Safety Indicators and Metrics

Safety Metrics Fail: 6 Ownership Gaps

Safety metrics fail when ownership is vague. These 6 gaps show how to assign one owner, one steward, and one decision rule before the next review.

By 9 min read
metrics dashboard representing safety metrics fail 6 ownership gaps — Safety Metrics Fail: 6 Ownership Gaps

Key takeaways

  1. 01Each safety metric needs one owner, one data steward, and one forum that can act when the number changes.
  2. 02Activity counts do not prove control, because volume can rise while exposure quality gets worse.
  3. 03Formula drift, late extraction, and weak thresholds are proof gaps, not small reporting defects.
  4. 04A monthly review should ask what changed in the field, not only what changed on the screen.
  5. 05Andreza Araujo's safety culture work reinforces the same rule: measurement must change decisions, not just fill the dashboard.

A safety metric only changes behavior when one person owns its meaning, one person protects the data, and one forum has authority to act when the number moves. If those three pieces are missing, the dashboard stays busy while the field stays exposed.

A safety metric ownership model assigns one decision owner and one data steward to each metric, then ties the number to a review forum that can change work, not just describe it. Without that structure, a metric is a report item, not a control signal.

Across 25+ years in executive EHS and more than 250 cultural transformation projects, Andreza Araujo has seen the same pattern repeat in different countries and industries: sites collect more numbers, then discover that nobody can say who should respond when the signal turns red. ISO 45001:2018 expects performance evaluation to be part of the management system, and that expectation only works when the metric has a named owner and a clear decision path.

The thesis of this article is narrow. Safety metrics fail when ownership is unclear because ambiguity lets formulas drift, thresholds go unused, and activity counts replace proof of control. James Reason's work still applies here because the visible number is only the last layer of a longer chain that includes planning, supervision, data handling, and leadership response.

Key Takeaways

  • Each safety metric needs one owner, one data steward, and one forum that can act when the number changes.
  • Activity counts do not prove control, because volume can rise while exposure quality gets worse.
  • Formula drift, late extraction, and weak thresholds are proof gaps, not small reporting defects.
  • A monthly review should ask what changed in the field, not only what changed on the screen.
  • Andreza Araujo's safety culture work reinforces the same rule: measurement must change decisions, not just fill the dashboard.

Why ownership matters more than the dashboard color

A green chart can hide a weak system if nobody is named to explain what the number means or what should happen when it changes. The color is useful only after the organization has agreed on the action behind it. Otherwise, the meeting becomes a discussion about presentation instead of risk.

ISO 45001:2018 asks leaders to evaluate performance, but performance evaluation is not the same as counting. It is the discipline of deciding whether the control still works, whether the data still reflects the field, and whether the site will change anything because the metric moved. That is why a metric without ownership is a display, not a decision tool.

The most common failure is to treat the metric as if it owned itself. A board sees a line, a site manager sees a trend, and an EHS analyst sees a data pull. None of those views is wrong, yet none of them is enough unless someone is accountable for the action that follows the number.

For a related angle on this problem, the article on Safety KPI Weighting: 6 Dashboard Traps shows how weighting can distort the signal even when the raw data looks clean.

The three roles that each metric needs

The first role is the owner. The owner decides what the metric means, what decision it supports, and what action should follow when it crosses a threshold. If the owner cannot name that action, the metric has too many possible interpretations to be useful.

The second role is the data steward. The steward protects the source, the extraction timing, the calculation rule, and the completeness of the data. The steward does not own the meaning of the number, but the steward protects the number from drift. That distinction matters because many safety dashboards break at the handoff between meaning and data handling.

The third role is the reviewer or decision forum. This is the person or group that can change work when the number says the control is weak. A metric can have a strong owner and a careful steward, yet still fail if the review forum has no authority to change staffing, sequencing, maintenance, or supervision.

Across more than 250 projects, Andreza Araujo has seen that the sites with the cleanest dashboards are not always the sites with the strongest control. The stronger sites are the ones where the owner, steward, and reviewer do not hide behind the same ambiguity.

Where dashboards become decorative

Dashboards become decorative when they reward activity more than control. A site may celebrate the number of observations, audits, and meetings while no one checks whether those actions touched the highest-risk work. That is a shallow win, because activity volume can rise even while the same exposure remains untouched.

Dashboards also become decorative when the extraction happens too late. If the site exports data after the month is already closed, the review cannot help the crew that is still working the risk. In that case, the dashboard is a record of what happened, not a tool for changing what comes next.

Andreza Araujo's book Safety Culture: From Theory to Practice makes the same point in cultural language. The organization reveals its real priorities in what it keeps, what it ignores, and what it corrects under pressure. A metric that never changes work is just another way to keep score.

Six ownership gaps that distort the signal

Gap 1. No named owner

The first gap is the simplest. If nobody is named as the owner, the metric floats between functions. EHS may maintain the spreadsheet, operations may read the trend, and leadership may ask for a better chart, but nobody is clearly responsible for the decision the metric should trigger.

That gap matters most for metrics that should drive action, such as corrective action aging or SIF exposure hours, because the value of the metric is not the count itself. The value is the operational response.

Gap 2. The steward owns data but not meaning

A steward can pull the number on time and still leave the metric weak if the meaning is unclear. This gap appears when the dashboard is technically clean but operationally vague. The analyst can explain the extraction, yet the leader still cannot say what changed in the field.

James Reason's thinking helps here because the problem is not the last visible step. The problem sits earlier, where the organization failed to define what the metric is supposed to control. Once that gap exists, the steward becomes a courier for ambiguity.

Gap 3. The formula drifts by site or by forum

Formula drift is one of the quietest forms of metric failure. One plant counts contractors and temporary labor, another does not. One forum reviews monthly averages, another reviews the last seven days only. The number looks similar, but the decision basis is not the same.

This is why the article on near-miss quality matters. A high count can still be low quality if the calculation rule changes, because the leader is reading a moving target and calling it performance.

Gap 4. The threshold exists, but no action is tied to it

Some teams draw red, amber, and green bands and then stop there. A threshold without an action rule does not protect anyone. It only signals that someone should feel concerned, which is not the same as knowing what to do next.

A useful threshold names the action, the owner, and the time limit. If corrective-action aging rises beyond the agreed range, the owner should explain the bottleneck, the steward should verify the source, and the review forum should decide whether the backlog is now a control problem rather than a paperwork problem.

Gap 5. Activity count replaces exposure quality

Activity count is easy to report, which is why it survives. But counting observations or audits does not prove that the highest-risk work was touched, that the critical barrier was tested, or that the worker who mattered most was reached. Volume can rise while quality stays flat.

For C-level leaders, this gap is the one that hides behind positive motion. A team can post more meetings and still leave the same workfront unchanged. That is why metrics need a quality field, not just a count.

Gap 6. The review forum has no authority

The final gap appears when the metric reaches a meeting that cannot change anything. The forum may discuss the chart, but if it cannot adjust staffing, restart rules, maintenance priority, or supervisor attention, the review is theater. The signal arrived, yet the system had no hand to move.

This is where Patrick Hudson's maturity thinking is useful in practice. Mature systems do not just collect signals. They create a route from the signal to a decision that changes work. If the route is missing, the metric is only a conversation starter.

Comparison: activity metric, control metric, decision metric

Metric type What it tells you Who should own it What it should trigger
Activity metric How much work was counted Usually EHS or the program steward Review for volume and coverage, then test whether the count touched real risk
Control metric Whether a barrier or check was verified Operations or the control owner Confirm field evidence and correct the barrier if the rate drops
Decision metric Whether a leader changed work because of the signal The manager who can act Change staffing, sequencing, maintenance priority, or restart rules

This comparison matters because not every number deserves the same review logic. An activity metric can support learning, but a control metric should verify exposure, and a decision metric should force a management response. When a site mixes those three levels, the wrong number gets the most attention.

The article on Executive Safety Dashboard: 7 Metrics C-Level Leaders Need is useful as the next step, because a board view should focus on the few numbers that actually change decisions.

What a monthly review should require

The monthly review should begin with one simple rule. The owner speaks first, the steward confirms the source, and the reviewer states the decision that follows. If the conversation starts with opinions about the chart design, the meeting is already drifting away from control.

After that, the review should ask three questions. What changed in the field? What evidence supports the change? What action will happen before the next review? Those questions keep the discussion tied to work instead of to presentation. They also make it easier to spot when a metric is being used to decorate the agenda.

If the metric is slow to close or keeps rolling forward, compare the discussion with Corrective Action Aging: 7 Metrics Leaders Need. A backlog that never changes often tells you more about ownership than about workload.

What C-level leaders should ask

C-level leaders should not ask whether the dashboard is attractive. They should ask who owns the signal, what action the signal changes, and what the site will stop doing if the number gets worse. Those questions move the conversation from display to governance.

They should also ask where the metric comes from and how much delay sits between the field and the review. If a metric is extracted too late, it cannot help the work that is still in motion. The board then sees a historic record while the operation needs a live warning.

Across more than 250 projects, Andreza Araujo has found that leaders learn faster when they challenge the ownership model instead of the chart color. The moment a board asks who owns the metric, the site has to decide whether it is measuring risk or merely counting it.

FAQ

What is safety metric ownership?

Safety metric ownership is the assignment of one accountable owner, one data steward, and one decision forum to a metric. The owner decides what the number means and what should happen when it changes. The steward protects the source and calculation. The forum has the authority to change work.

Who should own a safety metric?

The owner should be the person or function that can act on the signal. For a control metric, that may be operations. For a data quality metric, that may be EHS or the analyst who maintains the source. What matters is not the title itself. What matters is whether the owner can change the condition the metric is reporting.

Is a green dashboard enough to prove control?

No. A green dashboard only proves that the metric is inside the expected range at the moment it was read. It does not prove that the formula is stable, that the source is current, or that the field control still works. James Reason's lens is useful here because the visible number can look calm while the system underneath still leaks risk.

How often should metric ownership be reviewed?

Review ownership whenever the work changes, the data source changes, the leadership structure changes, or the metric stops driving a decision. A metric can survive in the same dashboard for months while the work around it changes completely. That is when ownership needs a fresh check.

Which metrics should lead the monthly review?

The metrics that should lead the monthly review are the ones tied to critical controls, corrective-action aging, serious incident potential, and the few decisions that can change exposure before the next cycle. If a metric only creates discussion, it should not sit in the front row of the agenda.

Conclusion

Safety metrics fail when ownership is unclear because no one is truly accountable for the meaning, the data, or the decision that follows the number. Once the owner, steward, and review forum are named, the metric stops behaving like decoration and starts behaving like control.

The practical test is simple. If a metric moves, can one leader say what changed in the field and what will change next? If the answer is yes, the metric is working. If the answer is vague, the dashboard is still carrying the burden that leadership has not assigned.

Topics safety-indicators-and-metrics metric-ownership dashboard-governance leading-indicators control-verification ehs-manager

Frequently asked questions

What is safety metric ownership?
Safety metric ownership is the assignment of one accountable owner, one data steward, and one decision forum to a metric. The owner decides what the number means and what should happen when it changes. The steward protects the source and calculation. The forum has the authority to change work.
Who should own a safety metric?
The owner should be the person or function that can act on the signal. For a control metric, that may be operations. For a data quality metric, that may be EHS or the analyst who maintains the source. What matters is not the title itself. What matters is whether the owner can change the condition the metric is reporting.
Is a green dashboard enough to prove control?
No. A green dashboard only proves that the metric is inside the expected range at the moment it was read. It does not prove that the formula is stable, that the source is current, or that the field control still works. James Reason's lens is useful here because the visible number can look calm while the system underneath still leaks risk.
How often should metric ownership be reviewed?
Review ownership whenever the work changes, the data source changes, the leadership structure changes, or the metric stops driving a decision. A metric can survive in the same dashboard for months while the work around it changes completely. That is when ownership needs a fresh check.
Which metrics should lead the monthly review?
The metrics that should lead the monthly review are the ones tied to critical controls, corrective-action aging, serious incident potential, and the few decisions that can change exposure before the next cycle. If a metric only creates discussion, it should not sit in the front row of the agenda.

About the author

Andreza Araújo

Safety Culture Expert | Senior EHS Executive

Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.

  • Civil & Safety Engineer (Unicamp)
  • M.A. Environmental Diplomacy (University of Geneva)
  • Sustainability Cert (IMD Switzerland)
  • People Management & Coaching (Ohio University)
  • UN Paris speaker representative for Brazil
  • ILO Turin speaker
  • LinkedIn Top Voice
  • Indra Nooyi PepsiCo CEO recognition (2x)

Documentaries

Watch Andreza's documentaries

Three productions on safety culture, organizational failure and the human lessons behind major disasters.

Podcasts

Listen to Andreza's podcasts

She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.

Summarize with AI