Capptions
Back to blog

Risk, Compliance, Internal Control and the Management System

July 9, 2026

Organizations operating in safety-critical environments often talk about risk management, compliance, and internal control as separate domains. In practice, they are one system: the way an organization deliberately operates close to the boundaries of control.

For Seveso-classified sites, that system even has a legal name - the veiligheidsbeheersysteem (VBS) required under the EU Seveso III Directive 2012/18/EU. But the underlying model applies to any organization that runs real hazards for real returns. It starts with a shepherd.

The shepherd at the edge

It's early morning. Mist clings to the hills. A shepherd stands with his dog, watching a restless flock spread across the slope.

Behind them: safe, overgrazed land. Short grass. Predictable. Nothing goes wrong there - but nothing grows there either.

Ahead: the edge of a ravine. Not a dramatic cliff. Just a long, sloping drop where the ground becomes uncertain, and where, right along the rim, the grass turns impossibly green.

Every shepherd knows this place. That's where the best nourishment is. That's also where things go wrong.

He lets the flock drift forward. Not freely - never freely. The dog moves first: wide arcs, subtle pressure, keeping the edges tight, watching for the one sheep that wanders a little too far, a little too confidently.

The shepherd isn't trying to eliminate risk. He's managing distance. Too far back, and the flock weakens. Too close, and one misstep becomes a fall. So he constantly adjusts - a whistle here, a shift in position there, a sharper correction when needed. And always, in the back of his mind, a question he never fully answers: how much loss is acceptable if it means the flock thrives?

Absolute safety would mean turning away from the edge entirely. So he walks the line - not recklessly, not passively, but deliberately.

Risk: not only what to avoid, but where to go

Risk is usually framed as something negative. In reality it has two sides:

  • Downside: incidents, non-compliance, financial loss, reputational damage
  • Upside: efficiency, innovation, better use of assets, competitive advantage

Every organization continuously balances these forces. Operating too conservatively means missed opportunities. Operating too aggressively increases the chance of failure. The real question is: how close do we choose to operate to the edge, and what level of loss is acceptable if control fails?

Risk appetite: a strategic choice

This balance is defined through risk appetite. Leadership determines which risks are acceptable, which must be reduced or eliminated, and which are worth taking - or even amplifying.

This is not a purely technical decision. It reflects the experience and judgment of decision-makers, organizational culture, financial resilience, and external responsibilities - which weigh heaviest in high-hazard industries, where the downside extends beyond the fence line.

Two companies under identical regulations can behave very differently because their risk appetite differs.

The management system: the organization's playbook

The management system is where these choices are formalized. It consists of policies, procedures, roles and responsibilities, and operational rules. It answers one question: "Given our risks and our ambitions, how do we run this organization?"

It sits at the center of everything. Above it: laws, regulations, and standards. Below it: daily operations and execution. And it serves two purposes - translation (turning external requirements into internal rules) and reference (defining how performance is judged).

For a Seveso site, this layer is not optional. The VBS mandated by Annex III of the directive prescribes exactly what the playbook must cover: organization and personnel, identification and evaluation of major hazards, operational control, management of change, planning for emergencies, monitoring performance, and audit and review. Seven elements - and together they are precisely the organization's own statement of how it intends to remain in control.

Compliance: aligning with external expectations

Compliance ensures the management system correctly reflects applicable laws and regulations, industry standards, and permit conditions and obligations.

It answers: "Does our playbook meet what is required of us?" If this alignment is wrong, the organization is at risk of non-compliance by design - a VBS that would fail inspection even if everyone followed it perfectly.

ICS: proving control in practice

The Internal Control System (ICS) translates the management system into execution. It defines controls, workflows, checks and balances, and evidence collection.

It answers: "Are we actually doing what we said we would do?" This is where inspections, approvals, monitoring, and logging live. If this layer fails, the organization faces non-compliance in practice - a playbook that looks fine on paper and doesn't run on the ground.

Two fundamental gaps

Every organization must actively manage two types of gaps:

  1. Between regulations and the management system. Requirements are misunderstood, incomplete, or outdated. Result: the organization is structurally misaligned with its obligations.
  2. Between the management system and operations. Procedures aren't followed, controls are inconsistently applied, evidence is missing or unreliable. Result: the organization cannot demonstrate control.

When regulators like DCMR or the Nederlandse Arbeidsinspectie inspect a Seveso site, both gaps are on the table. They check whether the VBS covers what it must - and whether the site can prove it actually operates that way.

Closing the loop: Plan – Do – Check – Act

What inspectors and auditors ultimately expect is not documentation, but a functioning system. That system follows the Plan–Do–Check–Act (PDCA) cycle:

  • Plan: identify risks, define policies, procedures, and controls, align with regulations
  • Do: execute operations and controls, capture evidence
  • Check: assess whether controls work as intended, identify deviations and incidents
  • Act: implement corrective measures, improve controls and procedures, reassess risks

This is also where the last two VBS elements - monitoring performance, and audit and review - earn their place: they are the Check and Act of the whole system. The cycle becomes especially critical after incidents, where organizations must demonstrate not only what happened, but how their system responded.

Liability: where systems become personal

In regulated, high-hazard environments, this system connects directly to accountability. When failures occur, the questions are predictable: Were risks properly identified and assessed? Was the management system adequate? Were controls defined and implemented? Was execution consistent and verifiable? Were deviations detected and addressed?

These questions underpin organizational liability, personal liability of directors and management, and the responsibilities of specific safety and compliance roles. In other words: the integrity of the entire system becomes legally relevant.

One coherent model

Bringing it together:

  • Risk management defines direction and priorities
  • Risk appetite determines how far the organization is willing to go
  • The management system defines how the organization operates
  • Compliance ensures alignment with external requirements
  • ICS ensures execution and evidence

In practice they form a continuous loop: risk → management system → controls → evidence → insight → risk. The loop follows the PDCA rhythm: risks and choices are defined, translated into controls and executed, verified through evidence and insight, and adjusted through improvement and renewed risk evaluation. Only when this cycle is actively closed does the model move from documentation to real control.

The real challenge

Most organizations already have all these elements. The challenge is that they are fragmented across departments, document-driven rather than execution-driven, difficult to monitor in real time, and hard to keep aligned with changing requirements.

For Seveso sites, that fragmentation is exactly where generic safety management tooling falls short: the VBS demands one connected system across all seven elements, not seven separate document sets.

A final thought: are we in control?

Control is not achieved by writing more procedures. It is achieved when risks are clearly understood, choices are explicitly made, rules are consistently applied, evidence is continuously available, and gaps are systematically closed.

Or, simply put: risk defines where you operate. The management system defines how you operate. Compliance defines what is expected. ICS proves that you are in control.

The real work lies in continuously aligning all four.