Critical Controls: Moving Beyond the Risk Register to What Actually Prevents Fatalities
- Leverage Safety
- Dec 28, 2025
- 11 min read

Most mature organisations have risk registers.
They contain hazards, consequences, likelihood ratings, control measures, residual-risk scores, responsible persons and review dates. Significant risks are colour-coded, reviewed periodically and reported through management systems.
All of this can be useful.
But there is a more important question that a risk register does not always answer particularly well: What absolutely has to work today to prevent somebody from being killed or seriously injured?
That question takes us away from the administration of risk and towards the reality of control.
A worker entering a confined space is not protected by the risk register. A lifting crew is not protected because a risk assessment was approved. A driver is not protected by a green dashboard, and an operator standing near hazardous energy is not protected because the relevant procedure passed an audit.
People are protected when the controls that stand between them and a serious event are actually present, suitable and effective at the moment they are needed.
This is the central idea behind critical control management.
For organisations exposed to fatal and major accident hazards, understanding that distinction can fundamentally change the way safety is managed.
Not Every Control Is Critical
A typical risk assessment can contain a long list of controls.
Training. Procedures. PPE. Supervision. Inspections. Signage. Permits. Barriers. Competency requirements. Maintenance. Communication. Emergency arrangements.
They may all contribute to managing risk.
But they do not all contribute equally.
A critical control is different because its absence or failure would significantly increase the likelihood of a serious unwanted event occurring or substantially increase the severity of its consequences. Current ICMM guidance describes a critical control as one that is crucial to directly preventing a fatal unwanted event or mitigating its consequences, with performance that can be specified, measured and verified.
That distinction matters.
Consider a lifting operation involving a suspended load. Several requirements may apply: the lifting team has completed training, the procedure is current, the toolbox talk has been recorded and appropriate PPE is being worn.
All are relevant.
But if the lifting equipment is unsuitable, the load is improperly rigged or people are standing inside the line of fire, the existence of the other controls provides limited comfort.
Some controls matter more at the moment when failure becomes possible.
Critical control management is about knowing which ones they are.
Start With the Event, Not the Checklist
One of the weaknesses of traditional risk management is that organisations can become very good at identifying hazards without developing the same clarity about how serious events actually occur.
Critical control management starts from a different perspective.
What is the event we are trying to prevent?
Perhaps it is a vehicle collision, dropped load, fall from height, uncontrolled release of energy, loss of containment, fire, explosion or confined-space fatality.
Once the unwanted event is clearly defined, we can examine the pathways capable of producing it and identify the controls that interrupt those pathways.
This is one reason bow-tie analysis has become so useful in high-hazard industries. It provides a visual way of connecting threats to an unwanted event, and then connecting that event to its potential consequences, with preventive and mitigative barriers positioned between them. The Energy Institute describes bow-tie analysis as a barrier-management methodology for understanding prevention and mitigation pathways, particularly for major accident risk.
The value is not the diagram itself.
The value is the thinking it forces.
Instead of asking whether we have enough controls, we begin asking which controls genuinely interrupt the path to the event.
That is a much more demanding test.
A Risk Register Can Create False Confidence
Risk registers are useful governance tools, but they can also create an illusion of precision.
A hazard is assigned a likelihood and consequence. Controls are listed. A residual risk is calculated. The cell changes from red to amber or green.
The risk appears controlled.
But the residual-risk rating often assumes that the listed controls are functioning as intended.
That assumption is critical.
If a risk assessment says a fatal hazard has been reduced to tolerable levels because five controls exist, but two of those controls are routinely degraded in the field, the residual-risk rating may tell management very little about the risk that actually exists.
This is where the distinction between control design and control effectiveness becomes important.
A control can exist on paper without being available.
It can be available without being used.
It can be used without functioning properly.
And it can function under normal conditions while failing under the conditions where it is needed most.
The risk register tells us what should protect us.
Critical control verification helps establish whether it actually does.
The Question Is Not “Do We Have the Control?”
Imagine an organisation identifies energy isolation as a critical control.
The first question is straightforward: does the isolation process exist?
In most mature organisations, the answer will be yes.
There will be procedures, locks, tags, registers, training and permit requirements.
The more important questions come next.
Can all energy sources be positively identified? Are isolation points accessible and clearly labelled? Can zero energy be demonstrated? Are people performing isolations competent? Are temporary or unusual configurations properly addressed? Are isolations being independently verified where required?
These questions move from the existence of the control to its performance.
A useful critical control therefore needs defined performance requirements.
What must the control do?
What does acceptable performance look like?
How can somebody verify it?
What happens if it is unavailable or degraded?
Without those definitions, organisations can claim a control exists without having a reliable way of determining whether it is effective.
Verification Needs to Happen Where the Risk Exists
Critical control verification should not become another corporate paperwork exercise.
Its greatest value is at the point of exposure.
Immediately before high-risk work begins, the people performing and supervising the task should be able to confirm that the safeguards capable of preventing serious harm are actually in place.
IOGP's Start Work Checks illustrate this principle particularly well. They are designed as simplified checks undertaken at the job location immediately before work begins, focusing on safeguards that must be present to prevent serious injury or death. The approach also incorporates peer verification, with work expected to stop and assistance sought when a safeguard cannot be confirmed.
That timing matters.
A risk assessment completed three weeks earlier cannot confirm today's conditions.
An audit conducted last month cannot tell us whether the isolation is correct now.
A training certificate cannot confirm that the exclusion zone has been established around today's lift.
The closer verification occurs to the point of exposure, the more operationally meaningful it becomes.
Verification Is Not Another Checklist
There is a risk that critical control management itself becomes bureaucratised.
An organisation identifies critical controls, creates another verification form, establishes a target for the number of verifications completed and adds the percentage to the HSE dashboard.
Soon, managers are celebrating 98 per cent verification completion.
We should recognise the warning signs.
The purpose of critical control verification is not to complete verifications.
It is to find weak controls before those weaknesses contribute to serious harm.
A verification programme that never finds anything should therefore generate curiosity rather than immediate celebration.
Are the controls genuinely performing exceptionally well?
Or are the verification questions too superficial?
Are people checking the control or simply confirming the paperwork?
Do employees feel able to report that a critical control has failed?
A healthy verification system should occasionally produce uncomfortable information.
That is part of its value.
Critical Controls Need Owners
A critical control without clear accountability is vulnerable.
Someone needs to understand what the control is expected to achieve, how its performance will be maintained and what information indicates deterioration.
This is different from assigning somebody ownership of the risk register entry.
Consider a physical safety-critical system such as gas detection, emergency shutdown equipment or a pressure-relief device. The control may depend on engineering design, inspection, maintenance, testing, competent technicians, spare parts and management of change.
No single field verification can guarantee its continued effectiveness.
The organisation therefore needs both operational verification and systemic assurance.
The Energy Institute's guidance on safety-critical elements reflects this lifecycle perspective, emphasising management of equipment whose failure could cause or contribute substantially to a major accident, or whose purpose is to prevent or limit its effects.
The same thinking applies more broadly to critical controls.
Some controls need to be checked before every task.
Others require periodic technical assurance.
Some depend heavily on human action.
Others depend primarily on engineering integrity.
The assurance strategy should reflect how the control can fail.
Human Controls Need Special Attention
Not every critical control is a piece of equipment.
Many depend on people.
A worker verifies zero energy. A lifting supervisor confirms the lift configuration. A driver decides whether conditions are suitable to continue. An operator responds to an alarm.
A permit issuer checks whether conflicting activities are occurring.
These controls can be highly effective.
They are also influenced by the conditions surrounding the person performing them.
Competence matters. Workload matters. Time pressure matters. Interface complexity matters. Information quality matters. Fatigue matters. Equipment design matters.
This is why organisations should be cautious about defining a human action as a critical control without considering what enables reliable performance.
If the control depends on a person identifying a subtle warning sign while simultaneously managing several other tasks, the organisation needs to understand the conditions under which that action might fail.
Human reliability should not be treated as simply telling people to be more careful.
The Energy Institute's guidance on human reliability specifically recognises the importance of integrating human performance into wider barrier and risk assessment approaches for major accident hazards.
A critical human control therefore needs the same discipline as an engineered one.
What must the person do?
What information do they need?
What makes the action reliable?
What could prevent them from performing it?
How will we know the control is working?
Critical Does Not Mean Everything Important
One of the easiest ways to weaken a critical control programme is to label too many controls as critical.
If everything is critical, nothing is.
Organisations naturally want to be cautious. During workshops, participants can become reluctant to remove controls from the critical list because doing so appears to suggest those controls do not matter.
But that misunderstands the concept.
A control can be important without being critical.
The purpose of identifying critical controls is to create focus around the relatively small number of barriers whose failure has a disproportionate influence on fatal or catastrophic outcomes.
That focus allows the organisation to apply stronger performance standards, clearer accountability and more deliberate verification.
The 2026 ICMM Critical Control Management Good Practice Guide reinforces this need for disciplined selection, including clearer criteria for identifying controls and determining which should genuinely be classified as critical.
The objective is not to produce the longest list.
It is to identify the controls the organisation cannot afford to assume are working.
Life-Saving Rules and Critical Controls Are Connected, But Different
Many organisations use Life-Saving Rules or equivalent fatal-risk programmes.
These can be extremely valuable because they simplify expectations around activities historically associated with fatalities.
IOGP's Life-Saving Rules focus attention on activities most likely to result in fatal events and on the actions workers and supervisors can take to protect themselves and others.
Importantly, the rules are linked to underlying controls and barriers rather than intended to replace the wider management system.
That distinction is important.
A rule such as “protect yourself against a fall when working at height” communicates an essential behavioural expectation.
Critical control management goes deeper.
What prevents the fall?
Is there a fixed barrier? Is fall restraint being used? Is the anchor suitable? Has the equipment been inspected? Can the worker actually connect before exposure occurs?
The rule creates clarity about expected behaviour.
Critical controls provide the barriers that make the expectation reliable.
Organisations need both.
When a Critical Control Fails, the Response Should Be Different
If an ordinary administrative requirement is missing, work may sometimes continue after appropriate assessment and correction.
A failed critical control deserves a different response.
If the organisation has genuinely identified something as critical to preventing fatal or catastrophic harm, its absence cannot simply become another observation for later closure.
The immediate question should be whether work can proceed safely.
Often, it cannot.
This is where stop-work authority becomes meaningful rather than symbolic.
Employees should understand that identifying an ineffective critical control is not an inconvenience to production. It is the system functioning as intended.
Management behaviour at that moment is crucial.
If workers stop an activity because a critical control cannot be verified and leadership responds with frustration about delay, the organisation sends a powerful message.
The next control failure may not be reported as quickly.
If leadership responds by supporting the stop, understanding the weakness and ensuring the control is restored, the organisation reinforces the behaviour it needs.
Critical control management is therefore as much about culture and leadership as it is about risk methodology.
Look for Patterns Across Control Failures
Individual control failures matter.
Patterns matter even more.
Suppose critical-control verification repeatedly identifies problems with energy isolation across several sites.
The organisation could treat each failure individually.
Correct the isolation. Coach the employee. Close the observation.
Or it could recognise a systemic signal.
Are isolation drawings inaccurate? Are labels deteriorating? Is equipment modification outpacing documentation? Are contractors receiving inconsistent training? Are verification requirements unclear?
This is where critical control information becomes safety intelligence.
Instead of waiting for an incident to reveal a systemic weakness, the organisation can use control-performance data to identify deterioration earlier.
Current IOGP thinking increasingly emphasises exactly this combination: verification and validation of controls, meaningful leading indicators, learning from work as actually performed and closing competence gaps before higher-consequence events occur.
The organisation begins learning from weakness before weakness becomes failure.
Move the Executive Conversation Towards Control Health
Critical control management also gives senior leaders a better way to discuss serious risk.
Instead of receiving only injury statistics, executives can understand the health of the controls protecting the organisation from its most significant events.
Which fatal hazards are we most exposed to?
Which critical controls are performing well?
Where are we finding recurring degradation?
Which controls depend heavily on ageing equipment?
Where do we have competence concerns?
Which failures require investment?
This is considerably more actionable than simply reporting that the total recordable injury rate has improved.
It also addresses one of the fundamental problems with low-frequency, high-consequence risk: waiting for outcomes provides very little useful data.
Organisations cannot wait for a fatality to establish whether fatal-risk controls are working.
They need evidence before the event.
From Risk Assessment to Risk Control
Risk assessments will remain important.
So will risk registers, bow ties, procedures, permits, training and audits.
Critical control management does not replace these systems.
It gives them focus.
The question becomes less about whether the organisation has documented the risk and more about whether it understands the few things that must work when exposure occurs.
That is a powerful shift.
For every fatal or major hazard, leaders should be able to answer several basic questions: What is the event we are trying to prevent? What are the critical controls?
What must each control do? Who is accountable for its performance? How do we verify it? What happens when it fails?
If those answers are unclear, the risk may be considerably less controlled than the risk register suggests.
The strongest organisations therefore do not simply identify risk.
They maintain an active line of sight from the hazard to the unwanted event, from the unwanted event to the controls, from the controls to their performance requirements and from those requirements to verification in the field.
That is what turns risk management from an analytical exercise into an operational discipline.
Because ultimately, people are not protected by the number of controls written into a risk assessment.
They are protected by the controls that actually work when something begins to go wrong.
And those are the controls we should understand, verify and manage with exceptional discipline.
References and Further Reading
International Council on Mining and Metals (ICMM). Critical Control Management: Good Practice Guide, 2026.Updated industry guidance on identifying fatal hazards, selecting critical controls, defining performance requirements, assigning accountability, implementation, verification and responding to inadequate control performance.
International Association of Oil & Gas Producers (IOGP). Life-Saving Rules. Industry guidance focusing on activities associated with fatal events and the worker and supervisor actions, controls and barriers intended to prevent them.
International Association of Oil & Gas Producers (IOGP). Start Work Checks. Field-level verification tools designed to confirm that safeguards necessary to prevent serious injury and fatality are present immediately before exposure begins.
International Association of Oil & Gas Producers (IOGP). Process Safety Fundamentals. Frontline principles intended to prevent high-severity and fatal process-safety events by focusing attention on situations and controls associated with serious process-safety risk.
Energy Institute and Center for Chemical Process Safety (CCPS). Bow Ties in Risk Management: A Concept Book for Process Safety. Guidance on bow-tie barrier analysis and the use of preventive and mitigative barriers within process-safety and risk-management frameworks.
Energy Institute. Guidelines for the Management of Safety Critical Elements. Guidance addressing the lifecycle management and assurance of equipment and systems whose failure could cause, contribute to or fail to mitigate a major accident.



