Open Home Page

Critical Controls Only Work When They Actually Work

ICMM’s 2026 Critical Control Management update - what changed, what matters, and what to do about it.

JC
Jake Cole · Aug 4, 2026 · 1 min read

Key Insights

  • The 2026 ICMM update consolidates the good practice and implementation guides into a single resource and reframes critical control management (CCM) as an enterprise risk discipline, not just a safety program.
  • Verification is the central theme: controls fail not because they weren’t identified, but because no one confirmed they were still working in real conditions.
  • New maturity assessments and readiness tools help organisations honestly evaluate where their CCM program sits before investing further.
  • Leadership engagement is now an explicit expectation – CCM should appear in strategic risk registers and board-level conversations, not only in the safety function.
  • The update is relevant well beyond mining: any organisation managing high-consequence risk in shared-duty or multi-PCBU environments should take notice.

Most fatalities aren’t caused by hazards no one saw coming. They happen because a control that was supposed to be working simply wasn’t. That’s the gap ICMM critical control management is built to close, and it’s the gap the 2026 update is most concerned with.

In our experience, serious incidents rarely happen because the hazard was unknown. They happen because a critical control was missing, weakened, or simply not working as intended. That’s why critical controls matter so much. They direct attention to the controls that actually prevent fatalities, rather than treating every hazard on the register as equal.

At the most basic level, critical controls are the difference between people going home and people not. Everything else (the documentation, the verification, the governance architecture) is in service of that.

On 28 April 2026, the International Council on Mining and Metals (ICMM) released an updated Critical Control Management: Good Practice Guide. It’s worth a closer look. Not just for mining and metals operators, but for any organisation managing high-consequence risk.

What’s actually changed

This isn’t a reinvention. The familiar nine-step model, from planning through to evaluating and improving controls, is still there. What’s changed is the depth, the framing, and the practical tools wrapped around it.

Four shifts stand out…

  • One document, not two.
    The previous good practice and implementation guides have been consolidated into a single resource. For organisations starting out, or auditing an existing program, it removes the friction of working across two reference documents.
  • CCM is now framed as enterprise risk, not just safety.
    The update lifts ICMM critical control management out of the safety silo and into enterprise risk management, with explicit visibility in strategic risk registers. This matters because it pulls CCM into the conversations boards and executive teams are already having about catastrophic risk, rather than leaving it as a technical document that lives in the safety function.
  • Stronger direction on planning, governance, and leadership.
    New tools, including maturity assessments and readiness checks, give organisations a way to honestly evaluate where they sit before they start, and to track progress over time. This is a meaningful addition for organisations that have implemented CCM in name but never tested whether it’s actually working.
  • Sharper criteria for identification, implementation, and verification.
    The update tightens what counts as a critical control, what good implementation looks like, and what verification actually requires. This is where most CCM programs quietly fail. Teams identify controls, write them down, then verification slips: sporadic, unstructured, or done by people too close to the work to see the gaps.
2026/05/The-Critical-Control-Management-Process.png

Frequently asked questions

The 2026 edition consolidates the previous good practice and implementation guides into a single resource, reframes CCM as an enterprise risk discipline, introduces maturity assessments and readiness tools, and tightens the criteria for what counts as a critical control and what verification actually requires. It reflects a decade of member implementation experience since the original 2015 guide.

2025/11/cta-background.png Employees are demonstrating the AR/VR technology

Let's build something stronger together.

Whether you’re looking for strategic advisory, hands-on implementation, or practical tools your teams can use today, we’re here to help.

Want to keep up to date?

Subscribe to our newsletter to receive insightful content, event invites and special offers.

Fields marked with * are required.

"*" indicates required fields