How to Run a 20-Minute Control-Health Review When a Critical Barrier Is Unavailable
A short field-ready method for EHS managers, supervisors, and control owners who must decide whether work can continue when a safety-critical barrier is unavailable. The review defines the exposure, tests a temporary control, assigns decision rights, and sets a recovery condition before the exception becomes routine.
Key takeaways
- 01A critical barrier review is a decision gate, not a discussion about how to keep the schedule moving.
- 02The team must define the remaining exposure and verify whether the barrier is truly unavailable.
- 03A temporary control must change the exposure, be tested in the field, and have a named owner.
- 04Every exception needs an expiry time and recovery evidence so the temporary arrangement does not become normal practice.
- 05Work should resume only after the crew can explain the control, stop trigger, and restoration condition.
F2 how-to guide for EHS managers, control owners, and frontline supervisors
A critical barrier is unavailable when a safeguard that the work plan depends on cannot be confirmed, operated, tested, or maintained in its intended condition. The correct response is not to keep the schedule moving while someone searches for a workaround. It is to run a short decision review that makes the exposure, temporary controls, authority, and restart conditions explicit.
This guide shows how to run that review in twenty minutes. It is designed for the moment when a trip system is bypassed, a guard is removed, a gas detector is out of service, an isolation cannot be verified, or another safety-critical control no longer has the health assumed by the task plan.
Why an unavailable barrier needs a decision gate
A control can exist in a procedure and still be unavailable in the field. The distinction matters because a signed risk assessment may describe a protection layer whose test is overdue, whose owner is absent, or whose operating boundary changed during the job.
ISO 45001:2018 expects organizations to control planned changes, operational risks, and outsourced work, while James Reason's work on latent failures explains why the visible deviation is often shaped by earlier decisions about design, planning, maintenance, and supervision. The review therefore asks more than whether a replacement control was named. It asks whether the new arrangement can be verified by the people who must rely on it.
Use the four tests for barrier health as a reference point, then connect the result to the decision rights that keep critical risk owned. A barrier review is useful only when it produces an owner, a time boundary, and a decision that the crew can act on.
Step 1: State the unavailable barrier precisely
Name the barrier in operational terms. Do not write “safety system unavailable” when the actual condition is that a fixed gas detector is awaiting calibration, a relief path is blocked, or a machine guard cannot be refitted before the task starts. Precision keeps the discussion tied to a physical exposure.
Record what the barrier should prevent, which task depends on it, and whether the failure is total or partial. A control that protects one operating mode may remain usable for another, although that distinction must be verified rather than assumed by the person who wants to continue.
Step 2: Define the exposure that remains
Describe the credible unwanted event and the people, equipment, or environment that could be affected. Keep the statement specific enough to guide a decision, such as unexpected energization during maintenance, ignition in a classified area, or loss of detection before entry.
Ask what changes when the barrier is absent. The answer may include a larger exclusion zone, a different work sequence, a shorter exposure window, a second isolation, or a requirement to stop the task. The review should not use a risk matrix as a substitute for explaining how the exposure behaves in the actual work area.
Step 3: Check whether the barrier is truly unavailable
Verify the condition at the work face or at the relevant system. Check the test record, physical position, alarm status, isolation point, inspection label, calibration date, or maintenance status that supports the claim. If the evidence is incomplete, treat the barrier as unverified until the responsible technical role confirms it.
Separate an unavailable control from a control that is merely difficult to access. A supervisor may be able to restore a guard, obtain a calibrated instrument, or complete a test within the same shift, which creates a recovery action rather than a permanent replacement. The evidence should show what is known, what is uncertain, and who can close the uncertainty.
Step 4: Select a temporary control that changes exposure
Choose a control that interrupts the exposure or reduces the opportunity for the event. Examples include isolating and locking out the affected system, suspending simultaneous operations, assigning an independent spotter, installing a physical exclusion, changing the sequence, or postponing the work until the original barrier is restored.
Do not accept a verbal reminder, a poster, or a general instruction to “take extra care” as the main temporary control. Those actions may support a plan, but they do not replace a barrier whose function was to prevent access, energy release, ignition, or loss of containment.
Step 5: Test the temporary control in the field
Ask the control owner to demonstrate how the temporary arrangement works. The crew should be able to identify the boundary, explain the stop condition, and show where the control is installed or how it will be maintained. A control that exists only in the meeting record has not yet become an operating control.
Use a short field walk when the risk depends on location, visibility, access, or equipment state. The critical-control walkdown method is useful here because it forces the review to compare the planned protection with the work as it is actually configured.
Step 6: Assign decision rights and escalation
Name the person who can authorize the temporary arrangement, the person who verifies it, and the person who can stop the work when its condition changes. These roles may belong to different people, particularly when a contractor, area authority, permit issuer, and maintenance supervisor share the work boundary.
Set the escalation route before the task continues. If the temporary control fails, the crew should know whether to stop the job, isolate the area, call the control owner, or raise the decision to a higher level. Ambiguous escalation creates delay at the exact moment when delay is safer than improvisation.
Step 7: Set a time boundary and recovery condition
Write when the temporary control expires and what must be true before the original work plan resumes. “Until fixed” is too vague because it does not identify a responsible owner, a verification point, or a decision date.
A useful recovery condition describes the evidence required, such as a completed function test, an installed guard that passes inspection, a closed isolation verification, or a replacement instrument with a current calibration record. If the repair will not be completed within the agreed window, reopen the decision rather than allowing the temporary arrangement to become normal practice.
Step 8: Close the review with a crew-level confirmation
Before work resumes, ask the people who will perform the task to repeat the unavailable barrier, the temporary control, the stop trigger, and the recovery condition in their own words. This check reveals whether the decision was communicated clearly enough for the work face, which is different from collecting signatures.
Record the decision in the work package, permit, or control register that the next supervisor will use. Include the owner, expiry time, verification evidence, and unresolved question. A later weekly critical-control review can examine repeated barrier unavailability, but it must not be used to postpone the immediate decision to control today's exposure.
What a good twenty-minute review produces
A good review leaves the team with five visible answers. The unavailable barrier is named, the remaining exposure is understood, the temporary control has been tested, decision rights are clear, and the recovery condition has an owner and a deadline. If one of those answers is missing, the meeting has described the problem without controlling it.
The practical test is simple. Can the supervisor point to the control, can the crew explain when to stop, and can the owner show what evidence will restore the original protection? If the answer is no, the task is not ready to continue under the proposed arrangement.
Final checklist before work continues
- The unavailable barrier and affected task are stated precisely.
- The credible exposure and affected people are identified.
- The barrier condition is supported by field or system evidence.
- The temporary control changes exposure and has been tested.
- The authorizer, verifier, stop-work role, and escalation path are named.
- The expiry time and recovery evidence are recorded.
- The crew can repeat the decision in their own words.
A critical barrier review should make work safer, not make an exception easier to hide. When a safety-critical control is unavailable, the responsible decision is to define the exposure, install a verified temporary control, and restore the original protection before the exception becomes routine.
For more practical conversations about leadership, risk, and safer workplaces, visit Headline Podcast and bring the next operational question to the table.
Frequently asked questions
What is a critical barrier review?
Who should attend the review?
Can a procedure or toolbox talk replace an unavailable barrier?
How long should the review take?
When can work resume after a barrier is restored?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.