Risk Management

How to Run a Safety Pre-Mortem Before a Production Change in 9 Steps

A safety pre-mortem helps production, maintenance, and EHS teams identify how a planned change could fail before the new condition reaches the first shift.

By 6 min read
industrial production change review with supervisors and EHS leaders around a safety pre-mortem plan

Key takeaways

  1. 01A safety pre-mortem tests the planned operating condition before production, maintenance, or commissioning begins.
  2. 02The strongest session includes people who will execute, supervise, maintain, and respond to the changed work.
  3. 03Each concern needs an owner, a verification method, and a decision deadline rather than a vague promise to monitor it.
  4. 04The session should examine interfaces, temporary controls, workload, competence, emergency response, and conditions that can change after approval.
  5. 05A production change is ready only when the remaining uncertainty is visible and someone has authority to stop the start-up.

A production change can be approved, scheduled, and staffed while its most important failure path remains unnamed. The team may have reviewed the method statement, discussed the deadline, and signed the change record, yet nobody has asked how the new condition could defeat a critical control during the first shift.

A safety pre-mortem closes that gap before work starts. The team assumes that the change has already failed, then works backward to identify the decision, interface, condition, or missing verification that made failure possible. This is not a prediction exercise. It is a disciplined way to turn uncertainty into named actions.

Key takeaways

  • A safety pre-mortem tests the planned operating condition before production, maintenance, or commissioning begins.
  • The strongest session includes people who will execute, supervise, maintain, and respond to the changed work.
  • Each concern needs an owner, a verification method, and a decision deadline rather than a vague promise to monitor it.
  • The session should examine interfaces, temporary controls, workload, competence, emergency response, and conditions that can change after approval.
  • A production change is ready only when the remaining uncertainty is visible and someone has authority to stop the start-up.

What you need before starting

Bring the change description, the current process, the proposed process, relevant permits, equipment information, staffing assumptions, emergency arrangements, and the latest field constraints. The purpose is not to create a larger file. It is to make the changed condition concrete enough that the team can challenge it.

Invite the change owner, an operations supervisor, a maintenance representative, an EHS professional, and at least one person who will perform the work. Add a contractor lead, engineer, or emergency coordinator when the change affects their responsibilities. Across 25+ years of executive EHS work and more than 250 cultural transformation projects, Andreza Araujo has repeatedly seen that the person closest to the changed task notices a weakness that a review group can otherwise miss.

ISO 45001:2018 is useful as a management-system anchor because it requires organizations to control changes that can affect occupational health and safety. The pre-mortem adds a practical decision routine that helps the team test whether the planned control can survive contact with the work.

Step 1: State the change in operating terms

Write one sentence that describes what will be different in the work area. Name the equipment, task, people, sequence, location, and time window that will change. Avoid a sentence such as “improve line capacity,” because it hides the conditions that workers must actually control.

Use a statement such as “During the Saturday shutdown, the maintenance crew will replace the transfer pump while production operates on the parallel line.” The sentence should make interfaces visible. If the group cannot agree on what is changing, it is too early to discuss whether the change is safe.

Step 2: Define what failure would look like

Ask the group to complete this sentence: “The change has failed because…” Accept operational outcomes rather than abstract labels. Examples include an unexpected release, a person entering an exclusion zone, a control room receiving the wrong status, a rescue team arriving without the required equipment, or a restart occurring before a guard is restored.

James Reason’s work on latent conditions helps keep this discussion useful. The last visible event is rarely the whole story, so the team should describe both the immediate failure and the conditions that allowed it to develop.

Step 3: Map the interfaces that can pass risk forward

List every handoff between operations, maintenance, engineering, contractors, logistics, control room staff, and emergency responders. For each interface, ask what one group believes the other group has checked.

Risk often moves through an interface because responsibility sounds clear in a meeting but becomes ambiguous in the field. Record who gives the release, who confirms isolation, who controls access, who communicates a change in scope, and who can stop the work when the original assumption no longer holds.

Step 4: Identify the controls that must survive the change

Separate controls that prevent the unwanted event from controls that limit its consequences. Then identify which controls are permanent, which are temporary, and which depend on a person noticing a deviation at the right moment.

A checklist is not enough if it does not identify the control that protects people from the changed exposure. The team should be able to point to the physical barrier, isolation, permit condition, competence requirement, supervision practice, or emergency arrangement that must remain effective.

Step 5: Ask what assumption is most likely to be wrong

Write down the assumptions that make the change appear ready. Typical assumptions include equipment availability, contractor competence, access to a spare part, stable weather, adequate staffing, correct drawings, reliable communication, or enough time to test before production resumes.

For each assumption, ask how it will be tested before the first hazardous task. If an assumption cannot be checked, convert it into a condition of work or a stop trigger. A statement that the team “expects” a condition to hold is not a control.

Step 6: Test the first shift, not the ideal process

Walk through the first shift in sequence. Include the start-up, the most demanding task, the likely delay, the shift change, the break period, and the moment when production pressure is highest. Ask what happens if the plan is late, a person is absent, equipment behaves differently, or the work takes longer than expected.

This step exposes the difference between a safe method and a workable method. A control that requires uninterrupted attention for six hours may be technically sound and operationally fragile when the crew must also manage alarms, deliveries, and competing work.

Step 7: Rehearse the emergency decision

Choose the most credible serious event and ask the team to describe the first five decisions. Who raises the alarm, who stops the work, who isolates the energy, who accounts for people, who contacts external support, and who has authority to change the response when conditions worsen?

Do not accept “the emergency plan covers it” as an answer. The group needs to name the person, communication path, equipment, access route, and decision point that will exist in the changed condition. If any of those is unknown, assign a pre-start action.

Step 8: Convert concerns into hold points

Turn each material concern into a hold point with four fields: the condition that must be true, the person who verifies it, the evidence required, and the authority that decides whether work can proceed.

For example, “confirm the temporary barrier” is weak because it does not say what good looks like. “The area supervisor verifies the barrier, access gate, signage, and exclusion distance before the first lift, and records the result on the change permit” is specific enough to govern a decision.

Step 9: Set the start, stop, and review decisions

End the session by separating three decisions. The start decision states what must be complete before work begins. The stop decision states which change in condition suspends the work. The review decision states when the team will check whether the controls worked after the first operating period.

Give the change owner authority to delay the start when a hold point is incomplete. Give supervisors a clear stop trigger when the work no longer matches the reviewed condition. Schedule the post-start review while the evidence is still fresh, because a later discussion can otherwise become a story about intent rather than a test of control.

Final checklist for the change owner

  • The changed operating condition is written in concrete task language.
  • The group has described credible failure outcomes rather than only generic hazards.
  • Interfaces, handoffs, and decision rights have named owners.
  • Critical controls and temporary controls have field verification methods.
  • Weak assumptions have become conditions, evidence requests, or stop triggers.
  • The first shift, delays, staffing gaps, and production pressure have been tested.
  • The emergency response has named people, equipment, communication, and authority.
  • Open concerns have become hold points with deadlines.
  • Start, stop, and post-start review decisions are documented.

When the pre-mortem should stop the change

The pre-mortem has done its job when it makes an uncomfortable decision possible. If the group cannot verify a critical control, cannot identify who will act during an emergency, or cannot keep the changed condition within the reviewed boundaries, the correct outcome is a delayed start or a redesigned plan.

Andreza Araujo’s A Ilusão da Conformidade is relevant here because a complete record can still conceal weak execution. The purpose of this routine is not to produce a more persuasive approval. It is to make the remaining uncertainty visible while leaders can still change the work.

A production change is ready when its critical controls are verified, its uncertainty has an owner, and the people closest to the work can stop the start-up without retaliation.

Topics safety-pre-mortem production-change change-management operational-risk hold-points risk-management

Frequently asked questions

What is a safety pre-mortem?
A safety pre-mortem is a structured review in which a team assumes that a planned change has failed and works backward to identify the conditions, decisions, or missing controls that could have caused the failure.
Who should attend a safety pre-mortem?
The change owner, operations supervisor, maintenance representative, EHS professional, and at least one person who will perform the work should attend. Add contractors, engineers, or emergency coordinators when the change affects their duties.
How is a pre-mortem different from a hazard assessment?
A hazard assessment identifies hazards and controls for the work. A pre-mortem challenges the assumptions behind the change and tests how interfaces, delays, staffing, and pressure could defeat those controls during actual operation.
When should a pre-mortem stop a production change?
It should stop or delay the change when a critical control cannot be verified, an emergency decision has no clear owner, or the changed condition cannot remain within the boundaries reviewed by the team.
Does every production change need a formal pre-mortem?
The level of formality should match the change risk. A serious or unfamiliar change deserves a documented session, while a smaller change can use the same questions in a shorter review when the decision owner still records the conditions and stop triggers.

About the author

Andreza Araújo

Safety Culture Expert | Senior EHS Executive

Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.

  • Civil & Safety Engineer (Unicamp)
  • M.A. Environmental Diplomacy (University of Geneva)
  • Sustainability Cert (IMD Switzerland)
  • People Management & Coaching (Ohio University)
  • UN Paris speaker representative for Brazil
  • ILO Turin speaker
  • LinkedIn Top Voice
  • Indra Nooyi PepsiCo CEO recognition (2x)

Documentaries

Watch Andreza's documentaries

Three productions on safety culture, organizational failure and the human lessons behind major disasters.

Podcasts

Listen to Andreza's podcasts

She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.

Summarize with AI