Recordable rates keep improving while serious injury and fatality exposure doesn’t. Here’s why your best safety metric may be measuring luck, not control.
A falling TRIR tells you less than you think. Total recordable rates have improved across industry for years, yet serious injuries and fatalities have not fallen at anything like the same pace — many organizations drive recordables down while their exposure to a life-altering event stays exactly where it was. If your board deck shows a five-year downward TRIR trend and calls it risk reduction, there’s a real chance it’s measuring something closer to luck.
The conventional belief, inherited from the old safety pyramid logic: minor injuries and major injuries share causes, so grinding down the frequency of small events automatically shrinks the probability of catastrophic ones.
My counter-position in one sentence: serious injuries and fatalities have different precursors than everyday recordables, which means a program optimized for frequency can be — and often is — blind to severity.
Why doesn’t a falling TRIR mean falling fatality risk?
Because the two outcomes come from different failure modes. The everyday recordable — the laceration, the strain, the slip — is typically produced by routine variability: a moment of inattention, an awkward posture, a wet floor. The serious injury or fatality is typically produced by energy: stored, elevated, moving, pressurized, or electrical. Falls from height, mobile equipment strikes, machine entanglement during troubleshooting, hazardous energy released mid-maintenance, confined spaces, trench and structural collapses.
Those high-energy events don’t respond to the interventions that move TRIR. You can run engagement campaigns, tighten PPE compliance, and coach away the strains — and your lockout discipline during unplanned maintenance can be exactly as fragile as it was five years ago. The recordable count falls. The exposure stands.
This is why I treat the classic pyramids — Heinrich, Bird — with caution. The ratios were never a causal law, but they got used as one, and the operational consequence is a generation of programs that allocate attention by frequency instead of by energy.
“Frequency is where the data is. Energy is where the funerals are.”
A useful definition, stated plainly: SIF potential is any event or condition where, absent one fortunate variable, the realistic outcome was a fatality or a life-altering injury. The near-miss where the load swung past a head instead of through it. The recordable hand injury that happened eight feet from an unguarded shaft. Programs that don’t classify for SIF potential file both as minor events and learn nothing from either.
What does this have to do with LEAN?
Everything, because SIF exposure is fundamentally an operational-design problem, and LEAN is the discipline of operational design.
Walk any plant through a LEAN lens and ask where high-energy work actually happens. It’s almost never in the standard cycle — standard work is stable precisely because it’s been engineered. It’s in the exceptions: the jam being cleared, the changeover running late, the maintenance job that expanded once the guard came off, the forklift rerouted around a blocked aisle. SIF exposure lives in the gap between work-as-imagined and work-as-done, and that gap is widest exactly when production pressure is highest.
This is the Strategy–Execution Gap in its most dangerous form. The strategy layer of nearly every company says, in writing, that nothing matters more than preventing fatalities. The execution layer measures TRIR, bonuses on TRIR, and reviews TRIR at every operating meeting. The stated priority and the managed metric point at different things, and the organization always follows the metric. Nobody decided to deprioritize fatality prevention. The measurement system decided it for them.
The LEAN toolkit is also where the fix lives. Tiered daily management can escalate SIF-potential conditions with the same discipline it escalates downtime. Layered process audits can target the high-energy tasks — LOTO on unplanned work, elevated work, mobile equipment interfaces — instead of sampling whatever’s convenient. Standard work for maintenance exceptions, pre-task planning for non-routine jobs, and andon-style stop authority for line-of-fire conditions are all LEAN mechanics pointed at severity. Safety doesn’t need a parallel system. It needs the operating system you already run, aimed at energy.
Why should PE deal teams care?
Watch: The Diligence Gap Nobody Prices: Safety Exposure in Manufacturing M&A
Because TRIR is the metric that shows up in the data room, and it’s the one most capable of flattering a bad situation. A portfolio target with a 1.2 TRIR and no SIF-potential classification, weak energy-control discipline, and deferred guarding capex is carrying latent liability the recordable rate cannot see. One fatality reprices everything: the human cost first, then OSHA exposure, litigation, insurability, management distraction through the hold period, and the exit story.
In diligence, I’d trade the five-year TRIR trend for the answers to three questions: How does the company identify SIF-potential events? What were the last five, and what changed after each? And what does the maintenance backlog look like on guarding, energy isolation, and mobile equipment segregation? Those answers reveal the actual risk position. The TRIR chart reveals the marketing.
The steelman objection: “TRIR is what OSHA, customers, and carriers ask for — we can’t just abandon it.” Correct, and I’m not suggesting you do. Report TRIR; it’s the lingua franca and it does describe real harm. The argument is about internal management attention: what gets reviewed at the top of the house, what triggers escalation, and what leadership is paid on. Keep the scoreboard. Change what the coaches watch.
What should change on Monday?
Add a SIF-potential flag to your incident and near-miss process — a simple, honest yes/no answered by a defined energy-based criterion, not by outcome. Review every flagged event at the leadership tier within days, with the same seriousness as a lost-time injury, regardless of whether anyone was scratched. Point your next month of layered audits exclusively at your top three high-energy exposures. And in the next operating review, ask one question before the TRIR slide: “What almost killed someone this month?” The first time that question gets a real answer instead of silence, your program has started managing severity.
Key takeaways
- SIFs have different precursors than routine recordables — high-energy failure modes that frequency-focused programs don’t touch.
- A falling TRIR alongside flat SIF exposure is common: the program is winning the metric while the risk stands still.
- Classify SIF potential by energy and realistic worst outcome, not by what happened to result — the near-miss with fatal potential matters more than the recordable without it.
- SIF exposure concentrates in the gap between work-as-imagined and work-as-done. That makes it an operational-design problem, and LEAN mechanics are the native fix.
- For PE teams: TRIR in a data room can flatter latent liability. SIF-classification maturity and the energy-control maintenance backlog tell you the truth.


