What Is an Audit? A Practical Guide for Seveso Sites
July 9, 2026
If you work in EHS or compliance at a Seveso-classified site, "audit" is not an abstract word - it's a recurring event on your calendar, and often a source of low-grade dread. But the term gets used loosely, and it's worth being precise about what an audit actually is, because the precision changes how you prepare for one.
This article breaks down what an audit is, why it matters, the different types you'll encounter, how the process actually runs, who's involved, and how to prepare - all grounded in the context that matters most if you're reading this: audits of the veiligheidsbeheersysteem (VBS), the safety management system that Seveso III requires every upper- and lower-tier site to operate and document.
Defining an Audit
An audit is a systematic, independent examination of a set of records, controls, and practices against a defined standard - carried out to determine whether what's actually happening on site matches what's supposed to be happening on paper.
For a Seveso site, that standard is your VBS: the documented system of policies, procedures, and controls you've committed to in order to prevent major accidents and limit their consequences if they occur. A VBS audit isn't checking your bookkeeping. It's checking whether your major-hazard controls exist, work, are followed, and are documented well enough to prove all three.
That last part matters more than people expect. A control that exists but isn't documented might as well not exist, from an auditor's perspective - and often, in practice, on the day it's actually needed. An audit is as much a test of your evidence trail as it is a test of your safety measures.
Why Audits Matter for Seveso Sites
Audits matter for the obvious reason first: they're a legal requirement. Under Seveso III, upper-tier establishments must have an internal audit system as part of their VBS, with a defined audit cycle (in the Netherlands, typically annual internal reviews alongside longer-cycle inspections by the Nederlandse Arbeidsinspectie and DCMR or the relevant competent authority). Skipping this isn't a paperwork gap - it's non-compliance with the directive itself.
Beyond the legal floor, audits do three things that matter operationally:
They catch drift before it becomes an incident. Safety management systems degrade quietly. A permit-to-work procedure that was airtight at implementation slowly accumulates workarounds. A maintenance interval that made sense five years ago no longer matches current equipment condition. Audits are the mechanism that catches this drift while it's still a finding, not an incident investigation.
They create a credible record for the regulator. When DCMR or the Arbeidsinspectie inspects your site, they're not starting from zero - they're checking whether your own internal audit system is functioning and whether it's finding (and fixing) the same things they would find. A site with a weak or inconsistent internal audit trail draws more scrutiny, not less.
They protect the people who have to trust the paperwork. Shift operators, contractors, and emergency responders make decisions based on the assumption that documented procedures reflect reality - that the isolation plan is current, the evacuation route is correct, the safety-critical equipment was actually inspected on schedule. An audit is what keeps that assumption true.
Types of Audits You'll Encounter
Not all audits at a Seveso site are the same animal, and conflating them causes confusion about scope and stakes.
Internal VBS audits. Conducted by your own organization (often EHS staff independent of the audited department, or a corporate audit function for multi-site operators) against your own VBS elements - policy, organization and personnel, hazard identification and risk assessment, operational control, management of change, emergency planning, performance monitoring, and audit/review itself. This is the recurring, self-initiated audit that Seveso III requires as part of a functioning safety management system.
Regulatory inspections. Conducted by the competent authority - in the Netherlands, a joint inspection typically involving the Nederlandse Arbeidsinspectie, the regional environmental service (such as DCMR for the Rijnmond area), and the fire service, coordinated under the BRZO+ program. These aren't audits you schedule; they're compliance inspections against the Seveso III / BRZO 2015 framework, and they can include document review, site walks, and interviews, similar in mechanics to an internal audit but with regulatory consequences attached to the findings.
Compliance audits. Narrower than a full VBS audit, these check adherence to a specific regulation, permit condition, or standard - for example, a targeted audit of your PGS-15 storage compliance or a specific permit obligation, rather than the whole safety management system.
Technical or operational audits. These assess whether specific technical systems (a safety instrumented system, a relief and flare system, tank inspection regimes under API 653 or equivalent) meet their design and maintenance basis. They often feed into the broader VBS audit as supporting evidence.
Each type has a different scope and a different audience, but they share the same underlying question: does the evidence support the claim that the site is controlling its major-hazard risks the way it says it is?
The VBS Audit Process
The structure of a VBS audit follows the same three phases as any formal audit - planning, fieldwork, reporting - but each phase has a specific shape for major-hazard sites.
Planning. The audit team defines scope against your VBS elements (or the specific process safety topic under review), pulls the relevant documentation set - the safety report, the VBS procedures, prior audit findings and their close-out status, incident and near-miss records, maintenance and inspection logs - and builds an audit plan that allocates time across document review, site walks, and interviews. For an internal audit this is usually weeks; for a regulatory inspection you'll typically get advance notice but limited influence over scope.
Fieldwork. This is where the audit actually happens. Auditors review documentation against what's supposed to exist (is the risk assessment current, does the maintenance schedule match what was actually performed, is the emergency response plan consistent with the current site layout), walk the site to observe whether physical conditions match the documentation (barriers in place, signage current, permit-to-work in active use, equipment condition consistent with its inspection record), and interview personnel - operators, maintenance staff, shift supervisors - to check whether procedures are understood and followed in practice, not just filed.
Reporting. Findings are documented, typically categorized by severity (a missing signature on a permit is not the same finding as an expired pressure-relief inspection), and each finding is assigned an owner and a closure deadline. The report becomes part of your VBS's own record - which means next year's audit will check whether this year's findings actually got closed, not just logged.
A functioning VBS audit process also does a few things beyond producing a report: it surfaces where documentation and practice have quietly diverged, it gives you an evidence base for management review, and it builds the audit trail that makes a regulatory inspection go smoothly instead of becoming an adversarial exercise.
The Role of the Auditor
Whether it's your internal EHS team or an external inspector, the auditor's job is to form an evidence-based judgment on whether your major-hazard controls are in place and functioning - not to run your safety program for you.
To do that, auditors gather evidence through document review, direct observation, and interviews, and they're expected to maintain professional skepticism throughout - treating a procedure that "should" be followed as unverified until they've seen evidence it actually is. A significant part of the job is checking your management of change process specifically, because most major-accident precursors trace back to a change (equipment, procedure, personnel, or organizational) that wasn't properly assessed before it was implemented.
What auditors do:
- Review VBS documentation against the actual procedures and controls in place on site
- Walk the site and observe whether physical conditions and practices match the documentation
- Interview operators, maintenance staff, and supervisors about how procedures actually work day to day
- Test whether specific controls (permit-to-work, isolation procedures, inspection regimes) are followed consistently, not just documented
- Assess whether prior audit findings were genuinely closed out or just marked closed
What auditors don't do:
- Redesign your safety management system for you - findings identify gaps, they don't prescribe the fix
- Check every single record or inspect every piece of equipment - audits use sampling, not exhaustive review
- Certify that no incident will ever occur - an audit tests whether controls are in place and functioning at the time of the audit, not future performance
- Take responsibility for closing findings - that stays with site management
What auditors can't do:
- Be on site continuously. An audit is a point-in-time (or period-based) sample, which is exactly why the gap between audits is where drift accumulates and why internal monitoring between audit cycles matters as much as the audit itself.
- Guarantee zero deviations exist. The objective is a defensible opinion on whether the VBS is functioning as intended, not a promise that every procedure is followed perfectly at every hour of every shift.
How to Prepare for a VBS Audit
Preparation for a VBS audit is largely about not having to scramble when the audit team walks in.
Start with scope. Know which VBS elements or process safety topics are in scope for this specific audit - internal audits and regulatory inspections don't always cover everything at once, and knowing the scope tells you where to focus your prep time.
Then get your documentation trail in order: current risk assessments, up-to-date procedures (not the version from three revisions ago sitting in someone's inbox), maintenance and inspection records that actually match what was performed, management-of-change records for anything altered since the last audit, and - critically - the closure evidence for every finding from the previous audit. An auditor's first move is often checking whether last time's findings actually got fixed.
Walk the site yourself before the auditors do. Check that what's documented matches what's physically true: that barriers described in the risk assessment are actually installed, that the emergency plan matches current site layout, that safety-critical equipment shows the inspection tags and maintenance history the records claim.
Brief the people who'll be interviewed. Not to coach answers, but so operators and supervisors know an audit is happening, understand it's not a personal performance review, and can speak to procedures they actually use rather than freezing on a question about a document they've never opened.
This is exactly where inspection-readiness software like Capptions' Seveso Control earns its keep - keeping the VBS documentation trail current as changes happen, rather than reconstructing it under time pressure in the two weeks before an audit. A digital, continuously updated record of inspections, findings, and closures means "show me the evidence this was fixed" has an immediate answer instead of a document hunt.
Understanding Audit Outcomes
A VBS audit produces findings, and findings typically fall into a small number of categories: conformities (the control is in place and working), minor non-conformities (a gap that doesn't represent an immediate major-accident risk but needs correcting - a missing signature, an overdue but non-critical inspection), major non-conformities (a control that's absent or not functioning where it matters for major-hazard prevention), and observations or opportunities for improvement (not a failure, but a place the system could be stronger).
For regulatory inspections under BRZO+, outcomes carry more formal weight - findings can result in required corrective actions with deadlines, and in cases of serious or repeated non-conformity, enforcement measures up to and including operational restrictions. This is the sharp edge that distinguishes a Seveso VBS audit from, say, an internal financial audit: the findings connect directly to major-accident hazard, not just financial or reputational risk.
Either way, the outcome is only as useful as what happens next. A finding that gets logged and forgotten is worse than not auditing at all, because it creates a paper trail showing the site knew about a gap and didn't close it.
Making Audits Part of How the Site Runs
The sites that handle audits well aren't the ones that panic-prepare every cycle - they're the ones where the VBS audit is a checkpoint on an already-current system, not an event that triggers a documentation scramble. That means treating management of change, inspection records, and finding closure as continuous work, not audit-season work.
That's the real value of an audit, VBS or otherwise: it's not a hoop to jump through, it's the mechanism that keeps the gap between what you've documented and what's actually happening on site from growing unnoticed. Get that right, and the audit - internal or regulatory - becomes a confirmation of what you already know about your site, not a discovery process.