Safety Accountability: 6 Distortions That Let High-Consequence Risk Outlive Its Owner
A named risk owner is not the same as an owned control. This F1 diagnostic shows how directors, operations leaders, and EHS managers can test whether accountability reaches the decisions that keep high-consequence exposure controlled in the field.

Key takeaways
- 01A name in an accountability chart does not prove that a person controls the decisions, resources, and verification required to manage serious exposure.
- 02High-consequence risk outlives its owner when ownership is assigned to a function that cannot change the work or when interfaces are left undefined.
- 03A usable ownership model separates decision authority, control performance, field verification, escalation, and recovery after failure.
- 04Directors should ask who can stop the work, who can fund the correction, and who will know when the control has degraded.
- 05Across more than 250 cultural transformation projects, Andreza Araujo has seen accountability become credible only when leaders connect responsibility with observable decisions.
- 06James Reason’s work on latent failures helps explain why frontline attribution cannot substitute for leadership ownership of system conditions.
A serious-risk register can contain a responsible name beside every hazard and still fail at the moment protection is needed. The name may belong to an EHS manager who cannot change production priorities, a contractor coordinator who cannot approve engineering work, or a site leader who receives no evidence until the monthly review. The organization has assigned accountability, but it has not assigned control.
That distinction matters because high-consequence exposure does not wait for an organizational chart to become clear. It persists through shift changes, contractor interfaces, maintenance deferrals, design modifications, and leadership transitions. Across 25+ years of multinational EHS work, Andreza Araujo has repeatedly treated this as a leadership test: who can change the conditions that make the risk possible, and what evidence proves that the change held?
Why naming an owner is not enough for serious risk
Accountability becomes useful only when it connects a person to a decision that can alter exposure. A risk owner who can describe the hazard but cannot approve a control is an adviser, not the final owner. A control owner who can inspect a barrier but cannot stop production is a verifier, not the decision authority. Confusing these roles creates a polished governance model whose weak points appear only under pressure.
James Reason’s analysis of organizational accidents makes the problem easier to see. Failures are often shaped by latent conditions, local defenses, and decisions made far from the point of harm. That does not remove individual responsibility, although it does prevent leaders from treating a frontline deviation as the complete explanation for a system that made the deviation likely.
The first question in an accountability review should therefore be concrete. Which decision, if made differently this week, would reduce the exposure? If no named role can answer, the risk is not owned yet.
Distortion 1: the functional owner is mistaken for the decision owner
Many organizations assign critical risks to EHS because the function has the vocabulary, the register, and the review cadence. The assignment looks sensible until the control requires a capital project, a staffing change, a maintenance outage, or a change to the production plan. EHS can identify the gap, but another leader controls the action that closes it.
This creates a recurring pattern. The functional owner reports the same exposure, the operational owner acknowledges it, and the executive forum records an action without transferring decision authority. Months later, the risk still appears in the same place, now surrounded by evidence that the organization has discussed it often.
Correct the distortion by separating three roles in the register. Name the person who accepts the risk decision, the person who owns the control’s performance, and the person who verifies the field condition. If those names all point to one function by default, the model probably describes reporting rather than ownership.
Distortion 2: accountability is assigned without decision rights
A person cannot be held accountable for a control that they cannot pause, fund, redesign, or escalate. Yet many leadership systems use verbs such as monitor, support, coordinate, and ensure without specifying what the role is authorized to decide. Those verbs create a duty to observe, not a right to intervene.
Decision rights should be visible in the language of the control. The owner may be authorized to stop a task when a critical barrier is absent, reject a handover that lacks evidence, require an engineering review, or escalate an overdue correction directly to the plant manager. Without that authority, the role is expected to carry risk while waiting for permission to reduce it.
A practical test is to ask the owner to describe the last decision they made that changed the exposure. If the answer is a meeting, an email, or a reminder, the role may be administratively active but operationally weak.
Distortion 3: the control is owned, but its degradation is not
Controls rarely fail in a single dramatic moment. Inspection quality slips, alarms are bypassed, staffing changes, test intervals expand, spare parts become unavailable, and temporary fixes remain in place after the original reason has disappeared. A control can remain present in the procedure while becoming unreliable in the work.
Ownership must therefore include the conditions that show degradation. The owner needs defined evidence, a review trigger, and a route for escalation when performance falls below the required level. A monthly confirmation that a barrier exists is not enough if the risk depends on availability during abnormal work, maintenance, or a simultaneous operation.
Leaders can connect this review with the five gaps that make critical-control dashboards misleading. The question is not whether the control is listed. It is whether someone knows when its protective value has weakened and can act before exposure reaches a person.
Distortion 4: interfaces are treated as shared accountability
Shared accountability often sounds collaborative, but it can conceal the absence of a final decision owner. Operations owns the work, engineering owns the design, maintenance owns reliability, procurement owns the supplier, and EHS owns assurance. When a risk crosses all five boundaries, each group can point to a valid responsibility while the interface remains unowned.
High-consequence risk needs an explicit handoff model. The organization should identify who owns the decision before work starts, who owns the control during execution, who owns the change when conditions move, and who receives the escalation when the interface fails. A contractor may perform the task, but the host organization still needs a named role for the conditions under which the task is allowed to proceed.
The traps in critical-risk delegation become especially visible here. Delegation is not transfer of accountability when the receiving role lacks context, authority, or a clear boundary for saying no.
Distortion 5: assurance is confused with ownership
Audits, inspections, and dashboards can reveal whether a control appears healthy, but they do not own the exposure. Assurance teams sometimes become the default destination for unresolved risk because they are the group that names the weakness most clearly. The result is a strange reversal in which the person who detects the failure is treated as the person responsible for correcting it.
Good assurance creates pressure without absorbing operational ownership. It states what was observed, explains why the evidence is insufficient, confirms the accountable decision maker, and sets the next verification point. The assurance role should be independent enough to challenge the owner, while the owner remains close enough to change the work.
Andreza Araujo’s book Safety Culture: From Theory to Practice emphasizes the distance between declared commitment and operated practice. That distance narrows when leaders treat field evidence as a decision input rather than an audit score.
Distortion 6: escalation is available only after harm or delay
An organization may say that anyone can escalate serious risk, yet provide no clear trigger, response time, or protected route when the normal chain is unavailable. In that environment, escalation becomes a personal act of courage instead of a designed control. People wait, negotiate informally, or continue with a temporary workaround because the cost of raising the issue feels less predictable than the cost of tolerating it.
Define escalation around observable conditions. A missed verification, a failed test, an unavailable rescue resource, an unresolved design conflict, or a repeated temporary deviation should move the decision to a role with greater authority. The escalation record should show who received it, what decision was made, what exposure remained, and when the field condition would be checked again.
The tests for safety decision latency help leaders distinguish a busy system from a responsive one. A message that is acknowledged without a decision has traveled through the organization, but the risk has not moved.
What a credible accountability model must show
A strong model makes the relationship between authority and evidence visible. It does not need a complicated software platform. A single page can expose more truth than a large register when it answers the questions that pressure usually hides.
| Accountability question | Evidence leaders should see | Warning sign |
|---|---|---|
| Who accepts the risk decision? | Named role with authority and review date | The register names a department only |
| Who owns control performance? | Test, inspection, maintenance, and failure criteria | The control is described without a performance condition |
| Who verifies the field condition? | Independent or cross-functional evidence from real work | Verification relies only on a document review |
| Who can escalate or stop? | Trigger, response time, and protected route | Escalation depends on personal influence |
| Who confirms recovery? | Closure evidence after correction or change | Actions close administratively before exposure changes |
Directors and plant managers should review this model against one live high-consequence risk rather than asking whether the governance process exists. A live test reveals whether responsibility survives the boundary between the boardroom, the work plan, the contractor, and the person who must rely on the control.
How leaders can repair ownership before the next review
Start with one serious exposure that has remained open through more than one review cycle. Trace the decision that would reduce it, then identify the role with authority to make that decision. If that role is absent, create it before asking for another status update.
Next, define the control’s failure conditions in language that a supervisor, technician, or contractor can recognize. Assign the verification method and the escalation trigger at the same time. A control without a failure signal is easy to report and hard to trust.
Finally, review the arrangement after a change in leader, contractor, design, production plan, or maintenance strategy. Ownership decays when the organization changes around it. In more than 250 cultural transformation projects, Andreza Araujo’s work has kept returning to this practical standard: responsibility is credible when the field can see who will decide, who will verify, and what happens when the answer is not acceptable.
Read more about the boundary between accountability and blame and compare it with the decisions directors should keep visible before the monthly dashboard.
Conclusion: accountability is real when it changes the next decision
A named owner is only the beginning of safety accountability. High-consequence risk remains exposed when the owner lacks decision rights, control evidence, interface clarity, degradation triggers, or a reliable escalation route. The organization may look governed while the work continues to depend on informal influence.
Leaders can correct that gap by linking each serious risk to a decision owner, a control owner, a field verifier, and a recovery test. When those relationships are visible, accountability stops being a label on a chart and becomes a protection people can rely on. Safety is about coming home, and the leadership system must show who will act when the conditions for that outcome begin to disappear.
Explore Andreza Araujo’s work on safety leadership, culture, and measurable prevention.
Frequently asked questions
What is safety accountability?
Why does a risk owner sometimes fail to control the risk?
What should a director ask about a critical risk owner?
How is accountability different from blame?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.