This article was originally published on LinkedIn on 6 August 2025. It has been moved to the riskfacilitator Insights library so the website remains the permanent source.[1]

Audits are often seen as the safety net. They are treated as evidence that risks are managed, systems are followed, and everything is under control.

But a recent peer-reviewed study by Ben Hutchinson, Professor Sidney Dekker, and Dr Andrew Rae challenges that assumption in a powerful way. Published in Process Safety Progress (2024), the paper is titled:

“How audits fail according to accident investigations: A counterfactual logic analysis.”

Their team reviewed over 400 major accident investigation reports across oil and gas, chemicals, mining, and aviation. What they found should prompt all of us, leaders, advisors, and safety professionals, to re-examine how we view audit effectiveness.

Only 44 reports mentioned audits at all. And when they did, audits had often failed , quietly, subtly, and completely.

That absence is not just a data point. It is a signal.

So, How Do Audits Fail?

In the 44 reports that referenced audits, the researchers found they did not fail through action. They failed through inaction. They failed silently.

Audits:

  • Misread or downplayed emerging threats
  • Identified issues but failed to ensure timely action
  • Focused on paperwork over practice
  • Delivered false confidence to decision-makers

The study grouped the failures into four categories:

  1. Failure to Understand
  2. Failure to Act
  3. Failure to Manage
  4. Failure to Focus

These patterns reflect what many of us have seen firsthand. Audits that validate documents but miss the operational realities. Reports that look clean while controls are eroding.

Audits That Fail Silently

The most dangerous audit is not one that identifies failure. It is one that fails silently while praising performance.

In many of the reviewed incidents:

  • Auditors ticked every box
  • Reports confirmed compliance
  • Controls were assumed to be working

Then the incident occurred. The harm happened. The system failed. But the audit had passed.

The paper describes this as surface compliance. When the presence of a system is mistaken for the performance of the system.

Why This Matters

Across high-risk environments, there’s often an assumption that if an audit has been completed, risk is under control. But that confidence is frequently misplaced.

Audits are not confirmation that systems are working as intended. They are simply a snapshot, and their usefulness depends entirely on what they focus on, how they’re conducted, and what actions follow.

We need to ask:

  • Are our audits targeting the right risks?
  • Do they reveal the difference between how work is imagined and how it’s actually done?
  • Are they surfacing weak signals, or just validating what’s already known?
  • Do they challenge the system, or simply reassure it?

Takeaways for Risk Professionals

This paper does not suggest we abandon audits. It suggests we reclaim their value.

“An ideal audit should sensitise an organisation to emerging risks, not lull it into comfort.” – Hutchinson, Dekker & Rae (2024)

Audits must shift focus:

  • From validating compliance to verifying capability
  • From reviewing systems to interrogating practice
  • From checklists to conversations about risk, drift, and context

If we don’t evolve how we audit, we risk repeating old patterns, just with better formatting.

📖 Reference & Credit

Ben Hutchinson, Sidney Dekker, Andrew Rae 📄 How audits fail according to accident investigations: A counterfactual logic analysis Published in: Process Safety Progress, 43(3), 441–454 🔗 https://doi.org/10.1002/prs.12579[2]

References

  1. Paul Chivers, Ticked Every Box, Missed Every Risk: What Major Accidents Reveal About Audit Blind Spots, LinkedIn, originally published 6 August 2025.
  2. https://doi.org/10.1002/prs.12579, source linked in the original article, accessed 10 August 2026.