Safety Leadership

Risk Governance: 8 Questions That Keep Safety Decisions Owned at Board Level

Risk governance becomes practical when boards can see who owns residual safety risk, what evidence supports acceptance, and what changes when operating assumptions fail.

By 7 min read

Key takeaways

  1. 01Risk governance is effective when it makes safety decision ownership, evidence, and escalation visible at the level where resources and priorities are set.
  2. 02Residual risk needs a named accountable owner who can explain the remaining exposure and authorize a pause when a critical control is degraded.
  3. 03A board should connect important signals to explicit decision rules, because activity metrics alone do not prove that serious exposure has fallen.

A board can approve a safety strategy, receive a polished dashboard, and still leave the most important risk decisions without an owner. The problem is not always a missing policy. It often sits in the space between capital allocation, operational authority, and the moment when a changing condition requires someone to stop or redesign the work.

Risk governance becomes useful when it makes that space visible. The board does not need to run a permit review or rewrite a job hazard analysis. It does need to know which decisions remain open, who can make them, what evidence supports them, and what happens when the approved plan no longer matches the field. These eight questions turn safety governance from a reporting ritual into a decision-control system.

1. Which safety decisions belong at board level?

Not every safety decision belongs in the boardroom. A supervisor should decide whether a task can continue under a defined condition, while an engineer should resolve many design questions. Board-level governance begins when the decision affects the organization's risk appetite, capital priorities, operating model, or ability to meet a material obligation.

Examples include accepting residual risk after a major project change, deferring a critical safeguard, approving production under a constrained maintenance plan, and deciding whether a recurring exposure requires investment rather than another reminder. If the board only receives injury counts, it sees the result of decisions without seeing the decisions themselves.

Use a simple ownership test. Ask whether the decision can change the organization's exposure across sites, whether it requires resources outside the operating team, and whether a failure would create serious harm, legal exposure, or a loss of public trust. When the answer is yes, the decision should have a defined route to executive or board review.

2. Who owns the residual risk after controls are applied?

A risk register can name a hazard without naming the person who accepts what remains. That omission is common when the EHS function coordinates the assessment, operations controls the work, engineering owns the asset, and finance controls the budget. Everyone participates, yet no one is accountable for the residual exposure.

Residual risk is not an administrative remainder. It is the portion that still depends on a barrier, a condition, a competency, or a decision under pressure. The accountable owner should therefore be able to explain the exposure in operational language, identify the control that keeps it tolerable, and authorize a pause when that control is degraded.

Andreza Araujo's The Illusion of Compliance, whose Portuguese title is A Ilusao da Conformidade, offers a useful warning here. A signed approval can show that a process was completed, while the real test is whether responsibility survives contact with work. The board should reject risk entries that have a department but no accountable decision-maker.

3. What evidence supports the risk acceptance decision?

Risk acceptance should not depend on the confidence of the presenter. It should rest on evidence that explains the exposure, the control design, the operating assumptions, and the conditions that would invalidate the decision. The evidence may include a design review, inspection history, maintenance status, incident findings, competency records, or verification of a critical control.

The question is not whether the organization has collected many documents. The question is whether the documents answer the decision that is in front of the board. A risk acceptance memo that lists policies but cannot show the status of the relevant safeguard is evidence of activity, not evidence of control.

This is where a board can connect governance to the blind spots in safety dashboards. The dashboard should point to the evidence behind the decision, not replace it. A red control-verification result may require a different response from a red training-completion result, even though both appear as colored cells.

4. What happens when production pressure changes the original assumptions?

Every approval contains assumptions. Staffing may remain stable, equipment may be available, a contractor may retain the required capability, and a maintenance window may occur before the next high-risk activity. When those assumptions change, the original approval can become irrelevant even if the document remains valid.

Risk governance should define the triggers that reopen a decision. These can include a change in workload, a missed inspection, a critical-control failure, a serious near miss, a change in contractor, an abnormal operating mode, or a delay that removes the planned recovery window. The trigger should be specific enough that a supervisor can recognize it without asking for permission to notice it.

A board that asks only whether a risk was accepted misses the more important question of whether the acceptance conditions still exist. The review cadence should therefore include exceptions and changes, not just monthly status. The conditions for executive risk acceptance should be visible beside the decision, so a changed condition cannot hide behind an old approval date.

5. Can the person closest to the exposure stop the work?

Stop-work authority is often announced as a value and left as a personal test of courage. That arrangement is weak governance. A worker or supervisor should know what to stop, how to escalate, who responds, and what protection exists against retaliation when the concern is raised in good faith.

The board does not need to manage every intervention. It does need to test whether the organization's authority design makes intervention practical. Ask how many concerns reached a decision-maker, how long the response took, whether the control changed, and whether repeated concerns point to a design or planning problem.

Technical dissent also needs a route that does not depend on hierarchy alone. A person may see a credible exposure without having the title that authorizes a capital decision. The organization's response should preserve the technical signal while transferring the decision to the right owner.

6. What does the board do with repeated unresolved actions?

An overdue action is not automatically a governance failure. Some actions require engineering, procurement, regulatory review, or a planned shutdown. The failure appears when the organization repeatedly extends the deadline without changing the exposure, escalating the decision, or documenting why the remaining risk is acceptable.

Separate three conditions. An action can be late but controlled when interim barriers are verified. It can be late and exposed when the interim barrier is uncertain. It can be late and structurally blocked when the owner lacks the authority or resources to finish it. Those conditions need different responses, which is why a single overdue percentage is not enough.

The board should review the pattern behind overdue actions, not punish the number in isolation. The distortions that allow high-consequence risk to remain open usually involve unclear ownership, weak escalation, competing incentives, or a temporary measure that became permanent.

7. How does the governance system distinguish activity from control?

Training hours, completed inspections, meetings held, and observations submitted can describe effort. They do not prove that a serious exposure became less likely. Governance needs a second layer that tests whether the intended control exists, works under realistic conditions, and is restored when it degrades.

A practical board pack can compare activity with control evidence. For example, it can show that a site completed its critical-control verifications, then identify how many verifications found a failed barrier, how quickly the barrier was restored, and whether the same failure appeared again. That comparison makes it harder for volume to disguise weakness.

Andreza Araujo's Safety Culture: From Theory to Practice is relevant because it treats culture as a pattern of decisions rather than a collection of declared values. A board can apply that lens by asking what the organization did when the safe choice cost time, money, production, or status. The answer often reveals more than a favorable activity trend.

8. What decision will change if the signal worsens?

A metric without a decision rule is an observation. Before a dashboard reaches the board, each important signal should have a defined response. If critical-control verification falls below the agreed threshold, who reviews the exposure? If escalation time increases, what operating condition changes? If employees stop raising concerns, which leader investigates the silence?

The rule does not need to be mechanical. It needs to be explicit enough that leaders cannot reinterpret every deterioration as a temporary fluctuation. A signal should connect to an owner, a time window, and an action that can be checked later.

This question also exposes decision latency. A board may believe it has strong governance because it receives information quickly, while the operating system takes weeks to act. The tests for slow safety escalation help distinguish a communication problem from an authority problem. Both require attention, but they do not require the same remedy.

How the eight questions fit together

The questions are most useful as a connected review rather than as a board checklist that produces eight isolated answers. The sequence moves from decision scope to ownership, evidence, changed assumptions, authority, unresolved work, control quality, and response. Each answer should make the next answer easier to verify.

Governance questionEvidence to requestDecision owner
Which decisions belong at board level?Risk appetite, materiality, cross-site exposureBoard or executive sponsor
Who owns residual risk?Named accountable owner and control statusOperations, engineering, or executive owner
What supports acceptance?Control verification and current assumptionsRisk-accepting authority
What reopens the decision?Defined change and escalation triggersOperating leader
Can the closest person stop work?Intervention records and response timeLine leadership
What happens to repeated overdue actions?Interim barriers, blockers, and escalationAction owner and sponsor
Does activity equal control?Barrier performance and recurrence dataControl owner
What changes if the signal worsens?Threshold, owner, response, and follow-upDefined decision-maker

Conclusion: governance is visible in the decision path

Effective safety governance is not demonstrated by the number of reports that reach the board. It is demonstrated by the quality of the decision path that follows them. The board knows which risks require its attention, the accountable owner is visible, the evidence is current, changed assumptions trigger review, and the person closest to the exposure can raise a concern without losing authority.

When those conditions are absent, a polished safety program can remain disconnected from serious risk. When they are present, the board is no longer approving safety as a statement of intent. It is governing the decisions that keep people protected.

Topics risk-governance safety-leadership risk-acceptance board-safety safety-accountability

Frequently asked questions

What is risk governance in occupational safety?
Risk governance is the structure that defines which safety decisions are escalated, who owns residual risk, what evidence supports acceptance, and what happens when conditions change. It connects the board and executives with operational authority without turning the board into a task-level supervisor.
What should a board ask about safety risk acceptance?
A board should ask who accepts the residual risk, what controls keep it tolerable, which assumptions support the decision, what evidence verifies those controls, and what event would reopen the decision. The answer should identify an owner and a response, not only a risk score.
Why are safety dashboards not enough for risk governance?
Dashboards summarize signals, but they do not automatically show whether a critical control works, whether an assumption changed, or who can act. Risk governance becomes stronger when important dashboard signals connect to evidence, ownership, thresholds, and a decision rule.
How does risk governance support stop-work authority?
Risk governance supports stop-work authority by defining what conditions require intervention, how a concern reaches a decision-maker, how quickly the organization responds, and how the control or work plan changes afterward. It turns a slogan into an operating route.

About the author

Andreza Araújo

Safety Culture Expert | Senior EHS Executive

Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.

  • Civil & Safety Engineer (Unicamp)
  • M.A. Environmental Diplomacy (University of Geneva)
  • Sustainability Cert (IMD Switzerland)
  • People Management & Coaching (Ohio University)
  • UN Paris speaker representative for Brazil
  • ILO Turin speaker
  • LinkedIn Top Voice
  • Indra Nooyi PepsiCo CEO recognition (2x)

Documentaries

Watch Andreza's documentaries

Three productions on safety culture, organizational failure and the human lessons behind major disasters.

Podcasts

Listen to Andreza's podcasts

She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.

Summarize with AI