1. Definition
Audit in the context of Sexual Abuse Risk Management refers to regular, structured reviews (internal or external) of the organization’s safeguarding systems, policies, procedures, and practices.
It examines whether controls (frontline and supporting) are appropriately designed, implemented, maintained, and effective. Audits include review of documentation, interviews, testing adherence, and evaluation of learning and improvement from past incidents or feedback.
2. Purpose of Audit Controls
Audit controls serve several interrelated purposes:
- Verification & Assurance: Confirm that safeguarding controls are working as intended, not just good on paper.
- Defensibility: Provide evidence for regulators, funders, insurers, courts, or oversight bodies that the organization reviews its practices, identifies gaps, and follows through with corrective action.
- Risk Identification: Detect systemic weaknesses, drift, or emerging risk patterns before harm occurs.
- Continuous Improvement: Feed audit findings into change management, training, and policy updates.
- Accountability & Transparency: Enable oversight by leadership, board, and stakeholders in a structured and credible manner.
3. What Makes Audit Fit-for-Purpose
Strategic Fit
- Audits align with the organization’s mission and Swans, ensuring that safeguarding is core to what you do.
- Designed to strengthen trust with stakeholders by showing evidence of oversight and improvement.
Operational Fit
For an audit to be operationally strong, it should:
- Review both how controls are designed and how they operate in practice (not just documentation).
- Include sampling, spot-checks, and observation, not just self-reports or checklists.
- Be transparent in scope, criteria, and methodology.
- Be adequately resourced (in terms of skills, time, and staff) to carry out thorough reviews.
- Ensure follow-up: corrective actions are tracked and completed.
Lived Experience Fit
- Staff and stakeholders see audits as tools for safety & improvement, not blame or punishment.
- Clarity: people know what will be audited, why, and the timeline.
- Ownership: audit findings are owned by appropriate roles, not ignored.
- Adaptiveness: Audits evolve over time based on emerging lessons.
4. Examples of Audit Activities
Some possible audit tasks or scopes include:
- Reviewing incident / allegation / disclosure records to verify timing, response, follow-up, and to ensure that expectations/breach logs are maintained.
- Interviewing staff at different levels for understanding of policies, reporting, and communication flow.
- Observing practice (site walkthroughs, event settings) to see how behavior expectations, supervisory oversight, and security protocols are being lived.
- Comparing planned versus actual training completions, supervision ratios, and access control.
- Reviewing record retention and security of record-keeping.
- Auditing budget allocations vs actual expenditures for safeguarding activities.
- Checking feedback from stakeholders: staff, clients/participants, families.
5. Common Strengths and Gaps
Strengths Often Found
- Existence of some audit schedule or periodic review.
- Use of external or third‐party audits in part (e.g., partner or regulator audits).
- Audit reports that lead to visible change (policy updates, retraining).
Gaps Often Found
- Audit limited to documentation/policies, not actual practice.
- No follow-through: audit findings are noted but not fixed or tracked.
- Audit frequency is too low or reactive (after an adverse event) rather than proactive.
- Poor communication of audit findings to staff and stakeholders.
- Audits are not integrating perspectives of those with lived experience (participants, families).
6. Signals of Strong Audit Control Set
- Audit calendar with clear frequency (e.g., internal audit every 6-12 months; external review every few years).
- Audit scope includes both design and implementation of controls.
- Corrective actions are tracked in a plan, with deadlines and owners.
- Audit findings are shared broadly enough for learning.
- Evidence that previous audit findings resulted in sustained change.
7. Opportunities for Improvement
- Use mixed audit types (internal, external, peer reviews, self-assessments).
- Include stakeholder/participant input in audits.
- Simulate scenarios or tabletop exercises as part of an audit to test response, not just documented policy.
- Integrate audit findings into strategic risk reviews and budget decisions.
- Build audit into the two feedback loops: short-term monitoring (are we doing what policy says?) and long-term reviewing (is the policy still right given emerging risks?).
8. How Audit Is Tracked in Jigsaw
- The audit schedule is part of the Jigsaw Team planning with the owners.
- Audit reports stored, versioned, and linked to corrective action plans.
- Metrics from the audit are used in leadership reporting, budget review, and change management.
- Review of audit findings during governance meetings.
Bottom Line
Audit is the reality check in safeguarding. It’s what tells an organization whether its commitments have moved from policy into practice, whether its systems are holding when tested, and whether it can defend itself (and those in its care) when scrutiny comes. A robust audit framework gives confidence, direction, and momentum for improvement.
Download this checklist as a starter auditing tool.
