The Seveso VBS Compliance Audit Checklist
July 17, 2026
If you manage safety at a Seveso (BRZO) site, you already have a veiligheidsbeheersysteem on paper. The harder question is whether it holds up when someone actually looks for it: does the documentation exist, is it current, does it match what happens on the floor, and can you prove it with an evidence trail.
This checklist is built around the 7 Annex III elements of the Seveso III Directive. It's meant as a working self-assessment structure - something an internal auditor, EHS manager, or compliance lead can walk through site by site, not a substitute for your competent authority's formal inspection protocol or your own legally mandated audit procedure.
For each element, the checklist asks four things about every requirement:
- Exists - is there a document, procedure, or record for this?
- Current - is it up to date, version-controlled, and owned by someone?
- Matches practice - does what's written match what actually happens on site?
- Evidence trail - can you produce proof (sign-offs, logs, training records, dates) on request?
Use it as a running document. Mark each line, note the gap, assign an owner and a date.
1. Organization and Personnel
Covers roles, responsibilities, competence, and training for major-hazard control.
- Written major-accident prevention policy (MAPP / PBZO) exists, is signed by senior management, and is dated within the required review cycle
- Organizational chart identifies who is responsible for each VBS element, including deputies for key roles
- Job descriptions for safety-critical roles explicitly reference Seveso/BRZO responsibilities
- Training needs analysis exists for all roles with major-hazard responsibilities (operators, contractors, shift supervisors, emergency responders)
- Training records are current and traceable to specific individuals, dates, and competencies - not just "training completed" checkboxes
- Refresher training intervals are defined and tracked; overdue refreshers are visible, not buried
- Contractor and temporary worker competence is verified and documented before they're granted site access to hazardous areas
- Process for identifying and closing competence gaps (not just recording that training happened, but confirming it worked)
- Employee involvement/consultation mechanism on safety matters is documented (works council input, safety committee minutes, etc.)
- Evidence trail: signed training attendance sheets, competency assessments, org charts with revision dates, MAPP sign-off
2. Identification and Evaluation of Major Hazards
Covers hazard identification methodology, scenario coverage, and how risk assessments stay current.
- Hazard identification methodology is documented (HAZOP, What-If, bow-tie, or equivalent) and consistently applied across installations
- Major-accident scenarios are identified for every installation in scope, not just the ones covered in the original permit application
- Risk assessments reference actual current process conditions (temperatures, pressures, inventories, substance quantities) - not values copied from an outdated safety report
- Domino effect potential (interaction with neighboring installations or sites) has been assessed
- External hazards are considered (flooding, extreme weather, seismic activity, nearby infrastructure) where relevant to the site
- Risk assessments have a defined review trigger: fixed interval AND trigger-based (after incidents, near-misses, process changes, or new hazard information)
- Findings from hazard studies are traceable into the safety report / RIE (risico-inventarisatie en -evaluatie) rather than sitting in a separate, disconnected file
- Action items from hazard studies have owners, due dates, and a closure record - not just a list of open recommendations
- Evidence trail: HAZOP/risk assessment reports with dates and participant lists, updated scenario registers, closed action logs
3. Operational Control
Covers safe operating procedures, safety-critical equipment, and control of routine and abnormal operations.
- Safe operating procedures (SOPs) exist for all safety-critical activities, including startup, shutdown, and abnormal/emergency operation - not just steady-state running
- SOPs are version-controlled, with a visible owner and last-review date on the document itself
- Operators confirm (and can demonstrate) they're working from the current version of a procedure, not a printed copy from two revisions ago
- Safety-critical equipment (relief valves, interlocks, alarms, shutdown systems) has a defined inspection and testing schedule
- Inspection/testing records show the schedule is actually being met, with overdue items flagged and tracked to closure
- Permit-to-work system is documented and covers hot work, confined space entry, and other high-risk activities
- Permit-to-work records show sign-off at issue, during work, and on closeout - with names and timestamps, not just a form filed away
- Process safety-critical alarms and interlocks are identified as such, distinct from ordinary process alarms
- Bypassing or overriding of safety-critical systems requires documented authorization, and overrides are tracked and time-limited
- Evidence trail: current SOP register with revision history, equipment test/inspection logs, permit-to-work archive, override/bypass log
4. Management of Change
Covers how technical, organizational, and procedural changes are assessed before they're implemented.
- Management of Change (MoC) procedure exists and defines what counts as a "change" requiring review (not left to individual judgment)
- MoC applies to temporary changes as well as permanent ones - temporary bypasses and workarounds are a common gap
- MoC applies to organizational changes (staffing levels, contractor substitution, reporting lines) as well as technical/process changes
- Every change in the sample you pull has a documented risk assessment attached before implementation, not after
- Changes are signed off by someone with the authority and competence to approve them
- Affected procedures, drawings, and training materials are updated as part of the change closeout - check whether this actually happens or is a paper step
- MoC records are traceable: you can pick a random piece of equipment and reconstruct its change history
- Temporary changes have an expiry date and a process for either making them permanent (with full MoC) or reverting them
- Evidence trail: MoC request forms, risk assessment attachments, approval signatures, updated document register showing linked changes
5. Planning for Emergencies
Covers internal emergency planning, coordination with external responders, and testing.
- Internal emergency plan exists, is current, and covers the specific major-accident scenarios identified in Element 2 - not a generic template
- Emergency plan is coordinated with the external emergency plan held by the local authority/fire service, with no contradictions between the two
- Roles and responsibilities during an emergency are clearly assigned, including who has authority to declare an emergency and stand down
- Emergency contact information (internal and external) is current - test this by picking a random number and confirming it's correct
- Emergency equipment (alarms, shutdown systems, firefighting equipment, communication systems) is inventoried and inspection-dated
- Drills are conducted at a defined frequency covering different scenario types, not the same drill repeated
- Drill outcomes are documented, including what didn't work, and feeding back into plan updates
- Neighboring sites and relevant public authorities have received the information they're required to have (domino effect sites, public information duties)
- Evidence trail: current emergency plan with revision date, drill records with dates/scenarios/attendees, post-drill action logs, correspondence with external responders
6. Monitoring Performance
Covers how the site tracks whether the VBS is actually working, not just whether it exists.
- Safety performance indicators are defined, covering both lagging indicators (incidents, near-misses) and leading indicators (overdue inspections, training completion, open MoC actions)
- Incident and near-miss reporting procedure exists and is actually used - check reporting volume against what you'd expect for site size and activity
- Incidents and near-misses are investigated with documented root cause analysis, not just a description of what happened
- Corrective actions from investigations have owners, due dates, and verified closure - not just "action assigned"
- Trends across incidents/near-misses are reviewed periodically to catch recurring patterns a single investigation would miss
- Non-compliances found through internal monitoring (inspections, audits, observations) feed into the same corrective action system as incidents
- Performance data is reported to management at a defined frequency, not just compiled and filed
- Evidence trail: incident/near-miss log with investigation reports, KPI dashboard or report with historical trend, management review minutes referencing performance data
7. Audit and Review
Covers the VBS's own self-checking mechanism - including the audit this checklist supports.
- Internal audit program exists, with a defined schedule covering all 7 elements over a set cycle
- Audits are conducted by people with sufficient independence from the area being audited (not the process owner auditing their own area)
- Audit findings are documented with enough specificity to act on - not generic statements like "improve documentation"
- Audit findings are tracked to closure with owners and dates, and overdue findings are escalated, not left open indefinitely
- Previous audit findings are checked for recurrence - repeated findings across audit cycles indicate a systemic issue, not a one-off
- Management review of the VBS as a whole takes place at a defined interval, with senior management actually present and engaged, not just receiving a report
- Management review considers whether the VBS objectives and policy (from Element 1) are still fit for purpose, not just whether procedures were followed
- Outcomes of management review are documented and feed back into the MAPP, risk assessments, or procedures as appropriate
- Evidence trail: audit schedule and reports, closure records for findings, management review minutes with decisions and action owners
How to Use This
Run through each element with the people who actually do the work, not just the people who wrote the procedure - the gap between the two is usually where the real audit findings live. Where an item is marked "exists" but not "matches practice," that's higher priority than something missing entirely: a document nobody follows creates a false sense of assurance that's arguably worse than no document at all.
This structure mirrors what a competent authority inspection or a third-party VBS audit will look for, but it isn't a replacement for either. Treat it as the internal pass that should happen well before an external one does.