Plan, Do, Check, Act sits underneath most safety management systems, whether or not anyone names it. ISO 45001 is built on the cycle openly and sets out the mapping in its own introduction.
In practice, the first two stages tend to receive most of the attention. Hazards are identified, controls are introduced, actions are raised and closed. The two stages that follow, which ask whether the control worked and what should be done about the answer, are harder to resource and easier to postpone.
That is understandable. Check and Act depend on evidence that is often held in several places at once, and they need an owner after the immediate response is finished and attention has moved on. This article sets out what those stages ask for, and how teams make them workable.
What each stage means in a safety management system
Each stage answers a different question, and each maps to a specific part of the standard.
| Stage | The question it answers | ISO 45001:2018 clauses |
|---|---|---|
| Plan | What can harm people here, and what specifically are we going to change? | 4 Context, 5 Leadership and worker participation, 6 Planning, 7 Support |
| Do | Is the change in operation, as designed? | 8 Operation |
| Check | Did it work, and how do we know? | 9 Performance evaluation (9.1 monitoring and measurement, 9.2 internal audit, 9.3 management review) |
| Act | Do we standardise it, adjust it, or replace it? | 10 Improvement (10.2 incident, nonconformity and corrective action, 10.3 continual improvement) |
Plan: start from a specific failure
Planning is easier to act on when the subject is a failure you can observe rather than a topic.
"Improve forklift safety" is a topic. It has no end point, no measure, and no single control follows from it. "Three near misses in six months, all at the same door, all during the outbound loading window" is a failure. It suggests where to look, who to ask, and what success would look like.
The second thing worth building into Plan is the frontline account of why a control is bypassed. The people best placed to explain it are usually the people working around it, and they tend to have a reason that makes sense from where they stand. Clause 5.4 makes worker consultation a requirement rather than a courtesy, and this is the practical value of it: a plan built without that input can produce controls that fail for reasons the shift could have named in advance.
A workable Plan states four things: the failure in observable terms, a hypothesis about why it happens, the control that follows from the hypothesis, and the measure that will show whether the hypothesis was right. The measure is best chosen before the control goes in, because a measure selected afterwards tends to be the one that fits the result.
Do: implement it, and record what was implemented
Do is the stage most organisations run well. The detail worth watching is the distance between the control as written and the control as installed.
A procedure is revised, but the copy at the workstation is the previous version. Training is delivered to day shift and does not reach nights. A guard is specified and fitted, but fitted in a way that makes a routine task awkward, so it comes off within a fortnight. In each case the action record reads complete and the control is not fully in operation.
So Do produces two outputs rather than one: the change on the ground, and a dated record of what changed and where. The date carries more weight than it appears to, because without it Check has no boundary between before and after.
Check: the stage that needs the most support
Closing a corrective action records that something was done. Whether it worked is a separate question, and it is the one Check exists to answer.
For most controls introduced in the past year, the action record is easy to retrieve. The before and the after take longer. The obstacles behind that are practical rather than cultural, and there are usually three of them.
1. The evidence sits in several places
The corrective action is in one register. The inspection findings that would test it are in another. Near miss reports are in a third, training records in a fourth, and the original risk assessment in a document library. Verifying a single control means pulling several exports and reconciling them by hand.
Work of that kind tends to happen ahead of an audit rather than as a matter of routine, which is a reasonable response to the effort involved. It is also the part of the problem that tooling can genuinely remove: when the action, the risk it came from and the inspections that test it are one linked record, Check becomes a matter of filtering rather than reconstruction. That is the thinking behind how ENSURE keeps an action attached to its source.
2. The measure may be too infrequent to respond
On a site of 120 people, recordable injuries are a low-frequency number. If the injury rate is the only measure of whether a control worked, the signal takes years to appear, and a quiet quarter is not evidence either way.
Check works better with indicators close enough to the control to move with it. Whether the permit is being raised. Whether the guard is in place at an unannounced spot check. Whether the pre-task assessment is completed on the shift where the incident happened, rather than across the site as a whole. These respond within weeks, and they respond to the specific thing that changed.
3. Ownership is unclear
Plan has a risk assessment owner. Do has a line manager. Check often has a line on a management review agenda some months out, by which point the person who raised the action may have changed role.
The fix is unglamorous: when a control is approved, set the verification date and name its owner at the same time, in the same record. A verification that is not scheduled at the point of approval rarely gets scheduled later.
Act: adopt, adapt or replace
Act is the decision about what the system does with what Check found. There are three legitimate outcomes: adopt the control and standardise it across the other lines and sites, adapt it where the evidence shows it partly worked, or replace it with a different control.
It is sometimes read as a further round of implementation. A control underperforms, so more of it is applied: more training, more signage, more reminders, more sign-off. That is a second helping of Do, and it is worth naming, because the alternative conclusion available at that moment is that the control itself was not the right one.
Retiring controls that do not work is one of the more useful moves available, and one of the least used. Every control costs attention, and attention is limited on a working floor. Controls that are visibly ineffective also cost some of the credibility that the effective ones rely on.
Act has one obligation the other stages do not: it has to travel. A control proven at one site and never mentioned at the other four is a local fix rather than improvement. That is the intent behind clause 10.3, and the reason a corrective action worth adopting is better recorded as a change to the standard, the procedure or the training content than as a closed ticket.
The cycle works at two speeds
An annual cycle, arriving as a management review, is a governance exercise. It is required, it satisfies clause 9.3, and it is not usually where day to day improvement comes from.
The cycle that changes outcomes is short. A hazard is raised on Monday, a control is in place by Friday, and four weeks later someone checks whether the behaviour it targeted changed, and decides. The annual review then aggregates loops that have already turned rather than starting them.
Running the short loop asks something specific of the system: a hazard raised from the floor should be able to carry a control, an owner and a date without anyone opening a spreadsheet, and the follow-up should land on someone's list rather than in someone's memory. It is worth checking for when choosing or configuring a system.
A worked example
Pedestrian and forklift interaction in a warehouse. Three near misses in six months.
- Plan. The starting point is not "improve forklift safety". All three near misses were at the same door, during the outbound loading window. Asking the drivers and the pickers, rather than only the supervisor, produces the hypothesis: the marked pedestrian route adds ninety seconds, so people cross the lane instead. The control that follows is a route change rather than a briefing. The measure, chosen in advance, is a spot count of which route pedestrians take, broken down by shift.
- Do. Re-route so the compliant path is genuinely shorter than the shortcut. Brief both groups, since a change only one group understands can create a new hazard. Record the date the new route opened.
- Check. Spot counts across three shifts, including nights, at four weeks and again at twelve. Near misses at that door are tracked too, as the slower confirming measure.
- Act. The counts come back at 90 percent on days and 40 percent on nights. Retraining the night shift is one option. The more useful next step is to ask what is different at night, find that the new route passes an unlit section, and address the lighting. Then decide whether to adopt the change across the other sites.
The useful finding here was "it worked on days and not on nights", and it existed only because the measure was broken down by shift. A single site-level figure would have shown 65 percent, which invites a general reminder to everybody and changes little.
Five things that make the cycle stall
- The plan starts from a topicLittle that is measurable follows from "improve manual handling". A specific, observable failure gives the cycle something to close on.
- Completion is treated as installationAn action marked complete and a control in operation are two different claims. The second one is worth confirming.
- The measure is too infrequent to respondInjury rates on a single site move slowly. An indicator close to the control, chosen before it goes in, gives an answer within weeks.
- Act repeats DoMore of a control that is not working is implementation rather than a decision. Adopt, adapt or replace.
- Only the annual loop runsIf the shortest cycle available is twelve months, the system supports compliance more than improvement.
A practical starting point
Take one control introduced in the last year. Write down what it was meant to change, gather whatever evidence exists on either side of the date it went in, and decide whether to keep it, adjust it or replace it.
That is one full turn of the cycle. It is usually modest work, and it tends to show clearly which of the three obstacles above is the one worth fixing before the next turn.
Closing the loop
ENSURE keeps risks, actions, inspections and audit findings as one linked record, so checking whether a control worked is a matter of filtering rather than reconciling exports. If it would help to see that against your own process, we are happy to arrange a short session.