Female project assurance consultant observing digital gears and data analytics on a large transparent screen in an industrial control room.

Who Is Assessing Your Operating Management System?

8
Mins

Key Takeaways

  • IOGP Report 510 treats independence as a spectrum starting at self-assessment. An operator can meet the framework while grading its own work.
  • Third-party certification tests conformance to a standard on a sampled basis, over a three-year cycle governed by ISO/IEC 17021-1. Its scope is documented conformance rather than demonstrated control of operational risk.
  • The Baker Panel found that BP's process safety audits focused on whether required management systems were in place to satisfy legal requirements, rather than on whether those systems were delivering safety performance.
  • The peer-reviewed evidence is mixed. Research across 5,147 firms found certification only loosely related to accident rates, while later research in Safety Science found a measurable effect alongside a strong selection effect, with safer sites more likely to certify in the first place.
  • Independent review of an operating system is already mandated where consequences are catastrophic. The Global Industry Standard on Tailings Management requires an Independent Tailings Review Board for the highest-consequence facilities.
  • Accredited certification bodies operating under ISO/IEC 17021 cannot provide management system consultancy to a client and then certify that same client. Independent providers fill parts of the remaining space, but structured, board-commissioned review of the whole operating management system remains outside standard practice.

Almost every operator in the Energy, Minerals and Resources (EMR) sector runs an Operating Management System or an Integrated Management System. It has been designed, documented, rolled out, audited and in most cases certified. The framework exists, the element owners are named, and the assurance schedule is populated.

A narrower question tends to go unasked at board level. Who last formed an independent view on whether that system is controlling risk, as operated, at its current level of maturity? The question is about function rather than documentation. Does the system work?

For most operators the honest answer is that the work was narrower than the question, and commissioned by the people who own the answer: the corporate function that owns the system, an internal audit team with limited process safety depth, or a certification body working to conformance rather than effectiveness. Each of those is a legitimate activity. None of them answers the question a board needs answered.

What Does IOGP Report 510 Require of Assurance?

Report 510, the industry's reference framework for operating management systems, places assurance in Element 10. It asks that a documented, risk-based assurance process be established, and that this process include scheduled independent audits. It also asks that managers formally review the effectiveness and fitness for purpose of the system.

The detail worth reading closely sits in the glossary. Report 510 describes audits as varying in the extent of their independence, ranging from assessment performed locally within an activity or asset, through auditors appointed internally from elsewhere in the organisation, to third parties external to the company. Independence is presented as a spectrum, and the lowest point on that spectrum is self-assessment.

Report 510 is also explicit that it does not mandate requirements. It is guidance, deliberately written without the language of obligation. Report 511, the companion document on OMS in practice, goes further than most operators apply, recommending that the degree of independence be varied deliberately and that auditors with fresh eyes be engaged alongside those familiar with the facility, including third parties with experience of other operators and other high-hazard industries.

The practical result is a framework that leaves the degree of independence to the operator's judgement, and permits a well-run operator to meet the framework's expectations largely from inside its own organisation, entirely in good faith. Report 510 does not compel independence. Regulators, corporate governance codes, insurers, joint venture partners and investor expectations often do, and no operator of consequence designs its assurance programme from 510 alone. The question is whether those overlaying drivers reach the operating management system as a whole, or only the specific elements each of them cares about.

What Does a Certification Audit Test?

Certification is often read, particularly outside the technical functions, as the independent check that closes this gap. Mature operators know better and treat the certificate as a baseline. The gap sits between what certification claims for itself and what a non-technical stakeholder assumes it claims, so it is worth being precise about what it covers.

Under ISO/IEC 17021-1, audit duration is driven principally by the effective number of employees, multi-site sampling is permitted, and certification reports carry an explicit statement that auditing is based on a sampling process of the available information. The cycle runs from initial certification through annual surveillance to recertification at three years. The auditor is testing conformance of a documented system against a generic standard, within a time-boxed sample.

That is a useful discipline. It is also a narrower one than the certificate implies, and the research on the link between certification and safety outcomes is genuinely mixed. A study of 5,147 Spanish firms published in the Journal of Safety Research found occupational health and safety certification only loosely related to accident rates. Work in Safety Science in 2024 found a measurable reduction in injury and illness cases following certification, while quantifying a strong selection effect in which each additional case of the most severe type was associated with a substantially lower likelihood of an establishment becoming certified.

The two studies reach different conclusions on whether certification improves performance. What they agree on is that the certificate carries information about the organisations that seek it, and not only about the effect of holding it.

A board could reasonably read the selection effect as encouraging. If safer sites seek certification and certification is associated with lower injury rates, some combination of internal motivation and external scrutiny is working. That reading holds, and it holds for the outcome both studies measure, which is occupational injury and illness. Process safety and major accident risk are a different exposure, governed by different controls, and neither study measures them. This is the substitution the Baker Panel identified at Texas City, where improving personal injury rates were read as evidence of acceptable process safety performance.

What the Incident Record Shows About Audit Independence

The strongest evidence for independent assessment comes from investigations into events where the management system was formally in place and, in several cases, externally certified.

  • BP Texas City. The Baker Panel raised concerns about auditor qualifications, audit scope, reliance on internal auditors and limited review of findings. It also recorded that BP had interpreted improving personal injury rates as an indication of acceptable process safety performance.
  • Piper Alpha. The Cullen inquiry found the permit to work system had been habitually departed from, and that training, monitoring and auditing had been poor. Management had treated the absence of feedback on problems as an indication that the system was operating correctly.
  • Montara. The Commission of Inquiry found the operator had not adhered to its own approved well construction standards, and that not one well control barrier had been satisfactorily tested and verified. The standards existed. Verification of their application did not.
  • Pike River. The Royal Commission found the safety management system lacked procedures making specific people responsible for collecting, assessing and responding to safety information. Two third-party reviews in 2010 raised serious concerns that the Commission considered an alert board would have found revealing.
  • Brumadinho. A certifier's subsidiary signed a declaration of stability for the Feijão dam in September 2018, months before a collapse that killed 272 people. The documented sequence records drainage problems observed earlier that year and a declaration of stability issued regardless.

These cases do not establish that independent assurance would have prevented any of them. Each involved failures of leadership, culture and regulatory oversight that no assurance arrangement corrects on its own, and a reasonable reader could argue that what was missing was the willingness to act on uncomfortable findings rather than a different provider of them. The narrower claim is the one the investigations support. In each case the assurance arrangements in force reported comfort while the risk was live, and the substitution of documented conformance, and of lagging personal safety indicators, for a view on whether controls were working is what allowed that comfort to persist.

The willingness objection also cuts both ways. Independence changes who delivers an uncomfortable finding and who receives it, which is precisely the mechanism the Pike River Royal Commission identified when it noted that two third-party reviews in 2010 raised concerns an alert board would have found revealing. The findings existed. The route from finding to board did not. This is the same divergence between reported status and observed reality that independent review addresses in capital projects, applied to the operating system rather than to a single investment decision.

Project Assurance professional in reflective gear overlooking offshore oil rig with digital safety and weather data visuals.

Where Independent Assurance Is Already Expected

Independent assurance of an operating system is established practice in the Energy, Minerals and Resources sector wherever the downside is severe enough.

The UK offshore regime requires operators to appoint an independent and competent person to verify safety critical elements, with verifier findings functioning as leading indicators. Australia's NOPSEMA requires that a safety management system be implemented in practice and used as the primary means of ensuring safe operation, with validation of safety critical systems by an independent competent party. In mining, the Global Industry Standard on Tailings Management requires an Independent Tailings Review Board for facilities with extreme and very high consequence classifications. In pipelines, API Recommended Practice 1173 separates conformance assessment from evaluation of effectiveness, and supports both through a third-party assessment programme.

Each of these accepts a principle that most operators have not yet extended to the management system as a whole. Where consequences are severe, assurance should sit outside the function that owns the thing being assured.

What Independent OMS Assurance Should Cover

Independent assurance of an operating management system asks a different set of questions from a certification audit. It examines whether decision rights are clear and exercised as designed. Whether escalation routes function when tested rather than when described. Whether competence requirements match the roles as they are now performed. Whether management of change captures changes that originate outside the traditional change initiator model, including changes introduced by automated and AI-enabled systems. And whether the system's maturity, honestly assessed, matches the risk it is being asked to control.

The distinction that matters most is between the aspirational starting point and the forensic one. An operator that intends to become a top-quartile performer has stated an ambition. An operator that knows its current planned-to-reactive maintenance ratio, its actual wrench time, where its production variance originates and what the daily operating decisions look like that produce current performance has established a baseline. Work that begins from the ambition tends to confirm it. Work that begins from the operating data tends to find things.

Industrial valve and pipe with augmented reality overlay showing critical failure points

Timing matters too. Systems drift. Practice diverges from procedure gradually and without announcement, which is why work as done and work as imagined separate over time in every operating environment. A system assessed as sound at design is not evidence of a system controlling risk today, and the interval since the last genuinely external look is usually longer than the interval assumed.

The structural point is worth stating plainly, and stating narrowly. Accredited certification bodies operating under ISO/IEC 17021 cannot provide management system consultancy to a client and then certify that same client. Internal audit, whatever its quality, reports from inside the organisation it examines. Independent providers do fill parts of the remaining space, through technical safety audits, specialist consultancy reviews, joint venture partner assessments and insurer-commissioned work, and mature operators use them.

What is uncommon is the whole-system view. Those engagements are typically scoped to an element, an asset or a hazard, commissioned by the function that owns it, and reported into that function. A structured, board-commissioned review of whether the operating management system as a whole is controlling risk at its current maturity remains outside standard practice in the Energy, Minerals and Resources sector. That is the gap worth closing, and it is narrower than the sector's assurance spend would suggest.

PDAS begins from an independent operational maturity assessment: a forensic read of how the operating management system performs in practice, assessed against the expectations of IOGP Report 510 and the ISO management system standards operators already hold. Independent by structure, PDAS issues no certificates, sells no technology and takes no vendor commissions.

Book a discovery call with our team.

References

Read More Governance Insights