Critical Control Verification creates evidence about whether the controls relied upon to prevent serious harm are actually effective.
Not whether the check was completed.
Whether the control works.
Verification is not a checklist.
Completing a verification tells us one thing with certainty:
The verification was completed.
Whether it tells us anything useful about protection depends on what was verified, what evidence was gathered and what decision the question allows us to make.
A good verification should help answer:
Is this critical control effective enough to protect people from the defined serious-harm pathway?
That is the purpose of Critical Control Verification.
Start with the decision.
Verification questions are often written too early.
Someone identifies a critical control and immediately asks:
What should we check?
Start somewhere else.
01 — CONTROL
What is the control?
02 — FUNCTION
What serious-harm pathway does it interrupt?
03 — PERFORMANCE STANDARD
What must the control achieve?
04 — PERFORMANCE REQUIREMENT
What must be true for it to achieve that?
05 — EVIDENCE
What would demonstrate that requirement is being met?
06 — VERIFICATION QUESTION
What question allows the person verifying to make that decision?
Design the evidence first. Write the question second.
From risk to evidence.
Verification should have a clear line of sight back to the risk.
CRITICAL RISK
What event or exposure could seriously harm someone?
CRITICAL CONTROL
What are we relying on to interrupt that pathway?
PERFORMANCE STANDARD
What must that control achieve?
PERFORMANCE REQUIREMENT
What conditions must exist for effective performance?
VERIFICATION
What evidence tells us whether those conditions exist?
When that connection is lost, verification can become activity without purpose.
Two questions about effectiveness.
Verification needs to distinguish between two dimensions of control effectiveness.
DESIGN EFFECTIVENESS
Can it work?
Is the control capable of performing its intended function?
Is it appropriately designed for the hazard, energy, environment and pathway to harm?
Does the organisation provide the standards, engineering, maintenance, competency and other arrangements needed to support it?
OPERATING EFFECTIVENESS
Does it work here, now?
Is the control available where exposure exists?
Is it correctly implemented?
Is it in the required condition?
Is it functioning effectively under the actual circumstances of the work?
Both matter.
A control that cannot work by design will not become effective through better field compliance.
A well-designed control that is absent, degraded or incorrectly implemented won't protect anyone either.
Verify from different perspectives.
The same critical control looks different depending on where you stand.
NewEra uses three operational perspectives to understand whether protection exists.
SYSTEM
Does the organisation provide what the control needs?
This perspective looks at the arrangements supporting the control.
Standards.
Design.
Engineering.
Maintenance.
Competence.
Resources.
Governance.
Technical requirements.
The question is:
Have we created a system in which this control can succeed?
WORK
Is the work organised so the control can succeed?
This perspective looks at the conditions surrounding the task.
Planning.
Coordination.
Interfaces.
Resources.
Workload.
Changes.
Conflicting activities.
Environmental conditions.
Operational pressures.
The question is:
Does the way this work is being done support effective control?
CONTROL
Is the protection actually there?
This perspective gets closest to exposure.
Is the control present?
Available?
Correctly implemented?
In the required condition?
Performing its intended function?
The question is:
If exposure occurs now, will this control protect people?

