What actually happens in a COR audit
Last updated: Written by Blake Cowan, NCSO

The short answer
A COR audit is mostly reading and talking, not inspecting. It runs in order: an opening meeting, a documentation review sampled across the whole audit period, interviews the auditor chooses, a shorter site visit, then a closing meeting and a written report. The site walk is the smallest part.
Almost everybody facing their first COR audit expects an inspection. Somebody in a vest with a clipboard, looking for a missing guard or an untied ladder, deciding whether you pass on the strength of what they see that day.
That is a small part of it. COR certifies a management system, not a site. So the audit is mostly reading and talking. An auditor can spend a full morning at your kitchen table with a laptop and a stack of records and never put a boot on the ground until after lunch.
Know that early, because it changes what preparation means. You are not tidying up. You are proving a system existed, ran continuously, and reached the people doing the work. Here is the shape of it, in order, from somebody who has sat on both sides.
| Stage | What the auditor is doing | What it decides |
|---|---|---|
| Before the visit | Agreeing scope, requesting documents | Whether the work is already done |
| Opening meeting | Reading the room | How the day gets read |
| Documentation review | Sampling the whole audit period | Whether the system ran |
| Interviews | Checking documents against people | Most of your result |
| Site visit | Described controls against real ones | Whether paper matches work |
| Closing and report | Scoring, findings, next steps | What you fix and by when |
Scroll the table sideways to see every column. The first column stays in place.
Before the auditor arrives
The audit gets scheduled, the scope gets agreed, and a document request lands in your inbox before anybody shows up. That request is not a formality. What you send in advance is the first sample the auditor takes.
Here is the uncomfortable part. By the time the audit is booked, the work is mostly already done or already not done. The audit period has been running long before anyone picked a date. Every month inspections did not happen, every action that never closed, every ticket that quietly expired, all of it is already in the record. You are not preparing. You are finding out.
Which is why an honest self audit beats a month of tidying. The COR audit readiness checklist walks the same ground the auditor walks.
The opening meeting
Short, and more important than it looks. The auditor explains what they will do, in what order, and who they need access to. You confirm scope, sites and availability.
One piece of practical advice: the most senior person available should be in that room and should stay for the whole meeting. Not drop in, say something about safety being a priority, and leave for a call.
Management commitment is something the auditor is assessing, and this is the first place they get to observe it rather than read about it. If the owner cannot spare the time for the audit of their own safety program, the auditor carries that into every interview afterward. Absence is an answer.
The documentation review
This is where most of the clock goes, and the part people picture least accurately. The auditor is not ticking boxes against a table of contents. They are sampling.
That means they pick awkward dates on purpose. A random week from well over a year ago. The middle of your busiest season. The month a supervisor left. Then they ask for that week's field level hazard assessments, that month's inspections, the corrective actions that came out of them, and the training records for the crew on shift.
Gaps cluster exactly there. Nobody's records are thin last month. They are thin in the seam where somebody quit or where a season buried everyone.
The other thing being measured is one nobody warns you about: speed of retrieval. Taking twenty minutes to find a field card answers a different question, which is whether that document is part of how you operate or was assembled for the occasion. A record you hunt for was probably never used.
Auditors also read for contradictions. Your program says monthly inspections and the file has eight for the year. Those are findings your own documents created.
The interviews
This is the part people dread, and the part that decides most audits.
Start with the thing that surprises people most: the auditor chooses who they talk to. Not you. They ask for workers, supervisors and senior management, usually separately so nobody's answer is shaped by who else is in the room. Steer them toward your best communicators and they will notice, then ask for somebody else.
The questions are plain and specific:
- What hazard assessment did you do this morning?
- How would you refuse unsafe work here?
- Who is the first aid attendant on this crew?
- What happened the last time you reported a hazard?
- Have you ever been discouraged from reporting something?
Nothing there is a trick. That is the point. A worker who uses the program answers without thinking about it.
Which is why you cannot coach your way through this. Coached answers sound coached. They come out in program language instead of the worker's own words, they are identical across three people, and they fall apart on the second question. Worse, the attempt is itself something the auditor can write down.
Across the whole visit the auditor cross checks three sources: what your documents say, what your people say, and what they observe on site. A contradiction between any two is worth more than any single document, because it tells them which one is true. A complete binder your crew does not recognize scores as a system that exists on paper.
The COR audit questions page goes through the specific questions and what each one is testing.
The site visit
Shorter than almost everybody expects, and aimed at something narrower. The auditor is not grading your housekeeping. They are checking one thing: are the controls described in your documents the controls actually in use? The site walk closes the loop between the paper and the work.
Here is the mismatch that gets found. Your procedure for backing heavy equipment in a congested area requires a spotter. On site the operator backs up on his own, nobody is positioned for it, and asked when they last used a spotter for that task, the honest answer is that they do not. The site was clean. The finding is that a written control is not a real control, and it lands against more than one audit element, because it touches hazard control, training and supervision at once.
The reverse counts in your favour. A muddy site where the crew can point at the field card that explains the barricade reads as a working program.
The closing meeting and the report
At the closing meeting you get a verbal summary: the auditor's general impression, where they saw strength, and the significant gaps they intend to write up. They are normally careful not to give you a number on the day, because the report gets reviewed and scored before anything is official.
The written report comes later. It scores you against your certifying partner's audit elements, and the thresholds are set by that partner, not by the auditor sitting across from you. Where findings are recorded, there is normally a defined process and a set period for addressing them and showing what you did. Ask your partner for the current version, because it differs between partners.
What findings actually feel like
The reframe that helps most is this: the audit reports what your program actually is. It does not create the gaps. It finds them. Which gives you the only real measure of readiness. If the findings are a surprise to you, the problem is not the audit. It is that you did not know what your own program looked like.
A small number of findings on a genuinely functioning program is normal. Nobody expects zero, and auditors are far more forgiving of a gap you already identified, dated and assigned than most people expect.
What hurts is a pattern. The same weakness across several elements, because it is one root problem wearing different hats. Or evidence that only exists for the recent past, which tells the auditor exactly when somebody started caring.
The five things I would fix before any audit
If you have limited time, this is where I would spend it.
- Corrective actions found but never closed. The most common finding there is. Something got identified, assigned, and nobody followed up. Put every action from every source in one register with a name, a date and a verification column.
- Evidence gaps in the middle of the period. Not at the end, in the middle. Find the month a key person left or the season that swallowed the paperwork, because that is where the auditor will look.
- Expired tickets in active use. Check this today. It is the easiest finding in the world to hand somebody.
- Formal and field level hazard assessments that do not reference each other. Auditors look for that link specifically and it is often just missing. The difference between formal and field level assessments is the most commonly muddled part of a safety program.
- A program that lives entirely with one person. If one person is the only one who knows where anything is, you do not have a management system. You have that person. Auditors find this in interviews early.
Before your audit
Go find your own findings first. That is the whole job. The COR audit readiness checklist is a free download, no email required, and the template library has the field level card, the formal hazard assessment worksheet and the corrective action tracker on the same terms.
If the honest answer is that the program is not there yet, that is the work we get called in for, and the pricing page explains what a program build involves.
Questions people ask about this
What happens during a COR audit?
Does a COR auditor walk my site looking for hazards?
Who does the auditor interview during a COR audit?
What happens after the COR audit is finished?
How do I know if I am ready for a COR audit?
Next step
Take the templates and use them, whether or not you ever talk to us. If you would rather not build the program yourself, we will build it inside the app and keep it current.