The scoreboard, honestly: the hard targets, how often each one is actually looked at,
and the quiet human signals that never make it onto a dashboard.
Total Recordable Incident Rate (TRIR)
The number of work-related injuries or illnesses per 100 full-time employees over a one-year period.
Target · Reduce TRIR by 10% year-over-year across the business unit.If our TRIR was 1.5 last year, we're aiming for 1.35 or lower this year. This means fewer people getting hurt, which is the main point, honestly.
Cost of Risk (CoR) Reduction
The total cost associated with managing risks, including insurance premiums, self-insured losses, claims, and risk management programme costs.
Target · Achieve a 5-8% reduction in the total cost of risk across the business unit annually.By implementing better controls and reducing incidents, we expect to see our insurance premiums drop and fewer payouts for claims, saving us, say, £500K-£800K this year.
Regulatory Non-Conformities & Fines
The number and severity of regulatory breaches, including fines, penalties, and enforcement actions.
Target · Maintain zero major non-conformities and zero regulatory fines across the business unit.We had a minor breach last year that cost us £5K. Your job is to make sure those don't happen, especially the big ones that hit the news and cost millions.
Risk Management Maturity Score
An assessment of our organisation's capabilities in identifying, assessing, mitigating, and monitoring risks, often against a recognised framework.
Target · Improve our internal risk maturity score from Level 3 to Level 4 (out of 5) within two years.This means moving from a reactive, 'fire-fighting' approach to a more proactive, integrated risk management system. It's about getting better at spotting problems before they become disasters.
Executive & Board Confidence in Risk Posture
The level of trust and understanding the executive team and Board have in our risk management capabilities and the accuracy of our risk reporting.
- You'll know this is going well when the COO and Board members proactively seek your input on strategic decisions, rather than just waiting for your reports. They'll ask 'What's the risk here?' and genuinely listen to your answer. Your presentations will be clear, concise, and lead to informed discussions, not just blank stares.
Proactive Regulatory Engagement
Our ability to anticipate regulatory changes and engage constructively with external bodies, shaping policy where possible and ensuring smooth adaptation.
- This looks like you being invited to industry consultations, or our legal team asking you to review draft legislation. It's about us being ahead of the curve, not scrambling to catch up. When a new regulation drops, we should already have a plan, not just be starting to read it.
Culture of Reporting & Accountability
The extent to which employees at all levels feel comfortable reporting incidents, near misses, and concerns without fear of blame, and leaders take visible action.
- We'll see an increase in near-miss reporting (which is a good thing, believe it or not), and a decrease in 'pencil whipping' (where people just tick boxes). Managers will actively discuss safety in their team meetings, and you'll hear examples of people stopping work because something 'didn't feel right.' It's about ownership, not just compliance.
Strategic Integration of Risk Management
How well risk considerations are embedded into our business planning, project management, and daily operational decisions.
- You'll see risk assessments being done *before* new projects kick off, not as an afterthought. Business cases for new investments will explicitly address safety and compliance risks. Your team's input will be sought early in the planning stages for new products or market entries, not just at the end.