With OSHA Barely Watching, Who's Auditing Your Safety?
With federal OSHA down to roughly 1,700 inspectors for 12 million workplaces — meaning a facility might see a full inspection once every 191 years — self-regulation has effectively become the entire safety system. In this episode, Trish Kerin explains why internal teams stop noticing their own drift from procedure (normalization of deviance) and why "no incidents" doesn't mean a program is working — only that controls haven't been tested yet. She outlines practical fixes: cold-eyes audits between facilities, the three lines of defense model, and the crucial difference between assurance and reassurance. Her bottom line: good process safety isn't just compliance — it drives reliability, productivity and profit.
Transcript (edited for clarity)
Welcome to Process Safety with Trish and Traci, the podcast that shares insights from past incidents to help avoid future ones. Please subscribe to this free, award-winning podcast on your favorite platform to keep learning with Trish and me. I'm Traci Purdum, editor-in-chief of Chemical Processing. And as always, with me is the one and only Trish Kerin, director of Lead Like Kerin. Hey, Trish, what have you been up to lately?
Trish: Hey, Traci. I've been having fun storytelling with people lately, which has been fantastic. I just finished a three-day, three-night storytelling immersion — great fun. We laughed a lot, learned a lot, and it left everyone exhausted. Good exhaustion, though.
Traci: I can imagine. I was following your travels on LinkedIn and saw the peacocks and everything else you got up to, on top of all that safety learning. Very cool.
Trish: Yeah, the venue was amazing, with all kinds of animals around — camels, donkeys, Highland cows, emus, llamas and, of course, the peacocks that kept tapping on our windows and staring in, judging us as we worked. Spectacular-looking animals, and full of personality. It was fun to see.
Traci: That's awesome. I bet they were miffed the platypus was the star of the show — maybe they wanted top billing, too.
Trish: Absolutely.
Traci: Today's topic grew out of a news item I saw about the OSHA enforcement gap here in the U.S. Federal OSHA is down to roughly 1,700 inspectors covering 12 million workplaces — at that rate, a facility might see a full inspection once every 191 years.
That means self-regulation isn't a fallback anymore; it's basically the whole system. So I want to explore this: If the external check barely exists, is your process safety management program being tested by anyone but you? Even if you don't fall under OSHA rules, you can still apply the same best practices.
Trish, I'll start with this: If inspections are down to a once-in-a-generation event, and most PSM programs are reviewed only by the people who built them, what are the blind spots an outside auditor catches right away that an internal team walks past every day?
Where Are Your Blind Spots?
Trish: As we build systems, processes and documentation over time, we stop noticing when drift happens. It's what's called normalization of deviance: We design a great system, then slowly start doing something a little different. Nothing goes wrong, so we keep doing it — and over time we drift further from the original standard.
Because we're so used to seeing the same thing every day, we stop noticing that it no longer matches what the system says. Bring in an external auditor, though, and it becomes obvious right away that we're not following our own procedure. We're so used to our routine that we mentally treat it as the system, so we stop checking it against what's actually written down. Maybe we're not doing something at the right frequency, or not inspecting it the right way, or testing equipment differently than the manufacturer specifies. Normalization of deviance has quietly crept into our daily activities, and as long as nothing goes wrong, we don't notice we've drifted.
Think about learning to drive. You're taught to hold the wheel with both hands in a certain position. Over time, as you get more experienced, you relax into driving with one hand — and you don't even notice you've stopped following the rule. A driving assessor sitting beside you would catch it immediately, because they're checking against strict guidelines. But we stop noticing our own deviations. We assume we're a good driver, even getting better, when we might actually be getting worse. Nothing has gone wrong yet, so we don't see it as a problem.
Will Internal Audits Help?
Traci: So if we haven't had an incident yet, does that mean the program is working? Why is that a dangerous way to grade yourself, and what should replace it? Are there rigorous internal audits that can help?
Trish: Dr. Todd Conklin often says safety isn't the absence of incidents — it's the presence of controls. That sums it up well. An incident not happening doesn't mean you're safe; it likely means you got lucky, because the exact scenario just didn't play out this time.
Logically, the absence of one thing doesn't prove the presence of another. But that's exactly what we do when we look at our safety stats and say, "We haven't had an incident, so everything must be great." Maybe we're just not reporting them, or not noticing them, or maybe we've been lucky and the sequence hasn't played out yet. It will, eventually, if we don't actively manage it.
So what do we need to do? We need to understand our controls, barriers and safeguards — whatever term you use for the things that actively manage safety. We need to know what they are, be able to describe how they're meant to work, and verify they're actually doing what we think they're doing. Controls are the only thing that interrupts an incident scenario. They're the only thing that stops it, because hazards exist in our workplaces by the nature of the work we do. We can eliminate some hazards, but not all of them. In the oil industry, for example, we can't eliminate oil, and the hazard in oil is flammability. So we manage that flammability through controls: containment, so we don't release oil; and if it does release, mitigation controls such as evacuation procedures and ignition-source management, so the release doesn't find an ignition source and become a fire, explosion or fatality.
The key is making sure our controls are in place, we understand what they need to do, and they're working effectively. That means we can't keep blindly focusing on incident reports. We need structured processes to inspect and monitor how well our controls are implemented — checks we can do internally, without a regulator knocking on our door. That includes scheduled maintenance: making sure we perform it on the right schedule and confirm our controls are hitting the right performance parameters. When performance isn't right — when we test equipment and it fails — we need to understand why, and we may need to inspect that device more often if it has failed the last three times we checked it. Because if you inspect a piece of safety-critical equipment and find it wasn't working, you don't know how long it was out of service, which means you don't know how long you were exposed to that risk. That's why we need to focus on understanding our controls, making sure they're in place, and verifying we're meeting their performance standards.
Shake Up The Audits
Traci: You've made a good point — you don't need a regulator to walk in to do this. But do we need different people running these audits? Should we bring in third parties, or change how findings get escalated?
Trish: Having what we call a cold-eyes review is really valuable. If you have more than one facility, send people from Facility A to audit Facility B, and vice versa — because if I'm only looking at my own site, that's grading your own homework. It's better to swap your sheet with the person next to you and grade each other's homework. So swap people between facilities, and make sure whoever is doing your internal audits actually knows how to audit, and understands that an audit is about the process, not the person. We're not there to trip people up, and it's not a policing activity or about finding someone to blame — it's about asking whether the process is working. If it is, great; what's working well? If it isn't, how do we fix it and keep it working?
If you have the resources to send people to different plants, do that. If you don't, bring in someone external — and pick your consultant carefully, so you get someone who understands what they're looking at. There's no point bringing in an occupational safety professional with an ergonomics background to audit your pressure safety valve system. You need subject matter experts: an ergonomist to audit human factors and ergonomics, not a mechanical engineer, and vice versa for pressure relief valves. Match the right consultant to the right task. Even after a fatality, it can be valuable to bring in an external view. Time it right.
The reason we do all this is a widely used assurance methodology called the three lines of defense model, which describes the different lines of assurance in a workplace. Line one is the work site itself — the safety people embedded in your facility, working alongside operations. Remember, operations is responsible for safety; safety's role is to help and advise. Your on-site safety people are your first line of defense: They see what's happening, advise you and do reviews on the ground.
Line two is your corporate system — the people who set safety standards across the organization, monitor what's happening and advise the safety advisors on the ground.
Line three is your external audit process, usually at the corporate level, where you bring in outside auditors.
All three lines need to be functioning well to get the right outcome. If line one isn't functioning on-site, line two — who isn't on-site — can't help much, and external audit won't fix it either. I've also seen cases where line two was ineffective, leaving line one unsupported, and again, external audit couldn't do much in that situation. You need the whole structure working together, so make sure it's in place — and if you're a small organization without that capability internally, you can bring in subject matter experts to fill line two.
Are You Testing or Just Reassuring?
Traci: How can you tell whether you're actually testing yourself, or just reassuring yourself?
Trish: Great question, and it comes down to how you seek out evidence. I often talk about the difference between assurance and reassurance. Assurance means I trust you, but I'm going to verify — show me the evidence that proves what you're telling me. If you say you're maintaining a piece of equipment, I want to see the maintenance records and go through them, looking for a loose thread I can pull until things unravel. That's why audits and inspections should be narrow but deep: A shallow, broad audit makes it easy to hide problems, because you never get the chance to seek real evidence.
Reassurance sounds like, "Everything's okay, right? I just want to check we're all good." Questions like that telegraph the answer you want, and people will give it to you. It comes down to how you frame the question: "Here's what you're telling me — thank you, now show me the evidence," rather than, "Just tell me it's all okay." It's not that I don't trust you; I need to verify it. That's the key difference. If every audit you run comes back saying everything's fine, you're reassuring yourself, not assuring yourself — and you're being misled, because there is always something that isn't working. An audit report with no findings at all isn't a clean bill of health. It's useless and fake.
What Happens When Nobody's Watching?
Traci: Without the accountability of fines and formal findings, the loss of life should obviously be reason enough for facilities to audit themselves and keep their three lines of defense — trust but verify — in place. But it's a slippery slope. How do we make sure companies follow through without a regulator who could show up at a moment's notice?
Trish: There's an important point we often forget. We rightly talk about safety as keeping people safe — that's why we do this work. But not everyone thinks that way. Safety professionals do safety because it's the right thing to do, but not everybody is motivated the same way, and we need to accept that. Some people are driven economically — often the people in finance, legal and corporate leadership running the business.
As safety professionals, we need to speak their language and translate what good safety delivers in business terms. It's not enough to argue that an incident would be expensive, because the incident might not happen — and someone weighing the cost of controls against the cost of an incident that may never occur might just take the risk. That's not a winning argument.
Think about it differently. When an organization has effective maintenance and reliability strategies — equipment run properly, inspected and maintained preventively before it breaks down — the facility runs reliably. A reliable facility has a chance to make money, because the plant is running well. A plant that keeps breaking down isn't making money; it's costing money.
So the upside of good process safety management is a reliable plant — which means reliability, productivity and profitability. That's exactly what financially incentivized people want to hear: Good process safety generates profit. As safety professionals, we need to be willing to make that case if it's what gets us the outcome we're after.
Traci: Trish, is there anything you want to add?
Trish: Don't be tempted to think that because you won't see an OSHA inspection for 191 years on average, you can do whatever you want. Good process safety means a reliable, productive and profitable facility. It's tempting to back off and take the gamble once compliance pressure eases, but let's get serious about making money instead. Many studies over the years have found that safe businesses are often very profitable ones. So let's focus on that: Safety is profit. Do safety for that reason if that's what it takes — and the bonus is safer workplaces, where our employees, our community and our equipment stay safe, which also protects our environment, since we all live in it. We need to do this work to keep everyone safe. We need to know our controls are in place, know what they're supposed to do, and know they're functioning as expected.
Traci: Trish, thank you for always championing safety. You're basically the fourth line of defense for our listeners.
Trish: Stay safe!
About the Author
Traci PurdumTraci Purdum
Editor-in-Chief
Traci Purdum, an award-winning business journalist with extensive experience covering manufacturing and management issues, is a graduate of the Kent State University School of Journalism and Mass Communication, Kent, Ohio, and an alumnus of the Wharton Seminar for Business Journalists, Wharton School of Business, University of Pennsylvania, Philadelphia.
Recent Awards:
2025 Eddie Award for her column "Lax Regulations Burn Rivers"
2024 Jesse H. Neal Award for best podcast Process Safety with Trish & Traci


