Critical Control Verification creates evidence about whether the controls relied upon to prevent serious harm are actually effective.

Not whether the check was completed.

Whether the control works.

Verification is not a checklist.

Completing a verification tells us one thing with certainty:

The verification was completed.

Whether it tells us anything useful about protection depends on what was verified, what evidence was gathered and what decision the question allows us to make.

A good verification should help answer:

Is this critical control effective enough to protect people from the defined serious-harm pathway?

That is the purpose of Critical Control Verification.

Start with the decision.

Verification questions are often written too early.

Someone identifies a critical control and immediately asks:

What should we check?

Start somewhere else.

01 — CONTROL

What is the control?

02 — FUNCTION

What serious-harm pathway does it interrupt?

03 — PERFORMANCE STANDARD

What must the control achieve?

04 — PERFORMANCE REQUIREMENT

What must be true for it to achieve that?

05 — EVIDENCE

What would demonstrate that requirement is being met?

06 — VERIFICATION QUESTION

What question allows the person verifying to make that decision?

Design the evidence first. Write the question second.

From risk to evidence.

Verification should have a clear line of sight back to the risk.

CRITICAL RISK

What event or exposure could seriously harm someone?

CRITICAL CONTROL

What are we relying on to interrupt that pathway?

PERFORMANCE STANDARD

What must that control achieve?

PERFORMANCE REQUIREMENT

What conditions must exist for effective performance?

VERIFICATION

What evidence tells us whether those conditions exist?

When that connection is lost, verification can become activity without purpose.

Two questions about effectiveness.

Verification needs to distinguish between two dimensions of control effectiveness.

DESIGN EFFECTIVENESS

Can it work?

Is the control capable of performing its intended function?

Is it appropriately designed for the hazard, energy, environment and pathway to harm?

Does the organisation provide the standards, engineering, maintenance, competency and other arrangements needed to support it?

OPERATING EFFECTIVENESS

Does it work here, now?

Is the control available where exposure exists?

Is it correctly implemented?

Is it in the required condition?

Is it functioning effectively under the actual circumstances of the work?

Both matter.

A control that cannot work by design will not become effective through better field compliance.

A well-designed control that is absent, degraded or incorrectly implemented won't protect anyone either.

Verify from different perspectives.

The same critical control looks different depending on where you stand.

NewEra uses three operational perspectives to understand whether protection exists.

SYSTEM

Does the organisation provide what the control needs?

This perspective looks at the arrangements supporting the control.

Standards.

Design.

Engineering.

Maintenance.

Competence.

Resources.

Governance.

Technical requirements.

The question is:

Have we created a system in which this control can succeed?

WORK

Is the work organised so the control can succeed?

This perspective looks at the conditions surrounding the task.

Planning.

Coordination.

Interfaces.

Resources.

Workload.

Changes.

Conflicting activities.

Environmental conditions.

Operational pressures.

The question is:

Does the way this work is being done support effective control?

CONTROL

Is the protection actually there?

This perspective gets closest to exposure.

Is the control present?

Available?

Correctly implemented?

In the required condition?

Performing its intended function?

The question is:

If exposure occurs now, will this control protect people?

Different perspectives.