Safety Indicators and Metrics

Zero-Accident Targets: 3 Traps That Distort Safety Decisions

A zero-accident target can sound like a strong safety commitment while quietly changing what people report, escalate, and fix. This F4 guide shows leaders how to keep ambition without sacrificing evidence.

By 5 min read
Safety leader reviewing whether a zero-accident target reflects real control effectiveness

Key takeaways

  1. 01A zero-accident target can express ambition, but it becomes unsafe when people believe that reporting an event threatens the target.
  2. 02The first trap is treating zero as proof that risk is absent, even when exposure, control failures, or near misses remain unexplored.
  3. 03The second trap is rewarding a clean record without testing whether reporting quality, investigation depth, and control verification are improving.
  4. 04The third trap is asking frontline leaders to defend a number they cannot influence because the metric has no clear decision owner.
  5. 05Andreza Araujo argues in *Muito Além do Zero* that safety leadership must go beyond the appearance of zero and examine the conditions that make serious harm possible.

A site can celebrate ninety days without a recordable injury while a critical guard remains bypassed, a contractor reports nothing, and supervisors learn that bad news creates more work. The dashboard is clean, yet the operation has not demonstrated that serious exposure is under control.

That is the central problem with a zero-accident target when it becomes a performance score. The ambition may be defensible, but the measurement design can reward silence, confuse outcome with control, and move attention away from events that have not happened yet. In her Portuguese book Muito Além do Zero, translated as Far Beyond Zero, Andreza Araujo challenges the idea that an empty incident column is enough evidence for a safety decision.

Why zero can become a distorted safety signal

Every safety metric tells a partial story. An accident count describes outcomes that reached a reporting threshold, while a zero count describes the absence of those recorded outcomes during a period. Neither number proves that exposure disappeared or that the barriers designed to prevent serious harm are working.

James Reason's work on latent failures helps explain why this distinction matters. Harm can remain possible when weak decisions, maintenance gaps, unclear supervision, and production pressure line up across several layers. A zero-accident target becomes hazardous when it closes the conversation before leaders test those layers.

The three traps below are common because each one sounds responsible in a leadership meeting. Each also creates a different decision error.

Trap 1: treating zero as evidence that risk is absent

The first trap confuses an outcome with a control. If nobody is injured, leaders may assume that the work is safe enough, even though the operation has not tested whether a barrier would stop a credible high-energy event.

This error is especially serious in work where exposure is intermittent. A lifting failure, a vehicle interaction, or an unexpected release may be possible every day without occurring every day. The absence of harm does not remove the opportunity for harm. It only tells leaders that the outcome did not appear in the recorded period.

To correct the trap, ask what was verified rather than only what was avoided. A monthly review should connect the zero count to the critical controls that were tested, the conditions found in the field, and the decisions made when a control was weak. The question is not whether the organization can preserve a clean number. It is whether the organization can show why serious harm was less likely.

Trap 2: rewarding a clean record before checking reporting quality

A clean record can reflect good performance, low exposure, incomplete reporting, or a mixture of all three. Leaders create pressure for underreporting when recognition, bonuses, public praise, or promotion depend on keeping the incident number at zero and the review does not examine how the number was produced.

The warning signs are often found outside the incident register. Near-miss narratives become shorter, first-aid cases stop appearing, supervisors say that workers prefer to handle issues informally, or contractors disappear from the reporting picture. A rate that improves while the evidence around it becomes thinner deserves scrutiny, not applause.

Use a reporting-quality review beside the outcome metric. Examine whether people can describe a concern without fear, whether reports include enough context to support a decision, whether investigations reach control owners, and whether actions are checked after closure. In more than 250 cultural transformation projects supported by Andreza Araujo, the useful question is what management did after the concern was raised, not how attractive the reporting total looked.

Trap 3: assigning the target to leaders without assigning decision rights

Frontline supervisors are often asked to deliver zero incidents even when they cannot approve engineering changes, change contractor selection, adjust staffing, or stop work without escalation. The target is personal, but the control system is distributed across functions.

That arrangement encourages local protection of the number. A supervisor may coach a worker again because the coaching is available, while the real problem sits in an unstable process, a missing spare part, an unrealistic schedule, or a design decision owned elsewhere. The metric then measures who absorbs the pressure rather than who controls the risk.

Make ownership visible by linking each safety signal to a decision right. The plant manager may own production sequence changes, engineering may own guarding, procurement may own contractor requirements, and the EHS leader may own verification quality. Supervisors still matter, but they should not be made accountable for controls they are not authorized to change.

What a better monthly safety review asks

A stronger review keeps the aspiration of no harm while replacing the single-score conversation with questions that test the work. The chair should ask which serious-potential exposures were present, which controls were verified in real conditions, and where the evidence disagreed with the documented standard.

The review should also ask whether reporting became easier or harder, which concern took longest to resolve, and what decision changed because of worker input. These questions do not weaken accountability. They move accountability toward the people and processes that can change exposure.

When the answers are vague, the dashboard should show that uncertainty instead of hiding it behind a green status. A leader can accept temporary uncertainty when it is named, owned, and given a due date. Unnamed uncertainty becomes normalized exposure.

How to keep ambition without creating silence

State the ambition as a protection goal, not as a promise that the reporting system must defend. Then publish the evidence that will be reviewed alongside the outcome, including critical-control verification, serious-potential event learning, action effectiveness, exposure changes, and worker voice.

Define the response before the next event. A report should trigger fact-finding and control review, not an automatic search for someone to blame. James Reason's distinction between active errors and latent conditions remains useful here because it directs attention toward the conditions that shape decisions without removing individual responsibility for deliberate choices.

Finally, reward leaders for making risk visible early. A supervisor who escalates a weak barrier has produced a management signal, even if the signal makes the monthly dashboard look less comfortable. That is the behavior a serious prevention system needs.

What to change in the next 30 days

Start with one executive review and one operational review. In the executive meeting, remove the question that asks only whether the site stayed at zero. Add a question about which high-energy exposures were verified and which decisions changed. In the operational meeting, select one recurring exposure and trace it from report to owner to completed verification.

Then compare the old scorecard with the new decision set. If the new review produces more questions, that is not failure. It means the organization is seeing more of the work it previously compressed into a single outcome number.

Safety performance improves when leaders can hear bad news early enough to act on it. A zero-accident aspiration has value only when it strengthens that capability instead of protecting the appearance of success. For more practical guidance on safety culture and leadership, visit Andreza Araujo's English safety blog or explore her books at the Andreza Araujo store.

Topics safety-indicators-and-metrics zero-accident-targets underreporting safety-culture executive-safety sif-precursors

Frequently asked questions

Are zero-accident targets always harmful?
No. A zero-harm aspiration can focus attention on prevention when leaders pair it with honest reporting, exposure-based measures, control verification, and a response that does not punish people for raising concerns. The danger begins when zero becomes a score that teams must protect.
What should a company use instead of a zero-accident target?
Use a balanced decision set that includes serious-potential event reviews, critical-control verification, quality of corrective actions, exposure measures, and evidence that workers can report and escalate concerns. The right set depends on the operation and the decisions leaders need to make.
How can leaders detect underreporting?
Compare reporting patterns with workforce changes, overtime, production pressure, field observations, maintenance backlogs, first-aid trends, and worker conversations. A sudden clean period is not proof of improved safety when the surrounding signals become quieter at the same time.
How should executives discuss zero in a monthly review?
Executives should ask what the number cannot show, which high-energy exposures were verified, what workers tried to escalate, and which control decisions changed during the period. That keeps zero as an aspiration while preventing it from becoming the only story.

About the author

Andreza Araújo

Safety Culture Expert | Senior EHS Executive

Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.

  • Civil & Safety Engineer (Unicamp)
  • M.A. Environmental Diplomacy (University of Geneva)
  • Sustainability Cert (IMD Switzerland)
  • People Management & Coaching (Ohio University)
  • UN Paris speaker representative for Brazil
  • ILO Turin speaker
  • LinkedIn Top Voice
  • Indra Nooyi PepsiCo CEO recognition (2x)

Documentaries

Watch Andreza's documentaries

Three productions on safety culture, organizational failure and the human lessons behind major disasters.

Podcasts

Listen to Andreza's podcasts

She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.

Summarize with AI