Critical Risk Management
Turn fatal risks into controls that can be demonstrated in the field.
A practical operating model for mining, energy, Oil & Gas, construction and process industries. The objective is not to add another safety procedure, but to ensure the controls capable of preventing a fatal event are present, effective and maintained at the time of exposure.
The foundations of an effective programme
Critical Risk Management complements the HSE management system. It focuses attention on low-frequency events that could cause a fatality, multiple fatalities or life-altering illness.
Start from a clearly described unwanted event, not a generic hazard label.
Separate a true control from training, procedures and other supporting activities.
Prefer elimination and engineered barriers over dependence on human action.
Define observable performance requirements and clear Go / No-Go conditions.
Give operational leaders ownership of risks and controls; HSE owns the method.
Involve workers and contractors in design, localisation and verification.
Respond positively to reported gaps so weak signals remain visible.
Measure control health instead of relying only on injury-frequency indicators.
A nine-step implementation process
Plan the process
Assess readiness, define scope, appoint the executive sponsor and fund the programme.
Identify fatal hazards
Create the register of fatal hazards and precisely describe the related unwanted events.
Identify controls
Use BowTie, HAZOP, LOPA or another suitable barrier method to identify preventive and mitigating controls.
Select critical controls
Select the limited set whose absence or failure would materially increase likelihood or consequence.
Define performance
Specify the objective, requirements, failure modes, supporting activities and verification method.
Assign accountability
Name the risk owner, control owner and verification activity owners.
Implement locally
Adapt corporate content to each site and integrate it into work planning, maintenance and change management.
Verify in the field
Confirm that controls are present and effective, and stop or modify work when they are not.
Evaluate and improve
Combine verification, incidents, internal information and external learning to improve control design.
Minimum critical control performance standard
Related fatal hazard and unwanted event
Control objective in plain language
Specific, measurable and realistic performance requirements
Degradation and failure modes
Go / No-Go criteria and operating limits
Maintenance, inspection, calibration and competency requirements
Expected evidence and verification questions
Frequency based on exposure, variability and reliability
Owner, escalation and degraded-operation rules
Management-of-change requirements
Operational governance
Set appetite, challenge control health and fund material improvements.
Protect scope, remove obstacles and keep operations accountable.
Oversee the fatal hazard and accept or reject the aggregate control position.
Maintain design adequacy and operating effectiveness of the assigned control.
Confirm implementation at the point of exposure and act on gaps.
Maintain the method, coach operations and independently assess verification quality.
Provide risk-based assurance to the audit and risk committee.
Layered verification
Physically confirm the controls required for the task. Do not start when a mandatory control is absent or ineffective.
Check field application, evidence quality and alignment between the documented check and actual conditions.
Test design, technical integrity, maintenance, competency and supporting systems.
Assess the quality and sustainability of the overall process without replacing line accountability.
Deployment roadmap
Mobilise
Sponsor, readiness assessment, governance, fatality criteria and pilot site.
Design
Fatal hazard register, BowTie workshops, critical-control selection and ownership.
Specify
Performance standards, Go / No-Go rules, field tools and competency programme.
Pilot
Layered verification, dashboards and integration with PTW, LOTO, maintenance and MOC.
Assure
Effectiveness reviews, recurrence analysis and independent assurance.
Scale
Multi-site and contractor deployment, internal benchmarking and formal maturity review.
The indicators leaders should see
A dashboard that is always green is not proof of control. A healthy programme detects weaknesses, makes them discussable and demonstrates that corrective action is effective.
Maturity scale
1 Β· Limited
Initial activity, limited understanding and mainly compliance-driven behaviour.
2 Β· Emerging
Basic processes exist but design and implementation gaps remain visible.
3 Β· Established
A consistent approach is in place with proactive implementation and operational learning.
4 Β· Leading
The programme is integrated, sustained, operationally owned and continuously improved.
Failure modes to avoid
Calling every control critical
Using generic yes/no checklists without performance criteria
Making HSE the owner of operational controls
Setting verification quotas that encourage automatic green answers
Keeping verification separate from maintenance and work planning
Closing actions administratively without testing effectiveness
Assess your critical-control maturity
Nordik can facilitate the readiness assessment, fatal-hazard workshops, performance standards and a site deployment roadmap.