The gap between doing the work safely and proving it

Most operators on the UKCS aren't failing at safety. They're failing at proof. An OIM can walk you through how isolations are verified, how permits are authorised, and how competency is checked before a contractor picks up a tool. What's much harder is producing that same picture on demand, across every discipline, for an auditor who wants to see it in one place.

That gap — between operational reality and demonstrable assurance — is where most audit findings land. Permit to work sits in one system. Isolation certificates sit in a locked cabinet or a spreadsheet on a shared drive. Competency records live in a training provider's portal that nobody checks against the permit register. Joint integrity inspections get logged separately from the maintenance schedule that should be triggering them. Individually, each process might be sound. Collectively, nobody can answer a simple question quickly: can you show me every live permit right now, and confirm every person named on it holds a current competency for that task?

Why fragmented systems fail assurance and compliance

Paper registers and disconnected spreadsheets don't fail because the people using them are careless. They fail because they were never designed to cross-reference against each other. A permit to work register doesn't know that a competency certificate expired last week. An isolation log doesn't know that the same valve has been locked in position for months without revalidation. A maintenance backlog spreadsheet doesn't flag that a piece of equipment now overdue for inspection is also the subject of an open permit.

These aren't hypothetical failure modes. They're the specific gaps that show up when OEUK's process safety leadership principles or a Safety Case Regulations audit push past the paperwork and ask how the systems actually talk to each other. The honest answer, on most assets still running manual or semi-digital control of work, is that they don't.

What auditors and regulators actually check

HSE inspectors and OPRED auditors are not looking for a folder of completed forms. They're looking for a live, defensible chain of evidence: who authorised this permit, what isolations does it depend on, is the isolation certificate current, is the person executing the work competent for it, and does the equipment involved have an up-to-date integrity status. If any link in that chain requires someone to manually cross-check three separate systems before they can answer, that's the finding.

The same logic applies whether the question is about electrical permit to work and live working authorisation, scaffold inspection currency, or potable water verification records. Auditors are testing whether your control of work processes are genuinely integrated or only superficially compliant.

A diagnostic checklist for your own assurance posture

Before an auditor asks, ask yourself these questions:

- Can you produce a complete list of every live permit on the asset right now, without contacting three different people?
- Can you confirm, in the same view, that every named individual on those permits holds current competency for the task?
- If a valve or breaker has been isolated for more than 12 months, does your system flag it automatically for revalidation, or does that depend on someone remembering?
- When a piece of critical equipment falls into maintenance backlog, does that automatically restrict or flag any permit that depends on it?
- Could a new HSE manager, with no institutional memory, reconstruct the assurance picture for this asset from the system alone?

If any of these are difficult to answer without picking up the phone, that's where the audit finding will land.

Why operators choose a single system of record

Operators trust Elisian because it closes the gap between these disciplines instead of treating them as separate administrative tasks. Permit to Work, isolations, competency, and integrity data sit in one connected record, so a permit can't be authorised against an isolation that's out of date, or a task assigned to someone whose competency has lapsed. That's the same principle behind what we mean by operational assurance as a process safety framework rather than a collection of separate verification tasks.

The competency piece matters more than it's often given credit for, particularly on assets running mixed contractor and direct-hire crews. A permit system that doesn't check competency at the point of authorisation is only checking half the problem, which is precisely the gap explored in closing the competency gap on critical equipment. The same applies to integrity: a maintenance schedule that doesn't connect to the permit register will keep generating backlog that nobody notices until it's overdue.

This isn't about adding software for its own sake. It's about removing the manual reconciliation that currently sits between your teams and a defensible answer to a regulator's question.

The next step

Assurance and compliance stop being a paperwork exercise once the systems that generate the evidence are connected by design, not by someone's memory of where to look. If your current control of work, permit to work, and integrity processes still rely on separate registers and manual cross-checks, that's the first thing worth fixing before your next audit, not after it. Get in touch with Elisian to talk through how a connected system of record would look on your asset.

← Back to Blog