They aren't rules for organisations to adopt.
They're how we approach the work.
01
Understand before you intervene.
It's tempting to move quickly to solutions.
More training. Another procedure. A new checklist. A different control.
But solving the wrong problem well is still solving the wrong problem.
Start by understanding what is happening, why it is happening and the conditions surrounding it.
Understand the work first.
02
Go where the work happens.
There is only so much you can learn from a dashboard.
Documents describe expectations. Data reveals patterns. Systems provide structure.
But none of them replaces spending time with the people doing the work.
Go and see.
Ask.
Listen.
Understand what the work requires in practice.
03
People make sense.
When something goes wrong, behaviour is easy to see.
Context is harder.
People make decisions using the information, resources, experience, pressures and conditions available to them at the time.
Understanding those conditions gives us more useful questions than simply asking why someone didn't follow the rule.
Look beyond the behaviour.
04
Not all risk is equal.
Organisations face thousands of hazards.
A smaller number have the potential to kill or permanently change someone's life.
Those risks deserve particular attention.
Understand the pathways to serious harm.
Know which controls matter.
And know whether those controls are working before people are exposed.
Focus where failure matters most.
05
A control on paper protects no one.
A control can exist in a procedure, risk assessment or management system and still fail when it is needed.
Protection exists when the control can perform its intended function, is available when required and works in the conditions where people are exposed.
That requires more than implementation.
It requires evidence.
Don't assume protection. Verify it.
06
The gap is information.
There will almost always be a difference between how work is imagined and how it gets done.
That doesn't automatically mean someone is doing something wrong.
The gap can reveal where people adapt, where systems create difficulty, where controls are fragile and where work succeeds because people compensate for conditions the organisation hasn't fully understood.
Don't hide the gap.
Learn from it.
07
Success deserves attention too.
Most work doesn't end in an incident.
People routinely navigate complexity, adjust to changing conditions and keep work moving safely.
There is valuable information in understanding how.
What helped?
What protected people?
What adaptations worked?
What conditions supported success?
If we only learn after failure, we ignore most of the evidence available to us.
08
Bad news should travel.
A degraded control, weak signal or difficult piece of work is useful information.
People need to be able to surface problems without learning that silence is easier.
The aim isn't to make everything look green.
It's to know where protection is becoming vulnerable while there is still time to act.
Find the red. Learn from it.
09
Evidence over activity.
More activity doesn't automatically mean more protection.
More inspections.
More observations.
More training.
More verification.
More actions closed.
The useful question is what those activities tell us about the conditions of work and whether people are better protected as a result.
Measure what helps you understand the work.
10
Make the complex understandable.
Safety can become complicated very quickly.
Frameworks grow. Processes accumulate. Language becomes technical. Systems become harder to use.
Complex work sometimes requires sophisticated thinking.
It doesn't require unnecessarily complicated communication.
People should be able to understand what matters, why it matters and what they need to do.
If people can't use it, redesign it.
11
Design for the work you have.
A technically perfect solution that doesn't survive contact with real work isn't a good solution.
Controls and systems need to account for the people, equipment, environment, demands and variability that actually exist.
Good design makes the safer way easier to understand and easier to do.
Fit the solution to the work.
12
Improvement should change something.
Reports aren't improvement.

