Risk Management

How to Build a Risk Escalation Path for Unresolved High-Hazard Actions in 21 Days

A practical 21-day method for risk managers and plant leaders to turn unresolved high-hazard actions into owned decisions, deadlines, and visible escalation.

By 7 min read
risk management scene on how to build a risk escalation path for unresolved high hazard actions in 21 — How to Build a Risk E

Key takeaways

  1. 01A high-hazard action needs an escalation trigger before it becomes overdue, because delay can become informal risk acceptance.
  2. 02Task ownership and decision ownership are different when the response requires authority to stop work, allocate resources, or accept residual risk.
  3. 03An interim control needs an owner, a review point, and field verification so it does not become a permanent workaround.
  4. 04An action closes only when evidence shows that the changed control works under the conditions that created the exposure.

F2 how-to guide for risk managers and plant leaders

An unresolved high-hazard action is not merely an overdue task. It is a decision that has remained open while the exposure continues, which means the organization needs a visible escalation path before the delay becomes an informal risk acceptance.

This 21-day method helps a risk manager build that path with four outputs: a clear trigger, a named decision owner, a time-bound response, and evidence that the residual risk was reduced or deliberately accepted at the right level.

What you need before starting

Collect the current action register, risk assessments, control-verification records, management-of-change records, and the business calendar that may affect the response. Start with the evidence already used by the operation rather than creating a second register. Compare the risk register, decision log, and control-verification review when you need to separate exposure evidence from management-decision evidence.

Choose one audience for the first version. This guide is written for a risk manager who must connect supervisors, plant managers, engineering, and directors when a serious exposure cannot be closed at the working level. The path should support escalation, not replace technical assessment or applicable legal requirements.

Step 1: Define what counts as a high-hazard action

Define a high-hazard action as an open item whose delay could leave people exposed to a serious injury or fatality pathway, a major process-safety event, or a control failure that the current work plan cannot tolerate.

Use consequence, exposure, and control reliability together. A low-frequency event can require immediate escalation when the available barrier is weak, bypassed, or unverified. The definition should also cover temporary conditions, contractor interfaces, and changes that alter the original risk assessment.

Verify the step. Ask two managers to classify the same five actions without seeing each other's answers. If they produce different results, refine the definition before building the workflow.

Common error. Defining priority only through injury history, because a quiet incident record does not prove that high-consequence exposure is absent.

Step 2: Create one evidence record for each action

Create a single record that states the hazard, credible consequence, affected work, current controls, missing or weak control, action owner, due date, and evidence required for closure.

Keep the description specific enough that another leader can understand the decision without reopening the entire study. Link to the relevant risk assessment, drawing, permit, inspection, or verification result, while the action itself should describe the control change rather than a vague intention to improve safety.

Andreza Araujo's work on safety culture distinguishes visible compliance from real control. A signed action with no proof that the barrier works is a record of activity, not evidence of risk reduction.

Verify the step. Remove the owner's name and ask a peer to identify who must act, what must change, and what evidence will close the item.

Common error. Recording only the recommendation, which makes later escalation depend on memory and personal interpretation.

Step 3: Set escalation thresholds before the action becomes overdue

Set the escalation threshold when the action is opened, not after the due date has passed. A threshold can be based on consequence, exposure duration, control degradation, a missed verification, or a change in work that makes the original action more urgent.

Use a small number of levels. The supervisor may own a routine correction, the plant manager may own an unresolved high-hazard control, and the director may own an exposure that needs funding, production interruption, or formal residual-risk acceptance. The level should follow the decision authority required, not the seniority of the person who first noticed the problem.

ISO 31000:2018 supports a structured approach to risk ownership and treatment, while IEC 31010:2019 helps teams choose suitable assessment techniques. Neither standard turns escalation into a fixed formula, so the organization must define how its own authority and exposure thresholds work.

Verify the step. Test three historical actions and ask whether the threshold would have moved them to the right decision owner early enough.

Common error. Making every overdue action escalate automatically, which floods senior leaders with administrative noise and hides the items that need a material decision.

Step 4: Assign the decision owner, not only the task owner

Assign two distinct roles when needed. The task owner controls the work required to improve the condition, while the decision owner has authority to change the plan, allocate resources, stop the exposure, or accept residual risk within the organization's rules.

This distinction matters because an engineer may be able to design a safeguard without being able to authorize a shutdown, and a supervisor may be able to stop a task without being able to approve a capital change. The escalation record should make that boundary explicit.

Antifragile Leadership describes leadership as the capacity to make better decisions under pressure, rather than simply to maintain a calm appearance. That idea is useful here because the escalation path should make difficult decisions visible before production pressure turns them into private compromises.

Verify the step. Ask the proposed decision owner what authority they will use and what information they need before deciding.

Common error. Assigning the action to the person closest to the hazard while leaving the resource or operating decision with nobody.

Step 5: Define the response clock in working conditions

Define the response clock according to the exposure, not according to a convenient administrative cycle. A control that is unavailable before a high-risk task may require a same-shift decision, while a design change with a verified interim barrier may need an engineering review within a defined number of working days.

State four moments in the workflow: when the issue is logged, when the owner acknowledges it, when the decision is made, and when the control is verified. These moments should remain separate because an acknowledgement does not mean that the risk has been treated.

Use the action's current condition to shorten the clock when exposure increases. The residual-risk acceptance guide is a useful companion because approval should depend on evidence, authority, and conditions rather than on an overdue date alone.

Verify the step. Review the clock against one planned shutdown, one maintenance task, and one contractor interface.

Common error. Treating a due date as a control, even though nobody has defined what happens before the action is complete.

Step 6: Add interim controls that can be checked in the field

Require an interim control whenever the permanent action cannot be completed before the exposure occurs. The interim control may involve isolation, physical separation, restricted access, a revised sequence, additional supervision, or a pause until a missing safeguard is restored.

Interim controls need an owner, an expiry or review point, and a verification method. They are not permission to leave the permanent action open indefinitely. If the temporary arrangement becomes normal work, the escalation path should treat that drift as a new decision requiring review.

James Reason's analysis of latent failures helps explain why this step cannot focus only on the final operator. Weak planning, unclear authority, and untested temporary arrangements can align before anyone makes the last visible mistake.

Verify the step. Ask a field supervisor to demonstrate the interim control without reading the action record.

Common error. Writing an interim control as a reminder to be careful, which cannot be verified and does not change the exposure pathway.

Step 7: Run a short decision review with the right level

Run the review as a decision meeting, not as a status meeting. Present the exposure, the current control condition, the options, the consequence of delay, and the decision that the current authority must make.

Limit the meeting to people who can add evidence or make the decision. The risk manager should challenge missing assumptions, while the operational leader should explain how the selected option will work in the real task. If the decision requires capital, schedule change, or production interruption, invite the person who can authorize that consequence.

Safety culture becomes credible when the organization responds to bad news with a better decision instead of a more polished record. Andreza Araujo's position in Safety Culture: From Theory to Practice is consistent with this discipline because culture is revealed by what leaders do when a control is inconvenient.

Verify the step. End the meeting with one sentence that begins, “The decision is…” and one sentence that begins, “We will verify it by…”

Common error. Leaving the meeting with several options still open and calling that alignment.

Step 8: Close the loop with control evidence

Close the action only when the changed control has been implemented and verified under the conditions that created the exposure. A purchase order, completed training record, revised procedure, or management approval may support closure, but none of them proves that the barrier works in the task.

Capture the verification result, the person who checked it, the date, the limitations, and any follow-up needed. If the control is weaker than intended, reopen the action or escalate the residual risk rather than preserving a closed status for reporting convenience.

During 25+ years leading EHS in multinational environments, Andreza Araujo has kept the practical test simple: the organization must show what changed in the work and how it knows the change is holding.

Verify the step. Compare the closure evidence with a field observation, a functional test, or another method that can challenge the assumption behind the action.

Common error. Closing the record when the document is complete while the exposure remains present.

What a completed risk escalation path should contain

A completed path makes the next decision obvious to someone who was not in the original conversation. It identifies the high-hazard condition, the current control, the trigger for escalation, the decision owner, the response clock, the interim control, and the evidence required for closure.

Review the path monthly using a small sample of closed and overdue actions. Look for repeated escalation, expired interim controls, unclear decision rights, and actions that close without field evidence. The risk-acceptance review can help directors test whether approval is reducing exposure or merely transferring responsibility.

The strongest escalation path does not make every problem urgent. It makes the important problems impossible to leave ownerless. That is the difference between an action register that reports delay and a management system that changes risk before harm occurs.

Build decisions that hold under pressure. Explore Andreza Araujo's books and Safety School resources for practical methods that connect risk management, leadership, and safety culture.

Topics risk management risk escalation high-hazard actions risk owner residual risk

Frequently asked questions

What is a risk escalation path?
A risk escalation path is a defined route that moves an unresolved exposure to the person with authority to make the required decision. It sets the trigger, decision owner, response clock, interim control, and closure evidence so a high-hazard action does not remain ownerless.
When should a safety action be escalated?
Escalate a safety action when the delay leaves a serious injury or fatality pathway exposed, when a critical control is weak or unverified, when the required response exceeds the current owner's authority, or when a change in work increases the original exposure.
Who should own an unresolved high-hazard action?
The task owner should manage the work needed to improve the condition, while the decision owner should have authority to change the plan, allocate resources, stop the exposure, or accept residual risk within the organization's rules. One person may hold both roles only when that authority is real.

About the author

Andreza Araújo

Safety Culture Expert | Senior EHS Executive

Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.

  • Civil & Safety Engineer (Unicamp)
  • M.A. Environmental Diplomacy (University of Geneva)
  • Sustainability Cert (IMD Switzerland)
  • People Management & Coaching (Ohio University)
  • UN Paris speaker representative for Brazil
  • ILO Turin speaker
  • LinkedIn Top Voice
  • Indra Nooyi PepsiCo CEO recognition (2x)

Documentaries

Watch Andreza's documentaries

Three productions on safety culture, organizational failure and the human lessons behind major disasters.

Podcasts

Listen to Andreza's podcasts

She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.

Summarize with AI