Search for "operational assurance" and you'll find it used for software testing cycles, financial controls, IT service management, anything that needs a reassuring pair of words attached to it. None of that is what an HSE manager means when they use the term about a platform or a process plant. In a high-hazard environment, operational assurance describes something narrower and more consequential: the ongoing evidence that safety-critical systems, controls and personnel are performing as intended, not just that they were designed and installed correctly at handover.

That distinction matters because it's easy to confuse assurance with compliance. A written scheme of examination under the Pressure Systems Safety Regulations 2000 tells you a vessel was inspected and found fit for continued use. Operational assurance is the broader discipline of knowing, at any point in time, which safety-critical elements are currently verified, which are overdue, and what that overdue status actually means for the risk profile of the asset. One is a record. The other is a live picture.

What operational assurance actually covers

On an offshore installation operating under the Safety Case Regulations 2015, the safety case identifies safety-critical elements and sets performance standards for each of them, things like fire and gas detection, emergency shutdown valves, blast walls, deluge systems. Operational assurance is the day-to-day and shift-to-shift work of confirming those elements still meet their performance standards: the verification schedule, the deferred or overdue tasks, the management of change when a temporary deviation is accepted.

Onshore, under COMAH, the same idea applies to major accident hazard controls, though the regulatory architecture is different. In both cases, the practical question a duty holder needs answered isn't just "was this inspected", it's "is this currently in a verified state, and if not, who signed off the risk of leaving it that way and for how long".

Site safety and joint integrity fit the same pattern at a smaller scale. A bolted flange assembled and torqued correctly at a turnaround still needs its assurance record tied to the joint identifier, not buried in a contractor's paper folder, so that the next inspection or leak investigation can actually find it. We've covered this in more detail in why joint integrity management matters offshore.

Is there a certification for operational assurance

Not as a single, standalone credential. That's worth saying plainly because the term gets searched as though one exists. What you find instead is a set of overlapping standards and regulatory obligations that, taken together, form the evidence base for assurance:

- ISO 55001 sets out requirements for an asset management system, and auditors will look for how an organisation plans, delivers and reviews maintenance and verification activity against it.
- The written scheme of examination under PSSR 2000 is a legal requirement for pressure systems, not guidance, and sets out what must be examined and how often.
- Performance standards for safety-critical elements under the Safety Case Regulations 2015 are a legislative requirement for offshore duty holders, verified through a scheme approved by an independent and competent person.
- OEUK publishes guidance, including KPI frameworks for maintenance backlog, that isn't law but sets the accepted industry benchmark operators are measured against informally, even when it isn't a formal legal duty.

None of these is branded "operational assurance", but together they're what an operator can point to when asked to demonstrate it. Individual competency schemes, from NEBOSH qualifications to internal authorisation and competency frameworks for permit issuers and Area Authorities, sit alongside these as the human half of the same picture.

Backlog and assurance tracking as the proof point

Whatever the underlying framework, the practical evidence almost always comes back to backlog. How many safety-critical verification tasks are currently overdue, for how long, and against which performance standard. OEUK's maintenance KPI guidance gives operators a common language for reporting this, and we've written before about what that guidance on maintenance backlog actually asks for in practice.

Backlog on its own is a lagging indicator, though. A more useful assurance tracking question is whether the overdue task register is linked back to the risk assessment that justifies continuing to operate with it outstanding, and whether that link is visible to whoever is signing permits on the affected system today, not just to whoever wrote the report last quarter.

What to actually check when evaluating assurance tracking

Where a self-assessment is useful, it's worth being concrete rather than reaching for a checklist of generic questions. Ask whether the current system can show, for any safety-critical element, its verification history end to end: when it was last checked, against which performance standard, who deferred it if it's overdue, and what compensating measures were put in place in the meantime. Ask how backlog figures are produced, whether they come from a live query against the maintenance system or from a manually assembled spreadsheet compiled before a monthly review. Ask whether a permit issuer working a night shift can see that a piece of equipment they're about to isolate has an overdue verification against it, without needing to cross-reference a separate register.

Those questions tend to expose the gap between an organisation that has assurance data and one that has assurance. We've explored the same distinction, from the verification side rather than the certification side, in what operational assurance means as a process safety framework rather than a set of isolated checks.

Where this leaves the term

Operational assurance isn't a product you buy or a certificate you frame. It's the discipline of keeping verification, backlog and risk decisions connected to one another as an asset ages and conditions change, so that a duty holder can answer, honestly and quickly, whether the controls they rely on are still doing what the safety case says they do. Software has a role in that, mainly by making the connections between systems visible instead of leaving them to be reconstructed under pressure, and it's an area covered by assurance and compliance software energy operators trust.

If you're trying to work out whether your current backlog reporting genuinely reflects assurance status, or just activity completed, it's a reasonable exercise to trace one overdue item through your own systems and see how many places you have to look before you get the full picture.

Frequently Asked Questions

Is operational assurance just another word for compliance?
No. Compliance, like a written scheme of examination, tells you a system was inspected and passed. Operational assurance is broader: it's the live picture of which safety-critical elements are currently verified, which are overdue, and what that means for risk right now.
Is there an actual certification called 'operational assurance' you can get?
No single standalone credential exists under that name. Instead, it's built from overlapping standards and rules like ISO 55001, the PSSR 2000 written scheme of examination, Safety Case Regulations 2015 performance standards, and OEUK's KPI guidance, plus competency schemes for staff.
What's the difference between offshore and onshore requirements here?
Offshore installations work under the Safety Case Regulations 2015, which set performance standards for safety-critical elements like fire and gas detection or emergency shutdown valves. Onshore, COMAH applies the same underlying idea to major accident hazard controls, though the regulatory structure differs.
Why isn't tracking maintenance backlog enough on its own?
Backlog figures show how many verification tasks are overdue, but that's a lagging indicator. What actually matters is whether that overdue task is linked back to the risk assessment justifying continued operation, and whether that link is visible to whoever is signing permits today.
What should I actually check to see if our assurance tracking is any good?
Check whether you can see full verification history for any safety-critical element (last check, performance standard, who deferred it, compensating measures), whether backlog numbers come from a live system query or a manually built spreadsheet, and whether a night-shift permit issuer can see overdue verifications without cross-referencing a separate register.
How does joint integrity relate to operational assurance?
It's the same idea at a smaller scale: a bolted flange that's torqued correctly still needs its assurance record tied to the specific joint identifier, not filed away in a contractor's paperwork, so it can actually be found during a later inspection or leak investigation.
← Back to Blog