The most reliable control is often the project choice that removes the exposure before operations begin.

Risk registers can create the impression that managing risk means identifying an event, assigning a rating and listing a control. That is necessary, but it can become dangerously procedural when the project team assumes the underlying design is fixed.

Some risks should never reach the operating phase in their original form.

If a different layout, technology, process, location or staging approach can materially reduce exposure, the risk discussion belongs inside design. The organisation should not accept an avoidable lifetime burden simply because it has a plausible operating procedure.

This is especially important for environmental and infrastructure decisions because many consequences are long-lived. The stronger question is not “What control can we add?” but “Why are we designing the exposure into the asset?”

The Strategic Context

The supplied EPA Victoria guidance places controls in a hierarchy: elimination is strongest, followed by substitution or engineering controls, while administrative controls depend more heavily on human behaviour. That hierarchy is familiar in safety, but its strategic implication is often underused in project governance.

Risk treatment should influence the design baseline.

The Eastern Leases environmental risk assessment shows this clearly. An unconstrained mine design was assessed first. Significant environmental and social risks were then used to reshape the preferred design. Some exposures were eliminated through design changes rather than merely reduced through procedures.

For executives, this matters because design choices determine the organisation's residual risk profile for years after the project team has disbanded.

What Leaders Commonly Misread

A common mistake is to compare controls only by implementation cost. A procedural control may be cheap to introduce but expensive to sustain because it requires training, supervision, inspection, monitoring and repeated human compliance.

Another misread is to treat residual risk as an operational matter. If residual risk is created by the design, the sponsor and design authority share responsibility for it.

Teams can also become overconfident in layered controls. Several weak controls do not automatically equal one strong control. If each relies on the same human behaviour, maintenance regime or information system, they may fail together.

Finally, risk matrices can obscure design choices. A project may spend time debating whether a consequence is “moderate” or “major” while the more valuable question is whether the exposure can be removed.

Reframing the Issue

Risk treatment should be viewed through lifetime control economics.

A control is not just an item in a register. It is a future operating obligation. Leaders should consider:

  • whether the control operates independently of human action;
  • how often it must be inspected, tested or renewed;
  • what happens when the organisation restructures, outsources or loses experienced staff;
  • whether the control remains effective under abnormal conditions;
  • whether the control creates new interfaces or failure modes;
  • whether the risk could instead be removed through design.

This creates a useful distinction between designed resilience and managed vigilance.

Designed resilience reduces dependence on perfect behaviour. Managed vigilance assumes people and systems will continue to notice, remember and act correctly. Both are sometimes necessary, but they are not equivalent.

Strategic Analysis: Design Changes Can Convert Risk into Simplicity

The Eastern Leases material contains a particularly strong example. The unconstrained design contemplated mining beneath watercourses and using diversion arrangements. The preferred design ultimately avoided mining beneath watercourses. The mitigation was not another inspection, warning, procedure or contingency plan. The activity creating the specific exposure was removed from the project configuration.

That is risk treatment at its strongest.

The same principle applies elsewhere.

A hypothetical manufacturing plant could manage chemical spill risk through procedures and spill kits, or redesign storage with smaller inventories, segregation, bunding and automated isolation. A hospital could manage logistics conflicts through daily coordination, or redesign flow paths to separate public and service movements. A digital system could rely on users not to expose sensitive information, or redesign access permissions so inappropriate access is technically prevented.

In each case, the preferred treatment should move upstream where feasible.

The design decision has an owner

A recurring governance weakness is unclear ownership. Project managers coordinate, specialists advise, operators inherit and executives approve. When a residual risk remains, each party may believe another owns it.

A stronger governance model identifies:

  • who can change the design;
  • who accepts residual risk;
  • who operates the controls;
  • who funds monitoring and maintenance;
  • who can stop the project if the risk exceeds appetite.

Without this clarity, the organisation can “approve” a risk without actually assigning the future obligation.

Risk reduction must be demonstrated

The Eastern Leases assessment compared unmitigated and mitigated risk. Its value lies in showing the effect of design and control measures rather than merely listing them.

Organisations should adopt the same logic. For material risks, governance should see the baseline exposure, the treatment mechanism, the expected residual exposure and the evidence supporting control effectiveness.

This also creates a better basis for monitoring after handover.

Related article: Monitoring Is Part of the Decision, Not an Afterthought

Stronger controls can have strategic trade-offs

The hierarchy of controls should guide judgement, not replace it. Eliminating an environmental exposure may reduce production capacity, increase capital cost, create a different safety risk or undermine another strategic objective. Substitution may transfer impact elsewhere rather than remove it.

This is why design reviews need multidisciplinary participation. Engineering, operations, environment, safety, commercial and stakeholder perspectives should examine the same option rather than optimise separate versions of it.

The key is to compare whole-system consequences. A more expensive design can be justified when it materially reduces lifetime risk and operating burden. Equally, a lower-order control may be reasonable where the consequence is limited, the control is demonstrably reliable and stronger treatments would destroy disproportionate value.

The leadership responsibility is to make the trade-off explicit and to avoid presenting a commercial preference as though it were an unavoidable technical constraint.

Decision Framework

Before accepting a material residual risk, ask:

TestDecision question
EliminationCan the activity, interface or exposure be removed?
SubstitutionCan a safer technology, material, location or process achieve the same outcome?
EngineeringCan the design prevent or contain the event without depending on behaviour?
AdministrativeWhat procedures, training and supervision remain necessary?
Residual exposureIs the remaining risk within appetite and practical to sustain for the asset life?

The framework should not be applied mechanically. Eliminating one risk can create another or undermine value. The point is to make the trade-off visible.

For irreversible or high-consequence exposures, leaders should require stronger evidence before accepting reliance on administrative controls alone.

From Strategy to Execution

Immediately, major design reviews should include a risk-treatment challenge: which top risks are being reduced through design rather than procedure?

In the medium term, organisations should integrate the hierarchy of controls into option-selection criteria, not just workplace risk assessments. Design authorities and sponsors should be required to justify material residual risks that remain because a stronger design treatment was rejected.

Longer term, operating data should feed back into design standards. If particular controls repeatedly fail, require excessive maintenance or generate incidents, future projects should redesign the underlying interface.

Related article: Environmental Assessment Is an Investment Decision, Not an Approval Task

Signals to Monitor

Watch for risk registers dominated by training, signage, procedures and inspections; repeat incidents attributed to “human error”; controls whose effectiveness depends on a small number of experienced employees; escalating monitoring burden; and projects handing over risks that operators were not involved in accepting.

Another warning sign is a design team that describes environmental or operational controls as “the operator's problem”. That indicates governance has separated project optimisation from lifecycle value.

Questions for the Leadership Team

  1. Which of our top residual risks exist because of a design choice we could still change?
  2. Are we relying on people to compensate for a weak physical or system design?
  3. Who has authority to alter the design, and who has authority to accept the residual risk?
  4. What is the lifetime cost of the proposed control, not just its implementation cost?
  5. What evidence shows that the control will remain effective under abnormal conditions?
  6. Which lessons from operations should become mandatory design principles for future projects?

Closing Perspective

Risk treatment is not complete when the register has a control beside every hazard.

The more important leadership test is whether the organisation used the risk process to improve the design itself. A project that eliminates a material exposure may require more thought upfront, but it reduces dependence on permanent vigilance after handover.

Where risk can be designed out, accepting it and managing it forever is rarely the strongest strategic choice.