Your HSEQ Management System - working or 'weighing'?

I've spent a lot of time writing, reviewing, improving and auditing HSEQ management systems, and during this time, I've learnt some valuable lessons. One lesson relates to 'weight'.
There's a version of a HSEQ management system that makes an organisation safer, more consistent in its approach, and easier for personnel to audit. There's also a version that consumes significant effort, generates excessive paperwork, is hugely inefficient and provides a level of assurance to management that's mostly false.
Both types of system can pass a certification audit. Both systems can look, from the outside, like they're functioning well. However, the difference between them shows up in how the organisation actually operates, and most clearly in what the organisation does when something goes wrong.
How Systems Get Heavy
HSEQ Management systems don't usually start out overcomplicated. They accumulate weight progressively (and mostly undetected) over time, through a series of decisions that individually, seem both reasonable and appropriate; many are noted below.
An incident triggers a need for a new procedure.
A client asks for evidence of compliance with a specific requirement and a new form is created to demonstrate it.
An audit finding requires a new control, which requires a new record.
A new standard is adopted and added into the existing system without considering what's already there and whether the standard's requirements could be incorporated into existing system documents.
Each addition makes sense at the time. However, the cumulative effect is a system that requires significant administrative effort to maintain, effort that comes at the expense of the operational improvement work that the system was meant to support.
Over time, the system and the work begin to diverge. Increasingly, procedures describe 'how things were expected to be done' when they were written (work-as-imagined), not 'how they're done now' (work-as-done). Workers develop workarounds that aren't documented because updating the documentation has become too onerous, and often, workers can't work out how to do it. The system that was supposed to reflect 'best practice' starts reflecting 'historical practice' instead.
The Compliance Illusion
Heavy systems create a specific kind of risk that's easy to underestimate: the risk of believing that the system is working because the paperwork is complete.
A signed pre-start checklist confirms that someone signed a pre-start checklist. It doesn't confirm that the check was actually done, that issues were identified, that actions were defined, or that the person doing it understood what they were looking for. Records of training completion confirm that training occurred. They don't confirm that the training transferred to any changed behaviour in the field.
When organisations manage by documentation rather than by verification, the gap between 'work as imagined' and 'work as done' widens, without anyone necessarily knowing. The system looks healthy. The underlying risk picture may be quite different.
This isn't a criticism of documentation; good records matter. The problem occurs when record-keeping becomes a proxy for risk control, rather than evidence of it.

What a Fit-For-Purpose System Looks Like
A well-designed HSEQ management system is proportionate to the risk profile of the operation or business. It has depth where depth is needed (i.e, for high-risk activities, critical controls, and high-consequence scenarios), and it's lean where leanness is appropriate. Not every procedure needs to be 25 pages long, with eight sections, four appendices and a review matrix. Not every record needs to be retained for seven years.
The documents that exist in the system should be documents that people actually use in their day-to-day work. Procedures should reflect how work is actually done, not a theoretical version of it that exists only in the management system (or the head of the author!). If a procedure requires five approvals to implement a routine task, the procedure is almost certainly not being followed in full, and that gap, unacknowledged, creates risk exposure.
A useful test for any management system element is to ask two questions.
What risk does this element control, and how does it do that?
How would we know if it stopped working?
If those questions are hard to answer, the element probably needs rethinking.
The Cost of the Status Quo
The cost of a heavy HSEQ management system isn't just administrative. The effort spent maintaining a system that's disconnected from operational reality is effort not being spent on the improvement work that actually reduces risk. The false assurance that is created by a system that looks compliant, but doesn't function, delays the recognition that something needs to change.
Organisations that have done the work of rationalising their management systems (i.e., 'decluttering', removing duplication, aligning procedures with work as done, sharpening critical control verification, etc.) typically find that their system becomes easier to maintain and more effective at the same time. Less volume, more signal.
So, the question isn't whether to have a HSEQ management system; it's whether the one that you have is working for you, or whether you're working for it!

Comments