The file that saves you in an audit is usually smaller than the file you keep
When an auditor asks for WHS evidence on short notice, the documents that matter are rarely the ones people spend the most time filing. They want the records that show a hazard was identified, a control was put in place, someone checked it, and the site kept it live. If you can’t show that chain quickly, the rest is just noise.
I’ve seen plenty of sites with thick folders and weak proof. The problem is not volume. It’s whether the record set can actually defend the decisions made on the floor, in the dock, or at the pedestrian crossing.
For warehouse operators, that usually means a tight WHS documentation checklist built around site records, inspection logs, risk assessment records, and the version history behind them. Not a museum of old PDFs.
What auditors actually care about
The documents that save a site are the ones that prove control, not intent. If an inspector turns up after a near miss, they usually move straight past the pretty policy and ask for the working evidence:
- the current risk assessment for the task or area
- the inspection log showing the hazard was checked
- the corrective action record
- the sign-off or close-out note
- the training or toolbox record showing workers were briefed
- any photo evidence that shows the control in place
What they often ignore, unless the incident is serious, are generic corporate policies, outdated induction slides, and a safety manual that hasn’t been touched since the last office refresh. Those can support the story, but they don’t carry the story.
If you are running a warehouse, that means your warehouse compliance evidence needs to be anchored in the actual layout and work happening now, not the layout you had six months ago.
Key takeaway: If a document does not show the hazard, the control, the check, and the close-out, it is support material, not WHS evidence.
The records people think they have, until they need them
The most common gap is not “no paperwork”. It is weak paperwork.
Site managers often assume these are covered:
- induction records
- monthly inspections
- incident reports
- training registers
- maintenance tickets
- contractor sign-in sheets
Then the audit starts and the holes show up fast.
The usual weak spots
1. No link between the hazard and the fix.
A note says “forklift blind spot near dock door”. Great. What changed? Was it a barrier, a gate, line marking, a mirror, a traffic management change, or a supervisor instruction? If the record stops at the hazard, it is not enough.
2. No date the control became live.
A photo of a new bollard helps, but only if you can show when it was installed, by whom, and whether the area was reopened after the work.
3. No evidence workers were told.
A control that exists on paper but never made it into a toolbox talk, pre-start, or shift handover is a common failure point.
4. No version control.
If three supervisors have edited the same risk assessment across two shared drives and a printer tray, nobody can prove which version was current.
5. No close-out.
A hazard is logged, assigned, and then sits there for six weeks. That is not a control system. That is a waiting room.
The first document that usually goes stale
The first piece of WHS documentation to go out of date after a site change is usually the risk assessment record. Not the policy. Not the induction. The risk assessment.
That happens because site changes move faster than admin. A new rack run goes in, a pedestrian gate gets shifted, a loading pattern changes, or a temporary exclusion zone becomes permanent. The physical site changes on Monday, but the risk register still describes Friday’s layout.
The catch is simple, and most teams miss it until the audit does. Build a trigger list for updates:
- racking or shelving changes
- new equipment or plant
- changes to forklift routes
- new contractors or delivery patterns
- altered pedestrian access
- temporary barriers becoming permanent
- incident or near-miss trends in one zone
If any of those happen, the risk assessment record gets reviewed before the next shift cycle, not at the end of the quarter.
Keep some records at site level, centralise the rest
Not every record belongs in the same place. If you centralise everything, supervisors stop using it. If you leave everything on-site, version control turns to mush.
A practical split looks like this:
| Record type | Keep at site level? | Centralise? | Why |
|---|---|---|---|
| Daily pre-starts | Yes | Copy summary centrally | Used by supervisors on the floor, needed for immediate follow-up |
| Weekly inspection logs | Yes | Yes, if sites are many | Site team needs quick access, head office needs trend visibility |
| Risk assessment records for local hazards | Yes | Copy master centrally | Local controls change with the layout |
| Corporate WHS policy | No | Yes | One controlled version is enough |
| Training matrix | No, but accessible | Yes | Better managed centrally, but site leaders need read access |
| Incident reports and corrective actions | Yes | Yes | Site needs the live record, central team needs the pattern |
| Contractor compliance docs | Yes for active jobs | Yes | Site needs proof at the point of work |
The breakage usually happens when a site keeps its own “master” spreadsheet and head office keeps another. Then nobody knows which one was used after the incident. Pick one source of truth for each record type, and make the other copy read-only.
How to prove the hazard was fixed
A photo of a hazard is not proof of control. A photo sequence is. If you want to show a hazard was actually fixed, not just noted, build the record like this:
- photo of the hazard in context
- risk assessment or inspection note
- corrective action assigned
- evidence of the control installed
- photo of the area after the fix
- sign-off that the area was returned to service
- brief note to workers if the workflow changed
That matters on warehouse floors where controls are physical. If you install a Wall Mount Belt Barrier to cordon off a temporary aisle closure, the evidence should show the closure point, the reason for it, the installation date, and when it was removed or reset. Same with a gate, bollard, or cable protection. The control is only defensible if the record ties it to the actual site condition.
A good example is the Shiperoo warehouse fitout. They started with an empty warehouse and needed pedestrian separation from day one. The useful part for WHS evidence is not just that the layout was installed, it is that the layout was designed around how the warehouse would operate, so the record set could reflect the intended traffic flow from the start. That is much easier to defend than retrofitting controls after people have already formed bad habits.
What compliance teams wish you would write down
The stuff people leave out is usually the stuff an auditor asks about first. Compliance teams want the boring detail that proves the record was made by someone who was actually there.
Include:
- exact location, not just “warehouse floor”
- time of inspection, not just the date
- who was present
- what was operating at the time
- whether the area was live, isolated, or partially open
- what temporary controls were in place
- whether the issue affected pedestrians, forklifts, trucks, or contractors
- whether the control was tested, not just installed
That last one gets missed constantly. If a self-closing gate was fitted, did anyone check it actually closes under normal use? If a barrier was repositioned, did it still protect the blind spot it was meant to cover? Those details matter because they show the engineering control is functioning, not just sitting there looking compliant.
How to keep WHS evidence current without drowning supervisors
The fastest way to kill a WHS documentation checklist is to make it feel like paperwork for paperwork’s sake. Supervisors will update what helps them run the shift. They will ignore what feels like admin theatre.
Keep it lean:
- use one template per record type
- pre-fill site name, area, and supervisor fields
- make drop-downs for hazard types and control types
- keep free text for the actual observation
- limit photos to the ones that prove a change
- close actions in the same system where possible
The rule I use is simple. If a record takes more than two minutes to complete on the floor, it will drift.
If your warehouse runs across multiple shifts, the biggest failure mode is duplicate updates. One supervisor notes the issue in a notebook, another uploads a photo to email, a third edits the spreadsheet, and the actual close-out gets lost. That is how WHS evidence fragments.
A shared digital log helps, but only if it has disciplined ownership. One issue, one owner, one due date, one close-out field. Anything looser becomes a graveyard of half-finished actions.
How long to keep it before storage becomes the problem
Retention is where a lot of sites quietly fall apart. They keep too little, then panic. Or they keep everything, and nobody can find anything.
A realistic approach for warehouse compliance evidence is:
- daily or weekly inspection logs, keep on site for at least 12 months
- incident and near-miss records, keep for several years and align with your legal and insurer advice
- risk assessment records, keep the current version on site and retain superseded versions centrally
- training and induction records, keep long enough to cover the employment and audit cycle
- contractor and maintenance records, retain while the control is active and for a sensible historical period after
The exact retention period depends on the record type, the incident severity, and your legal advice. But the practical issue is not just retention, it is retrieval. If you cannot pull a record in five minutes, you do not really have it.
Version control matters here too. Name files so the latest one is obvious, and archive old versions in a way that stops people from using them by mistake. A file called “WHS risk assessment final final v7” is not a system. It is a cry for help.
When records are scattered everywhere after an incident
If warehouse compliance evidence is spread across email, shared drives, and paper folders, rebuild the record set in the order the incident happened. Not in the order people sent you files.
Start with:
- the incident report
- the immediate control put in place
- the inspection log for that area
- the risk assessment record in force at the time
- the corrective action and close-out evidence
- photos, CCTV stills, or maintenance records that support the timeline
- the training or briefing record if behaviour changed
Then lock the set. Create one incident folder with read-only access for the final version, and keep a simple index showing what each document proves. That is how you make a defensible record set out of a mess.
If the site is still changing, get a proper review of the layout and controls before you rely on the paperwork alone. A Site Safety Audits & Risk Inspections review is useful here because it forces the paper trail to line up with what is actually on the floor, which is where most gaps show up.
The practical WHS documentation checklist that holds up
If you only keep one checklist, make it this:
- current risk assessment for each active hazard area
- inspection logs with dates, times, and named owners
- corrective action records with close-out evidence
- training or toolbox records tied to the change
- contractor sign-in and permit records where relevant
- photos showing before, during, and after
- version-controlled layout or traffic management drawings
- incident and near-miss reports linked to the control used
That is the core of defensible WHS evidence. Not a pile of files. A clear chain.
If you want the faster path, get your site records reviewed against the actual warehouse layout and traffic flow before the next audit lands. MAD Safety’s Site Safety Audits & Risk Inspections service is built for that, and it saves a lot of time when the issue is not the lack of records, but the fact they do not match the floor anymore.

