They don't always tell you whether people are protected.

NewEra combines rigorous WHS auditing with risk-based assurance to test requirements, follow controls into the work and give leaders a clearer picture of where they can have confidence — and where they should look closer.

Audit the system.

Assure what matters.

Auditing and assurance are related.

But they aren't the same thing.

AUDIT

Tests evidence against defined criteria.

Are requirements being met?

ASSURANCE

Builds confidence around something important to the organisation.

Can we rely on this?

A strong WHS approach needs both.

Audit helps establish conformity.

Assurance helps leaders understand whether the systems and controls they rely upon are actually providing the protection expected of them.

Go beyond the document.

A procedure exists.

A risk assessment is current.

Training records are complete.

Inspections have been conducted.

Actions are closed.

On paper, everything looks good.

But what happens in the work?

NewEra follows requirements beyond the management system.

INTENT

What is expected?

DESIGN

Is the system or control capable of achieving it?

IMPLEMENTATION

Has it been put into practice?

WORK

What actually happens?

EVIDENCE

What demonstrates effectiveness?

CONFIDENCE

How much reliance should we place on it?

The document is evidence.

It isn't the end of the enquiry.

Start with the question.

Before deciding what to audit or assure, ask:

What do we need confidence about?

Compliance?

Management-system effectiveness?

A particular critical risk?

A control?

A contractor?

A project?

A site?

An emerging concern?

Implementation of a new process?

Readiness for certification?

A board-level risk?

The question should shape the assurance.

Not the other way around.

Assurance should follow risk.

Not everything deserves the same level of scrutiny.

A low-consequence administrative process and a control relied upon to prevent multiple fatalities should not automatically receive the same assurance effort.

NewEra uses risk to help determine:

DEPTH

How deeply should we test?

FREQUENCY

How often do we need evidence?

COVERAGE

Where and across how much of the organisation?

INDEPENDENCE

Who should provide the assurance?

EVIDENCE

What would genuinely create confidence?

Assurance should follow risk, reliance and uncertainty.

Follow the control.

Where serious harm is possible, assurance should get close to the protection being relied upon.

Ask:

What is the critical control?

What must it do?

What conditions must exist for it to work?

What evidence demonstrates those conditions?

Is the control available when required?

Is it correctly implemented in the work?

Is it reliable enough for the serious-harm pathway?

This moves assurance from:

“Was the process completed?”

to:

“Can we rely on the protection?”

Design effectiveness.

Operating effectiveness.

These are different questions.

DESIGN EFFECTIVENESS

Can it work?

Is the system or control appropriately designed?

Is the requirement technically sound?

Could it achieve the intended purpose under foreseeable conditions?

OPERATING EFFECTIVENESS

Does it work here, now?

Is it available?

Implemented?

Used correctly?

Maintained?

Performing as intended?