Health and safety audits and management system review
Last reviewed: October 2026
Audits assess whether the University’s Health and Safety Management System (HSMS) meets applicable requirements and operates effectively. They identify deficiencies and improvements, support ISO 45001 certification and self-insurance approval, and check whether corrective actions have addressed the underlying problems.
Management reviews use audit findings and other performance information to decide whether the HSMS remains suitable, adequate and effective, and what changes or resources are needed.
Audit requirements
The Management system review and audit requirements explain responsibilities for management reviews, audits and corrective actions.
The requirements cover University workplaces and wholly owned subsidiaries within the scope of the HSMS, including relevant activities involving staff, students, contractors and other personnel.
Internal audit program
Risk and Assurance plans and coordinates internal health and safety audits with Health & Safety Services and the relevant faculties and divisions.
Audits assess applicable legislation, University requirements, ISO 45001 and relevant WorkSafe assurance criteria.
The schedule takes account of operational risks, earlier findings, significant changes, incidents and external assurance obligations. Each faculty, division, non-faculty department and wholly owned subsidiary within the HSMS scope must be audited at least once in a four-year cycle. Higher-risk areas and areas with significant findings may be audited more frequently.
Audited areas receive advance advice about the scope, criteria and arrangements.
- Internal audit information — staff login required
Preparing for an audit
The audit team will explain what your area needs to provide. This will generally include:
- a local contact to coordinate arrangements
- requested records and evidence of how requirements are implemented
- access to relevant workplaces, employees, health and safety representatives (HSRs) and other personnel
- participation in audit meetings and review of the report
- corrective actions and evidence that they work.
Provide only necessary personal or health information and protect it through appropriate access controls.
Internal audit findings and corrective actions
The Dean or Head of Division is responsible for ensuring findings are addressed.
| Requirement | Timeframe |
|---|---|
| Risk and Assurance provides the interim report to the Dean or Head of Division | Within four weeks after the closing meeting |
| The audited area submits a plan to Risk and Assurance for each non-conformance and “requires correction” finding | Within four weeks after receiving the interim report |
| The audited area implements the required corrective actions | Within three months after receiving the interim report, unless an alternative completion date is formally agreed |
Plans must identify the finding and its causes, the actions, responsible officers, priorities, completion dates and evidence needed to verify effectiveness. Consider whether the same problem exists elsewhere.
Put necessary risk controls in place promptly. Audit deadlines must not delay these controls or compliance with a statutory notice.
Extensions require agreement from the Director, Risk and Assurance, in consultation with the Director, Health & Safety. Record the reasons, remaining risks, interim controls and revised date.
Risk and Assurance verifies implementation and effectiveness before recording closure. Escalate overdue or ineffective actions to the responsible Dean or Head of Division and the Director, Health & Safety. Report findings and progress to the relevant divisional health and safety committee.
ISO 45001 certification audits
The University holds ISO 45001:2018 certification. The current certificate was issued on 1 October 2025 and expires on 30 September 2028.
Certification is maintained through yearly surveillance audits and recertification every three years. Recertification takes the place of that year’s surveillance audit.
Health & Safety Services arranges the program with the accredited certification body, which determines the scope and sampling. Participating areas must provide evidence and personnel, address findings and meet the certification body’s deadlines.
University ISO 45001 certificate (PDF)
WorkSafe self-insurance assurance program
The University has self-insurer approval under the Workplace Injury Rehabilitation and Compensation Act 2013.
WorkSafe Victoria’s assurance program assesses the HSMS and safety performance throughout the approval period. It includes assessments, quarterly Victorian safety performance reporting, an annual safety presentation and review, information updates, responsible persons declarations and corrective-action monitoring.
Health & Safety Services coordinates participation and advises relevant areas about evidence, access and reporting needs. Local management must support assessments and address findings affecting their area.
WorkSafe submissions and actions have their own deadlines. Follow the University’s assurance plan and WorkSafe self-insurer assurance guideline (PDF).
Management system review
Senior management reviews the HSMS annually at University and faculty or divisional levels. The Director, Health & Safety coordinates the University review; Deans and Heads of Division ensure local reviews occur.
Reviews consider:
- audit results, compliance evaluations and outstanding actions
- incidents, injuries, performance trends and risk-control effectiveness, including psychosocial risks
- changes to legislation, operations and relevant stakeholder needs
- progress against objectives, targets and previous review decisions
- employee and HSR feedback and participation
- resources and opportunities for improvement.
Record conclusions about the HSMS, decisions, resource needs, action owners and completion dates. Report outcomes through the relevant management and committee arrangements and communicate them to affected employees and HSRs. Committees provide consultation and recommendations; approvals follow University delegations.
Managers must also review and revise risk controls when legislation requires, without waiting for the annual management review.
University context and health and safety planning
Need assistance?
For help with audit preparation, findings or management reviews, contact your local Health and Safety Business Partner through the Health & Safety contacts page.