Knowella

Fatal Risk Protocol Audit

Fatal risk protocols fail as paperwork long before they fail as protection. The document is current, the training matrix green, the permits signed — and the crew at height is tied off to a handrail because the anchor point is thirty metres away. The recurring failure mode is an audit run at a desk, scoring a protocol against its own documentation. This template splits the audit and will not close on the document half.

KnowSafeAuditSAF-08142 fields across 4 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ICMM, ISO 19011
Workspace
KnowSafe
Form type
Audit
Review trigger
Annually per protocol, and off-cycle where a finding suggests a systemic gap
Completed by
An auditor independent of the area, countersigned by the area manager

The short version

  • The audit is credible only if the auditor is independent of the area. Auditor Independent Of Area is scored rather than noted, because an area auditing itself produces a conformance rate and no information.
  • Conformance and maturity must both be recorded per requirement. Conformance alone flatters a protocol held together by one diligent supervisor; maturity alone excuses a system nobody follows this week.
  • Mandatory and good-practice requirements cannot carry equal weight. Requirement Type exists so a mandatory failure cannot be offset by good-practice passes elsewhere in the protocol.
  • Half the evidence is not in the filing cabinet. Workers Could Explain The Protocol and Practice Matches Documentation predict more than the document review; an audit skipping them is misnamed.

What this is

What is a fatal risk protocol?

What is a fatal risk protocol?

A mandatory standard covering one activity capable of killing someone — working at height, energy isolation, confined space, mobile equipment, lifting. It states minimum requirements, not guidance, and deviation needs formal authorisation rather than judgement at the workface.

What is a fatal risk protocol audit?

A conformance audit of one protocol at one site, run to a defined requirement list and scored on conformance and maturity. It differs from a general safety audit in scope and depth: one protocol, all of it, including how it is applied in the field. Findings are graded and fed to corrective action.

What is the difference between conformance and maturity?

Conformance asks whether the requirement is met now — yes, partly or no. Maturity asks how deeply it is embedded, from absent through ad hoc, defined, implemented and measured to embedded and improving. A protocol can conform on paper at maturity one, which predicts it will stop once attention moves.

Scope

When is a fatal risk protocol audit required?

This audit tests one protocol at one site against a requirement list. It is a periodic, planned, independent assessment — not a spot check, not an investigation, not a review of how a control performed over time. Used in place of a neighbouring template it satisfies the schedule and answers nothing.

Use this template when

  • The annual cycle falls due for a named protocol such as working at height, energy isolation or confined space
  • A serious potential incident or repeated finding suggests the gap is systemic rather than local to one crew
  • A new site, acquisition or major contractor comes into scope and the protocol has never been tested there
  • The protocol has been revised and you need to know whether the revision reached the workface
  • A customer, insurer or assurance function requires independent evidence of implementation

Do not use it for

  • Critical Control Verification, which tests one control against its performance standard in the field and is narrower than a whole-protocol audit.
  • Barrier Health Check, which walks the barriers named on a bowtie for one unwanted event rather than the requirements of a written protocol.
  • Critical Control Performance Review, which looks backwards across a period at verification rates and failures instead of conformance now.
  • Control Failure Report, which is raised when a control has failed in service and needs investigation rather than scheduled assessment.
  • Critical Control Owner Review, which examines whether named owners discharge their accountabilities and is about people, not requirements.

Compliance mapping

Which ICMM requirements does this satisfy?

Two families of obligation sit behind this template: the auditing method ISO 19011 sets out, and the duty to control fatal risks from the management-system standard.

ClauseRequirementWhere it lands
ISO 19011:2018, clause 4Audits follow the principles of independence and an evidence-based approach, with auditors free of bias and conflict of interestHeader
ISO 19011:2018, clause 6.4Audit activities collect and verify information against defined criteria, evidence recorded as obtainedProtocol requirements
ISO 19011:2018, clause 6.5Audit conclusions are prepared and the report given to those accountable for acting on itResult
ISO 45001:2018, 9.2.2An internal audit programme is planned and maintained, covering frequency, methods and reportingResult
ISO 45001:2018, 7.2Workers are competent on the basis of education, training or experience relevant to the hazards they faceField verification
ISO 45001:2018, 10.2Nonconformities are recorded, corrective action taken with ownership, and effectiveness reviewedResult

What it does not cover

  • A protocol document review, which confirms the standard is written and current and says nothing about whether anyone at the workface follows it.
  • A training completion report, which shows attendance rather than understanding, and reads one hundred per cent on protocols workers cannot explain.
  • A permit or certificate sample, which tests the paperwork the protocol produces rather than the requirements it imposes.
  • A management self-assessment, which asks the area accountable for conformance to declare it, and returns partial at worst.
  • A corporate assurance summary, which aggregates site scores into a portfolio position and cannot show which requirement failed.

Global

Fatal Risk Protocol Audit requirements by country

Fatal risk protocols map onto very different instruments depending on where the site sits, and the evidence a regulator expects varies with them. These three cover most use.

United States

OSHA 29 CFR 1910.147(c)(6) — periodic inspection of energy control procedures

Requires at least annual inspection of the energy control procedure by an authorised employee other than the one using it, certified with machine, date and inspector

For energy isolation this is the nearest thing to a statutory version of this template. Independence is not preference: the other than the one using it wording makes it a compliance requirement, and the certification content maps onto Header and Result.

Australia

Work Health and Safety Act 2011 (model), sections 19 and 27

A primary duty of care on the person conducting a business, and a due-diligence duty on officers to verify that resources and processes for controlling risk are in place and used

Officer due diligence is where this audit earns its keep. A signed, independent, graded audit with field verification is what an officer relies on to show verification rather than assumption — the distinction section 27 draws.

South Africa

Mine Health and Safety Act 29 of 1996, section 11

Requires the employer to identify hazards, assess and record the associated risks, and periodically review the effectiveness of measures taken

Periodic review of effectiveness is not satisfied by re-issuing the risk assessment. An annual audit scoring maturity and recording field observations answers it directly, and the ICMM lineage is recognised by inspectors.

How to complete it

How to complete a fatal risk protocol audit, step by step

The scoring mechanics are straightforward. Four judgements decide whether the record would survive being challenged.

Whether the auditor is genuinely independent

Auditor Independent Of Area is scored pass, partial, fail rather than yes or no, because independence has degrees. A corporate auditor is a pass; a supervisor from the next shift is partial; the area's own safety adviser is a fail however rigorous. A partial with a good audit behind it is defensible; a false pass poisons the record.

How each requirement is classified before fieldwork

Requirement Type must be set from the protocol, not from how the audit is going. Reclassifying a failed mandatory item as good practice to protect the score is the commonest manipulation here, and the easiest to spot on review. Agree the mandatory list with the protocol owner and freeze it.

What maturity level actually means here

The distinction that matters is between three, implemented, and four, measured. Implemented means it happens; measured means someone would know if it stopped. Most protocols sit at three and are recorded as four because a report exists somewhere. If you cannot name the measure, its frequency and who reads it, the level is three.

Whether the field half carries equal weight

Workers Interviewed, Workers Could Explain The Protocol and Field Observations Made need targets set beforehand, or they become whatever the day allowed. Practice Matches Documentation answered No should hold Result Band down whatever the requirement list scored — conforming on paper and not in practice is failing.

What auditors find

Most common fatal risk protocol audit findings

These findings recur when protocol audits are themselves reviewed, with the clause behind each and the change that stops it repeating.

FindingClauseWhat fixes it
Audit completed by the area's own safety adviser, Auditor Independent Of Area recorded as PassISO 19011:2018, clause 4Resolve the auditor against the area's reporting line and block a Pass where they fall inside it; require a different user for the second signature.
Score Percent above the pass threshold while a mandatory requirement does not conformISO 45001:2018, 9.2.2Force Result Band to Fail whenever a Mandatory requirement scores Does not conform, so weighting cannot be outvoted by good-practice passes.
Field verification numbers left at zero or one, the audit closed on document reviewICMM Critical Control Management Good Practice Guide (2015)Set minimums for Workers Interviewed and Field Observations Made proportionate to headcount, and prevent submission below them.
Findings written into Finding Detail with no Finding ID or grade, so nothing reaches corrective actionISO 45001:2018, 10.2Make Finding ID and Finding Grade mandatory once Conformance is anything but Conforms, and reject Action Required No where a Major grade exists.
Every requirement scored at maturity level three, giving an average that never movesISO 19011:2018, clause 6.4Require an evidence file for any level of four or five, and review Average Maturity Level year on year for implausible flatness.
Completeness Percent well below one hundred, a high Score Percent reported as a clean auditISO 19011:2018, clause 6.5Report Score Percent and Completeness Percent together in every summary, and suppress the band where completeness falls under the agreed floor.

Case in point

Case in point: the height protocol that scored ninety-four

A distribution business audited its working at height protocol across eleven sites. Ten scored above ninety. The requirement list came from the protocol's own contents page — policy exists, training register maintained, equipment inspected, permits issued — each with a document behind it, each marked Conforms. Field verification was a walk round with the site manager. Average maturity sat at 3.6 and had not moved in three years.

A fall from a mezzanine edge protection gap prompted a re-audit with two changes: an auditor from outside the region, and a requirement list written from outcomes rather than headings. Conformance dropped to sixty-one per cent. Anchor points had no inspection records; the rescue plan named a fire service response time nobody had confirmed; of nine workers interviewed, three could explain the protocol. Nothing in the document had changed — only what the audit looked at, and who looked.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

42fields
4 sections
Reference
SAF-081
Archetype
Audit
Record ID
AUD-2026-000
Scoring
Weighted percent
Direction
High is good
Singleton
No
Basis
ICMM, ISO 19011
Links
Links Critical Controls; feeds Finding
Tags
Critical risk, Audit
Sections
4
Fields
42
Follow up fields
7
Repeating sections
1
Links out
4
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

10 fields
Text

Audit ID*

Generated on save

Auto sequence. Format AUD-2026-00000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Date & Time

Date and Time*

Users

Completed By*

Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Single Choice

Protocol Audited*

Working at heightEnergy isolationConfined spaceMobile equipmentAmmonia managementMachine guardingHot workLifting operations
Single Choice

Auditor Independent Of Area*

Scored
  • Pass2 pts
  • Partial1 pt
  • Fail0 pts
  • N/Aexcluded from denominator
Pick List

Clause Reference

OptionalFrom FDN-009 Clause Reference
Text

Clause ID

OptionalLinked

Format CLS-0000.

Links to FDN-009 Clause ID

Protocol requirements

Repeats10 fields
Text

Requirement*

Single Choice

Requirement Type*

Mandatory or good practice. Mandatory failures carry more weight.

MandatoryGood practice
Single Choice

Evidence Sighted*

Scored
  • Pass2 pts
  • Partial1 pt
  • Fail0 pts
  • N/Aexcluded from denominator
Single Choice

Evidence Type

Optional
Third party verifiedInternal calculationSupplier declarationCertification
File Upload

Evidence File

Optional
Single Choice

Conformance*

Scored
  • Conforms3 pts
  • Partially conforms1 pt
  • Does not conform0 pts
Single Choice

Maturity Level*

Scored

Zero is absent, five is embedded and improving.

  • 0 Absent0 pts
  • 1 Ad hoc1 pt
  • 2 Defined2 pts
  • 3 Implemented3 pts
  • 4 Measured4 pts
  • 5 Embedded and improving5 pts
Text

Finding Detail

OptionalShows if Conformance not equals Conforms
Text

Finding ID

OptionalLinkedShows if Conformance not equals Conforms

Links to FDN-015 Finding ID

Single Choice

Finding Grade

OptionalScoredShows if Conformance not equals Conforms
  • Critical0 pts
  • Major1 pt
  • Minor2 pts
  • Observation3 pts

Field verification

6 fields
Info

Documents Are Not Enough

Half this audit happens in the workplace. Watch the protocol being applied and talk to the people applying it.

Numeric Answer

Workers Interviewed*

Numeric Answer

Workers Could Explain The Protocol*

Scored
Numeric Answer

Field Observations Made*

Single Choice

Practice Matches Documentation*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Text

Gap Detail

OptionalShows if Practice Matches Documentation not equals Yes

Result

16 fields
Numeric Answer

Items Assessed*

Excludes anything marked N/A.

Numeric Answer

Items Failed*

Numeric Answer

Score Percent*

Scored

Calculated on submission. High is good. N/A items leave the denominator.

Single Choice

Result Band*

Scored
  • Pass3 pts
  • Caution1 pt
  • Fail0 pts
Numeric Answer

Completeness Percent*

How much of the template was actually answered. A high score on a half completed form is not a high score.

Numeric Answer

Average Maturity Level*

Scored
Numeric Answer

Major Findings*

Scored
Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Date & Time

Next Audit Due*

Users

Auditor*

Signature

Signature*

Users

Area Manager*

Signature

Second Signature*

SAF-081 · record IDs look like AUD-2026-000 · Links Critical Controls; feeds Finding

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

Protocol audits fail on logistics more than method: the schedule slips, the independent auditor is unavailable, findings land in a spreadsheet, the next cycle starts blank.

KnowSafe

Holds the audit programme per protocol and site, carries last year's requirement list and findings into the new audit, and blocks closure where a mandatory nonconformity has no graded finding.

KnowTrain

Supplies the competence record behind the protocol so the audit compares who is signed off against who could actually explain it, turning that gap into a finding rather than an impression.

KnowComply

Maps each requirement to the obligation behind it — lockout periodic inspection, officer due diligence, periodic review of effectiveness — so evidence lines up with what a regulator asks to see.

Ella
Ella

Compares the same protocol across sites, surfaces requirements failing everywhere as a design problem rather than eleven local findings, and drafts actions for approval.

This template lives in KnowSafe — safety and compliance. Incidents, hazards, permits, inspections and the critical controls behind them.

Meet KnowSafe→

Glossary

Fatal Risk Protocol Audit definitions and key terms

Fatal risk protocol
A mandatory minimum standard for one activity capable of causing a fatality, written so deviation needs authorisation rather than judgement. Also called a life-saving rule.
Conformance
The degree to which a requirement is currently met — conforms, partially conforms or does not conform. A point-in-time judgement against stated criteria, not an opinion about safety.
Maturity level
How deeply a requirement is embedded, from zero, absent, to five, embedded and improving. It answers whether conformance would survive the departure of whoever holds it up.
Finding grade
The severity assigned to a nonconformity — critical, major, minor or observation — driving escalation and correction times. Grading turns a list of gaps into a plan.
Auditor independence
Freedom from responsibility for, or a reporting line to, the activity audited. Under ISO 19011 a principle of auditing; under some isolation regimes a legal requirement.

FAQ

Frequently asked questions about fatal risk protocol audit

How many protocols should be audited in one record?+

One. Protocol Audited is single-choice because scoring, findings and maturity averages only mean something within a protocol. Auditing height and energy isolation together gives a blended percentage that cannot be acted on or compared year on year.

Who counts as independent of the area?+

Someone with no line responsibility for the area's performance and no role in operating the protocol there. Corporate assurance, another site's team or an external auditor qualify. The area's own safety adviser does not, because the result reflects on their work.

How many workers should be interviewed?+

Set the target beforehand, from how many people perform the activity rather than site headcount. A useful floor is enough people, across shifts and contractors, that one confident answer cannot carry the result.

What happens when practice does not match documentation?+

It becomes the headline finding, not a note. Record specifics in Gap Detail, raise a graded finding against the requirement it breaks, and hold Result Band down. Direction matters: weaker practice is a control failure, stronger practice usually means the protocol is out of date.

How should mandatory and good-practice requirements be weighted?+

Mandatory failures should fail the audit alone; good-practice items should shape the maturity picture rather than the pass decision. Any Mandatory requirement scoring Does not conform sets the band to Fail whatever the percentage says, and generates a Major finding at minimum.

Does a high score mean the protocol is working?+

Only read next to Completeness Percent and the field verification numbers. Ninety per cent on a form sixty per cent complete, with two interviews and no observations, is a document review. The three figures should travel together, which is why completeness is a separate field.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO 19011:2018, clauses 4, 6.4, 6.5 and 7 — Guidelines for auditing management systems
  • ISO 45001:2018, clauses 7.2, 9.2.2 and 10.2 — Occupational health and safety management systems
  • OSHA 29 CFR 1910.147(c)(6) — periodic inspection of energy control procedures
  • Mine Health and Safety Act 29 of 1996 (South Africa), section 11

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.