Safety Indicators and Metrics

Critical Control Verification: 5 Gaps That Make Dashboards Lie

Critical control verification keeps dashboards honest by proving the barrier still exists in the field, not just on the scorecard.

By 7 min read
metrics dashboard representing critical control verification 5 gaps that make dashboards lie — Critical Control Verification:

Key takeaways

  1. 01Critical control verification tells leaders whether a barrier still exists at the point of work.
  2. 02A dashboard can be accurate and still be wrong when it counts activity instead of control health.
  3. 03Metric ownership only matters when the owner can change the threshold, the cadence, and the field check.
  4. 04Lagging numbers still matter, but they cannot replace precursor evidence or live verification.

Critical control verification is the field check that proves a barrier still exists and still works. Dashboards become unreliable when they count activity, closeout speed, or attendance as if those numbers were proof of control.

Across 25+ years in executive EHS and more than 250 cultural transformation projects, Andreza Araujo has seen the same pattern repeat. Leaders trust the dashboard because it is tidy, then discover that the tidy number did not tell them whether the barrier was live. During the PepsiCo South America period, where the accident ratio fell 50% in six months, the lesson was not to collect more numbers. The lesson was to ask better questions about the work behind the number.

This article is for plant managers, EHS managers, and directors who need a metric stack that can survive pressure. The companion piece on metric ownership shows why a number without an owner turns into theater, while safety indicators explained separates lagging, leading, precursor, and control checks before the room mixes them up.

ISO 45001:2018 asks organizations to monitor, measure, analyze, and evaluate performance, yet the standard does not tell a site which measure proves barrier health. That is the gap this article addresses. James Reason helps explain why the visible event usually sits on top of latent conditions, while Patrick Hudson's maturity model helps leaders see whether the site is still reactive, calculative, or genuinely proactive.

Why the scorecard can be accurate and still wrong

A dashboard can be accurate and still fail the work. It may count attendance, action closure, observation volume, and inspection frequency exactly as designed, while missing the real question, which is whether the control still protects the task that matters. A tidy score is not the same thing as a verified barrier.

That mistake survives because the scorecard is easy to present. A leader can point to a rising number and feel informed, even when the field has changed since the last review. In Safety Culture: From Theory to Practice, Andreza Araujo argues that culture shows up in repeated decisions, especially when pressure rises. A metric that does not change the decision simply decorates the pressure.

The practical reader for this piece is the manager who already has data but suspects the data is too polite. If the dashboard says the plant is safe while the field keeps finding the same exceptions, the plant does not have a measurement problem only. It has a control translation problem.

Gap 1: Completion rate replaces verification

The first gap appears when leaders reward completion as if completion meant control. A permit closed on time, an action marked done, or a checklist returned to the office may look disciplined, although none of those events proves the barrier still exists in the field.

This is where many teams over-read their own hygiene. If the completion rate rises, the room tends to assume the site is improving. Yet completion only says that administration moved. It does not say whether the guard was reset, the isolation was still in place, or the supervisor actually saw the task face before work resumed.

The article on leading-indicator quality audit is useful here because it forces the owner to show evidence, not just a closeout date. If a metric cannot survive a field question, it is probably measuring paperwork speed rather than control health.

Gap 2: The owner becomes the analyst

Dashboards often get assigned to analysts, coordinators, or EHS specialists who can refresh the numbers but cannot change the work. That setup feels efficient, although it quietly separates data from authority. The person who sees the trend is not the person who can fix the trend.

When metric ownership stays at the analyst level, the dashboard becomes a reporting asset instead of a decision asset. The analyst can explain the curve, but the line manager still decides staffing, sequencing, contractor interface, and stop-work timing. Without decision rights, ownership is only clerical.

Andreza Araujo's point in more than 250 projects is simple. If the owner cannot change the routine, the owner does not own the risk. That is why metric ownership and decision rights belong in the same conversation, not in separate meetings.

Gap 3: Lagging numbers crowd out precursor evidence

Lagging indicators still matter because they tell the organization what it already paid for. The problem starts when they crowd out precursor evidence that could have changed the decision earlier. If the review only sees incident counts, recordables, and days lost, it arrives after the real warning.

James Reason remains the right reference because latent conditions rarely announce themselves in the lagging number. They show up first as drift, repetition, weak supervision, poor handover, or a control that is no longer checked with the same discipline. A review that ignores those weak signals asks the injury count to do the job of foresight.

The companion article on safety indicators explained separates lagging, leading, precursor, and control checks so the team can stop asking one metric to answer every question. That distinction matters because a board that only sees the final number is reading yesterday, not governing tomorrow.

Gap 4: The field check arrives after the risk changed

Some teams do have a control check, but it is too late to matter. The verification happens after the task changed, the crew changed, or the worksite changed. In that case, the check proves that someone looked, not that the barrier was live when the exposure mattered.

This gap is easy to miss because the audit trail looks clean. The field check was completed, the file was signed, and the dashboard turned green. Yet the work moved faster than the verification cycle, which means the signal arrived after the hazard had already shifted.

Patrick Hudson's maturity model helps here because a reactive site treats verification as an event, while a proactive site treats verification as part of the work. If the check is not timed to the decision, it is only a memory of control, not proof of control.

Gap 5: The dashboard counts actions, not decisions

A very busy dashboard can still be a weak governance tool if it counts action volume instead of decision quality. Ten open actions look worse than five closed actions until the team asks whether any of those actions changed the control that mattered. Quantity can hide weak judgment.

This is where management reviews often drift into performance theater. The room celebrates closeout speed, observation volume, and attendance, while nobody asks which decision changed because of the data. A number that never changes a choice is decoration. A number that changes a control is management.

Andreza Araujo's book Safety Culture: From Theory to Practice is useful here because repeated decisions reveal the real operating model. If the dashboard creates activity without changing who decides, what is verified, or when the task stops, the dashboard is not governing risk. It is managing reassurance.

What a verification-grade metric stack looks like

A verification-grade stack does not replace all metrics. It sorts them by job. One layer tells the organization what already happened. Another layer shows whether control is moving. A third layer detects weak signals. The last layer proves the barrier still exists at the point of work.

Metric layer What it should answer What it must not pretend to answer
Lagging result What harm already landed? Whether the next serious event is prevented
Leading movement Is the control routine getting stronger? Whether the barrier was live in the field
Precursor signal Which weak pattern is starting to repeat? Whether the task is currently protected
Control check Does the barrier still exist now? Whether the scorecard looks neat
Decision metric Who must act now and by when? That the analyst already owns the risk

The article on metric ownership becomes the companion layer for this stack because each metric needs a person who can change the threshold, the review cadence, the escalation path, and the field check. Without that structure, the stack is only a prettier spreadsheet.

What leaders should change next

Start with one high-risk process, not the whole dashboard. Pick the control that matters most, name the decision owner, and ask what field evidence would prove that the control is still live. If the answer is vague, the metric is too far from the work.

Then remove one number that creates noise. Many sites need less measurement, not more. If the team already has attendance, closeout, and output data, add only the signal that tells leaders whether the barrier is still working. That discipline usually improves the dashboard faster than another round of metric expansion.

Finally, test the review rhythm. The article on safety dashboards shows why leaders should ask whether the board can change the work, not just admire the graph. If the review cannot trigger a decision, then the room is looking at data, not governing risk.

FAQ

What is critical control verification?

It is the field check that proves a barrier still exists and still works at the point of exposure. A sign-off, closeout, or attendance record does not by itself prove that the control remained effective when the task changed.

Why can dashboards lie even when the numbers are correct?

Because a correct number can still answer the wrong question. The dashboard may count activity, attendance, or closeout speed perfectly while missing the real issue, which is whether the control was live when the work happened.

What should a manager do when the dashboard looks good but the field does not?

The manager should trust the field, then simplify the metric stack until the scorecard reflects actual control. If the field keeps finding the same gap, the problem is usually not the worker. It is the way the system reads itself.

Which Andreza Araujo book fits this topic best?

Safety Culture: From Theory to Practice fits best because it links repeated decisions with real culture. Far Beyond Zero, glossed from Muito Além do Zero, is a useful companion when leaders need to understand how targets can distort the picture.

Which article should leaders read next?

Metric ownership is the best next step, because ownership decides who changes the number, who verifies the field, and who escalates when the signal turns red.

Critical control verification matters because it keeps the metric tied to the work. Once the dashboard is forced to prove the barrier, the scorecard stops being a comfort object and starts being a control tool.

Topics safety-indicators-and-metrics critical-control-verification dashboards field-evidence metric-ownership safety-leadership

Frequently asked questions

What is critical control verification?
It is the field check that proves a barrier still exists and still works at the point of exposure. A sign-off, closeout, or attendance record does not by itself prove that the control remained effective when the task changed.
Why can dashboards lie even when the numbers are correct?
Because a correct number can still answer the wrong question. The dashboard may count activity, attendance, or closeout speed perfectly while missing the real issue, which is whether the control was live when the work happened.
What should a manager do when the dashboard looks good but the field does not?
The manager should trust the field, then simplify the metric stack until the scorecard reflects actual control. If the field keeps finding the same gap, the problem is usually not the worker. It is the way the system reads itself.
Which Andreza Araujo book fits this topic best?
Safety Culture: From Theory to Practice fits best because it links repeated decisions with real culture. Far Beyond Zero, glossed from Muito Além do Zero, is a useful companion when leaders need to understand how targets can distort the picture.
Which article should leaders read next?
Metric ownership is the best next step, because ownership decides who changes the number, who verifies the field, and who escalates when the signal turns red.

About the author

Andreza Araújo

Safety Culture Expert | Senior EHS Executive

Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.

  • Civil & Safety Engineer (Unicamp)
  • M.A. Environmental Diplomacy (University of Geneva)
  • Sustainability Cert (IMD Switzerland)
  • People Management & Coaching (Ohio University)
  • UN Paris speaker representative for Brazil
  • ILO Turin speaker
  • LinkedIn Top Voice
  • Indra Nooyi PepsiCo CEO recognition (2x)

Documentaries

Watch Andreza's documentaries

Three productions on safety culture, organizational failure and the human lessons behind major disasters.

Podcasts

Listen to Andreza's podcasts

She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.

Summarize with AI