Dropped Objects Awareness and Prevention
DROPS Audit Question Set
Draft DROPS guidance on self-assessment and auditing of a Dropped Object Prevention Scheme. Explains how to carry an assessment out, why it is structured as it is, and what it reaches that inspections and third-party surveys do not. Includes a question set covering the fourteen minimum requirements plus Human Performance.
Introduction
The DROPS Recommended Practice requires each company to evaluate its own Dropped Object Prevention Scheme. Section 2.6 states that each company evaluates its Scheme against the minimum guidelines in that document to identify gaps or areas for improvement, and section 5.2 places the same duty on a defined cycle. The obligation is therefore already established. What has not been established is a common method for discharging it well.
These guidelines set out how a company can assess its own Scheme: how to structure the assessment, how to judge what it finds, who in the organisation should be asked what, and how the result relates to the physical surveys and inspections the industry already performs. They include a question set covering the fourteen minimum requirements of the Recommended Practice, together with Human Performance.
These guidelines build on the Recommended Practice. They do not replace it, and nothing here overrides it. Where this document and the Recommended Practice appear to differ, the Recommended Practice governs.
This is a draft, issued for comment. Every question and every chapter carries its own discussion thread, and the purpose of publishing it in this state is to have it argued with before it settles. The question set is free to use and adapt with attribution to DROPS Forum.
Purpose and Scope
These guidelines are written for the person who has to answer the question how do we know our dropped object scheme is working? — whether that question came from inside the company, from a customer, or from the Recommended Practice itself.
They apply to any organisation with dropped object exposure, at any size. All themes apply to everyone they apply to; what scales with the organisation is the depth of the arrangements, not the list of things to be arranged. A two-person operation and a fleet operator answer the same questions and will properly arrive at different answers.
The Recommended Practice is written from a wells perspective. Members working in wind, marine, construction and production will find that one or two themes do not apply to them, and the scoping section exists to establish that before any assessment begins.
- How to assess a Dropped Object Prevention Scheme against the Recommended Practice.
- How to judge what an assessment finds, rather than merely record it.
- Which parts of an assessment the organisation can perform itself, and which it cannot.
- How an assessment relates to inspections and third-party surveys.
- A question set covering the fourteen minimum requirements and Human Performance.
- How to prevent dropped objects. That is the Recommended Practice and the DROPS guidance library.
- How to conduct a physical DROPS survey. That is covered by the DROPS Common Guidelines for Independent Dropped Object Surveys.
- Certification of any kind. Nothing in this document produces a credential, and DROPS Forum does not endorse the result of any self-assessment.
What a Survey Reaches, and What It Does Not
Most organisations with dropped object exposure already buy an independent survey. A competent surveyor attends, examines structures, equipment, machinery and ancillary items at height along with their primary, secondary and safety securing, and reports what is unsafe. That regime works, and the industry has the inspection record to show for it.
This chapter is about what a survey is not designed to reach. It is not a criticism of surveying, and none of what follows suggests that surveys are performed poorly. It describes a different task that the Recommended Practice asks for and that no existing method addresses.
3.1A survey examines equipment; a scheme is a system
A survey answers a question about physical condition: is this item secured, is that retention fitted, is this fixing sound. Those questions have determinate answers and a competent person can settle them by looking.
A Scheme is not a physical thing. It is a set of arrangements — risk assessments, zone controls, training, registers, inspections, records, and the habits of the people carrying them out. Asking whether those arrangements work is a different kind of question, and it cannot be answered by examining hardware. A survey can tell you that a bracket was unsecured. It cannot tell you why your system allowed it to be.
3.2A survey is periodic; a scheme changes continuously
The Recommended Practice requires independent inspection before start-up and at least every three years thereafter. Between those points, crews rotate, contractors change, equipment is installed and removed, procedures are revised, and operations move. A survey is a photograph of the equipment. It is not a record of whether the arrangements held in the intervening period.
3.3A survey covers an asset; the Scheme belongs to the company
A survey is commissioned for a location and reports on that location. A Dropped Object Prevention Scheme is a company arrangement applied across locations. An organisation can hold a set of good survey reports and still have no view of whether its Scheme is applied consistently — or of where it is being applied well.
That second point is easily missed. Where oversight across locations is absent, good practice at one site is not noticed, and therefore never reaches the sites that need it. An assessment at company level finds strengths as well as gaps, and the strengths are usually the fastest route to closing the gaps.
3.4The Recommended Practice asks for more than a survey provides
Section 3.1 states that, in addition to examining equipment, auditors test the implementation of the site’s governing Dropped Object requirements. That is an assessment of a management system, and the Recommended Practice places it inside the independent inspection.
The DROPS Common Guidelines for Independent Dropped Object Surveys set out what a surveyor should be competent in: survey and inspection technique, structural integrity assessment, rope access, safe working at height, permit to work, tools-at-height systems, reliable securing, safe bolting, lifting and cargo handling, moving and dynamic equipment, drilling equipment, safety alerts, task risk assessment, hazard reporting, and the asset’s own DROPS arrangements. Fifteen subjects, all of them necessary, and none of them a method for assessing a management system.
3.5What a surveyor can verify, and what needs someone else
The distinction matters practically, because it determines who can check an assessment once it has been made. Most of the fifteen themes rest on conditions a competent surveyor can establish during a visit they are already making.
- Verifiable during a survey: inspection programmes, equipment at height, reliable securing, working at height, tubular handling, lifting and hoisting, shipping and transport, zone management, and much of equipment design. Registers can be compared against what is installed; completed checklists can be read; barriers, signage, tethers and kit can be seen.
- Not verifiable during a survey: the management system itself, roles and responsibilities, the interface with other companies, assurance, human performance, and parts of risk assessment. A surveyor can confirm that a bridging document exists. Whether it is any good, and whether the roles in it match who actually does the work, is a different judgement.
These are two different jobs rather than a choice between two kinds of person. Chapter 12 sets out how each is best performed.
The Three Levels of Assurance
The Recommended Practice already describes the structure this document works within. Section 3.5 requires assurance that documents conformance, performed by the company to verify that work conforms to its own practices and procedures and to those of its contractors, evaluating the Scheme as agreed in the bridging document. It names three methods.
4.1Self-verification
DROPS inspection completed by site personnel. Action items are tracked to closure by the assessment owner, and assessors are competent once they have received the appropriate level of training.
This is the level closest to the work and the one that can be performed most often. It is also the level with the least distance from what it examines.
4.2Company verification
DROPS inspection completed by a company representative from outside site operations, who has completed DROPS Focal Point training or is a recognised subject matter expert. Action items are tracked to closure by the auditee.
The distance here is organisational rather than contractual. Someone from another part of the same company satisfies this level. For organisations with more than one location it is the cheapest useful independence available, and it is the level most often missing entirely.
4.3Independent verification
Independent inspection or survey performed by a qualified external auditor, or by internal auditors from outside the business unit being audited, every three years or when the company deems it appropriate. Action items are tracked to closure by the auditee.
This is the level the industry already provides, and the only one with an established market. The first two have no published method at all, which is what these guidelines set out to supply.
4.4What all three have in common
Each of the three levels carries the same obligation: action items are tracked to closure. It appears three times in one short section of the Recommended Practice, and it is the requirement most often unmet. An assurance activity that produces findings nobody closes has documented a problem rather than addressed one.
Core Principles
The following principles govern how the question set is built and how an assessment should be carried out. They are stated plainly because each is a choice, and because anyone using the instrument is entitled to know why it behaves as it does.
5.1Assess What Happens, Not What Is Written
An arrangement is assessed on whether it reliably happens, not on whether it has been documented. A company whose crews do the right thing without a written procedure is not in the same position as a company that does nothing, and a company with a thorough manual that nobody follows is not compliant.
Documentation does not disappear from the assessment — it becomes evidence. Where the Recommended Practice requires a specific record, register or checklist, that record is itself the requirement and its absence is a genuine shortfall. Elsewhere, documents are how a claim is demonstrated rather than the thing being claimed.
5.2The Level Descriptions Are the Instrument
Where the person carrying out the assessment also selects the rating, the wording of the levels is the only thing standing between an assessment and an opinion. "Some requirements met" measures nothing. "Rated tethers are required, available and used on every job at height, with a tool count completed before and after" measures something.
Every question therefore carries four level descriptions written as observable conditions specific to that question. No two questions share level descriptions, because descriptions general enough to be reused stop discriminating.
5.3There Is No Overall Score
Each theme carries its own rating. Those ratings are not combined into a single figure, and no pass mark is published.
A single number would conceal the one theme that matters. An organisation with thirteen strong themes and one absent control would present well, and it is precisely that organisation which most needs to know. A single number also invites the reader to answer for the score rather than for the truth, which defeats the purpose of assessing yourself at all.
5.4Requirement and Guidance Are Not the Same Thing
Each section of the Recommended Practice contains a normative Recommended Practice block and a supplementary Additional Guidance block. The guidance is largely worked examples of how to satisfy the requirement above it — section 2.4 introduces its guidance as examples of the application of the hierarchy of controls.
Questions are therefore written against the requirement, and the guidance is used to describe what meeting it usually looks like. A risk register is the common way of tracking identified risks and the status of actions; it is not itself the requirement. An organisation meeting the requirement another way is compliant — provided it can demonstrate it. Without that condition, "we do it differently" becomes an answer to every question.
5.5Evidence Rises With the Claim
The higher the rating claimed, the more the instrument asks to be shown. A rating of 0 or 1 requires nothing to be proved; there is no incentive to overstate a weakness. A rating of 2 or 3 opens the detailed questions for that theme, and every one of them is then answered.
They are all answered because otherwise reducing a rating becomes a way of escaping the questions, and because the detailed answers are the useful output. An assessment that stops at the first problem found produces one gap instead of the list.
5.6One Requirement, Seen From Three Angles
Different levels of an organisation know different things. Head office knows what has been established. Site management knows whether it is implemented. The people doing the work know whether it is real. Asking all three the identical question produces a guess at two of the three levels.
So a requirement may carry more than one question, each written for what that level can actually know, and the answers are recorded separately. Chapter 10 sets out how this works and why the differences between the answers are the most useful thing an assessment produces.
5.7Self-Assessment Precedes Verification and Does Not Replace It
A self-assessment is not a substitute for independent verification, and it is not a lesser version of it. It is the step before it. Assessing yourself first drives improvement before anyone external arrives, and it makes the verification that follows shorter and cheaper, because the verifier is not spending the first day establishing facts the organisation could have supplied.
This is the sequence the wider industry already uses for contractor assessment: the organisation completes the assessment, and a client or third party verifies it against the same instrument.
5.8Scale to Risk, Not to Size
Every theme that applies to an organisation applies in full. What varies with size and complexity is the depth of the arrangements, not the list of them. A small operator is not excused from zone management; it will simply have a simpler way of doing it, and that simpler way may be entirely adequate.
The instrument therefore prescribes what must be demonstrated and never how it must be arranged. An assessment that marks a small organisation down for the absence of machinery it does not need has measured the wrong thing.
5.9"Self" Depends on Where You Stand
Self-assessment is not one activity. A crew reviewing its own task, a site assessing itself, a group from elsewhere in the company assessing a site, and an external auditor are four different degrees of distance, and the first three all count as self-assessment when viewed from outside the organisation.
Every assessment should therefore record who performed it — the people who run the work, another part of the same company, or an external party. That single field changes how the whole result should be read, and it costs nothing to capture.
Terms and Definitions
These terms are used consistently throughout. Where an organisation uses different words for the same things, the local words are perfectly acceptable, provided the meaning is clear.
- Assessment — the act of judging arrangements against a requirement.
- Self-assessment — an assessment carried out by the organisation being assessed, at any of the levels described in chapter 4.
- Verification — confirmation by a party at greater distance from the work that an assessment is accurate.
- Audit — used here for both the activity and the instrument. It carries no implication that DROPS Forum has judged, certified or endorsed anything.
- Theme — one of the fifteen subject areas, corresponding to the fourteen minimum requirements of the Recommended Practice plus Human Performance.
- Theme question — the single question that carries a theme’s rating.
- Depth question — a question beneath a theme, opened when the theme is rated 2 or 3, which tests that rating and does not carry its own weight in the result.
- Finding — a shortfall against a requirement of the Recommended Practice.
- Observation — something worth addressing that is not a shortfall against a requirement.
- Not applicable — a theme that does not apply to the operation being assessed. Set during scoping, with a reason.
- Not examined — a theme or question that was not looked at. A legitimate answer, and distinct from not applicable.
Running an Assessment
An assessment proceeds in eight steps. Most of the effort sits in the third.
7.1Scope
Establish what is being assessed — a site, a business unit, or the company — which themes apply, and which carry the most risk in this operation. Record who is performing the assessment and at what distance from the work. Chapter 9 covers this.
7.2Rate
Answer the fifteen theme questions. For many organisations this is the whole assessment, and it should be treated as a complete piece of work rather than a preliminary. Read all four level descriptions before choosing; if two seem to fit equally, the lower one is the honest answer.
7.3Evidence
For every theme rated 2 or 3, work through the detailed questions and gather what each asks to see. This is where the time goes, and it is where an assessment stops being an opinion. Answers that cannot be evidenced are not wrong — they are simply answers at a lower level than was claimed.
7.4Reconsider
Look back at the theme rating beside the detailed answers underneath it, and decide whether it still stands. Record both the original rating and any revision.
7.5Prioritise
Order the results with the lowest ratings first, using the risk weighting from scoping to separate themes that scored the same. Name the strongest themes as well: they are usually where the capability to fix the weakest ones already exists.
7.6Act
Assign each gap an owner and a date. An assessment whose findings are not tracked to closure has not met the requirement that produced it.
7.7Verify
Have the assessment checked by someone at greater distance from the work — another part of the company, or an external party. Chapter 12 sets out who can verify what.
7.8Working through it in stages
Few organisations will complete an assessment in one exercise, and there is no need to. Taking one theme at a time, over months, is a legitimate way to do this and often a more realistic one. Themes belong to different people — lifting to whoever owns lifting, training to the HSE function, inspection to the technical side — and assigning a theme to its natural owner works better than one person pursuing fourteen colleagues.
It also protects the effort. An organisation that has completed three themes properly has three themes of value. One that abandoned a long document part way through has none.
- Scope once, and rate all fifteen themes before splitting anything up. That is an hour or two and it produces a complete picture immediately. The detailed work then rotates underneath a result that already exists, rather than the result waiting on the last theme.
- Take the themes in the order scoping produced — lowest rated first, weighted by the themes identified as carrying most risk. Working through in chapter order means the theme that matters most may be examined last.
- Date each theme and show the dates. Fifteen themes assessed across a year is not a snapshot; the organisation changed underneath it. That is perfectly acceptable so long as nobody reads it as a picture taken on one day.
The fifteen theme questions are cheap to repeat, so re-rating them at the end of a cycle gives a current picture while the detailed work continues to rotate. That comparison — the same fifteen questions a year apart — is more informative than any single assessment.
Two things to watch. Weaknesses that cut across themes — the same gap appearing in inspection, assurance and management of change — are among the most useful findings an assessment produces, and they are hard to see when those themes are examined months apart. And one theme a month becomes one a quarter and then stops. Both are manageable provided the result always states what has been examined, what has not, and when each was done.
7.9Repeat
Reassess on a defined cycle, and whenever the Scheme, the organisation or the operation changes materially. Comparing your own result year on year is considerably more informative than comparing it with another organisation’s, because the same people are applying the same standard to themselves.
The Rating Scale
Every question is rated on the same four levels. They measure whether an arrangement reliably happens, and whether anyone checks that it is working.
| Level | What that looks like |
|---|---|
| 0 | Nothing. There is no arrangement for this at all. |
| 1 | Something exists but it does not hold — partial, intermittent, or dependent on particular people. A procedure that exists and is not followed sits here. |
| 2 | Reliable. It happens as it should, every time, and there is something to show for it. |
| 3 | Reliable and checked. Someone looks to see whether it is working, finds things, and acts on them. |
8.1What the levels are asking
The question behind every rating is whether the arrangement can be relied on. Three things have to be true, and they fail independently: the arrangement has to exist, it has to be followed, and it has to still be followed a year later.
Each level marks how many of those hold. A procedure that exists and is not followed is rated 1, not 2 — the document is real but the arrangement is not. Practice that is genuinely followed but written nowhere is also rated 1, for the opposite reason: it holds today and there is nothing to make it hold after a crew change.
8.2What to aim for
Level 2 on every theme that applies, and level 3 on the themes identified during scoping as carrying the most risk. An organisation at level 3 across every theme has either an unusually mature Scheme or an unusually generous view of itself, and the detailed questions exist to establish which.
8.3Answers that are not ratings
Two answers sit outside the scale, and they are not interchangeable.
- Not applicable. Set during scoping, with a one-line reason. It does not count as a zero and does not appear in the priority list. Because there is no overall score, marking themes not applicable is the only remaining way to flatter a result, which is why the reason is required.
- Not examined. The theme or question was not looked at. A legitimate answer; the report states how much was examined and how much was not.
Neither is a failure, and neither should be avoided out of a sense that a complete sheet looks better. A result that honestly records what was not applicable and what was not examined is more useful than one that guesses.
Scoping: What Applies to You
Answer these before starting. They establish which themes apply and which matter most, so that neither question has to be revisited fifteen times.
- What does this assessment cover — a single site, a business unit, or the whole company?
- Who is performing it: the people who run the work, another part of the company, or an external party?
- Do you run tubulars?
- Do you share worksites with other companies?
- Do you specify, manufacture or modify equipment, or only operate what others supply?
- Do you ship equipment between sites?
- Which three themes carry the most risk in your operation?
The last question does real work. Where two themes receive the same rating, the ones identified here rise higher in the report. An operation running continuous lifting and a plant doing mostly maintenance should not receive the same priority list from identical ratings.
Assessing at Three Levels of the Organisation
The most common weakness in a self-assessment is that one person answers on behalf of an entire organisation. They answer honestly, and they answer for the part of it they can see.
The remedy is not to ask more people the same question. It is to recognise that different levels of an organisation know different things.
10.1Each level knows something different
- Head office knows what has been established — whether the arrangement exists, what it requires, whether it is current.
- Site management knows whether it is implemented — whether it happens here, whether the records are complete, who does it.
- The people doing the work know whether it is real — what happens on a night shift when the job is behind and nobody is watching.
Those three correspond exactly to the three ways a requirement fails: never established, established but not implemented, implemented but not maintained. Asking at one level tells you about one of the three.
10.2One requirement, more than one question
A requirement may therefore carry up to three questions, each written for what that level can actually know. Asking the identical question at every level produces a guess at two of them. Tool tethering, as an example:
- Head office: what does your working at height procedure require for tethering and tool inventories, and how is it kept current?
- Site management: which kit is in use here, are pre-job and post-job counts completed, and can you produce the last three?
- The crew: what do you take up, what do you clip it to, and what happens if something does not come back down?
One requirement, three questions, three answers recorded separately. Not every question needs all three levels — many are properly answered at one — and each question states who it is for.
10.3The differences are the most useful output
An assessment answered at more than one level produces something no single respondent can: the difference between what the organisation believes, what its records show, and what its people experience. That difference is the point of asking, and which difference appears tells you what kind of problem you have.
- Head office describes an arrangement the site does not recognise — it was established and never implemented.
- Site records show compliance the crew does not describe — records without practice, or a supervision gap.
- The crew describes good practice head office knows nothing about — sound informal practice with no system behind it. Valuable, and fragile: it will not survive a crew change, and it handles unfamiliar situations badly.
10.4How to reach each level
Each level is best reached a different way, and the organisation does not have to perform all three itself.
- Head office is the easiest to assess internally. It is largely a matter of reading your own documents and knowing when they were last revised.
- Site management is where an external surveyor already is. Records, completed checklists, registers against installed equipment — this is most of what a verification visit covers anyway.
- The people doing the work is the level most often skipped, and the one where someone outside the reporting line has a real advantage. A crew answering in front of their supervisor tends to agree with their supervisor. A guided conversation, or an external party, does not carry that difficulty.
Record how and where each level was asked, and how many people took part. This is a factual note rather than a judgement, and it lets whoever reads the result weigh it properly.
10.5Answers are attributed, and the organisation makes that safe
These guidelines do not recommend anonymous responses. In a crew of eight an anonymous answer about a particular job is identifiable from its content, so anonymity is difficult to deliver honestly. More importantly, requiring people to be anonymous in order to be candid accepts that candour is unsafe, and works around the problem instead of addressing it.
The condition for gathering the third level is therefore that the organisation makes honest answers safe, and is seen to. That is a statement about the organisation, not about the instrument. Where an organisation is not prepared to make that commitment, the workforce level should not be attempted — asking people to take a personal risk on the assessor’s behalf is not a reasonable thing to do.
10.6One level is still a valid assessment
Most organisations will not reach all three levels the first time, and an assessment answered at one level is legitimate. It simply says less, and the result should state how many levels were consulted so that nobody mistakes its reach.
Adding a second level is usually the single largest improvement available to a self-assessment, and it costs nothing but the willingness to hear a different answer.
Using the Results
An assessment produces a picture, not a verdict. Presenting it well matters, because the point is to act on it.
11.1Lowest first
Order the themes by rating, lowest first, using the risk weighting from scoping to separate equal ratings. The first page should show where to start rather than a summary.
11.2Name the strengths as well
Report the strongest themes too. This is not to soften the result: where oversight across a company is thin, organisations are frequently unaware of what they do well, so it never reaches the places that need it. If your inspection programme is strong and your zone management is weak, the people who built the first are the best available resource for the second — and that only helps if the result says which is which.
11.3Where the levels disagreed
Give the differences between levels their own place in the result, together with what was done about each. They are the least comfortable part of an assessment and the most informative.
11.4Showing the result to a customer
A self-assessment is a reasonable thing to share, and in contractor assessment across the wider industry the organisation’s own assessment is routinely provided to the client alongside any verification.
What makes it credible is candour rather than the ratings. An assessment claiming the top level everywhere tells a reader very little, because anyone can claim it. One that says we are at level 1 on management of change and level 2 on zones, and here is what we are doing about both is difficult to dismiss and difficult to fake — claiming to be worse than you are carries no advantage.
Verifying an Assessment
Verification asks a different question from assessment. Not how good is this Scheme, but is what this organisation has said about itself accurate. That is a narrower question, and a considerably easier one to answer well.
12.1Verify claims, do not re-assess the system
Because the assessment already exists, verification can be targeted. Sample the themes rated 3. Investigate where the levels of the organisation disagreed. Note what was marked not examined. The verifier is never required to decide what good looks like — they are asked to confirm or refute specific statements.
That distinction matters for who can do the work. Assessing a management system is an open-ended judgement requiring audit competence. Establishing whether a stated claim is true is much closer to what a competent surveyor does routinely, and most claims in this instrument are physically checkable: whether tethers are rated for the tools in use, whether a register matches what is installed, whether the last three pre-lift checks are complete and within date, whether a zone is barricaded and signed.
12.2Your existing inspection provider can carry much of this
Most organisations already engage an inspection or survey company, and already have them on site periodically. That visit is the natural place for most of the verification to happen, and both parties frequently miss it.
12.3Who verifies what
Following the split in chapter 3, verification divides into two pieces of work rather than requiring one person to do everything.
- The themes resting on physical conditions and records can be verified by a competent surveyor working from a checklist derived from the organisation’s own answers, during a visit already being made.
- The themes resting on judgement — the management system, roles, interfaces, assurance, human performance — need someone who can read a management system and interview people. Where that is not available, those themes remain self-declared and should be labelled as such.
12.4The difference between declared and found
The most valuable output of verification is not a second set of ratings. It is the difference between what the organisation declared and what the verifier found, together with the verifier’s view of how reliable the answers were.
That difference cannot be produced by a self-assessment at any level of effort, and it is the specific thing an external party adds. An organisation whose self-assessment proves accurate has demonstrated something about itself that no rating conveys.
12.5How often
The Recommended Practice sets independent verification at least every three years. Beyond that minimum, a sensible interval depends on how well the organisation’s own assessment has been performing. An organisation whose self-assessment reliably surfaces real problems needs outside confirmation less often than one whose assessment keeps coming back clean.
Using Digital Tools to Support an Assessment
Most of the effort in an assessment is not judgement. It is retrieval — finding the procedure, locating the completed checklists, working out when the register was last reconciled, and getting to the people who know what actually happens. That is the part that makes an honest assessment expensive, and it is the part software can genuinely reduce.
The DROPS Asia chapter has developed an assistant that connects to the AI tools people already use, and is extending it to support the activities described in this chapter. It is offered as an aid to carrying out these guidelines, not as a substitute for them: the questions, the levels and the judgement remain the same whether or not any software is involved.
13.1Reading your own documents
Much of what an assessment needs is already written down somewhere in the organisation. Upload the working at height procedure, the lifting management system, the bridging documents, the inspection schedule, and the assistant can locate what each question asks for and show you where it found it.
Two uses, and the second is the more valuable. It can shorten the retrieval — telling you in seconds whether your procedure specifies rated tethers, requires a tool count, or names who authorises restarting when an item is unaccounted for. And it can tell you what the Recommended Practice asks for that your documents do not mention, which is difficult to see by reading your own material.
13.2Conversations with the people doing the work
Chapter 10 sets out why the third level — what the people doing the work actually experience — is the one most often skipped, and the hardest to gather honestly. A guided conversation addresses part of that difficulty.
A crew member can work through the questions relevant to their role in a few minutes, in their own words, and the assistant can follow up where an answer is vague or interesting — which a paper form cannot do, and which is where the useful detail sits. It also scales. Interviewing thirty people is impractical; letting thirty people each have a short conversation is not.
The conditions in chapter 10 apply in full. Answers are attributed, the organisation is expected to make honest answers safe, and where it will not, this activity should not be undertaken.
13.3Recording it in one place
Answers gathered at different levels, at different times and by different people are only useful if they end up together. The assistant records what it gathers against the question it belongs to, so that an assessment assembled over several weeks and several sites produces one coherent result rather than a folder of documents.
Holding it in one place is what makes two things possible that are otherwise manual. Comparing the answers from different levels of the organisation, which chapter 10 identifies as the most useful output of an assessment. And comparing this year against last year, which is the comparison that tells an organisation whether it is improving.
It matters more again where an assessment is worked through in stages, as chapter 7.8 describes. A theme completed in March and a theme completed in October are only a single assessment if something holds them together, keeps each one dated, and can still show at any point what has been examined and what has not. Otherwise a staged assessment becomes fifteen separate documents that nobody assembles.
13.4Supporting verification
Where the same record holds both an organisation’s own assessment and a verifier’s findings, the difference between them can be produced directly rather than assembled by hand. Chapter 12 identifies that difference as the real output of verification.
It also makes the verification visit more efficient. A checklist generated from the organisation’s own answers tells the verifier which specific claims to test, rather than leaving them to work out what to examine after they arrive.
13.5What software does not change
An assistant can find, prompt, follow up and record. It cannot decide what good looks like, and it should not propose a rating: the person answering selects the level, and an assistant that suggests one first has anchored the answer it was supposed to gather.
Nor does any of this alter what a self-assessment can establish. The limits described in the next chapter are properties of the organisation, not of the method, and no tool removes them.
Why Independent Verification Remains Necessary
It is worth being precise about the limits of assessing yourself, because the usual explanations are not the real one.
It is not a question of access. An organisation can walk its own deck, read its own records and talk to its own people, and structured self-evaluation elsewhere in industry requires exactly that — a review of written arrangements, a walk through the workplace, and interviews with employees. Everything this instrument asks for is reachable from inside.
Nor is it a question of method. Questions can be written well, levels can be described as observable conditions, and evidence can be required in proportion to the claim. That is what these guidelines are for.
That is the irreducible contribution of independent verification, and it explains why the Recommended Practice retains a third level of assurance rather than treating self-verification as sufficient. It is also why the two are complementary rather than competing: the self-assessment finds and fixes what the organisation can see, and the verification establishes whether the organisation was seeing clearly.
An organisation that assesses itself thoroughly and then has that assessment confirmed has something considerably stronger than either activity alone would produce.
The Question Set
The question set covers the fourteen minimum requirements listed in section 2.1 of the Recommended Practice, together with Human Performance as a fifteenth theme. Revision 02 of the Recommended Practice added a Human Performance section without updating its own table of minimum requirements, which is why it appears here as a labelled addition rather than as one of the fourteen.
Each theme carries one question and one rating. Beneath the themes rated 2 or 3, detailed questions open to test that rating; they do not carry ratings of their own. Each question states what the Recommended Practice requires, what to look for as evidence, and who in the organisation should answer it.
Management System
What the standard requires (Minimum requirement 1 · RP §2.1)
Where dropped object hazards are present, a Dropped Object Prevention Scheme shall be in place.
Is there a documented Dropped Object Prevention Scheme covering everywhere your people work at or below height, and does the work actually follow it?
| Level | What that looks like |
|---|---|
| 0 | No scheme. Dropped objects are handled as part of general safety, with nothing specific written down. |
| 1 | A scheme exists but does not cover everywhere, or is out of date, or does not match what people actually do. |
| 2 | A current scheme covers all your locations and activities, and what happens on site matches what it says. |
| 3 | As level 2, and someone periodically checks that the scheme still matches practice, with the differences acted on rather than noted. |
Who should answer: General manager or HSE manager, with site management confirming what happens in practice.
Also ask: would this still work if the crew changed next month?
Roles and Responsibilities
What the standard requires (Minimum requirement 2 · RP §2.1 and §2.5)
Companies shall create job specific roles, responsibilities, training, and competencies for dropped object prevention. Job positions are evaluated to identify at-risk personnel as well as barrier owners, and a Focal Point or Field Champion of applicable competency is appointed at each location.
Has every job position been assessed to identify who is exposed to dropped objects and who owns each control, and is a competent Focal Point appointed at each location?
| Level | What that looks like |
|---|---|
| 0 | Nobody is specifically responsible. Dropped object prevention belongs to everyone and therefore to no one. |
| 1 | A Focal Point exists at some locations, or the role is held by someone alongside several others and gets whatever time is left over. |
| 2 | Positions have been assessed for exposure and barrier ownership, a competent Focal Point is appointed at each location, and the people named know what they own. |
| 3 | As level 2, and ownership is reviewed when the organisation changes, with gaps closed before they matter. |
Who should answer: HSE manager for the assessment, site management for the appointments, workforce for whether they know who to go to.
Also ask: would this still work if the crew changed next month?
Working Alongside Other Companies
What the standard requires (Minimum requirement 3 · RP §2.1 and §2.6)
While work is being conducted between multiple companies, prevailing DROPS requirements shall be clearly communicated and understood by all present. Each company evaluates its Scheme against the minimum guidelines in the Recommended Practice to identify gaps.
When you work alongside other companies, is it clear whose dropped object rules apply, and does everyone on site actually know?
| Level | What that looks like |
|---|---|
| 0 | Nothing is agreed. Each company assumes its own rules apply. |
| 1 | A bridging document exists but is generic, out of date, or unknown to the people doing the work. |
| 2 | Whose rules prevail is agreed in writing before work starts, the differences between the two schemes are identified, and the people on site can tell you which applies. |
| 3 | As level 2, and the bridge is reviewed when either scheme changes or when the scope of work changes. |
Who should answer: HSE manager and contract holder, with the workforce of the visiting company as the real test.
Also ask: would this still work if the crew changed next month?
Risk Assessment
What the standard requires (Minimum requirement 4 · RP §2.1 and §2.2)
Risk assessments shall be conducted prior to beginning work to identify job-specific dropped object hazards and put controls in place. They cover area-specific activities and conditions, and the DROPS Calculator is utilized during job planning to identify hazards and implement both prevention controls and zone management.
Does every job that could drop something get assessed for that specifically before it starts, and do the controls that come out of it get put in place?
| Level | What that looks like |
|---|---|
| 0 | Dropped objects are not considered separately in risk assessment. |
| 1 | Dropped objects appear on the form but the entry is generic, or the assessment is copied from a previous job without being revisited. |
| 2 | Every job with a dropped object exposure is assessed for it before work starts, covering that area’s own conditions, with the controls carried through into the job. |
| 3 | As level 2, and the effectiveness of the controls is monitored afterwards, with what is learned fed back into the next assessment. |
Who should answer: HSE manager and the supervisors who write them; workforce for whether they take part.
Also ask: would this still work if the crew changed next month?
Inspection
What the standard requires (Minimum requirement 5 · RP §2.1 and §3.1–3.3)
Companies shall implement full inspection programs including Independent Inspections minimally every 3 years, systematic inspections for specifically identified equipment, unplanned inspections, and train competent personnel to properly inspect.
Do you have all three kinds of inspection running — independent surveys at least every three years, a systematic programme of your own, and unplanned inspections after unexpected events — with competent people doing them?
| Level | What that looks like |
|---|---|
| 0 | Inspections happen when someone thinks of them. No programme, no schedule. |
| 1 | One or two of the three exist. Commonly the independent survey happens and the systematic programme has drifted, or nobody is clear what triggers an unplanned inspection. |
| 2 | All three run to a defined schedule, the people doing them are trained for it, and the findings are recorded. |
| 3 | As level 2, and findings are tracked to closure with overdue items escalated rather than accumulating. |
Who should answer: HSE or technical manager for the programme, site management for completion, workforce for whether they are asked to inspect anything.
Also ask: would this still work if the crew changed next month?
Equipment Design and Selection
What the standard requires (Minimum requirement 6 · RP §2.1 and §4.1)
Manufactured equipment shall be designed to eliminate dropped object exposure where possible. Equipment and systems are easily accessed for maintenance and inspection, and design considerations include anti-collision measures, corrosion, limiting mass, and the equipment’s own dropped object history.
When you specify, buy or modify equipment, is dropped object exposure designed out — and does a piece of equipment’s track record influence whether you buy it again?
| Level | What that looks like |
|---|---|
| 0 | Dropped object exposure is not considered when equipment is specified or bought. |
| 1 | It is considered informally by individuals, or only for major purchases. |
| 2 | Purchase specifications require dropped object prevention features, accessibility for inspection, and secondary retention fitted by the manufacturer. |
| 3 | As level 2, and the dropped object history of equipment already in service feeds back into what you buy next. |
Who should answer: Technical or procurement manager. Often the theme with the least clear owner.
Also ask: would this still work if the crew changed next month?
Equipment at Height
What the standard requires (Minimum requirement 7 · RP §2.1 and §4.7)
All equipment at height shall be inspected and maintained per Original Equipment Manufacturer recommendations and Company policy. A log is kept of permanent equipment at height, and new equipment is included within the systematic inspection programme.
Do you have a complete register of what is up there, and is everything on it inspected and maintained to the manufacturer’s requirements?
| Level | What that looks like |
|---|---|
| 0 | No register. What is at height is known by the people who put it there. |
| 1 | A register exists but is incomplete, out of date, or not linked to the inspection programme. |
| 2 | The register is current and complete, and everything on it is in the inspection and maintenance programme at the intervals the manufacturer requires. |
| 3 | As level 2, and the register is reconciled against what is physically installed, with anything found that is not on it added and anything redundant removed. |
Who should answer: Technical manager for the register, site management for the reconciliation.
Also ask: would this still work if the crew changed next month?
Reliable Securing
What the standard requires (Minimum requirement 8 · RP §2.1 and §4.2)
All equipment at height that is not an integral part of the primary structure shall be reliably secured. Three levels apply — primary fixing, secondary retention, and safety securing — integrated into maintenance and inspection programmes. Safety securing is necessary where secondary retention is not feasible.
Is everything at height that is not part of the structure itself secured to all three levels the standard requires, and are those levels inspected as part of maintenance?
| Level | What that looks like |
|---|---|
| 0 | Securing is whatever was fitted originally. The three levels are not a concept in use. |
| 1 | Primary fixings are sound but secondary retention is inconsistent, or safety securing is absent where secondary retention is not possible. |
| 2 | All three levels are applied and specified, with safety securing used wherever secondary retention cannot be, and all three inspected within the maintenance programme. |
| 3 | As level 2, and the condition of retention and securing is judged as fit for purpose rather than just present. |
Who should answer: Technical manager and the inspectors.
Also ask: would this still work if the crew changed next month?
Working at Height
What the standard requires (Minimum requirement 9 · RP §2.1 and §4.5)
While working at height, all portable tools shall be transported in a secure manner and tethered while in use. Tools and tool kits must meet seven criteria covering locking systems, rated tethers, carrying pouches, engineered clips, carabiner design, an inventory checklist, and conformance to the company’s own working at height procedure.
Is everything taken up secured while it is up there, and does everything that went up come back down?
| Level | What that looks like |
|---|---|
| 0 | No requirement to tether. People take up what they need and are careful. |
| 1 | Tethers are used by some crews or on some jobs, or are available but not rated for the tools in use. |
| 2 | A certified tool-at-height kit is required and used on every job, with a tool count before and after that is actually completed. |
| 3 | As level 2, and someone checks that it is happening — spot checks, observations, or inspection of completed inventory sheets — and acts on what they find. |
Who should answer: Site management and the workforce. This is a theme where the crews will tell you more than the paperwork will.
Also ask: would this still work if the crew changed next month?
Asked at three levels of the organisation, as chapter 10 describes. The differences between the answers matter more than any one of them.
- Head office: What does your working at height procedure require for tethering, carrying and tool inventories, and when was it last revised against what crews actually do?
- Site management: Which kit is in use here, are pre-job and post-job counts completed for every job at height, and can you produce the last three?
- The crew: What do you take up, what do you clip it to, and what happens if something does not come back down?
15.9.1Which kit, and is it certified?
Do you use a certified tools-at-height kit, and does it cover locking systems for removable attachments, tethers rated to tool weight, approved carrying pouches, engineered clips for radios and gas detectors, and carabiners designed against accidental rollout?
| Level | What that looks like |
|---|---|
| 0 | No specified kit. People use what they have. |
| 1 | A kit is provided but people substitute their own tools, or parts of the kit are missing and not replaced. |
| 2 | A certified kit meeting all five criteria is specified, provided, and is the only thing taken to height. |
| 3 | As level 2, and kit condition is inspected on a schedule with damaged items withdrawn. |
15.9.2The tool count
Is a pre-job and post-job inventory checklist completed for work at height, and can you produce completed ones?
| Level | What that looks like |
|---|---|
| 0 | No inventory is taken. |
| 1 | A checklist exists but is completed inconsistently, or is filled in afterwards from memory. |
| 2 | Every job at height has a completed count before and after, and the sheets are retained. |
| 3 | As level 2, and the sheets are reviewed by someone other than the person who filled them in. |
15.9.3What happens when something does not come back
When an item logged out does not return, does that task stop and the area get searched — and if the item cannot be found, does the Person in Charge have to authorise resuming?
| Level | What that looks like |
|---|---|
| 0 | Nothing happens. A missing tool is noticed later or not at all. |
| 1 | People search informally, but there is no rule and no authority needed to carry on. |
| 2 | The task stops, the area is searched, and resuming without finding the item requires the Person in Charge to authorise it. |
| 3 | As level 2, and instances are recorded, so you know how often it happens. |
15.9.4Carrying tools up and down
Are tools and equipment transferred to and from height in secure, approved pouches rather than carried, pocketed, or hauled loose?
| Level | What that looks like |
|---|---|
| 0 | Tools are carried up however is convenient. |
| 1 | Pouches are available but not always used, particularly for short jobs. |
| 2 | Approved pouches are required and used for every transfer up and down. |
| 3 | As level 2, and the practice is observed and corrected when it slips. |
15.9.5Radios, gas detectors and other personal equipment
Are radios, gas detectors and other personal equipment secured with engineered clips?
| Level | What that looks like |
|---|---|
| 0 | Personal equipment is not considered — the focus is on tools. |
| 1 | Some items are clipped, others are pocketed or clipped to clothing. |
| 2 | Engineered clips are provided and used for all personal equipment taken to height, with radios in the pouch where clips are not available. |
| 3 | As level 2, and this is included in whatever checks are done. |
15.9.6Your own working at height procedure
Does the work conform to your company’s own working at height procedure, and does that procedure cover dropped objects specifically?
| Level | What that looks like |
|---|---|
| 0 | No working at height procedure, or none that mentions dropped objects. |
| 1 | A procedure exists but is generic, or predates your current tool arrangements. |
| 2 | A current procedure covers dropped objects specifically, and the work follows it. |
| 3 | As level 2, and the procedure is reviewed against what crews actually do, not just re-dated. |
15.9.7Would it survive a crew change?
If the crew doing this work changed next month, would the arrangement still hold?
| Level | What that looks like |
|---|---|
| 0 | No. This works because of who is currently here. |
| 1 | Partly. New people would pick it up eventually, informally. |
| 2 | Yes. It is specified, trained and equipped, so a new crew inherits it. |
| 3 | Yes, and it has been tested — the arrangement has survived a rotation or a contractor change without degrading. |
15.9.8Heavy tools, and what happens after a lanyard catches one
For tools of five kilos or more, is the work specifically risk assessed, are securing points positioned above the work site — and when a lanyard has arrested a falling tool, do both the lanyard and the tool come out of service until they have been inspected?
| Level | What that looks like |
|---|---|
| 0 | Heavy tools are treated the same as any other. Nothing happens after a tether catches something. |
| 1 | People are aware heavy tools need more care, but there is no separate assessment and a lanyard that has taken a shock load goes back in the box. |
| 2 | Tools of five kilos or more are specifically risk assessed, securing points are above the work site, and any lanyard and tool involved in an arrested fall are withdrawn until inspected. |
| 3 | As level 2, and withdrawals are recorded, so you know how often a tether has actually done its job. |
15.9.9Power tools
For powered tools used at height, is the supply cable or air hose secured at both ends, is retention attached to the tool body rather than to the cable, are sockets and extensions pin-locked, and are batteries locked in place?
| Level | What that looks like |
|---|---|
| 0 | Powered tools are taken up and used with no specific arrangements. |
| 1 | Powered tools are tethered, but retention is attached to the cable or hose, or attachments and batteries can come loose. |
| 2 | Cable and hose are secured at both ends, retention is on the tool body, sockets and extensions are pin-locked, and batteries are locked in. |
| 3 | As level 2, and powered tools are included in whatever pre-use checks and inspections are carried out. |
15.9.10Tools for work on electrical installations
Where work at height is done on electrical installations, are the lanyard and its attachment points insulated to the same standard as the tool grips, and are those tools kept for that work rather than used generally?
| Level | What that looks like |
|---|---|
| 0 | No distinction is made between tools for electrical work and any other tools. |
| 1 | Insulated tools are used, but their tethers and attachment points are not insulated, or the tools are also used for general work at height. |
| 2 | Lanyards and attachment points are insulated to the same standard as the grips, and the tools are reserved for that work. |
| 3 | As level 2, and the insulation is inspected on the same basis as the rest of the electrical equipment. |
15.9.11Storage, and the end-of-shift check
Are at-height tools kept in a secure storage facility, stored so that a glance shows what is missing, and does the person responsible check the facility and the register at the end of every shift?
| Level | What that looks like |
|---|---|
| 0 | At-height tools are stored with everything else, or wherever they were last left. |
| 1 | There is a dedicated store, but the contents are not laid out so gaps are visible and nothing is checked at shift end. |
| 2 | A secure store holds the at-height tools, laid out so a missing item is obvious, and a named person checks the store and register at the end of each shift. |
| 3 | As level 2, and discrepancies found at shift end are recorded and followed up rather than simply resolved. |
15.9.12Who inspects the tethers themselves
Is the tethering equipment inspected and certified — tools drop tested, lanyards batch tested, and written acceptance and rejection criteria available where the tools are kept?
| Level | What that looks like |
|---|---|
| 0 | Nobody inspects the tethers. They are used until they look wrong. |
| 1 | Tethers are bought certified but nothing checks them in service, or there is no stated basis for rejecting one. |
| 2 | Tooling is drop tested and certified, lanyards are batch tested and certified, and written acceptance and rejection criteria are available where the tools are stored. |
| 3 | As level 2, and someone competent inspects the kit on a schedule and withdraws what fails. |
Tubular Handling
What the standard requires (Minimum requirement 10 · RP §2.1 and §4.3)
Tubular handling mechanisms shall be measured, independently checked, and have functionality verified prior to use. During tripping, all areas containing moving parts are classified as a restricted access zone and non-essential personnel clear the floor.
Before tubulars are lifted, is the elevator physically measured against the tubular, and is the lifting apparatus load-rated and function-tested?
| Level | What that looks like |
|---|---|
| 0 | No pre-activity check beyond visual judgement. |
| 1 | A check happens but by eye rather than by measurement, or only when something looks wrong. |
| 2 | Internal diameter of the elevator is measured against the external diameter of the tubular, load rating and function are confirmed, and the check is recorded. |
| 3 | As level 2, and the checks are audited against records rather than assumed. |
Who should answer: Drilling supervisor and the crew doing the check.
Also ask: would this still work if the crew changed next month?
Lifting and Hoisting
What the standard requires (Minimum requirement 11 · RP §2.1 and §4.4)
A Lifting and Hoisting programme shall be in place that minimally meets the requirements of IOGP 376. Before a lift, an inspection physically verifies that no loose items are present in or around the load, and all lifting equipment is within inspection dates and certified.
Is there a lifting and hoisting management system meeting IOGP 376, and does someone physically check for loose items in and around every load before it is lifted?
| Level | What that looks like |
|---|---|
| 0 | Lifting is managed by competence and habit rather than by a system. |
| 1 | A lifting programme exists but does not classify lifts, or pre-lift checks are inconsistent. |
| 2 | A lifting and hoisting system meets IOGP 376, lifts are classified routine or non-routine, and a physical pre-lift check for loose items is completed and recorded. |
| 3 | As level 2, and the checks are verified rather than assumed, with findings acted on. |
Who should answer: Lifting focal point or crane supervisor, plus the riggers.
Also ask: would this still work if the crew changed next month?
Shipping and Transport
What the standard requires (Minimum requirement 12 · RP §2.1 and §3.4)
Pre-shipping inspections shall be completed prior to transporting equipment. Checklists address inspection activities, origin and destination, cargo identifiers, weight and the inspector’s name and date, and are kept on file. Equipment condition and packaging requirements are communicated to the worksite to ensure compliance in return of equipment.
Is equipment inspected for dropped object risk before it is shipped — and are the same requirements applied when it comes back?
| Level | What that looks like |
|---|---|
| 0 | No dropped object inspection before shipping. |
| 1 | Equipment is checked before it leaves but nothing covers its return, or the checklist is signed without the check being done. |
| 2 | A pre-shipment checklist covering loose items, fastening hardware, retention and load distribution is completed and retained, and return requirements are communicated to the worksite. |
| 3 | As level 2, and returned equipment is inspected on arrival against those requirements, with failures fed back. |
Who should answer: Logistics or materials manager, with the worksite receiving the equipment.
Also ask: would this still work if the crew changed next month?
Zone Management
What the standard requires (Minimum requirement 13 · RP §2.1 and §2.7)
Restricted Access and No-Entry Zones shall be established within the job plan based on job scope and dropped object risks present. Zones apply to everyone at the location including service partners and visitors, are marked with barricades and signage identifying the specific risk, have an identified authority controlling entry, and address emergency access and egress.
Are the areas where something could fall on someone identified, marked, and controlled — and does everyone on site, including visitors and service partners, know what the markings mean?
| Level | What that looks like |
|---|---|
| 0 | Zones are not defined. People are expected to be aware of what is overhead. |
| 1 | Zones exist in some areas or for some operations, or are marked but not controlled, or are known to your own crews but not to visiting companies. |
| 2 | Zones are defined for the work, physically marked with the specific risk stated, entry is controlled by a named authority, and they apply to everyone on site. |
| 3 | As level 2, and zones are re-examined when the operation changes, with temporary zones notified and removed deliberately. |
Who should answer: Site management for the arrangement, workforce and visiting contractors for whether it is understood.
Also ask: would this still work if the crew changed next month?
Asked at three levels of the organisation, as chapter 10 describes. The differences between the answers matter more than any one of them.
- Head office: How are exposure zones defined in your Scheme, who is accountable for them, and what triggers a zone to be reclassified?
- Site management: Show me the zone plan for this location and walk it with me. Who authorises entry to each, and where is that recorded?
- The crew: Which areas here are you not allowed into, how do you know when that applies, and who do you ask if you need to go in?
15.13.1Are the zones defined at all?
Are exclusion and restricted access zones defined for your operation — Black for total exclusion, Red for permanent restricted access, Yellow for temporary restricted access, Green for open access?
| Level | What that looks like |
|---|---|
| 0 | No zone scheme. |
| 1 | Some areas are treated as restricted by custom, but there is no defined scheme or the categories are used inconsistently. |
| 2 | The zone categories are defined, documented, and applied consistently across the location. |
| 3 | As level 2, and the definitions are reviewed against how they are actually used on site. |
15.13.2Marking and signage
Are zones and their access points clearly marked with physical barriers and signage that states the specific risk, rather than a generic warning?
| Level | What that looks like |
|---|---|
| 0 | No physical marking. |
| 1 | Barriers exist but signage is generic, missing, or does not say what the hazard is. |
| 2 | Zones and their access points are physically barricaded and signed, and the signage identifies the specific risk of that zone. |
| 3 | As level 2, and marking is inspected and reinstated when it degrades or is removed. |
15.13.3Who controls the zone
Is an authority identified for each zone, with responsibility for controlling entry established, delegated and communicated?
| Level | What that looks like |
|---|---|
| 0 | Nobody in particular controls entry. |
| 1 | There is an understanding of who is in charge, but it is not written down or it changes with shift. |
| 2 | Each zone has a named authority who controls and authorises entry, and people know who that is. |
| 3 | As level 2, and the arrangement is checked — entries are authorised in practice, not just in principle. |
15.13.4Does it apply to visitors and service partners?
Do the zone rules apply to everyone at the location — service partners, visiting contractors and visitors — and do they know?
| Level | What that looks like |
|---|---|
| 0 | The rules are for our own people. Visitors are escorted or trusted. |
| 1 | Visitors are told at induction, but nothing checks whether it stuck. |
| 2 | The rules apply to everyone on site, are communicated on arrival, and visiting personnel can describe them. |
| 3 | As level 2, and compliance by visiting companies is observed and addressed. |
15.13.5Emergency access and egress
When a zone is established, is emergency access and escape considered, so that people are not prevented from getting out?
| Level | What that looks like |
|---|---|
| 0 | Not considered. |
| 1 | Considered informally by whoever puts the barrier up. |
| 2 | Emergency access and egress are addressed when a zone is established, and escape routes remain usable. |
| 3 | As level 2, and this is verified — someone checks the route rather than assuming it. |
15.13.6Temporary zones
When a temporary zone is established, are people at the location notified so they do not enter it accidentally — and is it removed deliberately when the work ends?
| Level | What that looks like |
|---|---|
| 0 | Temporary barriers go up and come down without announcement. |
| 1 | People are told informally, or notification depends on who is putting it up. |
| 2 | Establishing a temporary zone triggers notification to everyone at the location, and removal is deliberate. |
| 3 | As level 2, and stale barriers are actively looked for — barriers that outlive their job train people to ignore them. |
15.13.7When the operation changes
When operations in an area change, is the zone classification revisited?
| Level | What that looks like |
|---|---|
| 0 | Zones are set once and stay as they are. |
| 1 | Changes are handled by whoever notices. |
| 2 | A change in operations triggers a review of the zone classification, and temporary reclassification happens where the risk assessment requires it. |
| 3 | As level 2, and you can point to a recent occasion when a zone was reclassified because the work changed. |
15.13.8Zones in the permit
Are no-entry zones identified in the permit to work, and are restricted zones established automatically during operations that require them, such as tripping?
| Level | What that looks like |
|---|---|
| 0 | Zones and permits are separate systems that do not reference each other. |
| 1 | Permits sometimes mention zones, depending on who writes them. |
| 2 | No-entry zones are identified in the permit, and areas with moving parts are classified as restricted during tripping with non-essential personnel clear. |
| 3 | As level 2, and permits are checked for this rather than trusted. |
15.13.9How were the zones arrived at?
Were your zones derived from a structured review of the areas — with prior incidents, layout drawings, equipment manuals, anti-collision details and operating procedures in front of the people doing it — or were they drawn from knowledge of the site?
| Level | What that looks like |
|---|---|
| 0 | Zones were marked out from experience, without a documented review. |
| 1 | A review was done, but by a small group without the drawings, incident history or equipment information in front of them. |
| 2 | A structured review covered each area, drew on prior incidents, layout drawings, equipment and maintenance manuals, anti-collision details and routine operating procedures, and included HSE and supervisory people. |
| 3 | As level 2, and the review is repeated when the area or its operations change, rather than standing as a one-off. |
15.13.10Standard work positions, and moving people out of them
Has the review identified where people habitually stand and work in each area — and where a standard position sits in harm’s way, has it been moved rather than fenced?
| Level | What that looks like |
|---|---|
| 0 | Standard work positions have not been identified. |
| 1 | It is understood informally where people stand, but no assessment has looked at separating those positions from the hazards. |
| 2 | Standard work positions are identified in each area and assessed for separation from moving or pressurised equipment, from objects that could fall, and for clear escape routes. |
| 3 | As level 2, and positions have actually been relocated where that was possible, with the change recorded. |
15.13.11The map, and how it was proved
Was the draft zone map physically checked on the ground before it was approved, and are zone maps displayed at the access points to the areas they cover?
| Level | What that looks like |
|---|---|
| 0 | No zone map, or a map that has never left the office. |
| 1 | A map exists and was approved on paper, or it exists but is not displayed where people enter the areas. |
| 2 | The draft map was walked and checked in the area before approval, and maps are displayed at access points. |
| 3 | As level 2, and the map is re-walked when the area changes, with displayed copies replaced. |
Assurance
What the standard requires (Minimum requirement 14 · RP §2.1 and §3.5)
Methods of assurance shall be implemented to show effectiveness of DROPS implementation. Assurance is performed by the company to verify that the work conforms to its own practices and procedures and with those of its contractors, and evaluates the governing Scheme as agreed in the bridging document. Three methodologies are named: self-verification, company-verification and independent-verification.
How do you know your dropped object scheme is actually working — and who checks, at what distance from the work?
| Level | What that looks like |
|---|---|
| 0 | Nothing checks. The scheme is assumed to work unless something happens. |
| 1 | Some checking happens, but by the people doing the work, or occasionally, or without findings being tracked. |
| 2 | All three levels run — site self-verification, company verification from outside site operations, and independent verification — with action items tracked to closure at each. |
| 3 | As level 2, and the assurance itself is evaluated: you know whether it is finding real things, and it covers your contractors as well as yourselves. |
Who should answer: HSE manager and the company auditor. This theme cannot be answered from the drill floor.
Also ask: would this still work if the crew changed next month?
Asked at three levels of the organisation, as chapter 10 describes. The differences between the answers matter more than any one of them.
- Head office: What assurance activities are scheduled at each of the three levels, who performs them, and how are their action items tracked to closure?
- Site management: When was this location last assessed, by whom, and what happened to the findings? Show me the action list.
- The crew: Has anyone come to check how this work is done? Who were they, what did they look at, and did anything change afterwards?
15.14.1Do all three levels exist?
Do you run all three of the assurance methods the standard names — self-verification by site personnel, company-verification from outside site operations, and independent verification?
| Level | What that looks like |
|---|---|
| 0 | None of the three run in any structured way. |
| 1 | One runs, usually the independent survey, and the other two do not. |
| 2 | All three run at defined intervals. |
| 3 | As level 2, and the mix is deliberate — you can say why each level runs at the frequency it does. |
15.14.2Self-verification
Do site personnel complete DROPS inspections as self-verification, and are the action items tracked to closure by the assessment owner?
| Level | What that looks like |
|---|---|
| 0 | Site personnel do not carry out structured self-verification. |
| 1 | Inspections happen but findings are noted rather than tracked, or nobody owns closure. |
| 2 | Site personnel complete DROPS inspections on a schedule, and the assessment owner tracks each action to closure. |
| 3 | As level 2, and overdue actions escalate rather than accumulate. |
15.14.3Company verification
Does someone from outside site operations verify the site’s scheme, and are they DROPS Focal Point trained or a recognised subject matter expert?
| Level | What that looks like |
|---|---|
| 0 | No verification from outside the site. |
| 1 | Someone visits, but from within site operations, or without specific DROPS competence. |
| 2 | A company representative from outside site operations carries out verification, holds Focal Point training or is a recognised expert, and the auditee tracks actions to closure. |
| 3 | As level 2, and their findings are compared with what the site found itself — the difference is the useful part. |
15.14.4Independent verification
Is independent verification carried out every three years or as your risk requires — by an external auditor, or by internal auditors from outside the business unit being audited?
| Level | What that looks like |
|---|---|
| 0 | No independent verification. |
| 1 | A survey is bought when a client asks for one. |
| 2 | Independent verification happens at least every three years, by a party outside the business unit assessed, with actions tracked to closure. |
| 3 | As level 2, and the interval is set by how well your own assurance is performing rather than by the calendar alone. |
15.14.5Does assurance cover your contractors?
Does your assurance verify that your contractors’ work conforms to the practices and procedures that apply to them, not only your own?
| Level | What that looks like |
|---|---|
| 0 | Assurance covers our own people only. |
| 1 | Contractor work is looked at when convenient or when there has been a problem. |
| 2 | Assurance explicitly covers contractor work against the requirements that apply to it, with findings raised to the contractor and tracked. |
| 3 | As level 2, and contractor findings feed into how you select and manage them next time. |
15.14.6Assurance against the bridging document
Where you work alongside other companies, does your assurance evaluate the scheme that was actually agreed in the bridging document?
| Level | What that looks like |
|---|---|
| 0 | Assurance does not reference bridging arrangements. |
| 1 | Bridging documents exist but assurance assesses against our own scheme regardless. |
| 2 | Assurance evaluates the governing scheme as agreed in the bridging document for that worksite. |
| 3 | As level 2, and mismatches between the bridge and practice are raised as findings. |
15.14.7Assessor competence
Are the people carrying out assurance at each level competent for it, and can you show how that was established?
| Level | What that looks like |
|---|---|
| 0 | Competence is assumed from role or experience. |
| 1 | Some assessors are trained, others inherited the task. |
| 2 | Assessors at each level hold the training the standard requires for that level, and the records exist. |
| 3 | As level 2, and competence is refreshed, with assurance quality itself reviewed. |
15.14.8When did an action last go overdue?
When did an assurance action last pass its due date, and what happened as a result?
| Level | What that looks like |
|---|---|
| 0 | Nobody could tell you. Due dates are not tracked. |
| 1 | Overdue items are visible in a list but nothing follows from being overdue. |
| 2 | Overdue actions trigger escalation to a named person, and you can describe a recent instance. |
| 3 | As level 2, and the pattern of overdue actions is reviewed — repeated overruns in one area are treated as a finding in themselves. |
Human Performance
What the standard requires (RP §2.10 — a fifteenth theme)
Human Performance programmes focus on identifying the nature of tasks, what errors could occur, the performance-shaping factors that make those errors more likely, the organisational factors that allowed them, and then challenge the controls managing them. Four elements are required at minimum: HP integration, HP competency, HP in proactive learning, and HP in investigations.
Do you treat human error as something your systems create conditions for, rather than something people simply do — and is that built into planning and investigation?
| Level | What that looks like |
|---|---|
| 0 | Human error is treated as a cause. Investigations end at what the person did. |
| 1 | There is awareness of human performance thinking, but it is not built into planning or investigation. |
| 2 | A documented human performance strategy exists with competency, proactive task analysis in job planning, and performance-shaping factors identified in investigations. |
| 3 | As level 2, and recommendations target those factors through the hierarchy of controls rather than through reminders and retraining. |
Who should answer: HSE manager. Workforce answers are particularly revealing here.
Also ask: would this still work if the crew changed next month?
Contributing to This Draft
This document is published in draft so that it can be argued with. Every chapter and every question carries its own discussion thread, and comments attach to the specific thing they concern rather than to the document as a whole.
- Questions that would not survive the field. If a question implies something no operation would actually do, it needs to go. Judgements of that kind are more valuable than any other comment, and they are best made by people who have run the work rather than written about it.
- Level descriptions that do not discriminate. If you read four levels and cannot tell which one you are, the descriptions have failed and need rewriting.
- Requirements that have been missed. The question set is written against the normative blocks of the Recommended Practice, but it is written by people and it will have gaps.
- Terminology that does not travel. Where a question uses a word your organisation does not use, say so — the intention is that every question can be answered whatever local vocabulary is in place.
- Length and effort. If completing a theme took longer than it was worth, that is a defect in the instrument rather than in the reader.
Commenting is by assigned access. If you would like to take part and do not yet have access, use the request form at the top of this document.