The rule: where the audit comes from
The audit takes its name from section 175 of the Education Act 2002. Subsection (1) places a duty on every local authority to “make arrangements for ensuring that their education functions are exercised with a view to safeguarding and promoting the welfare of children”; subsection (2) places the same duty on “the governing body of a maintained school”, in relation to its functions and “children who are pupils at the school”; subsection (3) on the governing body of a further education institution; and subsection (4) requires each of them to “have regard to any guidance given from time to time by the Secretary of State” – which is what makes Keeping children safe in education binding. Section 157 and the Education (Independent School Standards) Regulations 2014 apply the equivalent duty to the proprietors of independent schools, including academies and free schools, which is why the audit is called the “section 175/157 audit” in most areas.
The local authority’s own subsection (1) duty is the reason it asks. It cannot know whether every school in its area is exercising its functions “with a view to safeguarding” without asking, and Working Together to Safeguard Children 2026 expects the local safeguarding children partnership to include education in its arrangements and to be able to say how well schools are meeting their responsibilities. Devon’s guidance to its schools puts the purpose in a sentence: under sections 175 and 157, “all Local Authorities must ensure that every school, whether maintained, academy, independent, or registered with the Department for Education, is fulfilling its statutory safeguarding responsibilities”, and the audit “directly aligns with the expectations set out in the current Keeping Children Safe in Education”.
There is no statutory form. Each local authority or partnership designs its own audit, so the questions, the grading scale and the return date vary from area to area, but every one of them is a walk through Part two of KCSIE, which sets out “the responsibility of governing bodies, proprietors and management committees” (paragraph 83) and requires them to “have a strategic leadership responsibility for their school or college’s safeguarding arrangements”, to “ensure that they comply with their duties under legislation” and to ensure “policies, procedures and training in their schools or colleges are effective and comply with the law at all times” (paragraph 84). The audit can contribute to that assurance. Section 175 does not prescribe a single national annual audit form or return date.
What the audit covers
The headings follow Part two of KCSIE and the local partnership’s own priorities. A typical audit asks the school to grade itself and give evidence under:
- Governance and leadership: the “senior board level lead” KCSIE paragraph 86 requires, the nominated safeguarding governor, governor training (paragraph 87), how the governing body assures itself, the annual report to governors.
- Policies: a child protection policy that reflects the local multi-agency arrangements, includes online safety and SEND, “is reviewed annually (as a minimum) and updated if needed” and “is available publicly” (paragraph 123); the staff behaviour policy with low-level concerns, allegations and whistleblowing; the behaviour policy; the policy on children absent from education.
- The designated safeguarding lead: appointment, deputies, training and refresher dates, time and resources, the role as set out in Annex B.
- Staff training and induction: Part one read by all staff, induction as paragraph 124 describes, regularly updated training and safeguarding updates at least annually, the training record.
- Safer recruitment: the single central record, safer recruitment training on every panel, references, the checks in Part three, the DBS and barred list, overseas checks, agency and contractor assurances.
- Child protection records and information sharing: separate child protection files, prompt file transfer within KCSIE’s applicable five-day window, the local thresholds and referral route, the information-sharing arrangements.
- Online safety: filtering and monitoring reviewed “at least annually”, the annual online-safety review and risk assessment KCSIE paragraph 181 suggests, the curriculum.
- Child-on-child abuse, harmful sexual behaviour and the curriculum: the Part five procedures, relationships education, how reports are recorded and handled.
- Allegations and low-level concerns: the case manager, the LADO route, the low-level concerns file and its review for patterns.
- Attendance, early help, SEND and vulnerable groups: children absent from education, early help referrals, the additional barriers for children with SEND, children with a social worker, looked-after children, the Prevent duty.
- Site, visitors and lettings: site security, visitor procedures, the safeguarding arrangements of other organisations using the premises.
Many partnerships add a second part on their own priorities. Devon’s current audit, for example, includes “questions developed by each of the Partnership’s sub-groups” so that the returns can “shape, evaluate, and share the work of these groups”, and asks schools to grade many questions “on a scale of 1 to 4”, where 1 “indicates that safeguarding practices are fully embedded and supported by clear evidence”. Whatever the scale, the words that matter on every form are “supported by evidence”.
Who completes it, who signs it, and what happens to it
The audit is completed by the designated safeguarding lead – Devon’s instruction is that it “should be completed by the Designated Safeguarding Lead (DSL), or in their absence, the Deputy DSL”, with a fixed return date in February – and it is approved by the governing body, usually through the safeguarding governor and a minute of the full board. That approval is not a formality. Section 175 places the duty on the governing body, not the DSL; KCSIE paragraph 84 makes governors and proprietors responsible for ensuring the arrangements “are effective”; and a governing body that signs an audit it has not read has signed a statement about its own compliance it cannot stand behind. The safeguarding governor should complete the audit with the DSL, test a sample of the evidence, and report to the board what they saw.
On return, the authority or partnership reads it. Devon’s description is typical of the better ones: the education safeguarding team “will review and analyse them to identify trends and adjust training where appropriate. Every individual return is read in full. If any concerns are identified within a school or setting’s audit, a member of the team will contact that school directly to discuss and offer additional support”; the collective results go to an education advisory group with a proposed action plan and to the partnership’s leadership group, and an annual report is published. A school that grades itself low and honestly gets help; a school that grades itself high and is later found wanting by an inspector or a review has a signed audit on the file that says it knew.
Then it comes back to the school. The audit’s value to the school is its action plan: the items that the local scale identifies as needing improvement become safeguarding priorities in the school development plan, with an owner and a date, reported to governors at the next safeguarding update. Devon’s note that the audit “provides an excellent opportunity to review safeguarding practice across your setting, identify areas for development, and incorporate these into wider school improvement plans” is the right way round: the form is the by-product; the review is the point.
The evidence behind each grade
A grade is a claim; the evidence is what makes it true, and the audit is best completed with the evidence open rather than recalled. For each section, the document or record that proves the claim:
- Governance: the minute appointing the safeguarding governor and the senior lead; governors’ training certificates and dates; the minutes that show safeguarding as a standing item and the questions governors asked; the annual safeguarding report.
- Policies: the current child protection policy with its review date and the minute approving it; the staff behaviour policy; the website page where the policy is published.
- The DSL: the job description, the training certificate within two years, the deputies’ training, the time allocated in the timetable.
- Training: the training record showing every member of staff’s induction, Part one acknowledgement, annual training and updates, with dates; the induction checklist for the last three appointments.
- Safer recruitment: the single central record checked by the governor that term, with the check recorded; safer recruitment certificates for panel members; a sample of recruitment files.
- Records: a sample of child protection files against Annex B’s standard (“clear, factual, and distinguish between observed concerns, professional opinion, and historic information”); the file-transfer log with receipts; the referral log with the partnership’s reference numbers.
- Online safety: the filtering and monitoring review, the risk assessment, the provider’s report; the curriculum map.
- Allegations and low-level concerns: the low-level concerns file and the minute of its termly review; the LADO contact log.
- Attendance and vulnerable groups: the absence procedures and the log of children missing education referrals; the early help log; the register of children with a social worker.
The evidence is also what Ofsted and ISI ask for, which is why Devon tells its schools the audit “can also be used to evidence evaluation of safeguarding practices with inspectors”. A completed audit with its evidence indexed can help leaders explain their safeguarding evaluation to inspectors, and a school that keeps the two together – the audit and the folder of evidence behind it, updated each term – has done most of its inspection preparation without noticing.

The governing body’s year, built around the audit
Where the local audit is annual, it provides one review point; the safeguarding duty is continuous. The governing body that uses the audit well runs its safeguarding year around it: the safeguarding governor’s termly visit and single central record check in the autumn; the audit completed with the DSL and approved by the board in the spring, with the action plan; the DSL’s annual report and the policy review in the summer, ready for the September edition of KCSIE and the new academic year. Each of those is minuted, and the minutes are the evidence that KCSIE paragraph 84’s “strategic leadership responsibility” was exercised rather than delegated.
For a multi-academy trust the same cycle runs at two levels: each school completes its own audit, and the trust board – the proprietor, and so the body that holds the section 157 duty – receives a summary across its schools and the trust-wide action plan. The trust needs to understand weaknesses across its schools and check that the resulting actions are completed; the grade alone does not establish compliance or non-compliance.
The audit also fixes a habit inspectors look for: the governing body that asks the DSL “how do we know?” rather than “is everything all right?”. The grading scale forces the question, and the evidence folder answers it.
The question the audit asks that the records cannot answer
A typical safeguarding audit asks a question such as this: Are all staff clear about how to raise a concern, and are concerns raised and acted on promptly? Using a scale in which 1 is the strongest grade, the school grades it 1, and the evidence is the training record and the policy. But look at how concerns are actually raised in the school. The teaching assistant’s worry about a child is a message to the class teacher at half past four. The class teacher tells the DSL in a text because the DSL is teaching. The lunchtime supervisor’s concern about a colleague is a message to a friend on the staff. The head of year and the DSL agree in a WhatsApp at nine at night what to do about a disclosure. The staff room’s real conversation about a family is in a group chat the head is not in.
None of that is on the school’s systems. The child protection file records what the DSL wrote once the concern reached them; the audit’s evidence shows the policy exists and the training was given; and the actual first raising of the concern, the time it was raised, the reply, and the conversation between adults about the child are on personal phones in apps the school cannot open. When a review, a LADO enquiry or an inspector asks how quickly a concern was acted on, the school is asking staff for screenshots, and it needs a lawful, proportionate process for obtaining relevant work messages while protecting unrelated personal information. The audit’s grade 1 is honest about the policy and blind about the practice.
Use a restricted reporting route, with access limited to the people who need the information. A recorded message is not proof that someone has read or acted on a concern: follow the safeguarding procedure, contact the responsible person directly when action is urgent, and use the local authority or emergency route when required. Add the relevant information and decisions promptly to the formal safeguarding record.
The school cannot stop staff messaging each other about children; that is how concerns travel, and it is what the policy asks them to do. It can give those conversations a channel the school runs, reachable from a personal phone in a corridor or a kitchen, where the DSL is in the conversation from the first message, where everyone in it has been told it is on the record, and where the concern, the time and the reply are the record rather than a reconstruction of it. The next time the audit asks whether concerns are raised and acted on promptly, the evidence for the grade can be the channel itself.
Official guidance and your next step
The primary sources are section 175 and section 157 of the Education Act 2002 and the Education (Independent School Standards) Regulations 2014; Keeping children safe in education 2026, Part two (paragraphs 83 to 87 on governing bodies, 123 to 126 on policies and files, and Annex B on the child protection file) and Part three on safer recruitment; and Working Together to Safeguard Children 2026 on the local partnership’s arrangements. Your own audit form, its guidance and its return date are published by your local authority or safeguarding partnership; Devon’s section 175 audit page is quoted above as an example of the process.
This guide is a summary of published guidance for England, not a substitute for it and not legal advice. Colleges have their own duty under section 175(3); independent schools should read the Independent School Standards alongside KCSIE.
Then do one thing: open last year’s audit at the question about staff raising concerns, and beside the grade write where the last three concerns in the school were first raised. If the answer is a personal phone, the grade needs a note.
We build ComplyChat for the work conversations organisations need to keep. The organisational archive described here is available on paid plans, with a connected Microsoft 365 tenant and retention configured by the organisation. A school that grades itself well on how concerns are raised needs a channel that staff can reach from a personal phone at half past four and that the school can produce afterwards, and that is what ComplyChat is: a channel the school owns, on a compatible phone, on the record from the first message with everyone in it told so, filing into the school’s own Microsoft 365 once the tenant is connected and kept under the school’s own retention rules, with parents and families reachable as guests without a school account. It is not an audit tool and it does not replace the child protection file; it is where a concern and the response can be recorded. A member of staff’s own messages stay in their own apps. There is no WhatsApp, Signal or Meta anything in the path.
How it works · Why us · Pricing · FAQ



