Risk Management

Control Drift: 5 Myths That Keep Risk Assessments Stale

Five common myths let risk assessments drift away from real work. Learn how EHS leaders can reconnect exposure, controls, ownership, and evidence.

By 5 min read
risk management scene on control drift 5 myths that keep risk assessments stale — Control Drift: 5 Myths That Keep Risk Asses

Key takeaways

  1. 01Challenge review dates by testing whether exposure, people, task sequence, or controls changed before the next scheduled assessment.
  2. 02Separate a lower risk score from verified risk reduction by checking the control itself, its owner, and the evidence that it holds.
  3. 03Assign risk ownership to the operational role that can change work, allocate resources, accept residual risk, or stop the task.
  4. 04Reduce control drift by treating frontline challenge as evidence about changed conditions rather than as resistance to the assessment.
  5. 05Apply Andreza Ara�jo's practical safety leadership methods to connect risk decisions with culture, control verification, and accountability.

A risk assessment can remain signed, current in the database, and wrong for the work. When a control changes, a crew is replaced, or production pressure compresses the task, the risk picture can drift without any field event forcing a review.

Control drift is the widening gap between the protection a risk assessment describes and the protection the operation can actually deliver. This article examines five myths that allow that gap to grow, then translates each correction into a decision for EHS managers, risk owners, and frontline supervisors.

Why control drift deserves a separate review

Risk management is not complete when a hazard has been scored. It is complete when the organization can explain which control protects people, who owns it, what evidence shows that it works, and what change would trigger a new decision. ISO 31000:2018 describes risk management as an integrated process, which means the assessment cannot be detached from operations, governance, and review.

Andreza Ara�jo makes the same distinction in A Ilus�o da Conformidade, whose central warning is that a completed requirement can create false confidence when it is no longer connected to the work. A form may prove that an assessment existed at one point. It cannot prove that the barrier still holds under current conditions.

The practical question is not whether the score changed. It is whether the exposure, control, decision rights, or evidence changed. If any of those four elements moved, the assessment may need a new decision even when the risk matrix displays the same color.

Myth 1: A risk assessment stays valid until its review date

A calendar date is an administrative boundary, not proof that the operating risk is stable. A review scheduled every 12 months can miss a change that occurred after 12 hours, particularly when a contractor, temporary control, new material, or altered production sequence enters the task.

The myth survives because expiry dates are easy to audit. The harder test is whether the assumptions behind the assessment are still true. HSE guidance on managing risk places emphasis on identifying hazards, deciding who may be harmed, and reviewing controls, rather than treating the document as a permanent authorization.

Replace the date-only rule with four triggers: a change in equipment, a change in people or competence, a change in task sequence, and a control failure or near miss. A supervisor does not need to rewrite every paragraph. The supervisor does need authority to reopen the decision before work continues.

Myth 2: A lower score proves that the risk was reduced

A lower score can reflect a real improvement, but it can also reflect a softer severity estimate, a different assessor, or a control that was assumed rather than tested. The number describes the assessment method. It does not independently verify the condition in the field.

Suppose a confined-space assessment moves from 16 to 8 after a ventilation control is added. The reduction is meaningful only if the ventilation capacity, alarm response, inspection interval, and rescue route are defined and evidenced. Four pieces of paperwork should not be mistaken for four functioning safeguards.

NIOSH places elimination and engineering controls above administrative controls and personal protective equipment because controls that depend less on perfect human action usually provide stronger protection. A score should therefore be challenged when the claimed improvement comes mainly from instructions, reminders, or presumed compliance.

Myth 3: The risk owner is the person who completed the assessment

The author of an assessment may understand the hazard, yet authorship does not create authority over the equipment, staffing, budget, or operating decision that keeps the control effective. When those responsibilities are blurred, the EHS function becomes accountable for a condition it cannot change.

An effective risk owner is the role that can allocate resources, change the work, accept residual risk within defined limits, or stop the activity. The person who enters the data can support that decision, but should not silently inherit it.

Use a two-part record. Name the operational owner and name the technical adviser. Then record the evidence that each role must provide before the task starts. This arrangement makes escalation visible when a control needs design work, procurement, maintenance, or a staffing change.

Myth 4: More controls always mean less risk

Five weak controls do not automatically outperform one well-designed control. A long action list can conceal the fact that every item depends on the same supervisor noticing the same deviation during a busy shift.

Control quality depends on independence, reliability, detectability, and recovery. If a permit, toolbox talk, observation, and checklist all depend on the same rushed conversation, they may be four descriptions of one fragile administrative layer rather than four independent barriers.

Ask what changes the exposure if the first control fails. If the answer is another reminder to perform the same action, the assessment has accumulated activity rather than protection. The critical-control verification method offers a useful adjacent test because it asks for evidence that a barrier can hold under operating conditions, not merely evidence that someone listed it.

Myth 5: Frontline challenge means the risk assessment process has failed

A challenge from the person performing the work is often the earliest evidence that the assessment has lost contact with reality. Treating that challenge as resistance teaches people to preserve the document instead of improving the control.

Technical disagreement becomes useful when the organization separates the person from the problem, records the changed condition, and routes the decision to someone with authority. The aim is not to approve every objection. The aim is to ensure that a credible concern receives a reasoned response before exposure is normalized.

For supervisors, the response can fit in three questions. What changed since the assessment? Which control is now harder to execute? What evidence would allow the work to continue safely? The answers should update the decision log, not disappear into a verbal exchange.

Andreza Ara�jo's book Make The Difference: Be a Leader in Health & Safety treats leadership presence as an operating responsibility. That principle matters here because a supervisor who receives a challenge and returns with a visible decision strengthens the control system, while a supervisor who dismisses it protects the paperwork instead.

What to do now when control drift is suspected

Start with one high-consequence task rather than a full-system campaign. Compare the last approved assessment with the current work in five fields: exposure, control, owner, evidence, and decision trigger.

  • Mark each field as unchanged, changed, unknown, or no longer applicable.
  • Escalate every unknown that affects a serious-injury or fatality exposure.
  • Test the critical control under the same conditions in which the work occurs.
  • Record the decision, the owner, and the next verification time.
  • Close the review only when the operating condition, not just the document, is clear.

A useful governance cadence is a 30-day review for newly changed controls, a 90-day review for recurring drift, and an immediate review after a control failure or material change. Those intervals are decision prompts, not substitutes for judgment.

For a practical next step, compare this review with the risk-acceptance gate for frontline supervisors and the stale-risk-picture test for risk registers. Together, they help connect assessment, ownership, and verification.

Turn risk assessments into decisions that survive operational change. Explore Andreza Ara�jo's safety leadership resources for practical methods that connect culture, control, and accountability.

Conclusion: the assessment is only as current as the control

Control drift begins when the organization treats an assessment as a finished product instead of a living decision. A current date, a lower score, a longer control list, or a completed signature cannot replace evidence that the barrier still works.

The corrective move is specific. Reopen the assessment when the exposure, control, owner, or evidence changes, then require a decision that the operation can verify. That is how risk management moves from document maintenance to protection that people can rely on.

Topics risk-management risk-assessment control-drift critical-controls ehs-manager

Frequently asked questions

How often should a workplace risk assessment be reviewed?
Review frequency should combine a planned cadence with trigger events. A 12-month schedule may support governance, but a change in equipment, people, task sequence, materials, or control performance should reopen the assessment sooner. Review immediately after a serious control failure or material change, and use shorter intervals such as 30 or 90 days when a control is new or repeatedly unstable.
Does a lower risk score prove that risk was reduced?
No. A lower score shows that the assessment result changed, not that the control performed better. Confirm the claimed reduction by checking the control under operating conditions, naming its owner, and recording evidence such as inspection results, test records, or field verification. If the reduction comes only from a changed assumption or a softer rating, the exposure may be unchanged.
Who should own a workplace risk assessment?
The risk owner should be the operational role that can change the work, provide resources, accept residual risk within defined limits, or stop the activity. An EHS professional may facilitate the assessment and provide technical advice, while the operating leader remains accountable for the decision and the control conditions.
What is the difference between a risk assessment and a critical-control review?
A risk assessment identifies hazards, evaluates exposure, and selects controls. A critical-control review tests whether a control that protects against serious harm is present, effective, and owned under real operating conditions. The two activities complement each other. The assessment explains what should protect people, while the field review checks whether that protection can actually hold.
How does Andreza Ara�jo connect safety culture with risk management?
Andreza Ara�jo connects safety culture with the quality of decisions made when work changes or pressure rises. In her books, including A Ilus�o da Conformidade and Make The Difference: Be a Leader in Health & Safety, compliance is not treated as proof that protection is working. Leaders must connect ownership, field evidence, and visible follow-through.

About the author

Andreza Araújo

Safety Culture Expert | Senior EHS Executive

Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.

  • Civil & Safety Engineer (Unicamp)
  • M.A. Environmental Diplomacy (University of Geneva)
  • Sustainability Cert (IMD Switzerland)
  • People Management & Coaching (Ohio University)
  • UN Paris speaker representative for Brazil
  • ILO Turin speaker
  • LinkedIn Top Voice
  • Indra Nooyi PepsiCo CEO recognition (2x)

Documentaries

Watch Andreza's documentaries

Three productions on safety culture, organizational failure and the human lessons behind major disasters.

Podcasts

Listen to Andreza's podcasts

She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.

Summarize with AI