Safety Management Systems: What a Seveso Site Has to Run
July 7, 2026
If you searched "safety management system," you're likely looking for one of two things: a general framework for managing workplace safety, or the specific system your site is legally required to have. If you operate a Seveso or BRZO-classified major-hazard establishment, it's the second one - and it already has a name.
In the Netherlands and across the EU, the safety management system required of Seveso sites is the VBS (veiligheidsbeheersysteem). "Safety management system" is simply the English-language term for the same thing. There's no separate SMS you need to build alongside your VBS, and no gap between the two concepts to bridge. If your site falls under Seveso III / BRZO, the SMS you're required to operate is the VBS, and it's defined in detail by Seveso III Annex III.
This article explains that connection, what the VBS actually covers, and how it differs from the generic SMS frameworks used outside high-hazard industry.
SMS and VBS: same requirement, two names
Outside the Seveso framework, "safety management system" is a broad, largely voluntary concept. Many industries - construction, manufacturing, logistics - run some version of an SMS because it's good practice: a structured way to manage risk, assign accountability, and respond to incidents. The shape of that system is up to the company. There's no single regulatory text that dictates its content.
That changes the moment your site is classified as Seveso (lower-tier or upper-tier) or, in Dutch terms, BRZO. At that point, "we should have a safety management system" becomes "we are legally required to operate a VBS with a specific set of elements, and we have to be able to demonstrate it during inspection."
The practical implication: if your team has been asked to "set up an SMS" and you're a Seveso site, you're not starting from a blank page. You're building - or documenting - your VBS. Using "SMS" and "VBS" as if they're two different projects tends to create duplicate documentation, unclear ownership, and confusion during audits about which document is authoritative. They should be one system, one set of documents, one owner.
What Seveso III Annex III actually requires
Seveso III Annex III sets out the elements a VBS must address. We've covered the full breakdown element-by-element in our EHS management system guide, so we won't re-explain all seven here - but at a high level, Annex III requires your VBS to cover:
- Organization and personnel - roles, responsibilities, authority, and training for major-accident prevention
- Identification and evaluation of major hazards - systematic assessment of what can go wrong and how severe it could be
- Operational control - procedures for safe operation, maintenance, and handling of hazardous processes
- Management of change - a defined process for assessing new installations, processes, or storage facilities before they go live
- Emergency planning - preparation for foreseeable emergency scenarios, tested and updated
- Performance monitoring - ongoing evaluation of whether major-accident prevention objectives are actually being met
- Audit and review - periodic, systematic assessment of the VBS itself, with management follow-up
None of this is optional structure you can adapt to taste. Regulators expect to see each of these elements addressed, documented, and - critically - actually operating, not just written down. A VBS that exists as a policy document nobody follows is treated the same as no VBS at all.
Where SMS software claims fall short for Seveso sites
A lot of "safety management system" software on the market is built for the generic version of SMS: incident reporting, risk assessment forms, a training log, maybe a corrective-action tracker. Useful tools, but they weren't designed against Annex III's structure, and they don't map cleanly onto what a Seveso inspector is actually checking for.
The gap shows up in a few recurring ways:
- Documentation scattered across formats. VBS material ends up spread across Word, Excel, PowerPoint, and PDF files that don't stay in sync with each other, making it hard to show a single, current version of "the VBS" during inspection.
- No structural link to the seven Annex III elements. Generic SMS tools organize around modules like "incidents" or "training," not around the regulatory categories an inspector will ask about.
- Audit and management-of-change trails that don't hold up. Annex III specifically requires audit and review as a standing element - not a one-time checklist, but a demonstrable, ongoing process.
How Capptions supports the VBS
Capptions' Seveso Control is built specifically around Annex III's structure rather than a generic safety framework. It's designed to bring VBS documentation into one place instead of fragmented files, support the PDCA (plan-do-check-act) cycle the audit-and-review element requires, and keep sites in an inspection-ready state rather than scrambling to assemble evidence when an inspector calls.
If your team is currently searching for "safety management system" software because you've been told to formalize your SMS, it's worth checking first whether what you actually need is VBS-specific tooling built around Seveso III Annex III - rather than a general-purpose EHS platform adapted after the fact.
The bottom line
If you operate a Seveso or BRZO site, stop treating "SMS" and "VBS" as separate initiatives. They're the same legal requirement, defined by Seveso III Annex III, covering the same seven elements. The question isn't whether you need an SMS in addition to your VBS - it's whether your VBS is complete, current, and able to withstand inspection. For the full breakdown of what each Annex III element requires, see our EHS management system guide.