What this is
What is a critical control verification?
What is a critical control verification?
It is a field check, not a desk review, confirming that a barrier standing between people and a fatal event is physically present, working, and being used as intended. It is run against the performance standard written on the critical control register, at the frequency set for that specific control, often weekly for the highest-consequence barriers.
How is verification different from a routine inspection?
A routine inspection checks general condition and housekeeping. A critical control verification is narrower and deliberately more serious: it exists only for the handful of controls named on the fatal risk register, it is tied to a competent named verifier, and a failed result is escalated the same way an incident would be, not filed as a minor finding.
Who can carry out a critical control verification?
Only a person confirmed competent for that specific control, not competent in general. The template records this explicitly, because a verifier who does not understand how the control is meant to perform cannot tell the difference between it working and it merely being present.
Scope
When is a critical control verification required?
This is one inspection inside a fatal risk programme, not a general safety walk. Using it for anything other than a named critical control produces a record nobody can trust when it matters.
Use this template when
- A specific control on the critical control register has a verification due on its set frequency
- The control has just been installed, modified, or reinstated after a failure and needs a fresh check before being relied on again
- A near-miss or serious potential incident has raised doubt about whether a named barrier is still working
- You are running the Lockout and Tagout or Critical Control and Fatal Risk programme and this verification is one of its scheduled steps
- A linked control failure report or performance review needs this record to exist as evidence
Do not use it for
- Critical Control Performance Review, which rolls verification rates and failures up across a period rather than checking one control on one day.
- Barrier Health Check, which works through an entire bowtie branch by branch rather than a single named control.
- Fatal Risk Protocol Audit, which audits compliance with a whole protocol such as energy isolation, not a single barrier's condition.
- LOTO Periodic Inspection, which checks the lockout procedure and hardware for a specific machine rather than a fatal-risk barrier generally.
- A general condition or housekeeping inspection, which belongs on the standard site inspection template, not this one
Compliance mapping
Which ICMM Critical Control Management requirements does this satisfy?
ICMM's Critical Control Management guide is a staged process rather than a numbered clause standard, so the requirements below are cited by stage.
| Clause | Requirement | Where it lands |
|---|---|---|
| Step 5 – Accountability | A named, competent individual is accountable for confirming the control, not a rotating or unspecified role. | Header |
| Step 6 – Verification | Verification is a field method (site visit or direct record review), not a statement taken on trust. | Header |
| Step 6 – Verification | Presence, working order and actual use are checked as three separate facts, not one combined impression. | Verification |
| Step 4 – Performance requirements | The control is tested against the performance standard written on its register entry, not a general sense of adequacy. | Verification |
| Step 6 – Verification | Whether the control can be bypassed, and whether a bypass was actually seen, are recorded as distinct findings. | Verification |
| Step 7 – Reporting | A control found not effective is escalated with the same urgency as an incident, including a linked failure report. | Outcome |
| Step 5 – Accountability | The named control owner is informed of every verification outcome, not only failures. | Outcome |
| Step 6 – Verification | The next verification date is fixed and a competent verifier signs the record before it closes. | Outcome |
What it does not cover
- Verification Method, which was recorded as "Statement only" rather than a site visit or record review, so nothing was actually confirmed beyond someone's word.
- Performance Requirement Met, which was marked Pass without the performance standard on the critical control register ever being checked against.
- Control Can Be Bypassed, which was answered "No" on the same record where Bypass Observed reads "Yes", an unresolved contradiction.
- Erosion Since Last Verification, which was left as "None" with no reference made to the previous verification to compare against.
- Control Verification Result, which was scored "Effective" despite one or more of the Present, Working Order or Used fields above it reading Fail.
Global
Critical Control Verification requirements by country
Critical control verification is an ICMM practice rather than a national regulation, but three settings shape how strictly it gets enforced.
State mining safety regulators (e.g. NSW Resources Regulator, WA DMIRS) principal hazard management guidance
Regulators expect named principal hazard controls to have documented verification, and treat an unverified critical control as equivalent to an unmanaged principal hazard.
A verification record with a statement-only method or no named verifier is a live regulatory exposure, not just a quality gap.
Mine Health and Safety Act, read with DMRE guidance on critical control management
Verification of controls tied to catastrophic risk is expected to feed the mandatory risk management programme review, with the verifier's competence specifically scrutinised.
A verifier field left blank or filled with a generic role rather than a named, competent person weakens the whole programme's standing at review.
ICMM member company commitments under the Critical Control Management Good Practice Guide
Around two dozen major mining and metals companies have publicly committed to this verification discipline as a condition of ICMM membership, independent of any single country's law.
Records built on this template are often the evidence a member company cites in its own public assurance reporting, so gaps surface outside the site as well as inside it.
How to complete it
How to complete a critical control verification, step by step
Filling in the fields is mechanical; the judgement calls below decide whether the resulting record actually defends the control.
A record review or photograph can support a finding, but only a site visit where the verifier watches the control perform its function should be accepted for the highest-consequence barriers. Treat anything less as a partial verification pending the next cycle.
Present, Working Order and Used can each individually score Partial without any one of them failing outright, yet together they describe a control that is degraded in practice. Do not let three Partials average out to a clean overall result.
Erosion is judged against the last verification, not against day one. A control that has drifted from strong to merely adequate across three consecutive checks is trending toward failure even if today's snapshot still passes.
Work Stopped defaults to Not required, but a control found not effective on a genuinely fatal exposure should stop the associated task immediately, with the decision made by the control owner, not left to the verifier alone.
What auditors find
Most common critical control verification findings
The same gaps recur across sites running this template; each one is a real defect in the record, not a formatting nitpick.
| Finding | Clause | What fixes it |
|---|---|---|
| Verification completed by document review when the control is tagged as fatal-risk | Step 6 – Verification | Require Verification Method = Site visit before Complete can be selected for any control flagged fatal-risk on the register. |
| Bypass observed in the field but Action Required left as No | Step 7 – Reporting | Force Action Required = Yes whenever Bypass Observed = Yes, with no manual override. |
| Verifier competence recorded as a free-text opinion rather than checked against an approved list | Step 5 – Accountability | Validate Verifier against an approved-verifier list held on the critical control register instead of accepting any user. |
| Control Failure Report ID left blank when the result is Not effective | Step 7 – Reporting | Make Control Failure Report ID mandatory whenever Control Verification Result equals Not effective. |
| Next Verification Due set beyond the frequency stated for that control | Step 6 – Verification | Validate the chosen date against the frequency stored against the control on FDN-011 rather than trusting free entry. |
| Erosion marked None with no prior verification referenced for comparison | Step 6 – Verification | Surface the previous verification's field values alongside the current form so erosion is a stated comparison, not a guess. |
Case in point
Case in point: the lockout verification that passed on paper
A weekly LOTO energy-isolation verification had been closed as Effective for four straight cycles, each one completed by record review rather than a site visit, because the verifier trusted the maintenance log and never walked the line.
When a near-miss finally forced a physical check, the isolation point had been rerouted during an unrelated repair three weeks earlier and never reconnected to the register. Four consecutive clean verifications had confirmed nothing at all.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
3 sections
- Reference
- SAF-078
- Archetype
- Inspection
- Record ID
- CCV-2026-000
- Scoring
- Pass or fail
- Direction
- High is good
- Singleton
- No
- Basis
- ICMM Critical Control Management
- Links
- Links Critical Control Register
- Tags
- Critical risk, Verification
- Sections
- 3
- Fields
- 34
- Follow up fields
- 4
- Repeating sections
- 0
- Links out
- 4
Header
13 fieldsVerification ID*
Auto sequence. Format CCV-2026-0000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Area*
The area within the site.
Exact Location
Drop a pin for anything hard to find.
Critical Control
Control ID
Format CCTRL-000.
Links to FDN-011 Control ID
Verify In The Field
This is not a document review. Go and look at the control doing its job. A control that exists on paper and not in practice is the most dangerous kind.
Verification Method*
- Site visit4 pts
- Record review3 pts
- Photograph2 pts
- Statement only0 pts
Verifier Competent For This Control*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Verification
10 fieldsControl Present*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Control In Working Order*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Control Being Used*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Performance Requirement Met*
Against the standard written on the control register, not against a general impression.
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Evidence
People Understand The Control*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Control Can Be Bypassed*
- No3 pts
- With effort1 pt
- Easily0 pts
Bypass Observed*
- No3 pts
- Yes0 pts
Erosion Since Last Verification*
Controls degrade quietly. Compare against the last verification, not against zero.
- None3 pts
- Minor1 pt
- Significant0 pts
Detail
Outcome
11 fieldsControl Verification Result*
- Effective3 pts
- Partially effective1 pt
- Not effective0 pts
Control Failure Report ID
Links to SAF-082 Report ID
Work Stopped
- Not required3 pts
- Yes2 pts
- No0 pts
Control Owner Informed*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Next Verification Due*
Verifier*
Signature*
SAF-078 · record IDs look like CCV-2026-000 · Links Critical Control Register
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The check itself is quick; keeping verifications on schedule, competence current, and failures actually escalated is the part that slips without help.
Tracks every critical control's verification frequency against the register, flags overdue checks before they lapse, and keeps failed verifications linked through to their control failure reports.
Holds the machine-specific lockout procedures and isolation points that many critical control verifications are checking, so a verifier can confirm against the current configuration rather than an outdated one.
Rolls verification completion and failure trends into the governance evidence a fatal risk programme needs to show at audit, without a separate manual reconciliation.

Chases the named verifier when a check falls due, surfaces contradictory answers like a bypass observed alongside no action required, and holds every write for approval before it touches the record.
This template lives in KnowSafe — safety and compliance. Incidents, hazards, permits, inspections and the critical controls behind them.
Meet KnowSafe→Glossary
Critical Control Verification definitions and key terms
- Critical control
- One of a small named set of barriers that, on their own, prevent a specific unwanted event from becoming fatal, distinct from the wider set of controls in a general risk assessment.
- Verification
- A field-based check that a specific control is present, working, and in use, as opposed to an inspection of general condition or a review of past paperwork.
- Bypass
- Any way the control can be defeated or worked around, whether deliberately for convenience or accidentally through a process change.
- Erosion
- Gradual degradation of a control's performance across successive verifications, judged relative to the prior check rather than a fixed starting point.
- Performance requirement
- The specific, measurable standard a control must meet to count as effective, written on the critical control register rather than left to the verifier's judgement.
FAQ
Frequently asked questions about critical control verification
What is the critical control verification template based on?+
It is built against ICMM's Critical Control Management Good Practice Guide, which frames verification as one stage in a wider process running from identifying fatal risks through to reporting on control effectiveness.
What sections does the critical control verification contain?+
Three sections: Header, Verification and Outcome, holding 34 fields in total, 23 of them required, covering identification, the field check itself, and the resulting action.
How often is a critical control verification raised?+
On the frequency set for that specific control on the register, often weekly for the highest-consequence barriers, and again immediately after any change to the asset, procedure or area it protects.
Which programme does the critical control verification belong to?+
It sits inside both Lockout and Tagout and the wider Critical Control and Fatal Risk programme, as the recurring field check that proves a named barrier is still doing its job.
Why does the template ask about bypass separately from control failure?+
A control can fail outright, or it can still technically function while being easy to bypass in practice. Both are real weaknesses, and treating them as one question would hide whichever one the verifier didn't think of first.
Can the critical control verification template be changed?+
Yes. Every field, score and conditional rule is editable, including which methods count as acceptable verification, though most teams keep the site-visit requirement for fatal-risk controls unchanged.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Lockout and Tagout
Audit Finding Record
Records a single audit finding with its evidence, clause reference and classification
Lockout/Tagout Procedure (Machine Specific)
Sets out exactly how to isolate a specific machine, listing every energy source and isolation point
LOTO Periodic Inspection
Checks that a specific energy control procedure is being followed correctly in practice
Energy Isolation Verification
Records the physical test proving stored energy is gone before work begins
Group Lockout Record
Records a group isolation where several people work on one machine under a single lockout
Lock Removal Authorization
Authorises removing a lock when the person who applied it is not available
More in Critical Controls
Critical Control Performance Review
Reviews how a set of critical controls has performed over a period, including verification rates and failures
Barrier Health Check
Checks the barriers named in a bowtie are present and effective, working through the bowtie one branch at a time
Fatal Risk Protocol Audit
Audits compliance with a fatal risk protocol such as working at height, energy isolation or mobile equipment
Control Failure Report
Records that a critical control was found missing, bypassed or not working
Critical Control Owner Review
The named owner of a control confirms it is still the right control, still resourced and still working

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ICMM — Critical Control Management: A Good Practice Guide (2015)
- ICMM Health and Safety Performance — Minimum Requirement 8, verification of critical controls
- ISO 45001:2018, Clause 9.1.1 — monitoring, measurement, analysis and performance evaluation
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.