Your Safety Dashboard Is Green. So Why Do the Same Findings Keep Coming Back?
A finding can recur across an entire fleet without disturbing a green dashboard, provided it receives a new reference number and is closed each time.
On paper, the organisation appears responsive. Audits are completed, corrective actions are assigned, safety alerts are distributed and findings are closed before becoming overdue. Management receives a dashboard dominated by green indicators.
Then another auditor visits another vessel and finds substantially the same weakness. That should force an uncomfortable question: if the problem has returned, what exactly was closed?
Maritime organisations do not lack incident reports, audit findings, safety alerts or lessons-learned material. The weakness is often what happens afterwards. Individual defects are corrected and actions are recorded as complete, but the organisation does not always establish whether its underlying controls changed or whether those changes worked. Administrative closure is being mistaken for organisational learning.
Familiarity can make an exposure invisible
Some operational problems remain in place not because nobody knows about them, but because everybody has become accustomed to them.
I encountered a clear example on an older vessel. A header tank was positioned high in the machinery-space structure, requiring the duty engineer to climb to inspect it several times each day. Similar arrangements existed across vessels of comparable age and design.
To the engineers, the task was routine. It had been performed for years and formed part of normal watchkeeping. To me, as a former deck officer entering a less familiar working environment, it stood out immediately. Why was someone repeatedly climbing to inspect a tank? If the vessel were designed today, would the same inspection method still be accepted without question?
The initial responses were familiar: changing the arrangement would probably be too expensive, too difficult or technically impractical. Those were assumptions, not the outcome of an engineering assessment. I identified examples of remote-monitoring technology that appeared relevant, although suitability for that vessel would have required competent technical assessment of installation feasibility, class implications, cost, compatibility and unintended consequences.
My recommendation was therefore proportionate: alternatives should be formally considered during planning for the next major dry dock. I do not know whether that recommendation was ultimately assessed, accepted or rejected.
That uncertainty reveals another weakness. A potentially valuable recommendation can enter an organisational process without leaving a visible decision trail for the person who raised it. It may be evaluated properly, postponed, rejected for sound reasons or simply lost. Without traceability and feedback, those outcomes look identical.
The example also demonstrates the value of operational distance. Familiarity helps specialists work efficiently, but it can make inherited conditions appear inevitable. Someone outside the immediate discipline may notice an exposure precisely because it does not look normal to them. That person does not need to design the technical solution. The value lies in asking the question that familiarity has suppressed; competent specialists must then evaluate the answer.
Safety alerts are not evidence of learning
Safety alerts present the same problem in a different form. An incident occurs. An alert is distributed. Operations may stop for a safety stand-down or toolbox discussion. Teams are asked whether the event could happen to them.
Too often, the discussion reaches a reassuring conclusion: this would not happen here; our operation is different; our team already knows this. Attendance is recorded, the alert is acknowledged and the action is closed. The organisation can demonstrate that information was communicated, but not that anything was learned. Communication is not implementation.
The problem becomes worse when alerts arrive too frequently and with insufficient targeting. If every document containing the word safety is sent to every vessel and department, important information becomes routine administrative noise. Operational teams learn that the expected response is acknowledgement rather than analysis.
Alerts should be screened by accountable people with the necessary operational and technical knowledge, then classified by relevance, severity, affected activities and required response. General-information notices must be distinguishable from alerts requiring documented assessment or action.
Where an alert is applicable, the receiving team should examine whether equivalent conditions exist, whether it relies on the same assumptions, whether its controls have been tested realistically, what evidence supports its conclusion and whether local change is required. Vessels should report what they found, what they changed, what worked and what proved unsuitable in their operating context.
Fleet management and technical authorities should compare those responses and decide whether procedures, engineering standards, training or other controls require revision. The organisation should later return to the issue and verify whether the agreed changes were implemented and effective.
The Energy Institute's 2026 guidance on reporting, investigating and learning from incidents calls for learning to be analysed thematically, applied systematically and followed up for effectiveness. It also recommends indicators that track recurrence, causes and implementation of recommendations [3]. That is industry guidance rather than maritime law, but its underlying test is directly relevant: an alert should initiate learning, not represent its completion.
One management system cannot have isolated repeat failures
The contradiction becomes particularly clear when a company operates one safety management system across multiple vessels. A finding is raised on one vessel and corrected locally. A similar finding then appears on a second vessel and later on a third. Each vessel may respond properly to its audit and each action may close on time, while the common weakness remains untreated.
A company cannot credibly claim to operate one fleet safety management system while treating the same finding on every vessel as an unrelated local failure.
Document control provides a straightforward example. An auditor identifies an outdated or incorrectly controlled document. The document is amended, approved and reissued, and the finding is closed. But the defective document may only be the visible symptom.
If another audit identifies a different outdated document and another vessel reveals a similar failure, the organisation should no longer ask only how to correct each document. It should ask why the management system continues to produce documents that are outdated, inconsistent or noncompliant with its own standard.
The underlying causes may include unclear ownership, unmonitored review periods, difficult templates, approval routes that exist on paper but not in practice, insufficient competence or resources, overlapping repositories, poorly controlled local copies, or rules so complicated that personnel cannot apply them consistently.
Correcting the cited document is a correction. Identifying and changing the mechanism that repeatedly produces defective documents is corrective action. If every audit finds a different defective document, the organisation does not have a series of document problems. It has a document-control problem.
My recommendation is that two substantially similar findings should trigger a documented systemic review. That is a proposed governance threshold, not a regulatory rule. Two findings do not prove that the system has failed; apparently similar deficiencies can have different causes. They are, however, sufficient reason to test whether a common weakness exists.
Severity and recurrence answer different questions. Severity asks what consequence this deficiency could produce. Recurrence asks why the management system keeps producing it. An individually minor documentation error may have little immediate safety consequence, yet repeated errors can provide strong evidence that a management-system control is unreliable.
Closure has become the wrong measure of success
Management dashboards commonly show open actions, overdue actions and closure rates. Those measures help control workflow, but they do not demonstrate that risk has reduced. They can also create the wrong incentive.
Open actions appear untidy. Overdue actions attract attention. Rapid closure suggests control and responsiveness. People are therefore encouraged to produce the evidence needed to move an item from open to closed as quickly as possible. The dashboard turns green.
What it may not show is whether the same finding appeared before, whether related findings exist elsewhere, whether the corrective action addressed the cause, whether the change worked in real operations, whether improvement lasted, or whether the original weakness returned under a different reference number.
The organisation makes closure visible while recurrence remains invisible. A finding can return repeatedly while the record continues to show successful performance, provided each occurrence is individually closed. The database then contains repeated evidence of control failure while the dashboard presents repeated administrative success.
The UK Health and Safety Executive's HSG65 guidance places performance measurement, incident investigation, management review and organisational learning within a continuing Plan-Do-Check-Act cycle [1]. It is UK guidance, not a maritime regulation, but the management principle is clear: completing an action does not finish the process; the organisation must check performance and act on what the evidence reveals.
IOGP Report 597 distinguishes a short-term quick fix from longer-term corrective action intended to provide sustained improvement and calls for transparent management follow-up [2]. The cited extract was developed for fabrication-site construction safety, so it should not be presented as a maritime requirement. It is used here because it illustrates a transferable distinction between immediate containment and sustained corrective action.
These principles are incompatible with treating action completion as proof of effectiveness.
Closure should be an evidence-based conclusion
Organisations need a more honest status model. An issue may first be contained, meaning that immediate exposure has been controlled. Containment may be urgent and essential, but it does not establish that the underlying weakness has been removed.
A more honest closure model
- Action assigned: An accountable owner, resources and timescale have been established.
- Implemented: The agreed change has been put in place.
- Operationally tested: The change has been examined under relevant operating conditions.
- Documented: Procedures, training, drawings, risk assessments and associated controls accurately reflect the new arrangement.
- Effectiveness verified: Competent review and operational evidence demonstrate that the intended improvement has occurred.
- Closed: The organisation has sufficient evidence to conclude that the issue has been resolved.
Verification should remain proportionate to risk. A minor administrative correction does not require the same scrutiny as a fleet-wide engineering change or a control affecting emergency response. But an action should not be credited with effectiveness merely because somebody completed a task and uploaded a document.
For significant issues, verification may require evidence from different vessels, teams or operating conditions. Where a control must function during abnormal or emergency circumstances, evidence from ordinary operation may be insufficient. Feedback should be collected, unsuccessful approaches recorded and documentation subjected to competent review before the final change is approved.
This takes longer than closing an action after its first implementation. That is not unnecessary delay. It is the work required to determine whether risk has actually reduced.
The US Chemical Safety Board provides a useful comparative model. Its public recommendations system tracks responses and distinguishes closure outcomes rather than treating every closed recommendation as equivalent [4]. This is not a maritime requirement, but it demonstrates a valuable governance principle: closure should describe what the evidence establishes, not merely whether the workflow has ended.
Small failures reveal the standard being tolerated
It is easy to dismiss recurring documentation defects and other low-consequence findings because no single example appears likely to injure someone or cause a major operational failure. That misses their wider significance.
During my armed-forces service, I was taught a principle that has remained with me: an unbuttoned shirt pocket in ordinary conditions can become an unsecured magazine pocket when conditions matter.
The point was not that every minor uniform defect would cause a battlefield failure. It was that standards practised during routine conditions influence performance when pressure increases and consequences become serious. The same principle applies to management systems.
Repeated small errors reveal what the organisation notices, what it tolerates and whether its controls function without exceptional supervision. A system that cannot reliably maintain ordinary documents should not assume its critical information will automatically be correct, current and available during an abnormal operation.
Small findings do not inevitably predict major accidents and should not be exaggerated. But repeated minor failures can warn that ownership, discipline, competence or assurance is weaker than the dashboard suggests. Ignoring the pattern because each individual error appears harmless is not proportional management; it is a refusal to examine what the pattern says about the system.
The uncomfortable decision
You are the fleet director preparing for a board review and an important client tender.
Two vessels have reported substantially similar document-control findings. Neither deficiency caused an incident, and both can be corrected locally within days. If you close them separately, the actions remain on schedule, the dashboard stays green and the company enters the tender with a clean assurance record.
But the repetition suggests that the fleet's shared management system may be producing the errors.
You can close both findings after the documents are corrected. There is no immediate evidence that anyone will be harmed, and a wider investigation may consume time and resources without discovering anything more serious.
Or you can declare a potential systemic weakness, examine comparable documents across the fleet and keep the issue open until the common cause and effectiveness of any corrective action have been established. That decision may turn the dashboard red, expose further deficiencies and create difficult questions from senior management, clients or auditors.
Do you protect the appearance of control when no serious consequence has yet occurred?
Or do you deliberately expose uncertainty, knowing that the honest decision may make the organisation look less controlled before it becomes more controlled?
The real test of a learning organisation is not how it responds after the third failure causes harm. It is whether it is prepared to act when the first two failures reveal a pattern.
The leadership question
Senior management does not need more green indicators. It needs better evidence.
Leaders should ask how often findings recur, where equivalent weaknesses exist, whether local corrections have been converted into fleet-level improvements and what evidence demonstrates that corrective actions worked. They should be more interested in a difficult issue being investigated properly than in an action being closed quickly.
If the dashboard is green but the same weaknesses continue to appear, management is not looking at evidence of learning. It is looking at evidence that paperwork has moved.
Limitations and application
This article presents a governance and assurance framework, not a legal test or an organisation-specific corrective-action procedure. Requirements will depend on the vessel, flag, activity, management system, contractual arrangements and applicable authority. The proposed two-finding trigger is Phillip Inzaghi's professional recommendation for initiating review; it is not proof of common cause and is not presented as a statutory or industry-mandated threshold. Investigation depth and effectiveness verification should remain proportionate to risk and should involve competent technical or professional advice where required.
Sources
- Health and Safety Executive. Managing for health and safety (HSG65).
- International Association of Oil & Gas Producers. Report 597 extract: Continuous improvement.
- Energy Institute. Reporting, investigating and learning from incidents, accidents and events (2026).
- US Chemical Safety and Hazard Investigation Board. Recommendations system.
About the author
Phillip Inzaghi is a maritime QHSE and operational assurance specialist and the founder of AxiomOrdo Ltd. He has more than ten years of maritime experience, including shipboard operations, marine assurance, vessel and office auditing, management systems, incident investigation and QHSE leadership.
He is a qualified Officer of the Watch Unlimited, holds a Level 6 NEBOSH Diploma and has practical experience conducting and leading audits across international maritime operations.