Skip to content

HSE inspections up 47% - HSE carried out over 13,200 workplace inspections in 2024/25.

Health and Safety Audit Companies: 7 Points to Compare Before You Sign

A
Arinite Health & Safety Consultants
August 1, 2026
8 min read
Health and Safety Audit Companies: 7 Points to Compare Before You Sign

You have three quotes on the desk. The cheapest is a fifth of the price of the dearest, all three use the word "audit" in the title, and nothing in any of them tells you why they differ. This is the position most buyers are in, and it is not a pricing problem. It is a scoping problem. Health and safety audit companies sell products that look identical on a covering page and are not remotely comparable underneath.

This is not a guide to what an audit is or why you need one. You have already decided that. This is the procurement question: given three proposals, how do you work out which one will actually stand up when a regulator, an insurer or your largest client asks to see it. Seven points separate a defensible engagement from an expensive walkthrough.

1. What the word "audit" means in each proposal

The single largest source of price variance. An inspection is a visual check of a site at a point in time. A gap analysis compares your arrangements against a defined benchmark. A full audit examines the management system: documentation, competence records, consultation, incident data, and whether the arrangements you wrote down are the arrangements you actually operate. That last test is what regulation 5 of the Management of Health and Safety at Work Regulations 1999 is driving at when it requires arrangements for planning, organisation, control, monitoring and review.

All three get sold as health and safety audits. Only the third gives you something that survives scrutiny. Ask each provider to state, in the proposal, how many sites are covered, how many documents will be reviewed, how many staff will be interviewed, and how many days are on site. If a proposal cannot answer those four questions, the price is not low, the scope is empty.

2. The standard being audited against

An audit is only meaningful relative to a benchmark. There are three answers you will hear.

Some providers audit against ISO 45001, which is transferable, recognised by clients and insurers, and gives you a certification path if you want one later. Some audit against HSE guidance, principally the framework set out in HSG65, which is sound and free to reference. And some audit against a proprietary in-house framework with a trademarked name.

The third is the one to interrogate. A proprietary score of 74% tells you nothing you can benchmark against a competitor, hand to an insurer, or carry to a different provider next year. It also creates lock-in, which is usually the point. Ask what the framework maps to. If the answer is vague, treat the score as marketing.

3. Who actually turns up

The person who writes the proposal is frequently not the person who does the work. In a distributed engagement across several sites, you may get four different auditors of four different standards, and you will not know until the reports arrive in four different formats.

Ask for the named individual, their qualification level, and their experience in your sector specifically. A Level 5 or Level 6 qualification is the benchmark most corporate buyers now set, and it is reasonable to require the named consultant be written into the contract rather than the firm. Auditing a law firm's archive room and auditing a data centre plant room are different jobs, and a generalist will miss things in both. Where you retain ongoing support, the same question applies to whoever holds your competent person duty.

4. How multi-country sites are handled

This is where most proposals quietly fall apart, and where the price gap usually turns out to be justified.

A UK provider auditing your Frankfurt office has two options. It can audit against UK expectations and translate the report, which produces a document with no legal standing in Germany. Or it can audit against the Arbeitsschutzgesetz and the relevant DGUV requirements, using a practitioner qualified in that jurisdiction. Your Paris office needs a DUERP in the prescribed French format. Your Milan office needs an RSPP appointed under Italian law. All three descend from the same EU Framework Directive 89/391/EEC, but each member state implemented it with its own documentation rules. None of these is a translation exercise.

Ask directly: who conducts the audit in each country, what qualification do they hold there, and what national instrument does the output satisfy. Genuine global health and safety consultants will answer without hesitating. Providers who intend to send someone from London on a flight will not.

5. What the report contains, and whether anyone can act on it

There is a category of audit report that is 90 pages long, technically accurate, and completely inert. Findings are listed, nobody owns them, no dates are attached, and the document goes into a shared drive where it becomes evidence that you knew about a problem and did nothing.

A useful report prioritises findings by risk, states the legal basis for each one, assigns an owner, and sets a target date. Ask to see a redacted sample before you sign, not a contents page. The difference between a list of observations and a prioritised action plan is the difference between a cost and an improvement.

6. What happens to the findings afterwards

An audit produces a snapshot. Compliance is a state you have to maintain, and the handover is where most engagements leak value. If the output is a spreadsheet emailed to a facilities manager, the actions will be 60% complete in six months and nobody will be able to prove which 60%.

Ask what the tracking mechanism is. This is where health and safety consultants and software matter together rather than separately: a single register where every finding has an owner, a deadline and an evidence trail, visible across every site, is the difference between claiming you acted and demonstrating it. Reporting obligations such as RIDDOR run on the same data, so a system that holds both saves duplicating the work.

7. Whether the auditor also fixes what they find, and whether that matters to you

A real trade-off, and reasonable buyers land on both sides of it.

Full separation gives you independence. The auditor has no commercial interest in finding work for themselves, which matters if the report is going to an insurer, a board or a tender panel. Combined delivery gives you continuity: the people who found the problem understand the context and can close it faster, and you are not paying a second firm to relearn your estate.

There is no universally correct answer. What matters is that the provider declares its position rather than leaving it ambiguous. Ask whether the audit fee is contingent on any follow-on work, and how findings are handled if you take the remediation elsewhere.

The comparison table

Take this to your three proposals. The pattern in the right-hand column is what you are paying the difference for.

| Ask | A weak answer sounds like | A strong answer sounds like |

|---|---|---|

| What is the scope? | "A comprehensive health and safety audit" | "Four sites, 12 days on site, 40 documents, 25 interviews" |

| Against what standard? | "Our proprietary compliance framework" | "ISO 45001 clauses 4 to 10, mapped to HSG65" |

| Who conducts it? | "One of our experienced team" | "Named consultant, Level 6 qualified, 9 years in professional services" |

| How are overseas sites covered? | "We audit to UK best practice globally" | "Locally qualified practitioner per country, output satisfies the national instrument" |

| What do we receive? | "A detailed report" | "Risk-prioritised actions with legal basis, owner and date. Sample available" |

| How are actions tracked? | "We will send the findings over" | "Shared register, evidence trail, visible across all sites" |

| Do you also do the remediation? | Not addressed | Declared either way, with the fee structure stated |

If a proposal scores in the left column on four or more rows, the low price is not a saving. You are buying a document rather than an outcome, and you will discover the difference at the worst possible moment.

Where Arinite fits

Arinite has spent 15+ years auditing office-based organisations that operate in more than one country. We work with 1,500+ businesses across 50+ countries, protecting 100,000+ employees, with 95%+ client retention, and our health and safety consultants are salaried rather than subcontracted, so the person named in the proposal is the person who arrives. For multi-site groups, our international health and safety consultants coordinate locally qualified practitioners in each jurisdiction while you keep one point of contact, one methodology and one view of where every action stands.

If you want a straight read on your current arrangements before you commission anything, a free gap analysis will tell you what an audit is likely to find and what scope you actually need. That is a more useful starting point than three quotes you cannot compare.

Share this article
A

Written by

Arinite Health & Safety Consultants

Health & Safety Expert at Arinite

Free Resources

Health & Safety Factsheets

Download our comprehensive library of expert guides, checklists, and templates.

Get Professional Help

Need Expert H&S Advice?

Our qualified consultants are ready to support your specific business needs.