Why Australian Businesses Need to Review Their Standards Regularly

Australian businesses operate in an environment shaped by legislation, regulations, industry codes, Australian Standards, workplace requirements and customer expectations. While not every standard is legally mandatory, standards can play an important role in helping businesses operate safely, consistently and professionally.

The challenge is that standards do not remain static. They can be revised, replaced or referenced by legislation and regulations. A standard that was appropriate when a business procedure was written several years ago may no longer reflect current requirements.

For this reason, businesses should regularly review the standards referenced in their policies, procedures, work instructions and other controlled documents.

What Are Australian Standards?

Australian Standards are documents that provide specifications, procedures, guidelines or other information intended to promote safety, consistency, reliability and quality.

Standards Australia explains that standards can cover a wide range of areas, including construction, consumer products and services, energy, water, environment and other sectors. Standards may be Australian Standards (AS), Australian/New Zealand Standards (AS/NZS), or adopted international standards.

An important point for businesses is that an Australian Standard is not automatically law.

Standards are generally voluntary. However, Australian, state and territory governments can reference standards in legislation and regulations. When a standard is incorporated into legislation, regulatory requirements or other legally enforceable arrangements, compliance may become mandatory.

Businesses may also encounter mandatory industry codes, codes of practice, product safety requirements and other regulatory obligations that operate alongside standards.

Common Types Of Standards Businesses May Encounter

The standards relevant to a business depend heavily on its industry and activities.

For example, a business may need to consider standards relating to:

  • Workplace health and safety
  • Electrical work and equipment
  • Building and construction
  • Fire protection and emergency systems
  • Machinery and equipment
  • Personal protective equipment
  • Quality management
  • Environmental management
  • Information security
  • Food safety
  • Accessibility
  • Product design and safety
  • Testing and inspection
  • Installation and maintenance
  • Risk management
  • Competency and training
  • Documentation and record keeping

A business may also have contractual obligations to follow particular standards. A customer, principal contractor, insurer, certification body or tender specification may require work to be performed in accordance with a particular standard.

This means a business should look beyond legislation alone when identifying the requirements that apply to its operations.

Why Should Businesses Review Their Documented Standards?

One of the most common problems in business documentation is the “set and forget” standard.

A procedure may state:

“All inspections must be completed in accordance with AS XXXX:2018.”

But what happens if that standard has since been revised or superseded?

The procedure may continue to circulate internally, staff may continue following it, and the business may believe it is working to the appropriate requirement, when in fact its documented process is based on an outdated publication.

Regular review helps prevent this situation.

  1. Standards can change

Standards Australia regularly reviews standards to ensure they remain relevant as technology, industry practices and community expectations change.

A revised standard may introduce:

  • New safety requirements
  • Different testing methods
  • Updated terminology
  • New equipment requirements
  • Changed inspection intervals
  • Additional documentation requirements
  • Revised technical specifications
  • New responsibilities for workers or businesses

If an internal procedure continues to reference an old edition, there is a risk that the business’s documented process no longer reflects current industry requirements.

  1. Regulations can change

A standard may also become more significant because legislation or regulation changes.

Government agencies can reference standards in legislation. In those circumstances, a standard that was previously voluntary may become relevant to a legal compliance obligation.

Businesses should therefore consider standards as part of their broader compliance monitoring process rather than treating them as static technical documents.

  1. Your business may have changed

Even when a standard has not changed, the business may have.

Consider whether your organisation has:

  • Introduced new equipment
  • Changed suppliers
  • Expanded into another state or territory
  • Started offering new services
  • Changed its workplace or premises
  • Introduced new technology
  • Taken on new types of customers
  • Changed its processes
  • Outsourced activities
  • Started working on larger projects

These changes can introduce new standards and compliance requirements.

A standards review should therefore ask two questions:

“Has the standard changed?”

and

“Has our business changed?”

Both are important.

Standards Should Be Controlled Within Your Business

If your organisation maintains policies, procedures, work instructions, forms or manuals, standards referenced by those documents should be treated as controlled information.

A simple standards register can be extremely useful.

The register does not need to be complicated. Its purpose is to give the business visibility over the standards and requirements that underpin its operations.

What Should A Standards Review Include?

A practical review can include the following steps.

Step 1: Identify every standard you currently reference

Search your policies, procedures, manuals, forms, contracts, specifications and work instructions.

Look for references such as:

  • AS XXXX
  • AS/NZS XXXX
  • ISO XXXX
  • IEC XXXX
  • “current Australian Standard”
  • “relevant standard”
  • “applicable code”
  • “industry standard”

Create a central register of everything you find.

Step 2: Confirm the standard is still current

Check the official source to determine whether the publication is:

  • Current
  • Superseded
  • Withdrawn
  • Amended
  • Under revision
  • Replaced by another standard

Do not assume that the year shown in an internal procedure is still the current edition.

Step 3: Check whether the standard is legally relevant

Determine whether the standard is referenced by:

  • Commonwealth legislation
  • State or territory legislation
  • Regulations
  • Mandatory industry codes
  • Product safety requirements
  • Licencing conditions
  • Contracts
  • Project specifications
  • Certification requirements

This distinction is important because the legal status of a standard depends on how it is referenced and applied.

Step 4: Compare the new requirements with your procedures

If a standard has changed, ask:

Does our current process still meet the requirements?

This may require reviewing equipment, training, forms, inspection methods, records, responsibilities and work practices.

Step 5: Update your documentation

Where necessary, update the relevant:

  • Policies
  • Procedures
  • Work instructions
  • Forms
  • Checklists
  • Training material
  • Risk assessments
  • Registers
  • Contracts
  • Technical specifications

Make sure obsolete versions are removed or clearly identified so employees do not accidentally use them.

Step 6: Communicate the changes

Updating a document is only part of the process.

Employees who rely on the procedure need to understand what has changed and what they are now expected to do.

Business.gov.au recommends documenting policies, processes and procedures, making them accessible to staff, providing relevant training and regularly reviewing processes and procedures.

Make Standards Review Part Of Your Management System

Standards review should not be an activity that happens only when an auditor arrives.

A better approach is to incorporate it into the business’s normal management system.

For example, a business could establish an annual review process that asks:

  1. What standards do we rely on?
  2. Are they still current?
  3. Have any amendments or replacements been published?
  4. Are any of these standards referenced by legislation or regulations?
  5. Have our products, services or processes changed?
  6. Do our procedures still reflect the requirements?
  7. Do employees need additional training?
  8. Do our forms and records need updating?
  9. Are contracts or customer requirements affected?
  10. Has responsibility for monitoring each requirement been assigned?

This approach turns standards management from a reactive task into a proactive business process.

The Benefits Go Beyond Compliance

Keeping standards and internal documentation current can provide benefits beyond simply meeting regulatory requirements.

It can help businesses:

  • Reduce operational risk
  • Improve workplace safety
  • Improve consistency
  • Reduce errors and rework
  • Strengthen employee training
  • Demonstrate due diligence
  • Improve quality
  • Support tender and contract requirements
  • Prepare for audits
  • Improve customer confidence
  • Identify outdated business practices
  • Maintain better organisational knowledge

Standards can provide businesses with a recognised framework for achieving consistent and reliable outcomes.

A Final Reminder For Australian Businesses

Your business’s procedures are only as useful as the information on which they are based.

If a procedure references an Australian Standard from five or ten years ago, don’t assume it is still current. Check it.

If your business has introduced new equipment, technology or services, don’t assume your existing standards register still covers everything. Review it.

And if you discover that a standard has changed, don’t simply update the reference number. Determine whether the change affects the way your business actually operates.

Standards management is ultimately about keeping the connection between external requirements and internal business practices alive.

Regularly reviewing standards, legislation, industry codes and the documents that reference them can help Australian businesses stay informed, reduce risk and maintain processes that are fit for purpose.

Important: This article provides general information and is not legal or compliance advice. Businesses should confirm the specific requirements applicable to their industry, state or territory, products, services and contractual obligations with the relevant regulator or suitably qualified adviser.

HVNL Changes from 1 August 2026: What Heavy Vehicle Operators Need to Do

The biggest changes to Australia’s Heavy Vehicle National Law (HVNL) in more than a decade will take effect on 1 August 2026, bringing a stronger focus on proactive safety management, documented systems, and demonstrable compliance.

For heavy vehicle operators, the reforms represent a shift away from simply complying with prescriptive rules towards proving that your business actively manages transport safety risks.

Whether you operate a single truck or a national fleet, now is the time to review your systems and ensure your business is ready.

Why the HVNL is Changing

The reforms have been developed by the National Transport Commission (NTC) in partnership with the National Heavy Vehicle Regulator (NHVR) and participating state and territory governments. The aim is to modernise heavy vehicle regulation, improve safety outcomes and reduce unnecessary regulatory complexity while maintaining productivity.

The updated legislation applies in all Heavy Vehicle National Law participating jurisdictions:

  • Queensland
  • New South Wales
  • Victoria
  • South Australia
  • Tasmania
  • Australian Capital Territory

Western Australia and the Northern Territory continue to operate under their own heavy vehicle legislation.

The Biggest Change: Safety Management Systems Become Central

The most significant reform is the introduction of a formal Safety Management System (SMS) as the foundation of heavy vehicle accreditation.

Rather than focusing solely on meeting individual compliance requirements, operators will need to demonstrate they have systems in place that:

  • identify transport risks
  • assess those risks
  • implement effective controls
  • monitor performance
  • continually improve safety outcomes.

The regulator’s focus will increasingly be on whether your business can prove its systems are working, not simply whether paperwork exists.

What Operators Will Be Required to Have

Under the updated HVNL, operators should expect to have documented processes covering areas such as:

Leadership and Safety Commitment

Management must actively support transport safety rather than treating compliance as an administrative exercise.

This includes:

  • clearly defined responsibilities
  • documented safety objectives
  • evidence that management reviews safety performance.

Risk Management

Operators must identify hazards before incidents occur.

Examples include:

  • fatigue risks
  • vehicle maintenance
  • loading practices
  • scheduling pressures
  • driver competency
  • subcontractor management.

Importantly, businesses should be able to demonstrate how these risks are assessed and controlled.

Driver Competency

Businesses will need documented processes for:

  • induction
  • licence verification
  • ongoing training
  • competency assessments
  • refresher programs.

The expectation is that operators can demonstrate drivers remain competent throughout their employment.

Vehicle Maintenance

Maintenance systems must ensure vehicles remain roadworthy.

Operators should maintain documented procedures for:

  • inspections
  • preventative maintenance
  • defect reporting
  • repairs
  • maintenance records.

Incident Reporting and Investigation

Simply recording incidents will no longer be enough.

Businesses should investigate:

  • crashes
  • near misses
  • equipment failures
  • recurring defects

and use findings to improve safety systems.

Internal Auditing

Operators should regularly review their own compliance before the regulator does.

Internal audits help identify weaknesses and provide evidence that safety systems are functioning effectively.

Expanded “Fit to Drive” Requirements

The updated HVNL introduces a broader obligation regarding driver fitness.

Previously, compliance focused largely on work and rest hours.

The reforms extend this concept to ensure drivers are genuinely fit to operate a heavy vehicle.

This includes considering whether a driver may be impaired by:

  • fatigue
  • illness
  • injury
  • medication
  • alcohol or drugs
  • any other condition affecting safe driving.

Operators should have documented procedures for assessing and managing fitness for duty rather than relying solely on legal driving hours.

Changes to Accreditation

The National Heavy Vehicle Accreditation Scheme (NHVAS) will transition to a new accreditation framework built around documented Safety Management Systems.

The new framework includes:

  • General Safety Accreditation (GSA) as the baseline accreditation for operators seeking formal recognition.
  • Alternative Compliance Accreditation (ACA) for businesses seeking operational concessions, such as alternative fatigue management arrangements.

Existing accredited operators will have a transition period to move to the new framework.

Chain of Responsibility Remains Critical

The reforms do not remove existing Chain of Responsibility (CoR) obligations.

Instead, they strengthen expectations that every party in the transport supply chain actively manages safety risks.

This includes:

  • operators
  • employers
  • schedulers
  • consignors
  • loaders
  • loading managers
  • consignees
  • contractors.

Businesses must continue taking all reasonably practicable steps to eliminate or minimise transport risks.

Productivity Improvements

Not all reforms involve additional compliance.

Several changes are designed to improve productivity, including:

  • increases to General Mass Limits in some circumstances
  • simplified mass management arrangements
  • an increase in the general vehicle length limit from 19 metres to 20 metres for eligible vehicles.

These changes aim to simplify regulation while maintaining safety standards.

How Operators Should Prepare

Businesses should begin preparing well before the commencement date by:

  • reviewing current compliance systems
  • conducting a gap analysis against the new SMS requirements
  • documenting policies and procedures
  • reviewing fatigue and fitness-for-duty processes
  • training managers and supervisors
  • ensuring records can demonstrate compliance
  • preparing for future audits under the new National Audit Standard.

Operators who already have strong systems in place may only require refinements, while smaller businesses relying on informal processes are likely to have more work to do.

The Bottom Line

The updated HVNL marks a significant shift in how heavy vehicle safety is regulated in Australia.

The emphasis is no longer simply on following rules, it is on demonstrating that your business has effective systems to identify, manage and continuously improve transport safety.

For operators, success under the new legislation will depend on evidence. Policies, procedures, training records, maintenance documentation, risk assessments and internal audits will all play an increasingly important role in proving compliance.

Sherm Software has all of the necessary functions to cover your requirements, with all evidence available at the touch of a button for your next audit.

Businesses that begin preparing now will be in a stronger position when the reforms commence on 1 August 2026, reducing compliance risk while improving operational safety and efficiency.

Get in touch with us today and let us help you prepare.

Mid-Year Audit Planning: Aligning Strategy With WHS Trends

As the financial year gets underway, many Australian businesses are focused on budgets, growth plans, and operational priorities. However, the middle of the year is also an ideal time to assess another critical area of business performance, Work Health and Safety (WHS).

A mid-year WHS audit is more than a compliance exercise. It provides an opportunity to evaluate how effectively your current safety systems are working, identify emerging risks, and ensure your business is keeping pace with changing workplace expectations.

With evolving legislation, increased regulatory scrutiny, and new workplace risks continuing to emerge, businesses that review their WHS strategy mid-year are better positioned to protect their workers, maintain compliance, and support long-term business success.

Why Conduct a Mid-Year WHS Audit?

Annual reviews are important, but waiting until the end of the year to evaluate your safety systems can allow issues to persist for months.

A mid-year audit enables business owners to:

  • Identify gaps before they become compliance issues.
  • Review incident and near-miss trends from the first half of the year.
  • Assess whether existing controls remain effective.
  • Confirm that policies reflect current workplace activities.
  • Ensure workers have completed required training and competency refreshers.
  • Prepare for regulator inspections or external audits.

Rather than reacting to incidents, businesses can proactively strengthen their safety management systems.

WHS Trends Australian Businesses Should Consider

Workplaces continue to evolve, and so do the risks they face. During your mid-year review, consider whether your safety approach reflects current WHS trends.

  1. Greater Focus on Psychosocial Hazards

Mental health has become a key component of workplace safety.

Psychosocial hazards, including excessive workloads, workplace bullying, poor communication, fatigue, and role ambiguity, are now recognised as WHS risks that require the same level of attention as physical hazards.

Business owners should review:

  • Workload management
  • Employee wellbeing initiatives
  • Reporting processes
  • Leadership capability
  • Workplace culture

Addressing psychosocial risks early can improve both employee wellbeing and organisational performance.

  1. Increased Regulator Expectations

Australian WHS regulators continue to increase inspections and enforcement activities across many industries.

Businesses are expected to demonstrate not only that policies exist but that they are actively implemented, monitored, and reviewed.

Documentation should clearly show:

  • Risk assessments
  • Consultation with workers
  • Incident investigations
  • Corrective actions
  • Training records
  • Maintenance schedules

Strong records provide evidence that safety responsibilities are being effectively managed.

  1. Better Use of Safety Data

Many organisations now use safety data to identify trends before incidents occur.

Rather than focusing solely on injury statistics, businesses are monitoring:

  • Near misses
  • Hazard reports
  • Safety observations
  • Corrective action completion rates
  • Training compliance
  • Equipment inspections

Reviewing this information during a mid-year audit helps identify recurring issues that may otherwise go unnoticed.

  1. Contractor and Supply Chain Safety

Many businesses rely on contractors, subcontractors, and suppliers to deliver services.

A mid-year audit should confirm that contractor management processes remain effective, including:

  • Prequalification requirements
  • Inductions
  • Safe work procedures
  • Insurance documentation
  • Competency verification
  • Ongoing supervision

Managing contractor safety reduces risk across the entire operation.

Key Areas to Review During Your Mid-Year Audit

A structured audit provides a clear picture of your current WHS performance.

Consider reviewing:

Safety Management System

  • Policies and procedures
  • Risk management processes
  • Emergency plans
  • Safe work instructions

Workplace Inspections

  • Housekeeping standards
  • Plant and equipment condition
  • Hazard identification
  • Maintenance records

Training and Competency

  • New employee inductions
  • Refresher training
  • High-risk work licences
  • First aid qualifications

Incident Management

  • Incident reporting procedures
  • Investigation quality
  • Corrective action follow-up
  • Lessons learned

Worker Consultation

Consulting workers is a fundamental part of effective WHS management.

Review whether employees are:

  • Reporting hazards
  • Participating in safety meetings
  • Contributing to risk assessments
  • Providing feedback on controls

Workers often identify practical improvements that management may overlook.

Turning Audit Findings Into Action

The value of an audit lies in what happens after it is completed.

Prioritise findings according to risk, assign responsibilities, establish realistic timeframes, and monitor progress until actions are complete.

Business owners should also communicate improvements to employees. Demonstrating that concerns lead to meaningful action helps strengthen trust and encourages ongoing participation in workplace safety.

The Business Benefits of Mid-Year WHS Reviews

An effective WHS audit delivers more than regulatory compliance.

Businesses often experience:

  • Reduced workplace incidents
  • Improved operational efficiency
  • Lower workers’ compensation costs
  • Better employee engagement
  • Stronger reputation with clients and stakeholders
  • Greater confidence during regulator inspections

When safety becomes part of strategic planning rather than simply an administrative requirement, it contributes directly to business resilience and long-term performance.

Final Thoughts

Mid-year provides an ideal opportunity to step back and assess whether your WHS systems are supporting both your people and your business objectives.

By reviewing current performance, responding to emerging WHS trends, and addressing gaps before they escalate, Australian business owners can create safer workplaces while strengthening compliance and operational performance.

Rather than viewing a WHS audit as a once-a-year obligation, consider it an ongoing strategy that helps your business adapt, improve, and thrive in an evolving regulatory and workplace environment.

Learn more about audit readiness and use our free checklist to help with your mid-year audit plan.

Contractor Inductions: Why Compliance Slips Through the Cracks

Across Australian worksites, from construction and mining to logistics and facilities management, contractor inductions are a routine part of onboarding. They’re meant to ensure every worker understands site rules, hazards, and responsibilities before starting work. On paper, the process looks solid. In practice, however, contractor inductions are one of the most common points where compliance quietly breaks down.

This isn’t usually due to negligence or bad intent. More often, it’s the result of rushed processes, fragmented systems, and assumptions that don’t hold up under scrutiny. Understanding where things go wrong is the first step to tightening compliance and reducing risk.

The “Tick-and-Flick” Mentality

One of the biggest pitfalls is treating inductions as a box-ticking exercise. When deadlines loom and contractors are needed on-site quickly, the focus shifts from comprehension to completion. Workers may click through online modules or skim documents just to gain site access.

The problem? Completion doesn’t equal understanding. If a contractor hasn’t genuinely absorbed key safety procedures, the business is exposed, not just to regulatory penalties, but to real-world incidents.

Inconsistent Induction Standards Across Sites

Many organisations operate across multiple locations, each with slightly different induction requirements. While some variation is necessary due to site-specific risks, inconsistency can create confusion, especially for contractors moving between sites.

Without a standardised baseline, important information can fall through the cracks. Contractors may assume they’ve “already done this before,” while site managers assume prior knowledge that may not exist.

Poor Record-Keeping and Verification

In an audit or incident investigation, documentation is everything. Yet many businesses still rely on scattered systems like emails, spreadsheets and paper forms to track inductions.

This fragmentation leads to common issues:

  • Missing or incomplete records
  • Difficulty verifying who completed what training
  • Expired inductions going unnoticed

When regulators come knocking, these gaps quickly become liabilities.

Language and Literacy Barriers

Australia’s workforce is diverse, and not all contractors will have the same level of English proficiency or literacy. Standard induction materials often fail to account for this.

If critical safety information isn’t clearly understood, the induction has effectively failed, even if it’s been “completed.” Visual aids, translated materials, and interactive formats can make a significant difference here, but they’re not always implemented.

Lack of Engagement and Relevance

Generic inductions that cover broad policies without tailoring to specific roles or risks tend to lose attention quickly. Contractors may struggle to see how the information applies to their actual tasks.

Effective inductions need to answer a simple question: What does this mean for me, today, on this site? Without that connection, retention drops and compliance weakens.

No Ongoing Reinforcement

Induction shouldn’t be a one-off event. Over time, people forget procedures, become complacent, or develop shortcuts. Yet many organisations fail to reinforce key messages after the initial onboarding.

Toolbox talks, refresher training, and periodic assessments are critical to maintaining compliance, not just establishing it.

Overreliance on Contractors to Self-Manage

It’s common for businesses to assume that contractors, especially experienced ones, will manage their own compliance. While contractors do carry responsibilities under Australian work health and safety laws, the host organisation still has a duty of care.

Assumptions like “they’ve done this before” or “they know the risks” can lead to dangerous gaps in oversight.

Closing the Gaps

Improving contractor induction compliance doesn’t necessarily mean adding more content, it means improving how it’s delivered, tracked, and reinforced.

Some practical steps include:

  • Standardising core induction requirements across sites
  • Using digital systems for real-time tracking and verification
  • Designing content for clarity, engagement, and accessibility
  • Incorporating site-specific, role-relevant information
  • Scheduling regular refreshers and compliance checks

Ultimately, contractor inductions are more than a procedural step, they’re a frontline defence against incidents and non-compliance. When done well, they set clear expectations, build safety culture, and protect both workers and businesses.

When done poorly, they create a false sense of security.

That’s where the real risk lies.

For a broader explanation of how inductions fit into defensible contractor management, see our Contractor and Supplier Compliance Management Guide.

Sherm Software can help close the gaps using the Contractor and Supplier Register by maintaining records and sending automatic notifications when scheduled refreshers and compliance checks are due.

Use our Checklist to assess whether your contractor compliance approach would stand up to audit, investigation, or client scrutiny.

Contractor Prequalification in Australia, More Than a Paper Chase

Across Australia, contractor prequalification is often treated as a compliance exercise—collect the required documents, tick the boxes, and move on. With strict regulatory frameworks and a strong focus on workplace safety, it’s understandable why documentation plays such a central role.

But here’s the reality, collecting documents alone doesn’t ensure a contractor is safe, capable, or reliable. In fact, over-reliance on paperwork can create blind spots that expose businesses to serious operational and legal risks.

Compliance Doesn’t Equal Capability

In the Australian context, contractors are typically required to provide:

  • Public liability and workers’ compensation insurance
  • Relevant licences and tickets (e.g. White Cards, high-risk work licences)
  • Safe Work Method Statements (SWMS)
  • Safety management plans and policies

These are all essential. However, they only confirm that a contractor meets minimum requirements at a specific point in time. They don’t guarantee that work will be carried out safely on-site or that systems are actively followed.

A contractor might submit a compliant SWMS, but is it actually used in day-to-day operations? Are workers properly trained, supervised, and accountable?

Documentation alone can’t answer these questions.

The Risks of a “Set and Forget” Approach

Many businesses adopt a “set and forget” model—documents are collected during onboarding and rarely revisited. In a fast-moving environment like construction, mining, or infrastructure, this approach can quickly become outdated.

Common issues include:

  • Expired insurances or licences going unnoticed
  • Generic SWMS that don’t reflect actual site conditions
  • Changes in subcontractors or workforce capability
  • Deterioration in safety performance over time

Under Australian Work Health and Safety (WHS) laws, businesses (PCBUs) have a duty to ensure, so far as reasonably practicable, the health and safety of workers—including contractors. Simply collecting documents is unlikely to meet this obligation if something goes wrong.

Bridging the Gap Between Paper and Practice

The key challenge is ensuring that what’s documented is actually implemented.

To bridge this gap, organisations need to go beyond collection and focus on validation. This might include:

  • Reviewing SWMS for task-specific relevance, not just completeness
  • Verifying licences with issuing authorities where applicable
  • Confirming insurance coverage directly with providers
  • Conducting site observations or audits
  • Speaking with referees about past performance

These steps help ensure that contractors are not just compliant on paper, but competent in practice.

Prequalification Should Be Ongoing

In Australia’s high-risk industries, conditions can change rapidly. That’s why contractor prequalification should be treated as a continuous process, not a one-off task.

A more effective approach includes:

  • Regular reviews of contractor documentation
  • Automated alerts for expiring licences and insurances
  • Monitoring incident reports and near misses
  • Periodic reassessment based on project risk

This dynamic model aligns more closely with WHS expectations and helps organisations stay ahead of potential issues.

Using Technology the Right Way

Digital prequalification platforms are becoming increasingly common across Australia, particularly in sectors like construction and energy. While these systems can streamline administration, they shouldn’t be used as a shortcut.

The real value of technology lies in:

  • Providing visibility over contractor compliance status
  • Enforcing document currency through automated reminders
  • Highlighting gaps or inconsistencies in submissions
  • Supporting ongoing monitoring and reporting

Technology should enhance decision-making—not replace critical thinking.

A Shift Towards Risk-Based Thinking

To strengthen contractor prequalification, Australian businesses need to shift their mindset from compliance to risk management.

Instead of asking, “Have we collected everything?”, the better question is, “Is this contractor genuinely capable of doing the job safely and effectively?”

This means considering factors such as:

  • The complexity and risk level of the work
  • The contractor’s track record and experience
  • Their safety culture and leadership
  • Their ability to adapt to changing site conditions

A risk-based approach ensures that higher-risk work receives greater scrutiny, rather than treating all contractors the same.

Building a More Robust System

A stronger contractor prequalification framework in Australia should include:

  1. Baseline document collection to meet regulatory requirements
  2. Verification processes to confirm accuracy and authenticity
  3. Ongoing monitoring aligned with WHS obligations
  4. Risk-based assessments tailored to specific work activities
  5. Continuous improvement driven by performance data

This approach not only supports compliance but actively reduces the likelihood of incidents and disruptions.

Final Thoughts

In Australia’s regulatory environment, paperwork is essential—but it’s only the starting point.

True contractor prequalification goes beyond documents to assess real-world capability, behaviour, and risk over time. Businesses that move past the “paper chase” mindset are better equipped to protect their workers, meet their WHS duties, and deliver successful projects.

Because when it comes to contractor management, what happens on-site matters far more than what’s sitting in a folder.

This is explored further in our Contractor and Supplier Compliance Management Guide.

Sherm Software manages all of your Contractor and Supplier requirements, from monitoring incidents reported to notifications sent when expiry dates are approaching for documentation supplied.  Get in touch and let us help you make periodic reassessment much easier.

ISO 45001 vs WHS Act: What Businesses Get Wrong

Many Australian businesses assume that if they’re certified to ISO 45001, they’ve “covered” their legal WHS obligations.

Others assume that if they comply with the WHS Act, there’s no need to worry about ISO certification.

Both assumptions are wrong.

Understanding the difference between ISO 45001 and Australia’s WHS legislation — and how they intersect — is critical to avoiding compliance gaps, wasted effort, and audit findings.

The Legal Foundation: The WHS Act

Australia’s work health and safety laws are built around the model Work Health and Safety Act 2011, adopted (with variations) across most states and territories.

The WHS Act:

  • Is law
  • Imposes mandatory duties
  • Creates enforceable obligations
  • Carries penalties for non-compliance

It establishes the primary duty of care for a PCBU (Person Conducting a Business or Undertaking) and requires risks to be eliminated or minimised so far as is reasonably practicable.

Regulators such as SafeWork NSW and WorkSafe Victoria enforce compliance.

Failure to comply can result in improvement notices, prohibition notices, fines, or prosecution.

The International Standard: ISO 45001

ISO 45001 is an international management system standard published by International Organisation for Standardisation.

It is:

  • Voluntary (unless contractually required)
  • A framework for managing OH&S risks
  • Audited by certification bodies
  • Focused on systems and continual improvement

It does not replace or override legal obligations.

The Core Difference

WHS Act = What you must do (legal duties)

ISO 45001 = How you can structure your system to manage those duties

One is law.

The other is a management framework.

Confusing the two is where businesses go wrong.

What Businesses Commonly Get Wrong

  1. “We’re ISO Certified, So We’re Legally Compliant”

ISO 45001 requires organisations to identify and comply with applicable legal requirements — but certification does not guarantee legal compliance.

Auditors assess whether you have a system to manage compliance. Regulators assess whether you are actually compliant.

An organisation can pass an ISO audit yet still breach the WHS Act.

Certification bodies do not enforce legislation — regulators do.

  1. Treating ISO as a Paper Exercise

Some businesses implement ISO 45001 purely for:

  • Tender eligibility
  • Prequalification
  • Client expectations

They build extensive documentation but fail to ensure controls are embedded operationally.

ISO 45001 emphasises:

  • Leadership commitment
  • Worker consultation
  • Risk-based thinking
  • Continual improvement

If documentation exists without real implementation, both ISO auditors and regulators will identify the gap.

  1. Ignoring Officer Due Diligence

The WHS Act imposes personal duties on officers (e.g. directors and senior executives).

ISO 45001 requires leadership involvement — but it does not create personal criminal liability.

Some businesses mistakenly believe board-level review for ISO purposes automatically satisfies WHS due diligence.

Due diligence under the Act requires officers to:

  • Acquire knowledge of WHS matters
  • Understand operations and risks
  • Ensure resources are provided
  • Verify controls are implemented

That verification element is where many organisations fall short.

  1. Confusing Risk-Based Thinking with “Reasonably Practicable”

ISO 45001 uses risk-based thinking to manage OH&S risks.

The WHS Act uses the legal test of “so far as is reasonably practicable.”

These concepts overlap — but they are not identical.

The legal test considers:

  • Likelihood of hazard or risk occurring
  • Degree of harm
  • What the person knows (or should reasonably know)
  • Availability and suitability of controls
  • Cost relative to risk

If risk assessments don’t reflect this reasoning, legal defensibility may be weak — even if ISO processes exist.

  1. Over-Documenting to Satisfy ISO

ISO 45001 does not require excessive paperwork.

Yet many organisations create:

  • 100+ page manuals
  • Multiple redundant forms
  • Complex approval pathways

The WHS Act does not require elaborate documentation either — it requires effective risk management and control.

Over-complication often creates implementation gaps.

  1. Failing to Integrate Psychosocial Risk Management

Australian regulators are increasingly focused on psychosocial hazards (e.g. bullying, workload, fatigue).

While ISO 45001 covers psychological health risks in scope, many organisations:

  • Focus heavily on physical safety
  • Fail to systematically assess psychosocial risks
  • Lack documented controls

Regulators are far more likely to issue notices for these failures than ISO auditors are to withdraw certification.

Where ISO 45001 Adds Value

When implemented properly, ISO 45001 strengthens WHS compliance by:

  • Creating structured governance
  • Formalising consultation mechanisms
  • Improving documentation control
  • Embedding continual improvement
  • Driving leadership accountability

In mature organisations, ISO becomes a tool to demonstrate WHS compliance — not a substitute for it.

A Practical Comparison

WHS Act ISO 45001
 Mandatory law  Voluntary standard
 Enforced by regulators  Audited by certification bodies
 Breaches can lead to prosecution  Nonconformities affect certification
 Focus on duties and risk control  Focus on systems and improvement
 Personal liability for officers  Organisational certification only

The Smart Approach

Australian businesses should:

  1. Treat the WHS Act as the baseline requirement
  2. Use ISO 45001 as a structured framework
  3. Ensure risk management aligns with the “reasonably practicable” test
  4. Embed leadership accountability beyond symbolic review
  5. Focus on implementation, not paperwork

Final Thoughts

ISO 45001 and the WHS Act are not competitors.

They operate at different levels:

  • The WHS Act defines your legal duty.
  • ISO 45001 provides a management system to help meet that duty.

Businesses get into trouble when they mistake certification for compliance — or treat compliance as a tick-box exercise.

In Australia, the safest position is this:

Build a WHS system that genuinely manages risk and meets legislative duties.

Then use ISO 45001 to strengthen, structure, and continuously improve it.

Get in touch with us today and see how Sherm Software and Safety for Life can help.

Our Audit Readiness Guide explains how businesses can design systems that withstand multiple audit regimes simultaneously.

Why Spreadsheets and Shared Drives Stop Working for Audit Readiness

For many Australian businesses, spreadsheets and shared drives start as practical solutions for managing compliance evidence, policies, and audit documentation. They are familiar, inexpensive, and flexible.

But as organisations grow and regulatory expectations increase, these tools often become the very thing that slows down — or jeopardises — audit readiness.

From ISO certifications to industry-specific regulations and internal governance reviews, businesses across Australia are finding that spreadsheets and shared folders simply cannot keep up with modern audit requirements.

Let’s explore why.

  1. Version Control Becomes a Nightmare

In a spreadsheet-based compliance system, multiple people often update documents simultaneously.

This creates problems like:

  • Multiple file versions (e.g. RiskRegister_v5_FINAL_FINAL.xlsx)
  • Uncertainty about which document is the latest
  • Edits being overwritten
  • Important changes going untracked

During an audit, this leads to confusion and delays when auditors ask a simple question:

“Which version of this control was in effect during the review period?”

Without clear version history, proving this can become difficult.

  1. Evidence Is Scattered Across Systems

Audits rely heavily on evidence.

However, when organisations rely on shared drives, audit evidence is often spread across:

  • Email attachments
  • Different folders on network drives
  • Personal desktop files
  • Team collaboration tools
  • Individual spreadsheets

This fragmentation creates a huge administrative burden during audits. Teams spend hours — sometimes days — searching for documentation instead of demonstrating compliance.

Worse still, critical evidence can be accidentally missed.

  1. No Clear Ownership or Accountability

Compliance tasks typically involve many people across different teams:

  • IT
  • Finance
  • HR
  • Operations
  • Risk and compliance teams

In spreadsheets and shared drives, responsibilities are rarely structured. Tasks might be written in a sheet, but there’s usually no system enforcing:

  • Ownership of controls
  • Deadlines for reviews
  • Automated reminders
  • Escalation when tasks are overdue

Without clear accountability, controls that look complete on paper may actually be outdated or untested.

  1. Limited Audit Trail

Auditors want to see a clear trail of activity.

They need to know:

  • Who updated a policy
  • When a risk assessment was last reviewed
  • When a control was tested
  • What changes were made

Spreadsheets rarely provide a reliable audit trail, especially when files are downloaded, copied, or edited offline.

This lack of traceability raises questions about the integrity of compliance records.

  1. Scaling Becomes Impossible

A spreadsheet-based compliance approach may work when a business has:

  • One certification
  • A small team
  • Limited regulatory exposure

But as organisations expand, compliance requirements multiply. Businesses may need to manage:

  • Multiple standards
  • Several audits each year
  • Hundreds of controls
  • Dozens of evidence requests

At this point, spreadsheets become unmanageable. Teams end up maintaining multiple disconnected trackers that quickly fall out of sync.

  1. Audit Preparation Becomes a Fire Drill

Perhaps the biggest problem with spreadsheet-driven compliance is what happens before an audit.

Instead of being continuously audit-ready, teams scramble to prepare documentation:

  • Evidence is chased across departments
  • Controls are quickly re-reviewed
  • Policies are updated at the last minute
  • Teams rush to assemble audit folders

This reactive approach increases stress, wastes time, and increases the risk of non-conformities.

  1. Lack of Real-Time Visibility

Executives and compliance leaders need a clear view of risk and compliance status.

However, spreadsheets rarely provide real-time insight into:

  • Which controls are overdue
  • Which risks are increasing
  • Which departments are behind on reviews
  • What evidence is missing

Without this visibility, compliance management becomes reactive instead of proactive.

What Modern Audit-Ready Organisations Do Differently

Organisations that consistently pass audits with minimal disruption typically move beyond spreadsheets and shared drives.

Instead, they implement structured compliance systems that provide:

  • Centralised evidence management
  • Automated control tracking
  • Built-in audit trails
  • Clear ownership and accountability
  • Real-time compliance dashboards

This allows teams to maintain continuous audit readiness, rather than preparing only when an audit is scheduled.

The Bottom Line

Spreadsheets and shared drives are useful tools — but they were never designed to manage complex compliance frameworks or support audit readiness.

As Australian businesses face increasing regulatory expectations, relying on manual systems becomes risky and inefficient.

Moving toward a more structured approach to compliance management helps organisations:

  • Reduce audit stress
  • Improve accountability
  • Save time during reviews
  • Strengthen governance and risk management

And most importantly, it ensures that when auditors arrive, the business is already prepared.

Get in touch with us today and see how Sherm Software can help with that preparation.

Our Audit Readiness Guide explains what scalable, audit-ready systems look like in practice.

Audit Evidence: What to Keep, What to Drop, What to Digitise

If you’ve ever prepared for a WHS audit, you know the temptation: keep everything.

Folders expand. Shared drives overflow. Email chains get archived “just in case.”

But experienced auditors don’t reward volume — they look for relevance, reliability, and traceability.

Whether you’re preparing for a regulator interaction, client audit, or certification against ISO 45001, here’s how to decide what audit evidence to keep, what to drop, and what to digitise.

First: What Counts as “Audit Evidence”?

Audit evidence is any information that demonstrates your WHS management system:

  • Meets legal requirements (e.g. Work Health and Safety Act 2011 and state equivalents)
  • Is implemented in practice
  • Is effective and reviewed

Evidence must be:

  • Accurate
  • Current
  • Accessible
  • Traceable

If it doesn’t support those criteria, it’s probably clutter.

What to Keep

These are documents and records that auditors consistently request and rely on.

  1. Core Governance Documents

Keep:

  • WHS policy signed by senior leadership
  • Roles and responsibilities
  • Organisational chart
  • Legal compliance register
  • Risk management procedure

These demonstrate structure and accountability.

  1. Risk Management Records

Keep:

  • Current risk assessments
  • SWMS (where applicable)
  • Hazard registers
  • Control implementation records
  • Review evidence

Important: Outdated risk assessments that no longer reflect operations should be archived — not active.

  1. Training and Competency Records

Keep:

  • Induction records
  • High-risk work licences
  • Verification of competency (VOC)
  • Refresher training logs
  • Supervisor competency evidence

Auditors look for proof that workers are competent at the time of work, not just when they were first hired.

  1. Incident and Corrective Action Records

Keep:

  • Incident reports
  • Investigation findings
  • Root cause analysis
  • Corrective action tracking
  • Evidence of close-out

What matters most is showing that actions were implemented and verified.

  1. Consultation Evidence

Keep:

  • Safety committee minutes
  • HSR records
  • Toolbox talk records
  • Worker consultation feedback

WHS legislation places strong emphasis on consultation — auditors expect to see evidence of it.

What to Drop (or Archive Properly)

Not all documents need to stay in your active audit folder.

  1. Superseded Policies and Procedures

If a document has been replaced:

  • Archive it with version control
  • Remove it from operational folders
  • Ensure only current versions are accessible

Auditors often identify “document control failures” when outdated procedures remain in circulation.

  1. Redundant Forms

Many organisations collect forms no one reviews:

  • Pre-start checklists never analysed
  • Hazard reports with no follow-up
  • Meeting minutes no one reads

If a record doesn’t inform decisions or improvements, question why it exists.

  1. Excessive Email Evidence

Email chains are weak audit evidence unless:

  • They demonstrate formal approval
  • They verify a decision
  • They confirm action completion

Where possible, convert critical decisions into controlled records.

  1. Duplicated Records

If information exists in multiple systems:

  • Choose one “source of truth”
  • Eliminate manual duplication
  • Reduce reconciliation errors

Duplication creates audit risk.

What to Digitise

Digitisation isn’t just about convenience — it improves traceability and audit readiness.

  1. Training Registers

Move from spreadsheets to:

  • Centralised training management systems
  • Automated refresher alerts
  • Licence expiry tracking

This reduces non-compliance risk.

  1. Risk Registers

Digital risk systems allow:

  • Version control
  • Review tracking
  • Control verification
  • Dashboard reporting

Auditors appreciate systems that clearly show when risks were last reviewed.

  1. Corrective Action Tracking

Manual spreadsheets often fail because:

  • Actions aren’t assigned clearly
  • Deadlines aren’t monitored
  • Close-outs aren’t verified

Digital systems provide accountability and audit trails.

  1. Contractor Management

Digitise:

  • Prequalification documents
  • Insurance currency
  • SWMS approvals
  • Induction records

This is especially valuable for construction, logistics, and multi-site businesses.

How Long Should You Keep WHS Records?

Retention requirements vary depending on the type of record and state legislation, but common examples include:

  • Incident records involving serious injury: often 5+ years
  • Health monitoring records (e.g. asbestos exposure): decades
  • Training records: duration of employment + additional period

Always align with applicable WHS regulations and industry-specific requirements.

The “Audit-Ready” Test

Ask these five questions about any document:

  1. Does this demonstrate compliance or effectiveness?
  2. Is it current?
  3. Is it controlled (versioned and authorised)?
  4. Can we retrieve it within minutes?
  5. Does it show follow-through, not just intent?

If the answer is “no” to most of these, reconsider its place in your system.

The Biggest Mistake Businesses Make

They build systems for the audit — not for the business.

Auditors (including those assessing against ISO 45001) are trained to detect:

  • Over-documented systems
  • Forms created purely for compliance
  • Records that exist but aren’t used

Strong evidence is:

  • Simple
  • Relevant
  • Consistent
  • Embedded in daily operations

Final Thoughts

Good audit evidence isn’t about volume — it’s about clarity and control.

Keep what proves your system works. Drop what adds noise. Digitise what improves visibility and accountability.

An audit-ready organisation isn’t the one with the most folders. It’s the one where evidence is accurate, current, and easy to find — every day, not just before the auditor arrives.

Sherm Software will help you to become an audit-ready organisation, book a demo today to see how.

Our Audit Readiness guide explains how businesses can design systems that withstand multiple audit regimes simultaneously.

What WHS Auditors Actually Look For

Work Health and Safety (WHS) audits can feel intimidating. Whether you’re preparing for a regulator visit, a client prequalification, or certification against ISO 45001, many businesses aren’t entirely sure what auditors are really assessing.

The good news? WHS auditors aren’t looking for perfection. They’re looking for evidence of a functioning safety management system that is practical, understood, and consistently applied.

Here’s what WHS auditors actually focus on.

Legal Compliance with WHS Legislation

First and foremost, auditors assess compliance with the relevant state or territory WHS legislation, such as:

  • Work Health and Safety Act 2011
  • SafeWork NSW requirements
  • WorkSafe Victoria guidance

They want to see that your organisation understands its primary duty of care, officer due diligence obligations, and worker responsibilities.

Typical evidence requested:

  • WHS policy signed by senior management
  • Documented responsibilities
  • Legislative compliance register
  • Evidence of periodic legal reviews

Risk Management Processes

WHS law is risk-based. Auditors expect to see a structured process for:

  • Hazard identification
  • Risk assessment
  • Implementation of controls
  • Review of control effectiveness

They’ll check whether your process aligns with the hierarchy of control (elimination, substitution, engineering, administrative, PPE).

Common areas reviewed:

  • High-risk construction work
  • Plant and equipment
  • Manual handling
  • Hazardous chemicals
  • Psychosocial hazards (increasingly important)

They’re not just checking paperwork — they’ll verify that controls exist in practice.

Consultation and Worker Participation

Under WHS laws, consultation is mandatory. Auditors will examine:

  • Health and Safety Representative (HSR) arrangements
  • Safety committee meeting minutes
  • Toolbox talks
  • Worker feedback mechanisms

They may interview workers directly. If employees can’t explain safety procedures or feel disconnected from the system, that’s a red flag.

Training and Competency

Auditors look for proof that workers are competent to perform their tasks safely.

Evidence may include:

  • Induction records
  • High-risk work licences
  • Verification of Competency (VOC) records
  • Supervisor training
  • Contractor onboarding systems

They’ll also check whether refresher training is scheduled and tracked.

Incident Reporting and Investigation

A strong WHS system treats incidents as learning opportunities.

Auditors review:

  • Incident reports
  • Investigation findings
  • Root cause analysis
  • Corrective actions
  • Evidence that actions were closed out

They may ask:

“Show me an incident from the last 12 months and what changed because of it.”

Documentation vs. Reality

One of the biggest misconceptions is that WHS audits are purely document checks.

They aren’t.

Auditors conduct:

  • Site inspections
  • Worker interviews
  • Observation of work practices

If your procedures say one thing but work is done differently, that gap will be identified. Consistency between Policy, Procedure and Practice is critical.

Contractor and Supplier Management

If you engage contractors, auditors will examine:

  • Prequalification processes
  • SWMS (Safe Work Method Statements)
  • Contractor induction
  • Monitoring and supervision
  • Performance reviews

Principal contractors and businesses conducting high-risk work receive particular scrutiny.

Emergency Preparedness

Auditors assess whether you are prepared for reasonably foreseeable emergencies.

They’ll review:

  • Emergency plans
  • Evacuation diagrams
  • Fire warden training
  • Drill records
  • First aid arrangements

And they’ll often ask workers what they would do in an emergency.

Continuous Improvement

A mature WHS system shows evidence of ongoing improvement.

Auditors look for:

  • Internal audits
  • Management review meetings
  • KPI tracking (e.g. TRIFR, LTIFR)
  • Corrective and preventive action systems

Certification audits (such as ISO 45001) place strong emphasis on leadership commitment and system improvement over time.

Officer Due Diligence

Under WHS law, company officers must exercise due diligence. Auditors may review whether directors and executives:

  • Receive WHS performance reports
  • Allocate adequate resources
  • Understand critical risks
  • Verify the implementation of controls

Board-level visibility of safety is increasingly expected.

What Auditors Are Not Looking For

  • A perfect safety record
  • Zero incidents
  • Overly complex documentation
  • A 500-page safety manual no one reads

They want to see a system that is:

  • Practical
  • Proportionate to your business size and risk
  • Understood by workers
  • Actively maintained

Final Thoughts

WHS audits are about evidence, consistency, and effectiveness.

If your safety system:

  • Identifies real risks
  • Implements appropriate controls
  • Involves workers
  • Learns from incidents
  • Demonstrates leadership commitment

…you’re already aligned with what auditors actually look for.

The key is not preparing for the audit the week before — it’s building a safety system that works every day.

Sherm Software is that safety system, book a demo today and see for yourself.

For a deeper explanation of how these expectations come together, see our guide to Audit Readiness for WHS, ISO and Principal Contractor Audits.

Common Reasons Businesses Fail WHS, ISO or Principal Contractor Audits

Workplace audits, whether for Work Health and Safety (WHS), ISO certification, or principal contractor compliance, are designed to ensure businesses operate safely, legally, and systematically.

Audits may be conducted under state-based WHS regulators such as Safe Work Australia (policy body), enforcement authorities like SafeWork NSW, or as part of ISO certification through standards developed by International Organisation for Standardisation. Principal contractors on construction projects also conduct prequalification and ongoing compliance audits to manage site risk.

Despite good intentions, many businesses fail these audits for preventable reasons. Below are the most common causes, and how to avoid them.

Incomplete or Outdated Safety Management Systems

A common failure point is having a WHS or ISO system that looks good on paper but hasn’t been updated, or implemented, in practice.

Typical issues include:

  • Policies not reviewed annually
  • Procedures that don’t reflect current operations
  • Missing version control
  • Documents that reference outdated legislation

Auditors look for evidence that your system is live, current, and embedded, not just a template stored in a folder.

How to avoid it:

Schedule annual management reviews and document revisions. Ensure procedures match actual site practices.

Poor Hazard Identification and Risk Assessments

Under harmonised WHS laws, businesses must identify hazards and implement effective controls.

Audit failures often arise from:

  • Generic, copy-paste risk assessments
  • Missing Safe Work Method Statements (SWMS)
  • No evidence of site-specific risk review
  • Controls not aligned with the hierarchy of control

Principal contractors in construction are especially strict about SWMS compliance and site-specific risk management.

How to avoid it:

Ensure risk assessments are task-specific, signed, dated, and reviewed when conditions change.

Inadequate Training and Competency Records

You may have competent workers, but if you can’t prove it, you can fail the audit.

Common documentation gaps include:

  • Expired high-risk work licences
  • Missing VOC (Verification of Competency) records
  • No training matrix
  • No induction records
  • No refresher training evidence

ISO standards such as ISO 9001 and ISO 45001 require documented competency evidence.

How to avoid it:

Maintain a live training register and monitor expiry dates proactively.

Lack of Consultation and Worker Participation

WHS laws require consultation with workers on safety matters.

Auditors may ask:

  • How are workers consulted about hazards?
  • Are toolbox talks documented?
  • Is there evidence of safety meetings?
  • Are HSRs (Health and Safety Representatives) involved?

If consultation is informal and undocumented, it may not meet compliance requirements.

How to avoid it:

Keep minutes of toolbox talks and safety meetings. Record attendance and action items.

Incident Reporting and Investigation Failures

Many businesses fail audits not because incidents occurred, but because they weren’t managed correctly.

Red flags include:

  • No incident register
  • No investigation reports
  • No root cause analysis
  • Corrective actions not tracked
  • Notifiable incidents not reported

Regulators expect a structured approach to incident management and corrective actions.

How to avoid it:

Use a formal incident reporting system and track corrective actions through to completion.

Contractor Management Gaps

Principal contractor audits often focus heavily on subcontractor compliance.

Common issues:

  • No contractor prequalification process
  • Missing insurances
  • No SWMS review process
  • No evidence of subcontractor induction
  • Lack of monitoring and supervision

If you can’t demonstrate oversight of subcontractors, you may fail site audits.

How to avoid it:

Implement a documented contractor management procedure with checklists and approval records.

Internal Audits Not Conducted (or Not Effective)

For ISO-certified businesses, internal audits are mandatory.

Frequent problems include:

  • No internal audit schedule
  • Superficial audits with no findings
  • No evidence of corrective action follow-up
  • Management reviews not conducted

Auditors expect to see continuous improvement, not just compliance.

How to avoid it:

Conduct structured internal audits annually and document management review outcomes.

Poor Document Control

Document control is a major ISO audit focus area.

Typical failures:

  • Uncontrolled forms in circulation
  • Staff using outdated procedures
  • Missing document registers
  • No approval signatures

Even strong systems can fail audits if document control is weak.

How to avoid it:

Use a controlled document register with version numbers and review dates.

Leadership and Due Diligence Gaps

Under WHS laws, company officers must exercise due diligence.

Auditors may question:

  • How leadership monitors WHS performance
  • Whether safety KPIs are reviewed
  • If directors receive safety reports
  • How compliance obligations are tracked

If leadership cannot demonstrate active involvement, this can result in major non-conformances.

How to avoid it:

Document board-level WHS reporting and decision-making processes.

“Paper Compliance” Without Real Implementation

One of the biggest audit failures is when systems exist, but workers don’t follow them.

Auditors commonly:

  • Interview workers
  • Observe work practices
  • Compare procedures against actual behaviour

If there’s a disconnect between documentation and practice, it’s a serious red flag.

How to avoid it:

Ensure supervisors enforce procedures and conduct regular site inspections.

Final Thoughts

Most WHS, ISO, and principal contractor audit failures aren’t caused by catastrophic breaches, they’re caused by:

  • Inconsistent documentation
  • Lack of follow-through
  • Poor monitoring
  • Weak leadership engagement

The key to passing audits is embedding safety and compliance into everyday operations, not treating audits as one-off events.

If your systems are current, documented, implemented, and regularly reviewed, audits become far less stressful, and far more predictable.

Proactive compliance doesn’t just help you pass audits, it strengthens your business resilience, protects workers, and enhances your reputation in competitive industries like construction, manufacturing, and civil works.

This article expands on concepts covered in our Audit Readiness pillar page, which explains how these failures can be prevented structurally.