Legislation, Audits & Inspections7 min readPublished 24 August 2026

How Should a Multi-Site Business Scope an OHS Audit Programme?

Build a risk-based multi-site OHS audit programme that gives management comparable evidence without assuming every location has the same exposure.

Why this decision matters

This guide is written for executives, group SHEQ teams, regional managers and internal audit leaders. It focuses on which sites, criteria and activities should be reviewed first and how findings should be compared, escalated and closed across the organisation. That framing matters because a broad request for “compliance” or “safety support” can hide several different decisions, each requiring different information, competence and accountability. A useful engagement begins by defining the workplace or project, the people affected, the operating constraints and the result management needs to use.

Risk-based sequencing helps limited audit resources reach the sites where weak controls could cause the greatest harm or operational interruption. Prevention is not a promise that incidents will never occur. It is the disciplined work of identifying credible exposure, strengthening controls, recording decisions and checking whether action was effective. That approach protects people while also supporting continuity, cost control and defensible management decisions.

Information to prepare

  • Confirm the complete site and operating-activity register. Record the source, current owner and any uncertainty so that an adviser or provider does not have to fill gaps with assumptions.
  • Confirm risk, incident and previous-audit information by site. Record the source, current owner and any uncertainty so that an adviser or provider does not have to fill gaps with assumptions.
  • Confirm common requirements and site-specific obligations. Record the source, current owner and any uncertainty so that an adviser or provider does not have to fill gaps with assumptions.
  • Confirm business criticality, workforce and contractor profiles. Record the source, current owner and any uncertainty so that an adviser or provider does not have to fill gaps with assumptions.
  • Confirm governance, reporting and corrective-action arrangements. Record the source, current owner and any uncertainty so that an adviser or provider does not have to fill gaps with assumptions.

A practical five-step process

01
Segment sites by operating risk

Use this step to support the decision about which sites, criteria and activities should be reviewed first and how findings should be compared, escalated and closed across the organisation. Identify who has authority, what evidence will be considered, what must happen next and how the result will be checked. Step 1 should leave a clear record without creating unnecessary paperwork.

02
Set common and local audit criteria

Use this step to support the decision about which sites, criteria and activities should be reviewed first and how findings should be compared, escalated and closed across the organisation. Identify who has authority, what evidence will be considered, what must happen next and how the result will be checked. Step 2 should leave a clear record without creating unnecessary paperwork.

03
Choose coverage and sampling deliberately

Use this step to support the decision about which sites, criteria and activities should be reviewed first and how findings should be compared, escalated and closed across the organisation. Identify who has authority, what evidence will be considered, what must happen next and how the result will be checked. Step 3 should leave a clear record without creating unnecessary paperwork.

04
Calibrate finding and escalation rules

Use this step to support the decision about which sites, criteria and activities should be reviewed first and how findings should be compared, escalated and closed across the organisation. Identify who has authority, what evidence will be considered, what must happen next and how the result will be checked. Step 4 should leave a clear record without creating unnecessary paperwork.

05
Track systemic and site-specific closure

Use this step to support the decision about which sites, criteria and activities should be reviewed first and how findings should be compared, escalated and closed across the organisation. Identify who has authority, what evidence will be considered, what must happen next and how the result will be checked. Step 5 should leave a clear record without creating unnecessary paperwork.

Four questions to test the plan

Planning questionWhat to confirmWhy it matters
What is in scope?the complete site and operating-activity register and common requirements and site-specific obligations.It prevents different parties from acting on different assumptions.
What decision is required?The organisation must decide which sites, criteria and activities should be reviewed first and how findings should be compared, escalated and closed across the organisation.It keeps the work connected to a usable management outcome.
Who owns follow-through?governance, reporting and corrective-action arrangements, including authority, resources and escalation.Advice has limited value when nobody can implement or verify action.
What evidence is enough?risk, incident and previous-audit information by site together with business criticality, workforce and contractor profiles.Reliable evidence supports proportionate decisions and transparent limitations.
A concise brief should make each answer clear before work begins.

Plan the next step

For “How Should a Multi-Site Business Scope an OHS Audit Programme?”, turn the five planning inputs into a short written brief before requesting a proposal. State what is known, what remains uncertain and which decision is time-critical. Ask the provider to identify assumptions, exclusions, information dependencies and the evidence that will be delivered. This makes proposals easier to compare and reduces costly scope changes after work begins.

Diba BES can discuss which sites, criteria and activities should be reviewed first and how findings should be compared, escalated and closed across the organisation and define an appropriate next step through its existing service pathway. The enquiry should describe the operating context rather than presuppose an outcome. The agreed scope should then state Diba BES's role, the client's responsibilities, any third-party or regulated-provider dependencies, and how recommendations or service records will be handed over.

Frequently Asked Questions

What is the main purpose of how should a multi-site business scope an ohs audit programme?

The purpose is to help executives, group SHEQ teams, regional managers and internal audit leaders make a defined decision about which sites, criteria and activities should be reviewed first and how findings should be compared, escalated and closed across the organisation. It should connect evidence, responsibility and practical follow-through rather than produce activity with no clear management use.

What should be prepared before contacting Diba BES?

Prepare the complete site and operating-activity register, risk, incident and previous-audit information by site and common requirements and site-specific obligations. Add the location, timing, key contacts and any uncertainty that may change the scope or require another competent or authorised party.

Does consulting or service support guarantee compliance?

No. A scoped service can support assessment, planning, capability or improvement, but it cannot guarantee compliance, certification, approval, incident prevention or the performance of duties held by another party.

How does this approach help protect cost and continuity?

Risk-based sequencing helps limited audit resources reach the sites where weak controls could cause the greatest harm or operational interruption. The value comes from timely decisions and effective controls, not from quoting a universal savings number or promising that every interruption can be avoided.

How should a provider's scope and evidence be checked?

Ask for the exact role, proposed method, deliverables, exclusions and evidence relevant to which sites, criteria and activities should be reviewed first and how findings should be compared, escalated and closed across the organisation. Verify current credentials or regulated status at source where required, and keep this limitation in view: A sample of sites cannot automatically prove the condition of every location; management should record coverage limitations and triggers for additional review.

NR
Written by Nandipha Rambau
CEO and Director

Diba BES provides occupational health and safety consulting, workplace training and commercial workplace services for South African organisations. Its prevention-focused approach helps clients identify gaps, plan action and protect operational continuity.