How to Run a Safety Pre-Mortem Before a Production Change in 9 Steps
A safety pre-mortem helps production, maintenance, and EHS teams identify how a planned change could fail before the new condition reaches the first shift.

Key takeaways
- 01A safety pre-mortem tests the planned operating condition before production, maintenance, or commissioning begins.
- 02The strongest session includes people who will execute, supervise, maintain, and respond to the changed work.
- 03Each concern needs an owner, a verification method, and a decision deadline rather than a vague promise to monitor it.
- 04The session should examine interfaces, temporary controls, workload, competence, emergency response, and conditions that can change after approval.
- 05A production change is ready only when the remaining uncertainty is visible and someone has authority to stop the start-up.
A production change can be approved, scheduled, and staffed while its most important failure path remains unnamed. The team may have reviewed the method statement, discussed the deadline, and signed the change record, yet nobody has asked how the new condition could defeat a critical control during the first shift.
A safety pre-mortem closes that gap before work starts. The team assumes that the change has already failed, then works backward to identify the decision, interface, condition, or missing verification that made failure possible. This is not a prediction exercise. It is a disciplined way to turn uncertainty into named actions.
Key takeaways
- A safety pre-mortem tests the planned operating condition before production, maintenance, or commissioning begins.
- The strongest session includes people who will execute, supervise, maintain, and respond to the changed work.
- Each concern needs an owner, a verification method, and a decision deadline rather than a vague promise to monitor it.
- The session should examine interfaces, temporary controls, workload, competence, emergency response, and conditions that can change after approval.
- A production change is ready only when the remaining uncertainty is visible and someone has authority to stop the start-up.
What you need before starting
Bring the change description, the current process, the proposed process, relevant permits, equipment information, staffing assumptions, emergency arrangements, and the latest field constraints. The purpose is not to create a larger file. It is to make the changed condition concrete enough that the team can challenge it.
Invite the change owner, an operations supervisor, a maintenance representative, an EHS professional, and at least one person who will perform the work. Add a contractor lead, engineer, or emergency coordinator when the change affects their responsibilities. Across 25+ years of executive EHS work and more than 250 cultural transformation projects, Andreza Araujo has repeatedly seen that the person closest to the changed task notices a weakness that a review group can otherwise miss.
ISO 45001:2018 is useful as a management-system anchor because it requires organizations to control changes that can affect occupational health and safety. The pre-mortem adds a practical decision routine that helps the team test whether the planned control can survive contact with the work.
Step 1: State the change in operating terms
Write one sentence that describes what will be different in the work area. Name the equipment, task, people, sequence, location, and time window that will change. Avoid a sentence such as “improve line capacity,” because it hides the conditions that workers must actually control.
Use a statement such as “During the Saturday shutdown, the maintenance crew will replace the transfer pump while production operates on the parallel line.” The sentence should make interfaces visible. If the group cannot agree on what is changing, it is too early to discuss whether the change is safe.
Step 2: Define what failure would look like
Ask the group to complete this sentence: “The change has failed because…” Accept operational outcomes rather than abstract labels. Examples include an unexpected release, a person entering an exclusion zone, a control room receiving the wrong status, a rescue team arriving without the required equipment, or a restart occurring before a guard is restored.
James Reason’s work on latent conditions helps keep this discussion useful. The last visible event is rarely the whole story, so the team should describe both the immediate failure and the conditions that allowed it to develop.
Step 3: Map the interfaces that can pass risk forward
List every handoff between operations, maintenance, engineering, contractors, logistics, control room staff, and emergency responders. For each interface, ask what one group believes the other group has checked.
Risk often moves through an interface because responsibility sounds clear in a meeting but becomes ambiguous in the field. Record who gives the release, who confirms isolation, who controls access, who communicates a change in scope, and who can stop the work when the original assumption no longer holds.
Step 4: Identify the controls that must survive the change
Separate controls that prevent the unwanted event from controls that limit its consequences. Then identify which controls are permanent, which are temporary, and which depend on a person noticing a deviation at the right moment.
A checklist is not enough if it does not identify the control that protects people from the changed exposure. The team should be able to point to the physical barrier, isolation, permit condition, competence requirement, supervision practice, or emergency arrangement that must remain effective.
Step 5: Ask what assumption is most likely to be wrong
Write down the assumptions that make the change appear ready. Typical assumptions include equipment availability, contractor competence, access to a spare part, stable weather, adequate staffing, correct drawings, reliable communication, or enough time to test before production resumes.
For each assumption, ask how it will be tested before the first hazardous task. If an assumption cannot be checked, convert it into a condition of work or a stop trigger. A statement that the team “expects” a condition to hold is not a control.
Step 6: Test the first shift, not the ideal process
Walk through the first shift in sequence. Include the start-up, the most demanding task, the likely delay, the shift change, the break period, and the moment when production pressure is highest. Ask what happens if the plan is late, a person is absent, equipment behaves differently, or the work takes longer than expected.
This step exposes the difference between a safe method and a workable method. A control that requires uninterrupted attention for six hours may be technically sound and operationally fragile when the crew must also manage alarms, deliveries, and competing work.
Step 7: Rehearse the emergency decision
Choose the most credible serious event and ask the team to describe the first five decisions. Who raises the alarm, who stops the work, who isolates the energy, who accounts for people, who contacts external support, and who has authority to change the response when conditions worsen?
Do not accept “the emergency plan covers it” as an answer. The group needs to name the person, communication path, equipment, access route, and decision point that will exist in the changed condition. If any of those is unknown, assign a pre-start action.
Step 8: Convert concerns into hold points
Turn each material concern into a hold point with four fields: the condition that must be true, the person who verifies it, the evidence required, and the authority that decides whether work can proceed.
For example, “confirm the temporary barrier” is weak because it does not say what good looks like. “The area supervisor verifies the barrier, access gate, signage, and exclusion distance before the first lift, and records the result on the change permit” is specific enough to govern a decision.
Step 9: Set the start, stop, and review decisions
End the session by separating three decisions. The start decision states what must be complete before work begins. The stop decision states which change in condition suspends the work. The review decision states when the team will check whether the controls worked after the first operating period.
Give the change owner authority to delay the start when a hold point is incomplete. Give supervisors a clear stop trigger when the work no longer matches the reviewed condition. Schedule the post-start review while the evidence is still fresh, because a later discussion can otherwise become a story about intent rather than a test of control.
Final checklist for the change owner
- The changed operating condition is written in concrete task language.
- The group has described credible failure outcomes rather than only generic hazards.
- Interfaces, handoffs, and decision rights have named owners.
- Critical controls and temporary controls have field verification methods.
- Weak assumptions have become conditions, evidence requests, or stop triggers.
- The first shift, delays, staffing gaps, and production pressure have been tested.
- The emergency response has named people, equipment, communication, and authority.
- Open concerns have become hold points with deadlines.
- Start, stop, and post-start review decisions are documented.
When the pre-mortem should stop the change
The pre-mortem has done its job when it makes an uncomfortable decision possible. If the group cannot verify a critical control, cannot identify who will act during an emergency, or cannot keep the changed condition within the reviewed boundaries, the correct outcome is a delayed start or a redesigned plan.
Andreza Araujo’s A Ilusão da Conformidade is relevant here because a complete record can still conceal weak execution. The purpose of this routine is not to produce a more persuasive approval. It is to make the remaining uncertainty visible while leaders can still change the work.
A production change is ready when its critical controls are verified, its uncertainty has an owner, and the people closest to the work can stop the start-up without retaliation.
Frequently asked questions
What is a safety pre-mortem?
Who should attend a safety pre-mortem?
How is a pre-mortem different from a hazard assessment?
When should a pre-mortem stop a production change?
Does every production change need a formal pre-mortem?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.