What Is a VBS Audit? The Seveso Safety System Audit Explained
July 8, 2026
If your site falls under the Seveso III Directive (BRZO in the Netherlands), you already know the veiligheidsbeheersysteem - VBS - isn't optional. What's less well understood is the audit that comes with it. A VBS audit isn't a walkthrough with a checklist. It's a structured check on whether the entire major-hazard prevention system you've built actually does what it's supposed to do.
This is different from a general EHS audit, and treating it as the same exercise is where a lot of sites lose time - either by under-preparing for what regulators expect, or by over-preparing for the wrong thing entirely.
What Is a VBS Audit?
A VBS audit is the periodic, systematic evaluation of your safety management system as required under Annex III of the Seveso III Directive. It asks one core question: is the VBS being implemented as designed, and is it effective at preventing major accidents?
That's a narrower and, at the same time, a more demanding question than "are we following good safety practice." A VBS audit isn't checking whether workers wear PPE or whether a fire extinguisher was inspected on schedule. It's checking whether the seven (or so) elements of your safety management system - organization and personnel, identification of major hazards, operational control, management of change, emergency planning, monitoring performance, and audit and review itself - are functioning as an integrated system, not as isolated procedures that exist on paper.
The audit and review requirement is one of the VBS elements mandated by Annex III itself. In other words, the directive requires that your safety management system include a mechanism for auditing the safety management system. It's a self-referential requirement by design: the VBS has to check itself, and a competent authority inspection checks whether that self-check is happening and is credible.
How a VBS Audit Differs From a General EHS Audit
A general EHS audit typically looks at conditions: is the workplace safe, are procedures being followed, is the site compliant with applicable regulations across health, safety, and environmental domains. It's usually scoped to operational reality on the ground.
A VBS audit looks at system effectiveness at the level of major-hazard prevention. The distinction matters in three ways:
- Scope. A VBS audit is bounded by the Annex III elements of the safety management system, not by general workplace conditions. It asks whether major-hazard controls, not everyday safety practices, are working.
- Standard. A VBS audit measures against what your own VBS documentation commits you to, and against what Annex III requires that documentation to cover. A general EHS audit measures against broader good-practice or regulatory baselines.
- Consequence. Findings from a VBS audit feed directly into your Safety Report and into how the competent authority assesses your site's major-accident prevention policy (MAPP). A general EHS audit's findings usually stay internal.
In practice, most upper-tier Seveso sites still need both. A VBS audit doesn't replace routine safety and environmental auditing - it sits on top of it, specifically evaluating whether the major-hazard prevention system is real and working.
What a VBS Audit Actually Examines
The core distinction from a documentation review is this: a VBS audit checks implementation and effectiveness, not just existence. Having a procedure on file is not the same as the procedure being followed, understood by the people who need to follow it, and actually reducing risk.
A VBS audit typically examines:
- Whether major-hazard identification is current. Are the hazard and risk assessments still accurate, or has the process, inventory, or site layout changed without the assessment being updated?
- Whether operational controls are followed in practice. Are the procedures for safe operation, maintenance, and modification of hazardous installations actually being used on the floor, or do they exist only in a binder?
- Whether management of change is functioning. When something changes - equipment, process, personnel, contractors - is there evidence the change went through a documented risk assessment before it happened, not after?
- Whether emergency arrangements are tested, not just written. Has the internal emergency plan been exercised, and did the exercise surface gaps that were then corrected?
- Whether performance monitoring produces real signals. Are near-misses, deviations, and incidents actually being captured, analyzed, and fed back into the system - or is monitoring a formality that generates reports nobody acts on?
- Whether previous audit findings were closed out. A recurring finding from a prior audit that's still open is one of the clearest signals to a regulator that the VBS isn't functioning as a management system.
The common thread: an auditor is looking for evidence of a live, functioning system - records, exercises, corrective actions, updated risk assessments - not just the existence of a policy document.
Who Conducts a VBS Audit
There are two distinct layers, and sites need to be clear on both.
Internal audit, required by the VBS itself. Annex III requires the safety management system to include a procedure for periodic, systematic assessment of the VBS's own effectiveness. This is carried out by the operator - often using internal EHS or compliance staff, sometimes supplemented by external specialists for independence or expertise the site doesn't have in-house. This internal audit function has to be built into the VBS itself; it can't be an occasional ad hoc exercise.
External inspection by the competent authority. Separately, and independently of your internal audit cycle, the designated regulator (in the Netherlands, this runs through the BRZO regional environmental services alongside the Inspectorate SZW and the safety regions) carries out its own inspections of upper-tier sites. These inspections assess whether the VBS is implemented and effective, using your Safety Report and MAPP as reference points - but the inspectors form their own judgment, including through site visits, interviews, and document sampling.
The internal audit and the external inspection aren't the same exercise, but they're closely linked: a credible internal audit trail is one of the things a regulator looks for as evidence the VBS is functioning, and weak internal audits tend to surface as findings in external inspections.
How Often a VBS Audit Needs to Happen
Annex III requires periodic, systematic audits - the directive itself doesn't fix an exact interval, and neither does most member-state implementing legislation. In practice, the audit and review element of the VBS should run on a defined cycle set out in your own safety management system documentation, commonly annual or aligned with your Safety Report review cycle.
Beyond the scheduled cycle, a VBS audit - or at least a targeted review of the relevant elements - should be triggered by:
- A significant change to the installation, process, or hazardous substances inventory
- A near-miss or incident that suggests a control didn't work as intended
- Findings from an external regulatory inspection that require follow-up verification
- A scheduled update to the Safety Report or MAPP
Competent authority inspections operate on their own schedule, generally risk-based and more frequent for upper-tier sites, and are independent of your internal audit calendar - but a site with a strong, current internal audit trail is in a materially better position going into one.
Why This Distinction Matters in Practice
Treating a VBS audit like a generic EHS audit is a common and costly mistake. Sites that run their audit and review element as a general safety walkthrough end up with findings that don't map to what Annex III - or the regulator - actually cares about: system effectiveness, not workplace conditions. The result is an audit that satisfies an internal checkbox but doesn't hold up under external inspection, and doesn't actually reduce major-accident risk, which is the point of the exercise.
Running the VBS audit and review element digitally - with structured records of what was checked, what was found, what corrective action was assigned, and whether it was closed out - is what turns the audit from a point-in-time document into the kind of evidence trail that both your own internal audit function and an external inspector can actually rely on. That traceability is, in the end, what "effective" means under Annex III: not that the audit happened, but that you can show it worked.