Treadstone Associates
Article · 11 min read

How to prepare for a COR audit

A COR audit is not a document review with interviews attached. It is an assessment of whether a health and safety management system exists in practice, evidenced three ways — documentation, interviews and observation — and the three have to agree. Preparation therefore has two halves: making the evidence retrievable, and making sure the practice it describes is the practice on site.

Treadstone Associates · Updated 2026

Key takeaways

  • • IHSA describes the audit as a comprehensive review of the health and safety management system using interviews, documentation review and observation.
  • • Certification runs on a three-year cycle: an external audit, then successful internal maintenance audits in years two and three, then re-application in year four.
  • • Each WSIB account held by an employer must independently achieve its own certificate.
  • • AI can index evidence, map it to audit elements and find the gaps. It must never produce a record that did not exist — that is falsification, not preparation.

Contractors usually meet COR because a buyer asked for it. IHSA describes the Certificate of Recognition as a health and safety management system that is often required for contracts with both public and private sector construction projects in Ontario, noting that some municipalities expect their contractors to be registered in order to qualify for bidding. That commercial framing is accurate, and it is also why so many first audits go badly: the system was built to win work rather than to run the business.

What the auditor is actually testing

IHSA defines an audit as a comprehensive and detailed review of the employer’s health and safety management system, typically covering the basic elements of that system and including interviews, documentation review and observation techniques. It describes the management system itself as a framework put in place by employers to manage risks, establish controls, and minimise injury and illness, with scope and complexity varying according to the workplace.

The three evidence types are the whole design. Documentation shows the system was written; interviews show people know it; observation shows it happens. A binder that passes the first and fails the other two is the classic failure, and it is the one automation makes easier to produce — worth saying out loud before recommending any tooling.

The cycle, so you prepare for the right year

IHSA sets out the sequence plainly. A senior management representative and one designated full-time permanent employee take prescribed training, the employee becoming the internal auditor. The employer then conducts an internal audit using IHSA’s audit tool, IHSA reviews it, and an external audit follows; on successful completion of both, the certificate is issued. After that, certification is valid for three years provided the employer performs and successfully completes internal maintenance audits in the second and third years, with a Letter of Good Standing issued each year, and in year four the employer must re-apply and start the process again.

Two structural details catch people out. IHSA states that each applicable WSIB account held by an employer must independently achieve its own COR, and that employers should have a functioning health and safety programme in place for at least one year before participating — the elements may sit under different headings, and the auditor takes that into account. IHSA also notes that the time from registration to certification depends on the state of the existing system, and that some employers may require up to 18 months to implement all elements.

Submission is now platform-based: IHSA states that all firms must complete and submit internal maintenance audits and external audits through the AuditSoft platform, using the COR 2020 standard. It also provides equivalency to organisations certified to ISO 45001:2018, subject to submitting the equivalency form, a certificate bearing an accreditation body insignia recognised by the International Accreditation Forum, and a recent audit report demonstrating that representative Ontario-based operations were within scope.

If you hold COR in another province

IHSA states that COR must be achieved in the province where your office is located, so an Ontario office working in Ontario needs IHSA certification.

An employer with an out-of-province COR and no permanent Ontario office may apply for interim equivalency by providing confirmation from the CFCSA member safety association that the COR is current, plus proof that the COR internal auditor course was completed in the home province. A successful request produces an interim Letter of Good Standing that can accompany a tender.

What preparation actually consists of

Work backwards from the three evidence types.

Documentation. Every element needs evidence that is dated, attributable and findable in under a minute. The recurring records matter more than the policies: inspection records at the interval you claimed, training records for the people currently on site, hazard assessments matched to actual work fronts, incident and near-miss records with corrective actions closed, meeting minutes, and management review. In British Columbia the equivalent expectation is written into the regulation — section 3.3 requires the maintenance of records and statistics, including reports of inspections and incident investigations, available to the joint committee and, on request, to an officer or the workers.

Interviews. Workers and supervisors will be asked what they would do. If the written procedure and the site practice have drifted apart, the interview finds it, and the honest fix is to change whichever one is wrong — not to coach the answer.

Observation. The auditor watches work happen. Nothing prepared in an office affects this except the practice it produced.

Where AI helps, precisely

Three tasks, all of them retrieval and reconciliation.

Indexing and mapping. Most contractors already hold the evidence; it is spread across email, a shared drive, a phone camera roll and a project platform. Document extraction can read the pile and tag each item by type, date, project and person — Microsoft documents Azure Document Intelligence as a service that extracts text and structured fields from documents — and the resulting index can be mapped element by element against the audit tool.

Gap-finding. This is the highest-value use and the least glamorous: no inspection record for March on the Kanata project; four workers on site whose orientation record predates their start date; nine corrective actions raised and two closed; a hazard assessment referencing a product with no safety data sheet on file. These are structural queries over a well-tagged index, and they are exactly what an auditor samples for.

Interview readiness. A model can generate practice questions from your own written procedures — which is legitimate, because it tests whether the procedure is understandable. Using it to script answers is not, and an auditor talking to three people will hear the difference.

The line that must not be crossed

An auditor is testing whether a system operated. A generative tool asked to “produce the missing March inspection report” will produce a convincing one. That is a fabricated record submitted to obtain a certificate used to qualify for public tenders, and no framing makes it anything else. IHSA operates an appeal process for audit results; it does not operate one for invented evidence.

The correct response to a gap is to record the gap, fix the process, and let the score reflect reality. A lower score with a real corrective action is a better position than a high score that collapses on the next external audit — and unlike the alternative, it is recoverable.

A worked example

The following is illustrative — a composite of how the workflow is usually assembled, not a measured result.

An electrical contractor with 60 workers is six months from its first external audit. It ingests two years of safety records into a single indexed store, tagged by type, date, project and person. Mapping the index against the audit elements produces a one-page picture: strong on training and incident records, thin on documented management review, inconsistent on inspections — two projects with monthly records, one with almost none.

The response is operational rather than documentary. The inspection interval is written down, foremen get a dictate-and-submit workflow so the record takes two minutes, and a standing monthly management review goes in the calendar with an agenda drawn from incident trends. By the audit there are five months of consistent records in those two elements, and the auditor will see they are only five months old. That is fine: it is real, which the previous binder was not.

Common questions

How far back does an auditor look?

Ask IHSA or your auditor for the sampling rules that apply to your audit rather than assuming. What is safe to plan for is that a system needs a run of consistent evidence, not a burst before the audit — IHSA expects a functioning programme to have been in place for at least a year before participating.

Does COR replace our legal obligations?

No. It is a voluntary certification assessed against an audit standard; the statutory duties sit under provincial occupational health and safety law and apply regardless. See the Ontario record set and the BC record set for what the law requires irrespective of certification.

What is the fastest thing we can fix?

Retrieval. Most first audits lose points on evidence that exists but cannot be produced. Indexing what you already hold changes the score without changing the safety programme — and it tells you honestly which elements are genuinely missing, which is where the real work is. Start with hazard assessments and near-miss records, which are the two most commonly thin.

See where AI pays off first in your business.

A 30-minute call is enough to tell you whether AI pays for itself here.