An organization’s approach to auditing says a lot about its safety maturity

Independent, systematic audits check that risk-control systems and management arrangements within the Safety Management System (SMS) are effective.  An audit is an independent, systematic check of risk-control safeguards and the SMS to ensure business objectives are met. An audit can be an internal audit (first party, conducted by the organization) or an external audit (second or third party, conducted on behalf of the organization).

Auditing is recognized as a critical part of an SMS. A proportionate, targeted audit program should be devised and implemented to provide the board of directors of the organization with adequate assurance about the ‘health’ of the SMS and the sustainability of safety performance.

Taking from the “Five Themes for Excellence in Safety Management Systems (SMS),” we can look at the organization’s approach to auditing through this lens of excellence and measure the maturity of the safety culture. To recap the progression, here are the five (5) levels:

  1. Ad-Hoc
  2. Managed
  3. Standardized
  4. Predictable
  5. Excellence

Ad-HocThere is little or no understanding of the value of auditing, which is seen as a chore.

  • There is little or no evidence of any audits being carried out.
  • Audits that are carried out are not planned or prioritized, and the findings are not acted upon.
  • The value of an audit is not understood, or audits are only completed to satisfy a requirement.
  • There is no auditing of collaborative/joint working.
  • There is no audit oversight to ensure corrective actions and recommendations are acted on.
  • There is little or no evidence that the organization can demonstrate that persons undertaking audits are competent.

 

ManagedThe value of audit is inconsistently understood, and challenges are often taken personally, resulting in conflict between auditors and auditees.

  • There is some auditing, but there is no coordinated audit plan.
  • The audit plan is not proportionate to the organization’s risk profile or implemented consistently.
  • Some departments/processes are audited, but not all.
  • The role of audit is not understood consistently in the organization.
  • The audit is perceived defensively and negatively.
  • Some findings are acted upon dependent on the individuals involved.
  • There are some competent auditors, but no system is in place to ensure that they carry out the audits.
  • Some collaborative activities are subject to audit, but there is no consistency.

 

StandardizedThe value of audit is understood at all levels in the organization, and there is a culture in which the challenges and recommendations are positive influences.

  • There is evidence of a coordinated, effective, and up-to-date audit program.
  • The organization can show that competent auditors complete audits.
  • An audit is understood as an essential part of the risk management process, and senior staff and executives readily engage with the audit program.
  • Audit results are accepted, acted upon, and tracked through to completion.
  • Audit programs are adequately resourced.
  • Collaborative activities are included in the audit program.

 

PredictableAuditing is understood to be an essential part of the development of processes and procedures contributing to the improvement in risk management and the SMS.

  • Post-change audits are carried out as part of the verification of the change process.
  • The audit program includes consideration of new processes and procedures.
  • Audit of processes that have been changed is understood to be an essential part of the change process.
  • All parties use an audit in collaborative activities, Individually and jointly.
  • Audit findings are recognized as important indicators of successful changes.
  • Auditors keep their competencies current through practice and Continuing Educational Unit (CEU) activities.

 

ExcellenceThe organization strives to identify best practices in business risk management to inform the audit program.

  • Audit actions identify ways to continuously improve risk management in the organization by referring to examples of excellence in other sectors.
  • Identification of innovative solutions that improve risk management is encouraged in audit reporting and actions.
  • Audit and completion of actions arising are understood to be a driver of CONTINUOUS IMPROVEMENT.
  • Auditors are competent in making practical challenges and are encouraged to identify and deliver findings that drive continuous improvement.
  • Peer-to-peer reviews with other comparable organizations are routinely included in the audit approach.
  • The audit process provides a high level of assurance across the organization.

 

 

Source: RM3, 2019 – The Risk Management Maturity Model (UK’s HSE)

Scroll to Top