Why ‘Compliant’ Doesn’t Mean Safe

Date Published:
Date Reviewed:
TL;DR
Compliance proves you met the standard on the day, not that you are still safe as the plant changes, and the gaps that matter most are the ones your own team is too close to see.

A good GP doesn’t read your MRI. They refer it to a radiologist. That isn’t a gap in the GP’s ability. Reading scans is a specialism, and nobody treats the referral as a failure. It’s just how medicine handles the point where general expertise meets a problem that needs a specialist eye. Good care uses both, with the specialist brought in exactly where a miss would matter most.

Process safety works the same way.

Expecting one in-house person, or a single general competent person, to cover everything, stay current on everything, and stay genuinely independent of the site they’re assessing is a lot to ask of anyone.

Compliance Is a Snapshot. Safety Is Not.

If you manage process safety at a site with DSEAR, COMAH, or major accident hazards, your role comes down to one question: is your site’s process safety competence fully covered?

Compliance doesn’t equal safety, and the gap between them is easy to miss from the inside.

Your Management of Change procedures and risk assessments exist. But what happens when a line gets repositioned, a team turns over, or a procedure that was right two years ago quietly stops matching the plant? That’s where the gap opens.

Process Safety Insight

Compliance proves you met the standard on the day. Safety is whether you still meet it at 3am on a bad shift.

And this gap is hardest to see for the people closest to it.

The People Closest to the Risk See It Least

If you wrote the basis of safety for a unit, you’re the least likely person to challenge it, because challenging it means second-guessing your own past judgement. If you own a control, a near-miss against it reads as something to log and close, not as a sign the underlying logic was wrong.

Process safety has a name for this, normalisation of deviance. A small abnormality gets tolerated, then expected, then built into how the site runs. Then it stops looking like a risk at all.

Buncefield is the textbook case. The automatic tank gauge that should have registered the rising fuel level had been sticking intermittently for months after a service. The unreliability was known, and it was never acted on. The independent high-level switch that should have caught the overfill was effectively inoperable. The MIIB investigation traced it back not to a single broken part, but to management that had stopped treating an obviously unreliable system as a problem.

Process Safety Insight

A fresh, independent pair of eyes finds what the people who know the site best have stopped noticing.

The people at Buncefield were not incompetent, and that’s the uncomfortable truth. What they were missing wasn’t technical knowledge. It was distance.

We'll are your Process Safety Guide

Our consultancy team are on hand to discuss your requirements and provide actionable safety solutions.
Contact Us

Competent for What?

Under the Management of Health and Safety at Work Regulations 1999, you must appoint a competent person. Most businesses do. But the question is, competent for what?

The regulations define competence broadly: the training, knowledge, experience, and qualities to manage risk well. That breadth is the catch. It doesn’t tell you that general health and safety competence and process safety competence are different disciplines sharing one regulatory wrapper. General competence covers the slips, trips and noise every workplace shares. The major accident hazards, explosive atmospheres under DSEAR, loss of containment, runaway exothermic reactions, are a different discipline entirely.

That distinction isn’t ours to invent. For upper-tier COMAH sites, HSE expects the safety report to demonstrate a competence management system. You must show how you select competent personnel, identify their training needs, and assure they have enough competence to prevent the major accident hazards specifically.

There’s a third competence the regulations never name: independence. It’s the one part no in-house appointment can supply, because no one is placed to audit their own decisions.

So the question isn’t whether your competent person is good at their job. Assume they’re excellent. It’s whether process safety is genuinely covered as a specialism in its own right, and whether anyone independent is positioned to challenge the calls your own team is too close to question.

Five Questions That Expose the Gap

The three tie together, because the integration is the evaluation.

Reaction calorimetry gives you the cooling-failure picture. Follow it and you can see the adiabatic temperature rise and the MTSR that results. Screening data tells you wh

These aren’t a test to spring on a person. They’re what process safety competence has to cover on a major-hazard site. Run them against your current setup, in-house or otherwise, and see whether each one is genuinely covered. Where the answer is no, that’s a gap between compliant and safe worth closing.

  • Reading the process, not just the paperwork. Can someone walk the line and show where the documented basis of safety has drifted from what’s running?
  • Challenging a DSEAR zoning classification and defending the challenge. Not confirming the zoning exists but interrogating whether it still matches how the area operates today.
  • Telling a control that exists from a control that works. A documented Management of Change procedure and a functioning MOC process are not the same thing.
  • Reading a near-miss as a signal, not a log entry. Connecting it to the latent failure it’s pointing at.
  • Knowing what to prove, not just what to assume. When a control rests on a material property, like a dust’s ignition energy or a substance’s thermal stability, that’s something to measure, not estimate.

If every one of those is covered for your site, you’re in a strong position. If one or two aren’t, it may demonstrate the structural limit of asking a single person or team to span a broad specialism on its own.

This is exactly what an independent review is for, and what it covers comes next.

ether that MTSR is high enough to trigger a secondary reaction or decomposition, and if it is, you’ve confirmed a credible worst case. Adiabatic testing then simulates that exact scenario to validate it and generate the scalable numbers that size your relief systems.

None of that data stays in the lab. It feeds the assessments your process safety colleagues run, such as DSEAR, HAC and dispersion modelling, PSM, HAZID and HAZOP, and LOPA. Testing, interpretation, and the assessment that turns numbers into a safe design all work better when they aren’t handed across three organisational boundaries. That is the practical case for keeping evaluation, consultancy, and training under one roof, which is how we run it. The data arrives already understood.

Run the other way and the arithmetic gets ugly. Skip the sequence and you either over-characterise everything to be safe, which is slow and expensive, or you find the gap at pilot after the process is locked and the regulatory studies are running, which is the most expensive place there is to find it. The integrated evaluation is not the thorough option instead of the cheap one. Sequenced properly, it is the cheap one.

A Review That Reads the Floor, Not the File

You commission the point assessments as they’re triggered. A Fire Risk Assessment here, a DSEAR study there, a round of training when something prompts it. What almost no site has is a structured way to review the whole safety management system on a planned cycle, so the gaps between those point assessments don’t quietly widen.

That review is a legal expectation, not just good practice. The Management of Health and Safety at Work Regulations 1999 require your risk assessments to be “suitable and sufficient” and kept under review, not written once and filed.

A Comprehensive Safety Review closes that gap. We act as your external competent person and review the whole system in one structured pass, covering policy and permits, COSHH and DSEAR, fire and emergency planning, contractor control and the high-risk activities.

Breadth is the easy part to buy.

The danger is what that report does when it reaches the corners that can cause a major accident. A generalist ticks the box and moves on. It goes green, and you have no way of knowing the control behind it doesn’t hold. A specialist stops and tests whether it does, and when it can’t be assumed, measures it instead of guessing.

Because risks move, the review repeats. We run it on a six-monthly cycle, frequent enough to catch the changes that matter, a new material or a repositioned line, and to verify that the actions from last time were closed rather than just logged. Over a couple of cycles, you build the evidence trail that a Plan-Do-Check-Act approach and ISO 45001 both expect. This is what an inspector or insurer wants to see.

Example 1: DSEAR and Battery Storage

Take a cleaning room we assessed, where the vented traction batteries for the site’s lifting equipment were left on charge.

The paperwork didn’t flag it, because on paper a battery on charge is just a battery on charge. But a vented battery gives off hydrogen as it charges, and the walk found where it went. Up, into a pocket under a low ceiling, right where the light fittings sat, and none of them ATEX-rated. The door stayed shut for hours through a charge and the ventilation was poor, so the gas had nowhere to go and an ignition source waiting for it.

Nothing in the file was wrong. The file just didn’t know the hazard was being created. We moved the charging out to the warehouse, where the ceiling is high, the gates are wide, and hydrogen never gets the chance to collect.

Example 2: Thermal Stability and Hydrogen Peroxide

When a control rests on a material property, many pull a figure from the literature or reason from a comparable material instead of measuring it.

Take industrial-strength hydrogen peroxide. On the shelf it reads as a routine oxidiser, and plenty of sites keep it in an IBC in the yard without a second thought. But it decomposes exothermically, and the warmer it gets the faster it goes. Leave that IBC in direct sun and solar heating alone can start the reaction accelerating, generating oxygen and heat faster than the container can shed them. We have seen that end the way it sounds, an IBC that warmed through in the sun and let go. Nothing exotic happened. The substance did what its decomposition curve always said it would, for anyone who had measured the curve.

That is the whole gap between assuming a substance is stable and knowing the temperature at which it stops being stable. A DSC or ARC run tells you where the exotherm begins and how hard it accelerates, so a storage decision rests on the material’s real onset instead of the fact that it has sat there quietly so far.

We’re the only UK laboratory accredited for the combined dust-explosion and DSC/ARC test battery, backed company-wide by our ISO 9001 Quality Management System. When a decision turns on whether a dust is ignitable or a reaction can run away, that’s the difference between data a regulator or insurer accepts without argument and a number you’re hoping holds.

This is the radiologist reading the scan, the specialist who measures what a good generalist can only estimate.

The Bottom Line

Most sites that get caught out aren’t missing safety systems. They have the policies, the assessments, the procedures, all filed and all current. What they’re missing is someone independent, with the right specialism, checking whether those systems still hold as the plant changes around them.

Process Safety Insight

A report tells you where you were. A partner tells you where you’re drifting.

Work through the five questions this week. If one or two aren’t clearly covered, that’s where a specialist eye makes you safer.

Book a technical call with one of our competent persons and we’ll pressure-test where your competence reaches.

On-Demand: What a working COMAH framework actually looks like

Learn more about process safety in our FREE on-demand webinar. 

Watch Now

Table of Contents

Contact Us

We'll Guide Your Process Safety Strategy

Free Technical Consultation
Cross-Functional Support
Global PSM Support

Frequently asked questions

It meets the duty to appoint, but not the harder test of whether that person is competent for your major accident hazards specifically. General health and safety competence and process safety competence are different disciplines, and for COMAH sites HSE expects you to demonstrate the latter.

It is a structured, whole-system review by an external competent person, run on a planned cycle. An audit checks whether the paperwork exists. A Comprehensive Safety Review tests whether the controls behind that paperwork actually hold on the floor.

Experience is not the issue. No one is well placed to challenge the basis of safety they wrote themselves, so an independent reviewer catches the drift and the assumptions your own team has stopped noticing.

You can estimate when nothing hangs on it. But when a control rests on whether a dust ignites or a substance runs away, an estimate is a liability. Accredited DSC or ARC testing gives you a defensible onset temperature a regulator or insurer will accept.

sigma-hse-logo
Are you visiting Sigma-HSE from outside your region? Visit your regional site for more relevant process safety solutions.
North & South America
UK, Europe & Rest of World