route & fleet
Compliance

Preparing for a Fleet Compliance Audit

What auditors examine, how to run an internal audit before they do, and the record-keeping practices that turn an audit from a crisis into a formality.

Illustration: Preparing for a Fleet Compliance Audit
Advertisement
Ad space · activate by adding your AdSense publisher ID to lib/manifest.js

An audit tests your systems, not your intentions. Fleets that fail rarely intended to be non-compliant; they simply could not produce evidence that they were.

What auditors typically examine

The specifics vary by jurisdiction and regime, but the areas are consistent:

AreaEvidence sought
Driver licensing and qualificationComplete, current files with verification records
Driving and duty hoursRecords, violations, how violations were handled
Vehicle inspectionsDaily checks and the defect-to-repair chain
MaintenanceScheduled inspections performed on time, records retained
RoadworthinessDefect rectification, prohibition history
Load security and weightProcedures, training, evidence of checks
Incident and accident recordsReporting, investigation, corrective action
Management systemsWho is responsible, what they do, evidence they do it
TrainingInduction, ongoing, and evidence of competence
Drivers' hours infringementsDetection, investigation and action, not just recording

That last row is important and frequently misunderstood. Auditors expect infringements to occur; what they examine is whether you detected them, investigated them and acted. A fleet reporting zero infringements is usually a fleet that is not looking.

An internal audit finding costs a corrective action. The same finding from a regulator can cost licence conditions, operational restrictions and management time measured in weeks.

Run your own audit first

Do this annually, and treat it as if it were real.

1. Pick a date at random from six months ago. For that date, produce:

  • Every driver's hours record
  • Every vehicle's inspection record
  • Any defect raised, and its repair record
  • The roster showing who drove what

If you cannot assemble this in under an hour, that is your finding.

2. Sample driver files. Take five drivers, including one agency driver and one recent starter. Check every document, every expiry, every verification record.

3. Sample vehicles. Take five vehicles across classes. Check inspection schedule compliance, defect history and rectification timeliness.

4. Check the chains. Pick five defects from the last quarter and follow each through to repair and certification. Broken chains are the most common serious finding.

5. Review infringements. How many were detected, what was done, and is there evidence of the action?

6. Test the stop rules. Has any vehicle operated with an expired inspection, or any driver with an expired licence, in the last twelve months? The system should be able to answer this.

Advertisement
Ad space · activate by adding your AdSense publisher ID to lib/manifest.js

The management system

Regulators increasingly examine systems rather than individual records. They want to see:

  • A named responsible person with defined authority and adequate time
  • Documented procedures that reflect what actually happens
  • Evidence of monitoring — reports, reviews, meeting minutes
  • Corrective action with owners, dates and closure
  • Management review at defined intervals, with records
  • Competence — the responsible person is trained and current

The gap that catches fleets out is between the written procedure and the practice. If your procedure says defects are reviewed daily by the transport manager and they are actually reviewed weekly by an administrator, the procedure is a liability rather than a defence. Write what you do, then improve both together.

Record retrieval

Auditors judge your system partly by how fast you can produce records. Practical requirements:

  • Records searchable by vehicle, driver and date
  • Exportable in a readable format without vendor assistance
  • Retained for the full statutory period
  • Retrievable after a system change — test this
  • Backed up, with the backup tested

The system-change risk is real and under-appreciated. Fleets that migrate platforms frequently lose practical access to historical records, discovering it during an audit.

During the audit

  • Be organised and cooperative. Obstruction turns a routine audit into a detailed one.
  • Answer what is asked. Volunteering unrelated problems extends the scope.
  • If you do not know, say so and find out. Guessing produces contradictions in the record.
  • Take your own notes of what was requested and what was provided.
  • Ask for findings in writing, with the specific requirement each relates to.
Advertisement
Ad space · activate by adding your AdSense publisher ID to lib/manifest.js

After the audit

Corrective actions with owners and dates, tracked to closure, with evidence. A finding that recurs at the next audit because the corrective action was never verified is treated far more seriously than the original.

Frequently asked questions

How often should we audit ourselves?

Annually as a full exercise, with lighter quarterly checks on the highest-risk areas — driver documentation expiry, inspection compliance and the defect-to-repair chain. Fleets with recent findings should check more frequently until the improvement is demonstrable.

Who should perform the internal audit?

Someone independent of day-to-day operation of the process being audited: a different depot's manager, an internal compliance function, or an external consultant. Self-audit by the person responsible for the process rarely finds anything.

What is the most common finding?

Broken chains — an inspection record showing a defect with no corresponding repair evidence, or a driver file with a document that expired and was not renewed. Both are failures of follow-through rather than of intent.

Should we use a compliance management system?

For fleets of any size, yes. The automation of expiry tracking, defect chains and record retrieval addresses the majority of common findings directly, and the retrieval speed alone transforms the audit experience.

What if we find a serious non-compliance ourselves?

Act immediately: stop the unsafe activity, record the discovery and the action, investigate the cause and fix the system. Self-identified and properly remediated issues are viewed very differently from ones a regulator discovers, and in some regimes voluntary disclosure carries specific benefits.

Nil Masferrer Jiménez · Editor

Nil writes and edits Route & Fleet. It is an informational reference compiled from public sources — vendor documentation, regulator publications and published industry research — not consultancy, and not based on first-hand experience of running a fleet. Corrections are welcome and get published.

How we research and review our articles

This article is editorially independent. Route & Fleet is funded by advertising displayed on the page; advertisers have no influence over our research, recommendations or conclusions. See our advertising disclosure.

Keep reading

Related articles

Compliance

Hours of Service and ELD Rules Explained

How hours-of-service limits and electronic logging work, what fleets must record, the common violations, and how software should support compliance.

31 July 2026 · 5 min read

Advertisement
Ad space · activate by adding your AdSense publisher ID to lib/manifest.js