- What Most Organizations Get Wrong About Audits
- How COR Audits Actually Work
- How ISO 45001 Audits Work
- Five Places Where Programs Consistently Fall Short
- Gap 1 — Formal Hazard Assessments That Do Not Match What Happens in the Field
- Gap 2 — Training Records That Show Attendance but Not Competency
- Gap 3 — Emergency Response Plans That Are Generic and Undrilled
- Gap 4 — Incident Investigations That Close With ‘Worker Error’
- Gap 5 — Management Review That Is a Meeting on the Calendar
- What Auditors Find That Organizations Miss
- How to Prepare for an Audit — and Why That Is the Wrong Goal
- Your Next Step
- Summary
- Frequently Asked Questions
- What is the passing score for a COR audit in Alberta?
- What are the three methods a COR auditor uses to evaluate a safety program?
- What is the difference between a Formal Hazard Assessment and a Field Level Hazard Assessment?
- Does passing a COR audit mean my safety program is working in the field?
- How does ISO 45001 differ from COR in terms of what it audits?
- How does Fortriss help organizations prepare for COR or ISO 45001 audits?
- Sources and Citations
- Kellie Rose Ryder
- Related Posts
- Leave A Comment Cancel reply
TL;DR: Most audit failures are not caused by a bad safety program. They are caused by a good program on paper that nobody on site can describe, demonstrate, or apply under pressure. This article explains how COR and ISO 45001 auditors actually evaluate your system — using three methods, not one — and the five places most programs consistently fall short.
What Most Organizations Get Wrong About Audits
Here is a scenario that plays out more often than most organizations want to acknowledge.
A company prepares for its COR audit. Binders are updated. Training records are organized. The safety manual is reviewed. The team feels ready.
The auditor arrives. Spends three days reviewing documents, walking the site, and interviewing workers. The final score comes back at 68%. The certification does not pass.
The organization is surprised. The paperwork was solid.
That is exactly the problem. Most COR audit failures do not come from having a bad safety program. They come from having a good program on paper that workers on site cannot describe, demonstrate, or apply when the auditor asks them to.
The audit is not checking your binder. It is checking your system — what it says, whether people know it, and whether it is actually being used in the field. Those are three different things. Most programs only prepare for the first one.
This is the conformance gap in audit form. The full explanation of why compliance and conformance must work together is in Why Your Safety Program Passes Audits but Still Puts Workers at Risk — the pillar article for this hub. This spoke article focuses specifically on what auditors look for and where to find your gaps before they find them first.
How COR Audits Actually Work
In Alberta, the Certificate of Recognition (COR) is earned through a formal audit of your health and safety management system. The pass threshold is 80% overall, with a minimum score of 50% in each individual audit element. Maintenance audits in years two and three of your certification cycle require a 60% minimum.
What most organizations underestimate is that a COR audit uses three distinct evaluation methods — and all three carry weight in your score.
- Documentation review. The auditor reviews your written program: policies, procedures, training records, hazard assessments, inspection logs, corrective action records, incident investigations. The question is whether the documents are current, complete, and internally consistent.
- Worker interviews. The auditor speaks directly with workers — supervisors, crew members, safety representatives. The question is whether the people doing the work understand the system, know how to report hazards, and can describe what happens when something goes wrong.
- Site observations. The auditor walks the worksite and watches. The question is whether what is written in the documents matches what is actually happening in practice.
Most organizations prepare extensively for method one. They prepare lightly for method two. They do almost nothing to prepare for method three.
The gap between methods one and three is where most audit scores are lost — and where most incidents live.
How ISO 45001 Audits Work
An ISO 45001:2018 certification audit follows the same fundamental structure: document review, interviews, and site observation. The standard is organized into ten clauses, with the operational requirements concentrated in Clauses 4 through 10.
An ISO 45001 auditor evaluates whether your system genuinely follows the Plan-Do-Check-Act cycle: whether you plan for hazards and risks, implement controls, check that they are working, and act to improve. The audit is looking for evidence of a functioning management system — not just a documented one.
The areas where ISO 45001 auditors most frequently find nonconformances are the same places COR auditors find their lowest scores: worker participation, competency verification, corrective action effectiveness, and management review.
Both certifications are measuring essentially the same thing from different angles: does your safety management system actually work in the real world, or does it exist primarily on paper?
| Feature | COR / SECOR (Alberta) | ISO 45001:2018 |
|---|---|---|
| Issuing body | Government of Alberta + Certifying Partner | Accredited third-party certification body |
| Pass threshold | 80% overall; 50% minimum per element | No percentage threshold; pass/fail on nonconformances |
| Evaluation cycle | 3-year certification; annual maintenance audits | 3-year certification; annual surveillance audits |
| Audit methods | Documentation, worker interviews, site observation | Documentation, worker interviews, site observation |
| WCB premium benefit | Up to 20% rebate through PIR program | Eligible for COR equivalency recognition |
| Primary focus | Alberta OHS Act and provincial standards | International OHS management system requirements |
| Worker participation | Required, audited through interviews | Required; Clause 5.4 is a specific audit element |
Both certifications have real value. Both tell you what your program looked like on audit day. Neither tells you what it looks like on day 200 of your certification cycle — which is why ongoing conformance matters as much as certification readiness.
Five Places Where Programs Consistently Fall Short
These are the gaps that appear most frequently in safety program assessments and audit preparation reviews. They are not unique to any one organization. They are structural — they tend to develop in programs that were built for certification rather than built for field performance.
Gap 1 — Formal Hazard Assessments That Do Not Match What Happens in the Field
A Formal Hazard Assessment (FHA) is written in advance for a task type or work area. It identifies hazards and controls for that category of work. Most certified organizations have FHAs on file.
What auditors also look for is the Field Level Hazard Assessment (FLHA) — the daily, task-level check that workers complete before starting the specific work in front of them that day. This is where the gap appears. The FHA is in the site trailer. The FLHA is missing, incomplete, or completed after the work has already started.
Hazard identification in the field is not a filing exercise. It is a daily practice. When the practice does not match the documentation, both the audit score and the actual safety outcome suffer.
Gap 2 — Training Records That Show Attendance but Not Competency
Training records demonstrate that workers were present for a session. They do not demonstrate that workers can apply what they learned.
Auditors interview workers specifically to check this. A worker who attended LOTO training six months ago but cannot describe the steps when asked in the field has a competency gap — regardless of what the training record shows. This is one of the most consistent gaps in programs that rely on attendance records alone.
This connects directly to what we covered in 5 Signs Your Safety Supervisors Are Checking Boxes Instead of Changing Behavior — supervisor-level competency verification is what closes the gap between a training record and an actually competent worker.
Gap 3 — Emergency Response Plans That Are Generic and Undrilled
Emergency response is a dedicated audit element in both COR and ISO 45001. Auditors check for three things: that a plan exists, that workers know what it says, and that it has been practiced.
The most common finding is not that the plan is missing. It is that the plan is a generic template applied across every site, the contacts listed are outdated, and the last drill either never happened or was not documented with an after-action review.
Picture an auditor asking a crew member where the emergency muster point is. The crew member looks uncertain, points in two different directions, and says they think it changed last month. The plan is in the binder. The binder is in the office. The crew is on site. These are three different places.
Gap 4 — Incident Investigations That Close With ‘Worker Error’
Both COR and ISO 45001 require that incident investigations identify root causes and result in corrective actions that prevent recurrence. Auditors look at whether your investigations go deep enough to find system-level causes and whether the resulting corrective actions are implemented and verified.
The gap: investigations that conclude with worker error as the finding, corrective actions that read ‘remind all workers to follow procedure,’ and no evidence that the procedure itself or the conditions that led to the error were changed.
An auditor who reads five consecutive incident investigations and finds the same root cause listed each time is looking at a corrective action process that is producing documents, not corrections.
Gap 5 — Management Review That Is a Meeting on the Calendar
ISO 45001 Clause 9.3 requires a management review at planned intervals — an evaluation by top management of the OHS management system's performance, outputs, and direction. COR includes a similar requirement for leadership accountability.
What auditors find: a management review meeting that happened, minutes that were filed, and no evidence that the review changed anything. No updated objectives. No resource decisions. No documented responses to the data that was presented.
Management review is meant to be the moment when senior leadership evaluates whether the safety system is actually working and directs improvement. When it becomes a scheduled meeting with a fixed agenda that produces no decisions, it has stopped functioning as a management tool.
What Auditors Find That Organizations Miss
The three-method audit structure — documents, interviews, observation — is specifically designed to find the gap between what is written and what is real. Here is what each method tends to surface that the others do not.
| Audit Method | What It Surfaces | Common Finding |
|---|---|---|
| Documentation Review | Whether the written program is complete, current, and internally consistent | Outdated SOPs, unsigned records, missing evidence trails, FHAs not linked to field-level assessments |
| Worker Interviews | Whether workers understand the system, know their rights, and can describe safety procedures | Workers cannot name the hazard controls for their task, do not know the near-miss reporting process, or give conflicting answers about site emergency procedures |
| Site Observation | Whether actual work practices match written procedures and whether controls are functioning | Work proceeding without permits, PPE worn incorrectly or not at all, equipment used outside its rated capacity, hazard controls documented but not in place |
The finding in that third column — actual work practices not matching written procedures — is the conformance gap at audit level. Organizations can score well on documentation and moderately on interviews while failing significantly on site observation. The overall score reflects all three.
How to Prepare for an Audit — and Why That Is the Wrong Goal
Preparing specifically for an audit is a short-term strategy. A well-prepared organization can score 80% on audit day and then watch their actual safety performance drift through the maintenance cycle — because the preparation was for the event, not for the system.
The better goal is to build a safety management system that would pass an audit on any random day of the year. That is a different standard — and it is the one that actually protects people.
Here is what organizations with genuinely strong systems do differently from organizations that prepare for audits:
- They update FHAs and FLHAs when tasks or conditions change — not before audit season.
- They verify worker competency continuously — through observation, coaching, and field checks — not only when training records need to be filed.
- They drill emergency response plans on a scheduled cadence and document the after-action review every time.
- They treat corrective actions as closed only when the root condition has been verified as resolved — not when the form status changes to ‘complete.’
- They run management reviews that produce documented decisions, updated objectives, and resource commitments — not just meeting minutes.
This is exactly what the Fortriss C2C Assessment is designed to reveal. Not audit preparation — a gap map that shows where your system performs on paper, where it performs in the field, and what it would take to close the distance between the two.
The corrective action piece — how to build a system that closes findings reliably rather than logging them — is covered in detail in the final article in this hub: How to Build a Corrective Action Process That Actually Closes Safety Gaps.
PRO TIPS
Pre-audit self-check you can run in one day:
- Walk three active work areas and verify that FLHAs are completed before work starts — not after
- Interview five workers randomly and ask them to describe the hazard controls for the task they are doing right now
- Pull your last three emergency drills and confirm each has a documented after-action review with findings and follow-up items
- Review your last five incident investigations and check whether the corrective actions changed a process, a procedure, or a condition — or just reminded workers to be careful
- Pull your last management review minutes and identify three specific decisions that came out of it. If you cannot find three, the review is not functioning as intended
Your Next Step
If your safety program has passed audits but you still recognize any of the five gaps described in this article, the program is performing on one of three dimensions — not all three.
A Fortriss C2C Assessment covers all three. Documentation review. Field verification. A gap map across 12 service areas with a prioritized 90-day action plan. Delivered in 14 days.
The goal is not audit readiness. The goal is a system that works on any day, under any condition, whether or not an auditor is on site. Book a 20-minute call at fortriss.ca and find out where your system stands today — before the next audit tells you.
Summary
COR and ISO 45001 audits both use three methods: documentation review, worker interviews, and site observation. Most organizations prepare for the first. The second and third are where most scores are lost.
The five gaps that most consistently lower audit scores and real-world safety performance: hazard assessments on file but not completed in the field, training records that show attendance but not competency, emergency response plans that are generic and undrilled, incident investigations that stop at worker error, and management reviews that produce no documented decisions.
Preparing for an audit is the wrong goal. A system strong enough to pass on any random day — not just when the auditor arrives — is the standard that actually protects people and proves itself under pressure.
At Fortriss, COR and ISO 45001 readiness is one of the 12 service areas in every C2C Assessment. We review documentation, verify field behavior, and map the gap between your written program and your actual practice — so you know exactly what to fix and in what order.
Frequently Asked Questions
What is the passing score for a COR audit in Alberta?
Under the Alberta COR program, the certification audit requires a minimum overall score of 80%, with no individual element scoring below 50%. Annual maintenance audits in years two and three of the certification cycle require a minimum score of 60%. Missing either threshold can result in the certification lapsing.
What are the three methods a COR auditor uses to evaluate a safety program?
Documentation review, worker interviews, and site observations. All three carry weight in the final score. Documentation checks whether your program is written correctly. Interviews check whether workers understand and can apply it. Observations check whether what is written matches what is actually happening on site. Most organizations only prepare for the first.
What is the difference between a Formal Hazard Assessment and a Field Level Hazard Assessment?
A Formal Hazard Assessment (FHA) is a written document prepared in advance for a category of work or a work area. A Field Level Hazard Assessment (FLHA) is the daily, task-specific check a crew completes before starting the actual work in front of them. COR auditors check for both. The most common finding is that FHAs are on file while FLHAs are missing, incomplete, or filled in after work has already started.
Does passing a COR audit mean my safety program is working in the field?
Not necessarily. A COR audit evaluates your system on the days it is assessed. Between audit cycles, field practice can drift significantly from what was verified. Organizations can hold valid COR certification while having real conformance gaps on active sites. The certification tells you what your program looked like on audit day — ongoing field verification tells you what it looks like every other day.
How does ISO 45001 differ from COR in terms of what it audits?
Both standards use documentation review, interviews, and site observation. The key difference is scope and recognition. ISO 45001:2018 is an international standard applicable to organizations of any size and sector globally. COR is an Alberta-specific program administered through Certifying Partners and tied to WCB premium incentives. In Alberta, ISO 45001 certification can be used to apply for COR equivalency recognition through the Partnerships in Injury Reduction program.
How does Fortriss help organizations prepare for COR or ISO 45001 audits?
The Fortriss C2C Assessment includes COR and ISO 45001 readiness as a core service area. The review covers documentation completeness, field verification of how procedures are applied on site, worker competency checks, and corrective action effectiveness. The output is a gap map and prioritized action plan — so you know what to address before an auditor identifies it for you.
Sources and Citations
- Government of Alberta — Certificate of Recognition (COR). COR audit requirements, pass threshold, and certification process. https://www.alberta.ca/get-certificate-recognition
- Government of Alberta — Maintain or Renew a COR. Maintenance audit requirements including the 60% minimum threshold. https://www.alberta.ca/maintain-renew-COR.aspx
- ISO 45001:2018 — Occupational Health and Safety Management Systems. International OHS management system standard requirements and audit framework. https://www.iso.org/standard/63787.html
- Safety Evolution — How to Pass a COR Audit in Canada. COR audit methods, common failures, and field-practice gap analysis. https://www.safetyevolution.com/blog/how-to-pass-cor-audit-canada
- CCOHS — Health and Safety Program Elements. Framework for effective OHS program design and implementation in Canada. https://www.ccohs.ca/oshanswers/hsprograms/basic.html
- Government of Alberta — Partnerships in Injury Reduction (PIR). COR program structure and WCB premium rebate information. https://www.alberta.ca/partnerships-injury-reduction
- Alberta WCB — 2024 Workplace Fatality Statistics. Provincial fatality data and industry sector breakdown. https://open.alberta.ca/publications/workplace-injuries-illnesses-and-fatalities
- Fortriss Safety Solutions — C2C Framework. Compliance to Conformance assessment covering COR and ISO 45001 readiness. https://fortriss.ca
All external links verified as of May 2025. Alberta government sources are updated continuously.
Kellie Rose Ryder
Founder and CEO, Fortriss Safety Solutions Inc.
Kellie Rose Ryder is an occupational health, safety, and environmental systems professional focused on closing the gap between written requirements and how work is performed in the field. As the founder and CEO of Fortriss Safety Solutions Inc., she helps organizations build practical safety systems that protect workers, support compliance, and hold up under real operating conditions. (LinkedIn)
Her work connects assessments, procedures, training, contractor controls, field verification, and ongoing performance measurement. Through Fortriss, Kellie helps employers identify hidden safety gaps, turn findings into clear actions, and create systems aligned with standards such as COR, ISO 45001, CSA, and applicable NFPA requirements. (Fortriss Safety Solutions)
Kellie’s approach is direct and practical: safety should do more than satisfy paperwork requirements. It should guide daily decisions, strengthen workplace culture, reduce operational risk, and provide reliable evidence that people and processes are protected. (Fortriss Safety Solutions)

Leave A Comment