Safety Indicators and Metrics

Safety Assurance: 6 Blind Spots That Let Weak Controls Survive Executive Review

Safety assurance is only credible when it tests whether important controls remain effective under pressure. These six blind spots show why clean evidence packs, named owners, and green dashboards can still leave serious exposure unresolved.

By 7 min read
Executive safety assurance review focused on critical control evidence

Key takeaways

  1. 01Safety assurance tests whether important controls work under operating pressure, not whether documents exist.
  2. 02A named control owner needs a clear decision right and escalation route when the barrier is degraded.
  3. 03Assurance samples should include exceptions, temporary conditions, and recovery work where exposure is more likely to compress.
  4. 04Dashboards must separate activity, action completion, and verified risk reduction instead of merging them into one score.
  5. 05Andreza Araujo connects safety culture with observable leadership choices, field behavior, and evidence that challenges the preferred story.

A safety assurance review can end with a clean pack of evidence while a critical control remains weak in the field. The problem is not always a missing procedure. More often, the review accepts a proxy for control strength, treats a completed action as proof of risk reduction, or asks an executive dashboard to answer a question it was never designed to answer.

Safety assurance is the disciplined process of testing whether important controls are present, suitable, used, and effective under operating pressure. Its value depends on the quality of the test, not on the number of checks completed. Across 25+ years leading EHS work in multinational operations, Andreza Araujo has repeatedly seen that the gap between declared control and operated control is where serious exposure survives.

Why safety assurance fails before the review begins

Assurance becomes weak when the organization starts with available documents instead of the risk that must be controlled. A permit, training record, inspection form, or audit score can be real evidence, yet none of them proves that a person can rely on the control when production pressure, equipment change, or an unusual task alters the conditions.

James Reason's work on active and latent failures helps explain this gap. A visible deviation may be the final expression of earlier design, planning, supervision, or maintenance decisions. A serious review therefore asks which barrier should have prevented the exposure, how that barrier was expected to work, and what evidence shows that it worked on the day.

Andreza Araujo makes a similar distinction in Safety Culture: From Theory to Practice. The central issue is not whether the organization can describe a value. It is whether leadership choices, field behavior, and resource decisions make the value observable.

1. The review tests paperwork instead of control performance

Documentation matters because it records intent, ownership, and required conditions. It becomes dangerous when the presence of a document is treated as the result. A signed inspection can coexist with a missing guard, an overdue repair, or a supervisor who never saw the work.

Replace document confirmation with a three-part test. First, ask what the control is supposed to prevent. Second, inspect the physical or operational condition that makes the control credible. Third, ask the people who use it what changes when the control cannot be applied. The third question often reveals workarounds that a file review cannot see.

The distinction is especially important for SIF exposure, because a low count of recordable events does not prove that high-consequence barriers are healthy. The article on critical control verification gaps develops this point through the evidence that a dashboard can miss.

2. The owner is named, but the decision right is missing

Many assurance systems assign a control owner without defining what that person can stop, approve, escalate, or fund. The result looks orderly in a register, although the owner has no authority to resolve the condition that weakens the control.

An effective review should connect each critical control to an accountable role, a decision boundary, and an escalation clock. If a barrier is unavailable, the owner needs a clear route to suspend the task, accept a defined residual risk, or obtain a temporary alternative. Without that route, ownership becomes a label attached to exposure.

This is where executive review must become specific. Leaders should ask which decision was made when the control was known to be degraded, who made it, what evidence supported it, and when the condition will be tested again. A general request to improve compliance does not close an authority gap.

3. The assurance sample excludes the work under pressure

Routine observations usually produce the cleanest evidence. The task starts on time, the right people attend, and the control is easy to demonstrate. Serious exposure often appears during the exceptions that a routine sample excludes, such as breakdown recovery, night work, contractor mobilization, backlog reduction, or a temporary equipment configuration.

Sampling should therefore include moments when the system is stressed. The question is not whether every review must happen during an emergency. It is whether the sample represents the conditions in which people are most likely to compress planning, bypass a handoff, or accept a degraded barrier.

In more than 250 cultural transformation projects supported by Andreza Araujo's team, field evidence has been more useful when it is collected close to the decision that creates exposure. A scheduled walk can identify visible conditions. A pressure-point review explains why the condition was allowed to remain.

4. The dashboard rewards activity instead of risk reduction

Counts of audits, observations, meetings, and completed actions are easy to compare, so they often dominate executive reporting. They also create a false sense of movement when the underlying exposure remains unchanged.

A stronger dashboard separates activity from effectiveness. Activity shows whether the organization performed the planned work. Effectiveness shows whether the control condition improved, whether repeat findings declined for a credible reason, and whether the risk owner verified the change in the field. The difference is similar to the distinction between leading indicators and control evidence, which the article on leading-indicator dashboard distortions examines in detail.

Leaders should also resist one composite score. A high completion rate can hide a small number of severe unresolved conditions. The executive question is not whether the score is green. It is which serious exposure remains open, what prevents closure, and whether the current operating decision is still defensible.

5. Temporary conditions disappear from the assurance record

Temporary arrangements are often treated as short-lived exceptions, which makes them less visible as time passes. A bypass created for maintenance can remain after the work is complete. A staffing gap can become the accepted shift pattern. A changed route can outlive the original reason for the change.

The assurance test should record the start date, owner, compensating control, expiry condition, and return-to-standard evidence for every temporary deviation that changes exposure. The expiry condition must be observable. “When the situation is stable” does not tell anyone what to verify or who can close the exception.

This discipline also prevents temporary risk from being transferred between departments. The team that created the workaround may know its limits, while the next shift inherits only the instruction to keep production moving. A decision log, such as the one described in this guide to safety decision logs, keeps the reasoning available after the original meeting has ended.

6. The review closes the action before the barrier is retested

An action can be completed without changing the condition that produced the finding. A procedure may be revised, a briefing may be delivered, or a purchase order may be issued while the exposure remains present. Closure then records effort, not assurance.

Every significant action needs a verification question that can be answered with field evidence. If the action concerns machine guarding, the test should examine the installed guard, access points, interlocks, and use during the relevant task. If it concerns supervision, the test should examine decisions made during a real shift, not only attendance at a training session.

Andreza's experience at PepsiCo South America, where the accident ratio fell 50% in six months under a 180-day plan, illustrates why execution and verification must remain connected. The result was not produced by reporting activity alone. It depended on translating leadership priorities into decisions and conditions that could be observed.

What an executive safety assurance review should ask

An executive review does not need more slides. It needs a small set of questions that expose the difference between a declared control and a reliable one. The questions should be tied to the organization's highest-consequence exposures and answered with evidence that a decision-maker can challenge.

  • Which critical control protects the most serious credible exposure, and what evidence shows that it worked under pressure?
  • Which open condition has a named owner but no authority to resolve the barrier?
  • Which temporary deviation has passed its original expiry condition?
  • Which completed action has not yet been retested in the field?
  • Which dashboard result could remain green while a serious exposure grows?
  • What decision will change if the next verification fails?

These questions make assurance a management process rather than an audit ceremony. They also create a direct link between risk perception, leadership behavior, and the evidence used to allocate attention.

How to turn the six blind spots into a stronger assurance cycle

Start with the highest-consequence exposure, not with the easiest data set. Define the control in operational terms, identify the person who can make the relevant decision, and select evidence that tests the control where pressure is likely to distort it. Then separate action completion from barrier verification and give every unresolved condition an escalation path.

The cycle becomes credible when the organization learns from failed tests without lowering the boundary for known hazards. James Reason's framework is useful here because it keeps attention on both the immediate action and the latent conditions that made the action likely. Andreza Araujo's work adds the cultural test, which asks whether the organization is willing to see and act on evidence that challenges its preferred story.

Safety assurance earns trust when it can show more than completed work. It must demonstrate that important controls remain capable under the conditions that make them hardest to use. That is why the strongest review is not the one with the cleanest evidence pack, but the one that changes a decision before weak control becomes serious harm.

Topics safety-assurance critical-controls safety-indicators-and-metrics sif executive-leadership field-verification

Frequently asked questions

What is safety assurance?
Safety assurance is the structured testing of whether important risk controls are present, suitable, used, and effective under real operating conditions. It goes beyond checking documents by examining field evidence, decision rights, temporary deviations, and verification after corrective action.
How is safety assurance different from an audit?
An audit usually tests conformity against defined requirements. Safety assurance asks whether the controls that matter most for serious exposure can be relied on when work is pressured, changed, or abnormal. An audit can support assurance, but it cannot replace field verification and decision review.
What should executives review in a safety assurance dashboard?
Executives should review the highest-consequence exposures, the condition of their critical controls, unresolved exceptions, owners with authority to act, actions that have not been retested, and the decision that will change if verification fails.
Why can a completed corrective action still leave risk open?
Completion records that an assigned task occurred, but it does not prove that the barrier became effective. The organization must define a verification question and retest the control in the field under the conditions that created the original exposure.
How does Andreza Araujo approach safety assurance?
Andreza Araujo connects assurance with the difference between declared culture and operated culture. Her approach emphasizes observable leadership choices, field evidence, clear ownership, and verification that shows whether a decision changed the risk condition.

About the author

Andreza Araújo

Safety Culture Expert | Senior EHS Executive

Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.

  • Civil & Safety Engineer (Unicamp)
  • M.A. Environmental Diplomacy (University of Geneva)
  • Sustainability Cert (IMD Switzerland)
  • People Management & Coaching (Ohio University)
  • UN Paris speaker representative for Brazil
  • ILO Turin speaker
  • LinkedIn Top Voice
  • Indra Nooyi PepsiCo CEO recognition (2x)

Documentaries

Watch Andreza's documentaries

Three productions on safety culture, organizational failure and the human lessons behind major disasters.

Podcasts

Listen to Andreza's podcasts

She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.

Summarize with AI