Independent · Judgment-led Reference publication · Industrial safety Follow · 4,222
From the Floor.

Ground truth for safe work.

The Skeptic

The corrective action closure rate is not a safety metric

Sort last year's closed corrective actions by level on the hierarchy of controls: if most sit at training, procedure or signage, the CAPA system is producing paper, and the recurrence data will show it.

September 8, 2026

The five levels of the hierarchy of controls stacked as rows, with elimination, substitution and engineering marked as the levels that change the exposure, and administrative and PPE marked as the levels that close easily and let the same finding return.

The monthly EHS deck almost always carries the same slide. Actions raised, actions closed, percentage closed on time, a green arrow. Four hundred actions, ninety four percent closed, up two points on the quarter. Nobody argues with it. It is the one number in the management system that is unambiguous, auditable and cheap to produce.

It is also close to content free.

Closure certifies that a task was marked complete by the person it was assigned to. It says nothing about what the task was. Retraining closes. A toolbox talk closes. A revised work instruction closes. A new sign closes. So does an interlock, a redesigned fixture, or deleting the step from the process entirely. All six land in the same column, and only the last three change what happens the next time somebody gets it wrong.

What closure certifies, and what it does not

NIOSH ranks controls in a fixed order: elimination, substitution, engineering controls, administrative controls, PPE. Its framing of why is the part that matters. In the NIOSH hierarchy of controls guidance (United States, research guidance rather than regulation), the top three are described as more effective because they control exposures without significant human interaction, while administrative controls and PPE require significant and ongoing effort by workers and their supervisors. That is a statement about failure modes, not taste. A control that depends on a person remembering, reading or choosing correctly fails the way people fail: intermittently, under time pressure, on the shift where the trained operator called in sick.

A register that closes overwhelmingly at the bottom two levels is not a register of controls. It is a register of requests for better human performance, often reasonable and rarely durable. Because they close as cleanly as a guard does, the metric cannot tell the difference.

Re-code the register

The audit takes an afternoon and needs no new system.

Pull every corrective action closed in the last full year. Export three fields: action text, originating finding, and location or asset. Code each action to one of the five NIOSH levels using a single rule: code by what physically changed, not by what the action was called.

Level 1, elimination: the task, material or exposure no longer exists. Level 2, substitution: same job, less hazardous input or method. Level 3, engineering: a guard, interlock, barrier, ventilation path, hard-wired trip, or a fixture that makes the wrong sequence impossible. Level 4, administrative: training, briefings, revised procedures, permits, signage, rotation, supervision, checklists. Level 5, PPE: issued, upgraded or newly mandated.

Two coding traps. A “revised procedure” that installs an interlock is level 3, and a “guard installed” that turns out to be a laminated warning label is level 4, so read the action text and not the category field. And restoring a control that was already required is maintenance, not a new control. Code those separately, because counting them as engineering will flatter the result.

Then compute the share at each level, and do it again split by finding severity. The interesting failure is not that housekeeping findings get toolbox talks. It is that serious-injury-potential findings get them too.

What to compare it against

There is no credible cross-industry benchmark for corrective action recurrence, and importing one would be worse than having none. Benchmark the register against itself.

Take findings closed twelve to twenty four months ago. For each, ask whether a finding of the same type recurred at the same location or asset class afterwards. Compute that rate twice: once for actions coded at levels one to three, once for levels four and five. If the rates are close, the hierarchy is not doing the explanatory work at your site, which is itself worth knowing. If bottom-of-hierarchy closures recur at a materially higher rate, the metric has been measuring throughput while the hazard stayed where it was.

The only published baseline I could find for how such registers skew comes from healthcare, not industry. A Canadian multi-site academic health sciences centre found that 16 percent of its critical incident recommendations from 2020 to 2022 were system focused. A structured effort, including protected meeting time and classifying every recommendation by intervention level, raised that to 30 percent over sixteen months. Different sector, different jurisdiction, same mechanism. Note what that success looks like: seven in ten recommendations still aimed at the person.

The standards point the same way, with a caveat worth stating plainly. ANSI/ASSP Z10.0-2019, the United States voluntary consensus standard for OH&S management systems, gives the hierarchy of controls its own clause (8.4) and corrective actions their own clause (9.4), a structure visible in ANSI’s free preview pages. The requirement text sits behind a paywall and I have not read it, so I will not paraphrase it, and the same goes for ISO 45001:2018. What is free to read is the Z10.0 foreword, which illustrates the systems approach with an unguarded machine: refit the guard, then go after why it was missing, seeking “a long-term solution rather than a one-time fix.”

United States guidance already splits the job in two. OSHA’s hazard prevention and control guidance, recommended practice rather than an enforceable standard, lists “Follow up to confirm that controls are effective” as its own action item, and asks employers to evaluate whether existing controls continue to provide protection. A closure rate covers the tracking half. Most registers never run the second.

The diagnostic

Open last year's closed corrective action register and code every entry to a hierarchy level before you look at the closure rate. What share of your closed actions changed something physical, and how does the recurrence rate for those compare with the ones that changed only what people were told? If the register cannot answer that as it stands, it was built to be reported, not interrogated.

None of this is an argument against training. NIOSH lists it as a legitimate control and it is often necessary. The argument is narrower. A closure rate carrying no hierarchy level is administrative throughput wearing the uniform of a safety metric, and it reads green right up to the point the same finding returns.

The fix is one field. Make hierarchy level mandatory at closure rather than optional at review, and put it on the slide next to the percentage. It costs a dropdown. It changes what the green arrow is allowed to mean.