A process safety audit asks whether the management system is doing what it was designed to do, at the level where work actually happens. That is a harder question than whether the system exists, and most audits answer the easier one without saying so. A procedure is found, a register is found, a signed form is found, and the element is marked as compliant. The plant it describes may be operating quite differently.
This page sets out how to audit for the harder question. It covers the outputs an audit should produce, the evidence it should rest on, how to choose what to look at, and how to write findings that change something. It applies whether the system follows the CCPS Risk Based Process Safety framework, a corporate standard, or the OSHA process safety management rule.
What an audit delivers
Before the method, the outputs. An audit that produces less than this has been an inspection of documents, whatever it was called.
- A scope stating which elements, which units and which period were audited, and what was deliberately left out
- The protocol used, so the next audit can test the same things and a repeated finding can be recognised as repeated
- Findings that each state the requirement, the evidence examined and the gap between them
- A risk ranking for each finding based on what could happen if it stays open, not on how many were found
- An action register with an owner and a date against each finding, agreed with the people who will close it
- A record of what was examined and found sound, so a clean element is a result and not an absence
- A statement of the auditors' independence from the areas they audited
Three questions an audit can answer
Audits are usually described by who runs them: internal, corporate or third party. It is more useful to describe them by the question they answer, because the three questions need different evidence.
- Compliance. Does the system meet the legal requirement that applies to it? This is answered against the regulation, clause by clause.
- Conformance. Does the site follow its own standard? This is answered against the company's written procedures.
- Effectiveness. Does the element achieve what it exists to achieve? This is answered in the field, and it is the question the other two leave open.
A site can conform fully to a management of change procedure that nobody uses for the changes that matter, because they are not recognised as changes. A compliance protocol will not find that. An effectiveness question will, if the auditor looks for changes the system did not capture rather than reviewing the ones it did.
Evidence that holds

Records show what the system says happened. Interviews show what people believe they do, and often what they believe they are supposed to say. The field shows what is actually installed, configured and practised. Each of these can mislead on its own. A complete record can describe work that did not happen as recorded. A confident interview can describe a practice that has drifted. A field observation can catch an unusual day.
The value lies in comparing them. When the permit register, the operator's account and the isolation found at the equipment all agree, the element is working. When they disagree, the disagreement is the finding, and it is far more useful than a missing signature. An audit that spends its time in the document room will find missing signatures and very little else.
Choose the sample, do not accept it
Whoever chooses the sample largely decides the result. A site asked to provide examples of completed changes, permits or inspections will provide good ones, usually without any intent to mislead, because those are the files people know and can find. The auditor should draw the sample from the full population instead: the complete change register for the period, the permit log, and the inspection schedule, with items chosen by the auditor.
Some of the sample should be chosen deliberately rather than at random. Changes closed quickly, temporary changes still open past their expiry date, permits issued on night shift or during a turnaround, and inspections deferred more than once are where a system under pressure shows its weaknesses. An audit held only on weekdays and only in daytime sees one version of the site.
Follow one change all the way

Management systems usually fail between elements rather than within them. A change can be approved properly under management of change, with its hazard review recorded, while the drawing it altered is never updated, the operating procedure still describes the old arrangement, and the operators were never trained on it. Each element may pass its own audit, but the system as a whole has failed.
The most revealing test is to pick a completed change and follow it through every element it should have touched. Was the hazard review proportionate to the change? Did the process safety information, the drawings and the relief basis get updated? Were procedures revised and people trained before startup? Did the pre-startup safety review confirm all of this, or simply record that it had been done? Were any actions from the hazard review closed before the change went live? A handful of changes followed this way tells an auditor more than a full element-by-element checklist.
Writing a finding someone can close
A finding is only useful if the person who owns it can act on it. That requires three things: the requirement that was not met, the evidence that shows it was not met, and a statement of the gap specific enough that its closure can be verified. "Management of change needs improvement" cannot be closed. "Three of the eight changes sampled altered process conditions without the relief basis being reviewed" can be.
Findings should be ranked by what could happen if they stay open, not by how many there are or which element they fall under. One unreviewed relief basis can matter more than a dozen documentation gaps. An audit report that presents thirty findings at equal weight leaves the site to guess which ones matter, and it will usually close the easy ones first.
A finding closed by rewriting the procedure is often not closed at all. If the gap was between the procedure and the practice, a clearer procedure leaves the practice where it was. Closure should be verified the same way the finding was made, against evidence from the field.
Why an overall score misleads

Many audit protocols end with a score, either a percentage or a maturity level for each element rolled up into one number for the site. Scores are useful for tracking a system over time and for comparing sites. As a verdict on whether a site is safe, they are misleading, because an average spreads one serious gap across many sound elements.
A site can score very well overall with its management of change, or its mechanical integrity programme, effectively not working. Major accidents usually come from one element failing, not from every element being moderately weak. An audit report should therefore lead with its most serious findings and use the score, if there is one, as a trend measure rather than the headline.
Who audits
Auditors need two things that are hard to find in the same person: independence from the area audited and enough knowledge of the process to recognise what they see. A team drawn entirely from the unit it audits will not see what it has stopped noticing. A team with no process knowledge will check that documents exist, because that is the only thing it can check. The usual answer is a team that combines both, led by someone independent of the area. ISO 19011 gives general guidance on auditor competence and on managing audit programmes.
How often
Frequency depends on the regime and the hazard. In the United States, processes covered by the OSHA process safety management rule must have their compliance certified at least every three years under 29 CFR 1910.119(o). The rule requires the audit to include at least one person knowledgeable in the process, a report of findings, a documented response to each finding and evidence that deficiencies have been corrected, with the two most recent reports kept. That interval is a legal minimum for those processes, not a recommendation for everyone else.
Outside that rule, audit frequency should reflect the hazard, the rate of change on the site, and what the last audit found. A site with repeated findings on the same element, or a period of heavy modification, may justify auditing that element more often than a fixed cycle allows. Jurisdictions differ, so an audit plan should name the legal provisions that actually apply at the site rather than relying on a protocol written for another regime.
What happens after the audit
An audit only improves the system if its actions close and closure is checked. The action register should be reviewed by management until it is empty, with overdue actions escalated rather than quietly extended. The next audit should first check that the previous findings were actually closed in the field. A finding that appears again in the next audit shows that the system that closes findings is not working, and that is a finding in its own right.
Audit results should also feed the system's other learning loops. Findings should be read alongside process safety indicators, such as those defined in API RP 754, and alongside incident and near miss investigations, then brought together in management review. In the CCPS Risk Based Process Safety framework, auditing is one of four elements in the pillar concerned with learning from experience, together with incident investigation, measurement and metrics, and management review. An audit that is filed without being connected to the other three has done only part of its job.
CCPS publishes guidance on auditing process safety management systems. ISO 19011 covers the auditing of management systems generally. For US processes covered by the rule, OSHA 29 CFR 1910.119(o) sets the compliance audit requirement.
Arborion audits process safety management systems against the framework the site has adopted and the rules that apply to it. We draw our own samples, follow changes across elements, and test findings in the field, and we record what we found sound as carefully as what we found wanting. If your last audit found little and you are not sure why, or the same findings keep returning, send us the previous report and the action register and we will tell you what the audit tested and what it left untested.