Risk Assessment Versus Audit

Share
Low-angle view of glass skyscrapers reflecting the sky, symbolizing corporate environments and risk assessments.

Risk Assessment Versus Audit

An Essential Guide

It is not often that security organizations purchase professional security services. This might happen once every five to ten years. As such, consumers might not know exactly what service to request to best align with their physical security needs. 

This article is intended to clarify the difference between a physical security audit and a physical security assessment for organizations trying to validate the effectiveness of their security program to enable the appropriate choice to be made when the time comes.

Three Important Questions & What Is Risk?

Let’s start with three questions managers should ask themselves about their security program:

  • Risk Identification – Have you identified and understood the risks that are relevant to your organization?
  • Control Alignment – Are the controls in your physical security program aligned to those risks?
  • Performance – Are the controls likely to perform as intended and deliver good outcomes?

A Security Risk Assessment goed beyond whether those controls are appropriate for the risks that you face, and whether they are likely to perform as intended. Let’s start with a view of the many things that should be looked at to determine security adequacy. The following elements illustrate the three areas of security risk that are typically analyzed.

Risk considers 1) Threat, 2) Consequence and 3) Vulnerability (or effectiveness of security).

Security Audit Focus

A Physical Security Audit is only going to be focused on one of these elements of the security risk formula. An audit is not necessarily designed to diagnose criminal and terrorist risk, but certainly mitigates non-compliance risk.

A security audit is probably the easiest methodology to execute for the consultant as it is simply a verification that all security measures which are supposed to be in place are in fact in place, functioning, and documented correctly. 

The security audit will focus on the effectiveness of security or confirm whether a vulnerability is being properly mitigated. This is opposed to a physical security assessment, which is intended to be much more diagnostic and predictive into the future, typically five years or more. The physical security audit is a point-in-time check only. 

If the basis of design for the security program is incorrect, the audit may not shed light on this. However, the security audit is an important tool in the toolbox as an agent of positive change to protect people, assets, and information.

The challenge when organizations ask for a physical security audit and have no established security standard is that the security professional uses as the benchmark against which the physical security audit results will be measured. Some considerations if you face this common scenario:

If your organization does not have a set of security standards, you must ask your prospective security professional what methodology will be used to audit your organization. 

Ask to see the methodology so that you can review it and ensure you will be satisfied with the outcome. Will it cover all the necessary elements of your physical security program?

The Scope of Physical Security Audits

At a minimum, a proper physical security audit should include within its scope the following (note this list is by no means all inclusive):

  • Governance
  • Access control – site perimeter, building perimeter, restricted internal areas
  • Security systems installation, operation, and maintenance
  • Security-related policies and procedures
  • Security awareness training and education
  • Information protection
  • Asset protection
  • Security officer utilization (if applicable)
  • Competency of non-security personnel in key security roles
  • Crisis and emergency management protocols
  • Security change management

These components form the foundation of a reliable physical security audit checklist and help ensure consistency and accountability across your program.

If you are going to request an audit from an outside security professional without having organizational security standards, you will want to ensure that the security professional has some experience in the following areas:

  • Prior similar work within your industry (for example, if you are a chemical plant, the consultant should have some level of experience in the oil, gas or chemical arena).
  • Setting up corporate or global security programs for organizations.
  • Reporting out on audits with a methodology that supports a stratification of the findings. Some findings are going to be more important than others. There should be a means to classify gaps. For instance, the following definitions for high and lower priority observations and findings are shown below.

Findings – represent clear departures from, or exceptions to, existing applicable federal or state laws or established audit security standards, where such departures or exceptions can be confirmed. Exceptions may include any issues that were previously discovered in prior audits that are still open or were improperly or incompletely closed.

Suggestions – represent options for enhancing the plan and/or plant security to reduce the possibility of any exceptions or vulnerability to a security incident in the future.

Audit Types Explained: First-Party & Third-Party

Another caution is the type of audit that is conducted, as this will have a direct correlation to the validity of the outcome. Two types of audits are discussed below.

First-Party Audits

First-party audits are often called self-audits. This is when someone from the organization itself will audit a process or set of processes to ensure it meets the expectations set forth in the audit protocol. This person would typically be an employee of the organization. 

In some cases, particularly under some counter-terrorism regulations such as the Marine Transportation Security Act (MTSA), first-party audits are prohibited, and persons with any affiliation with the security program may not audit the program.

A first-party audit might be appropriate as a rehearsal for a more robust audit conducted by a third party. Otherwise, it could be argued that there could be a potential conflict of interest by auditing oneself.

At BPS, we would consider an audit by an internal audit group to be a step up from the self-audit as the internal auditors are typically strict and objective. The problem with internal auditors doing physical security audits is the lack of knowledge of the subject matter. 

If an internal auditor is going to be involved in physical security audits, it is important to carefully script what their scope will be so that they are looking at things they can fairly judge that are simple and high impact.

Third-Party Audits

A third-party audit occurs when a company hires an independent entity to perform an audit to verify that the company is executing a security program consistent with regulatory expectations, internal standards, or the methodology agreed upon with the auditor up front. Some would argue that this is the best and most stringent means of conducting an audit to ensure objectivity. But it also comes with a cost.

To close out the audit discussion, this type of physical security review is intended to answer the question, “For the things we are doing in our security program, are we meeting the commitments we have made to security, and are we doing things in a manner that achieves the desired outcomes?” You state that you do A, B, C, and D in your security program, and you have or pay someone to come in and verify that you are doing A, B, C, and D.

The Physical Security Assessment

Continuing with the A, B, C, and D discussion, the audit will not necessarily tell you if A, B, C, and D are the right things to be doing in your security program. To get this type of diagnostic insight, organizations need to be asking their consultant for a physical security assessment, not just a physical security audit.

As noted above, risk considers 1) Threat, 2) Consequence and 3) Vulnerability.

The security risk assessment is going to analyze all elements shown above. The predictive nature of the risk assessment is borne out of the threat assessment and pairing threats with critical assets. 

It formulates future security scenarios that will be analyzed for consequences (how bad would it be if it occurred) and vulnerability (how susceptible is the organization to a criminal or terrorist attack, or conversely, how well prepared is the organization to prevent a security incident). 

The methodology BPS employs is a hybrid approach where different combinations of circumstances are looked at together with a corresponding mathematical value.  When certain circumstances occur together, the score is higher and therefore the risk is higher.  For example, an incident that happens with some regularity and the incident carries serious consequences such as a hospitalization or death, and the site is not properly prepared to prevent the incident, the scores would be higher and therefore the risk score.  In summary, the combination of a serious security incident that could happen frequently and where there are opportunities for better preparedness represent a combination of factors which are considered a situation to present to the business leaders that is suitable for consideration of additional mitigation.

Risk assessments are forward-looking, but of course will take into account historical security incidents, which are one of the best predictors for future incidents. Physical security assessments can nicely inform a security master plan versus the physical security audit, which may generate some findings and corrective actions to remediate shortcomings in existing security measures.

Learn more about the BPS approach to Security Risk Assessments

The Many Benefits of Physical Security Assessments

  • Prevent incidents and criminal activity.
  • Compliance with the OSHA General Duty Clause or Duty of Care outside the US.
  • Identify to all stakeholders what needs to be protected, why, and from whom.
  • Learn where you can be victimized by criminals or terrorists.
  • Identify holistic mitigation strategies to reduce security risk to people, assets, and information.
  • Stage the implementation of recommendations at your own pace rather than hastily responding or overreacting after a security incident.
  • Secure funding for security improvements by making a compelling business case. (Management will sometimes react more rapidly to third-party recommendations or those that are well supported by crime and other data analysis.)
  • Implement many improvements without a capital investment. There are always easy, inexpensive, and impactful recommendations that can be implemented at a low or even no cost.
  • Identify emergency scenarios and calibrate emergency response and business continuity plans accordingly.
  • Defend against frivolous litigation.

The illustration below shows how scenarios can be analyzed and scored to identify the highest concerns for an organization.

Risk matrix showing how physical security threat scenarios are scored by probability and consequence, from low risk to critical risk.

Summary Comparison: Audit Versus Assessment

Below, we share a final comparison between a physical security audit and a physical security assessment.

Physical Security Audit

  • Point in time assessment
  • Verifies that security commitments are being met
  • Leads to potential action items where gaps are identified
  • Less expensive than a risk assessment
  • Does not validate that the security program is aligned with risk
  • Does not provide a basis of design for an organizational security program

Security Risk Assessment

  • Forward-looking methodology
  • Verifies that security commitments are being met
  • Leads to a long-term security master plan and cost staging
  • More expensive than a physical security audit
  • Validates that the security program is aligned with risk
  • Provides a better defense of conformance to the OSHA General Duty Clause
  • Provides a better defense against frivolous premises liability claims
  • Provides a basis of design for an organizational security program
  • Enhances crisis management and resiliency

We hope that this article helps you to make the correct choice when it is time to review your physical security program.

For additional information, please contact us

Independent, risk-based physical security consulting for complex environments.
Explore
Industries
Contact
© 2026 Business Protection Specialists