
The Best Safety Question: Why 'What Could Go Wrong?' Outperforms All Others in High-Risk Industries
Why One Question Outperforms Every Safety Checklist
Ask 100 safety professionals what the single most effective safety intervention is, and you’ll hear about lockout/tagout procedures, fall protection harnesses rated to 5,000 lbs (2,268 kg), or AI-powered hazard detection cameras. But peer-reviewed data from the National Institute for Occupational Safety and Health (NIOSH), Chevron’s internal safety analytics, and a 2023 Johns Hopkins Medicine study converge on a startling insight: the highest-impact safety tool isn’t hardware or software—it’s a question. Specifically, 'What could go wrong?' asked before work begins, in the right way, at the right time. Unlike prescriptive checklists—which miss 68% of emergent hazards according to a 2022 OSHA review—this question activates anticipatory cognition, surfaces latent organizational assumptions, and increases hazard identification accuracy by up to 53% in field crews. This article details why this question works, how leading organizations deploy it, and what happens when it’s misapplied.
The Cognitive Science Behind Anticipatory Inquiry
Human brains default to pattern matching—not prediction. When workers follow rigid procedures, they engage 'habitual mode' processing, which operates at ~120 ms per decision but suppresses novelty detection. In contrast, 'What could go wrong?' triggers 'prospective mode'—a neurocognitive state linked to increased activity in the anterior cingulate cortex and dorsolateral prefrontal cortex, as confirmed by fMRI studies at MIT’s Human Factors Lab. This shift forces mental simulation of failure modes, activating memory traces of past incidents and near-misses. A 2021 study published in Journal of Safety Research tracked 417 frontline workers across 12 U.S. refineries and found those who verbalized three or more 'what could go wrong' scenarios before shift start had a 42% lower near-miss rate over six months compared to control groups using only JSA (Job Safety Analysis) forms.
How It Differs From Traditional Risk Assessment Tools
Traditional tools like HAZOP (Hazard and Operability Study) or Bowtie analysis require trained facilitators, take 4–8 hours per process node, and are typically applied annually. 'What could go wrong?' requires no certification, takes under 90 seconds, and is repeatable before every task—even micro-tasks like changing a lightbulb in a Class I, Division 1 hazardous location. Crucially, it bypasses the 'normalization of deviance' trap: when teams repeatedly skip steps because 'nothing’s happened yet,' this question reintroduces uncertainty as a feature—not a bug—of safe operations.
The Psychological Safety Threshold
Google’s Project Aristotle identified psychological safety as the #1 predictor of team effectiveness—and safety outcomes are no exception. Asking 'What could go wrong?' fails catastrophically if workers fear blame. At DuPont, post-incident analysis of a 2019 ammonium nitrate handling event revealed that 83% of crew members had privately identified the hazard (inadequate ventilation during transfer) but remained silent because supervisors had previously dismissed similar concerns as 'overcautious.' Only after implementing mandatory 'no-blame framing' training—requiring leaders to respond to every 'what could go wrong' with 'Thank you—let’s mitigate that'—did reporting rates climb from 1.2 to 3.4 incidents per 100,000 work hours.
Real-World Deployment: How Industry Leaders Scale the Question
Alaska Airlines pioneered structured deployment of 'What could go wrong?' in 2015 across its maintenance hangars. Mechanics now begin every task—including routine engine inspections—with a standardized 3-minute huddle. Each team member must voice one unique scenario. If duplicates occur, the group explores *why* multiple people saw the same risk (indicating systemic exposure) or *why* no new risks emerged (suggesting cognitive fatigue or complacency). Over five years, Alaska reduced maintenance-related ground incidents by 37%, outperforming the industry average reduction of 12% (FAA 2020–2024 Safety Statistics).
Healthcare: Preventing 'Never Events' in Surgery
At Cleveland Clinic, surgical teams adopted 'What could go wrong?' as part of their pre-incision pause—replacing the WHO Surgical Safety Checklist’s static questions. Nurses, anesthesiologists, and surgeons each contribute one scenario related to patient positioning, equipment function, or communication breakdowns. Between 2018–2023, Cleveland Clinic recorded zero retained surgical items—a 'never event'—while national benchmarks show 1,500+ such cases annually (AHRQ 2023). Their analysis attributed 64% of prevented errors to scenarios surfaced *only* through this open question, not checklist items.
Construction: Mitigating Fall Hazards on Dynamic Sites
Skanska USA implemented 'What could go wrong?' huddles before every scaffold erection, crane lift, and trench entry. Crucially, they required specificity: answers couldn’t be vague ('fall from height') but had to name exact conditions ('unsecured toe board at Grid C-7, 22 ft elevation, wind gusts >25 mph'). Field supervisors used tablets to log responses in real time, feeding data into predictive analytics. In 2022, Skanska’s Midwest division achieved 1.8 million man-hours without a lost-time injury—beating the U.S. construction industry average of 2.7 injuries per 100 full-time workers (BLS 2023).
Measuring What Matters: Quantifying Impact Beyond Lagging Indicators
Most safety programs fixate on lagging indicators: TRIR (Total Recordable Incident Rate), DART (Days Away, Restricted, or Transferred), and fatalities. But 'What could go wrong?' generates leading indicators with proven correlation to outcomes. At ExxonMobil’s Baton Rouge refinery, analysts tracked three metrics alongside incident data:
- Average number of unique scenarios voiced per pre-work huddle (baseline: 1.4 → post-intervention: 3.1)
- Percentage of huddles where at least one scenario involved human factors (e.g., 'fatigue during night shift handover')—increased from 22% to 68%
- Time between scenario identification and mitigation action (median dropped from 47 hours to 3.2 hours)
These leading metrics predicted a 37% reduction in process safety events (PSEs) six months before OSHA logs reflected the change. The refinery sustained zero PSEs for 18 consecutive months—the longest streak in its 112-year history.
The Four Deadly Misapplications (And How to Avoid Them)
Despite overwhelming evidence, 'What could go wrong?' backfires when poorly executed. NIOSH reviewed 27 failed implementations between 2019–2023 and identified four recurring patterns:
- Ritualization: Teams recite canned answers ('slip on oil', 'electrocution') without contextualizing to the specific task, location, or conditions. At a Ford assembly plant, this led to 89% of huddles generating identical responses—rendering the exercise meaningless.
- Authority Bias: Supervisors answer first, anchoring group thinking. In a 2022 Caterpillar excavation crew study, when leads spoke before others, 73% of subsequent responses mirrored their phrasing—even when technically inaccurate.
- Single-Point Framing: Focusing only on physical hazards while ignoring procedural, cultural, or temporal risks (e.g., 'What could go wrong during the 3 a.m. handover?'). A Texas hospital ER reported a 400% spike in medication errors after eliminating 'timing-based' scenarios from huddles.
- No Follow-Through: Identifying risks without assigning owners, timelines, or verification. At a Georgia power plant, 92% of 'what could go wrong' items lacked mitigation tracking—creating illusion of control without safety improvement.
Best Practices for Authentic Implementation
Effective use demands structure, not rigidity. Shell’s global 'Stop, Think, Act' protocol requires:
- Every worker contributes one scenario—no exceptions
- No scenario is accepted without specifying location, timing, and triggering condition (e.g., 'At Pump P-42B, during 3rd shift calibration, if pressure sensor reads >120 psi')
- Each scenario triggers a 'Who/By When/How Verified' commitment logged in the company’s EHS platform
- Supervisors receive monthly reports on scenario diversity scores—low scores trigger coaching, not discipline
Data-Driven Validation: What the Numbers Reveal
A 2024 meta-analysis published in Safety Science aggregated data from 43 organizations across 11 countries, representing 1.2 billion work hours. Key findings:
| Industry Sector | Average Reduction in TRIR | Median Time to Sustain Zero Lost-Time Incidents | Reporting Rate Increase for Near-Misses | Key Implementation Factor |
|---|---|---|---|---|
| Oil & Gas (Upstream) | 29% | 14 months | 210% | Integration with permit-to-work systems |
| Aviation Maintenance | 37% | 22 months | 185% | Mandatory cross-role participation (mech + inspector + planner) |
| Hospital Surgery | 44% | 19 months | 320% | Non-punitive response protocol enforced top-down |
| Commercial Construction | 22% | 11 months | 145% | Mobile logging with geo-tagged photos of mitigation actions |
The analysis confirmed that success hinges less on frequency than on fidelity: teams achieving >3.0 unique scenarios per huddle saw 2.8× higher near-miss reporting and 5.1× faster mitigation cycle times versus teams averaging <1.5 scenarios. Critically, organizations measuring scenario *quality*—using rubrics scoring specificity, timeliness, and mitigatability—outperformed those measuring only quantity by 63% in TRIR reduction.
Building a Culture Where Uncertainty Is Welcome
Culture isn’t changed by posters or slogans—it’s reshaped by repeated, reinforced behaviors. At Ørsted’s offshore wind farms, 'What could go wrong?' is embedded in every transition: before boarding service vessels, before turbine blade inspections, even before coffee breaks on the platform. New hires undergo 'Uncertainty Immersion Training'—spending 4 hours simulating high-consequence failures with no solutions provided, solely practicing articulation of failure pathways. Within 90 days, new employees contribute 3.7 scenarios per huddle—matching veteran averages. Leadership modeling is non-negotiable: Ørsted’s CEO personally hosts quarterly 'What could go wrong?' sessions with frontline teams, recording all responses in a public dashboard updated in real time.
This cultural integration explains why Ørsted achieved zero fatalities across 27 offshore projects totaling 14.3 million work hours between 2020–2023—while the global offshore wind industry average stood at 0.8 fatalities per million hours (International Renewable Energy Agency, 2023). As Ørsted’s Global HSE Director stated bluntly: 'We don’t trust procedures. We trust people who’ve practiced imagining failure.'
The question’s power lies in its humility. It acknowledges that no procedure, no algorithm, no AI system can anticipate every variable in complex socio-technical systems. Humans remain the best anomaly detectors—but only when invited to speak uncertainty without penalty. That invitation starts with two words: 'What could...'
Organizations clinging to compliance-driven safety miss this fundamental truth: regulatory adherence prevents known failures; anticipatory inquiry prevents unknown ones. When BP’s Texas City refinery exploded in 2005, investigators found 28 documented 'what could go wrong' scenarios in prior audits—all unaddressed. Contrast that with TotalEnergies’ Le Havre refinery, which implemented daily 'What could go wrong?' huddles in 2016. By 2023, it recorded zero process safety events despite handling 12.4 million tons of crude annually—the equivalent of 3.2 fully loaded supertankers every day.
Measurement matters. Don’t track how many huddles occurred. Track how many unique, specific, mitigated scenarios were generated—and whether the person who voiced them felt safer speaking up tomorrow. At Siemens Energy, this shift in KPIs correlated with a 49% drop in contractor-reported safety concerns being escalated to senior leadership—because issues were resolved locally, immediately, and visibly.
Technology supports but doesn’t replace the question. Honeywell’s Forge EHS platform now includes an AI co-pilot that analyzes huddle transcripts, flags low-diversity patterns, and suggests contextual prompts ('Consider weather impact on crane ops today'). But the system’s terms of service explicitly prohibit auto-generating scenarios—'human imagination remains irreplaceable,' states Honeywell’s 2024 EHS Policy Directive.
Finally, recognize that 'What could go wrong?' is not a tactic—it’s a philosophy. It rejects the myth of perfect control. It embraces the reality that safety emerges from continuous, collective sense-making. When a nurse in a Tokyo ICU says, 'What could go wrong if we administer this dose 17 minutes before the next vitals check?'—and her colleague responds, 'The monitor alarm might mute during defibrillator testing'—that exchange embodies resilience engineering in action. No checklist captures that interaction. No audit verifies it. Yet it prevents harm.
So ask it. Insist on specificity. Protect the speaker. Act on the answer. Then ask again—before the next task, the next shift, the next decision. Because the best safety question isn’t about avoiding failure. It’s about building the capacity to imagine it, name it, and dismantle it—before it arrives.









