Risk Register vs Decision Log vs Control Verification: Which Evidence Should Leaders Trust Before Accepting Residual Risk?
Compare risk registers, decision logs, and control verification to decide which evidence leaders need before accepting residual risk in safety-critical work.

Key takeaways
- 01Separate the risk register, decision log, and control verification because each answers a different leadership question.
- 02Use the risk register to assign ownership and see the exposure portfolio, not to prove that a control works today.
- 03Use a decision log to preserve the assumptions, conditions, authority, and escalation triggers behind an acceptance decision.
- 04Use control verification when the decision depends on whether a critical barrier is present and effective in current conditions.
- 05Connect all three records when temporary work or high-consequence exposure makes residual risk difficult to defend.
A risk register can show that an exposure was identified, yet it cannot prove that the control works today or explain who accepted the remaining uncertainty. This comparison helps leaders choose between a risk register, a decision log, and control verification when a safety-critical decision must be defended.
Evaluation criteria: what makes risk evidence trustworthy?
Leaders should not treat every safety record as interchangeable. A register describes exposure at a chosen level of detail, a decision log preserves the reasoning behind an approval, and control verification tests whether a barrier is present and effective in the work as it is performed. Each answers a different question, which means the right choice depends on the decision being made.
The first criterion is purpose. If the organization needs a portfolio view of hazards, the risk register is the natural starting point. If a director must understand why a temporary deviation was accepted, the decision log is more useful. If the question is whether a critical control can be relied upon before work starts, verification carries the greatest weight.
The second criterion is time. A register may remain unchanged while conditions shift during a shutdown, staffing change, or contractor handover. A decision log records a point in time, whereas verification provides a current observation. Andreza Araujo’s work on risk ownership treats this distinction as a governance issue, because stale evidence can create the appearance of control while the exposure is changing underneath it.
The third criterion is consequence. Low-consequence routine work can often be managed with a proportionate register entry and local checks. Work with credible serious-injury or fatality potential requires evidence that is closer to the barrier, closer to the decision, and easier to challenge.
A fourth criterion is challengeability. Evidence should allow a competent person who was not involved in the original approval to ask what was checked, when it was checked, and what would invalidate the conclusion. If the record cannot be challenged without relying on the memory of one manager, it is not strong governance evidence.
Risk register: the best tool for seeing the exposure portfolio
A risk register is strongest when leaders need to see what risks exist, who owns them, what treatment is planned, and when the exposure should be reviewed. It supports prioritization across departments, projects, and sites, which is why it remains central to risk governance aligned with ISO 31000 and occupational safety management systems.
Its weakness is often mistaken for its purpose. A register is not a live certificate that a control is working. It is a structured representation of risk based on defined assumptions, and those assumptions may become invalid when the process, equipment, workload, or competence profile changes.
A practical register should make the decision-relevant fields visible. These include the hazard, credible consequence, exposed group, existing controls, control owner, evidence of effectiveness, residual risk, acceptance authority, review trigger, and action status. A field called “controls in place” is too vague because it collapses design, implementation, use, and performance into one statement.
The register also needs a useful level of granularity. A single entry called “maintenance risk” cannot guide a decision about stored energy, line breaking, lifting, or confined space entry. Excessive detail creates a different problem because nobody can keep hundreds of nearly identical entries current. The right level is the one at which an owner can identify the consequence, control, and next decision without reopening the entire system.
Use the register when the leadership question is, “Where is our exposure, and who is accountable for reducing it?” Do not use it alone when the question is whether a control can be trusted for this task and shift. That question requires current evidence about the conditions in which the work will occur. Pair the register with clear residual-risk acceptance conditions.
Decision log: the best tool for preserving judgment
A decision log records the choice that was made, the alternatives considered, the evidence available, the assumptions accepted, the authority involved, and the conditions that would require escalation. It is particularly valuable when production pressure, schedule constraints, or temporary controls create a decision that cannot be understood from the risk register alone.
The log protects more than memory. It protects the quality of the reasoning. A future reviewer can see whether the decision maker understood the consequence, whether dissent was raised, and whether the approval was conditional or open-ended. That record matters because risk acceptance is not the same as risk disappearance.
A weak decision log simply states, “Risk accepted by manager.” A useful one explains what was accepted, why the exposure was tolerable for the defined period, which controls were non-negotiable, what evidence was missing, and who had authority to stop or revisit the work. The quality of the record therefore depends on the quality of the questions asked before approval.
The log should also record the expiry of the decision. Temporary acceptance without a date or trigger quietly becomes a new baseline. A stronger entry names the repair date, the person responsible for closing the gap, the evidence required before extension, and the event that automatically reopens the decision, such as a process change, failed control, incident, or change in exposed population.
Use a decision log when a leader must explain a compromise, authorize a deviation, or transfer an unresolved issue to a named owner. It should complement, not replace, the register. The register gives the decision a home, while the log shows how the organization arrived there. This is consistent with the distinction explored in risk context and grounded safety decisions.
Control verification: the best tool for testing reality
Control verification asks whether a specified barrier exists, is available, is understood, and performs the function expected of it. The method may include field observation, document review, functional testing, interviews, sampling, or a combination of these, depending on the control and its consequence.
Verification has a different relationship with reality than a register or a decision log. It can expose a missing interlock, an expired inspection, an inaccessible rescue device, an unclear isolation boundary, or a supervisor who cannot explain the critical step. These findings are not administrative imperfections when the control is supposed to prevent a serious consequence.
The trap is to treat presence as effectiveness. A procedure in a document repository is evidence that a procedure exists. It is not evidence that the crew can apply it under time pressure. A training record shows that someone attended a course. It does not prove that the person can recognize the exposure or execute the control in the field.
Verification is the right choice when the decision is close to the hazard and the consequence is material. Before non-routine maintenance, leaders should know which critical controls must be checked, who will check them, what constitutes failure, and what happens when evidence is incomplete. The result should feed the register and, when an exception is approved, the decision log.
Verification quality depends on predefined failure criteria. “Looks good” is not a criterion that two competent reviewers can apply consistently. A useful protocol identifies the barrier, the expected condition, the test method, the sampling boundary, and the response to a failed result. When the test is consequential, the verifier should have enough independence to stop the work or escalate without negotiating against the schedule.
Decision matrix: which evidence answers which leadership question?
The three tools are not competitors in every situation. They operate at different levels, and the strongest governance system connects them without pretending that one record can do all three jobs.
| Evidence source | Primary question | Best decision level | Main limitation |
|---|---|---|---|
| Risk register | What exposure exists, and who owns its treatment? | Portfolio, site, or department planning | May become stale and may describe controls without testing them |
| Decision log | Why was this risk accepted, deferred, or escalated? | Executive, project, or deviation approval | Can preserve weak reasoning if the evidence was poor |
| Control verification | Does the critical control work in the current conditions? | Task, shift, project, or operational assurance | Can become a ritual if sampling and failure criteria are unclear |
The matrix shows why a polished risk register cannot compensate for missing field evidence. It also shows why a field check cannot replace governance. A verified control still needs an owner, a review trigger, and a decision rule for when the exposure is no longer acceptable.
Leaders should ask whether the evidence is current, independent enough to challenge the decision, specific to the exposure, and linked to an action. These questions are more useful than asking whether the form was completed, because completion measures activity while evidence supports judgment.
One practical test is to remove the title of the record and ask a reviewer to identify its purpose from the contents alone. If the reviewer cannot tell whether the record describes exposure, explains an approval, or verifies a barrier, the system is probably mixing evidence types. That ambiguity slows escalation because every disagreement becomes a debate about terminology instead of a decision about risk.
Recommendation by context: match the evidence to the decision
For annual planning and enterprise risk review, start with the risk register. Use it to compare exposure across sites, identify owners, fund treatment, and set review triggers. If the register contains no evidence field, add one rather than allowing “control in place” to stand as an unsupported conclusion.
For temporary work, schedule pressure, or a deviation from the approved method, use all three tools. Update the register if the exposure is material, write a decision log that records the conditions and authority, and verify the critical controls before execution. The combination prevents an exceptional decision from becoming a permanent operating condition.
For high-consequence tasks, begin with control verification and then connect the result to governance. A negative finding should not be hidden inside an audit action list when the control failure changes the decision to proceed. The accountable leader needs a clear stop, repair, escalate, or formally accept pathway.
For executive dashboards, show the relationship between exposure and evidence. A useful dashboard can distinguish open risks, overdue treatment, recent control failures, conditional approvals, and decisions awaiting escalation. This gives leaders more visibility than a single risk score, which is why the distinction between risk acceptance and risk transfer matters in governance conversations.
Across 25+ years of executive EHS work, Andreza Araujo has consistently placed ownership and practical decision quality ahead of paperwork volume. The implication for this comparison is direct: the record is valuable only when it changes who acts, what is checked, or when a decision must be revisited.
For a newly appointed risk owner, the first improvement is usually not another form. It is a short evidence map that connects each material exposure to its owner, latest decision, current verification result, and next review trigger. That map exposes gaps between what the organization says it controls and what it can demonstrate when a leader asks for proof.
Conclusion: trust the evidence that matches the risk
A risk register shows the exposure, a decision log shows the reasoning, and control verification shows what is happening in the field; leaders should connect all three when residual risk could cause serious harm.
If your organization needs to clarify risk ownership, strengthen control assurance, or build a decision process that leaders can defend, visit Andreza Araujo for practical safety culture and risk management support.
Frequently asked questions
What is the difference between a risk register and a decision log?
Can a risk register prove that a safety control is effective?
When should leaders use control verification?
Should every residual-risk decision have a decision log?
What evidence should an executive dashboard show?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.