The problem

In many organisations, the risk rating on a permit decides how much scrutiny the work receives. A higher rating may mean an additional reviewer, a more senior approver or a longer wait. A lower rating means the work can start sooner.

That link is sensible, but it creates an incentive. Under time pressure, a requester may choose a lower likelihood, a milder consequence or a more optimistic view of how effective the precautions will be. Nobody intends to hide anything; the rating simply drifts towards the answer that keeps the job moving.

Sospita's own Permit to Work guide states the principle plainly: don't underestimate risks to speed up approval.

Why it matters

A risk rating is not paperwork attached to the permit. It decides who looks at the work, which precautions are considered sufficient and what level of risk the organisation has knowingly accepted.

When a rating is understated:

  • The permit may skip the reviewers who would have challenged the plan.

  • Precautions are judged against a smaller risk than the real one.

  • The record shows a level of risk that was never actually present, which misleads anyone reviewing the permit later, including after an incident.

  • Over time, ratings across the organisation lose meaning, and trend data built on them becomes unreliable.

Understatement also tends to be invisible. An over-cautious rating is noticed because it slows work down. An understated rating is usually noticed only when something goes wrong.

A practical approach

Reducing this pressure is partly about culture and partly about how the process is designed.

Rate consequences in more than one dimension. A single severity score invites averaging. Rating consequences separately for People, Asset, Environment and Reputation makes the assessment more honest: work that is low risk to people may still be high risk to an asset or the environment, and that should be visible to the approver.

Start from a reasoned default. For known work types and hazards, the organisation usually already knows the minimum credible risk. Capturing that in a hazard library gives every requester the same starting point.

Treat lower ratings as claims that need support. If a requester believes risk is lower than the default, that is a reason to discuss the specific controls, not a reason to change a number quietly.

Separate speed from rating. If approvals are too slow, fix the workflow: clarify who approves what, reduce unnecessary steps, and make the information approvers need easy to see. Do not fix speed by making work look less risky.

Keep the decision with people. The rating informs the approver. It does not replace the approver's responsibility to decide whether the work can proceed.

What a good system should provide

A good Permit to Work system supports honest rating rather than relying only on good intentions. It should:

  • Rate residual risk per hazard, not only for the permit as a whole.

  • Show consequences across several dimensions, with a clear legend so ratings are interpreted consistently.

  • Prevent ratings from being set below a defined minimum for known hazards.

  • Present the rated risk clearly to approvers, so a high rating is noticed rather than buried.

  • Keep a time-stamped history of who submitted and approved the permit.

How Sospita SafeGuard addresses it

In Sospita SafeGuard, each hazard on a permit is assessed for residual risk using a 5×5 likelihood and severity matrix, with separate severity ratings for People, Asset, Environment and Reputation. Approvers see a colour-coded risk level for each hazard, supported by a risk legend and priority levels.

Hazards and their default ratings come from the organisation's hazard and precaution library, which is linked to work types. SafeGuard applies a residual-risk floor: residual ratings cannot be set below the defaults defined in that library. A requester can record a higher risk than the default, but not a lower one.

Approval itself follows the organisation's configured workflow. Each step can only be acted on by the user groups assigned to it, and every action is recorded in the permit's time-stamped timeline. For a broader view of what a permit system should control, see What Should a Digital Permit to Work System Actually Control?.

Limitations and human responsibility

A residual-risk floor prevents one common form of understatement. It does not guarantee that ratings are correct.

The floor is only as good as the library behind it. If default ratings are set too low, the floor will be too low as well. Libraries need periodic review by competent people who understand the work.

Ratings above the floor can still be inaccurate. A requester can choose a likelihood that is too optimistic within the permitted range, and an approver can accept it. The system makes the rating visible; it does not validate the judgement behind it.

Finally, the approval decision belongs to people. SafeGuard records who approved the permit and when, but the responsibility for accepting the risk rests with the authorised approvers and the organisation, not with the software.