Begin a conversation

contact@drjimoh.com
+49 30 75435580
Planetenstr. 53, 12057 Berlin

Begin a conversation
Process & plant safety · No. 03

The grey zone of vendor responsibility in process and plant safety

In the process industry, safety expertise is increasingly bought rather than built — yet with every outsourced safety project, an invisible risk grows: the grey zone.

Chemicals, pharmaceuticals, energy — the pattern is the same everywhere: more complex assets, fewer specialists, more external consultants. What starts as a pragmatic solution becomes a systemic vulnerability. Between what a vendor executes and what an operator owns, a dangerous gap emerges.

In this article, you’ll learn what the grey zone actually means, why it’s so dangerous, and how you as an operator can maintain control — without giving up external expertise.

Core thesis: Execution can be outsourced. Accountability cannot. The grey zone emerges where companies confuse the two.

What is the grey zone in process & plant safety?

The grey zone doesn’t exist in routine tasks like scaffolding or standard maintenance — deliverables there are easily measured. It emerges in judgment-based PPS activities where external expertise is used to define risk or validate safety barriers.

Unlike a fixed-price contract for commodity services, PPS outsourcing involves the delegation of intellectual authority. The grey zone forms precisely where the boundary between “providing information” and “making a risk decision” becomes blurred.

Common failure points in practice

HAZOP facilitation vs. decision ownership. An external chair leads a hazard and operability study. If a critical scenario is missed — who failed? The facilitator for not digging deeper? Or the operator for not providing the right context?

SIL studies vs. risk acceptance. A vendor conducts a safety integrity level verification. The grey zone exists where the operator blindly accepts the “pass” without verifying if the underlying assumptions (e.g. test intervals) are operationally feasible.

External safety cases. When experts draft safety cases without internal challenge, the result is often a “paper reality” that doesn’t match site-level operations.

Why the grey zone is so dangerous

The danger is rooted in systemic misunderstandings of how responsibility functions in complex organizations.

The illusion of transferred liability

Many organizations subconsciously believe that hiring a top-tier consultancy transfers the liability for the risk. Legally — under Seveso III, OSHA PSM, or comparable regulations — this is a fallacy: the operator remains the sole duty holder.

Procurement-driven models

When PPS is procured as a commodity, focus shifts from “outcomes” to “deliverables.” This incentivizes vendors to limit their scope to the letter of the contract — avoiding the difficult conversations necessary for true safety.

Erosion of internal design authority

As companies lean heavily on external expertise, internal technical muscle atrophies. Organizations eventually lose the ability to intelligently challenge and vet external work — becoming blind customers.

The responsibility trap model: three layers of accountability

Traditional RACI charts often fail in PPS because they treat safety as a single task rather than a layered obligation. To manage the grey zone, three distinct layers must be understood.

Layer 01 — Execution

Technical calculations, HAZOP facilitation, modeling, laboratory testing, drafting reports. Owned by the provider, and fully outsourceable.

Layer 02 — Verification

Challenging assumptions, testing site-specific accuracy, accepting the deliverable as fit for use. Shared, and requiring a governed handover. This is the grey zone: shared in practice, unowned on paper, and where outsourced-safety failures originate.

Layer 03 — Accountability

Accepting residual risk, maintaining safety barriers, holding the license to operate. Operator only, and non-delegable.

Governing the grey zone: the playbook

The grey zone cannot be eliminated — but it can be governed. The key lies in shifting from pure vendor management to technical governance and establishing the role of the intelligent customer.

1. Explicit grey zone mapping

Before a project begins, map exactly where the vendor’s doing ends and the operator’s owning begins. Document who is responsible for the accuracy of input data — P&IDs, process conditions, operating history.

2. The input vs. conclusion rule

Treat vendor outputs as inputs to a decision, not the conclusion itself. A consultant report is evidence — the final decision to operate remains with site leadership.

3. Retain design authority internally

Maintain an internal nucleus of PPS expertise capable of challenging external work. Rule of thumb: if your internal team cannot explain the logic behind a vendor’s recommendation, you have lost control.

4. Structured sign-off

Final sign-off should be a formal acceptance of risk where the internal lead confirms they have reviewed and understood the vendor’s assumptions.

Implications for executives

For CEOs and boards

Your duty of care cannot be satisfied through a procurement report. Ensure your organization maintains the internal capability to verify that vendors are providing the right answers.

For operations leaders

Resist the urge to use vendors as a shield against difficult safety decisions. A vendor knows the standard — the operator knows the plant.

For procurement and legal

A contract is the floor, not the ceiling. Ensure contracts explicitly state that vendor reports are advisory and that the operator retains final decision-making authority.

Conclusion

The trend toward outsourcing in process and plant safety is irreversible. But the safety of an industrial asset doesn’t exist in a report — it lives in the culture and decision-making of the people who own the risk.

In process and plant safety, the greatest risk is not outsourcing the wrong task — but outsourcing clarity of responsibility.

Next step. Evaluate your current vendor setup using the three-layer model. Where is your grey zone? Contact us for a governance assessment.

Frequently asked questions about the grey zone

What exactly is the grey zone in process safety?

The grey zone describes the space where the execution of a safety task is outsourced to external providers, but accountability for the outcome remains legally and operationally with the operator. It emerges when companies confuse doing with owning.

Can I transfer liability for safety decisions to consultants?

No. Under Seveso III, OSHA PSM, and comparable regulations, the asset operator remains the sole duty holder. External reports serve as decision inputs, but accountability for risk acceptance and safety barriers cannot be delegated.

What does intelligent customer mean in PPS?

An intelligent customer has sufficient internal expertise to critically review and challenge external work. Without this capability, an organization becomes a blind customer unable to verify vendor outputs.

How can I identify the grey zone in my organization?

Use the three-layer model (execution, verification, accountability) and examine each outsourced PPS activity: who is responsible for input data? Who verifies assumptions? Who formally accepts residual risk?

What role does procurement play in the grey zone?

When PPS is procured as a commodity, focus shifts to deliverables rather than outcomes. Contracts should explicitly state that vendor reports are advisory and that the operator retains final decision-making authority.

Test this against your own setup.

A short, fixed-fee diagnostic will show where accountability, compliance or market-entry risk actually sits in your organization — before any larger commitment is discussed.

Begin a conversation
Dr. Mohammed Jimoh

Dr. Mohammed Jimoh

Founder and principal of Dr. Jimoh Consulting. Process engineer, certified Störfallbeauftragter, and former Managing Director of Bayer Middle Africa in Lagos. Full credentials and career record.