What the LCA auditor will actually ask to see
Written by The BlueWave team · Published 25 June 2026 · 6 min read
General information, not legal or regulatory advice — your duties need your own competent advice.
Once a year an LCA assessor spends a day with your firm, and what they came to check is narrower than most people expect. Not whether you own the right kit. Not whether you can quote HSG274 from memory. They came to check that the management system you described in your Statement of Compliance is the one you actually ran, and they check it by sampling your own output back at you.
So the audit turns on records. Expect to be asked for your competence records covering every role, a handful of delivered reports pulled at random and checked against your own procedures, your internal audit log, your complaints log, and evidence for anything you subcontract. A firm that keeps these current as it works finds the audit dull. A firm that assembles them in the fortnight before finds problems it never knew it had. The LCA is blunt about how many: it says "it is not uncommon for the LCA Assessor to find a dozen or more non-conformances that require evidence of resolution". That is the LCA describing a normal audit, not a bad one.
What the Statement of Compliance commits you to
When you join, you summarise your management system in a Statement of Compliance covering the service categories you operate in. The assessor holds that document in one hand and your delivered work in the other, and checks that they match, against the Code of Conduct and the Service Delivery Standards. The audits focused on the Code of Conduct through 2021 and 2022, and on the Service Delivery Standards from 2022 onwards, so both are now in scope.
The Statement is a promise you wrote about yourself. The audit is someone checking you kept it. That has a practical consequence most firms miss: every category you declare is a category you'll be sampled on. Claiming risk assessment, water treatment, monitoring and inspection, cleaning and disinfection, and a training arm you barely run is five audit fronts, not four you can coast on. Declare what you deliver and can evidence. Nothing else.
The gap that catches nearly everyone
The most common recurring finding isn't about engineers. It's about the people who never go on site. The LCA puts it plainly: "While it is common to see good records for the 'technicians', there are significant gaps for the other roles within legionella control, such as, Surveyors, Designers and Planners".
The reason is predictable. Firms keep a training matrix for engineers because the engineer on the tools is the visible risk. The surveyor who writes the risk assessment, the person who designs a scheme, the planner who sequences the visits, their competence gets assumed rather than filed. Then the assessor asks for it and the folder is empty. The working rule: every role that touches a deliverable needs a dated competence record, and that includes office staff who wouldn't recognise a calorifier.
Internal audits, the thing that slips when the diary is full
Membership asks you to internally audit a representative sample of your own output and records, not just wait for the annual external visit. This is the requirement firms quietly drop first when work piles up, because it's the one with no client attached and no invoice at the end.
The external assessor asks to see that internal audit log, the findings you raised on yourself and the evidence you closed them. An empty log is itself a non-conformance, and worse, it tells the assessor exactly where nobody has been looking. A live internal audit process is the cheapest insurance against the external one going badly.
The three-month window, and why removal is the real penalty
Whatever the assessor finds, you get three months to produce evidence you've resolved it. Miss that window and your name comes off the LCA website. For a firm that wins work partly because clients check that list before they invite you to tender, being delisted costs more than any single finding ever could.
Then there's the repeat trap. Roughly one member in twenty carries the same non-conformance year on year, the identical finding at the next audit, because the fix was a one-off promise instead of a change to how the firm works. The assessor remembers last year. A finding that reappears reads as a system that doesn't correct itself, which is the one thing the audit exists to test.
A pre-audit checklist
Pull these together a month out, not a fortnight:
- A competence matrix covering every role, office included. Surveyors, designers, planners, schedulers and report reviewers, each with dated evidence, not a job title.
- An internal audit log with findings raised and closed, drawn from a representative sample of delivered work.
- A random pull of delivered reports, checked against your own written procedures. If your procedure says every risk assessment is reviewed before issue, show the review, not just the report.
- Subcontractor evidence. If you sublet sampling or remedial work, their competence and their output are yours to evidence.
- A complaints log, with what you did about each entry.
- Your monitoring records, retrievable by site and by asset.
That last line overlaps with the law as much as the LCA. HSE wants monitoring records kept at least five years and general records kept while current plus two years after. The assessor and the enforcing authority want the same evidence from different angles, so records that satisfy one usually satisfy the other. If producing a delivered report for a given site is a slow job, see our note on the proof debt that builds up in visit reporting.
Where BlueWave fits
The assessor's favourite move is to name a site and ask for its last visit, then ask for the one before. Answer both inside a minute and the day stays calm. BlueWave keeps every visit record against the site and the asset it belongs to, timestamped and attributed to the engineer who captured it, so five years of history is a search rather than a trip to the filing room. It won't write your competence matrix or run your internal audits, because those are management jobs and not software ones. What it removes is the retrieval scramble that turns a routine audit into a bad week. The scramble is one of eight operational leaks BlueWave was built to close; audit prep just has the sharpest deadline.
Joining in the first place is its own process, covered in LCA membership, from application to first audit. And whether your records are paper or digital changes none of this, which we argue in the piece on authenticated digital records.
The audit isn't a test of your best day. Pick a site at random and time yourself producing three things: the competence record for whoever surveyed it, its last three visit reports, and the internal audit that sampled them. Whichever of the three takes longest is the non-conformance the assessor will reach first.