The Missing Dimension in Safety Risk Management
- Apr 2
- 18 min read
Updated: Apr 8
Most organisations can point to a risk register, a set of procedures, and a suite of controls. Many can show training records, audits, assurance activity, and a pattern of review. On paper, the system exists. It looks structured. It appears deliberate. It gives comfort to those charged with governance and those responsible for day-to-day delivery.
Yet serious harm still occurs, often in organisations that believed they were managing risk well.
That should give leaders pause, because the issue is not always that hazards were unknown, or that no system existed. More often, the deeper issue lies in the space between what the organisation believes is protecting people and what is actually protecting them when conditions tighten, assumptions are tested, and reality begins to apply pressure.
This is where vulnerability becomes important.
In occupational health and safety, risk management is often dominated by hazard identification, risk ratings, and the listing of controls. That process has value, but it can also create false confidence when insufficient attention is given to the susceptibility of what is exposed to harm, and to the real capacity of the system to withstand, absorb, respond to, or recover from failure. In that sense, vulnerability is not peripheral. It is one of the missing dimensions in safety risk management.
Here, vulnerability is used in the systems sense. It refers to susceptibility to harm arising from exposure, weak protection, degraded barriers, poorly understood dependencies, or limited capacity to absorb and respond once failure begins.
A useful way to express this relationship, adapted from the Office of the United Nations Disaster Relief Co-Ordinator framework and later used in World Health Organization vulnerability and risk mapping material, is:
Risk ∝ (Hazard × Vulnerability)
Capacity
This is not offered as a strict mathematical formula, but as a way of thinking more clearly about why the same hazard can produce very different outcomes in different organisations. As hazard and vulnerability increase, risk rises. As capacity increases, risk is moderated. If capacity is thin, degraded, absent, or overstated, the relationship shifts quickly against the person, team, asset, or organisation exposed to harm.
This article argues that vulnerability deserves far more attention in OHS because it helps explain why apparently mature systems still fail, why risk assessments can flatter the true state of protection, why controls themselves can become points of weakness, and why leadership due diligence must extend beyond the existence of documentation into the real condition, strength, and reliability of the safeguards on which the organisation depends.
Looking at the Barrier
Imagine a large concrete dam holding back an enormous volume of water. It has been engineered, designed, inspected, and maintained. The barrier exists. On paper, the hazard is controlled.
But somewhere inside the structure, fine cracks begin to form.
They are small at first, almost invisible. The dam still stands. The water remains contained. Reports still indicate that the structure is sound. The hazard has not changed. The barrier is still there, yet something important has altered. The system has become more vulnerable.
The critical question is no longer simply whether the dam exists. The critical question is whether the integrity of the dam is known, understood, and being actively managed. If the cracks are missed, normalised, or poorly understood, the existence of the barrier may create reassurance at precisely the moment when deeper scrutiny is needed.
That is the uncomfortable reality at the centre of many serious harm events. The problem is not always the complete absence of a system. More often, it is that the organisation assumes the system is stronger than it really is. Vulnerability begins to grow in the space between the intended condition of the system and the condition it is actually in.
In many workplaces, that shift is gradual. A control becomes dependent on memory rather than design. A procedure becomes impractical in live conditions. Maintenance intervals stretch. Supervision softens. Training is treated as sufficient in place of physical separation. A workaround becomes routine. Over time, what the organisation thinks is protecting it and what is actually protecting it begin to diverge. The dam still stands, but the cracks widen.
What Vulnerability Means
Vulnerability is not a concept unique to health and safety. It appears across fields such as emergency management, ecology, sociology, public health, economics, infrastructure resilience, security, and information systems. Across those fields, vulnerability generally refers to susceptibility to harm when exposed to a threat, hazard, or destabilising force.
That distinction matters in OHS.
A hazard is a source of potential harm. In practical terms, it is often a source of energy, or a condition capable of releasing energy in a harmful way. Electricity, gravity, motion, pressure, heat, chemicals, vehicles, machinery, water, unstable loads, and hazardous atmospheres all fit comfortably within that frame.
Vulnerability concerns the exposed target. It asks how susceptible the person, asset, system, process, environment, or organisation is if exposure occurs. A target may be vulnerable due to limited protection, weak barriers, poorly understood dependencies, degraded condition, or the simple fact that it must operate near the limits of tolerance.
Capacity, by contrast, concerns the ability to withstand, absorb, adapt to, respond to, or recover from exposure to harm. Capacity may sit within a person, a team, a machine, a rescue arrangement, a supervision structure, a control framework, or the wider organisation. Capacity is not fixed. It can be strengthened, consumed, misjudged, eroded, or exhausted.
This matters because the effects of a serious event rarely remain confined to the initial point of failure. Once exposure occurs, harm can ripple through multiple layers of vulnerability within the organisation. What begins as a failure at the interface between hazard and target may quickly disturb supervision, emergency response, operational continuity, leadership confidence, financial stability, and the organisation’s wider capacity to cope. Vulnerability, in that sense, is not only about immediate susceptibility to harm, but also about how deeply the consequences of harm can travel through a system once its protections have been breached.
When these ideas are brought together, the relationship becomes more meaningful:
Risk ∝ (Hazard × Vulnerability)
Capacity
This helps explain why two organisations can face the same hazard and yet experience very different outcomes. One may have strong engineering, redundancy, competent supervision, realistic procedures, rapid emergency response, and an operating model that respects the limits of human attention and physical systems. Another may rely heavily on training, awareness, compliance language, and the expectation that experienced people will simply do the right thing. The hazard may be similar. But vulnerability and capacity are not, and neither therefore is the real level of
risk.
This way of thinking also improves the quality of OHS judgement. A control listed on a risk register is not necessarily a strong control. A visible control is not necessarily a reliable one. A control that depends on a person noticing, remembering, interpreting, deciding, and acting correctly under pressure is not equivalent to a control that physically prevents contact with the hazard. Vulnerability analysis begins to reveal those distinctions.
Why Conventional Risk Management Can Miss the Point
Many risk assessments are built around a familiar pattern. A hazard is identified. A risk rating is assigned. Existing controls are listed. A residual risk score is then recorded after those controls are taken into account. Often the visual endpoint is a colour: red, amber, or green.
This process can be useful, but it can also conceal the very thing that most needs attention.
Most leaders are not reading a risk register and interrogating every listed control against the hierarchy of control, likely failure modes, maintenance history, verification arrangements, and the actual operating conditions in which the job is done. More often, they are scanning for assurance. They want to know whether the issue has been considered, whether something is in place, and whether the organisation appears to be on top of it.
Their eye pauses at the final column. The box is green. Low risk.
There are many controls listed above it: training, supervision, procedures, PPE, toolbox talks, signage, monitoring, competence, awareness, and reporting. It looks comprehensive. It looks managed. It looks safe enough to move on from.
But this is precisely where vulnerability often hides.
There is also a strange discomfort, often visible when risk assessments are being completed, with leaving empty space in the control section beside a serious hazard. Where an entry appears thin, there is a tendency to keep adding controls so the line does not look exposed or incomplete. Our review of organisational risk material suggests that, over time, this can produce long lists of controls that are vague, weak, unallocated, or aspirational. Usually this is not a deliberate attempt to mislead. Yet the cumulative effect can still be significant. The risk assessment begins to present the image of a strong system simply because many controls have been recorded against the hazard. Attention shifts from the quality, strength, and ownership of controls to their number. In that way, administrative density can slowly be mistaken for actual protection.
A long list of controls does not necessarily mean the hazard is well controlled. In many cases, much of what is listed does not control the hazard itself, but instead places expectations on people around it. These measures rely on a worker recognising the problem, a supervisor noticing drift, a contractor following instructions, a team remembering a rule, or someone acting in time before energy is released. They may all have value, but they are not equivalent to physically separating people from harm.
Sometimes the listed controls are not even actual protections, but future intentions. An engineering solution has been proposed but not funded. A redesign has been discussed but not implemented. A review is planned. A procedure is in draft. Training is due next quarter. Yet on paper these future steps may sit beside actual controls, and the overall picture looks mature.
The issue is not merely that risk assessments are imperfect. It is that they can flatten important distinctions. They can make weak and strong controls look interchangeable. They can make behavioural dependence appear equivalent to engineered protection. They can conceal the difference between a barrier that exists, a barrier that is partial, and a barrier that is assumed.
This is how vulnerability can sit quietly inside a green box.
What Research and Prosecutions Begin to Show
Across our review of hundreds of New Zealand health and safety prosecutions, a consistent pattern has emerged: serious harm often occurs not because the hazard was unknown, but because the organisation’s protection was weaker than assumed. In many cases, the defendant had identified the hazard, had some form of system in place, and could point to policies, training, procedures, expectations, or management activity. What failed was the strength, implementation, maintenance, or verification of the controls relied upon in practice.
That pattern matters because it cuts against the simplistic view that harm occurs only in obviously chaotic or unmanaged environments. Often the evidence shows that the organisation knew the broad nature of the risk, understood the seriousness of the potential harm, and had already articulated measures that ought to have stood between people and the hazard. The problem was that those measures were not strong enough, not sustained, not checked, or not translated into real separation from the source of harm.
Our review also suggests that documentation can become double-edged. Many organisations build extensive safety management systems full of policies, procedures, standards, and plans. Those documents are often intended to demonstrate diligence. But when something goes wrong and an investigation begins, the same documents can become evidence that the organisation knew about the hazard, understood the risk, and had identified controls, yet did not implement, maintain, or verify them in a way that genuinely controlled exposure. Documentation intended to prove good
management can instead prove foreseeability and failure to act.
That is one of the reasons vulnerability matters so much. It moves the conversation beyond whether an organisation can describe a system and towards whether that system was truly capable of bearing the pressure placed upon it.
The System on Paper and the System Under Pressure
One of the places vulnerability grows most quietly is in the gap between the formal system and the operating system.
The formal system is what the organisation can point to. It sits in procedures, inductions, training packages, standards, risk assessments, permit systems, role descriptions, forms, and assurance reports. It reflects how the organisation intends work to be done and how risk is supposed to be controlled.
The operating system is what happens when the job meets reality. It is shaped by production demands, fatigue, weather, access constraints, competence, time pressure, contractor interfaces, equipment condition, supervision quality, and human judgement. It is the system that exists in workshops, warehouses, forests, vessels, construction sites, plant rooms, roads, and processing environments where exposure to hazardous energy is real.
The problem is not that reality is untidy. All meaningful work contains variation. The problem arises when the organisation assumes that the formal system and the operating system are closely aligned when, in critical areas, they are not.
That is where vulnerability takes hold.
A control may exist in a procedure but not in reliable practice. A pre-start check may be required but routinely abbreviated. An exclusion zone may be specified but difficult to maintain in a live job. A permit may be formally required but treated in practice as an administrative routine. A risk assessment may record strong separation from the hazard while the work actually depends on verbal coordination, timing, judgement, and people noticing when things begin to drift.
In these situations, the organisation may still believe the hazard is well managed because the formal system looks complete. But the real test is not whether the system can be described. The real test is whether it is operating reliably where the hazard exists.
Vulnerability grows when documented intention is mistaken for actual protection.
When Controls Become Vulnerabilities
Controls do not remain effective forever. They drift, degrade, fatigue corrode, go out of adjustment, are bypassed, misunderstood, or only partially implemented. They may be weakened by poor design, by production pressure, or simply because the organisation stops really seeing them; they become familiar, assumed, and unexamined.
Seen another way, organisations are always working against a quiet entropic pull: the gradual tendency for systems, controls, and assumptions to move away from their intended condition unless energy, attention, and verification are continuously applied. Entropy, and its implications for safety systems over time, deserves more attention than this article can give it. It is something we will return to in a future article.
This matters because controls are often treated as though their mere existence is evidence of protection. In reality, controls are part of a living system. They must be implemented, maintained, verified, and understood in context. If they are not, the control itself can become a source of vulnerability.
A procedural control that no longer reflects the way work is actually carried out becomes vulnerable. A permit system that is routinely treated as paperwork becomes vulnerable. A guarding solution that is removed or compromised to maintain output becomes vulnerable. A reliance on training as the primary defence against serious energy transfer becomes vulnerable the moment worker attention, recall, judgement, or situational awareness is weakened by fatigue, ambiguity, haste, or pressure.
There is also a cumulative point here. Controls can absorb only so much reliance, so many cycles, and so much operational variation before their strength begins to weaken. A barrier that is repeatedly depended upon without reinforcement, redesign, maintenance, or verification may remain visible while no longer being robust. In that sense, a control can still be present and yet no longer be trustworthy.
This is one of the most important distinctions for leaders to understand. The existence of controls is not the same as control integrity. The presence of documentation is not the same as system strength. A control environment can look mature at a distance while containing deep vulnerability close up.
When Strong Systems Still Do Not Remove Exposure
At the same time, vulnerability cannot be reduced simply to poor systems or weak documentation. Our review has also identified the opposite kind of case: situations where a court accepted that a company’s systems were robust, appropriate, and in some respects ahead of legislative requirements, yet the organisation was still prosecuted, convicted, and sentenced.
In at least one such prosecution, liability did not arise from any broad failure in policy, procedure, training framework, or emergency design. On the contrary, the court accepted that the company’s systems for managing the relevant risk were strong. Conviction followed because a senior employee, acting within the scope of his work, made a series of unreasonable decisions, and those acts were legally attributable to the company. What reduced sentence was not the absence of liability, but the court’s acceptance that the systems were robust, that the business had tried to stand ahead of minimum requirements, that it was not complicit in the unreasonable decisions, and that the conduct appeared to be a one-off aberration rather than evidence of deeper organisational failure.
This is an important counterpoint, because it shows that vulnerability is not always located in an obviously weak system. Residual exposure may still sit in human judgement at the edge of operations, in the limits of direct supervision, and in the legal reality that a PCBU may remain liable for unreasonable acts or omissions carried out on its behalf by those acting within their authority. Strong systems matter greatly. They may reduce exposure, improve response, and mitigate sentence. But they do not eliminate vulnerability entirely.
That is a difficult truth for leaders, but an important one. Safety maturity is not the same as immunity from harm, prosecution, or attribution. Even robust systems can still be tested by the decisions of individuals operating in live, time-sensitive conditions.
Thetis and the Importance of Residual Capacity
A powerful illustration of vulnerability is found not only in how systems fail, but in the condition they are left in once failure begins.
In 1939, the British submarine HMS Thetis sank during sea trials after the inner door of a torpedo tube was opened while the outer door to the sea was also open. A small amount of paint had blocked a test cock used to confirm whether the tube was flooded, contributing to a false indication. Water entered the submarine, flooding the forward compartments and causing it to sink.
The example is valuable because it captures something important beyond the initiating event. The initial failure was grave, but it was not instantly unsurvivable. Air remained in the rear compartments. Rescue was possible in principle. Men survived the flooding. But rescue depended on signalling the surface, managing the atmosphere inside the vessel, making sound decisions under severe stress, and external responders understanding the situation rapidly enough to act effectively. Carbon dioxide rose. Time narrowed. Options diminished.
Of the 103 men on board, 99 died.
What makes Thetis particularly instructive is the contrast with USS Squalus, which had sunk only a week earlier. In that case, crew were successfully rescued. One of the important differences was not simply the initiating failure, but the condition in which the submarine came to rest. Squalus settled on an even keel, allowing a diving chamber to be used. Thetis came to rest at a severe angle, which made that method impracticable.
That distinction is critical. Vulnerability is not only about what causes the initial event. It is also about what remains possible once the event has begun. It concerns the residual capacity left within the system after failure. Can the system stabilise? Can rescue reach it? Can people communicate? Can they breathe? Can emergency plans still function? Can failure be contained, or does it rapidly become catastrophic?
Two similar events can produce very different outcomes because vulnerability and capacity are different.
This has direct relevance to safety risk management. A fall may be survivable or fatal depending on arrest systems, rescue readiness, communication, suspension trauma management, and access. A vehicle rollover may be survivable or catastrophic depending on restraint, terrain, speed, isolation, and retrieval capability. A hazardous atmosphere may be escaped or become fatal depending on detection, alarms, procedural discipline, rescue planning, and the realism of emergency arrangements. A control failure is never the whole story. The condition of the system after failure begins is often what determines the magnitude of harm.
Financial Vulnerability: The Second Event
There is another dimension of vulnerability that is rarely discussed in occupational health and safety, yet it matters deeply, particularly for business owners and smaller enterprises. That is financial vulnerability after an incident.
In one industry sample we reviewed, the average fine endpoint after discounts following a health and safety prosecution was approximately $388,000. For a business operating on a 5% profit margin, that equates to approximately $7.7 million in revenue required simply to recover the cost of the fine. Put another way, the business would need to generate revenue equivalent to about twenty times the fine just to return to where it started. That is not a minor commercial inconvenience. It is a second event. More concerning still, our review of prosecutions within that sample showed that approximately 38% of defendants advanced evidence of financial incapacity or were unable to meet the fine that would otherwise have followed. Around 17% of companies were recorded in the case material as being in liquidation, or moving into liquidation, during the prosecution process.
The first event is physical, human, and operational. The second is legal, financial, emotional, and organisational. Investigation begins. Lawyers are engaged. Time passes. Projects are disrupted. Relationships strain. Insurers become involved. Directors experience prolonged uncertainty. Operational confidence may falter. Reputation can suffer. The prosecution timeline may run for years rather than months.
These patterns matter because vulnerability does not end with the moment of injury. It propagates. A company already operating with tight margins may have very little capacity to absorb prosecution costs, interruption, delay, and stress over a long period. Suppliers may be affected. Workers may leave. Maintenance and investment may be deferred. Pressure may spread into the wider market. In that sense, vulnerability can move beyond the incident itself and into the economic life of the business and the sector around it.
For many owners, this is not abstract. A business may represent years of personal risk, long hours, financial trade-offs, family sacrifice, and the dream of creating independence, security, and a better future through successful ownership. A serious event therefore does not simply create statutory consequences. It can destabilise the economic and emotional foundation of the enterprise itself, and threaten the very future the business was meant to secure.
That too belongs in the vulnerability conversation.
Vulnerability and Governance
For leaders, introducing vulnerability into safety changes the nature of the questions that need to be asked.
Not simply:
Have we identified the hazard?
Have we completed a risk assessment?
Do we have procedures?
Have we trained people?
But rather:
Where are we most exposed?
Which hazards involve the greatest transfer of harmful energy and the least margin for error?
What controls are we relying on most heavily, and how strong are they in practice?
How much variation, pressure, or change can this system tolerate before vulnerability increases?
If we add, remove, stretch, or relocate something — plant, people, contractors, supervision, or production demand — what happens to capacity?
How would we know the system was drifting or operating close to its limits?
If a key control failed tomorrow, could we still contain the event, rescue effectively, and recover?
Those questions shift due diligence away from paperwork alone and towards verification, integrity, system condition, and tolerance. They move leadership from asking whether a system exists to asking whether it remains trustworthy under pressure, variation, and change.
This is particularly important because many of the most serious events do not arise in areas of complete ignorance. They arise in areas the organisation believed it understood. That is why vulnerability matters so much. It challenges assumption. It reveals overconfidence. It distinguishes between stated protection and real protection.
The task for leadership is therefore not to eliminate all vulnerability. No complex system can do that. The task is to understand vulnerability more truthfully, especially where hazardous energy, exposure, and consequence converge. It is to know where capacity is strong, where it is thin, where it is being eroded, where tolerances are narrowing, and where administrative confidence may be outrunning operational reality.
Towards a Stronger Risk Practice
If vulnerability is a missing dimension in OHS risk management, what would a stronger approach look like?
It would begin by recognising that hazards, controls, and residual scores are not enough on their own. It would examine the susceptibility of the exposed target, the strength and integrity of barriers, the degree of behavioural dependence within the system, the effect of pressure and drift, and the real capacity available if prevention fails.
It would distinguish more clearly between controls that prevent energy transfer and controls that merely influence behaviour around the hazard. It would treat verification as a central discipline rather than an administrative afterthought.
It would pay closer attention to degradation, fatigue, maintenance, substitutions, adaptations, contractor realities, and the gap between what is documented and what is reliably done.
It would ask whether emergency response and recovery capacity are genuinely robust, not just theoretically described.
It would challenge the comfort created by long control lists and low residual scores where those ratings are based on assumption rather than demonstrated performance.
It would also accept that vulnerability exists at multiple levels: within people, within plant, within interfaces, within contractor arrangements, within emergency systems, and within the commercial resilience of the organisation itself.
Most importantly, it would accept that safety is not strengthened by optimism. It is strengthened by accuracy.
Closing Thoughts
Serious harm events rarely occur because a hazard was completely unknown. More often, they occur because vulnerability existed within the system and was not fully understood, not fully respected, or not truthfully seen. Controls were assumed to be stronger than they were. Capacity was assumed to be greater than it was. The organisation believed the system would hold. Then reality tested it.
That is why vulnerability deserves far greater attention in occupational health and safety.
It helps explain why two organisations facing similar hazards can experience very different outcomes. It helps explain why extensive documentation can coexist with serious failure. It helps explain why a green box on a risk register may conceal fragile assumptions. It helps explain why the condition of the system after failure begins can determine whether an event remains survivable or becomes catastrophic. It even helps explain why an organisation with robust systems may still be exposed through the unreasonable decisions of those acting on its behalf, and why legal liability can remain even where broader system strength is judicially recognised.
Most of all, it moves the conversation from administrative comfort to practical truth.
The question is not simply whether hazards exist. Every meaningful operation contains hazard.
The deeper question is this:
How vulnerable are we to the hazards we already know about, and what real capacity do we have when our controls are tested?
That, perhaps, is the missing dimension in safety risk management.
Author Note
Perennia Forge is a New Zealand risk advisory business focused on hazard and vulnerability intelligence, critical risk, and practical judgement about whether safeguards are likely to remain trustworthy when conditions tighten and consequences are real.
References
Office of the United Nations Disaster Relief Co-Ordinator (UNDRO). (1991).
Mitigating natural disasters: Phenomena, effects and options: A manual for
policy makers and planners. New York: United Nations.
Ebener, S. (2009, 12 August). Vulnerability and Risk Analysis and Mapping (VRAM) Platform for Health Risk Reduction [presentation]. Ninth United Nations Regional Cartographic Conference for the Americas, New York.
Alexander, D. (2013). Vulnerability. In K. B. Penuel, M. Statler, & R. Hagen
(Eds.),Encyclopedia of Crisis Management (pp. 980–983). Thousand Oaks,
CA: SAGE.
Kazmierczak, A., & Handley, J. (2011). The vulnerability concept: Use within GRaBS. Briefing paper. Manchester, UK: School of Environment and Development, University of Manchester.
Adger, W. N. (2006). Vulnerability. Global Environmental Change, 16(3), 268–281.
Blaikie, P., Cannon, T., Davis, I., & Wisner, B. (2004). At Risk: Natural Hazards, People’s Vulnerability and Disasters (2nd ed.). London: Routledge.
United Kingdom Parliament. (1939, 5 June). Loss of His Majesty’s Ship “Thetis”. Hansard.
Royal Museums Greenwich. (n.d.). HMS Thetis (1938): Warship; T-Class submarine.
La VO, C. (1988, April). The short life of the Squalus. Naval History.
.png)
