Knowella

Critical Control Performance Review

The recurring failure is treating a high compliance percentage as proof the controls are working. A site can complete every scheduled verification on time and still be exposed, because compliance measures whether the check happened, not whether the control passed. A quarter can close green on completion rate while effectiveness, bypasses and trend all point the other way.

KnowSafeReviewSAF-07937 fields across 3 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ICMM
Workspace
KnowSafe
Form type
Review
Frequency
Quarterly, plus after any trigger event
Completed by
Control owner with senior management

The short version

  • This review aggregates verification results across a period; it does not replace the individual verification of any single control.
  • Compliance percent (were checks done) and effectiveness percent (did controls pass) are scored separately, and a high compliance figure does not imply a healthy effectiveness figure.
  • The template holds 37 fields across three sections, with the controls-reviewed section repeating once per control covered in the period.
  • Overall Control Health and Confidence in Fatal Risk Management are the two summary judgements senior management is expected to act on, and they can legitimately diverge from each other.

What this is

What is a critical control performance review?

What is a critical control performance review?

It is a periodic roll-up, not a single verification, that looks across every named critical control at a site over a period and asks two separate questions: were the scheduled verifications actually completed, and when they were, did the controls pass. It is built against ICMM's critical control management approach and reported to senior management, not just the control owner.

How is a performance review different from a verification?

A verification is a field check of one control on one day. A performance review aggregates many verifications for many controls across a quarter, looking for patterns such as a control that passes individually but is trending toward failure, or one that is verified on time but never actually tested against its performance standard.

Why does the review distinguish compliance percent from effectiveness percent?

Compliance percent counts whether verifications happened on schedule. Effectiveness percent counts whether the controls that were checked actually passed. A programme can run at full compliance while effectiveness quietly falls, which is the specific failure mode this review is built to surface.

Scope

When is a critical control performance review required?

This review is a period-level roll-up sitting above the individual verification record, not a substitute for it. Using it to check a single control on a single day produces a review with no data to aggregate.

Use this template when

  • A quarter, or the review interval set for the programme, has closed and verification results need to be aggregated across all named critical controls
  • A trigger event, such as a serious potential incident or a control failure, forces an out-of-cycle review before the next scheduled one
  • You are running the Critical Control and Fatal Risk programme and this review is its periodic governance step
  • Senior management needs a single view of whether fatal risk defences are holding across the site, not a control-by-control drill-down
  • A linked high potential risk review needs this record's outcome as an input

Do not use it for

  • Critical Control Verification, which checks one named control on one occasion rather than aggregating results across a period.
  • Barrier Health Check, which works through a single bowtie branch by branch rather than reviewing programme-wide performance.
  • Fatal Risk Protocol Audit, which audits compliance with a whole protocol such as energy isolation rather than reviewing verification data already collected.
  • Annual Risk Register Review, which revisits the risk register itself rather than the performance of the controls already on it.
  • A single overdue or failed verification, which should be actioned immediately through its own record rather than held for the next quarterly review

Compliance mapping

Which ICMM requirements does this satisfy?

ICMM's guide frames this review as the reporting stage of a staged process, so requirements below are cited by stage rather than by numbered clause.

ClauseRequirementWhere it lands
Step 7 – ReportingVerification completion and control effectiveness are reported to senior management at a set interval, not left at control-owner level.Header
Step 6 – VerificationEvery critical control in scope is accounted for individually, with due and completed counts recorded per control.Controls reviewed
Step 6 – VerificationCompliance (checks done) and effectiveness (checks passed) are calculated and reported as distinct percentages.Controls reviewed
Step 6 – VerificationTrend direction is assessed against the prior period for each control, not inferred from a single quarter in isolation.Controls reviewed
Step 5 – AccountabilityEach control's named owner is confirmed still active and assigned, not left as a stale record.Controls reviewed
Step 7 – ReportingAn overall control health judgement and a confidence-in-fatal-risk-management judgement are recorded, and may differ from each other.Assessment
Step 7 – ReportingWhere the review finds a material weakness it is escalated to the high potential risk review, not filed only at programme level.Assessment
Step 5 – AccountabilityThe review is closed with two named signatures, the reviewer and the site manager, not one.Assessment

What it does not cover

  • Overall Control Health, which was scored "Strong" in the same period where Bypasses Reported and Related Serious Potential Events are both greater than zero.
  • Trend Direction, which reads "Improving" for a control whose Verifications Failed count rose against the prior period.
  • Controls At Full Compliance and Controls Below Target, which together do not reconcile against the total number of controls listed in the review.
  • Confidence In Fatal Risk Management, which was marked "High" while Effectiveness Percent for one or more controls sits well below the compliance figure for the same control.
  • Reported To High Potential Risk Review, which was left as "No" despite Programme Action Required being answered "Yes" for a high-priority item.

Global

Critical Control Performance Review requirements by country

This review sits above individual verification and is where programme-level assurance gets tested, which three settings treat with particular weight.

Australia

State mining safety regulators' principal hazard management guidance (e.g. NSW Resources Regulator, WA DMIRS)

Regulators expect periodic reporting on principal hazard control performance to senior site management, and a review that shows high compliance but does not separately track effectiveness is treated as an incomplete assurance case.

A quarter closed on compliance percent alone, without an effectiveness figure, does not meet the standard of evidence a regulator will accept after a serious incident.

South Africa

Mine Health and Safety Act, read with DMRE guidance on critical control management

Programme-level review of critical controls is expected to feed the statutory risk management programme review cycle, with senior management sign-off specifically required, not just the control owner.

A review missing the site manager's second signature, or missing escalation to a higher review when action is required, weakens the programme's standing at the statutory review.

International

ICMM member company commitments under the Critical Control Management Good Practice Guide

Member companies are expected to be able to demonstrate, at a group level, that critical control performance is reviewed and reported on a defined cycle across all sites, feeding public assurance statements.

This review's output is often the underlying evidence for group-level assurance claims, so a gap here can surface well beyond the site that produced it.

How to complete it

How to complete a critical control performance review, step by step

Filling in the counts is mechanical; the judgement calls below decide whether the resulting review is a genuine health check or a rubber stamp.

How compliance and effectiveness combine into overall health

A site can run at high compliance with mediocre effectiveness, or the reverse. Overall Control Health should weight effectiveness more heavily than compliance, because a control that is checked on time but keeps failing is a worse finding than one that is occasionally late but always passes.

What counts as a trigger event outside the quarterly cycle

A serious potential incident, a confirmed bypass, or a material change to the asset or process a control protects should all force an out-of-cycle review rather than waiting for the next scheduled quarter, even if the numbers still look acceptable on paper.

When confidence should diverge from control health

Confidence In Fatal Risk Management can legitimately sit lower than Overall Control Health, for example when the controls are individually passing but the owner named against several of them is no longer active. Forcing the two fields to always agree hides that gap.

Whether bypasses alone force escalation

A nonzero Bypasses Reported count should push Reported To High Potential Risk Review toward Yes regardless of how the percentages read, because a demonstrated bypass is evidence the barrier already failed once, not a risk that it might.

What auditors find

Most common critical control performance review findings

These are the gaps that recur across sites running this review; each weakens the assurance the review is meant to provide.

FindingClauseWhat fixes it
Overall Control Health scored Strong in a period with reported bypasses or related serious potential eventsStep 7 – ReportingCap Overall Control Health below Strong automatically whenever Bypasses Reported or Related Serious Potential Events is greater than zero.
Compliance and effectiveness percentages reported without any reconciliation against Verifications FailedStep 6 – VerificationCalculate Effectiveness Percent from Verifications Passed and Verifications Completed rather than accepting it as free entry.
Controls At Full Compliance and Controls Below Target figures that do not sum to the controls actually listed in the reviewStep 6 – VerificationDerive both counts from the repeating Controls Reviewed section instead of separate manual entry.
Programme Action Required marked Yes without Reported To High Potential Risk Review being updatedStep 7 – ReportingRequire Reported To High Potential Risk Review = Yes whenever Priority is High and Programme Action Required = Yes.
Control Owner Still Named And Active recorded Pass without cross-checking against current staff recordsStep 5 – AccountabilityValidate the named owner against the active-user list held on the critical control register rather than accepting manual confirmation.
Second Signature obtained from the same reviewer rather than an independent site managerStep 5 – AccountabilityRestrict Site Manager and Second Signature to a role distinct from the person entered against Reviewed By.

Case in point

Case in point: the quarter that closed green on compliance and red on effectiveness

A site's quarterly review showed 98 percent of scheduled verifications completed on time, and Overall Control Health was recorded as Strong on the strength of that figure alone, with the effectiveness percentage left unexamined by the reviewer.

A closer read showed effectiveness at 61 percent for the same controls, with two showing a worsening trend across three straight quarters. The controls had been checked reliably; they had been failing just as reliably, and the compliance number had been masking it the entire time.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

37fields
3 sections
Reference
SAF-079
Archetype
Review
Record ID
CCPR-2026-000
Scoring
Control health percent
Direction
High is good
Singleton
No
Basis
ICMM
Links
Links Critical Control Register
Tags
Critical risk, Governance
Sections
3
Fields
37
Follow up fields
3
Repeating sections
1
Links out
3
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

9 fields
Text

Review ID*

Generated on save

Auto sequence. Format CCPR-2026-000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Date & Time

Period From*

Date & Time

Period To*

Users

Reviewed By*

Pick List

Site 2*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID 2*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Controls reviewed

Repeats12 fields
Pick List

Critical Control

OptionalFrom FDN-011 Control NameFilter: Site matches
Text

Control ID

OptionalLinked

Format CCTRL-000.

Links to FDN-011 Control ID

Numeric Answer

Verifications Due*

Numeric Answer

Verifications Completed*

Numeric Answer

Compliance Percent*

Scored
Numeric Answer

Verifications Passed*

Numeric Answer

Verifications Failed*

Scored
Numeric Answer

Effectiveness Percent*

Scored
Single Choice

Trend Direction*

Scored
  • Improving3 pts
  • Stable2 pts
  • Worsening0 pts
Single Choice

Control Owner Still Named And Active*

Scored
  • Pass2 pts
  • Partial1 pt
  • Fail0 pts
  • N/Aexcluded from denominator
Numeric Answer

Bypasses Reported*

Scored
Numeric Answer

Related Serious Potential Events*

Scored

Assessment

16 fields
Info

Two Different Failures

Low verification compliance means you do not know whether the control works. Low effectiveness means you know it does not. The second is worse, but the first is more common and easier to hide.

Numeric Answer

Controls At Full Compliance*

Numeric Answer

Controls Below Target*

Scored
Numeric Answer

Controls With Failed Verifications*

Scored
Single Choice

Overall Control Health*

Scored
  • Strong4 pts
  • Adequate3 pts
  • Weakening1 pt
  • Poor0 pts
Single Choice

Confidence In Fatal Risk Management*

Scored
  • High4 pts
  • Adequate3 pts
  • Limited1 pt
  • Low0 pts
Single Choice

Programme Action Required*

Scored

Raise the action record, then enter its reference here.

  • Yes0 pts
  • No2 pts
  • N/Aexcluded from denominator
Single Choice

Priority

OptionalScoredShows if Programme Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Programme Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Programme Action Required equals Yes
Single Choice

Reported To High Potential Risk Review*

YesNo
Date & Time

Next Review Due*

Users

Reviewed By*

Signature

Signature*

Users

Site Manager*

Signature

Second Signature*

SAF-079 · record IDs look like CCPR-2026-000 · Links Critical Control Register

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The review itself is a rollup; keeping the underlying verification data honest and making sure a weak quarter actually reaches the people who can act on it is the part that slips.

KnowSafe

Pulls verification results automatically into the controls-reviewed section, so compliance and effectiveness percentages reflect what was actually recorded rather than a manual recount.

KnowComply

Holds the quarterly review cycle against its due dates, escalates a weak Overall Control Health or Confidence score into the governance reporting a fatal risk programme needs to show at audit.

KnowOps

Tracks the actions raised out of a review, including CAPA references and owners, so a Programme Action Required of Yes actually resolves before the next quarter closes.

Ella
Ella

Flags contradictions such as strong control health alongside reported bypasses, chases the second signature when it's missing, and holds every write for approval before it touches the record.

This template lives in KnowSafe — safety and compliance. Incidents, hazards, permits, inspections and the critical controls behind them.

Meet KnowSafe→

Glossary

Critical Control Performance Review definitions and key terms

Control health percent
The review's summary score for how a set of critical controls performed over the period, intended to combine both whether they were checked and whether they passed, not compliance alone.
Compliance percent
The share of scheduled verifications actually completed on time for a given control, which measures process discipline rather than control performance.
Effectiveness percent
The share of completed verifications that the control actually passed, the figure that speaks to whether the barrier is doing its job.
Trend direction
Whether a control's performance is improving, stable or worsening relative to the prior review period, used to catch slow degradation before it becomes a failure.
Fatal risk
A hazard with the potential to cause one or more fatalities, the category of risk this whole programme, and its critical controls, exists to manage.

FAQ

Frequently asked questions about critical control performance review

What is the critical control performance review template based on?+

It is built against ICMM's approach to critical control management, which treats periodic reporting on control performance as the closing stage of the wider process, distinct from any single verification.

What sections does the critical control performance review contain?+

Three sections: Header, Controls Reviewed and Assessment, holding 37 fields in total, 31 required, with Controls Reviewed repeating once for every control covered in the period.

How often is a critical control performance review raised?+

At the review interval set for the programme, typically quarterly, and again after any trigger event such as a serious potential incident or a confirmed control failure.

Which programme does the critical control performance review belong to?+

It sits inside the Critical Control and Fatal Risk programme, as the periodic governance step that rolls individual verification records into a single assurance judgement for senior management.

Why can Overall Control Health and Confidence In Fatal Risk Management disagree?+

They measure different things. Control health looks at verification and effectiveness data; confidence also weighs factors like whether owners are still active and whether findings have actually been closed out, so a lower confidence score alongside decent control health is a legitimate, informative combination.

Can the critical control performance review template be changed?+

Yes. Every field, score and conditional rule is editable, though most teams keep compliance and effectiveness as separate calculated percentages rather than merging them into one figure.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ICMM — Critical Control Management: A Good Practice Guide (2015)
  • ICMM Health and Safety Performance — Minimum Requirement 8, verification of critical controls
  • ISO 45001:2018, Clause 9.3 — management review

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.