The Hierarchy of Controls, and Why It Is Harder Than It Looks

IN SHORT

The hierarchy of controls ranks five ways of dealing with a hazard — eliminate, substitute, engineering controls, administrative controls, PPE — from most effective to least. The order tracks one thing: how much the control depends on a person doing the right thing in the moment.

Most corrective actions in practice land near the bottom. Usually not by preference, but because the bottom is affordable, quick and leaves an evidence trail, and the top is none of those.

Frameworks in health and safety come and go. This one has lasted the better part of a century, across industries with almost nothing else in common. That is worth understanding.

What is the hierarchy of controls?

The hierarchy of controls, drawn as an inverted pyramid. From most effective at the top:
eliminate, substitute, engineering controls, administrative controls, PPE. Effectiveness falls as
the control depends more on human behaviour.
The hierarchy of controls. Teal bands are designed-in; purple bands depend on someone getting it right on the day.

It appears in HSE guidance, in ISO 45001, in the NEBOSH and IOSH syllabuses — in the first week of nearly every safety qualification taught anywhere.

Why is the order the way it is?

Eliminating a hazard works whether or not anyone is paying attention. A guard rail works while someone is tired, distracted, new to the site, or having a difficult day. A procedure works when it has been read, remembered, understood and followed — which is often, but not equally on every shift. PPE works when it is worn correctly, maintained, and to hand at the moment it is needed.

That is not a comment on people. It is a comment on design.

The hierarchy is one of the few frameworks that says plainly: build the control so that it does not need anyone to be at their best.

So why do most corrective actions end in a briefing?

Because working up the hierarchy is not simply a matter of deciding to.

A toolbox talk can be arranged for Tuesday. It takes an hour. It leaves an attendance record — something an auditor, an insurer or a board can be shown.

Segregating vehicles from pedestrians takes capital, design work, downtime and a conversation with operations about throughput. It may take a year, and for most of that year there is nothing to show.

So the safety professional recommending the briefing is usually not choosing the easy option over the right one. They are working inside a budget cycle and an audit calendar, getting a real control in place this week rather than a better one possibly next year. That is a reasonable judgement, made in good faith, thousands of times a day.

The hierarchy is not a scolding. It is a way of knowing how much weight a control can carry before you rely on it.

What did the major thinkers add?

Timeline of safety thinking: Heinrich 1931, first systematic study of accident causation; Reason
1990, latent conditions versus active failures; Rasmussen 1997, drift toward the safety boundary;
Hollnagel 2014, Safety-II and how work goes right.
Ninety years of refinement — each one widening the lens from the person to the conditions around them.

Heinrich (1931) gave the field its first systematic look at accident causation, at a time when almost nobody was collecting data at all. The discipline exists in its modern form partly because someone thought to count.

Reason (1990) separated active failures — what happened at the sharp end — from latent conditions, the upstream decisions that shaped what was possible. Investigations naturally find the visible, recent thing. The more durable findings usually sit further back.

Rasmussen (1997) added time. Organisations adapt, which is a strength — but under steady pressure to be efficient, practice migrates toward the edge of the safe operating space in small, locally sensible steps. A barrier that has been removed is obvious. A practice that has quietly evolved looks much like the one that was written down.

Hollnagel (2014) reframed what we measure. Safety-I is the absence of things going wrong. Safety-II is the presence of things going right — the shifts that went well, and why.

None of this overturns the hierarchy. All of it explains why the hierarchy is right.

Does culture change what a control is worth?

Yes, and it is worth saying plainly.

A written procedure carries different weight on a site where people feel able to stop the job than on one where they do not. A near-miss system reflects how safe it feels to report. Shift patterns, language, contractor mix, how long people have worked together — all of it changes what a level-four control is actually worth on a given Tuesday.

That is not a reason to be pessimistic about administrative controls. It is a reason to look at the site in front of you rather than the one in the textbook, and to ask the people who do the work what would genuinely help.

How do you tell if a control is strong enough?

One question, and it can be asked without blaming anyone:

If the person doing this had a genuinely difficult day — tired, rushed, covering for a colleague, new to the site — would this control still hold?

If yes, it is probably an engineering control or better. If it depends on them remembering the briefing, it is a level-four control doing its honest best. That is not a failing. It is information, and it is useful when deciding where the next pound and the next hour should go.

Where this is heading

The encouraging part is that the profession is already moving this way. Learning teams, human and organisational performance, Safety-II thinking, the growing interest in leading rather than lagging indicators — all versions of the same shift: from asking why something went wrong to asking how the work actually happens, and designing from there.

What has changed most recently is not the principle but the visibility. It has always been hard to see how work is really done across a whole site, on every shift, over months. The more clearly we can see that, the easier it becomes to find the conditions worth changing rather than the moments worth correcting.

The hierarchy of controls has been right since it was written down. It has simply been asking for something the field is now much better equipped to give it.

Common questions

What is the hierarchy of controls? A ranking of five ways to deal with a workplace hazard, ordered from most to least effective: eliminate, substitute, engineering controls, administrative controls, and personal protective equipment. It appears in HSE guidance and is a normative requirement of ISO 45001:2018, clause 8.1.2.

Why is elimination ranked above PPE? Because the order tracks how much each control depends on a person doing the right thing at the moment it matters. An eliminated hazard cannot hurt anyone whether or not attention is being paid. PPE only protects if it is worn correctly, maintained and to hand.

Why do so many corrective actions end in retraining? Administrative controls are quick, affordable and leave an evidence trail — a briefing can happen this week and produces an attendance record. Engineering controls need capital, design work and downtime, and may take a year with nothing to show in the meantime. It is usually a constraint, not a preference.

What is the difference between Safety-I and Safety-II? Erik Hollnagel's distinction. Safety-I measures the absence of things going wrong — injuries, lost time, days since the last incident. Safety-II looks at the presence of things going right: the many shifts that went well, and the conditions that made them go well.

Are administrative controls bad? No. They are a real control and often the right one available at the time. The hierarchy simply indicates how much weight a control can carry, which is useful information when deciding where the next pound and the next hour should go.


References