Risk Management

Risk Criteria: 5 Blind Spots Boards Miss

Risk criteria only work when they test consequence, control health, authority, time horizon, and local context before leaders accept exposure.

By 7 min read
risk management scene on risk criteria 5 blind spots boards miss — Risk Criteria: 5 Blind Spots Boards Miss

Key takeaways

  1. 01Risk criteria should judge consequence, control health, authority, and time horizon, not only likelihood.
  2. 02A green matrix cell is not proof when the barrier was never verified in the field.
  3. 03Residual risk should be accepted by the person who owns the consequence and the evidence.
  4. 04Temporary changes and aging controls should force a fresh review before tolerance turns into drift.
  5. 05Use board criteria to change a decision, not to decorate a slide.

A board can approve a risk with clean criteria and still bless the wrong exposure. The failure is usually not a lack of rigor. It is criteria that measure document quality, color coding, or sign-off hygiene instead of the decision the organization is actually making.

Across 25+ years in executive EHS roles and more than 250 cultural transformation projects, Andreza Araujo has seen the same pattern repeat. The criteria looked disciplined, the meeting looked orderly, and the worksite still carried the same exposure because the reference point was too abstract. In Safety Culture: From Theory to Practice, that gap appears whenever leaders reward the appearance of control more than the control itself.

Risk criteria are the rules leaders use to judge whether a risk is tolerable, acceptable, escalated, or stopped. They only work when they include credible consequence, control health, decision authority, time horizon, and local context.

Why risk criteria fail when they stay abstract

ISO 31000 treats risk criteria as the reference point against which risk significance is evaluated, which means the criterion is supposed to sharpen a decision, not decorate a matrix. When the criterion stays abstract, the organization can still produce a neat answer, although the answer may not match the work that people actually do.

The practical failure is easy to miss. A team may score a task as acceptable because the probability looks low, the form is complete, and the usual controls are listed, even though the credible worst outcome is severe, the barrier has never been verified, and the work is being done by a new crew on a tight restart window.

James Reason's work helps here because it pushes leaders away from the visible label and toward the conditions that made the label possible. If the criterion cannot tell the difference between a paper-safe job and a field-safe job, it is not a decision rule. It is a filing rule.

Blind spot 1: the criterion ignores credible consequence

The first blind spot is treating likelihood as if it matters more than consequence. That is how leaders end up calling a task tolerable when the credible worst case is a serious injury, a fatality, or a major release of energy. Low probability does not make a severe outcome harmless. It only makes the event less frequent.

That distinction is why the article on SIF precursor review matters. A risk criterion that ignores serious injury and fatality potential can approve a job because the last ten repetitions were quiet, while the exposure is still alive and one timing shift away from a different outcome.

A better criterion asks a sharper question. What could credibly happen if timing, distance, load, supervision, or energy changed by a small amount? If the answer is severe, the board should not accept a neat low-probability cell as proof of control.

Blind spot 2: the criterion ignores control health

A criterion is weak when it assumes that a control exists without testing whether the control is healthy. A guard can be listed, a permit can be signed, a training record can be current, and the work can still be exposed because the physical barrier is missing, bypassed, degraded, or never verified in the field.

That is why the article on control effectiveness metrics belongs next to risk criteria. A board needs to know whether the barrier is present and reliable, not just whether someone once wrote it into the assessment. The same logic applies to lockout, access control, traffic separation, rescue readiness, and line-of-fire protection.

In more than 250 projects, Andreza Araujo has seen that control health changes the whole decision. A site with a green matrix and weak controls is not safer than a site with a tougher criterion. It is only better at producing a green slide.

Blind spot 3: the criterion ignores decision authority

Some criteria fail because they do not say who may accept the risk. If any manager can close the review, the organization has not defined a risk criterion. It has defined a weak habit.

The right owner is the person who holds the consequence, the evidence, and the escalation path. That is why the internal guides on safety risk acceptance authority and decision rights fit this topic. A criterion without authority gives production the power to win by default, because the person who wants the job finished becomes the de facto risk owner.

Andreza Araujo's book The Illusion of Compliance is useful here because a signed form can hide a weak decision chain. The organization may look aligned, although nobody with the right competence actually accepted the exposure. That is not governance. It is drift with paperwork.

Blind spot 4: the criterion ignores time

A risk that was tolerable last month may not be tolerable today. Temporary changes, deferred maintenance, new contractors, altered weather, a different shift, or a longer backlog can all move the criterion without changing the form that carries it. If the criterion has no review date, it slowly becomes a memory of past conditions.

This is the same problem that shows up in Management of Change and risk register upkeep. Time matters because controls age, assumptions drift, and temporary exceptions become normal when nobody forces a re-check. The board may still be looking at the original approval while the field has already moved on.

In practice, time belongs inside the criterion. Leaders should ask how long the exposure remains acceptable, what would force a re-review, and which change would invalidate the original decision. Without that discipline, a one-time acceptance becomes a permanent permission slip.

Blind spot 5: the criterion ignores local context

The same risk can be acceptable in one context and unacceptable in another. A task with an experienced crew, simple access, strong supervision, and stable conditions is not the same task when the crew is new, the language is mixed, the contractor boundary is blurred, or the work is being done under shutdown pressure.

That is why leaders should never treat local context as a footnote. The article on contractor interface risk shows how a job can look routine on paper and still become fragile at the point where two work systems meet. The criterion should ask who is present, who is missing, which assumptions changed, and whether the crew can prove the control in the actual conditions.

A context-free criterion sounds universal, but universality is exactly the problem. It removes the field from the decision and leaves only the policy.

What good criteria actually ask

A strong criterion does not ask whether the paperwork is complete. It asks whether the consequence is credible, whether the controls are healthy, whether the right person can accept the risk, whether the decision will still hold after a change, and whether the local work context supports the assumption behind the acceptance.

Dimension Weak criterion Stronger criterion
Consequence Names a low-probability event Names the credible worst outcome and who is exposed
Control health Assumes a barrier exists Requires field verification that the barrier works
Authority Lets any manager sign off Names the person who owns the consequence and escalation
Time Treats approval as permanent Sets a review date and invalidation trigger
Context Uses the same threshold everywhere Tests the criterion against the actual crew, shift, and workfront

A board that can read this table well is already asking a better question than the typical traffic-light review. It is asking what changed, what is verified, and who is accountable if the assumption fails.

How leaders should use criteria in the monthly review

The monthly review should not ask whether the score stayed green. It should ask what decision the criterion changed, what evidence supported the judgment, what control was verified in the field, and what would force a re-open if the situation drifted.

That format changes the conversation. In more than 250 transformation projects, Andreza Araujo has seen that leaders improve when they stop asking for a tidy summary and start asking for the operating logic behind the summary. During the PepsiCo South America period, where the accident ratio fell 50% in six months, the useful change was not a cleaner dashboard. It was a tighter link between evidence, leadership action, and field verification.

Use one criterion for one decision. If the criterion is being asked to govern fatal risk, contractor interfaces, maintenance backlog, and temporary change all at once, it is too broad. Split it until the board can say who decides, what evidence is required, how long the decision lasts, and what would make the acceptance invalid.

FAQ

What are risk criteria in practice?

Risk criteria are the rules used to judge whether a risk is tolerable, acceptable, escalated, or stopped. In practice, they should include consequence, control health, authority, time horizon, and the local work context.

Why do risk matrices fail so often?

Risk matrices fail when the color becomes more important than the decision. A green or yellow cell can hide severe consequence, weak controls, or a change in conditions that makes the original judgment obsolete.

Who should approve residual risk?

The person who approves residual risk should also own the consequence, the evidence, and the escalation path. If those three things do not sit together, the acceptance is probably too easy.

How often should risk criteria be reviewed?

Review risk criteria whenever the work changes, the control changes, the crew changes, or the assumption behind the original decision changes. If the risk is time-sensitive, the criterion should carry an expiry or revalidation date.

What is the first sign that criteria are too weak?

The first sign is when the board can approve a risk without being able to explain the credible worst outcome in the current work context. That usually means the criterion is measuring compliance, not control.

Conclusion

Risk criteria are only useful when they make a difficult decision clearer. If they ignore credible consequence, control health, authority, time, or local context, they will keep approving the wrong exposure while making the process look disciplined.

The practical test is simple. Before the next acceptance, ask whether the criterion would still hold if the crew changed, the control aged, or the task moved by one small step. If the answer is no, the criterion needs work before the board trusts it again.

For more conversations on risk management, leadership, and the decisions that shape safer workplaces, follow Headline Podcast and compare this article with risk matrix blind spots and risk acceptance authority.

Topics risk-management risk-criteria risk-acceptance board-oversight control-health sif-precursors

Frequently asked questions

What are risk criteria in practice?
Risk criteria are the rules used to judge whether a risk is tolerable, acceptable, escalated, or stopped. In practice, they should include consequence, control health, authority, time horizon, and the local work context.
Why do risk matrices fail so often?
Risk matrices fail when the color becomes more important than the decision. A green or yellow cell can hide severe consequence, weak controls, or a change in conditions that makes the original judgment obsolete.
Who should approve residual risk?
The person who approves residual risk should also own the consequence, the evidence, and the escalation path. If those three things do not sit together, the acceptance is probably too easy.
How often should risk criteria be reviewed?
Review risk criteria whenever the work changes, the control changes, the crew changes, or the assumption behind the original decision changes. If the risk is time-sensitive, the criterion should carry an expiry or revalidation date.
What is the first sign that criteria are too weak?
The first sign is when the board can approve a risk without being able to explain the credible worst outcome in the current work context. That usually means the criterion is measuring compliance, not control.

About the author

Andreza Araújo

Safety Culture Expert | Senior EHS Executive

Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.

  • Civil & Safety Engineer (Unicamp)
  • M.A. Environmental Diplomacy (University of Geneva)
  • Sustainability Cert (IMD Switzerland)
  • People Management & Coaching (Ohio University)
  • UN Paris speaker representative for Brazil
  • ILO Turin speaker
  • LinkedIn Top Voice
  • Indra Nooyi PepsiCo CEO recognition (2x)

Documentaries

Watch Andreza's documentaries

Three productions on safety culture, organizational failure and the human lessons behind major disasters.

Podcasts

Listen to Andreza's podcasts

She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.

Summarize with AI