Risk Management

Risk Criteria: 6 Decisions That Keep Board Thresholds From Hiding Exposure

Risk criteria only govern exposure when they change approval, escalation, funding, and stop-work decisions. This Headline Podcast analysis gives senior leaders six decisions for turning risk thresholds into operating controls.

By 7 min read updated
risk management scene on risk criteria 6 decisions that keep board thresholds from hiding exposure — Risk Criteria: 6 Decisio

Key takeaways

  1. 01Define consequence before debating probability.
  2. 02Separate risk criteria from risk acceptance and expiry rules.
  3. 03Escalate unknown exposure and degraded critical controls.
  4. 04Assign decision rights and response windows before pressure arrives.
  5. 05Follow Headline Podcast for more leadership and safety conversations.

Risk criteria determine which exposures receive escalation, funding, and stop-work authority, yet many boards approve them without seeing how the thresholds behave in a real decision. This article gives senior leaders six decisions that make risk criteria operational rather than decorative.

OSHA's safety management guidance explains that management leadership, worker participation, hazard identification, and program evaluation must connect. A threshold that cannot change one of those four management actions is not governing risk.

1. Define consequence before debating probability

A risk criterion should define consequence categories before the organization argues about likelihood. If a board starts with probability, familiar low-frequency events can be discounted before anyone has named the harm that the control system must prevent.

Use consequence language that senior leaders can recognize, including fatality, permanent disability, multiple serious injuries, major release, regulatory prosecution, and prolonged business interruption. The exact labels can vary, but the scale must distinguish a single catastrophic outcome from several routine recordable injuries.

James Reason's work on latent failures supports this ordering because a visible event is often the final expression of decisions made earlier. A low frequency does not make a high-consequence exposure acceptable when the organization has weak barriers, unclear ownership, or no credible recovery path.

Ask whether the consequence category would change capital allocation, operating permission, or executive attention even if the likelihood estimate moved down by one level.

2. Separate criteria from acceptance

Risk criteria set the boundary for evaluating exposure, while risk acceptance records a decision about a specific exposure. Combining them lets a signed form quietly become a permanent exemption, so governance should keep the boundary and the exception visibly separate.

ISO 31000 describes risk criteria as the terms against which significance is evaluated. The ISO risk management overview describes criteria as part of the management system, not as a substitute for treatment, monitoring, or review.

A useful register holds two different fields. One records the approved criterion, and the other records the exposure, owner, expiry date, compensating controls, and evidence required before the decision can be renewed.

The distinction matters during production pressure. A plant can accept a temporary residual risk for 24 hours under a named decision, yet that acceptance must not rewrite the criterion for every similar job in the next 24 months.

3. Set a lower threshold for unknown exposure

Unknown exposure deserves a stricter decision threshold than familiar exposure because uncertainty reduces the quality of the evidence supporting the estimate. A board should require escalation when the organization cannot describe the hazard, exposed population, or critical-control performance.

That rule does not claim that every unknown is catastrophic. It recognizes that an incomplete model cannot justify the same confidence as a verified one. The NIOSH hierarchy of controls places elimination and engineering controls above administrative instructions and PPE, which gives leaders a way to test whether uncertainty is managed at the source.

Use evidence statuses such as verified, partially verified, or unknown, and connect each status to a decision right. Unknown control performance should trigger field verification, technical review, or temporary work suspension rather than a longer narrative in the risk register.

Headline Podcast conversations return to the same leadership tension. A leader does not need perfect information before acting, but the leader does need to make uncertainty visible to the people who can change the exposure.

4. Make the threshold sensitive to control failure

Risk criteria become useful when they change as critical controls weaken. A residual-risk score that stays green after isolation, detection, guarding, or emergency response becomes unavailable is measuring paperwork stability rather than protection.

OSHA's process safety rule, 1910.119 requires process hazard analysis, operating procedures, training, mechanical integrity, management of change, and incident investigation for covered processes. Those elements show why a threshold must be connected to control health instead of treated as a one-time rating.

Give each critical control a status that the decision-maker can understand in less than 30 seconds. Available, degraded, bypassed, and unavailable are more useful than a single score whose color hides the reason for change.

Ask how many unavailable controls can exist before the work moves to a different approval level. If the answer is not written down, the organization has delegated a high-consequence decision to whoever is closest to the production deadline.

5. Assign decision rights before the meeting

Every risk criterion needs a named decision owner, an escalation route, and a stop-work authority that remains valid when production pressure rises. Without those three elements, the criterion describes an aspiration while the operation waits for permission that nobody clearly owns.

Separate technical advice from decision authority. EHS may identify that an exposure exceeds the approved boundary, while the plant manager decides whether work stops, resources move, or the operating plan changes. The roles should reinforce each other rather than make the specialist responsible for every operational consequence.

Dr. Megan Tranter's leadership perspective on Headline Podcast reinforces the human side of this design. People need to know not only that they may raise a concern, but also what will happen after they raise it and who must respond within a defined window.

Set response windows such as 15 minutes for immediate escalation, 2 hours for executive review, and 1 business day for a documented governance decision. These are operating choices, not universal legal requirements, so connect them to the hazard profile and emergency arrangements.

6. Test the criterion against competing pressure

A criterion is credible only when it survives competing pressure involving schedule, cost, staffing, or customer demand. Leaders should pressure-test the boundary with a realistic scenario before they rely on it during an active operation.

Choose a scenario with at least 2 competing pressures, such as a maintenance outage that is already 12 hours late and a critical barrier that cannot be restored before the next shift. Ask the decision-maker to state what changes, who is consulted, and what evidence would permit restart.

Use a short tabletop exercise, then compare the written criterion with the decision people actually make. A gap between the two is not a reason to blame the individual. It is evidence that the organization has not translated its stated risk appetite into a usable operating rule.

As Andreza Araujo argues in Safety Culture: From Theory to Practice, culture becomes visible through repeated decisions. The test should examine behavior under pressure, not just whether the policy contains the correct vocabulary.

7. Review the threshold after learning events

A serious near miss, control failure, regulatory finding, or material change should trigger a review of the risk criterion itself, not only a corrective action assigned to the worksite. The question is whether the boundary helped the organization see and govern the exposure early enough.

Review the criterion when a precursor shows that the assumed likelihood was wrong, when a control failed without detection, or when a decision was escalated too late. NIOSH and OSHA materials emphasize hazard identification and evaluation, which means the learning loop must reach the management system rather than stop at the incident file.

Andreza Araujo's work across 25+ years of multinational EHS leadership places this review in a broader cultural context. A mature organization treats a changed threshold as evidence of learning, not as an admission that the previous document was embarrassing.

Record the trigger, evidence reviewed, revised boundary, and person accountable for communicating the change. Close the loop in 7 days when the learning affects active work, and use a longer cycle only when the exposure is stable and the reason is documented.

8. Report threshold breaches as governance information

A threshold breach should reach the board as a decision-quality signal, not as a count of non-compliant forms. Executives need to see the exposure, failed or missing control, duration, owner, and action that changed the operating condition.

Use a monthly view that separates breaches caused by control unavailability, weak hazard identification, decision delay, and deliberate acceptance. Those categories point to different interventions, even when the dashboard displays the same red status.

A board that receives only lagging injury rates can miss serious exposure during a quiet month. OSHA's management guidance and the BLS injury and illness data explain why reported outcomes are useful but incomplete evidence for controlling future risk.

Andreza Araujo's challenge to compliance theater is relevant here. A green dashboard is not proof of safe work when leaders cannot explain which high-consequence exposures were tested, which controls were unavailable, and which decisions changed because of the evidence.

Comparison: Decorative criteria versus operating criteria

The difference between decorative and operating risk criteria is whether the boundary changes a decision that affects exposure. The comparison below gives boards a fast way to examine the quality of their own governance language.

Decision dimensionDecorative criterionOperating criterion
ConsequenceUses broad labels without a decision impactConnects consequence to approval and resource rights
UncertaintyAssumes missing evidence is neutralEscalates unknown control performance
Control healthLeaves the score unchanged after a bypassChanges the threshold when a critical barrier degrades
OwnershipLists departments but no accountable decision-makerNames the owner, escalation route, and response window
LearningCloses corrective actions without reviewing the boundaryRevises criteria after serious learning events

Boards can use this table during a 20-minute review, then select one exposure whose criterion needs a live pressure test. The objective is not to create a more elaborate matrix. It is to make the next high-consequence decision harder to misunderstand.

Related Headline analysis on risk acceptance distortions, barrier health, risk transfer, and safety governance shows how the same boundary behaves across different decisions.

Urgency note: If a critical control is unavailable today, do not wait for the next monthly dashboard to reveal the breach. Escalate the exposure through the decision route defined by the risk criterion.

Conclusion: Make risk criteria change the work

Risk criteria protect people only when they define consequence, expose uncertainty, respond to control failure, assign decision rights, survive competing pressure, learn from events, and reach the board as governance information. A signed matrix is not evidence of control until it changes what the operation is allowed to do.

Start with one high-consequence exposure and test the boundary this week. For more conversations where leadership and safety come together to shape better workplaces and better lives, follow Headline Podcast and bring the decision back to the people who own the work.

Topics risk-criteria risk-management board-oversight control-health executive-safety headline-podcast

Frequently asked questions

What are risk criteria in workplace safety?
Risk criteria are the terms an organization uses to evaluate whether an exposure is acceptable, requires treatment, or must be escalated. Effective criteria define consequence, uncertainty, control performance, ownership, and review conditions so that the threshold changes an operating decision rather than remaining a score in a register.
How are risk criteria different from risk acceptance?
Risk criteria define the boundary used to evaluate exposure across the organization. Risk acceptance records a decision about a specific exposure, including its owner, controls, expiry date, and evidence for renewal. Keeping them separate prevents a temporary exception from silently becoming a permanent operating rule.
Why should unknown exposure receive stricter escalation?
Unknown exposure has weaker evidence behind its likelihood and control assumptions. A stricter escalation rule prevents incomplete information from being treated as proof that the risk is low and directs leaders toward verification, redesign, or temporary suspension.
Who should own a risk threshold breach?
The organization should name the operational decision-maker, technical advisor, escalation route, and stop-work authority before a breach occurs. EHS may identify that the boundary has been exceeded, while an operational leader decides how work, resources, and schedule change.
How can a board test whether risk criteria work?
A board can select one high-consequence exposure and run a short scenario involving schedule pressure and a degraded control. Leaders should state what changes, who decides, what evidence is required, and how quickly the decision is reviewed. Comparing that response with the written criterion exposes governance gaps.

About the author

Andreza Araújo

Safety Culture Expert | Senior EHS Executive

Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.

  • Civil & Safety Engineer (Unicamp)
  • M.A. Environmental Diplomacy (University of Geneva)
  • Sustainability Cert (IMD Switzerland)
  • People Management & Coaching (Ohio University)
  • UN Paris speaker representative for Brazil
  • ILO Turin speaker
  • LinkedIn Top Voice
  • Indra Nooyi PepsiCo CEO recognition (2x)

Documentaries

Watch Andreza's documentaries

Three productions on safety culture, organizational failure and the human lessons behind major disasters.

Podcasts

Listen to Andreza's podcasts

She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.

Summarize with AI