Incident Corrective Actions: Verify Them in 30 Days
A practical 30-day method helps incident owners verify that corrective actions changed exposure, strengthened controls, and survived normal operating pressure.
Key takeaways
- 01Rewrite every corrective action as a control claim that identifies the exposure, barrier, owner, and evidence.
- 02Separate immediate containment from permanent correction so temporary protection is not mistaken for lasting risk reduction.
- 03Test the barrier at the worksite, with the people who perform the task, and under at least one changed condition.
- 04Use later checks and relevant leading signals to confirm that the action survived normal operating pressure.
- 05Apply Andreza Araujo’s safety-culture lens by closing actions only when operational decisions and conditions have actually changed.
A corrective action can be marked complete while the original exposure remains in the work. The form is closed, the training record is filed, and the same weak barrier waits for the next shift. That is why incident investigation is not finished when the report is approved. It is finished when the operation can show that the decision changed the risk.
This 30-day method gives an EHS manager, investigation chair, or line leader a practical way to test that change. It separates administrative completion from control verification, because a signed action is evidence of activity rather than proof of prevention. The method also reflects a central lesson in Safety Culture: From Theory to Practice by Andreza Araujo, whose work connects culture to the repeated decisions that leaders accept, review, and reinforce.
What you need before starting
Use the approved investigation report, the action register, the applicable procedure, and one person who owns the affected control. If the incident involved a serious injury or fatality exposure, include the manager who can stop or redesign the work. A review that only includes EHS can identify technical weaknesses, but it may not have authority to remove production constraints that keep the weakness alive.
Start with no more than five high-consequence actions. If the register contains twenty low-value tasks, group them by the control they are meant to strengthen. A focused review makes it possible to test whether the barrier works under normal conditions, which is more valuable than collecting another long list of open items.
Step 1: Rewrite each action as a control claim
Convert vague wording into a statement that can be tested. Replace retrain operators with supervisors verify the isolation boundary before work begins, and replace improve housekeeping with the shift team removes the identified obstruction before access is released.
Each claim should identify the exposure, the barrier, the owner, and the evidence that would demonstrate performance. When the wording cannot answer what should be different at the point of work, the action is not ready for verification.
Step 2: Separate immediate containment from permanent correction
Record what protected people immediately after the incident, then separate it from the change intended to prevent recurrence. A barricade, temporary approval, or extra supervisor may reduce exposure for a few days, although none of those measures proves that the underlying design or work process has improved.
Use the distinction to set two dates. The containment date confirms that people are protected now. The correction date marks when the permanent barrier must be installed, tested, and handed to its operating owner.
Step 3: Assign one accountable owner for each barrier
Give each action one accountable operational owner, even when several departments contribute. EHS may define the verification standard, maintenance may modify equipment, and operations may control the shift routine, but one leader must answer whether the barrier is functioning.
Andreza Araujo has seen this distinction across more than 250 cultural transformation projects. Shared participation can improve a solution, yet shared accountability often makes weak actions look complete because every contributor assumes that someone else owns the final test.
Step 4: Define the evidence that can disprove completion
Choose evidence that could show the action failed. A completion email cannot do that. Useful evidence may include an observed isolation, a sampled permit, a guarded machine under production conditions, a maintenance record tied to the control, or a supervisor decision made during a changed condition.
Ask what an independent reviewer would need to see without relying on the action owner’s explanation. That question creates a stronger test, since evidence which only confirms the author’s narrative is unlikely to reveal a weak barrier.
Step 5: Verify the physical or procedural change at the worksite
Visit the area before the 30-day review meeting. Compare the current condition with the condition described in the investigation, and test the action during the task for which it was created. If the control only works when an EHS professional is present, the change has not yet become part of the operating system.
Check the interfaces that are easy to miss, such as contractor handoff, shift change, startup, abnormal operation, and maintenance return. James Reason’s work on latent failures is useful here because a visible correction can coexist with an organizational condition that still recreates the exposure.
Step 6: Test whether the control survives a changed condition
Ask the responsible supervisor to explain what happens when the original assumption changes. The test might involve a different material, a late delivery, a failed sensor, an absent operator, or a change in staffing. The purpose is not to create a theatrical drill. It is to see whether the decision path remains clear when pressure makes shortcuts attractive.
A control that depends on perfect conditions is a fragile control. In Sorte ou Capacidade, Andreza Araujo examines how apparent luck can hide the quality of decisions and the conditions surrounding them. The same question belongs in corrective-action verification: did the operation improve its capacity to manage variation, or did it only prepare for the last incident?
Step 7: Interview the people who perform the work
Speak with the operator, supervisor, maintainer, and contractor who encounter the barrier. Ask what changed, what still creates friction, and what people do when the formal route is slow. Their answers should be compared with the procedure and the physical condition, because each source reveals a different part of control performance.
Do not turn the conversation into a compliance quiz. A worker who reports that the new step is skipped during a production surge may be providing the most important verification evidence, particularly when the record says that the action was completed without exception.
Step 8: Review the action after normal work resumes
Schedule a second check after the operation has returned to its ordinary rhythm. Early verification often happens while managers are attentive and the incident is still visible. The later check shows whether ownership remained clear after attention moved elsewhere.
Review one or two leading signals that fit the control, such as overdue inspections, isolation deviations, repeat defects, permit quality, or unresolved maintenance requests. Do not treat a clean incident count as proof that the action worked. Low event frequency may reflect limited exposure, underreporting, or simple chance.
Step 9: Close, escalate, or redesign the action
Close the action only when the evidence shows that the intended barrier exists, is understood by its users, and remains effective under a changed condition. If one of those tests fails, keep the action open and state precisely what must change.
Escalate when the owner lacks authority, the control requires capital, or the work design defeats the approved procedure. Redesign the action when the evidence shows that retraining has become a substitute for engineering, staffing, planning, or supervision. This is where safety leadership becomes operational, because a leader must choose between accepting residual exposure and funding a better barrier.
What the 30-day review should produce
The final record should be short enough for a manager to use and specific enough for an investigator to defend. It should state the original exposure, the control claim, the owner, the evidence reviewed, the changed-condition result, and the next decision.
Use the same discipline for every serious action, while adjusting the test to the hazard. A machine guard, a confined-space rescue plan, and a contractor handoff require different evidence, although each needs a clear owner and a test that can reveal failure.
For related practice, compare this method with six distortions that make corrective actions look complete, review how to preserve incident evidence before the worksite changes, and use the near-miss speak-up debrief before the action register is finalized. Leaders who need a broader decision structure can also read the 45-day plan for a new incident review chair.
Andreza Araujo’s approach keeps the question practical. A corrective action earns closure only when the work has changed in a way that people can demonstrate, supervisors can sustain, and leaders are willing to defend under pressure. That standard turns investigation from a documentation exercise into a decision system.
Frequently asked questions
When is an incident corrective action complete?
Who should own a corrective action after an incident?
Why is retraining often insufficient after an incident?
What evidence should an investigator review?
How long should corrective-action verification take?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.