Critical Control Management identifies the controls that serious-harm prevention depends on, defines what they need to achieve and creates the evidence needed to know whether they are working.

More controls don't always mean more protection.

Risk assessments often contain long lists of controls.

Procedures.

Training.

Supervision.

Permits.

PPE.

Engineering safeguards.

Inspections.

Warnings.

Some may be important. Some may support other controls. Some may not actually interrupt the pathway to harm at all.

Critical Control Management asks a more demanding question:

What are we genuinely relying on to prevent or mitigate this serious-harm pathway?

Those controls deserve particular attention.

Start with the serious-harm pathway.

Don't start by deciding which controls are critical.

Start with what could happen.

THREAT

What could initiate the pathway?

CRITICAL EVENT

What event or exposure represents the loss of control?

CONSEQUENCE

How could someone be seriously or fatally harmed?

CONTROLS

What directly interrupts that pathway?

Only then should we ask:

Which of those controls are critical?

First prove it's a control.

Not everything listed as a control actually controls the risk.

A control should directly:

PREVENT

Stop the serious-harm pathway developing.

DETECT & WARN

Identify a dangerous condition early enough for action.

RESPOND

Control escalation or support recovery and survival.

If an activity doesn't directly influence the pathway to harm, it may still be useful, but it shouldn't automatically be treated as a control.

First prove the control. Then prove the criticality.

What makes a control critical?

Critical doesn't simply mean important.

A control becomes critical because of the role it plays in preventing or mitigating a defined serious-harm pathway.

Ask:

What happens if this control fails?

How much does the pathway depend on it?

Are other controls genuinely independent?

Could its failure materially increase the potential for serious harm?

Criticality is therefore about more than the control itself.

It's about reliance.

Define what the control must achieve.

Once a critical control has been identified, everyone needs a shared understanding of what effective performance looks like.

PERFORMANCE STANDARD

What must the control achieve?

The intended function and outcome of the control.

PERFORMANCE REQUIREMENTS

What must be true for it to achieve that?

The specific conditions required for successful performance.

EVIDENCE

What would demonstrate those conditions exist?

Observable, measurable or otherwise reliable evidence.

VERIFICATION

What question allows us to make the decision?

A focused assessment of whether the required protection exists.

This creates traceability from the serious-harm pathway all the way to the question being asked in the field.

A critical control has to work.

An effective critical control is:

CAPABLE

It can perform its intended function.

AVAILABLE

It is available when the work requires it.

CORRECTLY IMPLEMENTED

It is established and used as intended in the work.

RELIABLE

It can be depended upon enough to prevent or mitigate the defined serious-harm pathway.

A control can exist on paper and still fail every one of those tests.

Presence isn't protection.

Two dimensions of effectiveness.

Critical controls need to be understood from two different perspectives.

DESIGN EFFECTIVENESS

Can it work?

Is the control capable of providing the intended protection?

Does its design make sense for the hazard, energy, operating environment and serious-harm pathway?

Are the necessary specifications, systems and dependencies in place?

OPERATING EFFECTIVENESS

Does it work here, now?

Is the control available?

Correctly implemented?

In the required condition?

Working under the actual circumstances of the task?

Both matter.

A perfectly designed control that isn't available in the field provides no protection.

A consistently implemented control that was never capable of controlling the pathway doesn't either.

Controls depend on conditions.

Critical controls don't operate in isolation.

Their performance can depend on:

People.

Equipment.

Maintenance.