Knowella

Critical Control Owner Review

The failure mode here is delegation. An owner who forwards this review to a deputy, or answers from memory instead of checking the verification numbers, turns an accountability mechanism into a formality. The whole point of naming an owner is that one person stakes their name on a control's condition once a year — hand it off, and the control has quietly become nobody's job again.

KnowSafeReviewSAF-08333 fields across 4 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ICMM
Workspace
KnowSafe
Form type
Review
Review trigger
Yearly per control, and after any trigger event
Completed by
The named control owner, with the risk lead

The short version

  • A critical control owner review is the annual, named-owner confirmation that a control still addresses its threat, is still resourced, and is still working, carried out with the risk lead.
  • It runs yearly per control, and again after any trigger event such as a threat change or a failure.
  • The template holds 33 fields across 4 sections, 25 of which are required, and links directly to the Critical Control Register.
  • It is not scored for overall severity the way a failure report is; the resourcing and performance questions carry weighted answers, but there is no single pass/fail threshold.

What this is

What is a critical control owner review?

What is a critical control owner review?

It is the annual check where the named owner of a critical control states, in their own words, whether the control still addresses its threat, is still resourced, and is still working. It is carried out with the risk lead, not delegated to them.

How is this different from a critical control verification?

A verification is a routine field check that the control is physically present and functioning. An owner review is a governance check — it asks whether the control is still the right one, still funded, and still staffed, questions a field check cannot answer.

Why does the owner have to answer personally?

Because the review exists to stop a control quietly becoming nobody's job. If someone other than the named owner can answer on their behalf, the accountability the role was created for has already been lost.

Scope

When is a critical control owner review required?

This review is one step in a larger programme. Using it for work that belongs to a neighbouring template produces records that are hard to report on later.

Use this template when

  • A named control has reached its annual review date, or a trigger event such as a threat change or a failure has occurred
  • A new record is needed; each one gets its own ID in the form CCOR-2026-000
  • The named owner is available to answer personally, alongside the risk lead
  • You are running the Critical Control and Fatal Risk programme and this is one of its steps
  • A linked record needs this one to exist: links Critical Control Register

Do not use it for

  • Control Failure Report, which is raised the moment a control is found missing, bypassed or not working, not on a yearly cycle
  • Critical Control Verification, which is a routine field check that a control is present and working, not a governance review
  • Critical Control Performance Review, which reviews a set of controls' verification rates and failures over a period, not one owner's judgement
  • Barrier Health Check, which works through a bowtie one branch at a time rather than reviewing a single control's ownership
  • Anything outside KnowSafe, which belongs in the workspace that owns that process

Compliance mapping

Which ICMM requirements does this satisfy?

The requirements below come from ICMM's critical control guidance, read alongside the accountability provisions most WHS regimes attach to a named duty holder.

ClauseRequirementWhere it lands
ICMM Critical Control Management Good Practice Guide – control ownershipThe named Control Owner answers personally, with Owner Since recorded so accountability can be traced over timeHeader
ICMM Critical Control Management Good Practice Guide – control identificationThe review is tied to a specific Control ID from the register, not answered generically for the siteHeader
ICMM Critical Control Management Good Practice Guide – control reviewWhether the control still addresses the threat, whether the threat has changed, and whether a better control now exists are answered as three separate judgementsIs it still the right control
ICMM Critical Control Management Good Practice Guide – resourcingBudget, trained people, and spares or equipment are each confirmed separately rather than assumed from the control simply existingIs it resourced
ICMM Critical Control Management Good Practice Guide – maintenance and verificationMaintenance tasks and the verification frequency are both re-tested for whether they are still appropriate, not just whether they are being doneIs it resourced
ICMM Critical Control Management Good Practice Guide – performance evidenceVerification compliance, failures and bypasses for the year are entered as numbers before the owner states a confidence levelIs it working
ISO 45001:2018 Clause 9.1 – Monitoring, measurement, analysis and performance evaluationA required action is raised with a priority and CAPA reference before the review can be signed offIs it working
ICMM Critical Control Management Good Practice Guide – governance sign-offThe review closes with the owner's signature and a second signature from the site managerIs it working

What it does not cover

  • Owner Statement written before Verification Compliance This Year is entered, which means the confidence claim isn't actually grounded in the year's numbers.
  • Better Control Now Available answered No without comment, which is the field most likely to be skipped rather than genuinely considered.
  • Owner Since left blank, which makes it impossible to tell whether this is a first review or the fifth by the same person.
  • Verification Frequency Still Appropriate marked Pass by default, which quietly re-approves a schedule nobody has actually reconsidered.
  • Second Signature obtained from someone other than the site manager, which breaks the governance chain the review depends on.

Global

Critical Control Owner Review requirements by country

How this review reads to a regulator depends on how each regime treats a named owner's annual sign-off as evidence of active oversight.

Australia

Work Health and Safety Act 2011 (model law), s27 officer due diligence

An annual, named-owner review is close to what due diligence means in practice for a fatal risk — proof an officer is keeping themselves informed

A review answered by a deputy weakens the due-diligence evidence the whole record exists to create

United Kingdom

Health and Safety at Work etc. Act 1974, s2 and s3

HSE inspectors treat named ownership as evidence a risk assessment is a living document rather than a filed PDF

The yearly review is the mechanism that keeps the risk assessment current in the eyes of a regulator

International (ICMM members and adopters)

ICMM Critical Control Management Good Practice Guide (2015)

Owner review is the governance layer ICMM sits above verification: it asks whether the whole arrangement, not just the hardware, is still sound

Sites borrowing the framework outside mining take on the same expectation that ownership is reviewed, not just the control itself

How to complete it

How to complete a critical control owner review, step by step

Four judgement calls decide whether this review is a genuine accountability check or a formality.

Whether the owner is answering, or a deputy is

The Owner Answers Personally note exists because the whole mechanism collapses if someone else fills this in on the named owner's behalf. A review completed by a deputy should be treated as not having happened.

Whether 'still the right control' gets a real answer

Better Control Now Available is easy to wave through as No. Taking it seriously means checking what other sites or the wider industry have adopted since the control was first chosen, not just confirming the status quo.

Whether resourcing is verified or assumed

Budget In Place, People Trained And Available and Spares And Equipment Available are three different failure modes. An owner who checks only one and assumes the others is leaving exactly the gap a future Control Failure Report will expose.

Whether confidence is evidence-based

Owner Confidence should be read against the numbers directly above it — verification compliance, failures and bypasses — not against general impression. A Fully confident answer next to a high failure count is the clearest sign the review wasn't taken seriously.

What auditors find

Most common critical control owner review findings

The same gaps recur across sites running this review.

FindingClauseWhat fixes it
Review completed by a deputy rather than the named ownerICMM Critical Control Management Good Practice Guide – control ownershipBlock submission unless Control Owner matches the person logged in, or require a documented delegation reason
Owner Confidence recorded as high alongside a rising Failures This Year countICMM Critical Control Management Good Practice Guide – performance evidenceFlag any review where confidence exceeds what the year's failure and bypass counts would support
Better Control Now Available answered No every year with no evidence of a scanICMM Critical Control Management Good Practice Guide – control reviewRequire a short note on what was checked whenever this is answered No
Verification Frequency Still Appropriate left at Pass indefinitelyICMM Critical Control Management Good Practice Guide – maintenance and verificationPrompt a Partial or Fail review whenever verification compliance has dropped from the prior year
Action Required marked Yes with no CAPA ID attachedISO 45001:2018 Clause 9.1Block sign-off until CAPA ID and Action Owner are both populated
Second Signature obtained from someone other than the site managerICMM Critical Control Management Good Practice Guide – governance sign-offRestrict the second signature field to the site manager role for this record type

Case in point

Case in point: an owner review that kept saying 'fully confident' until the register caught up with it

A control owner had signed three consecutive annual reviews as Fully confident, each time answering from memory rather than pulling the year's verification log. Bypasses Reported was left at zero each year because nobody had asked maintenance for the actual number.

When a new risk lead cross-checked the fourth review against the verification schedule, bypasses had in fact risen from two to eleven over three years, and the interlock had been on a waiver twice. The owner's confidence had not moved once while the control quietly got worse.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

33fields
4 sections
Reference
SAF-083
Archetype
Review
Record ID
CCOR-2026-000
Scoring
Not scored
Direction
n/a
Singleton
No
Basis
ICMM
Links
Links Critical Control Register
Tags
Critical risk, Governance
Sections
4
Fields
33
Follow up fields
3
Repeating sections
0
Links out
3
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

11 fields
Text

Review ID*

Generated on save

Auto sequence. Format CCOR-2026-000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Date & Time

Date and Time*

Users

Completed By*

Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Pick List

Critical Control

OptionalFrom FDN-011 Control NameFilter: Site matches
Text

Control ID

OptionalLinked

Format CCTRL-000.

Links to FDN-011 Control ID

Info

The Owner Answers Personally

This is the named owner confirming, in their own words, that they believe this control is working. It is not delegated.

Users

Control Owner*

Date & Time

Owner Since

Optional

Is it still the right control

4 fields
Single Choice

Control Still Addresses The Threat*

Scored
  • Pass2 pts
  • Partial1 pt
  • Fail0 pts
  • N/Aexcluded from denominator
Single Choice

Threat Has Changed*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Better Control Now Available*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Text

Change Detail

Optional

Is it resourced

5 fields
Single Choice

Budget In Place*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

People Trained And Available*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Spares And Equipment Available*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Maintenance Tasks Exist*

Scored
  • Pass2 pts
  • Partial1 pt
  • Fail0 pts
  • N/Aexcluded from denominator
Single Choice

Verification Frequency Still Appropriate*

Scored
  • Pass2 pts
  • Partial1 pt
  • Fail0 pts
  • N/Aexcluded from denominator

Is it working

13 fields
Numeric Answer

Verification Compliance This Year*

Scored
Numeric Answer

Failures This Year*

Scored
Numeric Answer

Bypasses Reported*

Scored
Single Choice

Owner Confidence*

Scored

Would you be comfortable explaining this control's condition after a fatality.

  • Fully confident4 pts
  • Broadly confident3 pts
  • Some concerns1 pt
  • Not confident0 pts
Text

Owner Statement*

Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Users

Control Owner*

Signature

Signature*

Users

Site Manager*

Signature

Second Signature*

SAF-083 · record IDs look like CCOR-2026-000 · Links Critical Control Register

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The form is the easy part. Keeping it current, routing it to the right owner and holding the evidence together is the work that actually slips.

KnowSafe

Holds the owner review against the Critical Control Register, and flags any control whose review date has passed with no owner named.

KnowComply

Tracks due-diligence evidence for officers and duty holders, so a signed owner review counts as proof of active oversight, not just a filed form.

KnowMaintain

Feeds actual verification compliance, spares availability and maintenance task completion into the review, instead of leaving the owner to answer from memory.

Ella
Ella

Coordinates the crew, rolls completion and exceptions into one view, and holds every write for your approval before it touches a record.

This template lives in KnowSafe — safety and compliance. Incidents, hazards, permits, inspections and the critical controls behind them.

Meet KnowSafe→

Glossary

Critical Control Owner Review definitions and key terms

Control owner
The named individual accountable for a specific critical control, responsible for confirming annually that it still addresses its threat and is resourced to keep working.
Verification compliance
The proportion of scheduled checks on a control that were actually completed over a period, used as evidence rather than an owner's general impression.
Trigger event
An occurrence, such as a threat change, a failure, or a near miss, that forces an owner review before its scheduled annual date.
Due diligence (WHS)
The active steps an officer or duty holder must take to stay informed about risks, as distinct from simply holding the title of owner.
Critical Control Register
The master list of named critical controls, their owners and verification schedules that this review checks against and updates.

FAQ

Frequently asked questions about critical control owner review

What is the critical control owner review template based on?+

It is built against the ICMM Critical Control Management Good Practice Guide, a mining-sector framework for fatal risk control now widely borrowed outside mining.

What sections does the critical control owner review contain?+

There are 4 sections: Header, Is it still the right control, Is it resourced, Is it working. Together they hold 33 fields, 25 of which are required.

How often is a critical control owner review raised?+

A new record is raised at the review interval, and after any trigger event. Each one is given an ID in the form CCOR-2026-000, so it can be traced and referenced from other records.

Which programme does the critical control owner review belong to?+

It is part of Critical Control and Fatal Risk: named fatal risks with owned critical controls and a verification schedule that is actually run.

Is the critical control owner review scored?+

The individual resourcing and performance questions carry weighted answers, but there is no overall pass/fail score attached to the review as a whole.

Can the critical control owner review template be changed?+

Yes. Every field, option, score and conditional rule is editable, and the link to the Critical Control Register comes with it. Most teams install it as it is, run it for a cycle, then adjust.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ICMM — Critical Control Management Good Practice Guide (2015)
  • Work Health and Safety Act 2011 (model law) — s27, officer due diligence
  • ISO 45001:2018 — Clause 9.1, Monitoring, measurement, analysis and performance evaluation

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.