Risk Management

How to Run a Safety-Critical Change Review Before Startup in 14 Days

A safety-critical change can create new exposure even when the project appears complete. This guide gives plant managers, engineering leads, and EHS professionals an eight-step review that connects the change to hazards, controls, training, emergency readiness, and field verification before startup.

By 6 min read
Safety-critical change review before industrial startup

Key takeaways

  1. 01A change review should test what became different in the work, not only whether the project file is complete.
  2. 02The strongest review connects changed hazards to named controls, accountable owners, training, emergency response, and evidence from the field.
  3. 03Startup approval belongs to the people who can verify the control, not only to the person who delivered the engineering modification.
  4. 04A 14-day review is useful when it has decision gates, clear stop criteria, and a final return visit after the process starts.

A new pump, software interlock, production recipe, contractor arrangement, or shift pattern can change risk before anyone records a near miss. The project may be on budget and the equipment may pass commissioning, yet the people who operate, maintain, and isolate it may still be working with an incomplete control picture.

This guide gives plant managers, engineering leads, and EHS professionals an eight-step review that can run over 14 days. The central principle is simple, although it is often missed in practice: startup readiness depends on verified controls in the changed work, not on the number of documents completed.

What you need before starting

Choose one change that could affect energy, exposure, operating limits, task sequence, competence, staffing, or emergency response. Examples include a new automated cell, a process chemistry change, a revised maintenance method, a new contractor interface, or a production increase that alters the pace of work.

Bring together the change owner, an operations representative, an engineering or maintenance representative, and an EHS reviewer. Include a worker who knows the task as it is actually performed. The review becomes weaker when it relies only on the people who designed the modification, because design intent is not the same as field usability.

ISO 45001, updated in 2018, expects organizations to manage changes that can affect occupational health and safety. The practical question is not whether a form exists. It is whether the organization can show how the changed condition was understood, controlled, communicated, and checked.

Step 1: Describe the change in operating terms

Write a description that explains what people will do differently after startup. Avoid a project label such as “line upgrade” or “system improvement.” State which equipment, material, software, role, sequence, boundary, or decision will be different.

Ask the change owner to complete this sentence: “After startup, the person doing the work will no longer…” and then complete a second sentence: “After startup, the person doing the work will now…” These statements expose changes that a technical scope can hide.

Verify the description with an operator and a maintainer. If each person describes a different new sequence, stop the review until the operating condition is clear. A common error is approving a change whose physical installation is defined while its human interaction remains vague.

Step 2: Map the new exposure before reviewing controls

Walk through the task from preparation to recovery, including abnormal conditions and maintenance. Identify where a person can be exposed to energy, moving equipment, chemicals, height, traffic, pressure, heat, fatigue, or a decision made with incomplete information.

Use James Reason's distinction between active and latent failures to widen the review. The person closest to an error may be the last visible point in a chain that also includes design assumptions, unclear ownership, weak maintenance, poor communication, or production pressure.

Verify the exposure map at the point of work rather than in a conference room. The review should include access, visibility, line of fire, isolation points, alarms, handoffs, and the moment when the task is most likely to deviate from the written sequence. If the map describes only normal operation, it is not ready for approval.

Step 3: Test whether each control still fits

List the controls that are expected to prevent, detect, or limit the new exposure. Then ask whether each control still works after the modification. A guard may remain installed while access has changed. An interlock may function during a test while the reset decision remains ambiguous. A procedure may be current while the person performing the job cannot reach the required isolation point.

Separate controls that remove exposure from controls that depend on memory or vigilance. The distinction matters because a busy shift can defeat a control that exists only as an instruction, even when everyone has been trained.

Verify each critical control with a direct test, observation, document check, or demonstration. Record the evidence and the person who performed the verification. Do not mark a control complete because a supplier said it was included in the scope.

Step 4: Assign ownership at the decision point

Give every open risk and every critical control a named owner who can change the condition. The owner is not necessarily the person who entered the action in the system. It is the person who can allocate work, stop startup, revise the design, change the procedure, or provide competent support.

Ask who decides whether the task can proceed when the control is unavailable, degraded, or different from the approved design. If the answer is “the supervisor will decide,” name the supervisor and define the escalation route. Vague accountability creates delay precisely when the changed condition needs a fast, defensible decision.

Verify ownership by asking each owner what evidence they will provide before startup. If an owner cannot name the evidence, the action is still a promise rather than a control.

Step 5: Update the work method and competence requirements

Revise the procedure, permit, isolation plan, inspection routine, maintenance instruction, and emergency response information that the change affects. Do not update documents by copying the project description. Rewrite the steps that a person must perform at the point of work.

Define who needs briefing, practice, qualification, or supervised demonstration. Attendance proves that information was delivered; it does not prove that a worker can apply the changed method under realistic conditions.

Verify competence with a task demonstration or a structured walk-through before startup. Include the supervisor who will release the work and the maintainer who will troubleshoot it. A training record that excludes the people who make the next operational decision leaves a practical gap.

Step 6: Rehearse abnormal and emergency conditions

Test what happens when the change does not behave as expected. Consider loss of power, failed alarms, incorrect status indication, blocked access, communication loss, an unexpected restart, a chemical release, or a person becoming trapped in a changed area.

The rehearsal should identify the first safe action, the person who initiates it, the energy state that must be achieved, the communication route, and the rescue or medical support required. Emergency readiness is part of change control because a new layout or process can invalidate an old response plan.

Verify the response at the location where it would occur. Walk the route, inspect access, test communication, and confirm that the people named in the plan know their role. A written emergency step that cannot be performed in the changed environment is not evidence of readiness.

Step 7: Hold a conditional startup gate

Bring the evidence together in a short decision meeting. The group should classify the change as ready, ready with bounded conditions, or not ready. A conditional approval must state the exact boundary, duration, compensating control, accountable owner, and stop criterion.

Do not allow open actions to disappear into a general project tracker. The decision record should show which unresolved items affect startup and which items can safely wait. If the remaining gap concerns a safety-critical control, emergency response, isolation, or competence, the default decision should be to delay startup until the gap is resolved.

Andreza Araujo's work across 25+ years of executive EHS experience and more than 250 cultural transformation projects points to a practical leadership test. When leaders approve a changed condition, their decision teaches the organization what evidence is sufficient. The gate therefore shapes culture as well as risk control.

Step 8: Return after startup and verify the real condition

Schedule a field review during the first operating period and another after the process has encountered normal workload. The first visit checks whether the approved controls are present. The second checks whether people can sustain them when production, maintenance, and competing priorities are active.

Ask the operators what is harder than expected, which step is being improvised, where the control is slow, and what they would change before the next shift. Compare their answers with the approved change description and the original exposure map.

Close the review only when the new condition is stable, the remaining actions have owners and dates, and the post-startup evidence supports the decision. If the field differs materially from the approved design, reopen the change instead of treating the difference as a minor deviation.

Final checklist for the 14-day review

  • The change is described in terms of altered work, decisions, and exposure.
  • Normal, abnormal, maintenance, and emergency conditions were reviewed.
  • Critical controls were tested with evidence from the field.
  • Each open action has an owner who can change the condition.
  • Procedures, permits, isolation steps, and emergency information reflect the change.
  • People who operate, maintain, supervise, and respond were briefed or demonstrated competent.
  • Startup approval states boundaries, compensating controls, and stop criteria.
  • Post-startup verification is scheduled and connected to the original risk picture.

Conclusion

A safety-critical change review is not a document collection exercise. It is a decision process that tests whether the changed work can be performed with controls that are present, understood, owned, and verified.

For leaders who want to strengthen that discipline, Andreza Araujo's book Safety Culture: From Theory to Practice connects cultural credibility with the decisions that shape everyday work. More resources are available at Andreza Araujo.

Topics risk-management management-of-change startup-readiness safety-critical-controls industrial-safety

Frequently asked questions

What is a safety-critical change review?
It is a structured review of a modification that could alter exposure, control performance, operating limits, or emergency response. The review identifies what changed, tests whether existing safeguards still fit, assigns owners, and verifies the new condition before startup.
When should a management-of-change review happen?
It should begin when the proposed modification is clear enough to describe its effect on people, equipment, process, or work sequence. Waiting until commissioning compresses the time available to identify hazards and makes late corrections more expensive.
Who should approve startup after a safety-critical change?
Approval should come from accountable operations, engineering, and EHS representatives who can verify the changed condition and the controls that protect people. A project completion signature alone does not prove that the field is ready.
What evidence should a change review retain?
Retain the change description, hazard review, control verification, updated procedures, training records, emergency checks, open-action decisions, approval record, and post-startup verification. The evidence should show what was checked and who made each decision.

About the author

Andreza Araújo

Safety Culture Expert | Senior EHS Executive

Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.

  • Civil & Safety Engineer (Unicamp)
  • M.A. Environmental Diplomacy (University of Geneva)
  • Sustainability Cert (IMD Switzerland)
  • People Management & Coaching (Ohio University)
  • UN Paris speaker representative for Brazil
  • ILO Turin speaker
  • LinkedIn Top Voice
  • Indra Nooyi PepsiCo CEO recognition (2x)

Documentaries

Watch Andreza's documentaries

Three productions on safety culture, organizational failure and the human lessons behind major disasters.

Podcasts

Listen to Andreza's podcasts

She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.

Summarize with AI