How To Identify Critical Controls
Not every control on a critical risk is a critical control. Here’s a practical filter to identify critical controls, so you know which ones need rigorous verification.
Knowing the difference between a control attached to a critical risk and a critical control
Key takeaway: Not every control attached to a critical risk is itself critical. Critical controls are those that meet at least one of three criteria: they’re the only barrier against death or serious harm, they’re used for multiple threats or critical risks, and/or the absence of them significantly increases the risk of a significant event.
Ask most organisations to list the controls for one of their critical risks, and you’ll get a long list. Working at height might produce fifteen or twenty items: harness inspections, edge protection, exclusion zones, permit sign-offs, supervisor checks, worker competency records, weather thresholds, rescue plans. All of them matter. Not all of them may be critical.
That distinction gets lost more often than it should. When every item on the list gets treated with the same weight, three things tend to happen. Control implementation effort is diluted and verification effort spreads thin across everything. And the controls that genuinely stand between a worker and a fatality get no more attention than the record of who turned up to a toolbox talk.
What makes a control critical
A critical risk is the hazard itself: working at height, vehicle and pedestrian interaction, confined space entry, hazardous energy. Something that, if it goes wrong, is likely to kill someone or cause serious harm.
Attached to that risk is usually a whole range of controls, some hard/physical controls, and some administrative. What’s important to understand is that, although these controls are all attached to a critical risk, they may not all be critical controls.
Here’s why. A critical control is not just a control that’s attached to a critical risk. It’s a control that meets at least one of three criteria: it’s the only barrier against death or serious harm, it’s used for multiple threats or critical risks, and/or the absence of the control significantly increases the risk of a significant event.
Identifying which of your controls are in that subset is vital in making sure you allocate your implementation and verification resources most effectively.
How this shows up in day-to-day work
The test isn’t how often a control gets used, how visible it is, or how much it cost to put it in place. It’s the role it plays in preventing the incident and subsequent consequence – and that could extend to other critical risks in addition to the critical risk at hand.
A fall-arrest harness that isn’t properly implemented and inspected can fail the one time it’s needed, with nothing standing behind it as another line of defence. That makes it a critical control. A toolbox talk attendance register that’s a week out of date is important to know about, but it’s not a critical control – even though it’s attached to the same working-at-height critical risk.
The same split shows up everywhere. A machine guard interlock on a press is critical; the general maintenance checklist for the same work area isn’t. An isolation lock on live electrical equipment is critical; the induction record confirming a worker attended electrical safety training is important, but it isn’t the thing standing between them and the hazard in the moment.
Frequency doesn’t decide this either. A permit-to-work process used once a fortnight can be more critical than something that’s checked every shift, if its absence is the only thing standing between a worker and a fatal outcome.
Why this isn’t a different way of managing risk
Focusing on critical controls isn’t a fundamentally different discipline from managing risk generally. If resources and time were unlimited, every control on every risk would get the same rigorous, frequent verification, critical or not.
But resources and time have limits. Every organisation is making a resourcing decision, whether they’ve named it or not, about where their control implementation and verification effort goes. Understanding what makes a control critical makes that decision deliberate instead of accidental, so the controls that provide the most protection against the highest consequence get the closest attention, rather than getting the same treatment as everything else on the list simply because they happened to be on it.
Where controlling critical risk goes wrong in practice
Even organisations that understand the distinction between a control that’s attached to a critical risk and a critical control can get the application wrong. A few patterns come up often.
- The critical control list grows until everything is on it. Once “critical” starts attracting more attention and resourcing, there’s a pull toward reclassifying more controls as critical to make sure they get implemented and verified. That defeats the purpose. If the list runs to fifty items, it isn’t prioritising anything.
- Nobody revisits the list. Critical controls tend to get identified once, often during an initial risk assessment, then treated as settled. Work changes. Equipment changes. Contractors change. That means the critical controls need to be reviewed and updated, and they often aren’t.
- The filter of what is a critical control gets applied on paper, not on the ground. Someone works through these questions in a meeting room and reaches a reasonable-looking answer. Whether that answer holds up depends on how the work is done day to day, not how it was designed to be done. The two aren’t always the same, and the gap between them is exactly where a critical control can stop being effective without anyone noticing.
What governance guidance already expects
What we’re covering here is close to what IoD and WorkSafe’s governance guidance already asks of boards and officers. Their guidance is explicit that officers should be able to say what their organisation’s critical and catastrophic risks are, and understand the key controls used to manage them.
That’s a governance-level version of the same question this post is answering at the operational level: not what controls exist, but which of them matter most, and how anyone knows. An organisation that can’t answer that at the front line is unlikely to be able to answer it at board level either.
Questions to ask about how you identify critical controls
- Which of our critical risk controls:
- Are the only barrier against death or serious harm for the critical risks they’re attached to?
- Are used for multiple threats or critical risks?
- Significantly increase the risk of a significant event if they’re absent?
- Which of our critical risk controls would we notice failing, without being told?
- Are we spending the same amount of implementation and verification effort on a fall-arrest system as we are on a training register?
- Who identified our critical controls, and what process did they use to decide?
- If we could only verify five critical controls this month, would they be the same five that matter most?
Critter is built by IMPAC – New Zealand’s leading health and safety company, with 27 years of experience guiding organisations through complex critical risk challenges. Learn more about IMPAC.
