How AMCAS audits work under the new Master Code
An audit certificate is a piece of paper. What gives it meaning is everything behind it: how the criteria were developed, how the audit is conducted, what evidence is tested and how the quality of the audit is checked.
Over the past year, we have redesigned the Australian Master Code Auditing Service (AMCAS) program through industry consultation, legal review and a detailed examination of how assurance should work in practice.
Aaron Louws, Supply Chain Technical Manager at CoRsafe, explains how AMCAS works, what’s changed and what businesses should understand about the role of independent assurance in managing Chain of Responsibility risk.
Key takeaways
AMCAS was developed by industry for industry. The program originated with the Australian Logistics Council and is now maintained by CoRsafe.
The 2026 Master Code prompted a full review of the program. Industry working groups, public consultation and legal review all informed the updated framework.
An AMCAS audit looks beyond policies and procedures. Auditors assess the presence, suitability, operation and effectiveness of systems to validate that activities are understood, hazards and risks have been identified and controls are actually working in practice.
The audit process itself is subject to quality assurance. Auditor qualifications, auditing practices, findings, review processes and conflict-of-interest requirements are built into the program.
The certificate is only part of the value. The real benefit comes from understanding what can be improved, how this compares to other businesses, and then checking that those improvements are effective.
AMCAS was built by industry
The Australian Logistics Council (ALC) created AMCAS as an industry-led way for businesses to assess how they were managing their Chain of Responsibility obligations under the Heavy Vehicle National Law.
It evolved from the Retail and Logistics Supply Chain Code of Practice, an earlier ALC safety initiative, and translated the 2018 Master Code into a structured assessment framework.
We acquired AMCAS in 2023 and have since taken responsibility for developing and managing the program while maintaining its industry purpose.
That stewardship matters because an audit program only works if industry trusts what it measures, how it's delivered and how results are interpreted.
Updating AMCAS for the new Master Code
The release of the 2026 Master Code triggered a full review of AMCAS.
We used the 2026 Master Code as a prompt to review how the program should work, and consider where assurance can add value.
Working groups brought together consignors, retailers, carriers, industry bodies, auditors and consultants to consider the program and where independent assurance could add value.
We then released the draft for public consultation. Holding Redlich, a national commercial law firm with a specialist transport, shipping and logistics practice, also reviewed the program to assess whether the audit tool reflected the principles underpinning the 2026 Master Code.
The review also had to account for an important reality: Chain of Responsibility obligations aren’t identical across every Australian jurisdiction.
For that reason, AMCAS uses the Master Code as a national reference point. It doesn’t attempt to turn an audit into a checklist of jurisdiction-specific legal requirements.
What does an AMCAS audit actually assess?
The Master Code sets out guidance on activities, hazards, risks and controls. AMCAS turns that into a structured assessment of how a business manages them.
The updated program covers nine focus areas across two broad categories.
Safety Management Systems
1. Leadership and Commitment
2. Risk Management
3. People
4. Assurance, Monitoring and Improvement
5. Safety Systems
Operational Systems and Controls
6. Transport Operations
7. Site Activities
8. Working With Other Businesses
9. Specialised Activities
The distinction here is important.
Auditors aren’t simply checking whether a business has copied a recommended control from the Master Code. They’re assessing the presence, suitability, operation and effectiveness of systems to validate that the relevant hazards and risks have been identified and are being managed effectively.
That means understanding the business first, assessing only the activities that are relevant to it, and testing whether systems and controls are actually working as intended.
What happens during an onsite audit?
Before an onsite audit, the business receives information about the audit scope, evidence requirements and arrangements for the day. This allows more time onsite to test how work is actually being performed, rather than simply gathering documents.
The auditor uses a combination of document reviews, interviews, sampling, testing and observation to assess how the relevant systems and controls are operating.
Interviews involve the people who perform the work, supervise it or have responsibility for its governance. Sampling requirements are set by the audit framework and, where evidence points to a broader issue, the auditor is expected to investigate whether the problem is systemic.
At the end of the audit, a closing meeting is held to explain the findings and any non-conformances identified before a report is issued.
Onsite verification is required for certification because documents can only show part of the picture. A procedure may demonstrate that a control has been designed, but observation and testing provide evidence of whether it is being applied and if it is effective.
AMCAS also offers desktop assessments for businesses reviewing documentation or supporting prequalification. These can provide useful assurance, but they aren’t eligible for certification.
Who audits the auditors?
Strong audit criteria are only one part of a credible assurance program. There also need to be controls around the people applying those criteria.
AMCAS includes a defined quality assurance process for reviewing the work of its auditors.
Every new AMCAS auditor has their first two audits reviewed. Every three-day audit is reviewed, while at least 10 per cent of completed audits each quarter are also subject to additional review. Complaints or unusual results can also trigger further review.
The purpose is to test whether the evidence and comments recorded by the auditor support their findings and whether the audit was completed to the required depth and breadth.
Where a problem is identified, the response can involve correcting the identified issue with the auditor, retraining an auditor, recalibrating the auditor panel, revising the audit framework, or removing an auditor from future work.
Independence is another part of that governance.
AMCAS auditors must meet qualification requirements and comply with conflict-of-interest rules. They can’t audit businesses they’ve recently consulted for; design corrective actions; or audit the same site more than twice consecutively.
Why independent assurance matters
Internal reviews play an important role in risk management, but an independent audit can bring a different perspective.
A structured assessment can help identify where documented procedures and day-to-day operations diverge. It can also give businesses a consistent way to assess supply chain partners, rather than relying on repeated questionnaires or separate assessment processes.
Chain of Responsibility risk can extend across organisational boundaries. A common assurance framework can therefore help businesses better understand how other organisations manage risks within shared activities.
Industry consultation also highlighted the value of recognising other credible forms of assurance. The updated AMCAS program allows greater recognition of existing assurance where the evidence is relevant, current and independently supported.
What an AMCAS audit can’t tell you
AMCAS is a private, industry-led assurance activity. It’s not statutory accreditation, regulator approval or certification of legal compliance.
An audit is also a point-in-time assessment. Its findings are limited by the scope of the audit, the samples tested, the evidence available and what the auditor can observe on the day.
A certificate therefore can’t guarantee that a business remains compliant with the AMCAS program or its legal obligations, or that controls will continue operating effectively after the audit.
Responsibility for identifying and managing legal obligations remains with the business.
The real value is what happens next
The certificate isn’t the end of the process.
Often, the most valuable part of an audit comes after the findings have been identified: understanding why a gap exists, deciding what needs to change, implementing the improvement and checking that the change is working.
Good assurance shouldn’t encourage a business to ask, “How do we get a certificate?”
It should encourage a better question: “How do we know our controls are working, and what should we improve next?”
That’s the role AMCAS is designed to play.
It provides a consistent framework for assessment, independent verification and evidence-based findings, while leaving responsibility for managing risks and meeting legal obligations where it belongs: with the business.
Importantly, the support doesn’t help once the audit is complete. Businesses that undertake an AMCAS audit also gain access to supporting materials, templates, guidance and training designed to help them address identified gaps and strengthen their systems over time.
AMCAS is available through the CoRsafe platform, including free self-assessment against the audit standard.
Learn more about AMCAS and CoRsafe’s audit and advisory services, or contact the CoRsafe team to discuss your organisation’s CoR compliance and assurance needs.
© 2026 NTI Limited ABN 84 000 746 109 (CoRsafe). General information only. Limits and exclusions apply. Please refer to the full Terms and Conditions at www.cor-safe.com.au/terms-conditions. CoRsafe bears no responsibility, and shall not be held liable, for any loss, damage or injury arising directly or indirectly from your use of or reliance on the information on the CoRsafe platform or this article.
