Critical Control Verification: Are You Verifying – Or Just Documenting?

Most organisations with critical risk obligations believe they’re doing verification. Often, they’re doing something that looks like verification but functions like documentation. Here’s how to tell which one you’re doing.


Key takeaway: The difference between critical control documentation and critical control verification isn’t always obvious, even from the inside. Organisations can run what feel like rigorous verification processes and still be producing documentation – because the form is right but the substance isn’t. This checklist is designed to help H&S leads stress-test their own practice before the next board report, audit, or incident does it for them.


In almost every H&S function, the question of whether critical controls are being verified has a ready answer: yes, we have a process for that. Forms are completed. Records exist. The audit trail holds up.

What’s harder to answer is whether any of that activity is confirming that critical controls are in place and working – or whether it’s confirming that people filled in the form.

The distinction matters because both produce paperwork. Both generate records. Both can satisfy an auditor on a good day. The difference only becomes visible when a critical control fails silently – when the procedure exists but isn’t being followed, when the equipment check is a tick-box rather than a genuine inspection, when the record says “compliant” and the reality on the ground is something else entirely.

The Port of Auckland conviction is the clearest example of what that gap looks like under scrutiny. Exclusion zones around crane operations were documented. Workers weren’t complying with them. Nobody had taken adequate steps to check whether the critical control was functioning in reality, not just on paper. The documentation said one thing; the practice was another.

The question for every H&S lead is: how confident are you that your verification processes are genuinely confirming the second thing?


The most common ways organisations confuse the two aren’t due to carelessness – they’re the result of well-intentioned processes that have drifted from genuine checking toward record-keeping.

Here are a few common ways that might show up in your organisation.

Training completion as proof of control effectiveness. Recording that workers have completed induction training on a critical control is documentation. It tells you that training happened – it says nothing about whether the critical control is being applied correctly in the field. The gap between “trained on the procedure” and “following the procedure as intended” is exactly where silent failures can develop.

Scheduled checklists without observed practice. A checklist completed by the person responsible for the critical control is useful – but it’s self-reporting, not verification. If the person filling in the form is also the person whose work is being assessed, the form confirms their account of what happened, not what an independent observer would see. Genuine verification involves someone with relevant knowledge checking that the critical control is operating as designed, not just that a form has been returned.

Audit findings treated as ongoing confirmation. An audit confirms the state of a critical control on the day the auditor was present. It says nothing about what’s happening on the days they weren’t. Treating a clean audit result as evidence that a critical control is working reliably between audits is a category error – it confuses a point-in-time snapshot with continuous confirmation. As the HSWA Amendment Bill makes explicit, the officer duty requires ongoing verification, not periodic reassurance.

Incident-free periods as evidence of critical control effectiveness. The absence of incidents is not confirmation that critical controls are working. Critical controls can degrade silently for extended periods of time without causing an injury or death – until they do. A period without incidents tells you that no incidents occurred. It tells you nothing about the current state of the critical controls that are supposed to prevent them.


The questions below are designed to be applied to a specific critical control in your organisation – not to your verification process in general. Pick one and work through the questions, then check your results against the advice at the bottom.

On the evidence your verification produces:

  • Does your verification activity produce evidence that the critical control is in place and working – or evidence that someone reported it to be?
  • If a regulator asked to see proof that this critical control was functioning last Tuesday, could you show them something more than a completed form?
  • Is the person completing the verification check the same person responsible for the critical control? If so, is there an independent check at any point?
  • Does the verification record capture what was observed – or only whether the result was satisfactory?

On frequency and coverage:

  • Is the verification frequency calibrated to the severity of the risk, or does it default to your audit cycle? For more on setting the right cadence, see How To Set Critical Control Verification Frequency.
  • If this critical control failed today, how long before your current process would surface it?
  • Is verification happening across all locations, shifts, and contractor teams where this risk exists – or only where it’s convenient to check?

On what happens when issues are found:

  • When a verification check surfaces a problem, is there a clear escalation path – or does it depend on the individual who found it?
  • Can you point to examples where verification activity caught a critical control lapse before it became an incident?
  • Does your board receive information about critical control verification results – not just incident counts? For guidance on what that reporting should look like, see Briefing Boards on Critical Risk: A Practical Guide.

On whether the process is fit for purpose:

  • Does the person conducting the verification understand what an effective critical control looks like for this specific risk – well enough to distinguish genuine compliance from the appearance of it?
  • Would the verification process surface a situation where the procedure is technically being followed but the critical control isn’t functioning as intended?
  • If you asked the workers closest to this risk whether they think the critical control is being genuinely verified, what would they say?

No single question is diagnostic on its own. But a pattern of “no” or “I’m not sure” answers – particularly in the first section – is a reliable indicator that what you have is closer to documentation than verification.

That’s not a failure of intent. Most organisations that find themselves in this position have built processes in good faith. The issue is that documentation and verification can look similar, even from inside the organisation, and the difference only becomes clear when you ask specific questions about what the evidence confirms.

The difference between the two is the difference between knowing that a critical control has been recorded and knowing that it’s in place and working. In a high-risk environment, they’re not the same thing – and the current legal and regulatory environment is increasingly asking boards and officers to demonstrate the second, not just the first.

If this checklist surfaces gaps in your current practice, the practical next step is to work back through the critical controls that matter most and ask what genuine verification would look like for each one – what evidence it would produce, how frequently it needs to happen, and who is equipped to do it.

That’s a harder question than “do we have a process?”, but it’s the one that needs to be asked and answered properly.


We’ve put the checklist above into a one-page PDF – download it now to run through for your organisation.



Critter is built by IMPAC – New Zealand’s leading health and safety company, with 27 years of experience guiding organisations through complex critical risk challenges. Learn more about IMPAC.