Risk Management

How Bhopal Exposed the Cost of Unowned Process Risk

The Bhopal disaster was not only a chemical-release event. It was a risk-management failure in which hazard knowledge, maintenance, operating discipline, emergency readiness, and public accountability were not held together by clear ownership.

By 6 min read
risk management scene on how bhopal exposed the cost of unowned process risk — How Bhopal Exposed the Cost of Unowned Process

Key takeaways

  1. 01Bhopal shows that a major hazard becomes harder to control when technical risk, maintenance decisions, emergency planning, and public accountability sit in separate ownership silos.
  2. 02A written process-safety program is not a working barrier unless someone can show its condition, operating limit, verification method, and escalation route.
  3. 03Risk ownership must follow decision authority, which means that local supervisors cannot carry risks created by design, staffing, budget, or production decisions alone.
  4. 04Emergency planning is part of prevention because credible consequence management exposes whether the organization understands its hazard before an event occurs.
  5. 05Leaders can apply the Bhopal lesson by tracing one major-hazard scenario from source inventory to field control, senior decision, emergency response, and community communication.

On December 3, 1984, a toxic release at the Union Carbide India Limited pesticide plant in Bhopal became one of the defining cases in modern process-safety history. The immediate event involved methyl isocyanate, but the risk-management lesson is broader. A hazardous inventory can sit inside a system where ownership is fragmented, warnings lose authority, and the emergency plan is disconnected from the people who may be exposed.

This case study argues that Bhopal was not simply a failure at the final valve or the final shift. It was a failure to keep hazard knowledge, equipment condition, operating limits, maintenance choices, emergency readiness, and community accountability inside one decision system. That distinction matters because a leader who treats the case as a narrow equipment lesson can repeat the same structural weakness with a different substance.

What was the initial risk-management condition?

The Bhopal plant handled a highly hazardous intermediate whose behavior required disciplined storage, cooling, contamination prevention, instrumentation, maintenance, and emergency response. The Government of India and the Supreme Court of India records describe the event and its consequences within a wider dispute about corporate responsibility, site conditions, and the adequacy of the response.

The point for today’s risk owner is not to reduce the case to one disputed statistic. The point is that the site had multiple opportunities to recognize that the consequence of a release could extend beyond the process boundary, while the controls needed to prevent or limit that release depended on decisions made across operations, maintenance, engineering, management, and public authorities.

James Reason’s work on latent failures helps explain why the last visible action is rarely a complete account of a major accident. A control can be weakened long before the event through design assumptions, reduced staffing, deferred maintenance, poor information, or a management decision that makes the safe operating limit difficult to maintain. Bhopal makes that connection visible without excusing the people who were exposed to the hazard.

What decision should leaders have made earlier?

The key decision was to treat the hazardous inventory as an executive risk, not only as a production asset. That decision would have required a named owner for the inventory, a clear maximum operating condition, evidence that critical barriers were available, and an escalation route for any situation in which the plant could not maintain those conditions.

Risk ownership is different from assigning a task. A maintenance supervisor can own a work order, yet lack authority to stop production, fund replacement equipment, or change the storage strategy. The person who owns the risk must have the authority to accept, reduce, transfer, or stop the exposure. Otherwise, the organization has a name beside the risk but no real decision behind it.

Andreza Araujo’s work on safety culture and leadership consistently returns to this operating question. Does the organization’s stated priority change the decision when production, cost, and safety compete in the same meeting? If the answer is no, the culture statement has not reached the control system.

How did the execution gap appear in the field?

Major-hazard controls fail in combinations. A refrigeration system, scrubber, flare, alarm, inspection routine, or emergency procedure may each appear in a document, while the combined system is unable to perform under the actual condition. That is why the Bhopal case should be read as a barrier-management case rather than as a search for one defective component.

The control-reliability review on this blog uses four practical questions that fit this case. What is the barrier supposed to do? What evidence shows that it can do it now? Who responds when the evidence is missing? What decision changes while the barrier is unavailable? A risk register that cannot answer those questions is an inventory of concerns, not a control system.

The same logic applies to staffing and competence. A procedure may assume that operators recognize contamination, abnormal pressure, or an unexpected temperature change, yet the operating model may not provide enough people, time, training, or authority to act on that recognition. A warning that cannot trigger a decision is only information waiting to be ignored.

What was the measured result of the failure?

The result was not limited to the release itself. The case exposed how a process event can become a community emergency when consequence planning, public information, medical readiness, and accountability do not connect to the hazard before the event. The lasting result was a change in how governments, companies, and safety professionals discuss major-accident prevention and emergency preparedness.

The International Labour Organization’s guidance on major industrial accidents and the United Nations Environment Programme’s awareness and preparedness work both reflect the same governance lesson. Communities need credible information, authorities need usable emergency assumptions, and operators need controls whose condition can be demonstrated before a release occurs. The public boundary is part of the risk boundary.

Risk-management layerWeak condition exposed by the caseDecision-grade condition
Hazard knowledgeInformation is held by specialists or buried in documents.The hazardous source, credible scenarios, and operating limits are understood by the people who make daily decisions.
Barrier conditionEquipment and procedures are treated as present because they exist on a list.Availability, performance, impairment, and restoration are visible to the accountable leader.
EscalationLocal staff absorb risk created by resource or design decisions.Unacceptable exposure moves quickly to the leader with authority to change work.
Emergency readinessThe plan assumes response capacity that has not been tested with the community.Scenarios, communication, medical response, and public protection are exercised against field conditions.

Which generalizable lessons should leaders retain?

The first lesson is that storage strategy is a safety decision. Keeping a hazardous intermediate on site may be operationally convenient, but it creates a persistent exposure that needs stronger safeguards, monitoring, emergency capacity, and executive attention than a simple production-flow diagram suggests.

The second lesson is that deferred maintenance changes risk even when production continues. A barrier that is unavailable, degraded, or bypassed should change the operating condition, not merely create a note in a maintenance system. The responsible leader must define the temporary limit and the deadline for restoration.

The third lesson is that emergency planning tests prevention quality. If a site cannot explain who will detect the release, who will authorize shutdown, who will warn the public, and how vulnerable people will be protected, it has not fully understood the consequence it claims to manage.

The fourth lesson is that safety culture is visible in the treatment of bad news. When warnings are softened to preserve production confidence, the organization loses the evidence needed for earlier intervention. A mature risk conversation gives inconvenient information a path to action.

The fifth lesson is that accountability must cross organizational boundaries. Corporate leadership, site management, engineering, maintenance, emergency services, and regulators may hold different pieces of the risk, but the exposed worker and community experience one consequence. The management system must connect those pieces before the event.

How can a site apply the Bhopal lesson now?

Choose one credible major-hazard scenario that includes a hazardous source, a credible initiating condition, several barriers, and a consequence outside the immediate work area. Do not start with the easiest scenario. Start with the one whose failure would require decisions beyond the shift supervisor.

Then trace the scenario through six questions. Who knows the hazard? Which barrier prevents the release? Which barrier limits the consequence? What evidence confirms each barrier today? Who decides when a barrier is impaired? Which external people need timely information? The answers should come from operators, maintainers, engineers, emergency responders, and senior leaders, because a document review alone will miss the handoffs.

Use the risk-matrix review to challenge whether the scenario is being made to look acceptable through vague likelihood language, optimistic control assumptions, or a consequence boundary that stops at the fence. A credible risk picture should make the decision harder when evidence is weak, not easier because the worksheet is complete.

Finally, publish the ownership map internally. It should show the risk, the barrier, the evidence, the impairment response, the decision authority, and the verification date. When any one of those fields is blank, the site has identified a management gap that deserves attention before the next operating cycle.

What should the executive review ask next?

An executive review should ask whether the organization can demonstrate control performance under the conditions that actually exist. It should ask which major-hazard barriers are impaired, how long they have been impaired, who accepted the temporary condition, and what protection exists while restoration is delayed.

It should also ask whether the emergency plan has been tested with the people who would receive the warning, provide medical care, close roads, protect vulnerable neighbors, and communicate uncertainty. A plan that works only inside the plant’s assumptions is not a complete community-protection plan.

The Bhopal case still matters because it turns an abstract leadership question into a concrete one. When a hazardous process is operating outside its intended control condition, who has the authority to stop it, and what evidence proves that the decision was made before harm occurred?

That is the risk-management standard worth carrying forward. The control is not the procedure, the audit score, or the risk-register entry. The control is the decision system that keeps a credible hazard visible, owned, verified, and acted upon while there is still time to change the outcome.

Topics risk-management bhopal process-safety major-hazard-risk barrier-verification risk-ownership emergency-planning headline-podcast

Frequently asked questions

What did the Bhopal disaster teach about risk management?
Bhopal showed that major-hazard risk cannot be managed through isolated procedures. Hazard information, equipment condition, operating discipline, staffing, emergency response, and public communication must connect through explicit ownership and verification.
Why is Bhopal relevant to process safety today?
The case remains relevant because organizations still manage hazardous inventories, temporary operating conditions, deferred maintenance, contractor interfaces, and emergency plans that can look complete on paper while remaining weak in the field.
What is unowned process risk?
Unowned process risk is a credible hazardous condition for which no accountable decision-maker has accepted responsibility for the operating limit, control performance, resources, escalation, and consequence if the control fails.
How should leaders verify a major-hazard barrier?
Leaders should identify the barrier, its required performance, the evidence that confirms availability, the person who can authorize work when it is unavailable, and the deadline for restoration. Verification should include field evidence rather than document review alone.
How can a smaller site apply the Bhopal lesson?
A smaller site can choose one credible major-hazard scenario, map the hazardous source and barriers, interview the people who operate and maintain them, test emergency assumptions, and assign unresolved gaps to leaders who control the required resources.

About the author

Andreza Araújo

Safety Culture Expert | Senior EHS Executive

Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.

  • Civil & Safety Engineer (Unicamp)
  • M.A. Environmental Diplomacy (University of Geneva)
  • Sustainability Cert (IMD Switzerland)
  • People Management & Coaching (Ohio University)
  • UN Paris speaker representative for Brazil
  • ILO Turin speaker
  • LinkedIn Top Voice
  • Indra Nooyi PepsiCo CEO recognition (2x)

Documentaries

Watch Andreza's documentaries

Three productions on safety culture, organizational failure and the human lessons behind major disasters.

Podcasts

Listen to Andreza's podcasts

She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.

Summarize with AI