
In high-hazard industries, safety performance cannot be understood simply by counting accidents.
A facility can report:
…and still be moving toward a major process safety event.
Why?
Because major process incidents rarely begin at the moment of the explosion, fire, or toxic release.
They usually begin much earlier.
An inspection becomes overdue.
A safety-critical alarm remains unavailable.
A temporary modification stays in place longer than planned.
A relief valve develops a problem.
A HAZOP recommendation remains open.
An interlock is repeatedly bypassed.
A corrosion finding is not corrected.
Individually, these may look like small issues.
Together, they can indicate that critical safety barriers are deteriorating.
This is why organizations need both leading and lagging process safety indicators.
Process safety indicators are measurable signals used to understand whether a process safety management system and its critical controls are performing effectively.
They help answer two different questions:
“What has already happened?”
“Are our controls working well enough to prevent it from happening?”
A mature process safety system needs both.
Lagging indicators measure events that have already occurred.
They tell us that a process safety control has failed or that an unwanted event has taken place.
Common examples include:
These measurements are important because organizations need to understand their failures.
But there is a limitation.
A lagging indicator tells you that the barrier failed after the failure has occurred.
You cannot prevent yesterday’s incident.
You can only learn from it and prevent recurrence.
Leading indicators are proactive measurements.
They provide information about the health and reliability of controls before a major incident occurs.
Instead of asking:
“How many incidents did we have?”
leading indicators ask:
“Are we maintaining the conditions that prevent major incidents?”
That difference is fundamental.
Mechanical integrity is one of the most important areas for leading indicators.
Possible indicators include:
A pressure vessel does not suddenly become unsafe because an inspection becomes overdue.
The problem begins when the organization allows the condition of critical equipment to become unknown or uncontrolled.
That is why inspection backlog can be an important warning signal.
Alarms and interlocks are designed to help operators and systems respond to abnormal conditions.
Leading indicators can include:
Imagine a critical interlock is bypassed.
Nothing happens.
The plant continues operating normally.
If you only measure incidents, you may record:
Zero incidents.
But from a process safety perspective, something important has already changed.
One of your protective barriers is no longer providing its intended protection.
That is a leading warning signal.
Changes are a normal part of industrial operations.
But uncontrolled changes can introduce new hazards.
Useful MOC indicators include:
Temporary modifications are particularly important.
A temporary bypass may be approved for seven days.
Seven days becomes thirty.
Thirty becomes six months.
Eventually, people may forget why the bypass exists.
The equipment may continue operating with a degraded barrier.
That is exactly the type of deterioration a good leading-indicator system should expose.
Hazard identification is valuable only when identified risks are actually controlled.
Leading indicators can therefore include:
Ask:
How many high-risk recommendations are still open?
Then ask:
How long have they been open?
The second question can be even more important.
An open critical action that remains unresolved for months may indicate a deteriorating risk-control environment.
Human performance is another important component of process safety.
Possible indicators include:
The goal is not to punish employees for every deviation.
The goal is to identify whether the operating system makes safe performance reliable and repeatable.
Small leaks are often treated as minor events.
But they can provide valuable information.
Consider tracking:
A small hydrocarbon leak may not cause an incident today.
But repeated leaks can indicate:
Degrading equipment integrity → increasing loss of containment → increasing major accident potential.
Therefore, small events should not automatically be dismissed.
They can be early signals of a larger problem.
Think about process safety like a dam.
The dam has failed.
Which information would you rather receive?
Obviously, the second.
Because it gives you an opportunity to act.
The same principle applies to process safety.
This is one of the most important concepts in process safety.
A company can achieve:
Zero injuries
while simultaneously having:
Therefore:
Zero personal injuries cannot be used as proof that process safety risk is under control.
Personal safety and process safety are related, but they are not the same thing.
Simply having more safety activities does not automatically mean better process safety.
For example:
10,000 toolbox talks ≠ strong process safety
100% training completion ≠ effective safety barriers
More safety observations ≠ lower major accident risk
Zero injuries ≠ zero process safety risk
A useful indicator must be connected to a real hazard, critical control, or safety barrier.
The most important question is:
“Which major accident scenario does this indicator help us control?”
If there is no clear connection, the indicator may not be useful.
A good dashboard should not contain dozens of unrelated statistics.
It should provide management with visibility into the health of important risk controls.
A useful process safety performance chain can look like this:
Hazard Identification
↓
Risk Assessment
↓
Critical Controls
↓
Mechanical Integrity
↓
Management of Change
↓
Operating Discipline
↓
Alarm & Interlock Performance
↓
Emergency Preparedness
↓
Process Safety Event
The objective is to identify deterioration before it reaches the final stage.
For high-hazard facilities, one of the strongest approaches is to monitor critical barrier health.
Consider this scenario:
↓
↓
↓
Several barriers may exist between the initial release and the final consequence:
The question should not only be:
“Did an accident occur?”
The better question is:
That is where leading indicators become extremely valuable.
Leading and lagging indicators should not compete with each other.
They should work together.
What could happen?
What happened?
How effectively are we controlling process safety risk?
For example:
| Leading Indicator | Lagging Indicator |
|---|---|
| Overdue PSV inspections | Loss of containment |
| Interlock bypass duration | Process safety event |
| Open HAZOP actions | Fire or explosion |
| Overdue MOCs | Unplanned shutdown |
| Corrosion findings | Equipment failure |
| Alarm unavailability | Process incident |
This combination provides a much stronger picture than incident statistics alone.
Management should not simply ask:
“Are our numbers green?”
They should ask deeper questions.
These questions move process safety from measurement to risk control.
Traditional safety statistics can create a false sense of security when used alone.
Counting meetings, training hours, or toolbox talks does not necessarily show whether major accident risk is being controlled.
A dashboard with 100 metrics can make it difficult to identify the indicators that actually matter.
One overdue inspection may not be alarming.
But an increasing inspection backlog over six months is a different story.
An indicator has little value if nobody investigates poor performance or takes corrective action.
Instead of asking:
“How many incidents did we have?”
ask:
“Where are our safety barriers becoming weaker?”
Then ask:
“What are we doing about it?”
That is a much more mature approach to process safety management.
At The Safety Master (TSM), we believe process safety performance should not be measured only by the absence of incidents.
The real objective is to understand whether critical risk controls are present, available, effective, and continuously maintained.
A strong process safety system combines:
The best process safety indicator is not the one that tells you an incident happened.
It is the one that gives you enough warning to prevent the incident from happening.