Skip to main content
Create Free Account

Inspections & Incidents

How to Prepare for a Compliance Audit: Evidence, Not Intentions

Prepare for a compliance audit by assembling evidence, not intentions. An auditor works from your documented system outwards: the scope and the standard, then the register of what you say you do, then a sample of records against it, then the people who do the work. Almost every adverse finding is a control that exists and cannot be shown. Fix the evidence trail in the months before, because the week before is too late for anything but tidying.

  • Published
  • Updated
  • 8 min read
Two men in hard hats, safety glasses, and high-visibility vests standing in a steel fabrication workshop, one pointing while holding a rolled drawing, with a welder throwing sparks behind them
Almost everything an auditor asks about happened months ago, on an ordinary day like this one.

I have sat on both sides of enough compliance audits to know that the businesses that dread them are usually the ones doing the work properly. They just cannot prove it, and they know they cannot, and that is what the dread is.

So let us start by dropping the framing. An auditor is not an opponent, there is nothing to beat, and a business that treats the day as a contest tends to argue about findings instead of fixing them. The auditor’s job is to form a view on whether what you say you do is what you actually do. Everything below is about making that easy to check.

An Auditor Is Not an Opponent.

Two different things get called an audit, and knowing which one is coming changes what you prepare.

Safe Work Australia’s report on measuring and reporting draws the line clearly. A compliance audit gives feedback on the extent to which your safety management system and activities are legally compliant, conform to planned arrangements, and are operating as intended. A performance audit asks a harder question: whether the systems you have are actually effective and suitable to achieve your own policy and objectives, and what the weaknesses are.1

The first is a matching exercise between your documents and your records; the second is an opinion about whether any of it works. Most contractor and WHS audits are the first kind with a few questions from the second.

What an Auditor Asks For, in the Order They Ask.

The order is almost always the same, and understanding it removes most of the surprise.

  1. The scope and the standard. What is being audited, against which standard or client requirement set, over which period, at which sites.
  2. Your documented system. The policy, the procedures, the risk register, the requirement sets, and the org chart that says who owns what. This is the step where you tell them what you do.
  3. A sample of records. They pick, not you. Names and dates: this worker, that site, that week. Everything from here is measured against what you told them in step 2.
  4. The people. They ask a leading hand the same question they asked you, and listen for whether the two answers describe the same workplace.
  5. The loop. What did the last audit find, what did you do about it, and can you show that too.

Safe Work Australia names five things a compliance audit gives assurance on, and they are a useful pre-read of the sample: whether notifiable incidents are reported, whether workers have been consulted, whether notices issued under the WHS Act have been complied with, whether workers have been provided with WHS training and instruction, and whether health and safety representatives have received their training entitlements.1

Notification is the one people underestimate. An auditor will open the incident register, pick one, and ask when the regulator was told. SafeWork NSW requires that call immediately, on 13 10 50, and states the maximum penalty for failing to notify as AU$50,000 for a body corporate and AU$10,000 for an individual.4 Our post on which incidents must actually be notified works through where that line sits.

Having a Control and Being Able to Show It Are Different Things.

This is the whole post, and it is why “we do that” is not an answer.

An auditor cannot see a control. They can only see its trace: a record with a name, a date, and somebody’s sign-off on it. A pre-start check that happens every morning and is recorded nowhere is, to an auditor, indistinguishable from one that never happens.

Australian WHS law already treats verification as separate from doing. Section 27 of the model WHS Act sets out what an officer’s due diligence includes, and it lists two different obligations side by side: ensuring the business has and implements processes for complying with its duties, and taking reasonable steps to verify the provision and use of those resources and processes.2 Doing the thing is one duty. Being able to show it was done is another one, owed by the people at the top.

In practice that means every control worth having needs an artefact attached to it. In ComplyFlow, an inspection template fixes the categories, the checklist items, and the instruction against each item, so the same thing gets checked the same way by whoever is holding the phone.6 Scheduling it turns the intention into a due date: a template can repeat at a set interval and be assigned to a site, a staff category, or a named person, and the next pending inspection appears in the list and in the app.7 That is the difference between saying you inspect monthly and being able to show 12 of them.

The Three Findings That Come Up Every Time.

I have watched the same three arrive in report after report, across very different businesses.

Records that expired while still counted as current. A certificate is filed, the folder says the worker is cleared, and the expiry date lives only on the PDF. The construction induction card is the quiet one: under regulation 317 of the model WHS Regulations, a business must not direct or allow a worker to carry out construction work unless they have completed general construction induction training, and the training lapses where the holder has not carried out construction work in the preceding 2 years.3 A card in a wallet is not proof of currency on its own. Nor is a high risk work licence, which under regulation 92 expires 5 years after the day it was granted.3 The fix is to capture the expiry date at upload and run a standing report on what expires within a set window, which in ComplyFlow covers the whole life of the account, including documents rejected, expired, and never uploaded.5

Training delivered but never recorded against a person. Regulation 39 requires the information, training, and instruction given to a worker to be suitable and adequate having regard to the nature of the work, the risks, and the control measures implemented, and to be provided in a way that is readily understandable.3 A sign-in sheet with six first names on it does not evidence any of that. A record needs the person, the content, the date, the assessor, and the expiry where the course has one, which is why training and induction belongs in the same system as the rest of the record rather than in an email folder.9

Actions raised and never closed. Findings from the last audit, corrective actions from an incident, and items from an inspection all die the same way: they are raised, assigned to nobody in particular, and quietly outlive the person who raised them. In ComplyFlow the actions list defaults to incomplete actions assigned to you, and closing one requires a comment, a date of action, and a completion status of yes, no, or partial.8 An honest “partial, here is where it is up to” is a far better finding than an action that has been open for 14 months with no entries.

The Week Before, and What Is Already Too Late.

The week before is for retrieval, not creation. Five things are worth doing, and all of them are about being able to find what already exists.

  • Pull the expiry report for every site in scope and fix what is fixable.5
  • Close out or honestly update every open action, with dates.8
  • Pick three workers at random and build their full record end to end. Whatever takes you more than ten minutes is what the audit will find.
  • Brief the people who will be interviewed on what the audit covers, never on what to say.
  • Read the last report and be ready to speak to every finding in it.

What is already too late: anything that had to be created by doing the work. An inspection round that did not happen, a toolbox talk with no attendance record, a supervisor competency that was never assessed. You cannot manufacture those in a week, and the attempt is far more damaging than the gap.

When You Cannot Produce Something.

It will happen. Say so plainly, say what you do instead, and give a date by which the record will exist.

What not to say is the sentence every auditor has heard a thousand times: we do that, we just do not write it down. It sounds like an explanation and lands as something worse. It converts a documentation finding into a system finding, because the auditor now has no basis to accept anything else you have told them without testing it, and the practical consequence is that the sample widens. One unevidenced control is a finding. A pattern of them is a conclusion about your management system.

The second thing not to do is improvise a document during the audit. Auditors are good at spotting a record created last Tuesday for an event last March, and an integrity finding travels much further than a paperwork one, particularly on a client prequalification where the report goes to somebody deciding whether to keep you on the panel.

The Audit Worth Having.

The best outcome is not a clean report. It is a report that tells you something you did not know, about a control you believed was working.

That only happens when the evidence is good enough for the auditor to get past the paperwork and look at the work. Businesses that get there tend to have done one unglamorous thing: they made the record a by-product of doing the job, rather than a separate task somebody does on a Friday. Once the inspection, the induction, the document, and the action all live in the same record as the person and the site, preparing for an audit stops being a project and becomes a morning’s work for whoever owns compliance. The six mistakes in common contractor management mistakes are mostly the reasons that record does not exist yet.

Sources

  1. Measuring and reporting on work health and safety Safe Work Australia, March 2017
  2. Model Work Health and Safety Act, version dated 5 December 2025 Safe Work Australia, 5 December 2025
  3. Model Work Health and Safety Regulations, version dated 5 December 2025 Safe Work Australia, 5 December 2025
  4. Incident notification SafeWork NSW, Read 12 September 2026
  5. Reporting on all documents in the system ComplyFlow Help Centre, 6 May 2025
  6. Adding Inspection Templates ComplyFlow Help Centre, 9 April 2025
  7. Scheduled Inspections ComplyFlow Help Centre, 9 April 2025
  8. Closing Out Actions ComplyFlow Help Centre, 18 March 2026
  9. Training Module Overview ComplyFlow Help Centre, 6 February 2026
Mitchell Bourne

Written by

Mitchell BourneManaging Director, ComplyFlow

Mitch has run ComplyFlow since 2009 and has spent that time inside the contractor, site, and safety problems of Australian operators. He writes about where compliance actually fails, and what the people responsible for it can do about it.

Writes about: Contractor compliance, WHS duty and proof, Running a compliance program

Questions

Questions People Ask About This.

What does an auditor actually ask for first?

The scope and the standard, then your documented system: the policy, the procedures, and the registers that say what you do. Only then do they ask for records. The order matters, because everything after the first step is measured against what you told them you do, not against what a textbook says you should.

What is the difference between having a control and evidencing it?

A control is the thing you do. Evidence is what proves it happened on a named day, to a named person, checked by a named someone. An auditor cannot see a control; they can only see its trace. Section 27 of the model WHS Act puts verification of your own processes on an officer as a duty in its own right.

How long before an audit should we start preparing?

Months, for anything that has to be created by doing the work: inspection rounds, toolbox records, training, and closed-out actions. The week before is only good for retrieval and tidying, which means pulling the expiry report, closing or honestly updating open actions, assembling the sample, and briefing the people who will be interviewed.

What should we say when we cannot produce a record?

Say plainly that it does not exist, say what you are doing instead, and offer a date by which it will. Do not improvise a document during the audit. An auditor who finds one invented record will widen the sample on everything else, and a gap you name yourself is a finding rather than an integrity problem.

Does an auditor check whether incidents were notified to the regulator?

Yes. Safe Work Australia names it as one of the five things a compliance audit gives assurance on. They will ask for the incident register, pick one, and ask when the regulator was notified and by whom. In New South Wales that call goes to SafeWork NSW on 13 10 50, immediately.

See it against your own contractors, sites, and rules.

Book a 30-minute demo. We will show ComplyFlow working with your kind of sites, your kind of contractors, and your requirements. No slides, no hard sell.

  • ISO 27001
  • Hosted on AWS
  • Microsoft & Okta SSO
  • API & MCP
  • Data in Australia

Compliance you can prove, instantly.