Risk Ownership: 4 Decisions That Keep Critical Exposure From Becoming Everyone's Problem
Critical exposure rarely persists because nobody cares. It persists when ownership is implied, divided, or postponed. This article presents four decisions that turn risk ownership into an operating practice rather than a line in a register.

Key takeaways
- 01Critical exposure remains unmanaged when a risk has an analyst, a procedure, and a meeting, but no person with authority to change the condition.
- 02Risk ownership requires four decisions about the exposure, the control, the escalation threshold, and the resources needed to close the gap.
- 03A risk register records uncertainty, while field verification shows whether the control can protect people during the task that creates the exposure.
- 04ISO 31000 treats risk management as part of governance and decision-making, so ownership cannot be delegated to the safety function alone.
- 05The strongest dashboard is not the one with the most risks. It is the one that makes unresolved ownership impossible to hide.
At a plant review, the risk register can look disciplined while a critical exposure remains ownerless. The hazard has a description, the control has a procedure, and the action has a due date. Yet when a supervisor asks who can authorize a redesign or stop the task, the answer moves from engineering to operations, then from operations to EHS. That movement is not collaboration. It is a control failure.
Risk ownership is the missing management decision in many high-consequence systems. ISO 31000 describes risk management as part of governance and decision-making, which means the operational leader cannot treat risk as a document delegated to a specialist function. Across 25+ years leading EHS work in multinational companies, Andreza Araujo has repeatedly identified the same practical distinction: the person who explains the risk is not always the person who can change it.
Why critical exposure becomes everyone’s problem
Critical exposure becomes everyone’s problem when responsibility is distributed without a final decision right. A risk may cross maintenance, production, engineering, procurement, and contractor management, but the exposure still needs one accountable owner. Without that person, each function can complete its part while the combined control remains weak.
The pattern is common in work involving stored energy, temporary bypasses, lifting interfaces, process changes, or contractor handovers. The risk statement survives every meeting because nobody has the authority, budget, or operating incentive to resolve its underlying condition. The organization then mistakes discussion for control.
James Reason’s distinction between active and latent failures helps explain why this persists. A frontline error may be visible, while the ownership design that allowed a weak barrier to remain in place is less visible. Andreza’s book Safety Culture: From Theory to Practice makes the same management point in practical terms, because a declared value does not become a working control until leaders assign decisions and verify execution.
Decision 1: Name the exposure before naming the action
The first ownership decision is to define the exposure in operational terms before assigning corrective work. A useful statement identifies who can be harmed, by what energy or condition, during which task, and under what circumstances the consequence becomes serious. This level of definition prevents a broad phrase such as “machine safety improvement” from hiding several different decisions.
A precise exposure statement also reveals whether the proposed owner controls the problem. If the exposure is unexpected movement during maintenance, the relevant owner may need authority over isolation design, work planning, competence, and restart approval. Naming a coordinator who only updates the register creates administrative ownership without operational control.
Use the same discipline described in the existing risk acceptance review. Ask whether the owner can describe the worst credible outcome, identify the control that should prevent it, and explain what evidence shows that the control is ready for the real task.
Decision 2: Assign the owner who can change the condition
The accountable owner should be the leader who can change the process, equipment, staffing, contractor scope, or budget that shapes the exposure. This is different from assigning the person with the strongest technical knowledge. Expertise is essential, but authority determines whether a weak condition can be redesigned rather than merely documented.
For example, an EHS manager may identify that a temporary bypass removes a critical interlock, while the operations manager controls the decision to continue production. The EHS manager can challenge the decision and require evidence, but the operations manager must own the exposure because that role controls the operating choice.
In more than 250 cultural transformation projects, Andreza Araujo has observed that ownership becomes credible when a leader must make the trade-off visible. The question is not whether the safety team reviewed the risk. The question is which leader accepted the remaining exposure, with what evidence, for how long, and under which conditions.
Decision 3: Define the control and its proof
A risk owner needs a control statement that can be verified in the field, not a general intention such as “increase awareness” or “follow the procedure.” The control should describe the barrier, its required condition, the task in which it matters, and the evidence that confirms it works. OSHA’s lockout and tagout standard specifies control elements that must be applied before servicing begins, which illustrates why a control needs observable requirements rather than a slogan.
Proof can include a verified isolation, a tested interlock, a signed permit with field confirmation, or a documented inspection performed under the same conditions in which the work occurs. Training records may show that people received information, but they do not prove that the barrier is available, usable, and effective during production pressure.
That is why control verification should be linked to the task, not only to the audit calendar. The related control assurance tests offer a useful comparison when leaders need to distinguish a completed check from evidence that protection remains dependable outside the audit setting.
Decision 4: Set the escalation threshold before the failure
Escalation becomes reliable when the owner defines the threshold before the control fails. The threshold should state what evidence is unacceptable, who must be notified, what work may continue, and what decision is required within a defined period. A vague instruction to “escalate if needed” leaves the hardest judgment to the moment when production pressure is highest.
Thresholds work best when they are tied to observable conditions. An overdue action on a low-consequence housekeeping issue may need routine management attention, while an unverified isolation, disabled safeguard, or missing rescue capability may require immediate suspension of the task. The difference is not the age of the action. It is the exposure and the strength of the remaining barrier.
The owner should also define what happens when evidence conflicts. A clean dashboard should not overrule a field report that shows a critical control is unavailable. Leaders who receive bad news early can resource the correction. Leaders who reward the appearance of closure often receive the information only after the consequence.
How to test ownership during a real task
Ownership is credible only when it survives contact with the work. A short field test should ask the operator, supervisor, contractor, and accountable leader the same four questions: what can cause serious harm, which control prevents it, what proves the control is working, and who decides when the proof is missing?
Differences in the answers are valuable evidence. If the operator names a physical barrier while the dashboard reports a training completion rate, the organization is measuring different realities. If the supervisor believes the permit authorizes the task but engineering believes the permit only records the review, the decision boundary is unclear.
NIOSH recommends evaluating controls through the hierarchy of controls, which gives leaders a practical way to test whether ownership is focused on removing or reducing the exposure rather than relying only on worker behavior. The field test should therefore include a challenge question: what could be redesigned so that the person does not have to remember a perfect response under pressure?
What a risk ownership dashboard should show
A risk ownership dashboard should show the exposure, the accountable owner, the critical control, the latest field evidence, the escalation status, and the decision date. It should help a leader see which serious risks remain open because a condition is weak, a resource is missing, or a decision has been postponed.
Do not fill the dashboard with every action attached to a risk. A long action list can conceal the one decision that matters. Separate supporting tasks from the ownership decision, then show whether the owner has accepted, reduced, transferred, or stopped the exposure. The record should also preserve dissent when the technical reviewer does not agree that the remaining risk is tolerable.
Andreza Araujo’s work on leadership and safety culture emphasizes that the dashboard is a conversation tool, not a substitute for leadership. Its value appears when a director asks why a critical exposure remains open and the owner can answer with evidence, a decision, and a date rather than another explanation.
When ownership needs to move
Ownership should move when the decision rights move. A change in equipment, process, contractor scope, staffing model, operating envelope, or emergency response capability can place the exposure under a different leader’s control. Keeping the old owner for convenience creates a gap between accountability on paper and authority in practice.
Ownership should also be revisited after a serious near miss, repeated control failure, or unplanned workaround. The purpose is not to find a convenient person to blame. It is to ask whether the current owner can actually prevent recurrence and whether the governance design still matches the work.
A handover is complete only when the incoming owner accepts the exposure, understands the control standard, receives the evidence, and confirms the escalation path. This is the point at which a risk register becomes an operating system rather than an archive.
Risk ownership is a decision system, not a field in a register
Risk ownership works when one accountable leader can name the exposure, change the condition, verify the control, and escalate before the barrier fails. That standard is more demanding than assigning a name beside a risk, yet it is also easier to test because the evidence belongs in the work.
Start with the four decisions in the next review of critical exposure. Define the condition, assign the leader with authority, specify proof, and set the escalation threshold before the next failure. ISO explains that risk management supports informed decisions under uncertainty, and that principle becomes meaningful only when a named leader has to make the decision visible.
On the Headline Podcast, Andreza Araujo and Dr. Megan Tranter explore the conversations that connect leadership, evidence, and safer work. A risk that belongs to everyone often belongs to no one. The management task is to make one person accountable for changing what creates the exposure, while keeping the wider system responsible for providing challenge and support.
Frequently asked questions
What does risk ownership mean in workplace safety?
Why do risk registers often fail to create accountability?
Who should own a critical safety risk?
How often should critical risk ownership be reviewed?
What is the first sign that risk ownership is weak?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.