Risk Management

How Corrie Pitzer Thinks About Verification After Risk Controls Are Chosen

Episode 9 with Corrie Pitzer reframes risk competence as the ability to verify whether a chosen control still matches the work, rather than treating a signed procedure as proof that exposure is managed.

By 6 min read
risk management scene on how corrie pitzer thinks about verification after risk controls are chosen — How Corrie Pitzer Think

Key takeaways

  1. 01Risk competence continues after a control is selected because the work can change faster than the procedure.
  2. 02Verification should test whether the barrier exists, is usable, and still addresses the exposure that drove the decision.
  3. 03A signed assessment records a decision, but it does not prove that the decision remains valid at the point of work.
  4. 04Leaders should create a challenge route that can reopen a control decision without making the person who raises the concern the problem.
  5. 05Use Episode 9 with Corrie Pitzer to redesign one verification routine during the next 30-day operating cycle.

Episode 9 with Corrie Pitzer was published on November 6, 2025, and examined risk competence, control reliance, and the quality of safety decisions. Corrie Pitzer’s central thesis was that choosing a control is only one part of competence because the decision must still be tested against the work that actually unfolds.

That distinction matters whenever a risk assessment is signed before the shift begins, then treated as settled even though the equipment, people, sequence, or production pressure changes. A control can be technically correct and operationally weak at the same time. The question for leaders is not whether the procedure exists, but whether the barrier can still perform when the exposure appears.

Risk competence continues after the decision

Risk competence is the ability to identify exposure, choose proportionate controls, and keep testing whether those controls remain suitable as conditions change.

A procedure often receives its strongest attention before work starts. The team reviews the hazard, assigns responsibilities, and records approval. Those steps are necessary because they create a shared decision. They become misleading when approval is treated as evidence that the control has already worked.

Corrie Pitzer’s Episode 9 argument moves the center of risk management from paperwork to judgment in use. A competent leader can explain what the control is meant to prevent, what would make it unreliable, and who has authority to change the plan when the original assumptions no longer hold.

James Reason’s distinction between active and latent failures supports this approach. A field deviation may be visible at the point of work, while the conditions that allowed it to persist were built into planning, design, maintenance, supervision, or resource decisions made earlier.

Why control selection and control verification are different

Control selection answers what should protect the work, while control verification tests whether that protection is present, usable, and connected to the exposure it was chosen to address.

The difference can be seen in a lifting operation. A plan may specify an exclusion zone, a competent signaler, and a verified lifting accessory. Verification asks whether the zone is actually respected, whether the signaler can see the load path, whether the accessory identification is legible, and whether the work sequence has introduced a new interaction.

A completed form may confirm that someone considered those issues. It cannot confirm that the barrier survived contact with the task. A manager who wants reliable evidence therefore looks for observable conditions rather than completion alone.

Use the risk competence explanation to separate awareness from control, then apply the distinction to one task whose safeguards are routinely assumed rather than checked.

The signed procedure can create false confidence

A signed procedure creates false confidence when approval becomes the endpoint of thinking, because the team stops asking whether the work still resembles the scenario that was assessed.

Consider a maintenance task that begins with a known isolation boundary. During the first hour, a production interruption changes the sequence, a contractor arrives late, and a temporary access route is opened. The document remains accurate about the original plan, yet the risk picture has moved.

The danger is not the signature itself. The danger is the meaning attached to it. If a signature means “the decision is now closed,” people may hesitate to challenge the plan because reopening it feels like admitting incompetence or creating delay.

In more than 250 cultural transformation projects supported by Andreza Araujo, the practical question is always where responsibility appears in the routine. The person who signs a decision may not be the person who can see the control degrade, so the system must give the field a clear route to escalate and reset.

What verification should look for at the point of work

A field verification should connect the intended control to four observable questions about availability, usability, performance, and ownership.

Decision evidenceVerification evidenceLeadership question
The control is listed in the assessment.The control is present where the task occurs.Can the worker reach and use it without creating another exposure?
The responsibility is assigned.The responsible person can explain the boundary.Does that person have authority to stop or redesign the work?
The method is approved.The method matches the actual sequence.What changed since approval, and who noticed it?
The action is closed.The risk is reduced in the field.What evidence shows that closure changed the condition?

The four questions are deliberately ordinary because a verification method that only specialists can use will miss the moment when a control starts to fail. Supervisors should be able to describe the expected barrier in plain language, and workers should be able to challenge it without translating their concern into audit terminology.

A strong verification record names the exposure, the control, the evidence observed, the gap found, and the decision owner. It also records whether the task continued under an interim measure, stopped, or changed. That detail turns an observation into governance.

How leaders should respond to a weak control

When verification finds a weak control, leaders should protect the work first, assign a decision owner second, and decide whether the original risk assessment remains valid third.

The order matters. A team should not be asked to complete a long explanation while the exposure remains open. Interim protection may involve stopping the task, isolating the area, changing the sequence, adding competent supervision, or replacing a failed barrier with a stronger one.

The next decision belongs to the person who controls the condition, not automatically to the EHS professional who found it. Engineering may own a design weakness, operations may own a production conflict, maintenance may own an overdue repair, and the contract owner may own a supplier-control failure.

Andreza Araujo’s experience across 25+ years of executive EHS work points to a useful test. If the response depends on one safety professional repeatedly rescuing the operation, the organization has not built control ownership. It has built a dependency.

When challenge should reopen the assessment

Challenge should reopen a risk assessment when the exposure, control, people, sequence, or operating assumptions change enough that the original decision can no longer be trusted without fresh evidence.

Define the triggers before the task begins. A change in energy source, access, equipment condition, contractor scope, weather, staffing, simultaneous work, or emergency arrangement may require a new decision. The trigger list does not need to predict every variation. It needs to make the boundary visible.

Leaders should also make challenge socially safe. A worker who says, “This control is not available here,” is supplying decision-quality information, not refusing responsibility. The response should test the claim, protect the work, and report back. It should not turn the reporter into the subject of the review.

Use the risk acceptance tests when a manager is tempted to keep a signed decision in place because changing it would affect schedule, cost, or output. A decision that cannot survive a clear challenge route is not a strong decision.

What a 30-day verification reset can change

A 30-day reset can reveal whether the organization is verifying controls or merely recording that controls were selected.

During days 1 through 5, choose one critical control and define the exposure it is meant to address. During days 6 through 14, observe it in at least three different operating conditions, including one period of production pressure or abnormal work. During days 15 through 21, compare the design assumption with the field evidence and name the owner for every gap.

Use days 22 through 30 to decide whether the control should be strengthened, redesigned, replaced, or accepted with a documented reason and review date. The point is not to create another campaign. It is to give leaders a short cycle in which the quality of a decision becomes visible.

Track five pieces of evidence: the number of verifications completed, the number that found a meaningful gap, the time to protect the work, the time to assign an owner, and the number of repeated gaps. These are not proof of safety by themselves. They show whether the organization can see and act on control weakness before the consequence arrives.

The critical-control dashboard guide explains why leaders should read these signals beside field evidence instead of treating a clean status indicator as a finished answer.

Recommendation

Select one control connected to a serious exposure, then ask the people who use it to demonstrate how it works under normal, changed, and pressured conditions. Complete the first observation within 5 working days, assign every gap to a named owner, and set a review at 30 days.

Publish the decision to the team that supplied the evidence. Explain what changed, what did not change, and what would cause the assessment to reopen. This closes the information loop that separates genuine competence from procedural confidence.

Conclusion

Corrie Pitzer’s Episode 9 argument gives risk management a demanding but practical standard. A control is not validated because it appears in a procedure, receives a signature, or survives an audit question. It is validated when the people doing the work can use it, challenge it, and show that it still addresses the exposure that made the control necessary.

Listen to the full conversation with Corrie Pitzer on Episode 9, then choose one control whose reliability is currently assumed. Verification is where the decision becomes real.

Continue the conversation about leadership, safety, and better workplaces with the Headline Podcast.

Explore Headline Podcast
Topics headline-podcast episode-companion corrie-pitzer risk-management risk-competence control-verification decision-quality

Frequently asked questions

What is Corrie Pitzer's main point about risk competence?
Corrie Pitzer's position in Episode 9 is that competence is not only the ability to identify a hazard or select a control. It also includes the judgment to test whether the control still fits the work, the conditions, and the exposure when the task is actually performed.
Why is a signed risk assessment not enough?
A signed assessment shows that someone made a decision at a particular time. It does not show that the field condition, equipment, staffing, sequence, or control performance still matches the assumptions behind that decision.
What should a control-verification check include?
A useful check asks what exposure the control addresses, what evidence shows that it is available and usable, who owns correction when it is weak, and what change would require the decision to be reopened.
How often should leaders verify a risk control?
The cadence should follow the speed at which the exposure or control can change. A 30-day review can reveal recurring drift, while high-consequence work may require verification at the start of each task, shift, or change in condition.
What should an EHS manager do after listening to Episode 9?
Select one critical control, observe it in the field, compare its design with its use, and document the decision owner, the evidence, and the trigger that would reopen the risk assessment.

About the author

Andreza Araújo

Safety Culture Expert | Senior EHS Executive

Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.

  • Civil & Safety Engineer (Unicamp)
  • M.A. Environmental Diplomacy (University of Geneva)
  • Sustainability Cert (IMD Switzerland)
  • People Management & Coaching (Ohio University)
  • UN Paris speaker representative for Brazil
  • ILO Turin speaker
  • LinkedIn Top Voice
  • Indra Nooyi PepsiCo CEO recognition (2x)

Documentaries

Watch Andreza's documentaries

Three productions on safety culture, organizational failure and the human lessons behind major disasters.

Podcasts

Listen to Andreza's podcasts

She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.

Summarize with AI