Capability

Health, Safety & Environment

Certified organisations still have serious incidents. Not because the certificate was fraudulent, but because a management system audit tests whether procedures exist and were followed on the day of the audit. It does not test whether the operation is resilient when things are not normal.

In short

The problem

The management system is certified, the audits are passing, and the injury numbers look acceptable — yet the people who run the plant have a list of things that worry them, and none of it appears in the reporting that reaches the board.

Why it matters

Personal injury statistics do not predict major events. Organisations with excellent lost-time records have suffered catastrophic process safety incidents, because the two have different causes and different controls. A board reading only injury frequency is reading the wrong instrument, and the gap between what is measured and what is dangerous is where serious incidents live.

Who typically needs this

  • Plant and operations leadership carrying personal accountability for a running site
  • Boards responsible for operational risk who suspect their reporting is incomplete
  • HSE leadership trying to move an organisation past compliance
  • Process industries, energy and infrastructure operators with loss-of-containment exposure
  • Organisations with recurring incidents of the same type
  • Sites preparing for a major shutdown, turnaround or capacity change

What we do

  • HSE management system review
  • Process safety review
  • HAZOP facilitation
  • Operational risk assessment
  • Critical control verification
  • Contractor management framework
  • Incident investigation
  • Emergency response assessment
  • Safety culture assessment
  • Operational readiness review
  • ISO 45001 and ISO 14001 implementation

A plant head reading this will recognise the situation. The management system is certified. The audits pass. The injury numbers are acceptable. And there is still a list — the bypass that was never removed, the permit that gets signed before the job is properly understood, the contractor crew nobody is really supervising, the inspection that has slipped twice.

None of that appears in the reporting that reaches the board.

Safety is a property of the operating system

Not of the audit, the paperwork, or the certificate. Those are records of an intention. What determines whether an operation is safe is whether the controls it depends on are actually in place and working, on an ordinary Tuesday, during a breakdown, at 2am, in the third week of a shutdown, when the experienced operator is on leave and the contractor is new to the site.

That is not something a document review establishes. It is established by being on plant, watching work happen, and looking at where practice has moved away from design.

Compliance is an outcome, not an objective

We implement ISO 45001 and 14001, and we do it properly. But a system built to satisfy clauses produces a certificate and a filing cabinet. A system built around how the site actually operates produces both the certificate and an operation that is genuinely more resilient.

The order matters. Sites that pursue certification first frequently end up maintaining two realities: the documented one and the real one. Every audit then becomes an exercise in reconciling them, which consumes the effort that should have gone into the operation.

What you actually receive

Services describe activity. These are the artefacts that exist at the end, and that you own.

  1. HSE management system review

    An assessment of whether the system describes how the plant actually runs — including where procedure and practice have diverged, which is the gap an audit is least likely to find and most likely to matter.

  2. Operational risk assessment

    The material risks to the operation, ranked by consequence rather than by ease of mitigation, with the controls each one depends on identified by name.

  3. Critical control register and verification plan

    For each major hazard, the small number of controls that actually prevent or limit it, who owns each, how its effectiveness is verified, and how often. Barriers you rely on but never check are the ones that fail.

  4. HAZOP facilitation

    Independently facilitated study to the required node depth, with actions written to be closable and tracked to closure rather than to acknowledgement.

  5. Process safety review

    Loss-of-containment risk assessed on its own terms — inventory, energy, escalation paths, safeguards and their integrity — separate from occupational safety performance.

  6. Contractor management framework

    Pre-qualification, bridging documents between your system and theirs, supervision expectations, and commercial terms that do not make the safe method the unprofitable one.

  7. Permit-to-work review

    An assessment of whether permits are controlling work or documenting it, based on observing permits being raised and closed rather than on reading the procedure.

  8. Incident investigation

    Independent investigation to systemic cause, with actions placed against the hierarchy of controls. An investigation that concludes at operator error has stopped early.

How we approach the work

  • We look at the operation, not the documentation

    The first week is spent on plant, on shift, watching work being permitted, executed and closed out. Management systems describe an intended operation. Every site also has an actual operation, and the distance between them is the risk. That distance is not visible from a document review.

  • Process safety is assessed separately from personal safety

    Slips, cuts and manual handling have different causes and different controls from loss of containment, structural failure or runaway reaction. Sites that manage the first well often assume they are managing the second. Injury frequency is a poor proxy for major hazard risk, and treating it as one is among the more consequential errors in operational risk management.

  • We identify the controls you actually depend on

    Most sites have hundreds of controls and a handful that genuinely stand between normal operation and a major event. Those few deserve named owners, defined performance standards and scheduled verification. Everything else is important, but it is not the same thing, and treating all controls as equal dilutes attention away from the ones that matter.

  • We look for drift rather than for non-conformance

    Systems rarely fail suddenly. A temporary modification becomes permanent. A bypass fitted for a shutdown is never removed. A procedure step is skipped because it was always unnecessary, until the day it was not. We look for where practice has moved away from design and nobody has updated either.

Weak signals worth watching

Serious failures are usually preceded by months of readable indicators. Most sites already hold this data; it is rarely assembled into one view, and rarely owned by anyone.

A falling near-miss reporting rate
Almost always a reporting problem rather than a safety improvement. Reporting falls when people conclude that reporting produces paperwork rather than change, or that it is held against them. A site with genuinely few near misses is rare; a site that has stopped hearing about them is common.
Growing backlog of overdue safety-critical maintenance
This is a risk position, not a scheduling problem, and it is frequently reported as the latter. Every overdue item is a control you are assuming works while explicitly deferring the check.
Temporary modifications that are still open after six months
Management of change has become an administrative step rather than a control. The plant is no longer the plant that was designed, hazard-reviewed and proceduralised.
Standing alarms and bypassed or inhibited trips
Operators are being trained to ignore the alarm system, and the protective layers assumed in the risk assessment are not all present.
Repeat findings across successive audits
The strongest single indicator of a system that is not learning. It means corrective actions are closing on paper without changing anything, and it predicts recurrence better than any other measure.
Actions from investigations that are mostly training and reminders
Investigations are stopping at the individual. Training and communication sit at the weak end of the hierarchy of controls, and a pattern of them indicates that systemic causes are not being reached.
Nobody can recall work being stopped recently
Stop-work authority exists on paper but not in practice. The useful question is not whether people have the authority but what happened to the last person who used it.
Rising contractor headcount without rising supervision
The people at highest risk are the least familiar with the site, and the supervision ratio has quietly moved. Most serious harm in industrial operations falls on contractors.
Sustained overtime among experienced operators
Fatigue is a control failure with a delay. It also signals a competence gap being covered by a small number of individuals, which is a single point of failure in human form.
Deviation and concession requests trending upward
The organisation is progressively accepting conditions it once considered unacceptable. Each individual approval is defensible; the trend is the finding.

Every engagement runs on the same model, whatever the discipline — one accountable partner, a fixed reporting cadence, a live risk register and a decision log.

HSE engagements vary widely in shape. A HAZOP or an investigation is a focused piece of work measured in weeks. A management system rebuild or a multi-site programme runs the full lifecycle, including the improvement stage where the change either holds or quietly reverses.

  1. 01 Discovery
  2. 02 Assessment
  3. 03 Strategy
  4. 04 Planning
  5. 05 Implementation
  6. 06 Governance
  7. 07 Handover and improvement
  • One accountable partner, end to end
  • Fortnightly written reporting, including the quiet weeks
  • We agree in advance what would make us recommend stopping

Who this is for, and what they arrive with

  • Process industries

    Loss-of-containment exposure where occupational safety performance is strong and gives false assurance about major hazard risk.

  • Manufacturing

    Machinery, energy isolation and contractor interfaces across multiple sites with inconsistent practice and no reliable way to compare them.

  • Energy & infrastructure operators

    Distributed assets, high contractor dependence and work at height or on live systems, often at sites with no permanent supervision.

  • Construction

    Transient workforce, changing site conditions and a commercial structure that transmits schedule pressure directly to the people at greatest risk.

  • Data centres

    Electrical safety and arc flash exposure during live work, and a construction-to-operations transition that outpaces the safety management system.

  • Government & PSUs

    Statutory obligations across a diverse asset base, with documentation that must satisfy audit years later and workforce practices that vary widely by location.

Standards & practice

  • ISO 45001 — occupational health & safety management
  • ISO 14001 — environmental management
  • IEC 61882 — HAZOP study methodology
  • Hierarchy of controls applied to investigation actions
  • Critical control verification with defined performance standards
  • Process safety indicators separated from occupational indicators
  • Practitioner-led — the work is done by people who have run operations, not by auditors reading a standard against a checklist
  • Process safety treated as a separate discipline from occupational safety, because the controls are different
  • HAZOP and risk studies facilitated to the technical depth a regulator expects
  • Findings reported as we found them, including where the honest answer is uncomfortable

Questions buyers ask about this work

Why do organisations with certified management systems still have serious incidents?

Because certification tests conformance to a standard, not resilience under real conditions. An audit samples: it establishes that procedures exist and were followed on the days it looked. It does not establish whether the procedure is correct, whether it is followed during a breakdown at 2am, or whether the plant still matches the drawings. Certification is worth having and it is not a safety verdict. The widest gaps tend to sit in organisations with the longest record of clean audits, because nothing has forced them to look harder.

How do safety systems deteriorate when nothing obvious has changed?

Gradually and reasonably. A temporary bypass is fitted during a shutdown and not removed. A procedure step is skipped because it appeared unnecessary and no harm followed, so it is skipped again. A safety-critical inspection slips a month, then a quarter. Each individual decision was defensible at the time and the outcome confirmed it. Drift is not carelessness; it is the accumulation of locally rational choices, which is why it is invisible to the people making them and visible to someone from outside.

How do you find problems before an incident rather than after?

By reading the leading indicators as a risk position rather than as a backlog — overdue safety-critical maintenance, open temporary modifications, permit quality, standing alarms, repeat audit findings, near-miss reporting trend. Most sites already hold this data across different functions. The failure is usually that nobody assembles it into one view and nobody is accountable for what it says.

How much does leadership behaviour actually influence operational risk?

More than any procedure. What leadership asks about in the morning meeting defines what the organisation treats as real. If the daily review covers production and cost, and safety appears only when something has gone wrong, people correctly infer the priority. Production pressure is rarely a directive — it is transmitted through what gets attention, what gets approved, and what happens when someone raises a concern that is inconvenient.

When should work be stopped?

When the controls the risk assessment assumed are not all present, when conditions have changed beyond what the permit contemplated, or when the person doing the work does not understand why it is safe. The harder question is whether stopping is genuinely available. Stop-work authority is real only if using it costs nothing — so the diagnostic question is not whether people have the authority, but what happened to the last person who exercised it.

How should incidents be investigated?

To systemic cause, by someone independent of the area, with actions placed against the hierarchy of controls. An investigation that concludes at operator error has stopped one step early: the useful question is why that action was reasonable to that person at that moment, given the information, time and pressure they had. If the resulting actions are mostly training and reminders, the investigation has not reached the causes.

Health, Safety & Environment

Discuss what is actually worrying your operations team

The most useful starting conversation is usually not about your management system. It is about the two or three things your plant leadership already knows are not right, and why they have not been resolved. We can tell you quickly whether the issue is local or systemic.

A partner replies within one working day.