Capptions
Back to blog

Health and Safety Audits on Seveso Sites: Auditing the VBS

July 14, 2026

Running a health and safety audit at a Seveso or BRZO-classified site is a different exercise than auditing a standard warehouse or office. The scope has to account for major-hazard scenarios, the findings feed directly into your VBS, and the people in the room often include process safety engineers, not just an HSE generalist with a clipboard. Knowing what an audit is or why it matters doesn't tell you how to actually run one from a blank calendar to a signed-off report. This is that process, broken into the steps that make the difference between an audit that produces a filed PDF and one that produces real corrective action.

Step 1: Define the scope before you schedule anything

The most common reason a health and safety audit runs over time or under-delivers is that scope gets decided on the fly, usually during the opening meeting. Fix it in writing first.

Decide:

  • Which installations, processes, or areas are in scope. A full-site audit and a single-process audit (e.g., ammonia storage, a specific loading bay) require different team sizes and timelines. At a Seveso site, scope should map to your major-hazard scenarios, not just organizational boundaries.
  • Which standard or framework you're auditing against. This might be your internal VBS procedures, a specific Seveso III / BRZO 2015 obligation, ISO 45001, or a combination. Name the reference documents up front so findings can be tied to a specific clause or requirement, not a vague impression.
  • Audit type. A compliance-focused audit (are we following our own procedures and the law) is a different exercise than a process audit (is the safety management system actually effective) or a risk-based audit (are we controlling our highest-consequence scenarios). Most site audits blend elements of all three, but the primary lens should be explicit.
  • Time window. Set a start and end date for the audit itself, separate from the reporting deadline. Fieldwork that has no end date tends to expand until it hits a holiday.

Write this down in a one-page audit charter or terms of reference. It becomes the reference point when scope creep shows up mid-audit, which it will.

Step 2: Assemble the right team

Team composition is where generic H&S audit guidance breaks down for Seveso sites. A checklist walk-through can be done by one competent auditor. A meaningful audit of a major-hazard installation usually can't.

Consider:

  • Lead auditor. Owns the schedule, the scope, and the final report. Needs enough standing to push back on operations if fieldwork gets deprioritized.
  • Technical/process safety input. For scenarios involving specific hazardous substances or process conditions, someone who understands the process chemistry or engineering should review findings before they're finalized. A missing safety valve reads very differently to a process engineer than to a generalist auditor.
  • Independence. Whoever operates a process day-to-day shouldn't be the sole auditor of that process. This doesn't require an external party for every audit, but the auditor should not be auditing their own daily work.
  • Employee and contractor representation. Not as auditors, but as interview subjects. Field-level insight from operators and maintenance staff routinely surfaces gaps that document review misses entirely.
  • External auditor, when required. Some Seveso obligations, insurance requirements, or internal governance policies call for third-party involvement on a fixed cycle (e.g., every third audit). Confirm this before scheduling, not after the internal team has already done the work.

Assign roles and confirm availability before the audit start date. A half-staffed audit team is the second most common reason audits stall mid-fieldwork.

Step 3: Prepare - don't start fieldwork cold

Preparation is where most of the audit's efficiency is won or lost. Walking onto the floor without a documentation baseline means spending fieldwork time hunting for records instead of verifying them.

Before fieldwork starts:

  • Pull the reference documents. Procedures, permits, previous audit reports, incident logs, and the relevant sections of the VBS. Know what "compliant" is supposed to look like before you go check.
  • Review previous findings. Open corrective actions from the last audit are the first thing to verify. An audit that doesn't check whether last year's findings were actually closed isn't adding much.
  • Build the audit plan. A sequence of what gets checked, in what order, by whom. For multi-day audits, this prevents duplicated effort and missed areas.
  • Notify the site, but don't over-announce. Operations needs to know an audit is happening and roughly when, so the right people are available. It doesn't need to know the exact checklist in advance - that turns an audit into theater.
  • Prepare interview questions and inspection checklists tied to the scope defined in Step 1. Generic checklists produce generic findings; checklists built from your actual procedures and past incidents produce useful ones.

Step 4: Run the fieldwork

This is the part people picture when they hear "audit," but it's built entirely on the first three steps. Fieldwork typically combines three activities:

  • Document review. Verify that required records exist, are current, and match what's actually happening on site - permits to work, maintenance logs, training records, inspection certificates.
  • Physical inspection. Walk the area in scope. Check equipment condition, housekeeping, signage, emergency equipment access, and whether control measures described in procedures are actually in place. Photograph findings as you go; a written note saying "guard missing" is weaker evidence than a photo with a timestamp and location.
  • Interviews. Ask operators and supervisors to describe the procedure in their own words, not recite it. A gap between what's written and what people actually do is one of the most common - and most important - findings in any audit, and it only surfaces through conversation.

Log findings as you go rather than trying to reconstruct them from memory at the end of the day. Categorize each finding by severity as you record it (for example: critical/major/minor, or nonconformity vs. observation) so prioritization isn't a separate exercise later.

Step 5: Write findings that lead to action

A finding that says "housekeeping needs improvement" is not actionable. A finding needs four things to be usable by the people who have to fix it:

  1. What was observed. Specific, factual, no interpretation. "Secondary containment bund at Tank 4 had standing water and visible debris, observed 14:20."
  2. What it should be. The requirement or standard it's measured against - a procedure clause, a permit condition, a regulatory requirement.
  3. Why it matters. The risk if left uncorrected. This is what gets a finding prioritized correctly instead of filed and forgotten.
  4. Who owns the fix and by when. Every finding needs an assigned owner and a due date before the audit is considered closed, not just a note that something should happen "eventually."

Group findings by severity, and separate systemic issues (a procedure that's unclear or unrealistic) from one-off lapses (someone skipped a step this one time). They need different fixes - retraining someone doesn't help if the underlying procedure is the actual problem.

Step 6: Present results to management

Findings that stay inside an audit report rarely get resourced. The audit isn't finished until it's been presented to the people who control budget and priorities.

  • Bring a summary, not the full report, to the management meeting. A one-page overview of critical findings, trends versus previous audits, and proposed timelines gets read. A forty-page document gets skimmed at best.
  • Flag anything with regulatory exposure explicitly. If a finding relates to a Seveso obligation or a permit condition, say so directly rather than leaving management to infer the compliance risk from a technical description.
  • Ask for decisions, not just awareness. Each critical or major finding should leave the meeting with a confirmed owner, budget (if needed), and deadline - not just acknowledgment that the issue exists.
  • Set the follow-up review date in the same meeting. Don't let action-item tracking become a separate, easily-deprioritized task for later.

Step 7: Track corrective actions to closure

An audit that ends at the management presentation hasn't actually improved anything yet - it's only documented the gap. Closure means:

  • Verifying each corrective action was actually implemented, not just marked complete in a spreadsheet.
  • Re-inspecting physical fixes (a repaired guard, a relocated extinguisher) rather than accepting a photo or a verbal confirmation as sufficient.
  • Feeding unresolved or recurring findings into the scope of the next audit, so patterns across audit cycles become visible instead of resetting every time.

This is also the point where findings should flow back into the VBS itself - if an audit repeatedly finds the same gap, the safety management system's procedures, not just site behavior, may need revising.

Building this into a repeatable cycle

A one-off audit is useful. A repeatable process - same scope logic, same team structure, same finding format, same closure discipline every cycle - is what actually moves the needle on safety performance over time. It also produces something a single audit can't: a trend line. Once you're running audits on a consistent cycle with consistent categorization, you can see whether the same finding types keep recurring, whether closure times are improving, and where the next audit should focus before you even walk the floor.