IPAC Risk Assessment vs Audit: Which One Does Your Facility Need?
Kamyab Ghatan
Founder & Lead IPAC Consultant
September 12, 2026
10 min read
Clinics often use “risk assessment” and “audit” interchangeably, then get confused when a consultant or inspector asks for one and not the other. They are related tools, but they answer different questions and belong at different points in your infection prevention cycle.This article breaks down exactly what separates an IPAC risk assessment from an IPAC audit, when your facility needs each one, and how to build both into a single coherent program rather than treating them as competing priorities.
The Core Difference Between a Risk Assessment and an Audit
An IPAC risk assessment looks forward. It identifies potential hazards before or during an activity, asking what could go wrong given a specific situation, population, or environment.An IPAC audit looks backward and sideways. It measures whether your existing policies and practices are actually being followed as written, comparing current performance against a defined standard.Put simply, a risk assessment answers “what could happen here,” while an audit answers “is what we said we would do actually happening.”
What an IPAC Risk Assessment Actually Involves
Point-of-Care Risk Assessments
The most frequent type is the point-of-care risk assessment, a quick evaluation staff perform before each patient interaction to determine what PPE and precautions the specific situation requires.This is not a document filed once a year. It happens dozens of times daily across a busy clinic, which is why training staff to do it instinctively matters more than any written policy alone.
Facility-Level Risk Assessments
A broader facility-level risk assessment evaluates your physical layout, patient population, and known vulnerabilities on a less frequent basis, typically annually or when something material changes.Ourmedical clinic IPAC risk assessment guide walks through how to structure this kind of facility-wide review specifically for outpatient and clinic settings.
Project-Specific Risk Assessments
Construction, renovation, and outbreak situations each require their own targeted risk assessment, scoped narrowly to the specific activity or event rather than the facility as a whole.AnICRA for healthcare construction is the clearest example of this category, applied specifically before and during a defined project.
Personal Risk Assessments
Long-term care and retirement settings also apply individualized risk assessments tied to specific residents, which ourguide to personal risk assessments in the context of IPAC covers in more depth.Understanding these different risk assessment types matters because each has its own timing and trigger, unlike an audit, which typically follows a scheduled cycle.
What an IPAC Audit Actually Involves
Compliance Audits
A compliance audit checks whether your facility is following its own written policies and applicable external standards, such as PIDAC best practices or your provincial IPAC standard.This is the type most people picture when they hear “audit,” and it typically produces a scored or rated result against specific criteria.
Practice-Specific Audits
Narrower audits target a single practice area, such as hand hygiene compliance or sterilization log completeness, giving you focused data without the full scope of a comprehensive review.
External and Regulatory Audits
External bodies, including public health units and accreditation organizations, conduct their own audits using their own criteria, which your internal audit process should anticipate rather than be surprised by.OurPIDAC audit guide breaks down how to prepare specifically for the standards these external reviewers apply.With both concepts defined clearly, the practical question becomes when your facility should reach for each one.
When Your Facility Needs a Risk Assessment
Before Any New Activity or Change
Any time your facility introduces a new procedure, admits a patient or resident with a known transmissible condition, or begins a construction project, a targeted risk assessment should happen before the activity, not after.
When Your Patient or Resident Population Changes
A shift in the acuity or vulnerability of who you serve, such as a long-term care home admitting more medically complex residents, warrants a fresh facility-level risk assessment even without a specific triggering event.
During an Active Outbreak
Outbreak situations require rapid, ongoing risk assessment as the situation evolves, distinct from your routine audit schedule, since the pace of decision-making during an outbreak does not match a typical audit timeline.
When Your Facility Needs an Audit
On a Scheduled, Recurring Basis
Most facilities benefit from a defined audit calendar, whether quarterly, semi-annually, or annually, rather than running audits only when something goes wrong.Our guide onhow often to review your IPAC program offers a practical framework for setting this cadence based on your facility type and risk profile.
After a Known Compliance Issue
Following anyafter-ipac-compliance-finding situation, a focused audit specifically targeting the area of concern confirms whether corrective action actually resolved the underlying problem.
Before an External Inspection
Running your own internal audit ahead of a known external inspection gives you time to address findings on your own terms, rather than having them documented first by an outside reviewer.
How Risk Assessments and Audits Work Together
These two tools are not competitors. A mature IPAC program uses risk assessment to identify where attention is needed, and audits to confirm whether the response to that attention actually took hold.
A Practical Example
Imagine a risk assessment identifies that your waterline testing protocol has a gap during staff turnover periods.The follow-up step is not another risk assessment. It is a targeted audit, conducted a few weeks later, confirming whether the corrective training actually changed staff behaviour during the next turnover period.
Building Both Into Your Annual Calendar
Rather than treating risk assessment and audit activity as separate initiatives, map them onto the same annual calendar so your team sees clearly which weeks involve which type of activity and why.This structure also makes your documentation cleaner, since inspectors reviewing yourIPAC audit documentation can quickly see the connection between an identified risk and the audit that verified its resolution.
Common Confusion Points Worth Clarifying
Is a Program Review the Same as an Audit?
Not quite. Aprogram review versus audit comparison is worth reading if your facility uses these terms loosely, since a program review tends to be broader and more strategic, while an audit is typically narrower and criteria-based.
Does a Risk Assessment Require External Expertise?
Point-of-care risk assessments are designed for frontline staff to perform independently after training, while facility-level and project-specific risk assessments often benefit from external input, particularly for facilities without a dedicated infection control practitioner.
Can One Consultant Handle Both Functions?
Yes, and in fact this is often more efficient. A consultant retained forIPAC consulting can typically run both your periodic audits and support targeted risk assessments as they arise, giving your facility continuity between the two functions rather than switching providers depending on which task is needed.
How These Tools Apply Differently Across Facility Types
Dental Practices
Dental practices lean heavily on point-of-care and project-specific risk assessments, such as those tied to a sterilization room renovation, paired with periodic audits following the structure in ourdental IPAC self-audit resource.
Long-Term Care Homes
Long-term care homes require both facility-level and individualized personal risk assessments alongside a more heavily regulated audit cycle, given the interdisciplinary committee structure required under current provincial regulation.
Veterinary Hospitals
Veterinary facilities apply risk assessment principles adapted for species-specific and zoonotic risk, paired with audits covering the broaderveterinary IPAC audit categories relevant to animal care settings.
Building a Simple Decision Framework for Your Team
Ask What Changed First
When deciding which tool to reach for, start by asking whether something in your environment, population, or activity has changed recently. If yes, a risk assessment is the right starting point.
Ask What You Are Verifying Second
If nothing has changed but you want to confirm existing practices are being followed consistently, an audit is the appropriate tool rather than a fresh risk assessment.
Document the Decision Either Way
Whichever tool you choose, document why you chose it, since this reasoning becomes valuable context if a regulator or accreditation surveyor later asks about your facility’s overall IPAC methodology.
Avoiding the Trap of Doing Neither Consistently
The Danger of Reactive-Only Activity
Facilities that only conduct risk assessments and audits in response to a specific incident tend to have larger, more severe findings when problems do surface, simply because smaller issues were never caught early.
Building Both Into Standing Operating Rhythm
Treating both risk assessment and audit activity as standing operational rhythm, rather than exceptional responses to a crisis, is what separates facilities with consistently strong IPAC performance from those cycling through repeated compliance issues.
Deciding What Your Facility Needs Right Now
If your facility has never had either a structured audit process or a facility-level risk assessment, start with the risk assessment.It gives you the clearest picture of where your actual vulnerabilities sit, which then tells you exactly what your first audit should focus on rather than trying to audit everything at once with limited resources.
Signs You Need to Bring in External Support
If your internal team cannot confidently distinguish between these two functions, or if your last audit and risk assessment both happened more than a year ago, that combination is a reliable signal it is time to considerwhen to hire an IPAC consultant for your facility.
What This Looks Like Over a Full Calendar Year
A Sample Annual Rhythm
A typical annual rhythm might include monthly point-of-care risk assessment spot checks, a quarterly practice-specific audit rotating through hand hygiene, sterilization, and environmental cleaning, a mid-year facility-level risk assessment, and a comprehensive annual audit ahead of any expected external inspection.
Adjusting the Rhythm for Your Facility Type
A dental practice might compress this rhythm given its smaller footprint, while a long-term care home following the interdisciplinary committee structure required under current regulation will typically need a more frequent, more heavily documented version of the same underlying cycle.
Keeping the Rhythm Realistic
The right cadence is one your team can actually sustain consistently, since an ambitious schedule abandoned after two months provides less protection than a modest one followed reliably all year.
FAQ
Is an IPAC audit legally required?Requirements vary by facility type and jurisdiction, but most regulated healthcare and long-term care settings in Ontario are expected to maintain both documented risk assessments and periodic audit activity as part of a functioning IPAC program.How long does a typical facility-level risk assessment take?Timelines vary with facility size and complexity, but a thorough facility-level risk assessment for a mid-sized clinic or home typically takes one to two weeks from initial data gathering to a completed report.Should point-of-care risk assessments be documented?Yes, at minimum through spot-check verification during audits, even though the assessment itself happens quickly and informally at the point of care.What comes first, the risk assessment or the audit?Generally the risk assessment comes first, since it identifies where your facility’s specific vulnerabilities lie, which then focuses your subsequent audit activity on the areas that matter most.
Unsure whether your facility needs a risk assessment, an audit, or both right now?
Book afree consult with InfectionShield to get a clear recommendation tailored to your facility type and current IPAC program status.