EHS & Risk Glossary
Plain-language definitions of the core terms in EHS, risk & compliance — from bowtie analysis to Scope 1/2/3 emissions.
Bowtie analysis is a qualitative risk method that places a single hazardous 'top event' at the center, maps its potential causes on the left and its consequences on the right, and shows the barriers that prevent or mitigate each pathway. The result is a diagram, shaped like a bowtie, that makes clear how preventive and mitigating controls reduce risk. It is widely used in high-hazard industries to communicate major-accident risk and demonstrate that credible barriers are in place.
A Process Hazard Analysis is a systematic, team-based assessment of the hazards of a process, examining equipment, instrumentation, procedures, and human factors that could lead to an uncontrolled release of hazardous material or energy. Common methodologies include HAZOP, What-If, Checklist, and Failure Modes and Effects Analysis. PHAs are a core element of OSHA Process Safety Management (29 CFR 1910.119) and must be revalidated on a defined cycle.
A Job Hazard Analysis, also called a Job Safety Analysis, breaks a task into its individual steps, identifies the hazards associated with each step, and defines the controls needed to perform the work safely. It is typically completed before non-routine or higher-risk work and used to brief the crew. JHAs embed hazard recognition into everyday task planning rather than relying on after-the-fact incident review.
Lockout/Tagout is a set of procedures for isolating and de-energizing machinery and equipment so it cannot be started while servicing or maintenance is performed. Energy-isolating devices are physically locked in a safe position and tagged to warn others, protecting workers from the unexpected release of hazardous energy. In the United States it is governed by OSHA's Control of Hazardous Energy standard, 29 CFR 1910.147.
A Permit to Work is a formal, documented authorization that specifies the controls, precautions, and time limits required before high-risk work such as hot work, confined-space entry, or work at height may begin. Control of Work is the broader management system that coordinates permits, energy isolations, risk assessments, and simultaneous operations so that conflicting activities do not create new hazards. Together they provide an auditable record that hazards were assessed and controlled before work started.
Enterprise Risk Management is a structured, organization-wide approach to identifying, assessing, prioritizing, and treating the risks that could affect an organization's objectives, spanning strategic, operational, financial, compliance, and hazard risks. It aggregates risk information so leadership and the board can make decisions against a consistent view of exposure and risk appetite. Widely referenced frameworks include COSO ERM and ISO 31000.
Barrier management is the practice of identifying the technical, operational, and organizational barriers that prevent or mitigate major accidents, and ensuring they remain effective throughout an asset's life. It sets a performance standard for each barrier, monitors barrier status, and manages impairments so residual risk stays within acceptable limits. It is closely tied to bowtie analysis, which visualizes the barriers protecting against a top event.
Incident management is the end-to-end process of reporting, recording, investigating, and learning from incidents, near misses, and unsafe conditions. A mature process captures the event, triages severity, drives investigation and root cause analysis, and tracks corrective and preventive actions (CAPAs) to closure. Its purpose is not only regulatory recordkeeping but organizational learning that prevents recurrence.
Root Cause Analysis is a structured investigation method for identifying the underlying causes of an incident rather than its immediate symptoms, so corrective actions address why the event was able to occur. Techniques range from the iterative '5 Whys' to systemic models such as ICAM (Incident Cause Analysis Method), which separates absent or failed defenses, individual actions, task and environmental conditions, and organizational factors. Effective RCA produces controls that prevent recurrence across similar work, not just the single event investigated.
Under the GHG Protocol, an organization's greenhouse gas emissions are grouped into three scopes: Scope 1 covers direct emissions from owned or controlled sources; Scope 2 covers indirect emissions from purchased electricity, steam, heating, and cooling; and Scope 3 covers all other indirect emissions across the value chain, both upstream and downstream. Scope 3 is usually the largest and hardest to measure because it depends on suppliers, customers, and product use. The scopes provide a consistent basis for carbon accounting and disclosure.
ESG reporting is the disclosure of an organization's performance on environmental, social, and governance factors, such as emissions, resource use, workforce safety, diversity, and board oversight, to investors, regulators, and other stakeholders. It may be voluntary or, increasingly, mandated by regulations such as the EU's Corporate Sustainability Reporting Directive. Reports typically follow one or more standards, for example GRI, SASB/ISSB, or the TCFD recommendations, to make the information comparable and decision-useful.
The SASB Standards identify the subset of sustainability topics most likely to be financially material for companies in each of 77 industries, along with standardized metrics to report them. Designed primarily for investors, they emphasize decision-useful, industry-specific disclosure. SASB is now maintained by the IFRS Foundation's International Sustainability Standards Board (ISSB), which has built on it in developing global sustainability disclosure standards.
The TCFD issued recommendations for disclosing climate-related risks and opportunities across four pillars: governance, strategy, risk management, and metrics and targets. Its framework emphasizes forward-looking, scenario-based analysis of how climate change could affect an organization's financial position. The TCFD was disbanded in 2023 after its recommendations were absorbed into the ISSB's IFRS S2 climate disclosure standard, which now carries them forward.
The Global Reporting Initiative provides the most widely used standards for sustainability reporting, oriented toward an organization's impacts on the economy, the environment, and people. Its 'impact materiality' lens serves a broad set of stakeholders and complements investor-focused frameworks such as SASB and IFRS. GRI Standards are modular, comprising universal, sector, and topic standards.
CDP operates a global environmental disclosure system through which companies, cities, and governments report on climate change, water security, and deforestation. Organizations respond to standardized questionnaires and receive a graded score, from A to D- (with an F for non-disclosure), that investors and buyers use to benchmark environmental performance and transparency. CDP disclosure aligns closely with the GHG Protocol and TCFD recommendations.
A Safety Data Sheet is a standardized document that communicates the hazards of a chemical product and the precautions for its safe handling, storage, transport, and emergency response. Under the UN Globally Harmonized System (GHS), it follows a fixed 16-section format covering identification, hazards, composition, first aid, firefighting, and more. Employers must keep SDSs readily accessible to workers who may be exposed, as required by OSHA's Hazard Communication Standard.
A HAZOP is a structured PHA technique in which a multidisciplinary team examines a process design node by node, applying guide words such as No, More, Less, and Reverse to process parameters to identify deviations, their causes, and their consequences. It systematically surfaces both safety hazards and operability problems that less rigorous methods can miss. HAZOP is one of the most common methodologies used to satisfy Process Hazard Analysis requirements.
Management of Change is a formal process for reviewing, approving, and documenting changes to processes, equipment, procedures, or organization before they are implemented, so that new hazards are not introduced unintentionally. It ensures that technical review, hazard assessment, and updates to documentation and training accompany any change that is not a replacement in kind. MOC is a required element of OSHA Process Safety Management and a frequent contributing factor when incidents are traced to unmanaged change.
Lagging indicators measure safety outcomes that have already occurred, such as recordable injuries or spills, while leading indicators measure proactive activities believed to prevent them, such as inspections completed, near misses reported, or overdue actions closed. A balanced program uses leading indicators to predict and drive improvement rather than relying solely on after-the-fact outcome data. The two are complementary: leading indicators signal where to act before lagging indicators register harm.
The Total Recordable Incident Rate expresses the number of OSHA-recordable injuries and illnesses per 200,000 hours worked, roughly equivalent to 100 full-time employees for a year, so organizations of different sizes can be compared. It is calculated as recordable cases multiplied by 200,000 and divided by total hours worked. As a lagging indicator it reflects past outcomes and is best interpreted alongside leading measures.
Process Safety Management is a regulatory and management framework for preventing catastrophic releases of highly hazardous chemicals from processes. OSHA's PSM standard (29 CFR 1910.119) comprises 14 interrelated elements, including process hazard analysis, mechanical integrity, management of change, operating procedures, and incident investigation. It targets low-frequency, high-consequence events, distinct from everyday occupational safety.
The Corporate Sustainability Reporting Directive is an EU law that expands the scope and rigor of mandatory sustainability disclosure, requiring in-scope companies to report against the European Sustainability Reporting Standards (ESRS). It applies the principle of 'double materiality,' requiring companies to report both how sustainability issues affect the business and how the business affects people and the environment. Reported information is subject to third-party assurance and digital tagging.
ISO 31000 is the international standard that provides principles, a framework, and a process for managing risk of any kind. It is guidance rather than a certifiable requirements standard, applicable to any organization regardless of size or sector, and is designed to embed risk-informed decision-making into governance and strategy. Its process — establishing context, then identifying, analyzing, evaluating, and treating risk with ongoing monitoring and review — is widely used as the backbone of enterprise risk management.
ISO 22320 sets guidelines for incident management within the security-and-resilience family of standards, covering command and control, operational information, and coordination among the parties responding to a disruption or emergency. It establishes clear roles, responsibilities, and information flows so responders can stabilize and resolve an incident effectively. It is often applied alongside emergency-management and business-continuity practices.
ISO 22301 specifies the requirements for a business continuity management system (BCMS) — the policies, plans, and procedures an organization uses to prepare for, respond to, and recover from disruptive events such as outages, cyberattacks, or disasters. It requires a business impact analysis and risk assessment to identify critical activities and acceptable recovery times, and mandates tested continuity and recovery plans. As a requirements standard, it can be certified.
ISO 37301 specifies the requirements, with guidance, for establishing, maintaining, and improving a compliance management system. It helps an organization systematically identify its compliance obligations — laws, regulations, codes, and ethical standards — and embed the controls, monitoring, and culture of integrity needed to meet them. As a requirements standard it is certifiable, and it replaced the earlier ISO 19600 guidance.
ISO 19011 provides guidelines for auditing management systems, covering the management of an audit program, the planning and conduct of internal or external audits, and the evaluation of auditor competence, all using a risk-based approach. It is advisory guidance rather than a certifiable standard and applies across management-system disciplines such as quality, environment, and health and safety.
ISO 45001 is the international standard specifying requirements for an occupational health and safety (OH&S) management system, built on the Plan-Do-Check-Act cycle. It requires organizations to identify hazards, assess and control OH&S risks, engage workers, and continually improve safety performance. As a requirements standard it can be certified, and it replaced the earlier OHSAS 18001.
ISO 14001 is the international standard for an environmental management system (EMS), setting requirements to identify and control environmental aspects and impacts, meet compliance obligations, set objectives, and improve environmental performance through the Plan-Do-Check-Act cycle. As a requirements standard it can be certified, and it is the most widely adopted EMS standard worldwide.
See these in one platform.
HSECai brings bowtie risk, control of work, incidents, audits and ESG together — deployed in weeks.