Skip to content

Fatigue records and audit

Fatigue management improves when organisations can show how decisions were made — not only what the current roster says.

Fatigue records and an audit trail can support assurance, investigation, and learning. They help demonstrate that fatigue risk was considered, reviewed, and responded to proportionately. They do not prove a shift was safe, guarantee compliance, or replace competent person judgement.

Records vary by organisation size and risk profile. Common elements:

Record type What it may capture
Planned assessment Roster version, assumptions, risk assessment reference, model inputs/scores if used
Actual hours and deviations Overtime, overruns, call-outs, swaps — see planned vs actual fatigue
Decisions and accountability Who approved elevated exposure, when, and on what basis
Mitigations Controls applied when work proceeded despite elevated risk
Review notes Periodic or triggered reviews and outcomes
Worker fatigue reports Reports received and how they were handled — see worker fatigue reporting

Records should be contemporaneous where possible — created at or near the time of the decision, not reconstructed after an incident.

A usable audit trail can:

  • Support learning — show whether repeated deviations were noticed and addressed
  • Help explain decisions — what was known when a roster or extension was accepted
  • Assist investigations — provide context after incidents or near-misses (without predetermining cause)
  • Support management review — evidence for FRMS assurance cycles
  • Demonstrate proportionate governance — that fatigue was considered as part of wider health and safety management

ORR guidance on managing rail staff fatigue describes checking whether plans are implemented, measuring performance, and acting on findings — including reviewing whether fatigue contributes to events and learning lessons. Those principles apply broadly to organisations managing shift-based fatigue risk.

An audit trail supports audit and learning. It is not a substitute for effective controls or competent oversight.

When a roster or assignment is planned, useful documentation may include:

  • Scope of the assessment (roles, sites, period)
  • Hazard and control summary from fatigue risk assessment
  • Model methodology and version, if quantitative tools are used
  • Assumptions about breaks, workload, and travel
  • Named reviewer or competent person role
  • Date and roster version identifier

If only a spreadsheet or template exists without site-specific content, it adds little assurance value.

Operational records help compare plan and reality:

  • Clocking, timesheet, or job management data
  • Overtime and extension logs
  • Call-out and on-call records
  • Significant travel variance from planned door-to-door assumptions

Organisations may choose to flag when deviations exceed defined thresholds for fatigue review. Thresholds are policy choices — not universal legal standards.

Decisions, mitigations, and named accountability

Section titled “Decisions, mitigations, and named accountability”

When fatigue exposure is elevated but work proceeds, records should show:

  • What was decided (proceed, redesign, defer, mitigate)
  • Who had authority to accept residual risk — see management accountability
  • Why the decision was considered reasonably practicable in context
  • What mitigations were applied (supervision, task adjustment, recovery planning, transport arrangements)
  • When the decision will be reviewed again

Absence of a recorded decision when exposure was foreseeable is a governance gap — regardless of what a planning tool displayed.

Worker reports are one input to the wider picture. Records may note:

  • Report received and channel used
  • Response taken (roster adjustment, occupational health referral, task change — per policy)
  • Whether the report triggered broader review

Low report volume does not prove absence of fatigue risk — it may indicate reporting barriers. See worker fatigue reporting.

Records have boundaries. They generally cannot:

Limitation Explanation
Prove safety Documentation shows process — not that no one was impaired
Replace judgement Competent review still required at the time of decisions
Capture private sleep Whether someone slept during rest is usually unknown
Guarantee compliance Sector rules and contracts need separate verification
Prevent incidents Records are retrospective and supportive, not preventive alone

Retention periods and data protection obligations depend on organisational policy and law. This page does not provide legal advice on record-keeping.

Organisations may aim for records that are:

  • Findable — linked to roster period, contract, or incident reference
  • Understandable — plain language, not only raw scores
  • Complete enough — assumptions and decisions visible, not only outputs
  • Reviewed — periodically tested for usefulness in assurance and learning

HSG256 discusses implementing and monitoring shift work policies and reviewing effectiveness — records should serve those aims, not exist only for box-ticking.

This page does not reproduce ORR or industry checklists, endorse specific software, or state that any record format satisfies audit or regulatory requirements for your organisation. Sector-specific and contractual requirements vary.