← Back to Blogs

ISO Audits

ISO Audits Explained: What Your Auditor Will Look For in HSEQ Systems

An audit notification lands in your inbox and, almost immediately, the questions start. What exactly will they look at? What records do we need? Will they interview the workforce? What happens if they find something?

These are the right questions, and the fact that you’re asking them before the audit starts puts you ahead of most. ISO audits are not designed to catch organisations out. They are a systematic, evidence-based review of whether your HSEQ system, your integrated framework for Health, Safety, Environment, and Quality management is functioning as designed, achieving its objectives, and continuously improving. Understanding what auditors look for, and why they look for it, is the most practical preparation you can do.

This guide covers how ISO audits work, what auditors examine across the four disciplines of an HSEQ system, and how to approach a health and safety compliance audit with confidence.

What Is an HSEQ System?

An HSEQ system is an integrated management framework that combines Health, Safety, Environment, and Quality disciplines under a single set of policies, processes, and performance measures. In ISO terms, a mature HSEQ system typically maps to:

  • ISO 9001:2015 – Quality Management System (QMS)
  • ISO 14001:2015 – Environmental Management System (EMS)
  • ISO 45001:2018 – Occupational Health and Safety Management System (OHSMS)

These three standards share the same High-Level Structure (Annex SL), which means their requirements can be integrated into a single coherent HSEQ framework rather than maintained as three separate systems. Read our guide on ISO Integrated Management Systems for a full breakdown of how integration works.

The health safety environment and quality HSEQ standards that underpin a certified HSEQ system all share the same audit logic, evidence of planning, implementation, monitoring, and continual improvement, verified by a competent, independent auditor.

Types of Health and Safety Audits and Inspections

Before examining what auditors look for, it helps to understand which type of audit you are preparing for. Health and safety audits and inspections fall into three distinct categories:

  • First-party audits (internal audits): Conducted by your own team against your HSEQ system and the applicable ISO standards. Required by all three standards as a clause 9.2 obligation. The findings feed directly into the management review.
  • Second-party audits (supplier or customer audits): Conducted by a client, contractor, or partner organisation to verify your HSEQ compliance before or during a contract relationship. Common in oil and gas, construction, and food supply chains.
  • Third-party audits (certification audits): Conducted by an accredited certification body. These result in the award, surveillance, or withdrawal of ISO certification. Stage 1 reviews documentation; Stage 2 verifies implementation on the ground.

HSEQ Professionals provides expert support for all three audit types through our technical and auditing services, including internal audit delivery, second-party supplier assessments, and certification readiness reviews.

What ISO Auditors Actually Look For: The Four Dimensions

Regardless of which standard is being audited, ISO 9001, ISO 14001, or ISO 45001 certification auditors approach every audit through four consistent lenses. Understanding these lenses is the foundation of effective audit preparation.

1. Documentation: Is it defined?

Auditors start with documented information, your policies, procedures, risk assessments, objectives, legal registers, and work instructions. They are not looking for a particular format or volume. They are asking: does the organisation have documented information that satisfies the requirements of the standard, is it controlled, and is it current?

Common documentation failures include outdated procedures that no longer reflect how work is actually done, policies that are not dated or authorised by top management, and risk registers that have not been reviewed since a significant operational change. A well-maintained document control system (Clause 7.5) is the foundation of a credible HSEQ audit.

2. Implementation: Is it done?

Documentation is necessary but not sufficient. Auditors spend the majority of their time verifying that procedures are actually followed on the ground. This is where health and safety audits and inspections become operational rather than administrative, auditors will walk the site, observe work activities, and verify that what the procedure says matches what workers actually do.

For a health and safety compliance audit under ISO 45001, this means checking that hazard controls described in the risk register are physically in place, not just documented. A procedure that says ‘all contractors must complete a site induction’ will be tested by asking a contractor when they last attended one and reviewing the induction records.

3. Effectiveness: Is it working?

ISO standards are not prescriptive about how you achieve outcomes, they are outcome-focused. Auditors therefore assess whether your HSEQ system is actually delivering results against its own stated objectives. An organisation that set an environmental objective to reduce waste generation by 20% but has no monitoring data, or whose data shows a 15% increase, will receive a nonconformity regardless of how well-documented the objective is.

Performance evaluation (Clause 9) is frequently where auditors find the gap between intent and reality. Monitoring programmes that exist on paper but generate no data, KPIs that are tracked but never reviewed at management level, and incident investigations that identify root causes but never verify corrective action closure are all common findings.

4. Continual improvement: Is it getting better?

Clause 10 of every ISO management system standard requires the organisation to continually improve the suitability, adequacy, and effectiveness of its system. Auditors look for evidence that the organisation learns from nonconformities, near misses, audit findings, and management review outputs and that learning translates into documented improvements that are tracked through to closure.

An HSEQ system that has produced the same audit findings across three consecutive surveillance cycles, with no evidence of root cause analysis or sustained corrective action, is not demonstrating continual improvement. Auditors will note this.

Audit Checklist ISO: What Auditors Examine Across HSEQ Standards

The table below summarises the key areas examined during a third-party certification audit across a combined HSEQ system. Use it as a practical audit checklist ISO reference when preparing for an upcoming audit.

 

Standard Audit area What auditors check
All Context & scope Is the scope clearly defined? Have internal/external issues and interested parties been identified and kept current?
All Leadership Can top management articulate the HSEQ policy? Are roles and responsibilities formally assigned and communicated?
All Objectives Are objectives measurable, monitored, and linked to the HSEQ policy? Is progress tracked and reported?
All Document control Is documented information current, authorised, and accessible to the people who need it? Are obsolete documents removed?
ISO 9001 Customer focus Are customer requirements captured? Is customer satisfaction measured? How are complaints handled and resolved?
ISO 9001 Nonconforming outputs Are nonconformities identified, segregated, and dispositioned? Is root cause analysis conducted and verified?
ISO 14001 Aspects & impacts Is the environmental aspects register complete, current, and used to drive operational controls and objectives?
ISO 14001 Legal compliance Is there a current register of applicable environmental legislation? When was compliance last evaluated?
ISO 14001 Emergency preparedness Are environmental emergency scenarios identified? Are response procedures tested and personnel trained?
ISO 45001 Hazard identification Is the risk register comprehensive, current, and reviewed after incidents and operational changes?
ISO 45001 Worker participation Is there documented evidence of worker consultation in hazard identification and OHSMS decisions (Clause 5.4)?
ISO 45001 Contractor management Are contractor HSEQ requirements defined? Are induction records and competency checks verified?
All Internal audits Has a full audit cycle been completed? Are auditors competent and independent? Are findings closed?
All Management review Are minutes documented? Does the review cover all required inputs? Are decisions and actions tracked?
All Corrective actions Are nonconformities investigated to root cause? Are corrective actions verified as effective before closure?

 

The Part Most Organisations Under-prepare For: Staff Interviews

Documentation and records can be prepared, organised, and presented in the best possible light before an auditor arrives. Staff interviews cannot. Auditors interview workers at multiple levels, from the shop floor to senior leadership because worker responses reveal whether the HSEQ system is genuinely embedded in the culture or exists only in the filing system.

Questions typically asked of front-line workers during a health and safety compliance audit include:

  • ‘What do you do if you identify a hazard you have not seen before?’
  • ‘Can you show me the emergency procedure for this area?’
  • ‘When did you last receive HSEQ training? What did it cover?’
  • ‘Have you ever raised a near miss? What happened as a result?’
  • ‘Who is responsible for HSEQ in your team?’

The answers auditors receive to these questions tell them more about the health of an HSEQ system than any document review. If workers are unaware of the hazards in their area, cannot recall their last HSEQ training, or have never heard of the near-miss reporting process, the system has an implementation gap, and the auditor will document it.

Most Common Audit Findings in HSEQ Systems

Based on our experience conducting and supporting audits across manufacturing, construction, logistics, healthcare, and oil and gas sectors, these are the findings that appear most frequently:

  • Objectives without monitoring data: The objective exists, the target is stated, but no one is collecting the data that would show whether it is being achieved.
  • Risk assessments not reviewed after incidents: An incident or near miss occurs, a corrective action is raised, but the underlying risk assessment is never updated.
  • Training records that cannot be produced: The training happened, but records are incomplete, missing sign-off, or held by a department that has since been reorganised.
  • Contractor HSEQ not controlled: The organisation has strong internal HSEQ controls but applies minimal scrutiny to contractors and sub-contractors on site.
  • Internal audits not covering all clauses: The internal audit programme exists but has gaps, certain clauses are never sampled, or entire departments are excluded from the scope.
  • Management review minutes too vague: Minutes record that the review took place but do not document the specific inputs reviewed, decisions made, or actions assigned.

How to Prepare for a Third-Party ISO Audit

  • Run a pre-audit internal audit: Conduct a full internal audit against all applicable clauses before the certification body arrives. Close any findings or document them with a clear remediation plan.
  • Check your corrective action register: All previously raised nonconformities should have evidence of root cause analysis, corrective action implementation, and effectiveness verification before the audit.
  • Review your legal compliance register: Particularly for ISO 14001 and ISO 45001, auditors will ask for your most recent compliance evaluation. Ensure it is current and can be evidenced.
  • Prepare your objective performance data: Pull together the monitoring data for all active HSEQ objectives. Auditors will want to see trends, not just the latest data point.
  • Brief your management review team: Ensure top management can speak to HSEQ performance, recent findings, and upcoming resource decisions. The auditor will typically interview the senior management sponsor.
  • Walk the site with audit eyes: Before the certification auditor walks your site, walk it yourself. Are hazard controls in place? Are emergency notices current? Are contractor areas controlled to the same standard as your own operations?

Our team delivers structured pre-audit readiness reviews and certification preparation support, contact us to discuss a technical and auditing services engagement ahead of your next audit cycle.

Build Your Internal Audit Capability

One of the most effective long-term investments an organisation can make in its HSEQ system is developing internal lead auditors. A competent internal audit team catches nonconformities before the certification body does, builds a culture of evidence-based improvement, and reduces reliance on external support over time.

HSEQ Professionals delivers ISO Lead Auditor courses covering ISO 9001, ISO 14001, and ISO 4500, all CQI-IRCA certified and delivered by experienced practitioners with real-world audit backgrounds across the Middle East, Pakistan, and the USA. Participants leave with the competence to plan, conduct, report, and follow up audits in accordance with ISO 19011.

Combined auditor training, covering multiple ISO standards in a single programme is also available for organisations running an integrated HSEQ system and wanting to build auditors capable of conducting combined audits.

Ready to Strengthen Your HSEQ Audit Performance?

Whether you are preparing for a first certification audit, responding to findings from a recent surveillance visit, or building a long-term internal audit programme, HSEQ Professionals can help. Our consultants and auditors bring hands-on HSEQ experience from oil and gas, manufacturing, healthcare, logistics, and construction, the sectors where health safety environment and quality HSEQ standards matter most.

Contact our team to discuss audit preparation support, internal audit delivery, or ISO 45001 Lead Auditor training for your organisation.