What documents does a COR auditor ask for?
Last updated: Written by Blake Cowan, NCSO
What gets requested, roughly in the order it gets requested, and what separates a weak version of each document from a strong one.
The short answer
A COR auditor asks first for the signed health and safety policy, written roles and responsibilities, formal hazard assessments for your main tasks, and worker orientation records. Those four establish whether a management system exists at all. Everything after that is evidence it ran continuously, sampled across the whole audit period.
There is a moment in every audit where the auditor asks for something and you either produce it in about a minute or you start explaining. The explaining is the finding. Not the delay itself, but what the delay reveals about whether the document was part of how you work or was assembled for the occasion.
What follows is what actually gets requested, in roughly the order it gets requested, and what separates a weak version from a strong one. I have been on both sides of this.
The first four requests
These establish that a management system exists. If any of the four is weak, the auditor now expects the rest to be weak, and reads everything afterward in that light.
| Document | Why the auditor wants it | Weak version | Strong version |
|---|---|---|---|
| Health and safety policy | To see whether safety has authority, and at what level | Unsigned, undated, or signed by the safety coordinator. Generic wording that could belong to any company | Signed and dated by the most senior person, reviewed on your stated cycle, with the review recorded even in years when nothing changed |
| Roles and responsibilities | To see whether duties are assigned or assumed | One paragraph saying everyone is responsible for safety | Specific duties for senior management, supervisors, workers and contractors, and the people in those roles can describe their own duties without reading them |
| Formal hazard assessments | To see whether you have assessed the work you actually do | Bought in a binder, or inherited from a previous employer. Task names that do not match your operation | Assessments naming your tasks, with participants listed including workers who do the job, controls following the hierarchy, and a dated review history |
| Worker orientation records | To see whether the program reaches the worker | A signature under the words "orientation completed" | A record showing what was covered, by whom, when, site specific content, and a competency verification for the tasks assigned |
Scroll the table sideways to see every column. The first column stays in place.
On orientation specifically: it is the most examined document in most audits. It is the seam between your program and the person doing the work, and it is where a weak program shows first.
The evidence that the system kept running
Once the auditor accepts a system exists, they test whether it ran continuously. Every one of these gets sampled from across the audit period, not from the recent past.
| Document | Why the auditor wants it | Weak version | Strong version |
|---|---|---|---|
| Field level hazard assessments | To see hazard assessment happening daily, in real conditions | Photocopied and reused. Same hazards regardless of task or weather. Signed by one person for a crew of six | Task and condition specific, completed before work started, referencing the formal assessment, signed by everyone who took part, with changes during the shift recorded |
| Inspection reports | To confirm your stated frequency actually happened, and deficiencies closed | Twelve identical reports with nothing found. Deficiencies with no owner or date | Real findings, varied by site and season, each deficiency assigned with a due date and a verified closure, plus positive observations |
| Incident and near miss reports | To see whether reporting happens and where causes are found | Injuries only, no near misses. Every investigation concluding worker error | Near misses reported in numbers, contributing factors across people, equipment, environment, process and management systems, and a root cause your system controls |
| Corrective action records | To see that what you found got fixed and verified | A list of open items with no dates, or items marked "ongoing" | One register from every source, each action assigned, dated, closed and verified by somebody other than the person who did the work |
| Training records and matrix | To confirm competency for the work assigned | A pile of certificates and no way to tell who needs what | A matrix of role against requirement, current certificates, no expired tickets in use, and competency verified by observation rather than assumed from a ticket |
| Committee or representative records | To see worker participation is real | Attendance lists only | Minutes showing issues raised, actions taken, and issues closed, with a visible trail from a worker concern to a resolution |
| Emergency plans and drill records | To see the plan is site specific and has been practised | One generic plan for all sites, no drills | Site specific plans with current contacts and muster points, drills recorded with dates and participants, and workers who can describe the plan without reading it |
| Management review | To see the system is examined and adjusted | Nothing, or a signature on last year's document | An annual review with findings, statistics interpreted rather than just listed, and an action plan with owners |
Scroll the table sideways to see every column. The first column stays in place.
What the auditor is actually testing when they ask
This is the part that is not written in any protocol, and it is what turns a good program into a good audit result.
Speed of retrieval. How long it takes you to produce a specific record for a specific worker on a specific date. This is a proxy for whether the document is part of your operation or was assembled for the audit. Somebody hunting through four systems and a filing cabinet has answered the question before finding the file.
Consistency across the period. They will deliberately pick an awkward date: a random week eighteen months back, the middle of your busiest season, the month a supervisor left. Gaps cluster in exactly those places.
Agreement between three sources. Documents, interviews, and site observation have to tell the same story. The auditor is looking for contradictions between them, and a contradiction is worth more to them than any single document.
Attribution. A record has to be traceable to a person and a time. An unsigned, undated form is close to worthless as evidence, however good its content.
Closure. Not that you found the hazard, but that something happened afterward, somebody's name is on it, and somebody verified it worked.
The pattern behind almost every finding
After enough of these, the findings collapse into one sentence: the evidence was created for the audit rather than by the work.
Everything else follows from it. Photocopied field level cards, inspections that found nothing, corrective actions that never closed, workers who do not recognize their own hazard assessments, records that stop when somebody went on holiday. They are all the same failure showing up in different elements.
Which points at the only durable fix. If producing a record is a separate administrative task that somebody has to remember, it will not survive a busy August, a staff change, or a bad winter. If it is a by product of doing the work, it survives all three.
That is the reasoning behind how Cor Pathway 360 handles evidence: the form the crew fills out at the tailgate is the audit record, mapped to your certifying partner's audit elements as it is collected, rather than assembled from four places the week before the auditor arrives.
A short list of things not to do
- Do not backdate anything. Auditors cross check documents against each other and against interviews. It gets found, and the consequence is not a lower score.
- Do not present a blank template as a completed document. It is obvious.
- Do not coach workers on interview answers. Coached answers sound coached, and attempting it is itself a finding. A crew that uses the program answers naturally.
- Do not hide a gap. Say it is missing, say what you are doing about it, and show the dated action. Auditors deal with honest gaps constantly and they are far more forgiving than most people expect.
- Do not assume last audit's protocol applies. Protocols and their element naming change between versions and between partners. Ask for the current one.
Get your documents in order
The audit readiness checklist walks the same ground an auditor walks, theme by theme, and is a free download with no email required. The template library has the field level card, formal hazard assessment worksheet, incident report, corrective action tracker, orientation checklist and inspection form, in print and editable formats.
If the honest answer is that most of the first four documents do not exist yet, that is the situation we are usually called into. The pricing page explains what a program build involves and what it costs.
Questions about audit documentation
What documents does a COR auditor ask for first?
How far back will an auditor look?
Can I give the auditor digital records instead of paper?
What if a document does not exist?
Does having the documents mean we will score well?
If the first four documents do not exist yet
That is the situation we are usually called into, and it is a normal place to start. We write the program and map the evidence to your certifying partner's audit elements.