How a Risk Register Became a Decision System Across 30 Countries
A case-based account of how risk registers become useful when leaders connect each exposure to an operating decision, a control owner, and field evidence, drawing on Andreza Araujo's work across more than 250 cultural transformation projects and 30 countries.

Key takeaways
- 01A risk register creates value only when it changes a decision about exposure, control, resources, or escalation.
- 02Across more than 250 cultural transformation projects in over 30 countries, Andreza Araujo has seen that stale registers usually fail at the ownership and verification boundary.
- 03The strongest risk records identify the condition that could change, the control that should hold, the person who can act, and the evidence that will confirm the action worked.
- 04A central register should preserve common language without forcing every site to use identical controls for different operating conditions.
- 05Leaders should review risk information at the cadence of the decision it supports, not only during an annual management review.
A risk register can look authoritative while making almost no difference to the work. It may contain polished descriptions, color-coded ratings, and named hazards, yet supervisors still face the same unresolved exposure when production changes, contractors arrive, or a control fails during a busy shift.
Across more than 250 cultural transformation projects supported by Andreza Araujo, including work that reached teams in over 30 countries, one pattern appeared repeatedly. The register became useful only when leaders stopped treating it as a storage location for risk statements and started using it as a record of decisions that had to remain true in the field.
Initial scenario: the register looked complete
The multi-site operation already had a common risk register. Each location reported major hazards through a familiar template, and regional leaders could compare entries during scheduled reviews. The process produced consistency in format, but it did not always produce consistency in control quality.
A risk owner could explain the rating in a meeting without being able to show the control that prevented the exposure during a night shift. A site could report that a critical barrier was in place even though the barrier had no recent verification record, no clear failure condition, and no escalation route when maintenance or staffing changed the work.
James Reason's work on latent failures helps explain why this gap persists. A visible event at the point of work can be the final expression of weaknesses that sit earlier in planning, design, supervision, communication, or resource allocation. A register that describes only the event or hazard therefore gives leaders an incomplete picture of what can actually fail.
The central problem was not that people lacked a risk methodology. The problem was that the method separated risk description from operational decision-making.
The decision: make every material risk answerable
The change began with a direct question. What decision should this risk record help a leader make before the next review?
That question moved the register away from passive description. Each material entry had to state the exposure, the control expected to hold, the condition that would weaken it, the owner with authority to change that condition, and the evidence required to verify performance. The record also had to show what would trigger escalation rather than waiting for the next scheduled meeting.
This did not mean that every location received the same checklist. A common structure protected the quality of the conversation, while local teams still had to explain how the exposure appeared in their process, equipment, staffing model, and contractor interface.
In Safety Culture: From Theory to Practice, Andreza Araujo describes culture through repeated choices that people can observe. The register became part of that culture when its entries revealed whether leaders were willing to fund, sequence, stop, or redesign work in response to evidence.
Execution: connect the register to the operating rhythm
The first execution step was to separate review levels. Site teams reviewed conditions they could change directly. Regional leaders reviewed risks that crossed locations, contractors, standards, or shared resources. Executives reviewed exposures whose controls depended on capital, production priorities, or decisions outside the EHS function.
That separation prevented a common failure. A site manager no longer had to carry a risk that only a regional or corporate leader could resolve, while the executive team received fewer entries that were actually routine maintenance issues.
The second step was to replace generic status language with evidence. Instead of marking a control as effective, the owner identified the last verification, the operating condition tested, the gap found, and the decision taken. When evidence did not exist, the record remained open. That made uncertainty visible without pretending that a green status represented assurance.
The third step was to define the failure boundary. A control description such as “training completed” did not explain what would happen when a new supervisor took over, when a contractor used a different tool, or when a schedule compressed the task. The record had to state what condition would make the control unreliable and who would receive the escalation.
The fourth step was to bring the register into field conversations. Supervisors used material risks to compare the planned control with the work in front of them. If the two did not match, the discussion focused on the decision needed to restore control rather than on updating a spreadsheet after the fact.
Measured result: management could see decision quality
The portfolio did not produce one universal accident-rate claim because the projects involved different sectors, exposures, maturity levels, and operating structures. The measured improvement was more specific. Leaders could see which risks had a real owner, which controls had been tested under relevant conditions, and which items were being carried forward without a decision.
That visibility changed the quality of review. A long list of high risks was no longer automatically treated as a sign of rigor. A shorter list with weak evidence was not accepted as proof of improvement. The useful question became whether the organization had reduced uncertainty around the exposure and strengthened the decision that controlled it.
Sites also became better able to explain why a local control differed from the regional model. The difference had to be tied to the exposure and supported by evidence, rather than defended as local preference. This preserved local ownership without allowing local custom to hide a weak barrier.
Generalizable lessons from the case
A register is not a control
Writing down a risk does not reduce it. The register is valuable because it creates a shared decision surface. The actual control still lives in design, equipment, planning, supervision, competence, and the choices leaders make when conditions change.
Ownership must include authority
Assigning a name without assigning decision rights creates administrative accountability. The owner must be able to change the condition, obtain support, escalate a conflict, or stop the work when the expected control cannot hold.
Verification must resemble exposure
A document review can confirm that a procedure exists, but it cannot establish that the procedure remains usable during the shift, under production pressure, or at the contractor interface. Verification should test the conditions that make failure plausible.
Uncertainty is information
When an organization records uncertainty honestly, leaders can decide whether to investigate, add a temporary control, allocate resources, or accept the residual exposure through a defined process. Hiding uncertainty behind a rating delays the decision and weakens trust in the register.
What to apply in your operation
A risk-management leader can begin without replacing the entire system. Select the material risks that influence life-critical work, production continuity, or major resource decisions. For each one, ask what decision the record should support, what control must hold, who has authority to act, what evidence will be accepted, and what event requires escalation.
Then compare the written control with the field condition. Speak with the supervisor who owns the next decision, not only with the person who maintains the register. If the record cannot explain what changes at the point of work, it is not ready to support an executive review.
Andreza Araujo's work on safety culture and risk leadership offers a broader foundation for leaders who want to turn risk information into operating discipline. The focus is not on producing a more impressive register. It is on making the next safe decision easier to see and harder to defer.
Frequently asked questions
What makes a risk register useful?
A risk register becomes useful when it connects an exposure to a control, an owner with authority, evidence of performance, and a clear escalation decision.
Who should own a material operational risk?
The owner should be the person or leadership level that can change the condition creating the exposure. EHS may coordinate the method, but ownership should remain with the operation that controls the decision.
How often should leaders review a risk register?
The review cadence should match the decision and the rate at which the exposure can change. High-consequence work may require shift, weekly, or event-based review, while stable governance items may need a different rhythm.
Can different sites use different controls?
Yes. Sites can use different controls when the difference reflects their exposure and is supported by evidence. A common register structure should improve comparison without forcing false uniformity.
What is the first sign that a risk register is stale?
The first sign is often a gap between the recorded control and the supervisor's description of how the work is actually performed. Repeated carry-forward items and unclear decision owners are additional warnings.
Frequently asked questions
What makes a risk register useful?
Who should own a material operational risk?
How often should leaders review a risk register?
Can different sites use different controls?
What is the first sign that a risk register is stale?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.