Knowella

High Potential Risk Review

The common failure isn't skipping this review, it's letting the fatal-risk list grow past the small set of things that could kill someone. Once it swells, senior management stops reading line by line, barrier weaknesses hide behind averages, and the review becomes a status update, not an assurance check.

KnowSafeReviewSAF-066Pinned in navigation31 fields across 3 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ICMM critical risk practice
Workspace
KnowSafe
Form type
Review
Review cadence
Twice a year, plus after any trigger event
Chaired by
Senior management, not the safety team alone

The short version

  • A high potential risk review only earns its keep if the fatal-risk list stays short; once it grows to cover ordinary hazards, senior management stops engaging line by line and the review becomes ceremonial.
  • Verification compliance and barrier health measure different things — a control can be checked on schedule and still be rated weakening, and only the second number tells you that.
  • The owner confidence statement is a judgement call in the owner's own words, not a scored field, and is the one place a reviewer can catch a control that looks fine on paper but the owner doesn't trust.
  • Escalation to the board is a deliberate gate, not automatic, so a review recording deteriorating barriers without triggering escalation leaves the finding at site level with no one above accountable for it.

What this is

What is a high potential risk review?

What is a high potential risk review?

A standing agenda item, chaired by senior management, that walks through each named fatal risk in turn and asks whether its critical controls are verified, effective and improving. It exists separately from the general risk register because fatal risks need line-by-line attention a 200-row register review can't give.

What makes a risk a 'fatal risk' rather than an ordinary entry on the register?

One where a single control failure, on its own, can kill or permanently disable someone; mobile equipment interaction, energy isolation and confined space entry are typical examples. The list is deliberately short, because a long list defeats naming the risks that matter most.

Why is barrier health scored separately from verification compliance?

Verification compliance tells you a control was checked; barrier health tells you what the check found. A site can run 100% of scheduled verifications and still rate the barrier weakening, because checks pass on a technicality while the control degrades in practice.

Scope

When is a high potential risk review required?

This review sits inside the Critical Control and Fatal Risk programme and only covers named fatal risks. Using it for the wider register, a single incident, or a control-by-control check produces records the programme can't roll up.

Use this template when

  • The scheduled six-monthly cycle for the named fatal risk list has come round
  • A trigger event — a control failure, a serious potential event, or a new fatal risk being named — forces an out-of-cycle review
  • A new record is needed; each one gets its own ID in the form HPR-2026-000
  • You are running the Critical Control and Fatal Risk programme and this is one of its standing steps
  • A linked record needs this one to exist: it links to Bowtie analyses and the Critical Control register

Do not use it for

  • Annual Risk Register Review, which covers every recorded risk once a year — the wrong venue for a fatal risk needing senior eyes twice a year.
  • Bowtie Analysis, which maps the threats, controls and consequences for one fatal risk in depth, and feeds this review rather than replacing it.
  • Critical Control Verification, which checks a single control once; this review rolls several verification cycles into one barrier-health judgement.
  • Job Safety Analysis, which breaks a job into steps, finds the hazards in each and sets the controls — a task-level tool, not a portfolio review.
  • Anything outside KnowSafe, which belongs in the workspace that owns that process.

Compliance mapping

Which ICMM critical risk practice requirements does this satisfy?

The review borrows its structure from ICMM's critical control practice, with monitoring and escalation duties mapping onto ISO 45001's management-review requirements where a site also certifies to it.

ClauseRequirementWhere it lands
ICMM Critical Control Management — control identification elementEach fatal risk carries a named owner and defined critical controls before it can be reviewedFatal risks
ICMM Critical Control Management — verification elementVerifications due in the period are compared against verifications completed, with a compliance percentageFatal risks
ICMM Critical Control Management — control failure reporting elementControl failures and serious potential events in the period are counted against each named fatal riskFatal risks
ISO 45001 cl.9.1 Monitoring, measurement, analysis and performance evaluationThe review interval, chair and attendance are recorded so the monitoring activity is auditableHeader
ICMM Critical Control Management — performance reporting elementBarrier health and direction since last review are reported per fatal risk, then rolled to an overall assurance levelResult
ISO 45001 cl.9.3 Management reviewDeteriorating barriers or a low assurance level are escalated to the board, not absorbed at site levelResult
ISO 45001 cl.10.2 Incident, nonconformity and corrective actionWhere action is required against a fatal risk, a CAPA reference is raised and linked before the record closesFatal risks

What it does not cover

  • A 100% verification compliance percentage, which only proves the checks happened on schedule, not that the control checked is still fit for purpose.
  • A 'Strong' barrier health rating with no supporting detail, which is a conclusion standing in for evidence unless the reviewer can name what changed since last cycle.
  • Senior management attendance recorded but no owner confidence statement entered, which means the person closest to the control never went on record about whether they trust it.
  • An 'Improving' direction rating alongside a control failure logged the same period, which is a contradiction the reviewer has to resolve, not wave through.
  • A high overall assurance level with one fatal risk left unreviewed, which hides the gap inside a portfolio number instead of surfacing it.

Global

High Potential Risk Review requirements by country

ICMM's critical control practice is voluntary guidance, not statute, so its force depends on which regulator or member commitment sits behind it at a given site.

International (ICMM member companies)

ICMM Critical Control Management — Good Practice Guide

A voluntary commitment adopted by ICMM members and widely copied elsewhere in heavy industry

No inspector checks this happened; assurance is only as strong as the board's own appetite to ask for it

Australia

State work health and safety mining legislation and codes of practice

Regulators expect documented major-hazard management plans with named controls and verification, mirroring ICMM's structure

A weak or missing review is defensible evidence in an inspection, not just an internal governance nicety

South Africa

Mine Health and Safety Act, major hazard risk assessment obligations

Statutory duty holders must identify major hazards and demonstrate ongoing control, and the Chief Inspector can compel evidence

This review can be the primary record showing major hazard controls are actively assured, not just assessed once

How to complete it

How to complete a high potential risk review, step by step

Filling in every field is the easy part; the judgement calls below separate a review that caught something from one that just repeated last cycle's rating.

What counts as 'verified', not just 'checked'

Asking an operator whether a control still works is not the same as testing it. Decide what evidence each control type needs before the cycle starts, or compliance percentage measures activity, not assurance.

Downgrading barrier health with no incident behind it

The hardest call is rating a barrier 'Weakening' when nothing has failed yet — a control tested less often, or an owner who has changed role. Waiting for a failure before downgrading defeats the purpose.

Whether the confidence statement is evidence or reassurance

A statement reading 'all good, no concerns' three cycles running signals the field isn't being used, not that the risk is well controlled. Push for specifics, or drop it rather than treat boilerplate as evidence.

When to escalate to the board versus hold at site

Escalation should follow the barrier rating and direction, not comfort reporting bad news upward. Fix the rule in advance — say, any 'Poor' or 'Weakening' rating trending 'Deteriorating' — so it isn't decided in the room.

What auditors find

Most common high potential risk review findings

The same gaps recur in most high potential risk reviews audited afterwards.

FindingClauseWhat fixes it
Fatal risk list has grown to include ordinary hazards alongside genuinely fatal onesICMM Critical Control Management — control identification elementRe-scope against the single-control-failure-kills definition and move the rest back to the general register
Verification compliance high but checks only confirm the control exists, not that it functionsICMM Critical Control Management — verification elementDefine evidence per control type, distinguishing existence checks from function tests
Barrier health rated 'Strong' or 'Adequate' with no owner confidence statement to support itISO 45001 cl.9.1Require the confidence statement wherever barrier health is above 'Weakening', and reject boilerplate entries
Deteriorating barrier logged but escalation to board left blank or marked 'No'ISO 45001 cl.9.3Apply a fixed escalation rule tied to barrier health and direction, not the chair's discretion
Control failures recorded in fatal risks never produce a CAPA referenceISO 45001 cl.10.2Block the record closing when action required is 'Yes' with no CAPA ID linked
Same fatal risk rated 'Improving' two cycles running with nothing changedICMM Critical Control Management — performance reporting elementRequire a one-line reason for any repeated rating so the review can't just echo last cycle

Case in point

Case in point: the compliance percentage that hid a live gap

A site reported 96% verification compliance across nine fatal risks for two half-year cycles, with overall assurance 'Adequate' both times. The one control missing verification each cycle was energy isolation on a specific line, deferred because the vendor's technician wasn't available.

That risk's barrier health had quietly moved from 'Adequate' to 'Weakening', but the portfolio number was what senior management scanned first, so no one asked why. A serious potential event on the same line — caught before anyone was hurt — forced a line-by-line re-read; the deferred verification had sat unescalated for a full year.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

31fields
3 sections
Reference
SAF-066
Archetype
Review
Record ID
HPR-2026-000
Scoring
Barrier health, control gaps
Direction
High is good
Singleton
No
Basis
ICMM critical risk practice
Links
Links Bowtie, Critical Controls
Tags
Risk, Critical risk, Governance
Sections
3
Fields
31
Follow up fields
1
Repeating sections
1
Links out
3
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

8 fields
Text

Review ID*

Generated on save

Auto sequence. Format HPR-2026-0000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Info

The Small Number That Matter

This covers only the risks that could kill or permanently disable. Everything else belongs in the annual register review. Keeping this list short is what makes it useful.

Date & Time

Review Date*

Users

Chaired By*

Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Text

Attendees*

Senior management attendance is the point of this review.

Fatal risks

Repeats14 fields
Single Choice

Fatal Risk*

Mobile equipmentWorking at heightEnergy isolationConfined spaceAmmonia releaseMachine entanglementFire or explosionElectricalLifting operations
Users

Risk Owner*

Text

Bowtie ID

OptionalLinked

Links to SAF-062 Bowtie ID

Numeric Answer

Critical Controls Defined*

Scored
Numeric Answer

Verifications Due This Period*

Numeric Answer

Verifications Completed*

Numeric Answer

Verification Compliance Percent*

Scored
Numeric Answer

Control Failures This Period*

Scored
Numeric Answer

Serious Potential Events*

Scored
Single Choice

Barrier Health*

Scored
  • Strong4 pts
  • Adequate3 pts
  • Weakening1 pt
  • Poor0 pts
Single Choice

Direction Since Last Review*

Scored
  • Improving3 pts
  • Stable2 pts
  • Deteriorating0 pts
Text

Owner Confidence Statement*

In the owner's own words, whether they believe this risk is genuinely controlled.

Single Choice

Action Required*

Scored
  • No2 pts
  • Yes0 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Links to FDN-014 CAPA ID

Result

9 fields
Numeric Answer

Fatal Risks Reviewed*

Numeric Answer

Risks With Deteriorating Barriers*

Scored
Single Choice

Overall Assurance Level*

Scored
  • High4 pts
  • Adequate3 pts
  • Limited1 pt
  • None0 pts
Single Choice

Escalated To Board

Optional
YesNo
Date & Time

Next Review Due*

Users

Chaired By*

Signature

Signature*

Users

Site Manager*

Signature

Second Signature*

SAF-066 · record IDs look like HPR-2026-000 · Links Bowtie, Critical Controls

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The review itself is a conversation twice a year. Keeping it honest between cycles — tracking schedules, catching a drifting barrier, making sure a failure produces a CAPA — is the work that falls through if nothing is watching.

KnowSafe

Holds the fatal risk list and its bowtie and critical control links, tracks verification schedules between cycles, and flags any control approaching its due date before the next chair meeting.

KnowMaintain

Where a critical control is a physical barrier — an isolation system, an interlock, a guard — links its maintenance history straight into the fatal risk it protects, so barrier health isn't rated from memory.

KnowComply

Keeps the escalation rule consistent across sites, surfaces any deteriorating barrier not yet raised to the board, and holds the audit trail regulators ask for.

Ella
Ella

Pulls attendance, outstanding CAPAs and repeated-rating patterns into one brief ahead of the review, and holds every write for your approval before it touches a record.

This template lives in KnowSafe — safety and compliance. Incidents, hazards, permits, inspections and the critical controls behind them.

Meet KnowSafe→

Glossary

High Potential Risk Review definitions and key terms

Critical control
A control whose failure, on its own, can result in a fatality — distinct from controls that only reduce likelihood or severity in combination with others.
Barrier health
A qualitative rating of whether a critical control is currently working as designed, informed by verification results, control failures and owner assessment — not a simple pass or fail on the last check.
Bowtie
A diagram mapping the threats leading to a fatal risk on one side and the consequences on the other, with critical controls sitting in the middle as the barriers between them.
Verification compliance
The proportion of scheduled control verifications actually completed in a period — activity that must be read alongside barrier health, not in its place.
Assurance level
A rolled-up judgement — high, adequate, limited or none — of how confident senior management can be that the fatal risk list is genuinely controlled.

FAQ

Frequently asked questions about high potential risk review

What is the high potential risk review template based on?+

It follows ICMM's critical control management practice, a voluntary framework that names fatal risks and their controls, schedules verification, and reports barrier health up to senior management.

How is this different from the annual risk register review?+

The register review covers everything recorded, once a year, at area-manager level. This review covers only fatal risks, twice a year, chaired by senior management.

Who should be on the fatal risk list?+

Only risks where a single control failure can kill or permanently disable someone. If it starts absorbing moderate-severity hazards, everything else should move back to the general register.

What does a 'Weakening' barrier health rating actually mean?+

The control is still operating but showing signs it may not hold — reduced verification frequency, a near-miss, a change of owner, or a failed check with no root cause closed out. It should trigger a named action even without an incident.

When does a finding get escalated to the board?+

Best practice is a fixed rule agreed in advance, tied to barrier health and direction — for example, any risk rated 'Poor' or 'Weakening' and trending 'Deteriorating' — not the chair's judgement on the day.

Can the fatal risk list and its options be changed per site?+

Yes. The picklist, scoring and escalation rule are all editable, but changes should go through the programme owner so the review stays comparable across sites and cycles.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ICMM — Critical Control Management: Good Practice Guide
  • ISO 45001 cl.9.1 — Monitoring, measurement, analysis and performance evaluation
  • ISO 45001 cl.9.3 — Management review
  • ISO 45001 cl.10.2 — Incident, nonconformity and corrective action

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.