The Risk Ratchet: How Normal Work Drifts Toward a SIF
A serious event rarely begins with one dramatic failure. More often, the system weakens, the work still succeeds, and yesterday’s exception becomes tomorrow’s normal.

Production did not stop, so the weakness became acceptable
Imagine a pump whose condition is slowly worsening. A seal shows early leakage. A guard fastener loosens. The inspection route is shortened during a busy week. None of these changes stops production, and nobody is injured. The plant learns the wrong lesson: the system still works.
This is where many safety discussions become too narrow. One view treats degradation as a maintenance problem. Another treats repeated shortcuts as a behaviour problem. A SIF lens shows that they can reinforce each other. The physical system loses margin while people become less sensitive to the loss. Continued success then appears to validate both.
Two useful ideas, one dangerous interaction
An earlier EHS Today article described an Entropy Model that separates residual risk from risk created as processes, technology, the physical environment and human resources degrade. Its central business argument remains useful: deterioration can threaten safety, quality and output at the same time. Maintenance, competence and system renewal are production controls as well as safety controls.
Rick Tobin’s later account of risk normalization adds the perceptual mechanism. Repeated exposure without a bad outcome can make a hazardous condition feel acceptable. Experience improves judgment and skill, but past success can also make a weak signal easier to dismiss. The point is not that experienced workers are careless. All people update their beliefs from outcomes, and a safe outcome may be produced by luck, remaining margin or a control that almost failed.
Taken together, these ideas support a practical proposition: system degradation increases the opportunity for failure while normalization reduces the chance that people will recognize and reverse it. High-energy exposure determines whether that combination can become a serious injury or fatality.
The HSE Hub Risk Ratchet
The Risk Ratchet is an original HSE Hub practice model. It is a proposed framework for structured discussion, not a validated predictive equation or a replacement for formal risk assessment. It describes four linked movements:
- Margin erodes. Equipment wears, staffing changes, access worsens, procedures age, temporary arrangements remain, or competence becomes uneven.
- Work adapts. People find a way to keep the task moving. Some adaptations are skilful and necessary. Others bypass, weaken or place extra demand on a control.
- Success confirms the adaptation. The job finishes without harm. That outcome is interpreted as evidence that the revised method or degraded condition is safe enough.
- The new baseline hardens. The exception becomes customary. Future planning assumes the reduced margin, so the next adaptation begins from a weaker position.
The ratchet moves because operational success is visible and immediate, while lost protection is often hidden. Resetting it requires two actions together: restore the control and correct the organization’s understanding of what successful work has actually proved.
Where SIF changes the priority
Not every deviation has equal consequence. SIF prevention asks whether credible high-consequence energy or hazardous material can reach a person, and whether the controls preventing that transfer are present and effective. Examples include suspended loads, mobile equipment, electrical energy, pressure, gravity, confined atmospheres, fire and explosion hazards, and toxic releases.
A loose office drawer and a degraded crane braking system may both demonstrate deterioration. Only one presents a credible fatal pathway. The Risk Ratchet must not become a campaign to correct every defect with equal urgency. Use it first where there is SIF potential, then identify the few critical controls whose failure would materially increase the likelihood or consequence of the unwanted event.
IOGP’s Life-Saving Rules provide clear worker-level actions for common fatal risks. They are most effective when the organization supplies the planning, equipment, isolation, supervision and stop-work conditions needed to follow them. A rule cannot compensate indefinitely for a degrading system.
Early signals are operational, not only statistical
A low injury rate cannot show whether the ratchet is moving. US OSHA recommends using leading indicators to identify and correct weaknesses before an incident occurs. For SIF exposure, useful signals are specific to control performance:
- critical controls unavailable, bypassed or outside their defined performance standard;
- repeat temporary repairs and overdue safety-critical maintenance;
- work permits repeatedly extended or changed after work starts;
- high-potential near misses with low reporting or slow corrective action;
- routine dependence on individual vigilance where an engineered control was expected;
- differences between the procedure, the plan and the method people actually use;
- production plans that rely on degraded equipment or reduced operating margin.
Counts alone are weak. A useful indicator has a defined owner, threshold and response. “Critical-control checks completed” measures activity. “Percentage of lifting operations where exclusion-zone integrity was independently verified before the lift” is closer to control health.
A near miss is evidence, not reassurance
When a high-energy event misses a person by chance, the absence of injury is not proof of effective control. Ask what prevented harm. If the answer is timing, distance, weather, an unplanned intervention or luck, the event is a warning about potential outcome.
A sound review separates actual consequence from credible potential. It reconstructs energy sources, exposure, control status and the conditions that shaped decisions. It also asks how long the condition existed and how many successful repetitions made it feel ordinary. This turns “nothing happened” into usable information without exaggerating every near miss into a fatal scenario.
Break the ratchet without blaming the workforce
Blaming the last person who adapted the work hides the mechanism. Leaders should test four things:
- Control reality: Is the critical control available, functional and used as intended?
- Operating pressure: What target, delay, staffing condition or resource gap makes the weaker method attractive?
- Normalization history: How often has this happened without consequence, and who knows about it?
- Restoration quality: Did the response restore durable margin, or add another instruction that depends on memory?
Workers still have responsibilities, including following applicable controls and stopping where there is immediate serious danger. Fair accountability distinguishes deliberate misuse from adaptation encouraged by the way work is designed, resourced or supervised.
A 30-minute field review
Select one current task with credible SIF potential. In ten minutes, ask the team to name the unwanted event, energy source and critical controls. In the next ten, inspect those controls where the work occurs. Look for deterioration, temporary measures and differences between the written and actual method. In the final ten, ask: What has become normal here? What are we relying on that is weaker than it appears? What must be restored before the task continues?
Record facts and uncertainties separately. Stop and escalate any immediate serious danger through the site’s approved process. For other gaps, assign an owner and verification date. Do not close an action because a repair order was raised. Close it when the control meets its defined performance requirement in the field.
The theory in one sentence
A SIF becomes more credible when system margin degrades, successful work normalizes the degradation, and people remain exposed to consequential energy without reliably verified critical controls.
This statement does not predict when an incident will occur. It tells leaders where to look before one does: declining margin, repeated adaptation, misleading success and weak control verification. Safety and productivity meet at the same point. Reliable systems protect people and produce consistently. Degraded systems eventually fail one, the other, or both.
Leadership takeaway
Do not ask only whether work was completed or whether anyone was hurt. Ask what margin was consumed, what adaptation became normal and whether every critical control performed to its standard. Restore the system before successful exposure becomes the organization’s proof that the risk is acceptable.
Sources & Further Reading
Author/editor: Myaser HSE Hub Editorial
Published and reviewed: August 4, 2026
Editorial note: The Risk Ratchet is an original Myaser HSE Hub practice model developed by synthesizing the cited concepts. It has not been validated as a scientific accident-prediction model.
Disclaimer: This article provides general HSE education. Apply applicable law, standards, engineering judgment and competent professional advice to your operation.