A multi-site internal audit program should combine central process audits, risk-based project sampling and follow-up that tests effectiveness. It should reveal systemic patterns without assuming every site is identical.
Build the audit universe
Map corporate functions, regions, active projects, joint ventures and lifecycle stages. Record changes, critical risks, prior findings, incidents, worker concerns and legal-compliance evaluation results. Use that information to prioritize—not to exclude difficult locations indefinitely.
Combine three audit views
- System process: how governance, competence, procurement, data and improvement work centrally.
- Project implementation: whether the system is understood and used in live work.
- Critical-control trace: whether selected high-consequence risks are controlled from planning through verification.
Sample for evidence, not convenience
Select projects and records that test variation: new leadership, different work types, high subcontractor density, schedule change or repeat findings. Interview workers and supervisors, observe conditions and trace records to the actual work.
| Finding question | Weak approach | Stronger approach |
|---|---|---|
| What failed? | Missing form | Broken decision or control process |
| How broad is it? | One project only | Comparable projects and central process |
| Is it closed? | Action marked complete | Effectiveness verified in the field |
Aggregate without hiding context
Use common themes and definitions so leaders can identify repeat weaknesses, but preserve project facts. Report positive practices where they can be transferred. Do not dilute a significant finding by averaging it into an overall score.
Close the loop
Assign owners and dates based on risk, verify effectiveness and feed systemic findings into management review. The audit program should itself be reviewed for competence, independence, coverage and whether it is finding issues early enough to support improvement.
Frequently asked
Questions from construction leaders
Must every project be audited in the same way?
No. Use consistent audit principles and system criteria, then adapt scope and sampling to project risk, maturity, changes and prior results.
Can the project safety manager audit their own work?
Audit arrangements should preserve objectivity and impartiality. The organization should manage conflicts and competence in its audit program.
Primary sources
Sources and further reading
- ISO 19011 Guidelines for auditing management systemsInternational Organization for Standardization
- ISO 45001 Occupational health and safety management systemsInternational Organization for Standardization
Sources are provided for education and reference. Inclusion does not imply affiliation, sponsorship or endorsement. This article is not legal advice or a certification determination.
For currently certified U.S. developers and general contractors
