top of page

How Organisations Drift from Safe Practice and How Leaders Spot It Early

Mar 22
10 min read

Major incidents rarely begin with one reckless decision. More often, the organization moves away from safe practice in small steps that look reasonable at the time. A permit is signed before all controls are verified because the job is routine. A scaffold tag is left in place after a minor change because the crew knows the area. A pressure alarm is treated as a nuisance because it has behaved that way all week.


None of these actions may feel like a breach in the moment. Together, they create drift.


Sociologist Diane Vaughan popularised the term “normalization of deviance” in her analysis of the Space Shuttle Challenger disaster. Her work showed how repeated acceptance of abnormal conditions can become normal when previous outcomes appear successful. The same pattern appears in oil and gas, construction, aviation, marine, mining, and other high-risk work.


For HSE leaders, the challenge is practical. Drift is often visible before an incident, but it does not announce itself as danger. It appears as small exceptions, local fixes, missing checks, and quiet changes in what people tolerate.


Drift Starts When Abnormal Becomes Familiar


Normalization of deviance happens when a departure from the expected standard keeps producing acceptable short-term results. Because nothing goes wrong, the departure feels safe. Over time, the exception becomes the new informal standard.


In oil and gas, this may show up as repeated acceptance of equipment running outside ideal parameters because production remains stable. A pump vibrates above its preferred range, but it has done so for months. A temporary clamp remains in place after the planned repair window has passed. Gas detector faults are cleared so often that people stop asking why they occur.


In construction, drift may appear as edge protection removed “just for a lift” and not replaced immediately. It may be workers stepping over openings because the hatch was open yesterday and nobody fell. A telehandler route may slowly move closer to pedestrians because the original traffic plan no longer suits the work sequence.


In high-risk operations, including aviation maintenance, rail, utilities, and emergency response, drift often hides in routine handovers. The written process says one thing, but the real method depends on local knowledge. The system keeps working because experienced people compensate.


The warning sign is not only that a rule was broken. The stronger warning sign is that the break no longer creates surprise.


Useful indicators include:


  • Repeated “temporary” controls with no end date

  • Operators describing abnormal conditions as “normal for this unit”

  • Permits approved with copied language from earlier jobs

  • Risk assessments that do not change when the work changes

  • Supervisors relying on trusted individuals instead of verified barriers

  • Pre-start checks completed after the task has already begun


A practical leadership question is simple: What are we accepting today that would have concerned us a year ago?


That question works because it focuses on tolerance, not blame. Drift is rarely a people problem alone. It is usually a system problem made visible through people’s habits.


Production Pressure Changes What Feels Reasonable


Production pressure does not need to be shouted. It can be implied by schedule recovery plans, delayed shutdowns, bonus structures, customer commitments, night-shift handovers, or subcontractors waiting to start their scope.


After the 2005 Texas City refinery explosion, investigation reports highlighted a mix of cost pressure, aging equipment, alarm management issues, and weaknesses in process safety leadership. The lesson for other sites was not that people deliberately wanted unsafe outcomes. It was that business pressures can reshape decisions until risk controls become negotiable.


Production pressure often changes language first.


A team may stop saying, “We cannot proceed until this is isolated.” They start saying, “Can we do it carefully?” or “Can we manage it live?” In construction, the phrase may be, “We just need to get this pour done before the weather changes.” In lifting operations, it may be, “We have made this lift before.” In shutdowns, it may be, “We are already behind the plan.”


None of those phrases prove unsafe work. They do show that time has entered the risk decision.


Leaders should listen for these practical signs:


  • Controls described as delays rather than requirements

  • Increased use of simultaneous operations without fresh review

  • Deferred maintenance justified by short-term availability

  • More work authorized under generic permits

  • Supervisors spending most of their time expediting work

  • Near misses reframed as productivity issues rather than risk signals


The key test is whether the organization can still say no when the answer is inconvenient.


Production pressure becomes hazardous when the people closest to the work believe that stopping is technically allowed but socially punished. The punishment may be subtle. A crew that stops work may be labeled difficult. A subcontractor may fear losing future work. A supervisor may receive praise only when they recover lost time.


A leader looking for drift should ask:


  1. Which jobs are we most reluctant to stop?

  2. Which controls are most often challenged as excessive?

  3. Where are schedule recovery meetings more detailed than risk review meetings?

  4. What work continues because “there is no other option”?

  5. When someone stops a job, what happens in the next hour?


The last question matters. Stop-work authority is weak if support arrives days later in a campaign poster. It is strong when a manager turns up, helps resolve the barrier issue, and thanks the person in front of the crew.


Workarounds Reveal The Gap Between Work As Imagined and Work As Done


A workaround is not automatically a sign of poor attitude. Many workarounds begin as attempts to get the job done despite barriers that the formal system has not solved. The problem starts when the workaround becomes permanent, invisible, and untested.


A good HSE investigation separates two questions:


  • Why did people work around the process?

  • Why did the process make the workaround attractive?


In oil and gas, operators may develop informal steps for starting equipment because the written procedure is outdated or too slow for field conditions. In construction, crews may store materials closer to the workface than the logistics plan allows because planned drop zones are full. In confined space work, teams may create informal sign-in methods because the official board is too far from the entry point.


These are not excuses. They are clues.


Workarounds matter because they often preserve production while weakening defenses. They can produce good outcomes many times before failing once. James Reason’s “Swiss cheese” model remains useful here: incidents occur when weaknesses in multiple layers of defense line up. Workarounds can enlarge those holes without anyone seeing the whole pattern.


Practical indicators of workaround culture include:


  • “Tribal knowledge” needed to complete routine tasks

  • Tools or equipment stored where the procedure says they should not be

  • Operators using personal checklists instead of approved ones

  • Frequent handwritten changes to printed procedures

  • Controls bypassed with informal approval

  • New starters confused because the taught method differs from the real method


A strong leader does not respond by demanding blind compliance. That can drive workarounds further underground. The better response is to make the real work visible.


Useful actions include:


  • Walk the task with the crew and compare each step with the procedure

  • Ask what makes the approved method hard to follow

  • Track repeated deviations by task, area, contractor, and shift

  • Fix poor procedures quickly, then communicate the change

  • Treat unauthorized shortcuts differently from intelligent field adaptations

  • Involve frontline workers in procedure reviews before the next campaign or shutdown


One of the most effective questions is: If I asked a new competent person to follow the written procedure, where would they get stuck?


That question exposes design flaws in the system without making the crew defensive.


Procedural Erosion Happens One Small Edit At A Time


Procedures do not only erode when people ignore them. They also erode when organizations keep adding, deleting, copying, and reissuing documents without checking how they function in the field.


A procedure can be technically available and practically useless. It may be too long, too generic, out of date, or written for a version of the plant that no longer exists. It may describe safe isolation in perfect conditions but not explain what to do when valves are seized, labels are missing, or access is restricted.


Procedural erosion also shows up in permit systems. A permit to work should confirm that hazards and controls have been reviewed for a specific job at a specific time. It loses value when it becomes a paperwork transaction.


Signs include:


  • Identical hazard controls across very different jobs

  • Permits signed in batches before the worksite inspection

  • Isolation certificates that do not match field labels

  • Job safety analyses copied from previous projects

  • Low-quality toolbox talks where crews cannot name the main hazard

  • Field changes handled verbally with no documented review


The Piper Alpha disaster in 1988 remains one of the clearest examples of how permit, maintenance, and handover weaknesses can combine in offshore operations. The public inquiry found serious failures in the safety management system, including communication and permit-to-work issues. The lasting lesson is that paperwork does not control risk unless it accurately reflects the asset's physical state.


Construction offers similar warnings. A method statement may specify exclusion zones for lifting, but site congestion creates pressure to shrink them. A temporary works design may require inspections after alteration, but the actual alteration happens between shifts. The document still exists. The work has moved on.


HSE leaders should audit procedure health by looking beyond document control. Version numbers and review dates matter, but they do not prove usability.


Better tests include:


  • Ask workers to point to the step that controls the fatal risk

  • Compare the procedure with the visible work in progress

  • Check whether field conditions match the assumptions in the document

  • Review how often workers request clarification

  • Look at how many procedures have not changed despite plant or sequence changes

  • Test whether supervisors can explain the reason for critical steps


A useful rule is to clearly identify critical steps to treat. Not every step in a procedure carries equal risk. If everything is bold, nothing is. Critical steps are the actions that prevent serious harm, such as verifying zero energy, testing atmosphere before entry, confirming ground bearing capacity for a crane, or maintaining separation between people and moving plant.


Early signals appear before major incidents


Drift can be detected before harm occurs, but leaders need to look at weak signals together. One minor deviation may mean little. A pattern across teams, shifts, or contractors means the operating envelope is changing.


Near-miss reporting helps, but it is not enough. Many early signs never enter the reporting system because no one treats them as incidents. They appear in planning meetings, maintenance backlogs, permit offices, stores, access routes, and supervisor routines.


A practical drift dashboard does not need to be complex. It should combine field observations with operational data. The aim is to find movement away from the safe operating basis.


Useful leading indicators include:


Indicator

What it may reveal

Growth in deferred maintenance

Risk controls are competing with availability

Repeat defects on safety-critical equipment

Barriers may be degraded or poorly understood

Permit extensions and revalidations

Work is taking longer, or conditions are changing

Late changes to lifting plans or method statements

Planning assumptions are weak

Increased overtime or fatigue exceptions

Staffing pressure may be affecting judgement

Repeated housekeeping issues in the same area

Supervisory control may be slipping

Frequent alarm overrides or inhibits

Operators may be normalizing abnormal states


The value comes from asking what changed, not from counting indicators for a monthly report.


For example, if a site sees more permit extensions during a shutdown, the cause may be poor planning, unexpected corrosion, contractor shortage, or congestion. Each cause has different controls. If leaders only ask whether the permits were extended correctly, they miss the drift mechanism.


Field verification is essential. Leaders should spend time where risk is present, but visits must test controls rather than provide visibility. A useful field conversation might include:


  • Show me the control that prevents the serious injury here.

  • What has changed since this task was planned?

  • Which part of the procedure is hardest to follow?

  • What would make you stop this job?

  • What workaround are people tempted to use?

  • If this job goes wrong, what is the most likely reason?


These questions work because they focus on the task, not on slogans. They also reveal whether people understand the risk controls or simply recognize the paperwork.


Preventive Action Means Restoring the Operating Envelope


Once drift appears, the response must be specific. A generic safety campaign may raise awareness, but it rarely changes the conditions that caused drift.


The first step is to define the safe operating envelope. That means clarifying the limits within which work remains controlled. In process industries, this may include pressure, temperature, corrosion limits, alarm set points, staffing levels, and safety-critical maintenance. In construction, it may include exclusion zones, temporary works limits, lifting conditions, access routes, sequencing rules, and competence requirements.


The second step is to identify where the organization has moved outside that envelope or close to its edge.


Preventive actions should match the mechanism of drift.


If production pressure is the driver, leaders may need to reset priorities for a shutdown, add resources, stop low-value work, or make clear which deadlines can move. If workaround culture is the driver, the organization may need to redesign the task, improve access, provide suitable tools, or rewrite a procedure with the crew. If procedural erosion is the driver, the answer may be to simplify critical procedures, remove obsolete documents, and verify field use.


The strongest controls are often boring and practical:


  • Close overdue safety-critical maintenance or formally assess the risk of deferral

  • Review long-standing temporary repairs and assign removal dates

  • Limit permit extensions for high-risk work without supervisor revalidation

  • Require field verification after significant changes

  • Protect time for pre-job planning on complex tasks

  • Involve experienced operators and trades in procedure updates

  • Track stop-work events and whether the underlying issue was fixed

  • Audit handovers after abnormal operations, not only after incidents


Senior leaders should also examine incentives. If the organization rewards output while treating safe control as assumed, people will learn the real priority. Metrics should include control health, not only injury rates. Low injury rates can coexist with serious process safety risk, as several major accident investigations have shown.


The Takeaway for Leaders


Organizational drift is dangerous because it feels ordinary. People adapt, solve problems, and keep work moving. Those strengths become hazards when the adaptations hide weakened controls.


Leaders spot drift early by looking for changes in tolerance. What is now accepted? Which controls are being negotiated? Where do procedures no longer match the work? What temporary condition has become permanent? Which abnormal alarms, defects, access issues, or planning gaps no longer create concern?


The practical response is to reconnect three things: the written system, the real work, and the physical controls that prevent serious harm. That requires field verification, honest conversations, quick fixes for poor procedures, and visible support when work stops for the right reason.


Safe practice does not disappear in one step. It drifts. The earlier that movement is seen, the easier it is to correct before the incident writes the lesson.


bottom of page