Health and safety audits and management system review

Health and safety audits provide an independent and systematic assessment of the University’s Health and Safety Management System (HSMS).

Audits help the University to:

  • assess compliance with legal and other requirements
  • confirm that the HSMS is effectively implemented
  • maintain ISO 45001 certification and self-insurance approval
  • identify non-conformances and opportunities for improvement
  • monitor whether corrective actions have been implemented and are effective.

This page explains the University’s internal, ISO 45001 and WorkSafe audit programs.

Last reviewed: August 2026

Audit requirements

The University’s requirements for management system reviews and internal and external audits are set out in:

Read the Health & Safety: Management System Review and Audit Requirements (PDF)

These requirements apply to staff, students, contractors and other people at workplaces under the University’s management or control.

Internal audit program

Risk and Assurance coordinates the University’s internal health and safety audit program in consultation with Health & Safety Services and relevant faculties and divisions.

The annual audit schedule considers:

  • previous audit results
  • the level of health and safety risk associated with an area’s activities and operations
  • the need to prepare for external audits
  • the University’s self-insurance obligations.

Each faculty, division, non-faculty department and wholly owned subsidiary within the scope of the OHSMS must be audited at least once during each four-year internal audit cycle.

Areas selected for audit will be advised of the proposed timing, scope and audit criteria before the audit begins.

View internal health and safety audit information (staff login required)

Download the Health & Safety: Internal Audit Methodology (Word)

If your area is selected for an internal audit

The audit team will contact the relevant area to confirm the audit arrangements.

The audited area will generally need to:

  1. nominate an appropriate contact person
  2. review the audit scope and criteria
  3. provide requested records and other evidence
  4. ensure relevant personnel are available
  5. participate in the opening and closing meetings
  6. review the interim audit report
  7. develop and implement corrective actions for applicable findings
  8. report audit outcomes through the relevant health and safety committee.

The internal audit methodology provides further information about the audit process, meetings, evidence, findings and reporting arrangements.

Internal audit findings and corrective actions

Risk and Assurance must provide an interim internal audit report to the relevant Dean or Head of Division within four weeks of the audit closing meeting.

Within four weeks of receiving the interim report, the Dean or Head of Division must ensure that a corrective action plan is provided for each:

  • non-conformance
  • “requires correction” finding.

Each corrective action plan must identify:

  • the relevant audit criterion
  • the audit result and finding
  • the proposed corrective action
  • the action priority and completion date
  • the responsible officer.

Required corrective actions must be completed within three months of receiving the interim report, unless an alternative timeframe has been formally agreed.

Audit reports and progress against corrective actions must be tabled at the relevant budget division health and safety committee.

ISO 45001 external audit program

The University’s HSMS is certified to ISO 45001:2018.

External audits confirm whether the HSMS continues to meet the certification standard. The certification cycle generally includes:

  • annual surveillance audits
  • a recertification audit every three years, replacing the surveillance audit for that year.

Health and Safety Services coordinates the external audit program. The external auditor determines the areas and activities to be sampled, and affected faculties and divisions are advised before the audit.

The University’s current ISO 45001 certification was issued on 1 October 2025 and is valid until 30 September 2028.

View the University’s ISO 45001 Certificate of Approval (PDF)

WorkSafe self-insurance audits

The University is an approved self-insurer under the Workplace Injury Rehabilitation and Compensation Act 2013.

As part of the University’s self-insurance arrangements, WorkSafe Victoria may assess the University’s health and safety management system against ISO 45001 and other applicable approval requirements.

Health and Safety Services coordinates the health and safety components of the WorkSafe audit program and advises affected areas about the audit scope, schedule and evidence requirements.

Management system review

Audits are one source of information used to review and continually improve the HSMS.

Management reviews also consider:

  • incident and injury data
  • changes to legislation
  • organisational or operational changes
  • progress against health and safety objectives and key performance indicators
  • the relevance, practicality and readability of OHSMS documentation.

Read the University context and health and safety planning information

Need assistance?

For support preparing for an audit or responding to an audit finding, contact your local Health and Safety Business Partner.

Find Health & Safety contacts