Critical Controls: Evidence Before Assurance
A board-level perspective on critical-control assurance, operating effectiveness, and the evidence leaders need before they can rely on a control.
Many organizations operating in high-risk environments can identify their most significant hazards. They can also point to procedures, permits, standards, inspections, training records, and dashboards that aim to keep those hazards under control.
However, leaders still need to answer a harder question: will those controls continue to work when operating conditions change?
In 2026, ICMM updated its Critical Control Management Good Practice Guide and brought its previous good-practice and implementation guidance into one resource. IOGP also published Report 815 on meaningful leading indicators and explained how organizations can identify, measure, and address inadequate controls before harm occurs. Together, these developments reinforce a fundamental HSEQ distinction: a management system may contain a control without proving that the control works in practice.
That distinction matters because broad injury metrics can move in a different direction from fatal risk. In its June 2026 discussion of 2025 member data, IOGP reported 52 fatalities and a 75% increase in the fatal accident rate compared with 2024, even though the total recordable injury rate fell by 6%. These figures cover participating IOGP member companies and their contractor workforces rather than every sector. Still, they show why a lower injury frequency cannot prove, on its own, that critical controls remain effective.
A documented control is not the same as a demonstrated control.
Control on Paper Is Not Control in Practice
Industry guidance treats a control as critical when that control plays an essential role in preventing a material unwanted event or mitigating its consequences.
A critical control may take the form of an engineering barrier, an isolation process, a maintenance requirement, a competency standard, a permit condition, or a defined supervisory decision. Organizations need to document these controls. Yet documentation alone does not provide assurance.
Even so, operating pressure can weaken a control after the organization adds it to a risk register or procedure. Common pressure points include:
- Changing operating conditions.
- Deferred maintenance or temporary repairs.
- Contractor turnover and variable capability.
- Unclear or divided ownership.
- Uncontrolled workarounds and normalized deviation.
- Weak supervision or verification.
- Production, cost, or schedule pressure.
- Poorly managed interfaces between teams and organizations.
- Changes that the operating system does not fully reflect.
Meanwhile, the organization may continue to report that the control exists while its capacity to prevent or mitigate the event declines. As a result, administrative confidence can drift away from operating reality.
Verification and Effectiveness Are Different Questions
Many assurance activities confirm completion rather than effectiveness. For example, teams may check whether someone completed an inspection, signed a permit, provided a procedure, recorded training, or closed a corrective action.
Those questions provide useful evidence. However, they do not always show whether the control can perform its intended function under the conditions in which people rely on it.
Effective critical-control assurance goes further. It examines:
- The control’s availability when people need it.
- Performance against defined requirements.
- Whether the people who rely on the control understand when and how to use it.
- How operating conditions, interfaces, and pressures affect performance.
- How quickly teams identify degradation, bypasses, and exceptions.
- What action leaders take when the control becomes unavailable or unreliable.
Consequently, assurance moves beyond a completion exercise and tests design, implementation, and operating effectiveness. Ventari Global’s Audit & Assurance work follows that distinction: it compares documented requirements with operating evidence and identifies where gaps remain.
Critical Controls Can Degrade Between Audits
Periodic audits provide a valuable point-in-time view. However, they cannot show, on their own, how every critical control performs between reviews.
Operations continue to move between those reviews. For example, work changes, contractors mobilize, equipment ages, and temporary arrangements remain in place longer than leaders expected. At the same time, production priorities shift and responsibilities move across functions and organizations.
Each change can affect the conditions on which a critical control depends. This issue becomes especially important across major projects, multi-site operations, and contractor-intensive environments. In those settings, one organization may own a control, another may implement it, and several more may rely on it.
When accountability fragments, a control can weaken without any single person seeing the full exposure. Therefore, organizations need to connect formal reviews with reliable evidence of how critical controls perform between those reviews.
Better Leading Indicators Measure Control Health
The move from lagging to leading indicators is not new. However, many leading indicators still measure activity rather than the condition of the system.
Organizations may count inspections, safety conversations, training hours, observations, and closed corrective actions. Those measures confirm that activity occurred. Yet they do not automatically show whether the organization is reducing its most serious exposures.
As Ventari Global previously examined in TRIF Is Dangerous: The Illusion of Safety, a favourable injury-frequency rate cannot prove, by itself, that the organization controls fatal risks. The same principle applies to leading indicators. Therefore, each measure should reveal something material about exposure, control capability, or the need for intervention.
A more meaningful approach starts with the risks that could produce the greatest consequences. For each material risk, leaders should understand:
- Which controls matter most.
- What each control must achieve.
- How teams verify effectiveness.
- Which signals indicate degradation.
- Where exceptions or repeated failures occur.
- Who owns the response.
- How quickly the organization restores control capability.
The goal is not to generate more HSEQ data. Instead, leaders need a clearer view of whether the controls protecting people, operations, and enterprise value remain dependable.
Activity is not the same as assurance.
Verification should show whether a critical control can still perform its intended function under real operating conditions.
Assurance Must Be Connected to the Work
Strong critical-control assurance moves evidence in both directions.
At the frontline, teams can confirm whether a control remains available, understood, and usable at the point of work. Supervisors can then test whether people apply requirements consistently. Next, operational leaders can identify patterns across sites, shifts, contractors, and activities. Finally, executives can determine whether recurring weaknesses, resource decisions, or organizational conditions are increasing exposure.
Boards do not need every operational detail. However, they do need confidence that the organization can identify its most consequential risks, understand the health of the controls that manage them, and act when those controls begin to weaken. Therefore, board and executive reporting should show where material exposure is changing, where evidence remains uncertain, and where leaders need to intervene.
Leaders should ground confidence in evidence, not assumption.
Questions Leaders Should Be Asking
Start with the consequence: Which controls cannot be allowed to fail? Not every procedure or safeguard carries the same consequence. Leaders need clarity on the limited number of controls that prevent or mitigate high-consequence events.
Then test the evidence: What demonstrates that those controls are effective? Completion records may confirm an activity. Assurance should determine whether the control can still produce the required result.
Next, examine recurring weakness: Where do controls repeatedly become unavailable, bypassed, or degraded? Recurring exceptions can reveal deeper problems involving system design, maintenance, contractor management, competence, resources, or operating pressure.
Also test the interfaces: Do contractor and organizational boundaries weaken control ownership? When several parties share responsibility, ambiguity can create material exposure.
Plan for failure: What happens when a critical control is unavailable? The organization needs clear escalation, authority, and operating responses. Leaders should not allow teams to normalize work without the required control.
Finally, challenge the reporting: Does executive reporting reveal control health or only HSEQ activity? Board and executive reporting should show where exposure is changing, where evidence is weak, and where leadership intervention is necessary.
From Documented Control to Demonstrated Confidence
Critical controls should not create confidence merely because they appear within a mature management system.
Instead, leaders should base confidence on evidence that the organization has identified the controls that matter most, established clear performance requirements, tested operating effectiveness, and acted when changing conditions placed those controls at risk.
This discipline does not add another layer of HSEQ reporting. Rather, it connects enterprise risk, operational control, assurance, and leadership accountability.
Consequently, organizations in complex and high-risk environments can move from documented control to demonstrated confidence. The Ventari Summit™ Framework supports a more integrated view of risk and critical controls, governance and assurance, operational control and performance, and leadership accountability.
The real test is not whether an organization can describe its critical controls, but whether leadership can rely on them when conditions are changing, accountability is distributed, and the consequences are material. Where that confidence is incomplete, the issue is no longer only technical. It becomes a governance question, an operating-performance question, and a board-level risk that warrants independent challenge, stronger assurance, and a clearer enterprise view.
References
- International Council on Mining and Metals (ICMM), Critical Control Management: Good Practice Guide, 2026.
- International Association of Oil & Gas Producers (IOGP), Report 815: Preventing Fatalities and Permanent Impairment Injuries – Developing Meaningful Leading Indicators, May 2026.
- International Association of Oil & Gas Producers (IOGP), Monthly Reflections: June 2026, discussing 2025 member safety-performance data.
Strengthen the View of Critical Risk
When safeguards begin to fail, the window to respond narrows quickly. Ventari Global gives boards and executives the independent view they need to intervene before operational weakness becomes enterprise loss.
