Capptions
Back to blog

Audits Definition: What an Audit Is and What It Proves

September 18, 2026

The short definition

An audit is a structured, independent comparison between a defined set of criteria and the evidence of what actually happens.

That is the whole thing. Criteria, evidence, conclusion. Everything else, the opening meeting, the sampling, the findings register, the closing presentation, exists to make those three parts hold together.

The word carries three requirements that people tend to drop in daily use:

  • Criteria. A standard, a regulation, a procedure, a contract, a policy. Something written down in advance that the situation can be measured against.
  • Evidence. Records, observations, interviews, system data. Not impressions, and not what someone remembers about a decision from three years ago.
  • Independence. The person auditing is not the person who owns the work. Internal auditors can be colleagues, but not the colleagues whose own output is under review.

Take one of the three away and you still have something useful. You just do not have an audit.

Audit, inspection, assessment, review

These get used as synonyms, and in practice that costs people time, because they answer different questions.

Inspection

An inspection looks at a physical state at a moment in time. Is the guard in place, is the eyewash station in date, is the storage separated correctly. It answers: is this thing right now correct?

Audit

An audit looks at a system over a period. It samples the output of a process to judge whether the process works. It answers: can you rely on this, again, next month, when the person who normally does it is on holiday?

Assessment

An assessment measures maturity or risk against a model, usually without the pass or fail character of an audit. Gap analyses live here.

Management review

A management review is the decision moment: leadership looks at the results, including audit results, and commits time and resources. It is not an audit of itself, however often it gets treated as one.

The distinction matters most when an inspection finding gets treated as the whole story. A missing label is a fact. Why the labelling process did not catch it is the audit question, and that is the one that changes anything.

The types you will actually encounter

  • First party, or internal audits. You audit yourself. Required by most management system standards, and the most undervalued of the three.
  • Second party audits. A customer audits you, or you audit a supplier or contractor.
  • Third party audits. An accredited certification body audits you against a standard.
  • Regulatory oversight. Not an audit in the formal sense, though it feels like one from the inside. In the Netherlands, supervision on workplace safety and major hazard sites comes from bodies such as the Nederlandse Arbeidsinspectie and, regionally, DCMR. Their findings tend to reveal the same weak spots your internal audits should have found first.

For a broader map of the terms that surround all of this, our compliance definition and EHS definition articles cover the vocabulary that audits sit inside.

What separates a real audit from a checklist exercise

A four page checklist, two hours in the diary, one walk across a large installation. Everyone in this field has seen that version, and it produces a signature rather than knowledge.

The difference is not effort. It is traceability.

A real audit leaves a trail you can follow backwards: this conclusion rests on that evidence, which was sampled against this criterion, and it produced this action, which has an owner and a closing date. A checklist exercise leaves a tick, and a tick says almost nothing about the world.

Practical markers of an audit that holds up

  1. Criteria named per question. Not "housekeeping", but the clause, procedure or permit condition the question comes from.
  2. Scope written before the day. What is in, what is out, which installations, which period, which shifts.
  3. Evidence captured at the point of observation. Photo, meter reading, record reference, name of the person interviewed. Captured on the spot, not reconstructed on Friday afternoon.
  4. Findings graded, and graded honestly. Separate the serious from the administrative, because a list where everything is important is a list nobody can act on.
  5. Every finding has a corrective action with an owner. This is where most audit programmes quietly fail. The finding gets written, the action gets assigned to a team rather than a person, and nothing closes.
  6. Effectiveness checked later. Did the action actually change the thing it was supposed to change? Closing an action is not the same as fixing the cause.
  7. Trends read across audits. One finding is an incident. The same finding across four audits is a design problem in your system.

Step five and step seven are where audits stop being a cost and start being management information.

What the audit is really testing

Formally, an audit tests conformity against criteria. In practice, at least in the oversight we see on high hazard sites, what is being tested is whether your management system is a living thing or a filing cabinet.

Can you show that you planned against your risks, did what you wrote, measured whether it worked, and corrected course where it did not? That is not a documentation question. It is a governability question, and it is increasingly the one that gets asked.

Generic safety management software often handles the first half of that loop well and leaves the check and act half scattered across email, spreadsheets and separate tools. We wrote about where that breaks down for major hazard sites in why generic safety management software falls short for Seveso-III companies.

Where to start

If your audit programme feels like a chore, do not start by redesigning the programme. Start by pulling the findings from your last four audits and asking two questions: how many are still open, and how many are the same finding wearing different clothes.

The answer usually tells you what your audits are worth right now, and where the first fix belongs. For a worked example of how one audit type gets structured in practice, the HACCP checklist for internal audits walks through the logic on food safety.

Capptions builds inspection and audit software with custom forms, workflows and corrective action tracking, so the trail from finding to closed action stays in one place. Software does not make an organisation compliant and it does not carry the judgement. People do that. If you want to look at how the audit and corrective action side would work on your own processes, we are happy to walk through it with your own documents in front of us.