligations side by side: ensuring the business has and implements processes for complying with its duties, and taking reasonable steps to verify the provision and use of those resources and processes.2 Doing the thing is one duty. Being able to show it was done is another one, owed by the people at the top.
In practice that means every control worth having needs an artefact attached to it. In ComplyFlow, an inspection template fixes the categories, the checklist items, and the instruction against each item, so the same thing gets checked the same way by whoever is holding the phone.6 Scheduling it turns the intention into a due date: a template can repeat at a set interval and be assigned to a site, a staff category, or a named person, and the next pending inspection appears in the list and in the app.7 That is the difference between saying you inspect monthly and being able to show 12 of them.
The Three Findings That Come Up Every Time.
I have watched the same three arrive in report after report, across very different businesses.
Records that expired while still counted as current. A certificate is filed, the folder says the worker is cleared, and the expiry date lives only on the PDF. The construction induction card is the quiet one: under regulation 317 of the model WHS Regulations, a business must not direct or allow a worker to carry out construction work unless they have completed general construction induction training, and the training lapses where the holder has not carried out construction work in the preceding 2 years.3 A card in a wallet is not proof of currency on its own. Nor is a high risk work licence, which under regulation 92 expires 5 years after the day it was granted.3 The fix is to capture the expiry date at upload and run a standing report on what expires within a set window, which in ComplyFlow covers the whole life of the account, including documents rejected, expired, and never uploaded.5
Training delivered but never recorded against a person. Regulation 39 requires the information, training, and instruction given to a worker to be suitable and adequate having regard to the nature of the work, the risks, and the control measures implemented, and to be provided in a way that is readily understandable.3 A sign-in sheet with six first names on it does not evidence any of that. A record needs the person, the content, the date, the assessor, and the expiry where the course has one, which is why training and induction belongs in the same system as the rest of the record rather than in an email folder.9
Actions raised and never closed. Findings from the last audit, corrective actions from an incident, and items from an inspection all die the same way: they are raised, assigned to nobody in particular, and quietly outlive the person who raised them. In ComplyFlow the actions list defaults to incomplete actions assigned to you, and closing one requires a comment, a date of action, and a completion status of yes, no, or partial.8 An honest “partial, here is where it is up to” is a far better finding than an action that has been open for 14 months with no entries.
The Week Before, and What Is Already Too Late.
The week before is for retrieval, not creation. Five things are worth doing, and all of them are about being able to find what already exists.
- Pull the expiry report for every site in scope and fix what is fixable.5
- Close out or honestly update every open action, with dates.8
- Pick three workers at random and build their full record end to end. Whatever takes you more than ten minutes is what the audit will find.
- Brief the people who will be interviewed on what the audit covers, never on what to say.
- Read the last report and be ready to speak to every finding in it.
What is already too late: anything that had to be created by doing the work. An inspection round that did not happen, a toolbox talk with no attendance record, a supervisor competency that was never assessed. You cannot manufacture those in a week, and the attempt is far more damaging than the gap.
When You Cannot Produce Something.
It will happen. Say so plainly, say what you do instead, and give a date by which the record will exist.
What not to say is the sentence every auditor has heard a thousand times: we do that, we just do not write it down. It sounds like an explanation and lands as something worse. It converts a documentation finding into a system finding, because the auditor now has no basis to accept anything else you have told them without testing it, and the practical consequence is that the sample widens. One unevidenced control is a finding. A pattern of them is a conclusion about your management system.
The second thing not to do is improvise a document during the audit. Auditors are good at spotting a record created last Tuesday for an event last March, and an integrity finding travels much further than a paperwork one, particularly on a client prequalification where the report goes to somebody deciding whether to keep you on the panel.
The Audit Worth Having.
The best outcome is not a clean report. It is a report that tells you something you did not know, about a control you believed was working.
That only happens when the evidence is good enough for the auditor to get past the paperwork and look at the work. Businesses that get there tend to have done one unglamorous thing: they made the record a by-product of doing the job, rather than a separate task somebody does on a Friday. Once the inspection, the induction, the document, and the action all live in the same record as the person and the site, preparing for an audit stops being a project and becomes a morning’s work for whoever owns compliance. The six mistakes in common contractor management mistakes are mostly the reasons that record does not exist yet.