Injury rates fall. Fatal risk doesn’t.

    Riskolabs shows boards and HSE leaders whether the controls against fatal energy are in place and working, before anyone is exposed.

    Methodology proposal v2.0 by RISKOPILOT · validation protocol published

    Mining, 2012 to 2025ICMM member companies: the recordable injury rate fell from 3.94 to 2.21 per million hours between 2017 and 2025, while fatalities stayed between 33 and 50 a year.025507510002462012: 902013: 912014: 562015: 602016: 632017: 502018: 502019: 372020: 442021: 452022: 332023: 352024: 432025: 392012: 5.072013: 4.522014: 4.502015: 4.702016: 4.262017: 3.942018: 3.412019: 3.202020: 2.942021: 2.902022: 2.662023: 2.592024: 2.292025: 2.211213141516171819*202122232425Injury rate: −44% since 2017Fatalities: no steady decline
    Mining, 2012 to 2025. Source: ICMM (2026). 2019 excludes Brumadinho.
    Chart data
    YearFatalitiesRecordable injuries per million hours
    2012905.07
    2013914.52
    2014564.50
    2015604.70
    2016634.26
    2017503.94
    2018503.41
    2019*373.20
    2020442.94
    2021452.90
    2022332.66
    2023352.59
    2024432.29
    2025392.21

    Why don’t injury rates predict fatalities?

    Injury rates count frequent, low-energy harm. Fatalities come from a barrier against high energy that is missing or fails on the day. One number cannot see the other.

    3.2 trillionworker-hours in the largest statistical test of the recordable injury rate
    96 to 98%of the variation in that rate is random
    No linkdiscernible between the recordable injury rate and fatalities

    Sources: Construction Safety Research Alliance (Hallowell et al., 2021); ICMM (2026).

    ICMM itself warns that injury performance is not a proxy for fatality risk.

    How does critical control health work?

    Critical controls and the direct-control test

    A critical control is crucial to preventing a fatal-energy event or limiting its consequences; its failure would significantly raise the risk despite the other controls. To count, it must pass three tests.

    Targeted
    it acts directly on the fatal energy or on the pathway to a person
    Effective
    it works as designed when the demand comes
    Tolerant of honest error
    a single slip by a competent person does not defeat it

    Training, procedures, permits and signage keep controls healthy. They are degradation controls, not barriers, and score no protection.

    The gate

    Before a high-energy task starts, every critical control is verified in the field. Each is either verified (1) or not (0), and the gate is their product. Evidence that is only a document scores 0.

    Try it: select a control to mark it as failed.

    G = v₁ × v₂ × … × vₙ = 1 × 1 × 1 × 1 = 1All four verified. Work may start.

    Protection points follow the hierarchy of controls

    Each barrier earns points according to how much it relies on people. One point is roughly a tenfold reduction in risk.

    Protection points follow the hierarchy of controls
    Passive engineeringguardrail, fixed guard, separation2.0
    Automated engineeringinterlock, trip, proximity slowdown1.0
    Human-activated engineeringlockout with test, alarm with response0.5
    Active human barrierspotter with stop authority0.3
    Personal protective systemanchored fall arrest0.2
    Fails the direct-control testtraining, procedure, signage0.0
    • Independent barriers add up; controls that share a cause, such as the same crew, count once at the lower value.
    • Each pathway is capped at 3.0 points; a task is only as protected as its weakest pathway.
    • Points are planning conventions, not measured failure probabilities.

    Four decisions

    G = 0
    Stop. Restore the failed control.
    2.0 points or more
    Robust: work may start.
    1.0 to 1.9
    Tolerable: start, and log the weakest pathway for upgrade.
    Below 1.0
    Fragile: start only with authorisation, and escalate.

    Will the controls still hold next month?

    The Organisational Resilience Factor (ORF) is the lowest of three indicators, never their average.

    O1Control upgrade rate
    fragile pathways moved up the hierarchy or eliminated
    O2Critical equipment health
    overdue safety-critical maintenance, failures on test, expired bypasses
    O3Verification integrity
    false passes found by independent re-checks, with Cohen’s kappa

    What the board sees

    Five indicators, worst first. E1 (gate failures) is always read with O3: few gate failures with many false passes means checks are completed on paper. E2 measures the share of fatal-energy exposure protected by less than one point.

    1. Reactiveat least one indicator is red
    2. Developingno red, at least one amber
    3. Verifiedall five indicators are green
    4. Resilientall green for six months, fragile exposure at most 5% and most fragile pathways upgraded

    An averaged score is never used: it can hide the one crew exposed today.

    L.O.C.K.: one loop, two speeds

    Crews run the inner loop at every task; the enterprise runs the outer loop every month. Each knock-out redraws the pathway map, so improvement is built in, in line with ISO 45001 and double-loop learning.

    The L.O.C.K. double loop: the crew loop at every task and the enterprise loop every month.
    1. Locatethe fatal energies and pathways of the task
    2. Observeeach critical control: present, functional, in use
    3. Confirmthe gate: all verified, or stop
    4. Knock outfragile pathways, by moving them up the hierarchy

    Actions follow the hierarchy of controls

    Every recommendation starts with eliminating the energy or reducing it below the fatal threshold, then engineering (passive before automated), then keeping engineered barriers working. Verification and culture keep barriers honest but add no protection; administrative measures and personal protection are interim only.

    Status, limits and validation

    Version 2.0 is a proposal. It may be called piloted after phases A to C, and validated only after phase D.

    1. A
      Content validitytwo-round expert panel on the typology, points and thresholds
    2. B
      Reliabilitypaired verifications; Cohen’s kappa of at least 0.61
    3. C
      Field pilottwo to three sites for at least 12 weeks, with point values varied
    4. D
      Criterion validity12 to 24 months comparing E1, E2 and O3 with high-energy near misses and precursors

    Limits: answers and checks are self-reported, points are conventions, and the association between CCHI and fatal outcomes has not yet been demonstrated on field data.

    Riskolabs The CCHI lab, the first Riskolabs tool

    An interactive demonstration that runs in the browser. A fictional company, Veyra Minerals, shows the method end to end; the assessment applies it to your own organisation.

    Simulation parameters are illustrative and pending expert review. Your assessment answers stay in your browser.

    A 2-minute tour

    Six screens from the live lab. Use the buttons or the arrow keys.

    Story mode: the illusion over 24 months
    Screen 1 of 6

    The illusion, in 90 seconds

    Watch the injury rate fall while high-energy events rise, open a gate, and move a pathway up the hierarchy.

    The CCHI lab opens to early-access members first, while its simulation parameters complete expert review.

    Request early access

    What does the evidence show?

    The CCHI lab replays three major accidents from their official investigation reports. In each, the organisation believed protection was in place: 1.5 points at Buncefield and Piper Alpha, 0.5 at Texas City. The true protection when the demand came was 0.

    Does CCHI warn before harm?

    On 300 simulated companies, when serious events are rare, as in most real operations:

    SignalRanking power, from the next quarter to 9 months ahead
    CCHI score0.62 to 0.72
    Counting past events0.51 to 0.59
    LTIFR0.46 to 0.64

    Ranking power (AUC): 0.5 is a coin toss. This is in-model evidence: the simulation assumes that failing controls drive high-energy events. Field validation (phase D) is the real test, and the lab states what would disprove the claim.

    Early access and documents

    The CCHI lab opens in stages, and the methodology documents are sent by email. Tell us about your operations; we confirm your email, then send what you asked for.

    What happens next

    1. Confirm your emailwithin a minute; the link is valid for 24 hours
    2. Receive your documentsstraight after confirmation, if you asked for them
    3. Get your lab accessafter review, within 2 business days; personal link valid for 30 days
    4. Go further, if usefulfor a guided demo or a pilot, we reply by email with proposed times
    What would you like?

    We keep your details only to handle this request, never sell them, and delete unconfirmed requests after 7 days. How we handle your data

    Resources

    In-depth articles, the full methodology, and the official sources behind this page.

    Articles

    RISKOPILOT Editorial Team, 4 min read

    Why injury rates do not predict fatalities

    TRIR and LTIFR measure how often people get hurt. Fatal risk follows a different mechanism, and boards need a different instrument.

    Methodology documents

    Sent by email after a quick confirmation.

    • Methodology, EnglishPDF, 24 pages
    • Méthodologie, françaisPDF, 26 pages
    • Executive presentation, EnglishPDF, 22 slides
    • Présentation exécutive, françaisPDF, 22 slides

    Get the documents by email

    Rollout playbook

    Free to download, in four languages.

    About the author

    Bruno Hounkpati has spent more than twenty years preventing fatal risk in high-hazard industry, at the three levels this method measures: at the task, in petroleum terminals and contractor fleets; across the organisation, as a group vice-president for safety; and in the chair, as a country chief executive. An accredited Tripod Beta practitioner, he founded RISKOPILOT.

    A low injury rate is not proof of safety. It is often proof of silence.

    Bruno Hounkpati

    Frequently asked questions

    Q.01What is Riskolabs?

    Riskolabs is RISKOPILOT’s home for interactive risk tools. Its first tool, the CCHI lab, lets boards and HSE leaders explore critical control health on a simulated company and assess their own organisation.

    Q.02What is critical control health (CCHI)?

    Critical control health is a method to verify, before exposure, that critical controls against fatal energy are present and working, and to rate each fatal-energy pathway along the hierarchy of controls. It gives boards five indicators and a readiness stage set by the weakest.

    Q.03Why don’t TRIR and LTIFR predict fatalities?

    Injury rates mostly count low-energy events, while fatalities come from high energy reaching a person through a missing or failed barrier. The largest statistical study of the recordable injury rate, on 3.2 trillion worker-hours, found no discernible association with fatalities.

    Q.04Is the method validated?

    Not yet. Version 2.0 is a proposal with a published four-phase validation protocol. It may be called piloted after phases A to C and validated only after phase D.

    Q.05How do I get access to the CCHI lab?

    Request early access on this page. You confirm your email, we review the request within 2 business days, and you receive a personal link valid for 30 days. The 2-minute tour is open to everyone.

    Q.06Can I see a demo?

    Yes. Take the 2-minute tour on this page, or choose “A 30-minute guided demo” in the form; we reply by email with proposed times.

    Q.07How do I get the methodology documents?

    Ask for them in the same form. They arrive by email as soon as you confirm your address; no review is needed.

    Q.08Does the CCHI lab send my assessment data anywhere?

    No. The assessment runs in your browser and your answers are stored only on your device. You can clear them at any time or save them as a file.

    Q.09Can CCHI predict fatal accidents?

    No indicator can predict a specific accident. In simulation, when serious events are rare, CCHI ranks the risk of the coming months better than counting past events, and more consistently than the injury rate. Validation phase D will test whether this holds on field data.

    Q.10Does it replace Tripod Beta investigations?

    No. Tripod Beta explains why barriers failed after an event; CCHI verifies barriers before exposure. Red CCHI indicators point to the basic risk factors an investigation would examine.

    Q.11How can we pilot it?

    A pilot covers two to three sites for at least twelve weeks, with the gate, the pathway register and independent re-checks. Choose “A pilot discussion” in the form.

    Q.12How do we roll out critical control health?

    Start with the free CCHI Rollout Playbook in the method section: ten conditions before day 1, a first site in 100 days, then extension site by site, each stage ending at a gate. It is available in English, French, Spanish and Portuguese, with no email needed.

    Pilot CCHI on your own sites

    Start with early access to the CCHI lab and its assessment, then test the gate and the pathway register on two or three sites.