You identify unsafe behavior in two steps, and almost every guide on this subject only does the first. Step one is seeing the act: the shortcut, the missing glove, the guard swung open. Step two is working out which kind of human failure produced it, because a slip, a mistake and a deliberate shortcut look identical from twenty metres away and need three completely different fixes. Get step two wrong and you will run a training course to solve a problem training cannot touch.
This guide covers what to look for, how to classify it, where and when to look, and what the law expects in the US, the UK, Ireland and internationally. I have spent 15 years doing this across 14 countries and 170+ workplaces, most of it on night shift, and the classification step is where I see programmes fail.
Key takeaways
The six points below are what the rest of this article defends. If you read nothing else, read these.
- Seeing an unsafe act tells you almost nothing about its cause. The same observable behavior can be a slip, a mistake, or a deliberate shortcut, and each needs a different control.
- The UK Health and Safety Executive splits human failure into errors (unintended) and violations (deliberate deviations). Errors divide further into slips, lapses and mistakes.
- Training does not fix slips and lapses. HSE states this plainly. Better task and equipment design does.
- The behaviors you can see on a walkabout are the visible minority. Omitted steps, wrong plans and defeated interlocks are found by asking and by reading physical evidence, not by watching.
- Day-shift-only observation samples the safest hours of the week. Nights, handovers, changeovers and contractor peaks are where the behavior lives.
- Under 29 CFR 1904.35(b)(1)(i), a US employer's injury reporting procedure is not reasonable if it would deter or discourage a reasonable employee from reporting accurately. Programmes that punish reporting destroy the data they depend on.
Unsafe behavior, defined against what you can actually see
Unsafe behavior is any action or omission by a person that raises the chance of harm, whether or not it breaks a written rule. That definition matters because a lot of what I write up is not a rule breach at all: it is a person doing exactly what the procedure says, where the procedure is wrong.
Two terms get muddled constantly. An unsafe act is what the person does. An unsafe condition is what the workplace presents. They are not independent. In my experience the act is usually the downstream symptom of a condition somebody chose to leave in place. Record the act without the condition that produced it and you have logged a symptom, then called it a cause.
The harder problem is visibility. A walkabout is good at catching behavior that has a physical signature: no gloves, a body inside a barrier, a guard open. It is close to useless at catching a person who forgot step 7 of an 11-step isolation, or who is confidently following a method that has been wrong since the line was rebuilt. Those failures produce no visible signature at all until something breaks.
The table below is how I split what an observation round realistically catches from what it does not.
| What you are looking at | A walkabout catches it? | How you actually find it |
|---|---|---|
| PPE not worn or worn wrong | Yes, easily | Direct observation |
| Person inside an exclusion zone | Yes | Direct observation |
| Guard removed, interlock defeated | Usually | Observation plus equipment inspection |
| Step omitted from a procedure | No | Ask the person to walk you through the task |
| Wrong plan followed confidently | No | Compare the method used against the current procedure |
| Fatigue-driven degradation | No | Roster, overtime and workload data |
| Behavior that stops when you appear | No | Physical traces left behind: worn paths, tape, wedges |
Before you design any observation programme, decide honestly which of these rows you are trying to cover, because a PPE-heavy checklist covers the top three rows and reports near-perfect compliance while the bottom four go unexamined.
The categories worth building your detection around are:
- Visible acts — anything with a physical signature, caught by direct observation
- Invisible omissions — missed or reordered steps, found only by questioning
- Wrong plans — the person is competent and compliant, and the method is out of date
- Conditional behavior — what people do when nobody is standing there
- Degraded performance — fatigue, workload and time pressure, visible in data before it is visible on the floor

Classify the failure before you choose the fix
This is the step that decides whether your corrective action does anything. The HSE's guidance on managing human failures draws the line at intention: an error is an action or decision that was not intended, a violation is a deliberate deviation from a rule or procedure. The fuller treatment sits in HSG48, Reducing error and influencing behaviour.
You cannot make this call by watching. You make it by asking two questions at the point of work: what did you intend to do? and what stopped you doing it? Thirty seconds of conversation separates categories that a checklist tick will merge forever.
Slips and lapses: the failures training will not fix
Slips are actions that did not go as planned. Lapses are memory failures, typically a missed step. Both happen on familiar tasks performed without much conscious attention, and they happen to the most experienced people you have. HSE is direct on this point: these cannot be eliminated by training, and improved design is what reduces them.
On a substation outage with ESB in Ireland, I overheard a clearance confirmation being rushed, and a required switching check went past unspoken. Nobody had decided to skip it. The sequence had been compressed because the outage window was closing, and a step that lives in someone's head rather than on a card is the first thing to disappear under time pressure. I stopped the sequence, restarted the switching order step by step, and coached the crew through it.
The lesson is about where the check lived, not about the crew. Outage pressure is exactly when switching discipline matters, and a verbal confirm with no physical prompt is a lapse waiting for a bad day.
Mistakes: the plan itself is wrong
A mistake is an error of judgement. The person carries out their intention correctly, and the intention was wrong. HSE separates these from violations for a reason: the person believed they were working safely, so discipline changes nothing and better procedures change everything.
In an assembly cell on the Boston Scientific Minnesota campus, I watched a solvent wipe-down being done in gloves that were incompatible with the solvent blend named on the safety data sheet. The operator was not cutting a corner. He was using the glove the job had always used, and the blend had changed. I stopped the task, matched the PPE to the SDS, and ran a short matching drill on the line.
Had I logged that as a violation, the record would have said "wrong PPE" and the fix would have been a reminder. The actual fix was rebuilding the link between an SDS change and the glove on the shelf.
Routine violations: the shortcut everyone takes
Routine violations are shortcuts that have become the normal way of working, usually because the compliant route is slower, longer or harder and nobody has fixed that.
At 02:00 in the packaging hall at Midleton, I walked a shortcut that agency packers had worn across an active forklift aisle. It was visible in the floor: the tape was scuffed through and there was a track. That is what a routine violation looks like when nobody is watching, and it had been forming for weeks. I closed the shortcut, reinstated the lit walkway, and briefed shift leads before the next inbound surge.
Fatigue plus a shorter walk creates desire paths, and desire paths injure people. Coaching the packers would have achieved nothing while the compliant route stayed the long way round in the dark.
Situational violations: the job forced it
Situational violations happen when the task as designed cannot be completed by following the rule. The person is not choosing risk over compliance; they are choosing between two impossible options.
On a corrugator line at Smurfit Kappa in Ireland, I saw a nip guard lifted to clear a jam with the line still capable of motion. The operator's alternative was a full isolation for a thirty-second clear, on a line that jammed several times a shift. I stopped the task, reinstated the guard, and coached jam clearing under isolation. The durable fix was upstream: reduce the jam rate and make isolation fast enough that nobody has to choose.
Here is the classification table I use in the field. The right-hand column is the one people skip.
| Failure type | What you observe | What works | What does not work |
|---|---|---|---|
| Slip | Wrong action in a familiar task | Task and interface redesign, physical prompts | Retraining an already-trained person |
| Lapse | A step missed or reordered | Checklists, forced sequence, error-tolerant design | Telling people to concentrate |
| Mistake (rule-based) | A wrong but confident method | Correct, current, accessible procedures | Discipline |
| Mistake (knowledge-based) | Improvising in a novel situation | Training on good procedures, competence assurance | Discipline |
| Routine violation | An established shortcut | Remove the reason: fix the compliant route | Coaching alone |
| Situational violation | A rule broken to finish the job | Redesign the task; make compliance possible | Enforcement |
Source for the error and violation categories: HSE, Managing human failures, linked at the top of this section.
Two questions at the point of work will place almost any behavior in that table:
- "What were you trying to do?" — an answer that matches the safe method points to a slip or lapse; an answer that describes a different method points to a mistake
- "What made the safe way harder?" — an answer naming time, distance, tooling or jam rate points to a situational violation rather than a choice

Six methods that surface unsafe behavior, ranked by what they catch
Most articles list five detection methods and treat them as interchangeable. They are not. Each catches a different slice, and the two that catch the most are the two nobody runs.
Structured observation at the work face
Observation earns its place for visible acts, and only if it happens where the work is rather than at the access point. Use a short checklist built from the actual critical risks on that task, not a generic PPE list. Record the condition alongside the act every time.
Asking the person to walk you through the task
This is the highest-yield method I know and it costs three minutes. Stand at the job and ask the operator to describe what they are about to do, in order. Omitted steps, out-of-date methods and misunderstood rules surface immediately, and none of them would have appeared in an observation. Ask about the last time the task went wrong, and ask what makes the safe way slower.
Reading the physical evidence
Behavior leaves traces. Worn shortcuts across marked aisles, tape scuffed through, wedged doors, taped-over sensors, a guard fastener that turns too easily, gloves stored somewhere other than the point of use. Traces record what happens when nobody is present, which is the behavior you most need and least often see.
Roster, overtime and workload data
Fatigue shows up in numbers before it shows up in incidents. Reviewing roster data across a night packaging operation for Diageo, with Scottish site interfaces, I found high-risk forklift roles stacked with overtime beyond the fatigue thresholds the site had set for itself. Nobody observed anything unsafe that week. The exposure was in the roster. I challenged the overtime stack, reset the roster window, and briefed supervisors.
Fatigue is a system design problem, not a personal weakness, and it is the one performance influencing factor you can audit from a desk.
Near-miss, hazard and stop-work reports
Reports are the only method that reaches behavior you will never be present for. Their value depends entirely on whether reporting is safe, which is covered in the legal section below and in the failure modes at the end.
Post-change and post-restart verification
Behavior degrades right after a change: a modification, a new product, a changeover, a restart after a fault. On an assembly line at the Boston Scientific Costa Rica campus, an andon was pulled for a safeguard fault and production restarted without anyone verifying the fix. I stopped the line, verified the safeguard, and reset the restart authority rules. Check behavior in the hour after a change, not in the quiet week that follows.
If you are building a programme from nothing, run them in this order of return on effort:
- Walk-me-through questioning, added to whatever observation you already do
- Physical evidence, which costs nothing but a change in what you look at
- Post-change verification, targeted at modifications and restarts
- Roster and workload review, monthly and before every production peak
- Structured observation, rebuilt around critical risks rather than PPE
- Reporting, which needs the trust conditions in the final section before it yields anything
The six methods, and what each is genuinely good for:
| Method | Catches | Misses | Realistic frequency |
|---|---|---|---|
| Structured observation | Visible acts, conditions | Omissions, wrong plans | Weekly per area |
| Walk-me-through questioning | Lapses, mistakes, rule confusion | Deliberate concealment | Every observation round |
| Physical evidence | Unobserved routine violations | Intent behind the behavior | Continuous, on every walk |
| Roster and workload data | Fatigue, time pressure | Everything task-specific | Monthly, and before peaks |
| Reports and near misses | Behavior nobody witnessed | Anything people fear reporting | Continuous |
| Post-change verification | Degradation after modification | Steady-state drift | Every change and restart |

Where and when to look: the sampling problem nobody audits
You can run a technically perfect observation programme and still see almost nothing, because you sampled the safest hours of the week. This is the single most common structural fault I find in mature programmes, and it never appears in the programme's own metrics.
Comparing day and night findings during a fab assignment at Leixlip, I found that leadership walks were almost entirely a day-shift activity. Night shift ran with lower supervision, thinner support, and the same production targets. I scheduled night walkabouts with leaders and tracked finding closure. Findings rose sharply at first, which is what success looks like at that stage, and then recurring issues declined.
If leaders never see night work, they manage half the risk and report on the wrong half.
The windows where unsafe behavior concentrates, and where I deliberately sample:
- Night shift, particularly 01:00 to 04:00 — lowest alertness, thinnest supervision
- Shift handover — information loss, and the point where half-finished work changes owner
- Changeovers and jam clearing — the moments guards come off
- Turnarounds and outages — unfamiliar crews, compressed windows, peak contractor density
- The hour after any change or restart — verification is skipped under schedule pressure
- End of a long overtime run — check the roster first, then go and look

What the law requires in the US, UK, Ireland and internationally
No jurisdiction has a standard called "identify unsafe behavior". The duty arrives through risk assessment, through the general duty to provide safe work, and through the rules protecting the reporting channels you depend on for detection.
United States
Section 5(a)(1) of the OSH Act, the general duty clause, requires employers to furnish employment and a place of employment free from recognised hazards likely to cause death or serious physical harm. Behavior-related hazards are covered where they are recognised and where a feasible means of abatement exists.
More directly relevant to detection is 29 CFR 1904.35. Paragraph (b)(1)(i) requires a reasonable procedure for employees to report work-related injuries and illnesses. It states that a procedure is not reasonable if it would deter or discourage a reasonable employee from reporting accurately. Paragraph (b)(1)(iv) prohibits discrimination against an employee for reporting. OSHA's interpretation of those paragraphs addresses discipline, post-accident drug testing and incentive programmes as potential routes to retaliation.
United Kingdom
Regulation 3 of the Management of Health and Safety at Work Regulations 1999 requires a suitable and sufficient assessment of risks. HSE's position is that human failure should be addressed within that assessment: identify the significant potential human errors, identify the performance influencing factors that make them more likely, and design controls accordingly. HSG48 is the guidance an inspector will expect you to have considered.
Ireland
Section 19 of the Safety, Health and Welfare at Work Act 2005 requires every employer to identify the hazards in the place of work, assess the risks, and hold a written risk assessment. The Health and Safety Authority sets out that duty in its guidance on safety statements and risk assessment. Section 20 carries the assessment into the safety statement and Section 26 requires consultation with employees, which is where behavioral findings should surface rather than sitting with the safety function. The HSA also publishes direct guidance on reducing errors and non-compliances, which is the closest regulator treatment of this topic on either island.
International
ISO 45001:2018 Clause 5.4 covers worker consultation and participation, which is the mechanism that makes reporting work. ISO 45003:2021 gives guidance on psychosocial risk, including workload, time pressure and fatigue, which are the performance influencing factors sitting behind most of the behavior discussed here.
Across all four, the duties that bear on identifying behavior reduce to three:
- Assess the risk, and include human failure within that assessment rather than alongside it
- Consult the workforce, because the people doing the task hold the information observation cannot reach
- Protect the reporting channel, since a deterred report is a hazard you never learn about
The comparison that matters for a multi-site operator:
| Jurisdiction | Instrument | What it requires | Source |
|---|---|---|---|
| US | OSH Act 5(a)(1) | Workplace free of recognised hazards | osha.gov |
| US | 29 CFR 1904.35(b)(1)(i) and (iv) | Reporting procedure that does not deter; no retaliation | osha.gov |
| UK | MHSWR 1999 Reg. 3 | Suitable and sufficient risk assessment, human failure included | legislation.gov.uk |
| UK | HSG48 | Error and violation taxonomy, performance influencing factors | hse.gov.uk |
| Ireland | SHWWA 2005 s.19, s.20, s.26 | Hazard identification, safety statement, consultation | hsa.ie |
| International | ISO 45001 Cl. 5.4; ISO 45003 | Worker participation; psychosocial risk guidance | iso.org |

The first five minutes after you see it
What you do immediately decides whether you ever see that behavior again. Handle it badly once and the person, their crew and the shift behind them will simply wait until you have gone.
My sequence is short and I do not vary it:
- Stop the work if there is immediate exposure. Nothing else matters until the person is out of the line of fire.
- Ask before telling. "Walk me through what you were about to do." You are gathering the classification, and you cannot get it any other way.
- Ask what made the safe way harder. This is the question that finds the situational violation and the broken procedure.
- Classify it against the error and violation table above, and write the classification down.
- Agree the immediate fix at the job, then log the systemic one separately. Those are two different actions with two different owners.
- Close the loop with the person. Tell them what changed. If nothing changed, tell them that too.
The record fields I insist on, because a record without them cannot be analysed later:
- The behavior, described as an observable action rather than a judgement
- The condition present at the time, including lighting, time, workload and staffing
- The failure type — slip, lapse, mistake, routine violation or situational violation
- What made the safe route harder, in the person's words
- Immediate action taken at the job
- Systemic action, with a named owner and a date
- No individual's name. Names turn an observation record into a disciplinary file, and the day that happens the record stops being true.

Four ways behavior programmes destroy their own signal
Every failure below produces improving numbers and worsening risk, which is why they survive audits.
"We hit our observation quota." Quotas produce paperwork, not observations. When a supervisor owes twenty cards by Friday, the cards get written from memory in the office on Thursday. If your observation volume is stable and your finding severity is falling, check whether people are submitting the easy ones to make the number.
"We disciplined the individual." Discipline is the correct response to a small set of behaviors, and it is the wrong response to slips, lapses and mistakes, where the person did not choose the outcome. Used broadly it teaches the workforce that being seen is the hazard. HSE's guidance is that getting to the root cause of a violation is what prevents it, and you cannot reach a root cause through a workforce that has stopped talking to you.
"Our incentive scheme rewards zero incidents." A bonus tied to an absence of recorded injuries pays people to stay quiet. OSHA does not prohibit safety incentive programmes, and says so plainly, but its interpretation of 29 CFR 1904.35(b)(1)(iv) treats withholding a benefit simply because an injury was reported as adverse action. The same interpretation encourages rewarding participation in safety training and the identification of unsafe conditions instead. Reward the reporting, not the silence.
"Compliance is in the high nineties." Check what the checklist measures. PPE, housekeeping and barriers are easy to observe and easy to score, so a checklist drifts toward them. A programme reporting near-perfect compliance on those items can be running alongside untouched isolation and permit failures.
The signals I look for when auditing a programme:
- Observation volume high, finding severity low and falling
- Almost all findings are PPE or housekeeping
- Near-miss reporting flat or declining while observation volume rises
- Corrective actions overwhelmingly "retrain" or "remind"
- No findings recorded from night shift, weekends or turnarounds
- Individual names appearing in observation records

Frequently asked questions
These are the questions I am asked most often after running this work on site, answered briefly. The detail sits in the sections above.
What is an example of unsafe behavior in the workplace?
Clearing a jam with the machine guard lifted, walking a shortcut across a live forklift aisle, skipping a step in an isolation sequence, or using a glove that does not match the chemical on the safety data sheet. The first two are visible on a walkabout. The last two are not, and are found by asking.
What is the difference between an unsafe act and an unsafe condition?
An unsafe act is what a person does; an unsafe condition is a hazard present in the workplace. They are linked. A blocked walkway is a condition, and the shortcut people take around it is the act. Recording only the act loses the cause.
What causes unsafe behavior at work?
HSE identifies performance influencing factors including poor design, distraction, time pressure, workload, competence, morale, noise and communication systems. Human failure is not random. Because those factors can be identified and assessed, the failures they produce can be predicted and managed rather than treated as carelessness.
Who is responsible for identifying unsafe behavior?
Legally the employer, through the risk assessment duty. Practically it is distributed: supervisors during work, workers through reporting, and the safety function through sampling and analysis. A programme that leaves detection solely with the safety function will only ever see the hours that function is present.
How often should safety observations be conducted?
Set frequency by risk, not by quota. Weekly structured observation per high-risk area is a reasonable baseline, with additional coverage at every change, restart, turnaround and night-shift peak. Frequency matters far less than whether the sample spans the hours where risk actually sits.
Can you discipline an employee for unsafe behavior?
Employers can discipline for genuine violations of legitimate safety rules. Discipline is the wrong tool for slips, lapses and mistakes, where the person did not intend the outcome. In the US, discipline applied because someone reported an injury raises an issue under 29 CFR 1904.35(b)(1)(iv).
What is a behavior-based safety observation?
A structured observation of a worker performing a task, scored against a checklist of defined behaviors, with feedback given at the time. It works for visible acts. Pair it with questioning and physical evidence, or it will report high compliance while missing omissions, wrong plans and fatigue.
Is it true that most accidents are caused by unsafe acts?
The frequently quoted 88% figure originates in H.W. Heinrich's Industrial Accident Prevention (1931) and its method has been widely questioned since. Heinrich himself traced unsafe acts back to management and supervisory faults. HSE's current position is that human failure contributes to almost all accidents, and that it is predictable and manageable rather than random.
About the author
Grace Thompson is an Irish Occupational Health, Safety and Environment (OHSE) Human Factors, Fatigue and Emergency Preparedness Consultant with 15 years of continuous field experience across 14 countries. She has led night-shift human factors and fatigue assurance work at Intel's Leixlip fab, roster and manual handling programmes across Diageo's packaging operations, and machine safeguarding and solvent control work at Boston Scientific sites in Galway, Minnesota and Costa Rica. Her focus is redesigning tasks and rosters so alert people can follow controls, and proving emergency arrangements work under real conditions. She currently leads Thompson Human Factors Safety in Dublin, after senior roles with Intel, Diageo, Glencore, Veolia, Skanska, Boston Scientific, Pfizer, Ericsson, Heidelberg Materials, Aer Lingus, ESB and Smurfit Kappa.
Credentials: Chartered Member of IOSH (CMIOSH), NEBOSH International Diploma in Occupational Health and Safety, ISO 45001 Lead Auditor, ISO 14001 Internal Auditor, Human Factors Awareness (CIEHF-aligned pathway), Fatigue Risk Management Awareness, Incident Investigation (ICAM or equivalent pathway), IOSH Managing Safely.
Sources and further reading
- HSE — Managing human failures: Overview
- HSE — HSG48, Reducing error and influencing behaviour
- legislation.gov.uk — MHSWR 1999, Regulation 3
- OSHA — 29 CFR 1904.35, Employee involvement
- OSHA — Interpretation of 1904.35(b)(1)(i) and (iv)
- OSHA — OSH Act Section 5, Duties
- Health and Safety Authority (Ireland) — Safety statement and risk assessment
- Health and Safety Authority (Ireland) — Reducing errors and non-compliances




























