Knowella

Site Security Audit

A security plan can look complete on paper while the site it describes has never actually been tested against it. This audit's recurring failure is treating the annual visit as a document review, walking the same route with the same escort at the same announced time each year, which confirms the plan exists without ever discovering whether an unfamiliar person walking in would be challenged, or whether the gate someone forgot to lock last month is still open.

KnowSafeAuditSAF-14949 fields across 6 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 45001 cl.9.2
Workspace
KnowSafe
Form type
Audit
Completed by
Carried out independently of site security
Audited
Yearly, on the schedule, and wherever a finding elsewhere suggests a systemic gap

The short version

  • A passing score built from an announced, escorted audit is not evidence the site is secure. The unannounced or penetration-style version of this audit is the only one that tests culture rather than preparation.
  • Whether an unfamiliar person gets challenged is the single most revealing test in the whole audit, and it is also the one most audits never actually attempt.
  • Findings marked fixed on the spot without a finding ID raised leave no way to confirm the same gap has not simply recurred by next year's audit.
  • Chemical stores, personal items in production and out of hours arrangements sit in this audit specifically because they double as food defense controls, not just physical security ones.

What this is

What is a site security audit?

What is a site security audit?

It is an independent test of whether the site's security arrangements actually work: perimeter integrity, access control at every point, how visitors and contractors are handled, key control, and whether out of hours arrangements have ever really been tried. It tests the arrangements rather than reading the plan that describes them.

Why must the auditor be independent of site security?

Someone who manages the security arrangements day to day has a stake in them passing, and unconsciously walks the audit along the route that already works. Independence, whether an internal auditor from another site or a third party, is what allows the audit to find what routine operation has learned to work around.

How is this different from the CCTV and Monitoring Review?

CCTV and Monitoring Review tests one control, the camera system. This audit tests the whole security position: doors, gates, keys, visitors, contractors and out of hours cover, of which cameras are only one part.

Scope

When is a site security audit required?

This audit is one step in a larger programme. Using it for work that belongs to a neighbouring template produces records that are hard to report on later.

Use this template when

  • The annual audit schedule has come round, or a finding elsewhere (a break-in, a tailgating complaint, a failed CCTV review) suggests a systemic gap
  • The workspace is being set up and the site needs a first independent baseline audit
  • You are running the Lone Working and Security programme and this is one of its steps
  • A linked record needs this one to exist: links Security Risk Assessment, Access Control Review
  • A prior audit found gates or doors that were later reinstated, and the fix needs re-testing rather than taking on trust

Do not use it for

  • Security Risk Assessment, which assesses the site against theft, unauthorised access, sabotage and product tampering as a standing document.
  • CCTV and Monitoring Review, which reviews one control, the camera system, rather than the whole security position.
  • Access Control Review, which reviews the access permission system itself, not whether the doors it controls hold up under a real test.
  • Anything outside KnowSafe, which belongs in the workspace that owns that process

Compliance mapping

Which ISO 45001 cl.9.2 requirements does this satisfy?

ISO 45001 treats this audit as the internal audit function applied to a specific operational control, which is why independence and objectivity carry as much weight in the clause structure as the physical checks themselves.

ClauseRequirementWhere it lands
ISO 45001 cl.9.2.2Internal audits planned, established and conducted by auditors who are objective and impartial to the area auditedHeader
ISO 45001 cl.8.1Operational controls at the perimeter and access points established, implemented and maintainedPerimeter and access
ISO 45001 cl.8.1Operational controls extended to visitors and contractors present on siteVisitors and contractors
ISO 45001 cl.8.1Operational controls over restricted areas, key control and materials that could be misusedInternal controls
GFSI schemes (food defense)Site security controls, including chemical stores and personal item restrictions, treated as part of the food defense programme where applicableInternal controls
ISO 45001 cl.10.2Nonconformities identified during audit evaluated, corrected and tracked to closureFindings
ISO 45001 cl.9.1Monitoring and measurement of operational controls, including whether arrangements work when actually testedResult

What it does not cover

  • Security Risk Assessment, which assesses the site against theft, unauthorised access, sabotage and product tampering as a standing document, not a tested arrangement.
  • CCTV and Monitoring Review, which tests one control, the camera system, coverage, image quality and retention, rather than the whole security position.
  • Access Control Review, which reviews who holds access permissions and cards, not whether the doors and gates they control actually hold under test.
  • Food Defense Plan, which sets out the standing food defense controls this audit tests a slice of, chemical stores and personal items, alongside the general physical security.
  • Lone Working Risk Assessment, which assesses tasks done alone or out of sight, rather than the site's perimeter and access arrangements as a whole.

Global

Site Security Audit requirements by country

There is no single statute requiring a site security audit in the way there is for many safety records; the duty arrives indirectly, through general workplace safety law, food defense regulation, and the audit obligations of whichever management standard the site is certified to.

United States

OSHA general duty clause, state workplace violence prevention laws (e.g. California SB 553), FSMA Intentional Adulteration rule (21 CFR 117 Subpart C) for registered food facilities

Physical site security is not directly regulated federally, but registered food facilities carry a specific duty to mitigate vulnerabilities to intentional adulteration, which overlaps heavily with this audit's internal controls.

A food site cannot treat this audit as purely a security exercise; the chemical store and production access findings feed a food defense obligation with its own enforcement exposure.

United Kingdom

Health and Safety at Work etc. Act 1974 s.2 and s.3, ISO 45001 cl.9.2 where certified, BRCGS Global Standard for Food Safety site security clause where applicable

The general duty to protect employees and others affected by the undertaking extends to a securely run site; certification schemes add their own explicit audit requirement.

A certified food site's security audit has to satisfy the scheme auditor as well as the general duty, and a gap found here is a gap the scheme audit will also find.

International

ISO 45001 cl.9.2 internal audit requirement, GFSI-benchmarked schemes (BRCGS, SQF, FSSC 22000) requiring a documented, audited site security programme

Wherever a site is certified to a management standard or a GFSI scheme, a periodic, independent security audit is an explicit requirement rather than good practice.

The independence requirement is not local custom, it is written into the audit clause itself, and an audit run by site security fails the standard regardless of what it finds.

How to complete it

How to complete a site security audit, step by step

This audit is only as good as the test behind it. The judgement calls sit in how far the auditor is willing to push past the escorted, expected route.

Test it, do not read it

Reading the security plan and confirming the gates match the diagram is a document review, not an audit. The useful version tries the doors, follows a visitor through the process, and walks in without a badge to see whether anyone stops to ask who you are.

Use the unannounced and penetration-style options deliberately

An audit type that is always announced tests the site's ability to prepare, not its ability to be secure. Rotating in unannounced visits, and periodically a genuine penetration-style test, is what separates this record from a checklist walkthrough.

Treat an unchallenged walk-through as a real finding, not a curiosity

Whether an unfamiliar person is challenged is the sharpest available signal of whether the culture matches the plan. A never-challenged result should drive an immediate correction, not sit alongside a passing overall score as an outlier.

Raise a finding ID for anything beyond a trivial, provable fix

Fixed on the spot is legitimate for a door that was simply unlocked and is now locked in front of the auditor. It is not legitimate for a gap that depends on someone remembering to do something differently next time; that needs a finding ID and a CAPA that can be checked at the next audit.

What auditors find

Most common site security audit findings

Findings on this audit concentrate where the test was softened, an audit that was announced, an auditor who was not really independent, or a fail that was waved through as fixed on the spot with nothing to check next time.

FindingClauseWhat fixes it
Audit scheduled and announced to site management weeks in advance, every year, with no unannounced variant used.ISO 45001 cl.9.2.2Rotate in unannounced or penetration-style audits so the site cannot prepare a route for the auditor.
Auditor was a member of the site security team being audited, rather than independent of it.ISO 45001 cl.9.2.2Assign an auditor from outside the reporting line responsible for the arrangements under test.
Unfamiliar person walked through the site without a badge and was never challenged by anyone.ISO 45001 cl.8.1Treat an unchallenged walk-through as an immediate finding requiring correction, not just a scored line item.
Chemical and ingredient stores found unlocked during the audit, despite passing the same check the year before.GFSI schemes (food defense)Physically test the lock at every audit rather than confirming the policy that says it should be locked.
Out of hours arrangements confirmed only by reviewing the written procedure, never by an actual test.ISO 45001 cl.9.1Run a genuine out of hours test, alarm response included, rather than a review of the document describing it.
Finding marked fixed on the spot with no finding ID raised, leaving nothing to check for recurrence.ISO 45001 cl.10.2Raise a finding ID for any fail that is not both trivial and provably permanent, even where corrected during the audit.

Case in point

Case in point: the audit that announced itself

A processing site's annual security audit had followed the same pattern for years: scheduled by email two weeks out, walked with the site security manager as escort, doors tested and found secure, visitors signed in and badged, every year passing comfortably. The auditor challenging an unfamiliar person was, on paper, always ticked yes.

After a break-in through the contractor gate, a penetration-style follow-up was ordered without warning site management. The same auditor walked the same route without a badge and was never once stopped, all the way to the loading dock, where a driver waved them through assuming they belonged there. The prior year's clean audit had tested a version of the site that only existed when everyone knew an audit was happening. The fix was not a new door or a new camera; it was retiring the announced format as the only format used.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

49fields
6 sections
Reference
SAF-149
Archetype
Audit
Record ID
AUD-2026-000
Scoring
Score
Direction
High is good
Singleton
Yes
Basis
ISO 45001 cl.9.2
Links
Links Security assessment, Access review
Tags
Security, Audit
Sections
6
Fields
49
Follow up fields
9
Repeating sections
1
Links out
3
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

10 fields
Text

Audit ID*

Generated on save

Auto sequence. Format AUD-2026-00000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Date & Time

Date and Time*

Users

Completed By*

Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Users

Auditor*

Single Choice

Independent Of Site Security*

Scored
  • Yes3 pts
  • No0 pts
Single Choice

Audit Type*

Scored
  • Announced1 pt
  • Unannounced3 pts
  • Penetration style test4 pts
Info

Test It, Do Not Read It

The useful part of a security audit is trying the doors, following a visitor through and seeing whether anybody challenges you.

Perimeter and access

6 fields
Single Choice

Perimeter Intact*

Scored
  • Yes3 pts
  • Gaps1 pt
  • Breached0 pts
Single Choice

Gates Secured Out Of Hours*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Doors Tested And Secure*

Scored
  • All3 pts
  • Most1 pt
  • Several open0 pts
Single Choice

Access Cards Required At All Points*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Tailgating Observed*

Scored
  • No3 pts
  • Occasionally1 pt
  • Routinely0 pts
Single Choice

Unfamiliar Person Challenged*

Scored

Walk in without a badge. Whether anybody asks who you are is the real measure.

  • Yes, promptly3 pts
  • Eventually1 pt
  • Never0 pts

Visitors and contractors

6 fields
Single Choice

Visitors Signed In And Badged*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Escort Rules Followed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Contractor Approval Checked At Gate*

Scored
  • Yes3 pts
  • Sometimes1 pt
  • No0 pts
Single Choice

Deliveries Verified Against Expected*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Drivers Confined To Agreed Areas*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Visitor Log Accurate And Current*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Internal controls

6 fields
Single Choice

Restricted Areas Secured*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Keys Controlled And Signed Out*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Chemical And Ingredient Stores Locked*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Personal Items Controlled In Production

OptionalScored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Waste Removal Supervised

OptionalScored
  • Yes3 pts
  • Sometimes1 pt
  • No0 pts
Single Choice

Out Of Hours Arrangements Tested*

Scored
  • Yes3 pts
  • No0 pts

Findings

Repeats7 fields
Single Choice

Result*

Scored
  • Pass3 pts
  • Pass with conditions2 pts
  • Fail0 pts
Single Choice

Severity

OptionalScoredShows if Result equals Fail
  • Minor3 pts
  • Moderate1 pt
  • Serious0 pts
Single Choice

Element Tag

OptionalShows if Result equals Fail

Groups deficiencies by hazard type across every template.

Hazard identificationPPEHousekeepingEnergy isolationMachine guardingErgonomicsChemicalElectricalWorking at heightConfined spaceMobile equipment
Text

Deficiency Detail

OptionalShows if Result equals Fail
File Upload

Photo Evidence

OptionalShows if Result equals Fail
Single Choice

Fixed On The Spot

OptionalShows if Result equals Fail
YesNo
Text

Finding ID

OptionalLinkedShows if Fixed On The Spot equals No

Raise a finding record where this needs tracking to closure.

Links to FDN-015 Finding ID

Result

14 fields
Numeric Answer

Items Assessed*

Excludes anything marked N/A.

Numeric Answer

Items Failed*

Numeric Answer

Score Percent*

Scored

Calculated on submission. High is good. N/A items leave the denominator.

Single Choice

Result Band*

Scored
  • Pass3 pts
  • Caution1 pt
  • Fail0 pts
Numeric Answer

Completeness Percent*

How much of the template was actually answered. A high score on a half completed form is not a high score.

Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Date & Time

Next Due*

Users

Auditor*

Signature

Signature*

Users

Site Manager*

Signature

Second Signature*

SAF-149 · record IDs look like AUD-2026-000 · Links Security assessment, Access review

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The audit form is the easy part. Making sure it was independent, unannounced often enough to mean something, and that every real finding got a tracked CAPA rather than a shrug, is the work that slips.

KnowSafe

Holds the audit against the annual schedule, flags when the audit type has been announced every cycle running, and blocks closure on fails without a finding ID.

KnowContractor

Cross-checks contractor approval and induction records against what the audit actually found at the gate, so a paper approval doesn't stand in for a real check.

KnowQuality

Links chemical store and personal item findings to the site's food defense programme, so a security gap and a food defense gap are not tracked as two unrelated issues.

Ella
Ella

Coordinates the crew, rolls completion and exceptions into one view, and holds every write for your approval before it touches a record.

This template lives in KnowSafe — safety and compliance. Incidents, hazards, permits, inspections and the critical controls behind them.

Meet KnowSafe→

Glossary

Site Security Audit definitions and key terms

Independent audit
An audit conducted by someone with no responsibility for the arrangements being tested, required so the result reflects the actual state rather than a defended one.
Tailgating
Following an authorised person through an access-controlled door without presenting your own credential, the most common way access control is bypassed in practice.
Penetration-style test
An unannounced audit that actively attempts to bypass controls, walking through without a badge or following a visitor, rather than checking that controls exist.
Out of hours arrangements
The security controls in force when the site is unattended or minimally staffed, including alarms, gate locking and any patrol or monitoring cover.
Escort rules
The requirement that visitors and certain contractors remain accompanied by an authorised person while on site, rather than moving unsupervised.

FAQ

Frequently asked questions about site security audit

What is the site security audit template based on?+

It is built against ISO 45001 cl.9.2, the internal audit clause, applied to the site's physical security arrangements as an operational control under cl.8.1. Where the site handles food, GFSI-benchmarked schemes add their own explicit food defense expectations covered by the same audit.

What sections does the site security audit contain?+

There are six sections: header, perimeter and access, visitors and contractors, internal controls, findings, result. Together they hold 49 fields, 37 of which are required, with findings repeating for each entry.

How many site security audit records should we have?+

This is a singleton. One record per workspace, set up once and maintained through the audit cycle, rather than one per event.

Which programme does the site security audit belong to?+

It is part of Lone Working and Security, contributing tested arrangements toward a security position covering theft, access and food defense across the site.

Why does the audit type field include a penetration-style option?+

Because an announced, escorted audit tests preparation, not security. Rotating in unannounced and penetration-style visits is what surfaces the gap between the written plan and what actually happens day to day.

Can the site security audit template be changed?+

Yes. Every field, option, score and conditional rule is editable, and the links to other templates come with it. Most teams install it as it is, run it for a cycle, then adjust.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO 45001 — Occupational health and safety management systems, cl.9.2, cl.8.1, cl.10.2, cl.9.1
  • 21 CFR 117 Subpart C — FSMA Intentional Adulteration rule, mitigation strategies and vulnerability assessment
  • Health and Safety at Work etc. Act 1974 — s.2, s.3, general duties
  • GFSI-benchmarked schemes — food defense and site security requirements (BRCGS, SQF, FSSC 22000)

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.