Safety Indicators and Metrics

Critical-Control Dashboards: 4 Gaps That Make Executive Safety Data Look Better Than the Work

Executive safety dashboards become misleading when they report activity without showing whether critical controls were present, used, verified, and corrected when they failed.

By 5 min read

Key takeaways

  1. 01A complete safety dashboard can mislead executives when it counts activity without showing whether the critical control held in the work.
  2. 02Every critical-control measure should identify the serious exposure, expected control state, evidence collected, and correction owner.
  3. 03Action closure is not proof of effectiveness because the original exposure may remain after a procedure, training event, or repair is recorded as complete.
  4. 04Regional averages should appear with material exceptions, repeated deviations, unresolved temporary controls, and escalation ownership.
  5. 05Across 25+ years and more than 250 cultural-transformation projects, Andreza Araujo has seen that measurement matters when it changes an operating decision.

A dashboard can be complete, timely, and visually reassuring while the control that prevents a fatal exposure has not been tested in the field. Executive safety data is useful only when it helps leaders decide whether serious risk is controlled, funded, escalated, or accepted with a visible owner.

The central thesis is simple but demanding. A safety dashboard should not ask only whether an inspection happened or an action was closed. It should show whether the work condition changed, whether the critical barrier held, and what leadership did when evidence showed that it did not.

Why activity data can hide critical-control failure

Most organizations begin with activity because activity is easy to count. They report training completion, inspections, observations, meetings, corrective actions, and audit scores. Those measures can reveal management effort, yet they do not automatically demonstrate that a person was protected when the exposure mattered most.

James Reason's work on organizational accidents helps explain the gap. Harmful events emerge when active failures meet latent conditions embedded in design, supervision, resourcing, maintenance, or decision-making. A dashboard that counts activity without checking those conditions can show a busy safety system while the pathway to harm remains intact.

Across 25+ years leading EHS work in multinational environments, Andreza Araujo has observed that leaders gain better decisions when safety evidence is tied to the work condition they can change. In more than 250 cultural-transformation projects, the recurring lesson is that measurement creates value only when it clarifies ownership and changes an operating choice.

1. Verification is counted without naming the control

A verification percentage sounds meaningful until leaders ask what the verifier actually checked. A field check may confirm that a form exists, a permit was signed, or a briefing occurred. None of those observations proves that the critical control was available at the exposure point and used as the task required.

The first gap is a missing object. The dashboard reports the act of verification but not the control, condition, or exposure that was tested. Executives should require every measure to name the exposure, expected control state, evidence collected, and person with authority to correct a failure.

2. Presence is reported without reliability under pressure

A control can be present during a planned audit and unreliable during the shift when production changes, contractors arrive late, equipment is unavailable, or the sequence is altered. One observation is not proof that a control will hold across normal variation.

The exposure-based safety metrics framework helps leaders connect measurement to the time, task, and population that actually encounter the hazard. A decision-ready dashboard shows where reliability was demonstrated, where it was assumed, and where evidence is missing.

Leaders who still rely on injury-rate summaries should compare this evidence with the TRIR, SIF exposure, and control-effectiveness comparison, because a low lagging rate does not prove that a serious exposure is controlled.

3. Actions are closed without testing whether risk changed

Action closure is often treated as the end of the safety process. The team uploads a procedure, completes training, repairs equipment, or records a review, and the dashboard turns the item green. A closed action can still leave the original exposure unchanged.

Effectiveness needs a defined test that matches the action. Inspect a physical barrier in the work area. Sample a decision process and ask which evidence supported it. Observe competence in the task rather than relying on attendance. The safety-assurance diagnostic helps leaders test whether weak controls survive when review stops at completion status.

4. Material exceptions disappear inside averages

Averages make cross-site reporting easier, but they can conceal the one exception that deserves executive attention. A high regional verification rate may coexist with a facility where a control is repeatedly bypassed, a temporary measure became permanent, or the risk owner lacks authority to resolve the condition.

Executives should receive the average and the exceptions together. The exception view should identify the exposure, failed or uncertain control, duration, decision owner, and next review date. Material uncertainty cannot disappear because stronger sites improved the average.

What a decision-ready dashboard should show

A decision-ready dashboard connects the serious exposure, expected control, field verification, and response when evidence is weak. The table separates common activity reporting from evidence that supports executive action.

Activity viewDecision-ready view
Inspection completedCritical control verified against a named exposure, with field evidence and owner
Training completedRequired decision demonstrated during the task
Action closedEffectiveness tested after implementation
Regional average is greenAverage shown with material exceptions and escalation

How leaders should review the evidence

The answer is not a larger dashboard. Select a small number of critical exposures, ask for the original field evidence, and trace one item from the reported measure to the decision that followed. If the route cannot be reconstructed, the metric is not ready to guide executive judgment.

Review the evidence with the operational owner, not only with the person who maintains the data. The owner should explain what condition could cause harm, which control should hold, what was observed, and what authority exists when the control is unavailable. EHS can provide method and challenge, while the operation remains accountable.

What to change in the next executive review

Remove one activity metric that no longer changes a decision, then replace it with a measure that links exposure, control, verification, and response. Ask for one record that passed and one that failed, because the failure often reveals more about system reliability than a long sequence of green results.

Return to the worksite and check whether the executive review changed anything workers can see. Andreza Araujo's work, including the 50% accident reduction achieved at PepsiCo South America in six months, reinforces the point that measurable improvement comes from changing how leaders and operations act, not from polishing the report.

Conclusion: make the dashboard answer the risk question

Executive safety data becomes trustworthy when it answers whether the serious exposure is controlled in the work, whether the control can be relied on under pressure, whether the corrective action changed the condition, and whether unresolved exceptions are visible to the person who can act.

If the dashboard cannot answer those questions, its activity measures may still be useful, but they should not be mistaken for proof of control. For leaders who want to connect safety culture, critical-risk governance, and measurable operational change, visit Andreza Araujo.

Frequently asked questions

What is a critical-control dashboard?

It reports whether controls that prevent or limit serious exposures are defined, available, verified in the field, and corrected when evidence shows weakness.

Why are activity metrics insufficient?

They show that a task occurred, but not always whether the task addressed the exposure or changed the condition.

How can executives test a metric?

Ask what decision it changes, which exposure it represents, what evidence supports the result, who owns the response, and when effectiveness will be checked.

Should every site use identical controls?

Sites should share definitions for serious exposures and evidence quality, while specific controls can reflect local conditions when the difference is documented and justified.

What should appear beside a regional average?

Show material exceptions, repeated failures, unresolved temporary controls, duration of exposure, accountable owners, and the next review date.

Topics safety-indicators-and-metrics critical-controls safety-dashboard control-verification executive-safety serious-injury-fatality-prevention ehs-leadership

Frequently asked questions

What is a critical-control dashboard?
It reports whether controls that prevent or limit serious exposures are defined, available, verified in the field, and corrected when evidence shows weakness.
Why are activity metrics insufficient?
They show that a task occurred, but not always whether the task addressed the exposure or changed the condition.
How can executives test a metric?
Ask what decision it changes, which exposure it represents, what evidence supports the result, who owns the response, and when effectiveness will be checked.
Should every site use identical controls?
Sites should share definitions for serious exposures and evidence quality, while specific controls can reflect local conditions when the difference is documented and justified.
What should appear beside a regional average?
Show material exceptions, repeated failures, unresolved temporary controls, duration of exposure, accountable owners, and the next review date.

About the author

Andreza Araújo

Safety Culture Expert | Senior EHS Executive

Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.

  • Civil & Safety Engineer (Unicamp)
  • M.A. Environmental Diplomacy (University of Geneva)
  • Sustainability Cert (IMD Switzerland)
  • People Management & Coaching (Ohio University)
  • UN Paris speaker representative for Brazil
  • ILO Turin speaker
  • LinkedIn Top Voice
  • Indra Nooyi PepsiCo CEO recognition (2x)

Documentaries

Watch Andreza's documentaries

Three productions on safety culture, organizational failure and the human lessons behind major disasters.

Podcasts

Listen to Andreza's podcasts

She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.

Summarize with AI