See how AI and Critical Control Management help organisations analyse safety data, verify controls and make better-informed risk decisions.
.png)
.jpg)
For many organisations, the challenge in workplace safety is no longer simply collecting information. Incident reports are being submitted. Hazards are being recorded. Inspections are being completed. Risk assessments, actions, training records and control checks are generating more data every day.
The harder questions are becoming:
What is all of that information telling us?
Which risks deserve our attention first?
Are the controls protecting people from our most serious risks actually working?
And perhaps most importantly:
How quickly can we recognise when something is beginning to go wrong?
These questions are influencing how we think about the future of safety technology at myosh.
Two areas in particular have become an important part of that direction: Critical Control Management (CCM) and Artificial Intelligence. They solve different problems, but together they represent a shift from safety software being primarily a place to record what happened towards a system that can help organisations understand risk, verify important safeguards and make better use of the information they already collect.
The problem isn't necessarily a lack of safety data
Modern organisations can accumulate enormous amounts of safety information. A single incident may include classifications, descriptions, photographs, investigation findings, contributing factors, corrective actions and supporting documentation.
Multiply that across hazards, inspections, observations, risk assessments, audits, equipment and multiple sites, and the amount of information requiring review can become substantial.
More data does not automatically mean better risk management. Someone still needs to interpret it.
A recurring issue may be spread across hundreds of records. Important information may be buried in attachments or free-text descriptions. An incomplete incident investigation might look perfectly acceptable when viewed quickly. A gradual deterioration in the effectiveness of a control may not be obvious from a conventional lagging indicator.
The opportunity for safety technology is therefore not simply to capture more information. It is to make that information easier to understand and connect it more directly to the risks and controls that matter.
Critical Control Management asks a different question
Traditional risk management often involves identifying a hazard, assessing the risk and documenting a range of controls. Critical Control Management goes further by concentrating attention on the controls that are essential to preventing or mitigating events with potentially catastrophic consequences.
These are often referred to as Material Unwanted Events (MUEs).
The CCM approach provides organisations with a structured way to identify these events, determine the controls that are genuinely critical, define what those controls need to achieve, establish how their performance will be verified and assign accountability for ensuring they remain effective.
That distinction matters. A control being written in a risk assessment is not the same as knowing that the control is present, functioning and effective today.
Moving from documented controls to verified controls
This is where technology can fundamentally change the process.
Within myosh, Critical Control Management can be integrated with everyday activities such as workplace inspections and observations. Verification outcomes can automatically create or update critical-control records rather than requiring a separate administrative process.
For example, imagine an organisation has identified isolation as a critical control for a particular Material Unwanted Event. An inspection performed in the field can verify whether that control is working as intended. That result can then contribute to the current status of the control.
If a problem is identified, the system can trigger actions or notifications. The corresponding Digital Bowtie can also reflect changes in control status, giving people a visual indication that part of the organisation's protection against a serious event may have been weakened.
The result is a very different safety-management process.
Instead of asking:
“Do we have this control documented?”
the organisation can begin asking:
“What evidence do we have that this control is working?”
The Digital Bowtie makes risk easier to see
Bowtie analysis is particularly useful because it connects several concepts that are often managed separately. On one side are the threats or causes that could lead to an unwanted event. On the other are the possible consequences. Between them are the preventative and mitigating controls intended to stop the event occurring or reduce its impact.
myosh connects the Digital Bowtie with the underlying Critical Control Management records. Changes to controls can be synchronised between the CCM process and the Bowtie, while compromised control statuses can be reflected visually.
That makes the Bowtie more than a static diagram. It can become a view of an active risk-management process. Inspections can generate verification records, control status can change, notifications can be triggered, and dashboards can aggregate verification information across sites or organisational hierarchies.
For organisations managing high-consequence risks, this provides something particularly valuable: visibility of whether the barriers relied upon to prevent serious events are actually healthy.
Where AI changes the equation
Critical Control Management helps answer an important question:
Are the controls protecting us from our most serious risks working?
AI introduces another:
What can we learn from the information surrounding those risks?
Over the past 24 months, myosh has been developing AI capabilities directly within the platform. Importantly, the approach is not based around adding a generic chatbot beside the safety system. AI is being embedded into records, forms, dashboards, exports and risk-management workflows so it can assist users in the context of the work they are already performing.
That distinction becomes important when thinking about practical applications.
AI can help review the record in front of you
Consider an incident report.
A safety professional reviewing it might ask:
myosh AI Record Analysis can review the fields within an individual record together with attached PDFs or images, producing a summary and logical quality check.
That does not replace the investigation. It gives the person conducting the review another way of interrogating the information before making a decision. The distinction is important: AI can help find the question. A person still determines the answer.
AI can help find patterns across many records
The same principle becomes even more valuable as the volume of data increases. Imagine reviewing hundreds of incidents and asking:
What causes appear most frequently in these records, and are there recurring themes associated with manual handling?
That analysis may be possible manually, but it can require considerable time. AI analysis can instead be applied to exported groups of myosh records using instructions that specify what the organisation wants to understand. Scheduled exports can also be analysed to support recurring trend and anomaly identification.
This begins to move safety reporting beyond simply displaying counts.
A dashboard might tell you that incidents increased.
The next question is:
Why?
AI can also help interrogate the risk model itself
One of the more interesting areas is the intersection between AI and Bowtie analysis. A Bowtie can contain causes, controls and consequences developed by people with extensive operational knowledge. But Bowties can also become complicated.
Controls may be vague. Causes may overlap. Items may be incorrectly classified. Similar controls may have been described differently by different teams.
myosh AI can analyse existing Bowties and suggest improvements, including identifying duplicated causes, vague or potentially misclassified controls. AI can also work from source information such as images and PDFs when developing structured diagrams.
Conversational analysis adds another dimension.
Rather than performing a single review, a user can continue asking questions about the Bowtie—for example, examining the adequacy of a particular control or exploring part of the risk pathway in greater depth.
AI can also generate a first-draft Bowtie from a prompt, supporting material and operating context.
Again, the purpose is not to allow AI to determine how a serious safety risk should be managed. It is to give experienced people a stronger starting point for review.
From building documents to improving them
The same idea extends beyond Bowties.
AI capabilities within myosh can generate first drafts of Safe Work Method Statements, assist administrators in creating the initial structure and fields for new forms, and provide configurable AI-driven fields that can analyse selected information or attachments and return structured outputs.
The potential process improvement here is easy to underestimate. Consider the amount of safety work that involves establishing a first draft:
creating a form;
None of those activities eliminate the need for competent people. But reducing the time spent getting from a blank page to something useful gives those people more time to question, verify and improve the result.
The interesting part is what happens when AI and CCM meet
AI and Critical Control Management are valuable independently. Their greater potential becomes apparent when safety information, risk models and control verification exist inside the same connected environment.
Consider a simplified example.
An organisation has identified a Material Unwanted Event and mapped the relevant threats, preventative controls, mitigating controls and consequences in a Bowtie. Critical controls have been identified and verification requirements established. Workers then perform inspections and other operational activities.
Those activities produce verification data.
If a critical control is compromised, its status changes and relevant people can be notified.
Dashboards provide visibility of verification performance.
AI can then help users examine the surrounding information, identify trends across records, review individual reports, interrogate the Bowtie and help interpret dashboard information.
The important development is therefore not any single AI function or dashboard.
It is the connection between operational information and the organisation's risk model.
A practical example: when an inspection becomes more than an inspection
Imagine a high-risk operation where several critical controls protect workers from a serious vehicle interaction event. A conventional inspection might identify an issue and create a corrective action.
That is useful. But a connected system can potentially provide much more context.
That is where digital safety systems become much more powerful: individual records stop existing in isolation.
Dashboards should create questions, not just charts
Safety dashboards have traditionally been very effective at answering questions such as:
Those questions remain important.
But emerging AI capability creates an opportunity to ask more analytical questions of the information being displayed.
AI within the myosh dashboard experience is being developed to help users interpret graphs, explore likely contributing factors and identify possible actions or areas requiring further investigation.
The difference can be thought of as moving from:
“What does this chart show?”
towards:
“What might be driving what this chart shows?”
The answer still needs to be tested against operational reality. But helping people move more quickly from observation to investigation can make safety data considerably more useful.
Human judgement becomes more important, not less
There is an understandable concern that introducing AI into safety management could encourage organisations to outsource judgement to an algorithm.
That is not the approach myosh is taking.
The principle behind the AI capability is straightforward:
AI drafts, suggests and surfaces. People review and decide.
An AI-generated Bowtie is a draft.
An AI-generated SWMS is a draft.
An apparent incident trend is something to investigate.
A suggested control improvement is something to evaluate.
An AI summary of an incident is an aid to the reviewer—not the investigation itself. Safety decisions require knowledge of the task, workforce, equipment, environment and organisational context that cannot simply be delegated to a model. AI can reduce some of the effort required to find and organise information. Human expertise determines what that information means.
Governance has to be built in
Useful AI also requires more than simply connecting a language model to organisational data. Different organisations have different requirements concerning privacy, sensitive information, approved providers, access and acceptable uses of AI.
myosh therefore includes a central AI administration capability through which organisations can govern permitted models and providers, determine which AI capabilities are available, control access and configure individual functions. AI access can also be scoped so particular users or roles can use specified capabilities against appropriate data.
Features can be configured using prompts, checkboxes and other administrative settings rather than requiring custom code for every use case. That makes governance part of the architecture rather than an afterthought.
The bigger shift: from recording safety to understanding safety
Safety software will always need to perform the fundamentals well. Organisations need reliable records, they need workflows, inspections, actions, risk assessments, training records, reporting and evidence. myosh itself remains a configurable HSEQ platform with more than 50 modules that can work together across these processes.
But the next stage of safety technology is increasingly about what happens after the information enters the system.
This is where Critical Control Management and AI become particularly powerful. CCM creates a disciplined framework around the controls protecting an organisation from its most serious risks. AI provides new ways to interrogate, summarise and work with the information generated around those risks. Together, they create the possibility of a safety management system that does more than store evidence of safety activity.
It can help organisations understand what their data is saying, see whether their most important controls are working and direct human attention to the areas where it may matter most. That is a much more useful role for technology in safety.