What this is
What counts as a critical control failure?
What counts as a critical control failure?
A critical control failure is any state where a named barrier between a hazard and a fatality is found missing, bypassed, or present but not working — whether that's discovered through routine verification, an observation, a worker report, an audit, or during an incident itself.
What's the difference between a bypass and a passive failure?
A bypass is a deliberate act — someone switched the control off, propped it open, or worked around it. A passive failure is a control that stopped working on its own, through wear, a fault, or a missed maintenance step. The report treats them differently because the fix for one is behavioural and the fix for the other is engineering or maintenance.
Why is this treated as a high-potential event even when no one was hurt?
Because the outcome that time was down to circumstance, not the barrier doing its job. A fatal-risk programme scores a control failure against what could have happened if the exposure had lined up differently, not against the fact that it didn't this time.
Scope
When is a control failure report required?
This record is one step in a larger programme. Using it for work that belongs to a neighbouring template produces records that are hard to report on later.
Use this template when
- A critical control has been found missing, bypassed or not working, however it was discovered
- A new record is needed; each one gets its own ID in the form CASE-2026-000
- You are running the Critical Control and Fatal Risk programme and this is one of its steps
- The failure needs an immediate response recorded — work stopped, control restored, or an interim control applied
- A linked record needs this one to exist: feeds RCA, CAPA
Do not use it for
- Critical Control Verification, which checks a control is in place and working on a schedule, before anything has gone wrong
- Critical Control Performance Review, which reviews how a set of controls performed over a period, not a single failure
- Barrier Health Check, which works through a bowtie one branch at a time rather than reporting a single event
- Critical Control Owner Review, which is the owner's annual confirmation the control is still right, not a failure report
- Anything outside KnowSafe, which belongs in the workspace that owns that process
Compliance mapping
Which ICMM requirements does this satisfy?
The requirements below come from ICMM's critical control guidance and ISO 45001's incident-handling clause, mapped onto the sections that actually appear in this form.
| Clause | Requirement | Where it lands |
|---|---|---|
| ICMM Critical Control Management Good Practice Guide – control identification | Every critical control is named and given a control ID before it can be reported against | Header |
| ICMM Critical Control Management Good Practice Guide – verification and failure reporting | How the failure was found — verification, observation, worker report, audit or incident — is recorded alongside the description | The failure |
| ISO 45001:2018 Clause 10.2 – Incident, nonconformity and corrective action | Exposure to the failed control, and the number of people potentially exposed, is captured even when no one was hurt | The failure |
| ICMM Critical Control Management Good Practice Guide – deliberate bypass | A deliberate bypass is distinguished from a passive failure, with the reason and how widespread it was recorded separately | If bypassed |
| ICMM Critical Control Management Good Practice Guide – just culture | A confirmed bypass triggers a linked just-culture determination rather than an assumption of blame | If bypassed |
| ISO 45001:2018 Clause 10.2 – Incident, nonconformity and corrective action | Work is stopped and the control restored, or an interim control applied, before the report can move to closure | Immediate response |
| ICMM Critical Control Management Good Practice Guide – investigation and RCA | Investigation level is set by potential severity, not by what actually happened, and links to a root cause record | Immediate response |
| ICMM Critical Control Management Good Practice Guide – corrective action | A required action is raised as its own CAPA record with an owner and priority before the report is signed off | Immediate response |
What it does not cover
- Failure Type left blank, which drops the one clue that ties this report to a specific verification method when the RCA looks for a pattern.
- Work Exposed To The Risk answered No by default, which hides how many shifts ran with a barrier down before anyone noticed.
- Bypass Widespread left unanswered after a Yes to deliberate bypass, which is the one field that tells you whether the control itself is badly designed.
- Investigation Level set below what the potential severity warrants, which trades a real root cause analysis for a quick debrief because nothing actually happened.
- CAPA ID missing after Action Required is marked Yes, which leaves a corrective action with no record anyone can chase to closure.
Global
Control Failure Report requirements by country
How this report is read outside the site depends on which regime is deciding whether the barrier failure proves the duty of care was being met.
Work Health and Safety Act 2011 (model law), s19 duty of care
A critical control failure is read as evidence bearing directly on whether the PCBU was eliminating or minimising risk so far as reasonably practicable
The report needs to stand on its own as proof the duty was being met, not just as an internal near-miss note
Health and Safety at Work etc. Act 1974, s2 and s3
Inspectors read a pattern of unreported control failures as evidence that a risk assessment was never kept live
Each failure report is part of the paper trail that a risk assessment was acted on, not filed and forgotten
ICMM Critical Control Management Good Practice Guide (2015)
Failure reporting is the verification half of the bowtie: a barrier is only credible if its failures are visible
Sites outside mining that borrow this framework take on the same expectation — a barrier that fails silently is treated as if it does not exist
How to complete it
How to complete a control failure report, step by step
Four judgement calls decide whether this report holds up later, and none of them are about which box to tick.
How Long Has It Been Like This only works if the reporter is willing to say 'weeks' when that is the honest answer. A supervisor who defaults every report to 'discovered today' is quietly protecting the site's verification record rather than the workforce.
A control that was switched off is a different problem from one that quietly stopped working. Recording Was It Deliberately Bypassed honestly, even when it implicates a colleague, is what lets the reason field and the just-culture link do their job.
Investigation Level is meant to follow potential severity, not the fact that nobody was hurt this time. Downgrading a full RCA to a quick debrief because the outcome was lucky is the single most common way this record loses its teeth.
Bypass Widespread is the field that reframes the whole report. If bypassing is common practice, the fix belongs with whoever designed the control, not with the person who happened to be caught.
What auditors find
Most common control failure report findings
The same handful of gaps recur across sites running this record.
| Finding | Clause | What fixes it |
|---|---|---|
| Failure reports raised only after an incident, never on their own | ICMM Critical Control Management Good Practice Guide – verification and failure reporting | Route routine verification failures and worker reports into this same form, not just post-incident write-ups |
| Investigation Level downgraded once the outcome is known | ISO 45001:2018 Clause 10.2 | Lock Investigation Level to the potential-severity rating agreed at intake, before the outcome is known |
| Bypass reason recorded but Bypass Widespread left blank | ICMM Critical Control Management Good Practice Guide – deliberate bypass | Make Bypass Widespread mandatory whenever the deliberate-bypass field is Yes |
| Interim control applied but never described | ICMM Critical Control Management Good Practice Guide – control restoration | Require Interim Control Detail whenever Interim Control Applied is Yes, not just a Yes/No flag |
| CAPA raised without an owner | ISO 45001:2018 Clause 10.2 | Block sign-off until Action Owner is populated whenever Action Required is Yes |
| Extent of condition never checked for the same control at other sites | ICMM Critical Control Management Good Practice Guide – control identification | Treat Extent Of Condition ID as required whenever the control in question exists at more than one site |
Case in point
Case in point: a chill store door interlock that failed twice before anyone asked why
A door interlock in a chill store was found propped open during a routine verification. It was logged as a control failure, restored within the shift, and closed with a quick debrief because no one was exposed. Six weeks later the same interlock failed again, this time during an audit.
The second report finally triggered a full RCA, which found the interlock had been propped for years whenever the pallet truck needed to pass through — a workaround so routine that three different shifts assumed it was sanctioned. The fix was a wider doorway, not a reminder to keep it shut.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
4 sections
- Reference
- SAF-082
- Archetype
- Record
- Record ID
- CASE-2026-000
- Scoring
- Potential severity
- Direction
- High is bad
- Singleton
- No
- Basis
- ICMM
- Links
- Feeds RCA, CAPA
- Tags
- Critical risk, Incident
- Sections
- 4
- Fields
- 39
- Follow up fields
- 9
- Repeating sections
- 0
- Links out
- 6
Header
11 fieldsReport ID*
Auto sequence. Format CASE-2026-00000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Area*
The area within the site.
Exact Location
Drop a pin for anything hard to find.
Treat This As An Event
A critical control found missing, bypassed or not working is treated as seriously as an injury, because the only thing between that and a fatality was circumstance.
Critical Control
Control ID
Format CCTRL-000.
Links to FDN-011 Control ID
The failure
7 fieldsHow It Was Found*
Verification, observation, incident, audit or worker report.
- Routine verification3 pts
- Observation3 pts
- Worker report3 pts
- Audit2 pts
- During an incident0 pts
Failure Type*
Description*
Photograph
How Long Has It Been Like This*
- Discovered today2 pts
- Days1 pt
- Weeks0 pts
- Unknown0 pts
Work Exposed To The Risk*
- No3 pts
- Possibly1 pt
- Yes0 pts
People Potentially Exposed*
If bypassed
4 fieldsWas It Deliberately Bypassed*
Why It Was Bypassed
Slows the job, equipment faulty, no alternative, or unaware it mattered.
Bypass Widespread
If everyone bypasses it, the control is badly designed.
- No, isolated2 pts
- Some people1 pt
- Yes, common practice0 pts
Just Culture ID
Links to FDN-017 Determination ID
Immediate response
17 fieldsWork Stopped*
- Not required3 pts
- Yes2 pts
- No0 pts
Control Restored*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Interim Control Applied
- Yes2 pts
- No0 pts
Interim Control Detail
Investigation Required*
Set by potential outcome, not by what actually happened.
- No3 pts
- Yes0 pts
Investigation Level
RCA ID
Format RCA-2026-00000.
Links to FDN-013 RCA ID
Extent Of Condition ID
Check whether the same control has failed elsewhere.
Links to FDN-018 Review ID
Bowtie Review Needed*
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Reported By*
Signature*
Control Owner*
Second Signature*
SAF-082 · record IDs look like CASE-2026-000 · Feeds RCA, CAPA
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The form is the easy part. Keeping it current, routing it to the right owner and holding the evidence together is the work that actually slips.
Holds the control failure register against the critical control list, and won't let a report close without a Site, Control ID and Investigation Level attached.
Cross-checks failures found through ATP or allergen swabs against the quality programme, so a control failure and a quality deviation don't get logged as two unrelated events.
Picks up 'equipment faulty' bypass reasons and interim controls, and turns them into a work order instead of a note that gets forgotten.

Coordinates the crew, rolls completion and exceptions into one view, and holds every write for your approval before it touches a record.
This template lives in KnowSafe — safety and compliance. Incidents, hazards, permits, inspections and the critical controls behind them.
Meet KnowSafe→Glossary
Control Failure Report definitions and key terms
- Critical control
- A barrier identified as one of the small number of controls that, if it fails, removes the last thing standing between a hazard and a fatality.
- Bowtie
- A diagram that maps a threat to its consequences through the barriers, or critical controls, sitting between them, used to identify which controls actually matter.
- Verification
- A planned check that a critical control is present and working, as distinct from an incident that reveals it was not.
- Just culture
- A framework for deciding whether a person who bypassed a control acted recklessly, made an honest error, or was following an unsafe workaround the organisation had tolerated.
- Extent of condition
- A check for whether a failure found in one place is also present elsewhere, run before assuming a fix in one location has solved the problem.
FAQ
Frequently asked questions about control failure report
What is the control failure report template based on?+
It is built against the ICMM Critical Control Management Good Practice Guide, a mining-sector framework for fatal risk control that is now widely borrowed outside mining.
What sections does the control failure report contain?+
There are 4 sections: Header, The failure, If bypassed, Immediate response. Together they hold 39 fields, 23 of which are required.
How often is a control failure report raised?+
A new record is raised at the moment the event happens, rather than reconstructed afterwards. Each one is given an ID in the form CASE-2026-000, so it can be traced and referenced from other records.
Which programme does the control failure report belong to?+
It is part of Critical Control and Fatal Risk: named fatal risks with owned critical controls and a verification schedule that is actually run.
Does the report score severity even if nobody was hurt?+
Yes. Scoring runs on potential severity, where high is bad, precisely because the actual outcome that day was often down to luck rather than the control holding.
Can the control failure report template be changed?+
Yes. Every field, option, score and conditional rule is editable, and the links to RCA and CAPA come with it. Most teams install it as it is, run it for a cycle, then adjust.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Critical Control and Fatal Risk
Bow Tie Analysis Record
Maps threats, the top event, consequences and the barriers on each side for a major hazard
Barrier Health Review
Reviews whether the barriers relied on in a bow tie are actually in place and working
Critical Control Register
Lists the controls that stand between your people and a fatal or catastrophic event, with an owner and a required check frequency for each
Risk Assessment
The single risk assessment used across the whole business
Serious Potential Incident Report
Used when an event could have killed or seriously injured someone, whatever the actual outcome
Job Safety Analysis
Breaks a job into steps, finds the hazards in each and sets the controls
More in Critical Controls
Critical Control Verification
Checks that a control standing between people and a fatal event is actually in place and working
Critical Control Performance Review
Reviews how a set of critical controls has performed over a period, including verification rates and failures
Barrier Health Check
Checks the barriers named in a bowtie are present and effective, working through the bowtie one branch at a time
Fatal Risk Protocol Audit
Audits compliance with a fatal risk protocol such as working at height, energy isolation or mobile equipment
Critical Control Owner Review
The named owner of a control confirms it is still the right control, still resourced and still working

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ICMM — Critical Control Management Good Practice Guide (2015)
- ISO 45001:2018 — Clause 10.2, Incident, nonconformity and corrective action
- ICMM — International Council on Mining and Metals
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.