A process safety management audit is element-driven, and that structure is a gift to anyone preparing for one because it tells you the order of the work in advance. The elements cover the information about the process itself, the hazard analysis, the operating procedures, training, contractors, pre-startup review, mechanical integrity, hot work, management of change, incident investigation, emergency planning, compliance audits and trade secrets. Each element has a characteristic evidence set and a characteristic failure, and preparing element by element, oldest evidence first, finds the gaps in an order that matches how they will be found on the day.
Process safety information is the foundation everything else rests on
If the drawings, the chemical data, the design basis and the equipment specifications are out of date, then the hazard analysis built on them is out of date too, and so are the procedures. Auditors know this, so they test the information first, usually by walking the plant with a drawing and finding the difference. A single unrecorded field modification propagates into findings against several elements at once, which is why an information gap is disproportionately expensive and why a drawing reconciliation is the highest-value preparation task available.
Hazard analysis and its recommendations
The analysis needs to be current for the process as it now runs, revalidated on schedule, and led by someone competent with a team that includes operating experience. The finding that recurs is not the analysis itself but its recommendations: raised, recorded, and then left open for years without a resolution or a documented decision to reject them. Sort the recommendation log by age before an auditor does, and either close them, reject them with reasoning, or record the plan and its date.
Mechanical integrity and management of change, the two that bite
Mechanical integrity is tested through inspection and test records against the written programme, with attention to deficiencies found and how long they took to correct. Management of change is tested by finding a change that happened and asking for the record. Both fail in the same way, which is that the paperwork keeps pace during quiet periods and falls behind during busy ones, so sampling should deliberately target the busiest period in the audit window rather than averaging across it.
The compliance audit element, which audits your auditing
The standard requires the covered process to be audited at a stated interval, by people knowledgeable in the process, with the findings documented, responded to and the deficiencies corrected. That means your previous audit report and its closure evidence are themselves audit subjects, and a previous audit with open findings is a finding in its own right. Retaining the reports for the required period is part of it, and lost previous reports are a straightforward and entirely avoidable failure.
Questions people ask about process safety management audit
How often does a PSM audit have to happen?
The standard sets a required interval for certifying evaluation of compliance with the covered process requirements, and the audit programme has to meet it. Check the regulation text for your covered processes rather than relying on custom.
Who can perform a PSM audit?
At least one person on the team has to be knowledgeable in the process. That can be an internal person, which is why many sites pair an experienced operator with an external auditor for independence.
Which element produces the most findings?
Mechanical integrity and management of change dominate, with open hazard analysis recommendations close behind. All three share a cause, which is that they fall behind when the plant is busy.
Does a PSM audit cover the whole site?
It covers the processes that meet the coverage criteria in the regulation. Auditing everything is not required and dilutes the effort; the scoping decision itself should be documented and defensible.