The Compliance Audit on a Seveso Site: Making the VBS Work
July 13, 2026
Running a VBS audit takes time. It pulls EHS staff, site managers, and sometimes operations people away from other work for days at a stretch. It's easy to see the audit and review element of your veiligheidsbeheersysteem as a compliance checkbox - something you do because Annex III element 7 requires it, not because it changes anything on the floor.
That view misses what the audit is actually doing. This isn't about what a VBS audit is or how to run one - that's covered elsewhere. This is about why the investment is worth defending when budgets get tight, and what it actually costs a Seveso site to let it slide.
Drift is the default state, not the exception
Safety barriers don't fail all at once. They degrade. A gas detector that was calibrated correctly eighteen months ago drifts out of tolerance in small increments nobody notices day to day. A permit-to-work step that used to be followed rigorously gets shortened under time pressure, then shortened again, until the version people actually use bears little resemblance to the procedure on file. An emergency isolation valve that's supposed to be tested quarterly gets tested when someone remembers.
None of this shows up in daily operations. Everything looks fine until the one day it doesn't. The audit is the mechanism that catches drift while it's still a paperwork problem, not an incident.
This is the core economic argument for auditing regularly rather than treating it as a periodic formality: the cost of finding a degraded barrier during a planned audit is a corrective action item. The cost of finding it during an incident investigation is measured very differently.
What you're actually buying with a clean audit trail
A site that audits its VBS consistently - not just when a deadline forces it - builds something that's hard to manufacture after the fact: a documented pattern of self-identified issues and closed corrective actions.
That pattern matters for reasons beyond the audit report itself:
- Inspector conversations start from a different place. A competent authority inspector who sees two years of audit findings you identified and fixed yourselves is dealing with a site that demonstrably self-polices. A site that only produces findings when the inspector finds them is dealing with a very different conversation, and often a longer one.
- Repeat findings are the tell regulators look for. The same nonconformity showing up audit after audit doesn't read as "known issue, low priority" - it reads as a management system that identifies problems but doesn't close them. That's a specific trigger for closer scrutiny under Seveso enforcement practice, because it suggests element 7 itself isn't functioning.
- Corrective action follow-through is the actual deliverable. The audit that finds a gap and never verifies it got fixed is barely better than not auditing at all. The value is in the loop closing, not the finding being written down.
The cost of not auditing, or auditing badly
The counterfactual is worth stating plainly, because "we didn't have time this quarter" rarely gets weighed against what it actually risks:
- Undetected barrier failures accumulate silently. Every audit cycle skipped is another interval where a degraded control could exist without anyone knowing - not because people are negligent, but because nothing else in daily operations surfaces it.
- Findings pile up instead of closing. Skip or shorten enough audit cycles and corrective actions stack faster than they get resolved. Eventually the backlog itself becomes the finding.
- Regulatory trust is slow to build and fast to lose. A site with a thin or inconsistent audit history has less credibility to draw on when something does go wrong, and enforcement responses tend to track that credibility.
- The audit becomes reactive instead of preventive. Sites that let audits lapse often end up running them right before an inspection, which turns a management tool into a scramble - exactly the dynamic the audit is supposed to prevent.
Auditing regularly is cheaper than the alternative
None of this requires treating every audit as high-drama risk management. Most of the value comes from consistency: running the audit and review element on a real cadence, tracking findings to closure, and treating repeat findings as a signal rather than background noise. The sites that get the most out of element 7 aren't the ones with the most sophisticated audit methodology - they're the ones that actually do it on schedule and follow through on what it finds.
The audit itself is a cost. Skipping it isn't free - it just defers the cost to a moment you don't get to choose.