Safety Leadership: 6 Frictions That Keep Critical Risk Waiting for a Decision
Critical risk often remains open because the organization has not made the decision easy to see, own, fund, and verify. This F1 analysis identifies six leadership frictions that delay action, then gives executives and site leaders a practical way to move from concern to a defensible decision without confusing activity with control.
Key takeaways
- 01Critical risk can remain unresolved even when the organization has policies, meetings, and escalation channels.
- 02The six recurring frictions are vague thresholds, split ownership, temporary controls without expiry, budget ambiguity, production handoffs, and weak verification.
- 03A leader should make the exposure, interim protection, decision owner, decision date, and verification evidence visible in one place.
- 04James Reason’s distinction between active and latent failures helps leaders investigate the conditions that delay a decision instead of blaming the last person who noticed the risk.
- 05Across more than 250 cultural transformation projects, Andreza Araujo’s work emphasizes that leadership becomes credible when field concerns change priorities, resources, or work design.
A supervisor sees a damaged interlock during a night shift. The equipment can be isolated, but production will lose a shipment window. The concern is escalated, a meeting is scheduled, and the task continues under a temporary instruction that nobody has dated.
That sequence is not necessarily a failure of commitment. It is often a failure of decision design. Critical risk stays open when the organization has no shared threshold for action, no single owner for the trade-off, and no visible proof that the temporary protection works. The result is a familiar safety paradox. Leaders can discuss the exposure repeatedly while the work continues to carry it.
Why critical risk waits even when leaders care
Most organizations do not delay serious decisions because everyone is indifferent. Delay usually comes from friction between functions that each have a reasonable local concern. Operations protects continuity, engineering protects technical integrity, finance protects capital discipline, and EHS protects people from an exposure that may not fit neatly into any one budget or schedule.
The leadership task is to convert that friction into a decision that can be understood by the people doing the work. A risk register is useful only when it leads to a choice about exposure, controls, resources, or operating limits. If it only records concern, it creates a polished history of unresolved risk.
1. Vague thresholds make escalation subjective
One site escalates a failed guard immediately. Another calls it a maintenance backlog item. A third accepts the condition because the task has been performed without an injury for years. When the threshold is not defined in terms of credible harm, control failure, and operating context, the loudest voice in the meeting determines the response.
Leaders should define what makes a risk decision urgent. The trigger may involve a missing critical control, an exposure beyond the approved operating envelope, a change that invalidates the assessment, or a credible pathway to fatal or permanently disabling harm. This is not a demand for perfect prediction. It is a way to prevent familiarity from becoming evidence of acceptability.
James Reason’s work on organizational accidents is useful here because it separates the visible action from the conditions that make the action possible. A supervisor may continue a task, yet the deeper problem may be a threshold that never tells the supervisor when continuation is no longer defensible.
2. Split ownership turns a decision into a relay
Many escalations have several participants and no decision owner. Engineering can recommend a redesign, maintenance can estimate the work, operations can explain the schedule, and EHS can describe the exposure, but nobody is accountable for choosing the operating condition until the permanent solution is complete.
That gap becomes dangerous when the issue crosses a functional boundary. Each handoff sounds responsible, while the risk remains in the field. A leader should assign one person to own the decision and should name the people who must provide evidence, resources, or technical approval. Ownership does not mean that one person makes every technical choice. It means that one person is answerable for the unresolved exposure.
The practical test is simple. Ask who can authorize the task to stop, who can release the interim protection, and who must explain the decision to the workforce. If the answers are different and nobody coordinates them, the organization has distributed activity rather than accountability.
3. Temporary controls survive because expiry is optional
A temporary barrier often begins as a sensible response. The problem starts when the temporary condition becomes familiar, undocumented, or detached from a date. A sign, additional inspection, spotter, reduced speed, or work restriction can protect people while a permanent control is designed, but it should not become a permanent substitute by accident.
Every interim control needs an owner, a start date, an expiry date, and a verification method. The expiry date is not a promise that the permanent fix will be finished by then. It is a forced decision point. Before the date arrives, the owner must confirm whether the control remains effective, whether the task should stop, or whether the operating envelope must become narrower.
When leaders remove the expiry date because the project is late, they convert a temporary exception into an unspoken risk acceptance. That choice may be necessary in rare circumstances, but it should be signed, visible, and reviewed at the level with authority to accept the exposure.
4. Budget ambiguity makes safety compete without a sponsor
Critical controls frequently fail at the point where a technical recommendation becomes a funding decision. The organization agrees that a redesign is needed, yet the capital request has no sponsor, the maintenance budget cannot absorb it, and the project budget treats the work as an operational nuisance.
Leaders should distinguish the cost of controlling the exposure from the cost of continuing to carry it. That does not mean inventing a dramatic injury estimate. It means documenting the operating restriction, additional supervision, production vulnerability, maintenance burden, legal exposure, and human consequence that the organization accepts when it postpones the control.
Andreza Araujo’s experience across more than 250 cultural transformation projects supports a practical conclusion. Safety leadership becomes visible when the organization is willing to change a plan, allocate a resource, or redesign work after the exposure is understood. A message from the executive team cannot compensate for a decision process that leaves every control unfunded.
5. Production handoffs erase the original concern
A risk is often identified in one language and transferred in another. The night shift reports an unreliable interlock. The morning meeting records “equipment issue.” The weekly review records “maintenance action.” By the time the plant manager sees the item, the credible harm and the conditions that created it have disappeared behind a neutral label.
Good leadership protects the meaning of the signal as it moves through the system. The record should state what can happen, under which task conditions, which control is missing or weak, what has been done temporarily, and what decision remains open. That level of specificity helps a senior leader act without pretending to know every technical detail.
Handoffs should also preserve worker feedback. The person who raised the concern needs to know whether the task changed, whether the interim control was tested, and when the next decision will occur. Otherwise, the organization teaches people that escalation produces administrative movement rather than operational response.
6. Weak verification lets leaders close the record too early
A decision is not the same as a control. A work order can be closed while the hazard remains, and a procedure can be approved while the task still depends on workarounds. Verification asks whether the chosen measure changed the real conditions that produced the concern.
The evidence should match the decision. A redesigned guard may require a functional test under the relevant operating conditions. A staffing change may require observation of the critical task across shifts. A revised permit may require review of actual permits and worker understanding. The point is not to produce more paperwork. It is to test the claim that the exposure is now controlled.
Leaders should ask what evidence would make them reopen the decision. If the answer is “nothing,” the organization is treating closure as a status change rather than a judgment that can be challenged by field evidence.
What a defensible risk decision contains
A useful decision record is short enough for operations to use and specific enough for leadership to defend. It should identify the exposure, the credible consequence, the current control condition, the interim protection, the decision owner, the decision date, and the evidence that will confirm the result.
- Exposure and task conditions that make the risk credible.
- Control that is missing, degraded, bypassed, or not yet verified.
- Interim protection and the operating limits attached to it.
- Named decision owner with authority to stop, restrict, fund, or redesign the work.
- Expiry or review date for the interim condition.
- Verification evidence and the person responsible for collecting it.
This structure gives the C-level a better question than “Is the action complete?” The stronger question is whether the organization has made a visible choice about the exposure and whether the field can demonstrate that the choice works.
How leaders remove friction in the next review
At the next leadership risk review, select three open exposures that have crossed functions or remained on the register beyond their original date. Do not begin with the dashboard color. Begin with the work. Ask what the person faces, what control is supposed to prevent the harm, what is happening now, and what decision is still missing.
Then force the handoff into five sentences. The exposure is ____. The current protection is ____. The decision owner is ____. The decision will be made by ____. We will verify it by checking ____. If the team cannot complete those sentences, the friction is already visible and the meeting has a concrete job.
That discipline also protects leaders from false reassurance. A clean dashboard can coexist with weak control evidence when overdue items are reclassified, temporary controls are renewed without review, or unresolved exposure is split across several action owners. The field test is harder to manipulate because it asks whether the task became different.
Leadership is measured by the risk that no longer waits
Safety leadership is not proved by the number of escalations, meetings, or visible site visits. It is proved when a credible exposure receives a decision that is timely, owned, resourced, communicated, and tested in the work. The six frictions in this article are not personality defects. They are design problems that leaders can expose and remove.
When the organization defines thresholds, assigns ownership, dates temporary controls, sponsors resources, protects meaning across handoffs, and verifies the result, escalation becomes a route to action. Without those conditions, even a caring leadership team can leave critical risk waiting for a decision that never becomes explicit.
For more practical conversations about safety leadership, risk decisions, and the conditions that shape work, explore the Headline Podcast.
Frequently asked questions
What is a safety-leadership friction?
Why do critical risks remain open after they are escalated?
Should every critical risk be stopped immediately?
How can executives test whether risk escalation works?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.