Safety Indicators and Metrics

Zero-Accident Targets: 3 Failures That Turn Safety Metrics Into Underreporting Pressure

A zero-accident target can support prevention, but it becomes dangerous when it rewards silence. This F1 diagnostic explains how reporting pressure, activity metrics, and aggregate numbers hide changing exposure, then gives executives a stronger review model.

By 6 min read
metrics dashboard representing zero accident targets 3 failures that turn safety metrics into underreporting — Zero-Accident

Key takeaways

  1. 01A zero incident count does not prove that exposure or critical-control weakness has disappeared.
  2. 02Targets connected to recognition or punishment can make reporting feel like a personal threat.
  3. 03Activity measures become misleading when completion is counted without control verification.
  4. 04Executive reviews should separate unlike exposures and surface unowned or unverified decisions.
  5. 05A credible zero-harm ambition requires transparent reporting, escalation, and field evidence.

F1 diagnostic longform for EHS directors, operations leaders, and board-level safety reviewers

A zero-accident target can express a serious commitment to preventing harm, but it becomes dangerous when leaders treat the number as proof that risk is under control. The central question is not whether the monthly report shows zero. It is whether the organization can still see exposure, hear bad news, and verify that critical controls are working.

Picture a monthly review in which the safety dashboard is green, the incident count is flat, and every business unit is close to its target. The meeting should create confidence. Instead, the room becomes quieter. Near misses disappear from the discussion, supervisors describe fewer concerns, and the most consequential work is explained through completed forms rather than evidence from the field.

Andreza Araujo develops this distinction in Far Beyond Zero, where safety performance is treated as more than the absence of recorded events. A serious measurement system has to protect reporting, expose changing conditions, and help leaders decide before a high-consequence event makes the weakness visible.

Why a zero result is not the same as zero exposure

Incident counts describe what has been recorded. Exposure describes what the operation is asking people to face. Those two pictures can move in opposite directions because a quiet reporting channel may lower the first number while the second becomes more severe.

That is why a zero result needs interpretation. If the site has recently changed production, staffing, contractors, shift patterns, or maintenance scope, the absence of a record does not prove that the underlying risk stayed constant. It may only show that the organization has not received enough information to challenge its assumptions.

James Reason’s work on organizational accidents is useful here because it separates visible events from the latent conditions that make them possible. A dashboard that rewards only the visible event count can hide the conditions that deserve executive attention.

Failure 1: The target turns reporting into a personal threat

The first failure appears when a zero-accident target is connected to recognition, promotion, contract renewal, or public ranking without an equally strong expectation to report uncertainty. The message received by the workforce is not “help us prevent harm.” It is “do not become the reason this number changes.”

Under that pressure, a supervisor may classify a minor injury as ordinary discomfort, delay a near-miss discussion until the facts are less clear, or keep a contractor concern inside the shift team. Each choice can look efficient in the short term because the dashboard remains stable. The operation, however, loses the information needed to correct a weak barrier.

The practical test is simple. Ask what happens after a person reports a concern that does not fit the current target. If the answer is investigation, support, and a visible decision path, the target may still be useful. If the answer is blame, paperwork, or a warning about the team’s performance rating, underreporting pressure is already part of the measurement system.

A safer design separates learning information from personal punishment. Leaders can still require accountability for deliberate concealment, but the ordinary act of raising a weak signal must not be treated as a performance failure.

Failure 2: The metric counts activity instead of control quality

Many dashboards replace one weak number with a crowded set of activity measures. The site reports inspections completed, observations submitted, toolbox talks delivered, and corrective actions closed. Those figures look more proactive than injury counts, yet they can become another form of compliance theater when completion is easier to measure than effectiveness.

A completed inspection does not show that a critical control was available at the point of work. A closed action does not show that the exposure changed. A conversation record does not show that the next task was performed under better conditions. Each measure becomes meaningful only when it is connected to a decision and a verification method.

Use three questions in the monthly review. What exposure was the measure intended to reveal? Who had authority to change the condition? What evidence confirms that the change remained in place after the action was closed?

This approach makes the dashboard smaller but more demanding. It also protects leaders from the false comfort of high completion rates, which can conceal weak ownership and superficial verification.

Failure 3: The number hides unequal exposure across teams

A single company-wide safety number can conceal the fact that different teams face different hazards, work rhythms, and control maturity. A warehouse, a laboratory, a maintenance crew, and a construction project may all contribute to the same corporate total while experiencing very different pathways to serious harm.

Aggregation is useful for governance, but it is not enough for diagnosis. The executive review should break the picture down by critical exposure, work process, contractor interface, shift pattern, and recent operational change. The purpose is not to rank teams publicly. It is to see where a small signal carries a large consequence.

That distinction matters because a low-frequency exposure can remain invisible in a conventional rate. If a task is performed rarely but has severe potential consequences, the absence of an event tells leaders very little about whether the barrier is sound. The dashboard should therefore pair outcome data with exposure evidence, control verification, and overdue decisions.

In Far Beyond Zero, the critique of zero as a standalone ambition is not an argument for accepting harm. It is an argument for measuring the conditions that make prevention credible, especially when the event history is too small to provide reassurance.

What an executive safety review should ask instead

A useful review does not begin with “Did we hit zero?” It begins with “What changed in the work, and what evidence shows that the controls kept pace?” That shift moves the conversation from scoreboard management toward operational judgment.

Weak questionStronger question
How many incidents did we record?Which exposures changed, and where is the evidence?
How many actions were closed?Which controls changed in the field and who verified them?
Which team has the best rate?Which team has the most consequential unowned decision?
Why did reporting fall?Did exposure fall, or did the reporting path become less trusted?

The stronger questions require owners, dates, and evidence. They also make it harder to hide uncertainty behind a favorable aggregate number.

How to preserve ambition without rewarding silence

Leaders do not have to abandon an aspiration for zero harm. They do have to define what the aspiration controls. A credible standard can state that no injury is acceptable while also requiring transparent reporting, rapid escalation, and verification of critical barriers.

Recognition should follow the quality of decisions, not merely the absence of events. A team that identifies a weak control, stops a task, and improves the design should not be made to look worse than a team that reports nothing. The visible cost of prevention is often evidence that the system is working.

Andreza’s documented experience gives this point practical weight. During a 180-day plan at PepsiCo South America Foods, she led a 50% reduction in accident ratio in six months. That result does not prove that one target or one metric works everywhere. It does show why measurement has to sit inside a management system that changes decisions, rather than floating above the operation as a score.

What to put on the monthly dashboard

A decision-oriented dashboard can remain concise. It should show the current outcome picture, the main exposures, the status of critical controls, and the decisions that remain unowned or unverified.

  • Recorded events, interpreted with reporting context rather than presented alone.
  • Critical exposures by work process, including recent changes in staffing, schedule, contractors, or equipment.
  • Control verification results that show whether barriers were present, usable, and understood.
  • Repeat concerns and overdue responses, with a named operational owner.
  • Actions that were closed administratively but still lack field evidence.

The dashboard should also preserve a route for disagreement. If a leader believes that the data is incomplete, that challenge belongs in the review record. A metric becomes more trustworthy when the system shows how uncertainty was handled.

When a zero-accident target is still useful

The target can be useful when it is treated as an ethical boundary rather than a bonus score. It can focus attention on preventing harm, support difficult investment decisions, and make it clear that serious injuries are not an acceptable operating cost.

It becomes unreliable when the number is used to certify culture, compare unlike operations, or close a conversation that the evidence has not resolved. The test is whether the target makes bad news easier or harder to surface.

For a related analysis of measurement quality, read Safety Data Quality Explained: 5 Decision Checks. For the broader distinction between proactive measures and activity counts, see Leading Safety Indicators: 5 Myths That Make Prevention Look Measurable.

The strongest safety dashboard does not promise that risk has disappeared. It shows whether leaders can still see exposure, hear inconvenient information, assign the next decision, and verify that the work became safer.

Topics safety-indicators-and-metrics zero-accident-targets underreporting safety-metrics executive-safety far-beyond-zero

Frequently asked questions

Are zero-accident targets bad for safety performance?
Not necessarily. A zero-harm ambition can express a serious ethical boundary. It becomes unsafe when the target is treated as a score that determines recognition or punishment, because people may learn that reporting an event is more damaging than leaving a weak signal unseen.
What should leaders measure instead of accidents alone?
Leaders should combine outcome data with exposure changes, critical-control verification, repeat concerns, overdue decisions, and evidence that corrective actions changed the work. The exact dashboard depends on the operation, but every measure should support a decision and a verification method.
How can a company reduce underreporting pressure?
Separate transparent reporting from routine performance punishment, protect people who raise concerns, investigate the reporting path when signals fall, and hold leaders accountable for the quality of their response. Deliberate concealment can remain an accountability issue without treating ordinary reporting as failure.
Why are activity metrics not enough?
Inspections, observations, talks, and closed actions show that activities occurred. They do not prove that a critical control was available, usable, understood, and verified at the point of work. Activity measures need an effectiveness test to support a safety decision.
Can a low-frequency hazard be hidden by a good safety rate?
Yes. A rare task with severe consequences may produce too few events for a conventional rate to be informative. Review the exposure, the barrier design, and the evidence that the control works instead of relying on event history alone.

About the author

Andreza Araújo

Safety Culture Expert | Senior EHS Executive

Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.

  • Civil & Safety Engineer (Unicamp)
  • M.A. Environmental Diplomacy (University of Geneva)
  • Sustainability Cert (IMD Switzerland)
  • People Management & Coaching (Ohio University)
  • UN Paris speaker representative for Brazil
  • ILO Turin speaker
  • LinkedIn Top Voice
  • Indra Nooyi PepsiCo CEO recognition (2x)

Documentaries

Watch Andreza's documentaries

Three productions on safety culture, organizational failure and the human lessons behind major disasters.

Podcasts

Listen to Andreza's podcasts

She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.

Summarize with AI