Direct answer

A multi-site internal audit program should combine central process audits, risk-based project sampling and follow-up that tests effectiveness. It should reveal systemic patterns without assuming every site is identical.

Build the audit universe

Map corporate functions, regions, active projects, joint ventures and lifecycle stages. Record changes, critical risks, prior findings, incidents, worker concerns and legal-compliance evaluation results. Use that information to prioritize—not to exclude difficult locations indefinitely.

Combine three audit views

  1. System process: how governance, competence, procurement, data and improvement work centrally.
  2. Project implementation: whether the system is understood and used in live work.
  3. Critical-control trace: whether selected high-consequence risks are controlled from planning through verification.

Sample for evidence, not convenience

Select projects and records that test variation: new leadership, different work types, high subcontractor density, schedule change or repeat findings. Interview workers and supervisors, observe conditions and trace records to the actual work.

Finding question Weak approach Stronger approach
What failed? Missing form Broken decision or control process
How broad is it? One project only Comparable projects and central process
Is it closed? Action marked complete Effectiveness verified in the field

Aggregate without hiding context

Use common themes and definitions so leaders can identify repeat weaknesses, but preserve project facts. Report positive practices where they can be transferred. Do not dilute a significant finding by averaging it into an overall score.

Close the loop

Assign owners and dates based on risk, verify effectiveness and feed systemic findings into management review. The audit program should itself be reviewed for competence, independence, coverage and whether it is finding issues early enough to support improvement.

Frequently asked

Questions from construction leaders

Must every project be audited in the same way?

No. Use consistent audit principles and system criteria, then adapt scope and sampling to project risk, maturity, changes and prior results.

Can the project safety manager audit their own work?

Audit arrangements should preserve objectivity and impartiality. The organization should manage conflicts and competence in its audit program.

Primary sources

Sources and further reading

Sources are provided for education and reference. Inclusion does not imply affiliation, sponsorship or endorsement. This article is not legal advice or a certification determination.

For currently certified U.S. developers and general contractors

Turn your ISO 45001 foundation into visible, trusted evidence.