Application Overview

What Critical Control Management models, and the ideas behind it


Core Chain

Publication → Requirement → SiteObligation
PrincipalHazard → HazardScenario → MaterialUnwantedEvent
  → CriticalControl → ControlPerformanceStandard
  → VerificationTemplate/Questions → VerificationSchedule
  → VerificationEvent → ControlDeficiency
  → CorrectiveAction → WorkOrder → RestorationVerification
AdverseEvent → hazard/control links, injuries, losses → Investigation
Audit → AuditFinding;  ManagementOfChange → ChangeImpact
PrincipalHazardManagementPlan;  Kpi → KpiResult;  Notification

Key Concepts

From publications to obligations. External documents (legislation, recognised standards, industry guides) are registered with their authority and sections; discrete Requirements are extracted from them, then interpreted per site as Site Obligations with a responsible position, evidence description and due date. A superseded publication can't create new obligations.

Bowtie-shaped risk model. Each Principal Hazard breaks into Hazard Scenarios and Material Unwanted Events (MUEs — the credible worst outcomes, e.g. "collision between haul truck and light vehicle"). Every Critical Control belongs to exactly one MUE, carries a control objective and failure criteria, and CRITICAL-classified controls must have a performance standard and an owner.

Verification is the heartbeat. Each control has verification templates (field observation, function test, document review, telemetry…) with structured questions. Schedules drive Verification Events; a FAIL result must raise a Control Deficiency with severity, operational restriction and temporary control. LEVEL_4/5 deficiencies escalate immediately.

Work doesn't restore controls — verification does. A corrective action may spawn a Work Order, but a work order marked COMPLETE does not restore the control. An independent Restoration Verification (with its own result and evidence) is required before the control status returns to EFFECTIVE and the operation is released.

Events link back to controls. An Adverse Event records both actual and potential severity independently; high-potential events require investigation. Event-to-hazard and event-to-control links capture which controls were expected to operate and which failed — connecting the lagging world (incidents, injuries, losses) to the leading world (verifications).

Governance loop. Audits raise findings against requirements and controls; Management of Change assesses impacts on hazards, controls and requirements before implementation; Principal Hazard Management Plans bind it together per hazard; KPIs (leading, current-state, lagging, control-quality) and notifications keep failures visible until restoration is verified.