Learn · Fundamentals

How to Get a 5 Star Result on a Health and Safety Audit

A health and safety audit is not a box-ticking exercise — it is a structured examination of whether your safety management actually works, not just whether the paperwork exists. Whether you are facing a client audit, a principal contractor's site inspection, or an accreditation scheme assessment, the same principle applies: auditors award top marks to organisations that can demonstrate control, not just describe it.

Here is what that looks like in practice.


Understand What Auditors Are Actually Measuring

Most audit frameworks — whether CHAS, Alcumus Safe Contractor, ISO 45001, or a bespoke client scheme — assess the same underlying elements:

  • Policy and leadership — is there a written policy (required under the Health and Safety at Work etc. Act 1974 if you employ five or more), and does senior management visibly own it?
  • Risk assessment — are suitable and sufficient assessments in place under Regulation 3 of the Management of Health and Safety at Work Regulations 1999?
  • Competence and training — can you prove people are trained and that training is current?
  • Safe systems of work — do RAMS (Risk Assessment and Method Statement) documents exist for significant tasks, are they task-specific, and have workers signed them?
  • Monitoring and review — are inspections carried out, findings recorded, and corrective actions closed out?

A five-star result comes from evidencing all of these, not just the ones you find easy.


Get the Paperwork Right — Without Making It Generic

Auditors are experienced enough to spot a template that has never been read. Generic risk assessments with no site-specific detail, or method statements that could apply to any job anywhere, are a red flag.

For each significant task, your RAMS should:

  • Name the specific site, task, and date range
  • List the actual hazards present (not every possible hazard in existence)
  • Record realistic residual risk ratings after controls are applied
  • Describe controls in the correct hierarchy: eliminate the hazard first, then substitute, then apply engineering controls (such as guarding or LEV), then administrative controls (such as permits or supervision), with PPE as the last resort
  • Be signed by the workers carrying out the work — not just the manager who wrote it

Under the Control of Substances Hazardous to Health Regulations 2002 (COSHH), any work involving hazardous substances needs its own assessment referencing actual products used, with Safety Data Sheets available on site.


Make Competence Visible

Certificates in a filing cabinet score nothing. Auditors want to see a live competence matrix or training register that shows:

  • What training each operative holds
  • Expiry dates (IPAF, PASMA, asbestos awareness, first aid, etc.)
  • How gaps are identified and filled

Equally important: supervisors should be able to articulate the key risks on their own site without prompting. Worker competence is tested in conversation, not just on paper.


Show That Monitoring Actually Happens

A five-star system is a learning system. Auditors look for evidence that safety is checked regularly and that problems lead to change. Bring the following to any audit:

DocumentWhat it demonstrates
Site inspection recordsRegular, proactive monitoring
Near-miss and incident logsA reporting culture exists
Corrective action trackerFindings are closed out, not ignored
Toolbox talk recordsOngoing worker engagement

If your last inspection found nothing at all, an auditor will question whether it was conducted thoroughly — or at all.


Brief Your Team Before the Audit

An auditor who walks a site and asks a worker "what are the main hazards of your task today?" needs to get a sensible answer. Workers do not need to memorise anything; they just need to have read and discussed their RAMS. A signed briefing record helps, but genuine understanding is what scores marks.

On the day, make sure:

  • RAMS and COSHH assessments are accessible on site (not only in the office)
  • PPE is being worn correctly and is in good condition
  • Segregation, signage, and housekeeping are visible and maintained
  • Any work at height has been planned under the Work at Height Regulations 2005, with a hierarchy of controls applied (collective protection before personal fall protection)

Address the Previous Audit's Findings First

If you have been audited before, the single fastest way to drop marks is to have the same non-conformances outstanding. Close out every corrective action from the last cycle and bring evidence — photographs, updated documents, training records — that you have done so.


The Real Standard

The HSE's own expectation, set out in its guidance on the Plan-Do-Check-Act model, is a management system proportionate to the risks you create. A sole trader doing low-risk work and a principal contractor running a complex build will not produce the same volume of documentation — and should not. Auditors applying schemes like ISO 45001 understand this.

What they do not excuse at any scale is the absence of genuine control: work happening without a thought-through method, workers unaware of the hazards they face, or problems being recorded and then ignored.

Get those fundamentals right — specific assessments, demonstrated competence, active monitoring, and a team that understands the plan — and the five-star result follows from the substance, not the other way around.

Need the document itself?

RAMSReady generates RAMS, risk assessments, method statements, COSHH and fire risk assessments to the correct published standard — or check your existing one free.