What this is
What is a fatal risk protocol?
What is a fatal risk protocol?
A mandatory standard covering one activity capable of killing someone — working at height, energy isolation, confined space, mobile equipment, lifting. It states minimum requirements, not guidance, and deviation needs formal authorisation rather than judgement at the workface.
What is a fatal risk protocol audit?
A conformance audit of one protocol at one site, run to a defined requirement list and scored on conformance and maturity. It differs from a general safety audit in scope and depth: one protocol, all of it, including how it is applied in the field. Findings are graded and fed to corrective action.
What is the difference between conformance and maturity?
Conformance asks whether the requirement is met now — yes, partly or no. Maturity asks how deeply it is embedded, from absent through ad hoc, defined, implemented and measured to embedded and improving. A protocol can conform on paper at maturity one, which predicts it will stop once attention moves.
Scope
When is a fatal risk protocol audit required?
This audit tests one protocol at one site against a requirement list. It is a periodic, planned, independent assessment — not a spot check, not an investigation, not a review of how a control performed over time. Used in place of a neighbouring template it satisfies the schedule and answers nothing.
Use this template when
- The annual cycle falls due for a named protocol such as working at height, energy isolation or confined space
- A serious potential incident or repeated finding suggests the gap is systemic rather than local to one crew
- A new site, acquisition or major contractor comes into scope and the protocol has never been tested there
- The protocol has been revised and you need to know whether the revision reached the workface
- A customer, insurer or assurance function requires independent evidence of implementation
Do not use it for
- Critical Control Verification, which tests one control against its performance standard in the field and is narrower than a whole-protocol audit.
- Barrier Health Check, which walks the barriers named on a bowtie for one unwanted event rather than the requirements of a written protocol.
- Critical Control Performance Review, which looks backwards across a period at verification rates and failures instead of conformance now.
- Control Failure Report, which is raised when a control has failed in service and needs investigation rather than scheduled assessment.
- Critical Control Owner Review, which examines whether named owners discharge their accountabilities and is about people, not requirements.
Compliance mapping
Which ICMM requirements does this satisfy?
Two families of obligation sit behind this template: the auditing method ISO 19011 sets out, and the duty to control fatal risks from the management-system standard.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 19011:2018, clause 4 | Audits follow the principles of independence and an evidence-based approach, with auditors free of bias and conflict of interest | Header |
| ISO 19011:2018, clause 6.4 | Audit activities collect and verify information against defined criteria, evidence recorded as obtained | Protocol requirements |
| ISO 19011:2018, clause 6.5 | Audit conclusions are prepared and the report given to those accountable for acting on it | Result |
| ISO 45001:2018, 9.2.2 | An internal audit programme is planned and maintained, covering frequency, methods and reporting | Result |
| ISO 45001:2018, 7.2 | Workers are competent on the basis of education, training or experience relevant to the hazards they face | Field verification |
| ISO 45001:2018, 10.2 | Nonconformities are recorded, corrective action taken with ownership, and effectiveness reviewed | Result |
What it does not cover
- A protocol document review, which confirms the standard is written and current and says nothing about whether anyone at the workface follows it.
- A training completion report, which shows attendance rather than understanding, and reads one hundred per cent on protocols workers cannot explain.
- A permit or certificate sample, which tests the paperwork the protocol produces rather than the requirements it imposes.
- A management self-assessment, which asks the area accountable for conformance to declare it, and returns partial at worst.
- A corporate assurance summary, which aggregates site scores into a portfolio position and cannot show which requirement failed.
Global
Fatal Risk Protocol Audit requirements by country
Fatal risk protocols map onto very different instruments depending on where the site sits, and the evidence a regulator expects varies with them. These three cover most use.
OSHA 29 CFR 1910.147(c)(6) — periodic inspection of energy control procedures
Requires at least annual inspection of the energy control procedure by an authorised employee other than the one using it, certified with machine, date and inspector
For energy isolation this is the nearest thing to a statutory version of this template. Independence is not preference: the other than the one using it wording makes it a compliance requirement, and the certification content maps onto Header and Result.
Work Health and Safety Act 2011 (model), sections 19 and 27
A primary duty of care on the person conducting a business, and a due-diligence duty on officers to verify that resources and processes for controlling risk are in place and used
Officer due diligence is where this audit earns its keep. A signed, independent, graded audit with field verification is what an officer relies on to show verification rather than assumption — the distinction section 27 draws.
Mine Health and Safety Act 29 of 1996, section 11
Requires the employer to identify hazards, assess and record the associated risks, and periodically review the effectiveness of measures taken
Periodic review of effectiveness is not satisfied by re-issuing the risk assessment. An annual audit scoring maturity and recording field observations answers it directly, and the ICMM lineage is recognised by inspectors.
How to complete it
How to complete a fatal risk protocol audit, step by step
The scoring mechanics are straightforward. Four judgements decide whether the record would survive being challenged.
Auditor Independent Of Area is scored pass, partial, fail rather than yes or no, because independence has degrees. A corporate auditor is a pass; a supervisor from the next shift is partial; the area's own safety adviser is a fail however rigorous. A partial with a good audit behind it is defensible; a false pass poisons the record.
Requirement Type must be set from the protocol, not from how the audit is going. Reclassifying a failed mandatory item as good practice to protect the score is the commonest manipulation here, and the easiest to spot on review. Agree the mandatory list with the protocol owner and freeze it.
The distinction that matters is between three, implemented, and four, measured. Implemented means it happens; measured means someone would know if it stopped. Most protocols sit at three and are recorded as four because a report exists somewhere. If you cannot name the measure, its frequency and who reads it, the level is three.
Workers Interviewed, Workers Could Explain The Protocol and Field Observations Made need targets set beforehand, or they become whatever the day allowed. Practice Matches Documentation answered No should hold Result Band down whatever the requirement list scored — conforming on paper and not in practice is failing.
What auditors find
Most common fatal risk protocol audit findings
These findings recur when protocol audits are themselves reviewed, with the clause behind each and the change that stops it repeating.
| Finding | Clause | What fixes it |
|---|---|---|
| Audit completed by the area's own safety adviser, Auditor Independent Of Area recorded as Pass | ISO 19011:2018, clause 4 | Resolve the auditor against the area's reporting line and block a Pass where they fall inside it; require a different user for the second signature. |
| Score Percent above the pass threshold while a mandatory requirement does not conform | ISO 45001:2018, 9.2.2 | Force Result Band to Fail whenever a Mandatory requirement scores Does not conform, so weighting cannot be outvoted by good-practice passes. |
| Field verification numbers left at zero or one, the audit closed on document review | ICMM Critical Control Management Good Practice Guide (2015) | Set minimums for Workers Interviewed and Field Observations Made proportionate to headcount, and prevent submission below them. |
| Findings written into Finding Detail with no Finding ID or grade, so nothing reaches corrective action | ISO 45001:2018, 10.2 | Make Finding ID and Finding Grade mandatory once Conformance is anything but Conforms, and reject Action Required No where a Major grade exists. |
| Every requirement scored at maturity level three, giving an average that never moves | ISO 19011:2018, clause 6.4 | Require an evidence file for any level of four or five, and review Average Maturity Level year on year for implausible flatness. |
| Completeness Percent well below one hundred, a high Score Percent reported as a clean audit | ISO 19011:2018, clause 6.5 | Report Score Percent and Completeness Percent together in every summary, and suppress the band where completeness falls under the agreed floor. |
Case in point
Case in point: the height protocol that scored ninety-four
A distribution business audited its working at height protocol across eleven sites. Ten scored above ninety. The requirement list came from the protocol's own contents page — policy exists, training register maintained, equipment inspected, permits issued — each with a document behind it, each marked Conforms. Field verification was a walk round with the site manager. Average maturity sat at 3.6 and had not moved in three years.
A fall from a mezzanine edge protection gap prompted a re-audit with two changes: an auditor from outside the region, and a requirement list written from outcomes rather than headings. Conformance dropped to sixty-one per cent. Anchor points had no inspection records; the rescue plan named a fire service response time nobody had confirmed; of nine workers interviewed, three could explain the protocol. Nothing in the document had changed — only what the audit looked at, and who looked.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
4 sections
- Reference
- SAF-081
- Archetype
- Audit
- Record ID
- AUD-2026-000
- Scoring
- Weighted percent
- Direction
- High is good
- Singleton
- No
- Basis
- ICMM, ISO 19011
- Links
- Links Critical Controls; feeds Finding
- Tags
- Critical risk, Audit
- Sections
- 4
- Fields
- 42
- Follow up fields
- 7
- Repeating sections
- 1
- Links out
- 4
Header
10 fieldsAudit ID*
Auto sequence. Format AUD-2026-00000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Protocol Audited*
Auditor Independent Of Area*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Clause Reference
Clause ID
Format CLS-0000.
Links to FDN-009 Clause ID
Protocol requirements
Repeats10 fieldsRequirement*
Requirement Type*
Mandatory or good practice. Mandatory failures carry more weight.
Evidence Sighted*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Evidence Type
Evidence File
Conformance*
- Conforms3 pts
- Partially conforms1 pt
- Does not conform0 pts
Maturity Level*
Zero is absent, five is embedded and improving.
- 0 Absent0 pts
- 1 Ad hoc1 pt
- 2 Defined2 pts
- 3 Implemented3 pts
- 4 Measured4 pts
- 5 Embedded and improving5 pts
Finding Detail
Finding ID
Links to FDN-015 Finding ID
Finding Grade
- Critical0 pts
- Major1 pt
- Minor2 pts
- Observation3 pts
Field verification
6 fieldsDocuments Are Not Enough
Half this audit happens in the workplace. Watch the protocol being applied and talk to the people applying it.
Workers Interviewed*
Workers Could Explain The Protocol*
Field Observations Made*
Practice Matches Documentation*
- Yes3 pts
- Partly1 pt
- No0 pts
Gap Detail
Result
16 fieldsItems Assessed*
Excludes anything marked N/A.
Items Failed*
Score Percent*
Calculated on submission. High is good. N/A items leave the denominator.
Result Band*
- Pass3 pts
- Caution1 pt
- Fail0 pts
Completeness Percent*
How much of the template was actually answered. A high score on a half completed form is not a high score.
Average Maturity Level*
Major Findings*
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Next Audit Due*
Auditor*
Signature*
Area Manager*
Second Signature*
SAF-081 · record IDs look like AUD-2026-000 · Links Critical Controls; feeds Finding
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
Protocol audits fail on logistics more than method: the schedule slips, the independent auditor is unavailable, findings land in a spreadsheet, the next cycle starts blank.
Holds the audit programme per protocol and site, carries last year's requirement list and findings into the new audit, and blocks closure where a mandatory nonconformity has no graded finding.
Supplies the competence record behind the protocol so the audit compares who is signed off against who could actually explain it, turning that gap into a finding rather than an impression.
Maps each requirement to the obligation behind it — lockout periodic inspection, officer due diligence, periodic review of effectiveness — so evidence lines up with what a regulator asks to see.

Compares the same protocol across sites, surfaces requirements failing everywhere as a design problem rather than eleven local findings, and drafts actions for approval.
This template lives in KnowSafe — safety and compliance. Incidents, hazards, permits, inspections and the critical controls behind them.
Meet KnowSafe→Glossary
Fatal Risk Protocol Audit definitions and key terms
- Fatal risk protocol
- A mandatory minimum standard for one activity capable of causing a fatality, written so deviation needs authorisation rather than judgement. Also called a life-saving rule.
- Conformance
- The degree to which a requirement is currently met — conforms, partially conforms or does not conform. A point-in-time judgement against stated criteria, not an opinion about safety.
- Maturity level
- How deeply a requirement is embedded, from zero, absent, to five, embedded and improving. It answers whether conformance would survive the departure of whoever holds it up.
- Finding grade
- The severity assigned to a nonconformity — critical, major, minor or observation — driving escalation and correction times. Grading turns a list of gaps into a plan.
- Auditor independence
- Freedom from responsibility for, or a reporting line to, the activity audited. Under ISO 19011 a principle of auditing; under some isolation regimes a legal requirement.
FAQ
Frequently asked questions about fatal risk protocol audit
How many protocols should be audited in one record?+
One. Protocol Audited is single-choice because scoring, findings and maturity averages only mean something within a protocol. Auditing height and energy isolation together gives a blended percentage that cannot be acted on or compared year on year.
Who counts as independent of the area?+
Someone with no line responsibility for the area's performance and no role in operating the protocol there. Corporate assurance, another site's team or an external auditor qualify. The area's own safety adviser does not, because the result reflects on their work.
How many workers should be interviewed?+
Set the target beforehand, from how many people perform the activity rather than site headcount. A useful floor is enough people, across shifts and contractors, that one confident answer cannot carry the result.
What happens when practice does not match documentation?+
It becomes the headline finding, not a note. Record specifics in Gap Detail, raise a graded finding against the requirement it breaks, and hold Result Band down. Direction matters: weaker practice is a control failure, stronger practice usually means the protocol is out of date.
How should mandatory and good-practice requirements be weighted?+
Mandatory failures should fail the audit alone; good-practice items should shape the maturity picture rather than the pass decision. Any Mandatory requirement scoring Does not conform sets the band to Fail whatever the percentage says, and generates a Major finding at minimum.
Does a high score mean the protocol is working?+
Only read next to Completeness Percent and the field verification numbers. Ninety per cent on a form sixty per cent complete, with two interviews and no observations, is a document review. The three figures should travel together, which is why completeness is a separate field.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Critical Control and Fatal Risk
Bow Tie Analysis Record
Maps threats, the top event, consequences and the barriers on each side for a major hazard
Barrier Health Review
Reviews whether the barriers relied on in a bow tie are actually in place and working
Critical Control Register
Lists the controls that stand between your people and a fatal or catastrophic event, with an owner and a required check frequency for each
Risk Assessment
The single risk assessment used across the whole business
Serious Potential Incident Report
Used when an event could have killed or seriously injured someone, whatever the actual outcome
Job Safety Analysis
Breaks a job into steps, finds the hazards in each and sets the controls
More in Critical Controls
Critical Control Verification
Checks that a control standing between people and a fatal event is actually in place and working
Critical Control Performance Review
Reviews how a set of critical controls has performed over a period, including verification rates and failures
Barrier Health Check
Checks the barriers named in a bowtie are present and effective, working through the bowtie one branch at a time
Control Failure Report
Records that a critical control was found missing, bypassed or not working
Critical Control Owner Review
The named owner of a control confirms it is still the right control, still resourced and still working

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 19011:2018, clauses 4, 6.4, 6.5 and 7 — Guidelines for auditing management systems
- ISO 45001:2018, clauses 7.2, 9.2.2 and 10.2 — Occupational health and safety management systems
- OSHA 29 CFR 1910.147(c)(6) — periodic inspection of energy control procedures
- Mine Health and Safety Act 29 of 1996 (South Africa), section 11
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.