Risk Management

Critical Control Explained: 4 Proofs That a Barrier Can Hold

A critical control is a barrier that must prevent or limit a serious exposure. This glossary explains four proofs that show whether the control exists, works, is understood, and remains reliable under real operating conditions.

By 4 min read
risk management scene on critical control explained 4 proofs that a barrier can hold — Critical Control Explained: 4 Proofs T

Key takeaways

  1. 01Define a critical control by the serious exposure it must prevent or limit, not by the amount of paperwork around it.
  2. 02Test presence, function, understanding, and endurance before treating a barrier as dependable.
  3. 03Use field evidence and leadership decisions to verify whether the control remains credible when work changes.

F7 glossary for EHS managers, supervisors, and risk owners

A critical control is a barrier that must prevent or limit a serious exposure. It matters when a task can create a serious injury or fatality, because a general list of precautions may hide the one barrier whose failure changes the consequence.

This explanation uses four practical proofs. A control should be present, functional, understood, and durable under the conditions in which work actually takes place.

A critical control is a specific barrier linked to a credible serious exposure. It may be engineered, procedural, physical, or organizational, but its value depends on evidence that it is present, performs its protective function, is understood by the people who rely on it, and remains reliable when work changes.

What does a critical control mean?

A critical control is not simply the most important item on a risk assessment. It is the barrier whose failure would allow a serious exposure to reach a person or would remove a necessary limit on the consequences. The control can be a verified isolation, a guard, a fall-prevention system, a separation distance, a tested interlock, or a decision gate that stops work when conditions are not met.

James Reason’s work on latent failures, especially Managing the Risks of Organizational Accidents (1997), helps explain why the final unsafe moment is not the whole control story. Design, planning, maintenance, supervision, and decision rights can determine whether a barrier is available before the worker reaches the exposure.

Andreza Araujo’s safety work applies the same discipline to culture and risk. Her book Safety Culture: From Theory to Practice treats declared values as credible only when daily routines and decisions support them. A critical control therefore needs more than a procedure reference. It needs observable evidence.

4 proofs that a critical control can hold

1. Presence

The first proof is simple. The barrier exists at the point where the exposure can occur, and it is available before work begins. A fall-prevention anchor, isolation point, machine guard, or exclusion zone that is missing, bypassed, or unavailable has already failed this test.

Presence includes the correct specification and location. A control that exists in a storeroom, on a drawing, or in a checklist is not protecting the task until it is installed or available where the work requires it.

2. Function

The second proof is performance. The barrier performs the action that separates the person from the energy, substance, movement, or condition that can cause harm. A closed valve is not proof of isolation if stored energy remains. A guard is not proof of protection if it can be defeated during normal access.

Verification should connect the control to a test. That may involve a zero-energy check, a functional alarm test, a measured separation, a load rating, or a documented inspection whose result is clear enough for the next decision.

3. Understanding

The third proof is shared understanding. The people who perform, supervise, and authorize the task know what the control protects, how to recognize a failed condition, and which decision follows. This is where a short teach-back can reveal a gap that a signature cannot.

Andreza Araujo’s emphasis on behavior and risk perception is useful here because workers may see the same barrier differently from the person who wrote the procedure. Ask the person closest to the task to explain the failure signal in plain language, then check whether the escalation route is usable within the next few minutes.

4. Endurance

The fourth proof is endurance. The control remains dependable across shifts, handovers, maintenance, weather, staffing changes, simultaneous work, and production pressure. A barrier that works only during a planned demonstration is not a dependable barrier.

ISO 45001:2018 supports this systems view by requiring organizations to manage operational controls, change, competence, and monitoring as connected parts of the OH&S system. Endurance asks whether those parts still support the critical control after the plan meets the field.

How can leaders differentiate the four proofs?

ProofQuestionEvidenceFailure signal
PresenceIs the barrier available at the exposure?Correct control in the correct locationMissing, bypassed, or unavailable
FunctionDoes it perform its protective role?Test, inspection, measurement, or interlock responseFailed test or unknown condition
UnderstandingCan the team identify failure and act?Teach-back and clear escalation routeConflicting answers or hesitation
EnduranceWill it remain reliable through change?Shift, maintenance, and change evidenceControl weakens under pressure

The table separates four questions that are often collapsed into one audit result. A control can be present but nonfunctional, functional but misunderstood, or effective on day one but unreliable after a handover. Leaders should record the weakest proof because that is where the exposure remains open.

For a deeper review, compare this glossary with six distortions that hide weak controls and the four consequence checks that keep SIF exposure visible.

When should a critical control review be used?

Use the four-proof review before high-risk work, after a serious near miss, during management of change, when a control has failed, or when favorable metrics are not supported by field evidence. It is also useful when a risk owner is accepting residual risk and needs to show which barrier makes that decision reasonable.

Across 25+ years of EHS leadership, Andreza Araujo has connected safety performance with the choices that leaders make visible. Her experience across more than 250 cultural transformation projects reinforces a practical point. The number of controls in a register says less than the quality of the few barriers that matter most.

Start with one exposure, one control, and four questions. If the evidence is weak, do not rename the weakness as acceptable residual risk. Restore the barrier, clarify the decision, and verify the result in the work area. Andreza Araujo’s books and safety resources provide further guidance for connecting culture, leadership, and prevention.

Topics critical-controls barrier-verification sif risk-management control-effectiveness field-verification

Frequently asked questions

What is a critical control in safety?
A critical control is a barrier that prevents a serious exposure from reaching a person or limits the consequences if the exposure occurs. It can be an engineered feature, an isolation, a physical separation, a tested alarm, a permit condition, or a decision rule that stops work. The defining question is whether the control has a direct relationship with a credible serious injury or fatality pathway, not whether it appears in a procedure.
How do you verify whether a critical control works?
Verify four conditions. First, the control is present where the task occurs. Second, it performs the protective function it is meant to perform. Third, the people involved understand how to recognize failure and escalate it. Fourth, the control remains reliable across shifts, changes, maintenance, and production pressure. A signed checklist alone cannot prove all four conditions.
What is the difference between a critical control and a routine safety rule?
A routine safety rule can support orderly work, while a critical control is tied to a defined serious exposure and a credible failure path. Breaking a routine rule may create disorder or minor exposure. Losing a critical control can place someone directly in a fatal-risk pathway. The distinction helps leaders focus verification effort where control failure would matter most.

About the author

Andreza Araújo

Safety Culture Expert | Senior EHS Executive

Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.

  • Civil & Safety Engineer (Unicamp)
  • M.A. Environmental Diplomacy (University of Geneva)
  • Sustainability Cert (IMD Switzerland)
  • People Management & Coaching (Ohio University)
  • UN Paris speaker representative for Brazil
  • ILO Turin speaker
  • LinkedIn Top Voice
  • Indra Nooyi PepsiCo CEO recognition (2x)

Documentaries

Watch Andreza's documentaries

Three productions on safety culture, organizational failure and the human lessons behind major disasters.

Podcasts

Listen to Andreza's podcasts

She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.

Summarize with AI