Regulatory audits have been judged as a vital instrument to ensure compliance with regulatory obligations. Similarity in understanding of the achievement of regulatory outcomes in both authorities and companies is a prerequisite to secure conformity to regulations. A divergent approach to audits suggests restricted effects of regulatory audits. We analysed nonconformity, documented in 153 audits of 113 Norwegian hydropower and aquaculture companies. Twenty companies were audited 2–12 times during 2012–2020. There were no indications that an audit resulted in improved awareness in the company. A major part of nonconformity is connected to financial interest, likely of significance to the company itself. In addition to the environmental consequences, the failure to uncover, correct, and prevent nonconformity is alarming, seen both from a risk governance and a financial perspective. Our study of water resource management and regulation shows that merely performing audits have no significant effect on improvement. We claim that it is futile to implement audits if they are not put into some systematic constructed programme theory in every single company. When stating nonconformity in regulatory audits, the rational way of following up by the authorities should focus on how the company and site managers in practice work with improving safety and quality.