Risk Management

Safety Assurance Explained: 3 Evidence Layers That Make Control Decisions Defensible

Safety assurance is the structured process of gathering and testing evidence that critical controls are present, effective, and owned. This explainer separates assurance from inspection, audit, and risk assessment so leaders can make decisions from operating evidence rather than paperwork alone.

By 6 min read
risk management scene on safety assurance explained 3 evidence layers that make control decisions — Safety Assurance Explaine

Key takeaways

  1. 01Safety assurance tests whether evidence supports confidence in a control and a current operating decision.
  2. 02The three evidence layers are design, implementation, and performance evidence.
  3. 03An inspection finds conditions, an audit tests conformity, and assurance evaluates whether a control can be trusted.
  4. 04Escalation is required when a critical control is missing, degraded, untested, or unowned.
  5. 05A useful assurance record connects the exposure, control function, evidence, decision, owner, and review point.

A control can be documented, inspected, and still fail at the moment it is needed. Safety assurance addresses that gap by testing whether the control exists in the work, performs its intended function, and has an owner who can respond when its condition changes.

Safety assurance is the structured process of collecting and testing evidence that a safety control is present, capable of performing its intended function, and governed by a named owner. It connects risk assessment with operating reality, so a decision to continue, pause, or change work rests on evidence rather than the existence of a procedure.

What does safety assurance mean?

Safety assurance means establishing reasonable confidence that important controls will work under the conditions that matter. It is not a promise that risk has disappeared. The risk perception explainer shows why evidence must be interpreted in the context of the task. It is a disciplined decision process that identifies the control, defines its intended function, checks its condition, and records what the evidence supports.

ISO 31000:2018 describes risk management as an iterative process that includes identifying, analyzing, evaluating, treating, monitoring, and communicating risk. Safety assurance gives those activities an operational test. The ISO 31000 guidance provides the management framework, while field evidence shows whether the selected treatment is functioning where people work.

HSE explains risk assessment as identifying hazards, judging risk, and taking action to eliminate or control harm. Assurance begins after that decision and asks whether the action still protects people when the task, equipment, staffing, or schedule changes.

How is safety assurance different from an inspection or audit?

Safety assurance is a decision about confidence in control performance, whereas an inspection looks for conditions and an audit tests conformity against defined requirements. An inspection may find a damaged guard, and an audit may find a missing record, but assurance asks whether the control can still prevent the consequence it was selected to address.

The difference is visible in the question being asked. An inspection asks, “What is wrong here?” An audit asks, “Does the system meet the requirement?” Assurance asks, “What decision is justified by the evidence about this control?” The questions can share observations, although they do not produce the same conclusion.

Andreza Araújo connects this distinction with the practical logic of Safety Culture: From Theory to Practice. A mature safety culture is not demonstrated by the volume of forms completed. It is demonstrated when leaders use reliable evidence to remove obstacles to safe work and make ownership visible.

What are the 3 evidence layers in safety assurance?

The three evidence layers are design evidence, implementation evidence, and performance evidence. A control decision becomes stronger when all three layers agree, because each one answers a different question about whether the barrier can be trusted.

1. Design evidence

Design evidence shows why the control exists and what failure it is meant to prevent or limit. It can include a risk assessment, a bow-tie, an operating standard, an engineering drawing, a permit requirement, or a defined critical-control statement.

This layer should name the exposure, the control function, the boundary of the control, and the condition that requires escalation. If the document only says “follow procedure,” it has not yet described a testable control. The critical-control explanation is useful when a team needs to convert a broad requirement into observable proof.

2. Implementation evidence

Implementation evidence shows that the designed control is available in the operation. It can include commissioning records, competence checks, maintenance status, permit conditions, access arrangements, supervision, and confirmation that the people doing the work understand the control's purpose.

A procedure stored in a shared drive is not implementation evidence by itself. A lockout device that is not available at the isolation point is not implementation evidence either. The evidence must connect the intended control with the people, equipment, and sequence that must make it work.

3. Performance evidence

Performance evidence shows whether the control functions when the work is exposed to the conditions that can defeat it. It can come from field verification, functional tests, sampled work observations, alarm tests, control-room records, maintenance findings, or a review of repeated deviations.

Performance evidence should be specific enough to support a decision. “Inspection completed” is weaker than “interlock tested at the start of the maintenance window, with the isolation owner present and the expected trip confirmed.” The barrier-health model helps distinguish a control that is healthy from one that is degraded, unavailable, or unknown.

How do leaders test whether the evidence is strong enough?

Leaders should test the evidence for relevance, independence, recency, and traceability before accepting a control decision. Evidence is stronger when it addresses the actual exposure, comes from a source able to observe the condition, reflects the current work, and can be traced to a named decision.

TestQuestionWeak signalStronger signal
RelevanceDoes the evidence address the consequence?Generic checklistControl test linked to the exposure
RecencyDoes it reflect the current configuration?Old approval recordEvidence from the present task or shift
TraceabilityCan the decision be reconstructed?Unsigned observationOwner, condition, action, and review time
IndependenceCould the evidence challenge the assumption?Self-confirmation onlyCompetent review with permission to escalate

ISO 31000:2018 emphasizes monitoring and communication because risk information changes as the organization learns. Assurance therefore loses value when it becomes a ceremonial approval that cannot reopen a decision after new evidence appears.

In more than 25 years of multinational EHS leadership, Andreza Araújo has treated evidence quality as a leadership issue rather than an EHS filing exercise. Her work across 250+ companies reinforces a practical point: the person who owns the decision must be able to explain which evidence supports it and what would invalidate it.

When should a safety assurance decision be escalated?

A safety assurance decision should be escalated when a critical control is missing, degraded beyond its defined tolerance, untested under changed conditions, or owned by nobody with authority to act. Escalation is not a failure of the process. It is the process working before uncertainty becomes exposure.

Escalation should also occur when the evidence layers disagree. A strong design with weak implementation is not a controlled risk. A working control with no defined function is difficult to govern. A recent field observation that contradicts an approved document should trigger review of the assumption, not silent correction of the observation.

What should a safety assurance record contain?

A useful safety assurance record contains the exposure, the intended control function, the evidence reviewed, the current control state, the decision, the owner, and the next verification point. The record should be short enough to preserve the reasoning and complete enough for another leader to reconstruct the decision.

Andreza Araújo's Safety Culture Diagnosis: Learn how to do your own supports this discipline by treating evidence as part of diagnosis rather than as a score collected for presentation. That approach keeps assurance connected to the conditions people experience, including the gap between a written expectation and the work sequence that actually occurs.

The ILO guidelines for occupational safety and health management systems describe continual improvement as a practical management responsibility. A record that captures the decision, evidence, and review point makes that responsibility visible.

Frequently Asked Questions

Is safety assurance the same as a safety audit?

No. An audit evaluates conformity against criteria, while safety assurance evaluates whether evidence supports confidence in a control and a current operating decision. The two activities can inform each other, but they should not be treated as interchangeable.

Who owns a safety assurance decision?

The accountable operational or risk owner owns the decision, while competent EHS, engineering, maintenance, or assurance reviewers may provide evidence and challenge assumptions. Ownership should include authority to pause work or change the control.

How often should controls be assured?

The frequency should follow the control's consequence, change rate, failure history, and exposure pattern. A control that changes every shift needs more frequent evidence than a stable design feature whose condition is independently monitored.

What if the evidence is incomplete?

Incomplete evidence should be recorded as uncertainty, not converted into an assumption that the control is healthy. The owner should pause, add a temporary control, obtain the missing evidence, or escalate the decision according to the organization's risk criteria.

Can safety assurance replace risk assessment?

No. Risk assessment identifies hazards and selects treatments, while safety assurance checks whether important treatments remain capable and owned. Assurance is a feedback loop that helps a risk assessment stay connected to changing work.

Topics safety-assurance risk-management critical-controls control-verification evidence-quality

Frequently asked questions

Is safety assurance the same as a safety audit?
No. An audit evaluates conformity against criteria, while safety assurance evaluates whether evidence supports confidence in a control and a current operating decision.
Who owns a safety assurance decision?
The accountable operational or risk owner owns the decision, with competent reviewers providing evidence and challenging assumptions.
How often should controls be assured?
Frequency should follow consequence, change rate, failure history, and exposure pattern.
What if the evidence is incomplete?
Record the uncertainty and pause, add a temporary control, obtain the missing evidence, or escalate according to the risk criteria.
Can safety assurance replace risk assessment?
No. Risk assessment selects treatments, while assurance checks whether important treatments remain capable and owned.

About the author

Andreza Araújo

Safety Culture Expert | Senior EHS Executive

Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.

  • Civil & Safety Engineer (Unicamp)
  • M.A. Environmental Diplomacy (University of Geneva)
  • Sustainability Cert (IMD Switzerland)
  • People Management & Coaching (Ohio University)
  • UN Paris speaker representative for Brazil
  • ILO Turin speaker
  • LinkedIn Top Voice
  • Indra Nooyi PepsiCo CEO recognition (2x)

Documentaries

Watch Andreza's documentaries

Three productions on safety culture, organizational failure and the human lessons behind major disasters.

Podcasts

Listen to Andreza's podcasts

She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.

Summarize with AI