How to Build a Risk-Based Inspection Route for a Small Plant in 21 Days
A risk-based inspection route helps a small plant spend field time where exposure and control uncertainty are highest. This 21-day guide shows EHS leaders and supervisors how to build a route that produces decisions rather than another calendar of routine walks.

Key takeaways
- 01A risk-based inspection route should follow serious exposure and uncertainty, not simply repeat the same walk on the same day.
- 02The route becomes useful when each visit has a defined question, observable evidence, and a decision owner.
- 03Small plants can start without complex software by combining a simple exposure register with disciplined field verification.
- 04Inspection frequency should change when work, controls, equipment, staffing, or recent evidence changes the risk picture.
F2 how-to guide for small-plant EHS leaders, supervisors, and maintenance managers
A small plant often has enough inspection activity and still lacks a clear answer to a basic question. Which area deserves the next field check because the consequence could be serious and the control may not work as expected?
A risk-based inspection route turns that question into a repeatable operating process. It does not mean ignoring housekeeping, legal checks, or equipment schedules. It means adding a second layer that directs attention toward serious exposure, control uncertainty, recent change, and evidence that the work is drifting away from the intended condition.
James Reason’s distinction between active and latent failures is useful here because an unsafe condition may be visible in the work while the decision that allowed it to persist sits in planning, maintenance, procurement, or supervision. Andreza Araujo’s Safety Culture: From Theory to Practice makes a related point about the difference between declared standards and the decisions people experience in daily work. Your route should test that difference in the field.
What you need before starting
Gather the plant layout, task list, process changes from the last quarter, maintenance backlog, incident and near-miss records, authorization records, chemical inventory, contractor activities, and any existing inspection checklist. You do not need a new software system to begin. A shared table with an exposure, control, evidence, owner, and review date is enough for the first cycle.
Choose one person who understands the work and one person who can assign or escalate a decision. If the same person fills both roles, bring a second reviewer for tasks where production pressure may influence the judgment.
Step 1: Map the work that can cause serious harm
List tasks and conditions that could produce a fatality, life-changing injury, major release, fire, explosion, or severe occupational exposure. Include non-routine maintenance, energy isolation, work at height, confined spaces, vehicle movements, lifting, chemical transfer, temporary changes, and contractor interfaces when they exist.
Verify the map with a supervisor and a worker who performs the task, because the written process may omit an awkward step or interruption that changes the control. The common error is treating every department as equally important simply because every department receives the same number of visits.
Step 2: Separate exposure from inspection activity
For each exposure, write the control that should prevent the event or reduce its consequence. Then write the evidence that would show the control is present, available, and usable at the point of work.
| Exposure | Expected control | Evidence to seek |
|---|---|---|
| Unexpected energization | Isolation and verification | Isolation points, identification, and tested zero energy |
| Vehicle and pedestrian interaction | Separation and movement control | Physical route, crossing rules, visibility, and observation |
| Chemical transfer | Compatible equipment and response | Connection condition, labeling, containment, and readiness |
| Work at height | Suitable access and fall protection | Equipment condition, anchorage, rescue plan, and setup |
The common error is recording “inspection completed” without recording what was tested. A visit is an activity. Evidence is what makes the activity useful.
Step 3: Rank the route by consequence and uncertainty
Use three questions. How severe could the outcome be? How uncertain is the control in actual work? How recently has the task or condition changed? A task with high consequence and high uncertainty belongs near the start of the route, even if no recent injury has occurred.
Use the plant’s existing risk language, but keep the decision visible. A red, amber, and green label is acceptable when each label has a written meaning. The label is not the conclusion. It is a prompt for what the inspector must verify next.
Review the route alongside the plant’s barrier-health tests and its weekly work-plan risk register.
Step 4: Choose one field question for each stop
Every stop should answer one primary question. Can the isolation be verified before the guard is opened? Can pedestrians remain outside the vehicle path during the busiest movement period? Can a worker summon help without leaving the task exposed?
Write the question before the inspection begins. This prevents the reviewer from wandering through visible details while missing the control that matters. Replace “Is the area safe?” with a condition that can be seen, tested, or confirmed through a credible record.
Step 5: Set the route frequency from evidence
Assign each stop a provisional frequency for the first 21 days. High-consequence tasks with uncertain controls may need a check on each relevant shift or work window. Stable, well-controlled conditions may need less frequent focused review, while routine legal and maintenance checks continue on their own schedule.
Make the frequency sensitive to change. A new contractor, altered production rate, equipment modification, staffing gap, repeat near miss, or overdue action should move a stop closer in the route. A frequency that never changes is a calendar, not a risk-based system. Keep a link to the plant’s risk register and decision log.
Step 6: Test the control under ordinary pressure
Visit the task when the work is actually being performed, including a handover, changeover, delivery window, interruption, or maintenance constraint when those conditions are normal for the plant. Do not ask people to create danger or bypass protection. Observe how the control behaves under routine pressure.
Ask the worker what happens when the expected condition is missing. The answer may show that the control is physical and dependable, or that it depends on memory, a supervisor’s presence, or a difficult-to-access document. Record the dependency because it changes the strength of the control.
Step 7: Convert findings into an owned decision
For each finding, decide whether the work can continue, must pause, needs a temporary safeguard, requires engineering review, or needs a change to the route. Give the decision to an owner who has authority over the condition, not merely the person who noticed it.
Describe the action so it can be verified. “Improve awareness” is not a control action. “Install a physical pedestrian barrier at the loading-bay crossing and verify its use during the next two delivery windows” is specific enough to test. The common error is assigning every action to EHS when operations, maintenance, engineering, procurement, or contractor management owns the change.
Step 8: Revisit the route after the first cycle
At the end of 21 days, compare the original route with the field evidence. Which high-consequence controls were repeatedly available? Which findings returned? Which tasks generated uncertainty that the original map did not show? Use those answers to change the route rather than simply closing the first cycle.
Remove a stop only when the reason is documented and another control continues to cover the exposure. Add a stop when the work has changed, when an action has not reduced the condition, or when workers identify a credible failure mode that was absent from the original map.
What should the final route contain?
The final route should identify the exposure, expected control, field question, evidence standard, reviewer, frequency, escalation trigger, action owner, and next verification date for every focused stop.
- Exposure and possible consequence
- Expected control and observable evidence
- Primary field question
- Location, task, shift, or work window
- Review frequency and change triggers
- Decision authority and escalation path
- Action owner and verification date
A route earns credibility when it changes what the plant checks and what leaders decide. That is the practical difference between a risk-based inspection process and a recurring walk whose completion is mistaken for control.
For a broader leadership lens, compare the route with frontline risk escalation. The inspection is only valuable when the organization can act on what it finds.
Frequently asked questions
Can a small plant use this method without a dedicated EHS analyst? Yes. A supervisor, maintenance representative, and worker can build the first route with a shared table, provided the plant gives them time to review evidence and authority to escalate unresolved exposure.
Should every inspection produce a corrective action? No. A credible inspection can confirm that a control is working, identify a condition that needs monitoring, or trigger a decision to pause or redesign the work. The result should be explicit and reproducible.
What if the plant has too many exposures to inspect? Start with tasks that combine severe possible consequence with uncertainty, recent change, or weak evidence. Expand the route after the first cycle rather than creating a schedule that no one can execute.
How should leaders measure whether the route works? Review whether focused questions are answered with credible evidence, whether owners close decisions at the agreed level, whether repeat findings reduce, and whether route frequency changes when exposure changes. Counting visits alone is not enough.
Frequently asked questions
What is a risk-based inspection route?
How often should a small plant update its inspection route?
Does a risk-based route replace routine inspections?
What should an inspector record?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.