Safety Leadership

Safety Leadership: 4 Gaps That Keep Critical Risk Waiting for a Decision

Critical risk rarely becomes dangerous because nobody saw it. It becomes dangerous when leaders see the signal, but decision ownership, escalation timing, or resources remain unclear. This diagnostic shows how safety leadership can reduce decision latency before exposure becomes an executive surprise.

By 7 min read
leadership scene showing safety leadership 4 gaps that keep critical risk waiting for a decision — Safety Leadership: 4 Gaps

Key takeaways

  1. 01Define decision latency as the time between a credible critical-risk signal and a defensible decision by someone with authority.
  2. 02Assign an operational decision owner and backup for each serious exposure, because a risk-register owner may not control the work today.
  3. 03Separate escalation acknowledgement from decision ownership, and define the response window by hazard rather than office convenience.
  4. 04Give every temporary control an expiry point, verification requirement, and named approver so temporary does not become invisible normal.
  5. 05Use Safety Culture: From Theory to Practice by Andreza Araujo to connect leadership routines with the decisions employees can actually observe.

A critical control is missing at 10:20 a.m. The supervisor knows it, the EHS manager knows it, and the plant manager will hear about it in the afternoon review. The work continues because everyone assumes that someone else owns the decision to stop, fund, redesign, or escalate the exposure.

This delay is a leadership problem before it becomes an operational problem. In safety leadership, decision latency means the time between a credible risk signal and the moment a person with authority makes the next defensible decision. Andreza Araujo's work across more than 250 cultural transformation projects shows why visible commitment is not enough. The organization must make the decision pathway visible when production, cost, and safety compete.

The central thesis is simple but demanding. Leaders do not reduce critical risk only by asking for better information. They reduce it by removing the gaps that leave good information waiting for permission, resources, or ownership.

Why critical risk becomes an executive surprise

Executives often receive a polished version of risk. The dashboard shows open actions, the meeting records a concern, and the responsible manager reports that a control is being evaluated. Each statement may be accurate while the underlying exposure remains active. A risk can be technically visible and operationally unattended at the same time.

James Reason's work on latent failures helps explain this pattern. The final unsafe act may occur at the point of work, but the conditions that shaped it can sit in decision rights, maintenance priorities, staffing, or review routines established much earlier. The delay between signal and decision is one of those latent conditions because it teaches the operation that escalation does not necessarily change the work.

Leaders should therefore ask a harder question than whether risk was reported. They should ask what happened in the first hour after the signal appeared, who had authority to change the condition, and what prevented that person from acting. Those answers reveal whether the management system is controlling exposure or merely documenting awareness.

Gap 1: The signal has no decision owner

Many organizations assign a risk owner to a register but leave the operational decision owner undefined. The difference matters. A risk owner may monitor a hazard over a month, while the decision owner must decide today whether work can proceed, whether a temporary control is acceptable, or whether the task must be redesigned.

When the distinction is missing, escalation becomes a relay. The supervisor calls EHS, EHS asks maintenance, maintenance waits for engineering, and engineering requests a management review. No one is intentionally ignoring the risk. The system simply distributes responsibility so widely that the decision has no home.

Define the decision owner beside each serious exposure, not only beside the risk category. For a failed isolation, that person may be the permit authority. For a degraded guarding system, it may be the area manager with maintenance support. For a contractor interface, it may be the site leader who controls simultaneous work. The owner needs authority, competence, and a named backup.

The risk-owner transition plan is useful here because it separates register administration from the authority required to keep a control reliable. A register cannot compensate for an owner who cannot change the work.

Gap 2: Escalation is defined, but response time is not

A procedure can say "escalate immediately" and still leave people uncertain about what happens next. Immediate escalation may mean a radio call, a work stoppage, a message to the duty manager, or an entry in a digital system. If the response path is not explicit, people choose the channel that feels least disruptive.

Response time also needs two separate definitions. The first is acknowledgement, which confirms that the concern reached a person who is available to act. The second is decision ownership, which identifies when the operation will know whether the task is stopped, changed, or allowed to continue under a defined control. A message that receives a thumbs-up but no decision has not closed the exposure.

Set the response window according to the hazard, not according to office convenience. A life-threatening exposure requires an immediate stop and a live handoff. A planning concern may allow a same-shift review. The procedure should state what happens when the first owner does not respond, because silence must never be interpreted as approval.

Supervisors can test this gap with one practical exercise. Choose a realistic high-risk scenario during a shift briefing and ask the team to name the first call, the backup call, the temporary boundary, and the restart condition. If the answers vary by person, the organization has a latency problem even if the written procedure looks complete.

Gap 3: Temporary controls have no expiry decision

Temporary controls are sometimes necessary, especially when production cannot stop indefinitely while a permanent engineering solution is designed. The danger begins when temporary becomes the unexamined normal. A barrier that was accepted for one shift can remain in place for weeks because nobody owns the decision to renew, replace, or remove it.

Every temporary control needs four visible fields. The first identifies the exposure it is meant to contain. The second names the person who can approve its use. The third sets an expiry or review point. The fourth defines the evidence required for restart under the permanent condition. Without those fields, the control becomes a promise rather than a managed barrier.

Leaders should resist the temptation to treat an open action as proof of control. An action may be progressing while workers remain exposed. The useful test is whether the temporary measure has been verified at the point of work and whether the next decision date is protected in the operating calendar.

This is where safety assurance reviews can expose a quiet failure. An executive review that checks whether actions are open may miss whether temporary controls are still suitable, understood, and resourced for the current work conditions.

Gap 4: The decision is made, but its reasoning disappears

A safety decision can be correct and still fail to improve the system if nobody can explain why it was made. When the reasoning disappears, the next shift repeats the discussion, contractors receive a different message, and leaders cannot distinguish a controlled exception from an undocumented compromise.

A useful decision record does not need to become a long investigation report. It should capture the trigger, the exposure, the options considered, the person who accepted the residual risk, the control that was verified, and the condition that would reopen the decision. This short record protects continuity without replacing judgement.

The record also creates a learning loop for leaders. If the same decision is reopened every week, the issue may not be worker inconsistency. It may indicate that the control is poorly designed, the boundary is unrealistic, or the risk has been accepted without the resources required to manage it.

The decision-log method gives managers a practical way to preserve this reasoning. Used well, it changes review meetings from status collection into examination of how the organization is making and revisiting safety-critical choices.

How leaders can measure decision latency without creating another dashboard

Decision latency does not require a new corporate scorecard. Leaders can sample a small number of serious-risk signals and reconstruct the path from detection to action. The goal is to see where the delay accumulated, not to reward teams for closing records quickly.

Evidence to reviewQuestion for leadersWarning sign
First escalation timeWhen did the concern reach someone with authority?The first message stayed inside a local team.
Decision timestampWhen did the operation decide to stop, change, or proceed?Acknowledgement was recorded without a decision.
Control verificationWho confirmed the barrier at the point of work?The review relied on a document or verbal assurance.
Restart conditionWhat evidence allowed work to resume?Restart was based on time pressure or informal confidence.

Reviewing a small sample each month is more useful than adding a lagging metric that teams can close without changing the exposure. The comparison should include the work context, the decision owner, and the resources available at the moment. Otherwise, leaders will measure administrative speed while missing operational delay.

What Andreza Araujo's experience adds to the diagnosis

Across 25+ years leading EHS work in multinational environments and more than 30 countries, Andreza Araujo has repeatedly connected safety performance with the quality of everyday leadership decisions. That experience matters because decision latency is rarely solved by a single procedure. It is shaped by how managers allocate attention when the situation is inconvenient.

In Safety Culture: From Theory to Practice, Araujo describes culture through the routines and choices that employees can observe. That lens changes the leadership question from "Did we communicate the expectation?" to "What did the organization make possible when the expectation became difficult?" A delayed risk decision is therefore cultural evidence, not only a process defect.

Her book Antifragile Leadership also offers a useful leadership test. A disruption should leave the organization better able to recognize and resolve the next critical decision. If every event produces a new reminder but no clearer authority, the organization is absorbing the shock without improving its capacity.

For executives, the implication is practical. The leadership team should make decision ownership, escalation timing, temporary-control expiry, and reasoning continuity visible in the same way that it makes financial and operational commitments visible.

What to change before the next serious-risk review

Start with one exposure that repeatedly appears in meetings without a durable decision. Map the first signal, the people contacted, the time spent waiting, the control used during the delay, and the evidence that allowed work to continue or restart. This short review usually reveals whether the weakness sits in authority, communication, resources, or verification.

Then assign one accountable decision owner and one backup. Define the response window, set an expiry point for any temporary control, and preserve the reasoning in a brief record. The sequence matters because adding another escalation form before clarifying authority only gives the existing delay a better filing system.

Leaders who want to compare this work with board-level governance can use the board safety oversight model. The purpose is not to move every operational decision upward. It is to ensure that the board and executive team can see when the organization lacks the authority or resources to resolve a serious exposure locally.

Critical risk becomes more manageable when the organization does not leave the next decision to chance. A visible signal, a named owner, a defined response window, a controlled temporary measure, and a traceable reason form a leadership system that acts before exposure becomes an executive surprise.

Topics safety-leadership decision-latency critical-risk risk-escalation c-level decision-rights

Frequently asked questions

What is decision latency in safety leadership?
Decision latency is the time between a credible safety-risk signal and the next defensible decision by a person with authority. The decision may be to stop work, change the method, add a control, allocate resources, or accept a defined residual risk. Measuring the delay helps leaders see where authority and escalation are failing.
Who should own a critical safety decision?
The operational decision owner should be the person who has the authority, competence, and resources to change the work condition. That person may be a permit authority, area manager, engineering leader, or site leader, depending on the exposure. A risk-register owner can monitor the issue, but monitoring alone does not control the work.
How can leaders prevent escalation silence from becoming approval?
Define an acknowledgement time, a decision time, and a backup owner for each escalation path. The procedure should state what the supervisor does when the first owner does not respond. Silence should trigger the backup route or a stop decision, never an assumption that work may continue.
How long may a temporary safety control remain in place?
There is no universal duration that is safe for every hazard. The control needs an explicit expiry or review point, a named approver, verification at the point of work, and evidence for the permanent solution or restart condition. If the review date passes without a decision, the exposure should be escalated again.
Does tracking decision latency require a new safety KPI?
Not necessarily. Leaders can sample serious-risk signals and compare the first escalation time, decision timestamp, control verification, and restart evidence. A focused monthly review is often more useful than a broad KPI that rewards record closure without showing whether the work condition changed.

About the author

Andreza Araújo

Safety Culture Expert | Senior EHS Executive

Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.

  • Civil & Safety Engineer (Unicamp)
  • M.A. Environmental Diplomacy (University of Geneva)
  • Sustainability Cert (IMD Switzerland)
  • People Management & Coaching (Ohio University)
  • UN Paris speaker representative for Brazil
  • ILO Turin speaker
  • LinkedIn Top Voice
  • Indra Nooyi PepsiCo CEO recognition (2x)

Documentaries

Watch Andreza's documentaries

Three productions on safety culture, organizational failure and the human lessons behind major disasters.

Podcasts

Listen to Andreza's podcasts

She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.

Summarize with AI