Most businesses we work with can produce a folder of Chain of Responsibility documentation. Policies, procedures, a risk register, training records.
Far fewer can answer a simpler question: are you doing what you say you do?
That gap is where chain of responsibility risk management usually fails.
A control on paper is not a control
If your procedure says loaders will restrain loads using a particular system, that is a stated control.
It only becomes a real control when loaders actually use that system, every time, and when the system is adequate for the load in the first place.
Those are two separate questions, and both need checking:
- Is the control being followed in practice?
- Is the control adequate for the job even when it is followed?
A business can fail on either one while its paperwork looks complete.
Wheels stopped, wheels turning
At SCSE we describe the split as managing risk when the wheels are stopped, and when the wheels are turning.
Wheels stopped covers your WHS risks. Loading, unloading, pedestrian and vehicle interaction, storage and handling, working at heights.
Wheels turning covers your CoR risks. Speed, fatigue, mass, dimension, load restraint.
What you do when the wheels are stopped directly affects what happens when they are turning. That is the essence of CoR for off-road parties. If a load is poorly restrained in your yard, the risk travels down the road with it, and so does your exposure.
Why businesses miss this
Three reasons come up repeatedly.
The documentation was written for an audit, not for the work. It describes an ideal process rather than the actual one. Staff quietly work around it because the documented method does not fit the job.
Nobody has been to the coalface recently. The risk register was built in a meeting room. It has not been tested against what happens on the dock at 5am.
The control was adequate once. Loads changed, volumes changed, equipment changed, but the control did not.
None of these are failures of intent. They are failures of verification.
What checking properly looks like
Verifying chain of responsibility risk management means going and looking.
At SCSE we conduct field visits to check that existing CoR risk controls reflect operational practice, the way work is done, and to identify what is working and what is not working.
In practice that means:
- Watching the activity rather than reading about it
- Talking to the people doing the work, not only their managers
- Comparing what you see against what the procedure says
- Testing whether the control would hold up under pressure, at volume, or on a bad day
- Comparing and testing alignment with the Master Code and leading industry practice
Where controls fall short, we suggest improvements or additional controls that may be required. You can read more about our approach on our services page.
Then close the loop
Finding a gap is not the outcome. Closing it is.
Where an incident has already occurred, SCSE uses the ICAM process, Incident Causation Analysis Method, to investigate seriously enough to prevent repeat incidents rather than just record them.
Where no incident has occurred yet, the same discipline applies. Embed the fix, then check again later that the fix held. We covered the assurance side of this in Three Lines of CoR Defence.
Two questions worth asking today
Do you know what your CoR risks are?
Do you know if your CoR risk controls are effective?
If the second answer is less confident than the first, that is normal, and it is the gap worth closing.
If you need a fresh set of eyes on your CoR risks and controls, get in touch with Sean.