They don't always tell you whether people are protected.
NewEra combines rigorous WHS auditing with risk-based assurance to test requirements, follow controls into the work and give leaders a clearer picture of where they can have confidence — and where they should look closer.
Audit the system.
Assure what matters.
Auditing and assurance are related.
But they aren't the same thing.
AUDIT
Tests evidence against defined criteria.
Are requirements being met?
ASSURANCE
Builds confidence around something important to the organisation.
Can we rely on this?
A strong WHS approach needs both.
Audit helps establish conformity.
Assurance helps leaders understand whether the systems and controls they rely upon are actually providing the protection expected of them.
Go beyond the document.
A procedure exists.
A risk assessment is current.
Training records are complete.
Inspections have been conducted.
Actions are closed.
On paper, everything looks good.
But what happens in the work?
NewEra follows requirements beyond the management system.
INTENT
What is expected?
DESIGN
Is the system or control capable of achieving it?
IMPLEMENTATION
Has it been put into practice?
WORK
What actually happens?
EVIDENCE
What demonstrates effectiveness?
CONFIDENCE
How much reliance should we place on it?
The document is evidence.
It isn't the end of the enquiry.
Start with the question.
Before deciding what to audit or assure, ask:
What do we need confidence about?
Compliance?
Management-system effectiveness?
A particular critical risk?
A control?
A contractor?
A project?
A site?
An emerging concern?
Implementation of a new process?
Readiness for certification?
A board-level risk?
The question should shape the assurance.
Not the other way around.
Assurance should follow risk.
Not everything deserves the same level of scrutiny.
A low-consequence administrative process and a control relied upon to prevent multiple fatalities should not automatically receive the same assurance effort.
NewEra uses risk to help determine:
DEPTH
How deeply should we test?
FREQUENCY
How often do we need evidence?
COVERAGE
Where and across how much of the organisation?
INDEPENDENCE
Who should provide the assurance?
EVIDENCE
What would genuinely create confidence?
Assurance should follow risk, reliance and uncertainty.
Follow the control.
Where serious harm is possible, assurance should get close to the protection being relied upon.
Ask:
What is the critical control?
What must it do?
What conditions must exist for it to work?
What evidence demonstrates those conditions?
Is the control available when required?
Is it correctly implemented in the work?
Is it reliable enough for the serious-harm pathway?
This moves assurance from:
“Was the process completed?”
to:
“Can we rely on the protection?”
Design effectiveness.
Operating effectiveness.
These are different questions.
DESIGN EFFECTIVENESS
Can it work?
Is the system or control appropriately designed?
Is the requirement technically sound?
Could it achieve the intended purpose under foreseeable conditions?
OPERATING EFFECTIVENESS
Does it work here, now?
Is it available?
Implemented?
Used correctly?
Maintained?
Performing as intended?

