Capptions
Back to blog

An SMS should not be memory work

September 14, 2026

Pipelines at an industrial site at sunrise

Nobody remembers where these pipelines run. Nor do they have to — it is recorded. That is how a safety management system should work too.

How we captured Seveso III expertise in a Framework Definition, and why Clara can carry the administrative management of the safety management system without anyone handing over their responsibility.

For years we have organised Seveso compliance as if human attention were unlimited. As if a QHSE manager had time enough to track legislation, update policy, compare procedures, process inspection findings, chase actions, maintain dashboards — and still be visible on the shop floor. In practice I see something else.

Most Seveso establishments do have plenty of knowledge, documentation and committed people. The problem is that the knowledge has spread across too many places. Part of it sits in the MAPP. Part of it in procedures, safety studies, emergency plans, inspection checklists, spreadsheets and SharePoint folders. And part of it exists only in the head of one experienced colleague. Then someone asks a seemingly simple question.

Should this change go through our Management of Change process? Or: which barrier actually controls this scenario, and how do we demonstrate it is still effective?

And the searching begins. That searching is not an incident. It is a symptom of a management system that has become dependent on human memory, manual coordination and a handful of people who know exactly where everything is. A safety management system should not be memory work. It should be infrastructure.

Making a good specialist's knowledge explicit

So I put a question to Seveso specialists Christian Ackermans and Adam Ziolo LLM — a question that sounded simpler than it was:

Can we make the knowledge that now sits in the head of a good Seveso specialist so explicit that an intelligent system can apply it again every single day?

Christian looks at it from the technical and organisational workings of Seveso III and the SMS. Adam brings the legal view: which sources are authoritative, where the obligations lie, which interpretations are defensible, and where human judgement is simply necessary.

What we did not want: to put their knowledge into a chatbot. Loading a pile of documents into a language model is not that hard. But that does not give a system a reliable way of looking. It does not then know which source outweighs another, how a good SMS is built up, which links between documents must exist, or when an answer is too uncertain to use without specialist review. So we had to build something more fundamental: an explicit knowledge architecture. We call it the Framework Definition.

A Framework Definition is not a collection of documents

The Framework Definition describes not only what Clara must know, but above all how she must work with that knowledge. It records:

  • which type of organisation the Framework is intended for;
  • which legislation, official sources and legal knowledge are relevant, and which source takes precedence in case of doubt;
  • how safety policy, the MAPP, procedures, work instructions, forms and evidence relate to one another;
  • how risks, scenarios, lines of defence and control measures run through the system;
  • which links and internal references Clara must check, and when something counts as a substantive gap;
  • which questions Clara may answer on her own, and when uncertainty must be escalated to a human specialist;
  • how actions, KPIs, SPIs and management information emerge from the system.

The Framework Definition is therefore not a digital handbook, nor is it one customer's SMS. It is the blueprint that lets Clara assess what a good Seveso III management system should look like and how its parts work together.

That nuance is essential. The Capptions Seveso III Framework holds the reusable substantive logic. The customer's management system holds the reality of that one organisation: its installations, risks, people, policy, decisions and evidence.

The Framework says what good looks like. The customer determines what applies to their organisation and which decisions they take.

Three layers, three responsibilities

Capptions fulfils two roles in this model. We are author and maintainer of the Seveso III Framework — Christian and Adam feed and validate the content, our product team makes that knowledge executable. And we build and operate the Capptions.ai platform on which the Framework runs.

But that does not make us the owner of the customer's SMS. That responsibility stays deliberately separated:

Capptions maintains the Framework and the platform. Clara performs the analytical and administrative work. The customer owns the management system, the decisions and the operation.

That is not a legal footnote, it is the foundation of a trustworthy system. Clara can analyse, compare, flag, structure and prepare drafts. Christian and Adam can review and advise. But only the customer's management can decide which risks it accepts, which policy it sets, which resources it frees up and which measures actually land in the operation.

That is why we say internally:

Clara does the work. Experts review the output. Management carries the responsibility.

From Framework to the reality of one organisation

The value of the Framework only becomes visible in the first run at a real organisation.

We collect the customer's existing reality: policy, MAPP, procedures, work instructions, forms, registers, inspection findings, risk analyses, action lists and evidence. Clara does not read that as a pile of loose files; she compares the content with the structure and logic of the Framework.

What is missing? Which documents contradict each other? Does a procedure refer to a form that no longer exists? Is a control measure described but never linked to inspection, training or verification? Does a responsibility sit with a role that has been abolished? Did an inspection finding lead to an action whose effectiveness was never established?

On the basis of that analysis Clara produces a first proposal for the renewed management system: version zero. Emphatically a draft — a coherent proposal for policy, procedures, instructions, forms, actions and monitoring, not an automatically approved SMS.

That draft first passes our own substantive gate. Our Seveso experts assess whether the outcome is correct, whether the Framework has been applied well, and which questions only the customer can answer. Only then does it go to the customer's management, which weighs its own context, makes choices and, where needed, sets the risk profile, risk appetite, responsibilities and priorities. Clara processes the feedback, our experts review again, and then the customer can adopt, mandate and start using the documents.

This does not produce a management system invented by AI. It produces a management system prepared by experts, maintained by software and authorised by the customer.

AI alone is not the product

During development something else became clear: a strong AI agent on its own is not enough.

A Seveso establishment has no need for a box of technology delivered at the front door with a manual attached. The value only emerges when the technology is carefully connected to the organisation. That is why we have organised our Customer Success team around this way of working.

Customer Success supports the collection and structuring of documentation, the setup of users and responsibilities, the configuration of processes and the onboarding of teams. And the team guards the boundary between three kinds of questions: a usage or configuration question, a missing piece of customer information, and a substantive Seveso or legal question that must go to a specialist.

That triage is crucial. Not every question has to reach Christian or Adam, but a question that genuinely requires substantive judgement must not disappear into a generic AI answer either. Customer Success is the human air traffic control between customer, platform, Clara and the experts.

Clara is the engine. Customer Success makes sure that engine is installed properly and keeps running. The customer does the steering.

What Clara concretely takes into management

"Taking work off your hands" is used so often in software that the phrase has become almost meaningless. So let me be concrete. Clara does not take over the customer's safety, nor the responsibility of the board. What she does largely take into management is the administrative and analytical machinery around the SMS.

Documentation that stays connected. A policy change can affect a procedure; that procedure may require a new work instruction; that instruction may require training; and its functioning must later be demonstrated through inspection, observation or a KPI. In a traditional document system those are separate files. For Clara they form one chain — risk → policy → procedure → instruction → execution → evidence → review — and when one link changes, she flags which other links must be reassessed.

One central action register. Every inspection finding, every incident, audit point, change and management decision leads to an action with an owner, a deadline and a required outcome. Execution is recorded, and afterwards it is checked whether the measure was genuinely effective. We design the system so that no action is left sitting in a mailbox and no finding is closed administratively without it being clear whether the underlying risk is better controlled.

A dashboard that shows more than green and red. A good dashboard is not a Christmas tree of percentages; it must help management understand where attention is needed. Which actions are overdue? Which safety-critical measures are performing below standard? Where does evidence lag behind execution? Which trends call for a management decision? Clara collects and interprets; the dashboard makes it governable.

And above all: an SMS that stays alive. The most important difference is not in the first generation of documents, but in what happens afterwards. New findings, changes, incidents, actions and decisions become part of the same system. The SMS is not rewritten once and then slowly allowed to age again — it is maintained continuously. That is the shift from a static to a living SMS.

Not looking compliant, but being demonstrably in control

The Seveso III Directive is strikingly explicit on this point. Article 5 requires the operator to be able to prove to the competent authority at any time that all necessary measures have been taken, in particular during inspections and controls.

At any time. Not: in the week after the inspection has been announced.

The Netherlands has more than four hundred Seveso establishments, where responsibility for safety lies primarily with the establishment itself and joint inspection services supervise compliance. That makes inspection readiness not a temporary project. You can rewrite a document just before an inspection. You cannot retroactively demonstrate that actions were followed up properly for months, that control measures demonstrably worked, and that management steered on deviations in time.

That history has to build up while the organisation works.

Why now, and not in two years?

I regularly hear an understandable reaction: interesting, but AI is developing fast — wouldn't it be wiser to wait a while? I think that is precisely the wrong conclusion, for five reasons.

The backlog does not disappear by itself. Every month brings new actions, inspections, changes, incidents and decisions. A fragmented system does not spontaneously become clearer tomorrow; the pile grows and the dependency on key people increases. Waiting is not a neutral choice — waiting enlarges the migration that will have to happen anyway.

The next inspection starts today. The strongest demonstrability is a calm, consistent history: actions picked up in time, decisions recorded, deviations investigated, effectiveness assessed. You cannot construct that history afterwards; you can only start building it today. To illustrate how high the bar is: according to the Dutch State of Safety 2024, inspection services found more than nine hundred violations at the 393 inspected Dutch Seveso establishments. That does not say these companies work unsafely; it says demonstrability is structurally difficult under the current way of working.

Specialist time is too valuable for searching. Good Seveso specialists are scarce and should spend their time on risks, scenarios, technical trade-offs and difficult management choices — not on comparing version numbers, hunting for annexes and merging action lists. AI does not have to replace the specialist to deliver a major improvement; it is already valuable when it frees the specialist from work that does not need their expertise.

AI does not have to be perfect to be useful today. Many organisations seem to be waiting for the moment when AI can act independently, flawlessly and with legal accountability. That moment is not needed for this transition. Our model is deliberately human-in-the-loop: Clara executes, analyses and proposes; experts review; the customer decides. So Clara does not have to be able to do everything. She has to be reliable enough to do the bulk of the labour-intensive groundwork, to make uncertainty visible, and to direct human attention to the right exceptions.

Supervision is professionalising. Dutch Seveso supervision is moving towards more consistent enforcement, with growing attention to safety culture, effectiveness and demonstrability. That is no reason for panic. It is a signal that the real functioning of the management system is increasingly hard to replace with a well-prepared folder just before an inspection.

The reason to start now is not that AI can suddenly do everything. The reason is that AI can now do enough to let people finally do what people are needed for.

And the business case does not wait for the first inspection. The gain begins with every question that does not need to be researched again, every action that does not disappear from view, every management review for which the information is already in place. The hidden costs of today's way of working are spread across dozens of small handlings — which is exactly why they are so invisible and so persistent.

From toolbox to managed system

Software companies have long sold a toolbox. Here are forms, here is a workflow builder, here is a dashboard, good luck. That technology remains important, but for complex compliance it is no longer enough. The next step is that we deliver not only the tooling, but help organise the management of it.

With a Seveso III Framework fed by Christian and Adam. With Clara continuously doing the administrative and analytical work. With Customer Success organising onboarding, adoption and escalation. With human experts reviewing judgement. And with a customer who remains fully the owner of their policy, choices and operation.

That, to me, is the essence of Seveso Control™: not yet another system that an overloaded QHSE team has to feed, but a management system that actively helps keep itself current, coherent and governable.

Our ambition is sharp:

zero categorised violations at the next inspection

Not as a guarantee — nobody can give that — but as a design criterion for everything we build and organise.

The interesting question for those accountable for Seveso compliance is therefore no longer whether AI will ever play a role in their SMS. The interesting question is:

Which part of this work do we still consciously want people to do three years from now?

I am happy to discuss that question. Not in a demo, but in a conversation about where your SMS stands today and what this model would mean for your organisation.