A knock on the door from a SafeWork inspector is something every safety manager should be prepared for — even if it never happens. SafeWork inspectors have broad powers to enter workplaces, request documents, interview workers, and issue improvement or prohibition notices. In the context of drug and alcohol testing, they will want to see evidence that your program is lawful, properly implemented, and effectively managed.
The organisations that fare well in audits are not necessarily the ones with the most sophisticated programs. They are the ones with the best documentation. This guide covers what inspectors look for, the most common deficiencies, and how to maintain audit readiness year-round.
What SafeWork Inspectors Look For
When a SafeWork inspector examines a drug and alcohol testing program, they are assessing whether the organisation has met its obligations under the Work Health and Safety Act 2011 and the Work Health and Safety Regulations 2011 (or their state/territory equivalents). Specifically, they are looking at:
The Policy
- Does a written policy exist? The absence of a formal policy is the most fundamental deficiency.
- Is it current? A policy that has not been reviewed in five years may not reflect current legislation, Australian Standards, or workplace conditions.
- Was it developed through consultation? Evidence of worker consultation is essential. Inspectors may ask for meeting minutes, consultation records, or HSR endorsement.
- Has it been communicated? Inspectors will ask how employees were made aware of the policy and may request acknowledgement records.
The Testing Process
- What testing types are conducted? Inspectors will want to see that the program covers the testing types appropriate to the risk profile — typically random, for-cause, post-incident, and pre-employment at minimum.
- How are selections made? Evidence that random selections are genuinely random — typically software-generated with an audit trail.
- Who conducts the testing? Whether internal staff or an external provider, the inspector may ask about qualifications, training, and compliance with Australian Standards.
- What standards are followed? AS/NZS 4308 (urine) and AS 4760 (oral fluid) are the relevant Australian Standards. The inspector may ask whether your testing process complies with these standards.
Record Keeping
- Are testing records maintained? A complete record of all tests conducted, including results, dates, locations, and the identity of the tester.
- Are records accessible? The inspector may request records during the visit. If they are scattered across spreadsheets, emails, and filing cabinets, retrieval will be slow and may reveal gaps.
- Is there an audit trail? Digital systems that log who accessed records, when, and what changes were made are viewed more favourably than manual systems with no access controls.
Response to Positive Results
- What happens after a positive result? Inspectors will want to see a documented process — stand-down, confirmation testing, EAP referral, disciplinary action, and return-to-work.
- Is the response consistent? If the organisation treats positive results differently based on the employee’s seniority, tenure, or relationship with management, this is a significant concern.
Your Documentation Checklist
Use this checklist to assess your audit readiness. Every item should be accessible within minutes, not days.
Policy and Governance
- Current drug and alcohol policy (signed, dated)
- Evidence of legal review
- Consultation records (meeting minutes, feedback, HSR/union endorsement)
- Employee communication records (acknowledgement forms, induction records, email distribution evidence)
- Policy review schedule and evidence of review
Testing Records
- Complete register of all tests conducted (date, time, location, employee, testing type, result)
- Selection event records (pool, method, selection percentage, employees selected)
- Chain of custody documentation for all confirmation tests
- For-cause testing observation notes
- Post-incident testing records linked to incident reports
Provider and Equipment
- Testing provider service agreement
- Provider qualifications and accreditations
- Confirmation laboratory NATA accreditation evidence
- Equipment calibration and expiry records (if testing in-house)
- Tester training and certification records
Training
- Supervisor impairment identification training records
- Tester training and competency records
- Employee induction records covering the drug and alcohol policy
Response and Support
- EAP service agreement and referral records
- Return-to-work agreements and monitoring records
- Disciplinary action records for positive results
- Evidence of consistent application of consequences
Common Deficiencies Found in Audits
Based on regulatory actions and industry feedback, the most common deficiencies include:
- No policy, or an outdated policy. This is the single most common finding. If your policy has not been reviewed in the past two to three years, schedule a review immediately.
- No evidence of consultation. The policy exists, but there is no documentation showing that workers were consulted during its development. Even if consultation occurred, without records it cannot be demonstrated.
- Incomplete testing records. Tests were conducted but records are missing, inconsistent, or difficult to locate. Manual systems are particularly vulnerable to this deficiency.
- No for-cause testing. The policy provides for for-cause testing, but there are no records of it ever being conducted — suggesting that supervisors are either not trained or not willing to trigger it.
- Inconsistent consequence management. Positive results for some employees led to termination while others received a warning. Without a documented and defensible rationale for the difference, this creates significant legal and compliance risk.
- Expired equipment or lapsed provider agreements. Testing equipment that is past its expiry date, or a provider agreement that has lapsed without renewal, undermines the validity of any testing conducted.
Maintaining Audit Readiness Year-Round
Audit readiness should not require a frantic preparation effort when an inspection is announced. It should be the natural state of your program. The key to achieving this is:
- Digital record keeping. A purpose-built testing management platform that captures data at the point of entry eliminates the compilation and retrieval problems that plague manual systems.
- Regular self-audits. Conduct an internal review of your documentation quarterly. Use the checklist above. Identify and close gaps before an inspector finds them.
- Centralised document management. Keep all policy documents, training records, provider agreements, and testing records in a single, accessible location — not scattered across shared drives, email inboxes, and filing cabinets.
- Defined responsibilities. Assign clear ownership of each element of the documentation. Who maintains the policy? Who manages testing records? Who keeps training records current?
An audit should be an opportunity to demonstrate your program’s quality — not a source of stress. With the right systems and habits, it can be exactly that.
Want to be audit-ready at all times? Start a free trial of FairTest and maintain complete, searchable, instantly accessible testing documentation that stands up to any inspection.