Most safety inductions draw the same inverted triangle: elimination at the wide top, personal protective equipment at the narrow bottom, three levels in between. It is drawn so often that most people stop asking what the ranking means or where it comes from. The ordering is not a matter of taste and it is not a cost ladder. It ranks control measures by how reliably they keep working when nobody is watching. Once you see it that way, the way most organisations apply the hierarchy starts to look very different.
The message up front: the hierarchy of controls is a principle, not a standard. Nobody publishes "the hierarchy of controls" as a standalone document. It is required by ISO 45001:2018 at clause 8.1.2 and by ANSI/ASSP Z10.0-2019 at section 8.4, and it is described by NIOSH on a free public page, which is where the familiar triangle diagram comes from. US OSHA does not define it in any regulation. Getting that attribution right is the difference between sounding informed and repeating a misquote.
1. What the hierarchy of controls actually is
The hierarchy of controls is a ranked list of ways to deal with a hazard, ordered from most reliable to least reliable. The five levels, in the order everyone recognises, are elimination, substitution, engineering controls, administrative controls, and personal protective equipment.
The ranking is a decision rule. Having identified a hazard, you work from the top of the list down and move to a lower level only when the higher levels have been genuinely considered and found impracticable. You are not supposed to pick the level that suits your budget or your timeline.
That depends on a distinction which trips up a lot of otherwise competent risk assessments. Elimination and substitution act on the hazard: afterwards the source of harm is gone or has been swapped for something less harmful. Engineering, administrative and PPE controls act on the risk: the hazard is still present and the control stands between it and the person. The top two levels and the bottom three are doing fundamentally different work, so if the hazard versus risk distinction is fuzzy, the hierarchy will not make sense. It is essentially an instruction to eliminate hazards first and reduce risk only where you cannot.
The hierarchy also sits at the end of a process, not the start. It answers "what do we do about this?" and presumes something has answered "what can hurt someone here?" That earlier work belongs to hazard identification and then risk assessment. A hierarchy applied to a hazard list that missed half the hazards is a tidy answer to the wrong question. For how these pieces fit together, see the HSE overview pillar.
2. Where it comes from: the attribution most articles get wrong
There is no hierarchy of controls standard. No standards body issues it as a standalone numbered document, so if you see the phrase "the hierarchy of controls standard", the writer has invented a document that does not exist. What exists is a principle that several real documents require or describe.
- ISO 45001:2018, "Occupational health and safety management systems", requires it at clause 8.1.2, on eliminating hazards and reducing occupational health and safety risks. ISO's own formulation has five levels: eliminate the hazard; substitute with less hazardous processes, operations, materials or equipment; use engineering controls and reorganization of work; use administrative controls including training; and use adequate personal protective equipment. ISO 45001 is certifiable, so if you hold the certificate an auditor can ask how your control selection reflects that clause. Cite it as amended: ISO 45001:2018/Amd 1:2024, which added climate action considerations.
- ANSI/ASSP Z10.0-2019, "Occupational Health and Safety Management Systems", requires it at section 8.4. This is the United States national consensus standard for safety management systems, and it is voluntary, not law.
- NIOSH describes it on a free public page. NIOSH, the United States National Institute for Occupational Safety and Health, is a research agency rather than a regulator, and presents the hierarchy as a framework with no standard number and no normative status. The inverted triangle everybody draws traces back to that presentation, which is also the right free primary source to cite for the description.
- US OSHA does not define it in any regulation. This is the part most often misstated. 29 CFR 1910.1000 (air contaminants) and 29 CFR 1910.132 (personal protective equipment, general requirements) both impose duties around controlling exposure and both express a clear preference for engineering and administrative controls over reliance on PPE. Neither codifies "hierarchy of controls" as a defined, enumerated term. It appears in OSHA guidance and interpretation letters, not as a regulatory definition. So "as defined by OSHA" is wrong, and wrong in a way that matters if a regulator will read your procedure.
The precise phrasing to use
Write "as required by ISO 45001:2018 clause 8.1.2 and described by NIOSH". Never write "the hierarchy of controls standard" and never write "as defined by OSHA". If you need a US consensus reference, ANSI/ASSP Z10.0-2019 section 8.4 is the one.
One further nuance surfaces the moment you map an internal procedure onto both sources at once. ISO's list is not identical to NIOSH's. ISO 45001 puts "reorganization of work" inside the engineering controls tier, bundling a work organisation measure into the level most people think of as purely physical. NIOSH keeps engineering and administrative measures apart, so work reorganisation reads as administrative in that frame. The five headline levels match; the contents of level three do not. If your procedure cites ISO 45001 and also reproduces the NIOSH triangle, decide deliberately which formulation you follow rather than discovering the mismatch in an audit.
Two adjacent references are worth knowing. For machinery, ISO 12100:2010, "Safety of machinery: General principles for design, risk assessment and risk reduction", carries a closely related and more prescriptive sequence putting inherently safe design ahead of safeguarding; it consolidated and replaced ISO 12100-1:2003, ISO 12100-2:2003 and ISO 14121-1:2007, and is currently under revision. On the risk management side, ISO 31000:2018 is guidance only and not certifiable, and IEC 31010:2019 (the IEC prefix, not ISO) catalogues risk assessment techniques.
One jurisdiction note, and then I will stop qualifying. ISO and ANSI documents are voluntary and law nowhere by themselves; they bind you through certification commitments and contracts. Statutory duties are national: in Great Britain the general duty sits in the Health and Safety at Work etc. Act 1974 and the duty to assess risk at Regulation 3 of the Management of Health and Safety at Work Regulations 1999 (SI 1999/3242), Great Britain only. If you are implementing controls in a regulated environment, confirm what your own jurisdiction requires and involve someone competent in it. The rest of this guide is about how the principle works, not what any law obliges you to do.
3. Level 1: elimination
Elimination means removing the hazard entirely, so there is nothing left to control. Not guarding it, not restricting access to it, not warning people about it. Removing it. In maintenance and facilities work that usually looks like a design or process decision rather than a safety intervention:
- Designing out the need to work at height. Relocating a filter bank, gauge, grease point or isolation valve so it is reachable from ground level eliminates a fall hazard permanently, and every subsequent maintenance visit for the life of the asset inherits the benefit.
- Removing a chemical from the process. If a cleaning agent, solvent or water treatment chemical is no longer needed, the exposure, storage, spill and disposal hazards all disappear together. One decision retires four risk lines.
- Deleting the task. The most underused form of elimination in maintenance. A preventive task that exists out of habit rather than any credible failure mode is pure exposure with no reliability return, and every hour a technician spends in a switchroom or on a roof carries risk.
Elimination is the most effective control by a wide margin, because a hazard that is not there cannot fail to be controlled. It does not degrade, does not depend on behaviour, does not need inspecting, and does not need funding again next year.
It is also the level most often dismissed as impossible before anyone has tested whether it is. The pattern I see repeatedly in risk assessment workshops is that elimination gets one sentence, usually "not reasonably practicable", written within about fifteen seconds of the hazard being named, and the group moves straight to what guard or what permit. Sometimes that is right. Often it is the fastest way past the hardest question. The discipline worth building is to make the group state why elimination is unavailable, in terms of what would have to change and what it would cost. Half the time the answer is "it would need a capital project", which is a legitimate constraint but a very different finding from "impossible", and it belongs on a capital plan rather than in a closed risk assessment.
The honest cost: elimination is typically the most expensive control to retrofit and the cheapest to design in. That asymmetry is the most important economic fact about the hierarchy.
4. Level 2: substitution
Substitution replaces the hazard with something less hazardous. The task still happens and the function is still delivered, but the source of harm is smaller: a water-based cleaner instead of a solvent-based one, a lower pressure mechanical method instead of high pressure jetting, a lower voltage tool for damp conditions, a lighter component that can be handled without lifting equipment, or a cold method such as a bolted connection instead of welding or grinding. That last one deserves attention, because every hot work permit you avoid issuing is a fire risk you substituted away rather than administered.
Substitution ranks second because it acts on the hazard itself, like elimination, but leaves a residual hazard behind. It is also usually cheaper and faster than elimination, which often makes it the highest tier realistically available on an existing installation.
The substitution trap
Substitution is the one level of the hierarchy that can make things worse. Swapping a flammable solvent for a less flammable one that happens to be more toxic, or a chemical process for a mechanical one that introduces noise, vibration and a rotating machinery hazard, is a lateral move dressed as an improvement. Any substitution needs the replacement assessed in its own right, across all hazard types, not just against the one property you were trying to reduce. It is common for a substitution to be signed off on a safety data sheet comparison of flash points alone, with no one reading the health sections.
5. Level 3: engineering controls
Engineering controls are physical measures that separate people from the hazard, or contain it, without requiring anyone to do anything. The hazard remains, but a barrier or system stands between it and the person. This is the richest tier in practice:
- Fixed guarding on couplings, drive belts, fan inlets and rotating shafts, and interlocks that remove power when an access panel opens so the machine cannot run in an unsafe state.
- Local exhaust ventilation capturing fume, dust or vapour at source in workshops, battery rooms and chemical stores.
- Fixed access platforms, permanent ladders, guardrails and roof edge protection, which convert a work at height task into ordinary work on a protected surface.
- Isolation design: lockable isolators at the point of use, single point isolation for a whole skid, double block and bleed arrangements, drain and vent points designed in. Good isolation design is what makes a lockout tagout procedure practical rather than aspirational; see the lockout tagout guide for how the physical and procedural halves work together.
- Residual current devices, earthing and bonding, arc resistant switchgear, noise enclosures, vibration isolation and layout changes that increase separation distance.
Engineering controls are effective for one specific reason: they do not depend on behaviour. A fixed guard protects the distracted technician on a night shift under time pressure exactly as well as the attentive one on a quiet Tuesday morning. An interlock does not get tired, misread a procedure, or decide the job is quick enough to skip a step. That behavioural independence is why level three is the boundary in the hierarchy. Everything above it removes or reduces the hazard; level three controls the hazard without human reliability in the loop; everything below it depends on people.
The cost profile is moderate: real capital spend, usually a project rather than a purchase order, plus an ongoing inspection obligation. That last part is what organisations forget. An engineering control is an asset and it degrades. Guards get removed during a repair and not refitted. Interlocks get bypassed with a cable tie during commissioning and never restored. Ventilation performance drifts as ductwork fouls. If your engineering controls are not on the maintenance register with their own inspection tasks, they are slowly becoming decoration; treating safety critical guards, interlocks, detection and ventilation as assets with their own preventive tasks is an unglamorous but high value use of a maintenance management system, and the general discipline is in the facilities maintenance management guide.
Note also that ISO 45001's version of this tier explicitly includes reorganization of work, so under an ISO 45001 frame redesigning a task sequence so the hazardous step happens with the plant shut down counts here rather than as an administrative control. Under the NIOSH frame it reads as administrative. Neither is wrong; consistency within your own documents matters more than which you pick.
6. Level 4: administrative controls
Administrative controls change how, when and by whom the work is done: written procedures and method statements, permit to work systems, competence requirements and training, job rotation to limit exposure duration, scheduling at times of low occupancy, restricted access zones, signage that informs rather than physically prevents, supervision, and health surveillance that catches harm early.
These are genuinely valuable and no operation runs without them. A permit to work system is among the most powerful administrative controls in existence and for high hazard work is not optional in practice. Training is what makes every other control usable. Scheduling a noisy or dusty task outside occupied hours protects a whole population at essentially no cost. Where permits are integrated with the maintenance workflow rather than run as a parallel paper system, compliance improves; the mechanics are in the PTW and CMMS integration guide.
So why fourth? Because every one of them depends on a person doing the right thing, correctly, every time, including when rushed, tired, working alone, under commercial pressure, new to the site, or convinced from experience that the step is unnecessary. A procedure is a control only while it is followed, a permit only while it is properly raised, checked and closed, signage only while it is read and heeded.
The failure mode is quiet and gradual. Nobody announces that the procedure has stopped being followed. It erodes: one step skipped because the tool was not available, then two, then the shortcut becomes the local method, then it becomes what the new starter is taught. By the time an incident reveals the drift, the written procedure and the actual practice have been different documents for years. The organisations that manage these controls well are the ones that periodically go and watch the work being done rather than auditing the paperwork that describes it.
What administrative controls cost
They look cheap because they have almost no capital cost, and that is why they are over-selected. Their real cost is recurring and mostly invisible on a budget line: writing and revising procedures, training every new starter, issuing and auditing permits, supervising, investigating drift. A procedure is a liability that must be maintained forever. A guard is bought once and inspected.
7. Level 5: personal protective equipment
PPE is last. It is not last because it is useless, and treating it dismissively is both wrong and counterproductive, because for a lot of maintenance work PPE is the control standing between a technician and a serious injury right now, today, whatever the hierarchy says about the ideal.
It is last because of what it is and is not. Gloves, eye protection, hearing protection, respiratory protective equipment, arc flash clothing, fall arrest harnesses, safety footwear: none of them touch the hazard. The hazard remains intact at full strength, and the only thing reducing the harm is a layer worn on one person's body. That produces four weaknesses, and they compound:
- It protects one person. Every other person in the area, including the visitor, the contractor and the operator walking past, is unprotected. Every other tier protects everybody present.
- It only works if correctly selected. The wrong glove material against a particular chemical is worse than no glove, because it absorbs and holds the substance against the skin. The wrong respirator cartridge is a false sense of protection. Selection is a technical judgement, not a stores decision.
- It only works if correctly fitted, worn and maintained. A tight fitting respirator on an unshaven face leaks. A lanyard anchored below the user does not arrest a fall within survivable limits. Filters expire, visors scratch, gloves develop pinholes.
- It fails silently. This is the decisive point, and the reason PPE sits at the bottom rather than merely near it. A missing guard is visible from across the room. When a respirator's seal is broken or a cartridge saturated, nothing happens, no alarm sounds, and the wearer feels protected while being exposed. A failed engineering control announces itself; failed PPE does not, and the person relying on it is often the last to know.
None of that argues for less PPE. It argues for PPE as the last layer rather than the first answer, and for taking its selection, fit testing, inspection and replacement as seriously as any other safety critical system. See the PPE guide for selection, fit and programme management.
8. The five levels at a glance
The table below sets the five levels against what they mean, what they look like in maintenance and facilities work, why they sit where they do, and how each fails. The last column is worth reading closely, because failure mode is the real basis for the ranking.
| Level | What it means | Maintenance and FM examples | Why it sits here | How it fails |
|---|---|---|---|---|
| 1. Elimination | Remove the hazard entirely; nothing left to control | Relocate a serviceable component to ground level; delete an unjustified PM task; remove a chemical from the process | An absent hazard cannot be mismanaged. No dependence on behaviour, condition or funding | Rarely fails once done. Fails by never being attempted, or by the hazard returning via a later design change nobody reviewed |
| 2. Substitution | Replace the hazard with a less hazardous alternative | Water-based cleaner for solvent; bolted joint instead of welded; lower pressure cleaning; reduced voltage tools | Acts on the hazard itself, but a residual hazard remains, so second not first | The replacement introduces a different hazard nobody assessed, or reverts when the original product is reordered by habit |
| 3. Engineering controls | Physical measures isolating or containing the hazard. Under ISO 45001 this tier also includes reorganization of work | Fixed guards; interlocks; local exhaust ventilation; access platforms and guardrails; single point isolation design; RCDs | Works without anyone having to do the right thing. The highest tier not depending on human reliability | Degrades physically or is deliberately defeated: guard not refitted after a repair, interlock bypassed, ventilation fouled |
| 4. Administrative controls | Change how, when and by whom the work is done | Permit to work; method statements; competence and training; job rotation; out of hours scheduling; signage; supervision | Depends entirely on people following it correctly every time, including under pressure | Erodes quietly. Steps skipped, the shortcut becomes the local method, procedure and practice diverge unnoticed for years |
| 5. PPE | Equipment worn by an individual as the last barrier | Eye and hearing protection; respiratory protection; gloves matched to the substance; arc flash clothing; fall arrest harness | Does not touch the hazard, protects one person only, and depends on correct selection, fit, use and upkeep | Fails silently. Wrong selection, poor fit, expired filter, damaged item. The wearer usually cannot tell it stopped protecting them |
9. The ranking is about reliability, not cost or convenience
The most common misreading of the hierarchy is that it runs from expensive to cheap, and that working down the list is therefore a budget concession. It is not. The ordering is by reliability of the control: how likely it is to still be working, in the state you assumed, at the unplanned moment when it matters.
Read the failure column of the table again in that light. An eliminated hazard has essentially no failure mode. A substituted hazard fails only if the substitution was badly assessed or quietly reverted. An engineering control fails physically or by deliberate defeat, and in both cases the failure is usually visible: a missing guard, a cable tie on an interlock. An administrative control fails by erosion, invisible on paper and detectable only by watching the work. PPE fails silently on one person with no external sign at all. That is the pattern: as you move down the hierarchy, failures become harder to detect. Not just more likely, harder to see. A control you cannot verify is a control you are assuming, and a safety case built on assumed controls looks compliant for years and then does not.
The test I would apply
For each control you have selected, ask: if this control stopped working tonight, how would anyone find out, and how long would it take? If the honest answer is "when someone gets hurt", you have chosen a control from too low in the hierarchy, or you have chosen a low tier control without building any way to verify it.
10. Controls are combined, not chosen singly
The triangle diagram invites a wrong inference: that you pick one level. In practice a competent control set spans several levels simultaneously. Working down the hierarchy does not mean stopping at the first tier available; it means taking everything you can get at every tier.
The layers are complementary because they fail differently. An engineering control reduces the severity and frequency of exposure. An administrative control governs the residual situations it does not cover, such as the activity that requires the guard to come off. PPE covers the moment both have been defeated. Each layer catches what the one above it missed, which is why removing any single layer rarely causes an immediate incident, and why layers get removed so casually.
Here is a worked example. This is a hypothetical scenario constructed for illustration, not a description of any real site. The hazard: technicians periodically clean the interior of a large air handling unit in a plant room using a chemical coil cleaner, with rotating fans and electrical supply present, and the access hatch is currently reached from a portable ladder.
| Level | Control applied to this one hazard | What it removes or reduces | What it leaves behind |
|---|---|---|---|
| Elimination | Specify coil coatings and improved upstream filtration at the next unit replacement so interior wet cleaning leaves the maintenance regime; delete the PM task | The entire task, and with it the chemical, access, rotating machinery and height exposure for this activity | Only available at replacement or major refurbishment. Until then nothing is removed |
| Substitution | Replace the aggressive cleaner with a milder or water-based product qualified for the coil material, assessed in its own right across health, flammability and environmental properties | Severity of the chemical exposure hazard; may reduce the respiratory protection requirement | Cleaning still required. Rotating machinery, electrical and access hazards untouched, and may take longer, increasing time at height |
| Engineering | Fixed access platform with guardrails at the hatch; interlocked hatch removing fan supply when opened; lockable single point isolator at the unit; improved plant room ventilation | Fall hazard from ladder work; contact with rotating fan; energisation during work; vapour accumulation | Capital cost and lead time. Interlock and platform become assets needing inspection tasks or they degrade unnoticed |
| Administrative | Permit to work covering isolation and chemical use; lockout tagout at the isolator; competence requirement; two person working; schedule outside occupied hours; signage at the door | Governs the residual case, particularly work requiring the interlock to be overridden under controlled conditions | Entirely dependent on the permit being properly raised, the isolation verified and the procedure followed under time pressure |
| PPE | Chemical resistant gloves matched to the specific product; eye or face protection; respiratory protection with fit testing where the assessment requires it | Harm to the individual technician if a higher layer has already failed | Protects only the wearer, only while correctly selected, fitted and maintained, and fails without warning |
Five levels, one hazard, applied together. Notice two things. First, the upper tiers do not make the lower ones unnecessary; they reduce how much the lower ones are asked to carry. Second, elimination is available only at a specific future moment, which is the practical reality of most existing installations.
11. Why organisations default to the bottom two tiers
Here is the uncomfortable part. Read a sample of real risk assessments from almost any organisation and the controls column will be dominated by procedures, training, permits, signage and PPE. Engineering controls appear occasionally, substitution rarely, elimination almost never, and when it does it is usually a line saying it was considered and rejected.
This is not cynicism. The bottom two tiers can be implemented this week, by the safety function alone, with no capital approval: writing a procedure, adding a toolbox talk and issuing gloves needs nobody's budget sign off and closes the action. The top three tiers require engineering, projects, operations, procurement and finance to agree, which means a business case, a lead time, and a decision that is not the safety function's to make. And actions are tracked by closure, not by tier, so "issued PPE and briefed the team" and "installed a fixed platform" both show as one closed action. The measurement system is indifferent to the distinction the hierarchy exists to make.
How to recognise it and push back:
- Tag every control with its tier and report the distribution. A control set that is overwhelmingly tier four and five, reported as a number, is an argument that makes itself, and nobody has to be accused of anything.
- Require a recorded reason for skipping a tier, stated as what would have to change and what it would cost, not as the words "not reasonably practicable". Route the ones whose only obstacle is capital into the capital plan instead of closing them.
- Treat repeat administrative controls as a design signal. If the same hazard has generated the same permit hundreds of times, that frequency is telling you the task deserves an engineering solution. High frequency permits are a backlog of unbuilt engineering controls.
- Put the hierarchy into the change and project process, not only the risk assessment form. The decisions determining which tiers are available are made at design and procurement, long before a risk assessment is written.
One related tell is worth naming. PPE-first thinking is a symptom, not a policy. When a risk assessment's primary control is PPE and the upper tiers are blank or dismissed in a phrase, that rarely reveals a deliberate decision to accept a low reliability control. It reveals an assessment that skipped the upper tiers, usually because it was done under time pressure by someone without the authority to propose an engineering change, or from a desk rather than at the workface. The PPE line is where an incomplete assessment comes to rest, so if you audit anything in a control set, audit the assessments whose top answer is PPE, and go and look at the task.
12. Design stage versus existing installations: the honest difference
The hierarchy is written as though all five tiers are available for every hazard. At the design stage that is nearly true, and it is where the hierarchy has the most leverage per unit of effort. Before anything is built, elimination and substitution cost drawing revisions, and access, isolation points, ventilation, guarding and separation distances can be designed in for a fraction of the retrofit cost. This is the logic ISO 12100:2010 applies to machinery, where inherently safe design precedes safeguarding: the decisions with the greatest safety value are made earliest, by designers, usually before any safety professional is in the room.
On an existing installation the picture is different, and pretending otherwise is a disservice. For a plant room built fifteen years ago with an asset not due for replacement for another seven, elimination and often substitution are genuinely foreclosed within the current cycle. Not "difficult". Foreclosed, until a replacement or refurbishment opportunity arrives. The best available control may honestly be an engineering retrofit plus a robust administrative regime plus PPE. Say that plainly in the risk assessment, rather than pretending the upper tiers were unavailable in principle or that the resulting control set is as good as an eliminated hazard. Two things follow:
- Record the foreclosure with its expiry. "Elimination requires replacement of the unit, currently programmed for 2032; to be reconsidered at replacement design stage." That turns a dead end into a scheduled decision, and it survives the staff turnover that would otherwise lose the reasoning entirely.
- Accept that the residual control set needs more verification. If you rely on tiers four and five, you owe the people relying on them a real verification regime: observed task audits, permit quality checks, fit testing, PPE condition inspections, and the engineering controls you do have carrying their own maintenance tasks. Lower tier controls are not forbidden. They simply will not tell you when they stop working, so you have to go and ask.
Where the hierarchy does not help you
The hierarchy ranks control types. It does not tell you how much residual risk is acceptable, does not resolve conflicts where two hazards pull in opposite directions, and does not price anything. Two competent people can apply it to the same hazard and disagree about where "reasonably practicable" stops. It is a structured way to make sure the good options were considered, not a calculation that produces an answer, so treat it as a checklist against your own blind spots and do not expect it to settle an argument about cost.
The idea to walk away with
The hierarchy of controls ranks control measures by how reliably they keep working without anyone paying attention. Elimination and substitution act on the hazard, so there is less or nothing left to go wrong. Engineering controls act on the risk without depending on behaviour, which is why they sit at the boundary. Administrative controls and PPE depend on people getting it right every time, and they fail in ways progressively harder to see, with PPE failing silently on one individual at the very bottom.
So the useful question is not "which control should we use?" It is "how far up can we actually get, what is honestly blocking the tiers above that, and how will we know if the tiers we chose stop working?" A control set spanning several levels, with the reasoning for every skipped tier written down and verification proportionate to how low you had to go, is what competent application looks like. A single line saying "PPE to be worn" is what skipping the hierarchy looks like.
Final thoughts
The attribution is worth carrying away as carefully as the principle. The hierarchy of controls is a principle, not a standard. It is required by ISO 45001:2018 at clause 8.1.2 and by ANSI/ASSP Z10.0-2019 at section 8.4, and described by NIOSH on a free public page that is the origin of the diagram everyone draws. US OSHA does not define it in any regulation, though its air contaminant and PPE provisions clearly prefer engineering and administrative controls over reliance on PPE. And ISO's five levels are not quite NIOSH's, because ISO places reorganization of work inside the engineering tier. Precision on those points costs nothing and makes every procedure and training deck citing them defensible.
The harder work is cultural rather than technical. Most organisations know the triangle and still fill their risk assessments from the bottom of it, because the bottom is fast, cheap and within the safety function's own gift. Changing that means getting the hierarchy into design reviews and capital planning, tagging controls by tier so the distribution becomes visible, and refusing to let "not reasonably practicable" close an action that is really waiting for a budget. None of that needs new software or a new standard. It needs the top of the list asked seriously before the bottom of it is written.
Primary sources worth reading directly: NIOSH (CDC) , which publishes the free hierarchy of controls description and the original inverted triangle; ISO for ISO 45001:2018 and ISO 12100:2010; and OSHA for the US regulatory text on air contaminants and personal protective equipment, which is worth reading precisely because it does not contain the definition it is so often credited with.
Disclosure
Alongside advisory work I also build a CMMS and CAFM platform, so I have a commercial interest in this category. Nothing above is a recommendation for it, and no vendor named here has paid for inclusion or had any editorial input. Weigh the analysis accordingly.
Control set weighted to the bottom of the hierarchy?
Independent advisory on control selection, permit and isolation design, treating safety critical guards, interlocks and ventilation as maintainable assets, and getting the hierarchy into design review rather than only into risk assessment forms. 22+ years across utilities, oil and gas, manufacturing, government and facility operations.
Book a conversationRelated reading: What is HSE, Hazard vs risk, Hazard identification methods, Risk assessment guide, Lockout tagout, Permit to work, PPE guide, Facilities maintenance management.
Muhammad Abbas
CMMS / CAFM Manager & Independent Advisor · 22+ years across enterprise CMMS, EAM, CAFM and ERP implementations in utilities, oil and gas, manufacturing, government and facility operations.
Work with me