Are WHS Consultants Always ISO Audit-Ready?
Honestly, No.
This week, Red Insight will be sitting on the other side of the audit table as our own Integrated Management System is audited against ISO 45001, ISO 9001 and ISO 14001.
And honestly, we are not as ready as we would like to be.
That does not mean our management system is not functioning or that we do not know where we stand. We know which actions remain open, which improvements have taken longer than planned and where we want our system to be stronger.
We spend our days helping clients strengthen their systems, manage risk, respond to audit findings and prepare for certification. But, like the businesses we work with, we operate in the real world. Client commitments, workforce changes, legislative updates, new technology and the day-to-day demands of running a business all compete for time and attention.
Some of our own internal reviews, actions and planned improvements are not as far progressed as we intended them to be before this audit. There is a certain irony in an ISO consultancy experiencing its own pre-audit scramble. But there is also an important lesson in it.
Certification does not mean your system is finished
Red Insight’s journey began with an independent ISO 45001 gap analysis in 2020. At the time, 12 of the 34 requirements assessed were identified as not implemented. We had work to do.
Over the following two years, we developed and strengthened our management system and expanded it to incorporate quality and environmental management. In 2022, Red Insight achieved certification across ISO 45001, ISO 9001 and ISO 14001.
That was not the end of the journey.
Our Integrated Management System continued to be independently audited and improved as the business evolved. In 2025, Red Insight was recertified across all three standards.
And the system is still not finished. It never will be.
Businesses change. People leave and join. Legislation changes. New risks emerge. Technology changes. Priorities shift. Things that worked two years ago may no longer be the best way of doing them. A management system has to change with the organisation it is there to support.
Having open actions does not mean your system has failed
This is something we regularly remind our clients and, occasionally, need to remind ourselves. Going into an audit with open actions or identified areas for improvement is not, in itself, a sign of a poor management system.
The important questions are: Have they been identified? Is the risk understood? Has responsibility been assigned? Is there a plan to address them? If something has not happened when originally intended, do you understand why?
There is a significant difference between an organisation that has gaps it does not know about and one that can see where improvement is needed and is actively working through it.
A good management system should help you see where the business needs attention, not help you hide it.
Audits are not about putting on a performance
There can be enormous pressure in the weeks before an ISO audit to make everything look perfect.
Registers get reviewed. Actions suddenly move. Documents that have been sitting in draft are finalised. People start asking questions about records they have not thought about for six months.
We understand that pressure because this week we are experiencing some of it ourselves. But an audit should not be a performance staged once a year for an auditor. If something has fallen behind, the useful question is why.
Was the timeframe realistic? Did priorities change? Was responsibility clear? Were the right resources available? Has the process stopped working effectively? Those answers tell you far more about the health of a management system than racing to close an action simply because the auditor is coming.
Sometimes the consultant is the client
Maintaining our own certified Integrated Management System means Red Insight goes through the same process our clients do.
We prepare for audits. We have uncomfortable conversations about overdue actions. We find things we could have done better. We respond to audit findings when they arise. We make improvements. And sometimes we look at the calendar and wonder how the audit arrived quite so quickly.
Knowing the ISO standards does not make those realities disappear. If anything, experiencing the process ourselves reinforces why we approach our clients’ management systems the way we do. The objective is not perfection. It’s having a system that reflects the business, identifies and manages risk, creates accountability and drives continual improvement.
So, this week, we will sit down with our auditor with a system that is not perfect. We know where we need to improve. And if the audit identifies something we have missed, that is valuable too.
Because an audit is not about proving that your management system is perfect. It is about assessing whether it is working as intended, identifying where it is not and giving the business another opportunity to improve.

