Capptions
Back to blog

Digitising the VBS: Where Do You Actually Start?

July 11, 2026

Two EHS directors at comparable Seveso sites decide to digitize their veiligheidsbeheersysteem the same quarter. One picks a software platform, rolls it out across all seven Annex III elements at once, and six months later has three modules half-configured, a training backlog, and a site team quietly back to filling in paper checklists. The other picks one element, gets it working end to end, and uses that as the template for the rest.

Same budget. Same regulatory pressure. Different outcome - because they answered a different question first. Not "which software," but "where do we start."

This is the "where to fish" question. A VBS has seven mandatory elements under Annex III of the Seveso III Directive: organisation and personnel, identification and evaluation of major hazards, operational control, management of change, emergency planning, monitoring performance, and audit and review. Not all seven carry the same manual-effort burden, and not all seven carry the same risk if you leave them running on paper and spreadsheets a while longer. Digitizing a VBS isn't one project - it's a sequence, and getting the sequence wrong is more expensive than getting the tool wrong.

Why "digitize everything at once" fails on a Seveso site

A VBS touches nearly every function on site: process safety, maintenance, contractors, training, incident management, emergency response. That breadth is exactly why a single big-bang rollout struggles. Operational control alone spans permit-to-work, isolation procedures, and critical task checklists that different shift teams execute differently depending on years of local habit. Try to digitize that alongside management of change, audit scheduling, and emergency drill logging in the same rollout window, and you're asking operators, contractors, and shift supervisors to change how they work on five fronts simultaneously - during live operations, with no room to pause the plant while people learn a new system.

The result is predictable: adoption stalls on the hardest element, and that stall drags down confidence in the whole platform, including the parts that were going fine. A phased approach - one element digitized, stabilized, and adopted before the next starts - protects both the operation and the credibility of the project internally.

Where the manual-effort burden actually sits

Ask an EHS manager at a Seveso-classified site which parts of the VBS eat the most hours, and two elements come up consistently: operational control and audit and review.

Operational control generates the highest volume of routine paperwork of any Annex III element. Permit-to-work forms, isolation checks, contractor inductions, critical task verifications, and shift handovers all sit here, and on a major-hazard site they happen constantly - often multiple times per shift, across multiple teams, in the field rather than at a desk. When these stay on paper, someone still has to collect the forms, check they're complete, chase down the ones that are missing, and file them in a way that's retrievable if a regulator or auditor asks for them six months later.

Audit and review is less frequent but no less manual. Internal audits, management reviews, and follow-up on corrective actions typically live across separate spreadsheets, email threads, and shared drives. Tracking whether a finding from a March audit actually got closed out by June usually depends on someone remembering to check, not on the system surfacing it.

These two elements are the obvious starting candidates precisely because the manual burden is visible and the win from digitizing is immediate: fewer missing forms, faster field-to-record turnaround, and an audit trail that reconstructs itself instead of requiring reconstruction.

Where the risk sits if you leave it manual

Effort and risk aren't the same axis, and this is where the fishing analogy matters - the busiest water isn't always where the biggest fish are.

Management of change carries the highest risk-of-gap of any VBS element when it's run manually. MOC is, by design, the element that catches deviations before they become incidents: a modified pipe spec, a substituted chemical, a changed operating procedure, a temporary bypass that becomes permanent. On paper or in a spreadsheet, MOC depends entirely on someone remembering to raise it, someone else remembering to review it, and a paper trail that's complete enough to prove the review happened. Any one of those steps quietly failing doesn't show up as a missing form - it shows up as an unreviewed change sitting live on site, invisible until an audit or, worse, an incident investigation asks where the MOC record is.

That asymmetry is the reason MOC deserves a digitization slot early even if its day-to-day volume looks lower than operational control's. A missed permit-to-work form is a paperwork gap. A missed MOC review is a hazard gap.

Sequencing the rollout without disrupting operations

Once you know where the effort sits and where the risk sits, sequencing becomes a practical question rather than a guessing game.

Start with one high-volume, low-ambiguity element. Operational control checklists are a common first move: the workflows are already well-defined on paper, the forms don't usually need much redesign, and the win is visible fast - less chasing paper, faster completion tracking. This also builds a track record with the field teams who'll need to trust the system for everything that comes after.

Bring management of change in early, deliberately, even though it's not the highest-volume element. Because MOC is where an unreviewed gap does the most damage, it shouldn't wait until "phase three." It can run as a parallel, smaller-scope rollout: digitizing the MOC request, review, and approval chain so nothing sits unactioned, without needing the same field-wide rollout that operational control requires.

Layer in audit and review once the first two are generating clean records. Audit and review benefits from having digitized operational control and MOC data to draw on - findings and corrective actions can link back to the actual records instead of being tracked separately. Sequencing it third means the audit trail has real data behind it from day one instead of retrofitting old paper records.

Leave lower-frequency elements - emergency planning, organisation and personnel, monitoring performance - for later phases, once the team has been through the adoption curve twice and knows what a rollout at your site actually takes: how long training takes, which shift patterns cause friction, which forms need redesigning versus a straight digital copy.

At every stage, the goal is the same one the fishing parable points at: match the approach to where the site actually is, not to whichever platform demo looked the most impressive. A Seveso site running mostly on paper doesn't need every Annex III element digitized in month one. It needs the one or two elements where manual effort or risk is highest, done properly, before the rest follow.

What this means in practice

If you're an EHS director planning a VBS digitization roadmap, the sequencing questions worth answering before you touch a tool are:

  • Which element generates the most paperwork volume day to day, and where do forms most often go missing or come back incomplete?
  • Which element, if a step gets silently skipped, creates the biggest hazard gap rather than just an administrative one?
  • Can this element be piloted with one team or one shift before going site-wide, or does it require a full rollout on day one?
  • Does the next element in the sequence depend on data from the one before it?

Answer those honestly for your own site and the order tends to declare itself: operational control or audit and review first for volume relief, management of change close behind for risk coverage, and the rest following once the team has proven the model works. That's where to fish first - not because the other elements don't matter, but because that's where the fish actually are.