Skip to content
Risk Based Process Safety (RBPS)Learn from Experience

Auditing

An internal annual, corporate triennial, statutory, and insurer audit programme with finding closure governance

Strategic context

What this element is and why it matters

Auditing is the assurance mechanism that proves PSM elements are not merely designed but actually working. The element maps to OSHA PSM 1910.119(o) triennial certification, CCPS RBPS Element 19, the ISO 19011 audit principles, and the corporate, insurer, and statutory audit cycles that overlay site level execution. Modern programmes bring together cadences across the internal annual audit, the corporate triennial audit, OSHA and MSIHC statutory audits, third party certification such as ISO 45001 and RC14001, and insurer surveillance, and our team weaves them into one coherent programme.

Auditing

Individual significance for organisations

Auditing is how an organisation discovers what it does not know about its own performance. Sites that audit rigorously identify drift before it shows up as incidents, while sites that audit superficially miss the patterns that matter. The element is also where independent perspective enters, because without external eyes the system simply optimises around its own blind spots.

Contribution to Risk Based Process Safety (RBPS)

Auditing is the assurance layer over every other RBPS element. It validates Compliance with Standards (Element 2), tests PHA quality (Element 7), examines MOC discipline (Element 13), checks training records (Element 12), and verifies asset integrity programmes (Element 10). Audit findings feed Measurement and Metrics (Element 18) and Management Review (Element 20). Element 19 is the self diagnostic capability of the whole system.

Key requirements

What compliant execution looks like

An OSHA PSM (o) triennial compliance audit
The CCPS RBPS Element 19 audit framework
ISO 19011 audit principles and competency
Auditor competency and independence
Finding closure with a target close out cycle
Cross audit integration across internal, corporate, statutory, insurer, and certification cycles
Implementation methodology

How we implement this element

A focused six step methodology calibrated to deliver auditing as a working capability rather than a documented compliance artefact.

Audit Programme Design

We map the audit cadences across the internal annual audit, corporate triennial audit, statutory audits per requirement, third party certification, and insurer surveillance.

Auditor Competency and Independence

We specify lead auditor competency per ISO 19011 and CCPS, ensure the auditor is independent of the area being audited, and set the training and certification requirements.

Audit Protocol per Element

For each RBPS and OSHA PSM element we build an audit protocol covering sample size, evidence requirement, interview protocol, and scoring criteria.

Field Audit Execution

We run a multi day on site audit with document review, walk down, operator and supervisor interviews, and a leadership debrief.

Finding Categorisation and Closure

We categorise findings by severity as critical, major, or minor, assign an owner and target close out, and track them in the corrective action database.

Audit Programme Effectiveness

We run an annual programme review covering audit finding repeat rate, closure cycle metric, and audit quality against the incident trend, integrated with corporate HSE.

Implementation flow

Element implementation flow chart

A decision gated workflow that shows the actual sequence of activities from initiation through steady state operation, with key decision points highlighted.

Start
The PSM owner or corporate audit team initiates the audit cycle
Cycle Determination
Internal annual, corporate triennial, statutory, or insurer
Auditor Selection
Competency and independence per ISO 19011
Protocol Build
Sample size, evidence requirement, and interview script per element
Field Audit Execution
Document review, walk down, interviews, and a leadership debrief
Decision
Finding identified?
Decision gate
Finding Categorisation
Critical, major, or minor with severity scoring
Owner and Close Out Target
We assign the action, deadline, and verification protocol
Corrective Action Tracking
An electronic database with progress monitoring
Close Out Verification
The auditor verifies the action is effective
Annual Programme Review
Repeat finding rate, closure cycle, and programme refinement
Deliverables

What we produce

  • An audit programme charter with a multi cadence design
  • An auditor competency and independence framework
  • An audit protocol per RBPS and OSHA PSM element
  • A field audit execution plan
  • A finding closure database and tracking dashboard
  • An annual audit programme effectiveness review
Common pitfalls

Where execution fails

  • Tick box audits that find only what the auditors expect to find
  • Findings filed but never closed
  • Corporate audits that are never integrated with site level work
  • Auditor competency that sits below the rigour the element demands
Standards & references

Codes this element is built on

OSHA 29 CFR 1910.119(o) (Compliance Audits, US)CCPS Guidelines for Auditing Process Safety Management SystemsISO 19011 2018 (Auditing Management Systems)ISO 45001 2018 Cl.9.2 (Internal Audit)MSIHC Rules 1989 Rule 4 (India)Factories Act 1948 §41B (Safety Audit, India)
Implement this element

Talk to us about implementing Auditing

We can scope this element implementation against your facility, regulatory context, and existing management system maturity, then integrate it with the other Risk Based Process Safety (RBPS) elements you already operate.