Date_en
June 2026

Safety as a Defensible Governance Claim within Safety Management


subtitle
A minimal structure for auditable safety arguments
auteur
Author(s):
author

Junjie Wei, Haoyang Ren & Jian Miao

référence
Reference:
référence_en

Wei, J., Ren, H., & Miao, J. (2026). Safety as a defensible governance claim within safety management: a minimal structure for auditable safety arguments. Safety Science, 201.

Our opinion

stars_en
3
opinion

An interesting article written by Chinese colleagues on the polysemy of the concept of industrial safety. The authors invite us to recognize that definitions of safety are often used in ways that are vague, overly simplistic, or even rhetorical and difficult to verify.

They also encourage us to move beyond a “metric-based” view of safety and to consider that, in practice, safety is an argued claim made by governance, which must (better) clarify and substantiate its promises.
Worth reading to form your own opinion about the value of what is being proposed.
 

Our summary

“Safety” is among the terms most frequently invoked in the contemporary governance of high-risk activities, yet its definition remains conceptually ambiguous.

In everyday language, it may mean being protected from danger, the absence of accidents, or the feeling that danger has been eliminated. In research and professional debates, it is variously treated as a technical property, an organizational achievement, a regulatory objective, and a claim to public legitimacy.

This plurality is not merely a matter of semantics. Disagreement over the definition of safety quickly becomes disagreement over what constitutes evidence, what should be optimized, which types of harm matter most, and what obligations fall upon governments, companies, and customers. Organizations do not simply ask whether a system is “safe” in the abstract; they formulate, defend, challenge, and revise specific claims that a system is sufficiently safe to allow its continued operation under specified conditions.

In practice, organizations regularly claim that their systems are safe through management system, audits, barriers, risk analysis or regulation. However, the minimum structure of these assertions often remains insufficiently specified.

This immediately raises a practical and conceptual question: when managers, regulatory bodies, or practitioners claim that a system is safe, what must that claim contain to be intelligible, contestable, verifiable, and revisable – rather than merely rhetorical? The challenge is even greater in complex sociotechnical systems.

In this article, the authors propose a framework that better addresses this requirement for clarification and evidence of safety.

The central thesis developed is not only that safety is context-dependent and dynamic, but that any defensible claim that a system is safe must be able to specify how control is exercised, what feedback mechanisms maintain it, what uncertainties remain, and under what conditions the claim should be reevaluated.

Safety becomes a governance claim – that is, a reasoned judgment that a system is sufficiently under control to continue operating under given conditions. This claim is:

  • contextual (dependent on conditions),
  • dynamic (valid only temporarily),
  • uncertain (based on limited knowledge),
  • and normative (involving a judgment about acceptability).

 

It is clear that the work being proposed is essentially conceptual and theoretical, with the aim of clarifying what a defensible safety claim must contain.

The approach is based on three complementary components:

  1. conceptual clarification: the authors distinguish between the different uses of the term “safety” in everyday language, professional practice, and the academic literature.
  2. theoretical synthesis: they combine contributions from systems thinking in safety, risk and uncertainty analysis, and governance approaches concerned with acceptability and legitimacy. The work cites extensively – and repeatedly – several leading figures in safety science (Rasmussen, Hollnagel, Dekker, Leveson, Aven, and Hansson) as references underpinning this new theoretical approach.
  3. Finally, a normative argument: seeking to identify which elements must be explicitly stated whenever an organization claims that a system is safe.


To further develop the proposed new concept, the authors suggest building on existing practices and the ordinary meanings of safety. Although analytically insufficient, these meanings shape the expectations of stakeholders (operators, regulators, and the public) and influence how safety claims are understood, accepted, or challenged. Ignoring them would lead to safety arrangements that are disconnected from practice and therefore less legitimate. The notion of “ordinary meanings” is used in a selective and analytical way: the aim is not to provide an exhaustive typology, but rather to identify a few recurring and influential meanings (protection, absence of accidents, elimination of danger) that help illuminate the tensions surrounding the concept of safety.

The authors also clarify the limits of the article’s scope. The objective is neither to cover all concepts related to safety (such as risk perception, psychological safety, or resilience), nor to propose a comprehensive management system or a detailed sector-specific model. The ambition is more focused: to define a common minimum structure that makes safety claims explicit and auditable.
 

The ordinary meanings of the term “safety” remain influential in practice, but they are insufficient for complex systems. Three main meanings are identified.

Safety as Protection from Danger

Being safe means being protected from threats that could cause harm. This conception is intuitive and socially fundamental because it relates to moral expectations of responsibility and trust. However, it has a major limitation: the feeling of being protected may not reflect reality (because of latent hazards or degraded defenses). As a result, it is not sufficient as a basis for a robust assessment of safety.

Safety as the Absence of Accidents

A system is considered safe if no undesirable event has occurred. This approach is widespread because it relies on visible and quantifiable indicators. However, it is ambiguous: the absence of accidents may result from chance, underreporting, or temporarily favorable conditions. In complex systems, it does not guarantee that control is genuinely being maintained. It is therefore a useful indicator, but an insufficient basis for justifying a safety judgment.

Safety as the Elimination of Hazard

Something is safe if it cannot cause harm. This idea has strong normative appeal and supports inherently safe design approaches. However, it quickly reaches its limits in complex sociotechnical systems, where the complete elimination of risk is rarely possible. Hazards may evolve, reappear, or emerge from new interactions.

These three meanings coexist in practice and influence stakeholders (operators, managers, and regulators) in different ways. They explain both the stability and the ambiguity of the concept of safety. At the same time, their limitations show that, on their own, they cannot provide a sufficient basis for rigorous judgments in complex environments. Hence the need to move from an intuitive understanding of safety to explicit, structured, and justifiable claims that incorporate control, uncertainty, and conditions of validity.

 

 

The following section of the article is more conceptual. It proposes a major shift in perspective: safety should no longer be understood merely as a property of the system, but as a defensible claim to safety, produced within a framework of management and governance.

In complex sociotechnical systems, safety cannot be reduced to either formal rules (a top-down approach) or the local practices of operators (a bottom-up approach). It results from the interaction between organizational structure and actual activity. Formal mechanisms (procedures, audits, responsibilities) define the constraints, but their validity depends on how they are implemented in practice across a variety of situations. Conversely, local adaptations reveal the limitations or relevance of these mechanisms. Safety is therefore an emergent product of this dynamic interplay.

From this perspective, accidents do not stem solely from isolated failures, but often from dysfunctional interactions (between technical, human, and organizational systems). The key question then becomes: How are these interactions kept under control under real-world conditions, with uncertainties, variations, and delays? Mere formal compliance or the absence of accidents is not a sufficient answer.

The authors then introduce a crucial distinction between three levels that are often conflated:

  • Safety as a system property: the degree of control over the potential for harm (the actual state of control of hazardous interactions.)
  • Safety as a claim: a reasoned judgment asserting that the system is “sufficiently safe” under given conditions. This judgment is epistemic in nature, as it is based on partial knowledge, assumptions, and uncertainties.
  • Safety as a "governance process": the set of mechanisms (management systems, audits, regulation, and operational feedback) that produce, examine, and revise these claims.

This distinction helps avoid major misconceptions, such as equating the existence of procedures with evidence of actual safety or confusing the state of the system with the credibility of the judgment made about it.

The authors illustrate these ideas through the example of a coal mine, where the risk (explosion) depends on a set of interactions involving ventilation, sensors, maintenance, and work organization. In such a setting, safety cannot be reduced either to the compliance of each individual element or to the absence of recent accidents. Rather, it depends on the actual ability to keep these interactions under control and on the validity of the claim that this level of control is sufficient.

In conclusion, this section establishes that safety, in complex systems, must be understood as a reasoned, contextualized, and revisable judgment, rooted in management and governance processes. This sets the stage for the remainder of the article, which goes on to specify the requirements necessary to make such governance claims genuinely defensible.

 

What follows is a description of the epistemic and normative requirements necessary for a safety claim to be truly defensible. It highlights three main ideas: the central role of uncertainty, the limitations of the risk-based approach, and the need to justify acceptability.

A Safety Claim is Fundamentally Epistemic

A safety claim does not directly describe an observable state; rather, it constitutes an inference about the future control of risks. As such, it is based on incomplete knowledge regarding hazards, interactions, operating conditions, and organizational capabilities. Consequently, uncertainty is irreducible and takes multiple forms (uncertainty about the system, the available data, and future developments). To be credible, a safety claim should not conceal these uncertainties but instead make them explicit and manage them appropriately. Transparency regarding the limits of knowledge strengthens the robustness of the judgment by indicating where vigilance and reassessment are required.

Risk Assessment Is Essential but Insufficient

Risk analysis methods provide a useful discipline (identification of scenarios, estimation of consequences, and prioritization of actions), but they are not sufficient to establish that a system is safe. Models remain incomplete, assumptions may be debatable, and certain critical aspects of sociotechnical systems (adaptation, organizational drift, and feedback mechanisms) are difficult to quantify. Consequently, a low-risk estimate alone is not enough to support a credible safety claim; the claim must also make explicit the assumptions, limitations, and conditions of validity underlying the analysis.

The Question of Acceptability Is Central

A safety claim is not limited to characterizing a risk. It must also justify why the residual risk is considered tolerable. This acceptability does not arise from a simple quantitative threshold but from a governance process that integrates technical, organizational, and social dimensions: standards, legal obligations, the feasibility of additional measures, the distribution of risks, and the credibility of institutions. Acceptability is therefore institutional and contestable, and it may evolve as knowledge, values, or trust in stakeholders change.

The notion of legitimacy complements this analysis: a safety claim, even when technically sound, may be weakened if it is not perceived as fair, transparent, and accountable. Safety thus appears as an outcome of governance rather than merely a technical property.
 

 


Commentary from the Foncsi's team

In conclusion, and to summarize the summary of a long, well-written article, that is nevertheless thick, complex, and often highly repetitive, one may take away the following: safety judgments cannot be based solely on the absence of accidents, compliance, or risk metrics. They require an explicit account of control, transparent management of uncertainty, a justification of acceptability, and clearly defined conditions for review. The article’s main contribution is to propose a minimum structure for making safety judgments more explicit, more auditable, more contestable, and more revisable.

 

One might add that the central idea of a “governance claim” regarding industrial safety – one that is partly rhetorical and partly intended to reassure and satisfy public opinion in the broadest sense – is not entirely original. The authors deserve credit for developing it in a more structured manner than is usually the case, although the resulting framework is not yet necessarily highly operational. In this respect, it expands upon a widely shared and longstanding observation.

 

One may also regret that, despite being written by Chinese authors, the article contains no geographical or cultural perspective whatsoever. The reframed vision proposed by the authors is essentially Western in character, judging by the references cited, which include no Chinese or Asian authors. Beyond the use of a field example, there is no discussion of the possible influence of cultural factors on how safety is understood and assessed across different world regions. One might have hoped for more on these issues.

 

Indeed, viewing safety through the lens of governance raises the question of the social systems within which that governance is embedded, as well as the rules and conventions that determine what is considered valid in a specific society. To appreciate this point, one need only recall the governance of safety in the former Soviet Union. From this perspective, constructing a safety claim in China is likely subject to constraints that differ from those prevailing in Europe, for example. This way of understanding safety therefore also carries political implications.